Privacy Policy
Last updated: 6 July 2026
1. Data controller
Sweliv is a social mobile application dedicated to sports activities between friends and within communities. The controller of your data is:
- Naillik · SIREN 943 911 594
- Bâtiment 7, 3 Impasse Achille, 06300 Nice, France
- Privacy contact: privacy@sweliv.com · Support: support@sweliv.com
We are committed to collecting only what is strictly necessary for the app to work.
2. Data collected
- Account & identity: email, first name, last name, username, profile picture, date of birth (used to compute your heart-rate zones), and the sign-in identifier from Apple or Google.
- Sports activities: sport, date, duration, distance, elevation gain, speed/pace, score (racket sports), title, description, and the GPS track of the session.
- Health & wellness data (sensitive category): heart rate, read via Apple Health (HealthKit) and/or a Bluetooth heart-rate strap, weight (to estimate calories), and workouts written to the Health app. See section 4. Bluetooth power and cadence sensors (cycling) are also read during the session.
- Location: your precise GPS position during a session, including in the background (screen locked), to record the activity track and share it live with the members of your groups. Outside a session, no location is recorded.
- Content & interactions: photos and videos (posts, activity photos, stories, chat media), comments, private and group messages (DMs), reactions, follows, groups, tagged training partners, and walkie-talkie voice messages sent during a live session (broadcast to authorized viewers then deleted after 60 seconds, never stored durably).
- Technical data: device identifier, push notification token, device model and OS version, IP address, crash and diagnostic logs.
- Subscription: the status of your Premium subscription (active/inactive). We never store your payment information: it remains managed by Apple.
3. Why we collect this data (legal bases)
- Create and manage your account and keep you signed in from one session to the next: performance of the contract.
- Record your activities and compute your statistics and rankings: performance of the contract.
- Share your live location with your group: your consent (revocable at any time).
- Read / record your heart rate and your health data: your explicit consent.
- Personalized programs: if you use the AI generator, your goal is sent to a language model (Anthropic) which returns a plan. No identifying data (name, email) is transmitted: your consent.
- Push notifications: your consent.
- Moderate content and prevent abuse: legitimate interest / legal obligation.
- Improve the app through anonymised crash reports: legitimate interest.
4. Health data: specific commitment
Your health data (heart rate, weight, workouts) is sensitive data, processed only with your explicit consent and used exclusively to display and record your sports performance. In accordance with Apple's rules:
- data coming from Apple Health (HealthKit) is never used for advertising or marketing purposes;
- it is never sold or shared with third parties for advertising purposes;
- you can revoke this access at any time in iOS Settings → Privacy & Security → Health.
5. Content visible to other users
Sweliv is a social application: by design, some data is visible to other users depending on your settings. Your profile, your published activities, your live location (shared with the members of your groups / mutual followers), your posts, comments and messages. You keep control over the visibility (public / private) of each activity and post, and you can hide your live session from specific people.
Discovery mode (optional, disabled by default, restricted to users aged 18 and over): if you enable it during a session, the other athletes live nearby who have also enabled it see a deliberately imprecise location (a 200 to 600 m grid) under a session pseudonym, never your exact position nor your identity. Nothing is broadcast near your start and finish point, in order to protect your home. Can be disabled at any time.
6. Sub-processors
Sweliv relies on the following sub-processors, each contractually bound to protect your data in accordance with the GDPR:
- Apple: sign-in (Sign in with Apple), push notifications, payments/subscriptions, Health (HealthKit).
- Firebase / Google (Google LLC, United States): authentication (Google sign-in), storage of profile and cover images and of the media you publish (activity photos and videos, posts).
- Expo (Expo, United States): delivery of push notifications (excluding chat messages).
- Open-Meteo: weather displayed on live sessions. The approximate location of the session is sent to them in order to obtain the temperature and the humidity, without any account identifier.
- Neon (EU): PostgreSQL database hosting accounts, groups, activities, events.
- Stream Chat (Stream.io Inc.): real-time messaging engine.
- Mapbox (Mapbox Inc., United States): maps and map backgrounds.
- RevenueCat (United States): management of In-App subscriptions.
- Sentry (United States): crash diagnostics.
- Anthropic (United States): AI model for programme generation.
We do not sell your data. We may disclose it if the law requires it or to protect the rights and the safety of Sweliv and of its users.
7. Transfers outside the European Union
Some sub-processors (Apple, Google, Stream, Mapbox, RevenueCat, Sentry, Anthropic) are located in the United States. When your data is transferred there, it is transferred on the basis of appropriate safeguards, in particular the Standard Contractual Clauses of the European Commission and/or the EU-U.S. Data Privacy Framework.
8. Your rights
In accordance with the GDPR, you may:
- Access all the data concerning you (Profile → Account → Info).
- Rectify your information (email, username, picture) at any time.
- Erase your account and all the associated data in full: “Delete my account” button under Profile → Account → Info.
- Export your data on simple request to privacy@sweliv.com.
- Object to the processing or request its restriction.
- Withdraw your consent at any time (location, health, notifications) via the Settings of your device.
You also have the right to lodge a complaint with the CNIL, the French data protection supervisory authority.
9. Data retention
Your data is kept for as long as your account is active. On deletion, all the associated data is erased within 30 days, the time needed for it to propagate to our sub-processors, unless a legal retention obligation applies. Sentry crash reports are kept for 90 days then purged.
10. Security
All communications between the app and our servers are encrypted with TLS. Passwords are never stored in clear text (Firebase Auth). Authentication tokens have a limited lifetime and are revoked on sign-out. As no method is infallible, we implement measures that are in line with the state of the art.
11. Minors
Sweliv is not intended for children under 13. If you are between 13 and 15, you must have the consent of a parent or guardian. We do not knowingly collect data from children under 13.
12. Changes
We may update this policy. In the event of a significant change, we will inform you in the application or by email. The date of the last update appears at the top of this page.
13. Contact
For any question relating to your data or to this policy, write to us at privacy@sweliv.com. We reply within 48 working hours.