Scuttle

Privacy policy

Last updated: 16 August 2026

Status: Draft. A solicitor must review this before launch. It is written from the code as built, so every claim in it is currently true, but it has not been reviewed by a lawyer.

The short version

We read one number from your phone: how far you travelled each day, split by whether you walked, ran, cycled, swam or wheeled.

We never read where you went. We never read your heart rate. Nobody else in your challenge can see your activity, only your position on a leaderboard. Not even the person who set the challenge up.

Who we are

[COMPANY NAME] is the data controller for the information described here.

Contact: [privacy@domain]
ICO registration: [number, required before launch if processing health data commercially]

What we collect, and why

Health data

Daily distance, per activity, for example 6,000 metres walking on 2 September, to work out your position in a challenge.

Daily step count, for example 8,000 steps, for step-based challenges.

Daily duration, per activity, for example 3,600 seconds, to spot implausible entries during fairness checks.

Only daily totals. We do not collect, store or receive your location or GPS traces; heart rate, sleep, weight, blood pressure or any other health metric; or individual workouts.

This is special category data under Article 9 of the UK GDPR. Our lawful basis is your explicit consent, given when you connect Apple Health. You can withdraw it at any time in your phone's Settings, or by deleting your account.

Account data

We receive an Apple identifier through Sign in with Apple, your name on your first sign-in if you choose to share it, and your email. This may be an Apple private relay address, which is fine.

Our lawful basis is contract. We cannot run your account without it.

Device data

We collect a push notification token so we can tell you when someone is about to overtake you. Our lawful basis is consent. Decline notifications and we never create one.

Error reports

When something crashes, we send the technical fault to Sentry to fix it. We have explicitly disabled the three channels that would otherwise carry your data with it: personally identifying information, request bodies, and the contents of program memory at the point of the crash. A test fails if any of the three is turned back on.

What we do not do

No advertising. Health data is never used for advertising or marketing. Apple's HealthKit terms forbid it and so do we.

No selling. We do not sell your data to anyone, ever.

No data brokers and no analytics SDKs reading your health data.

Who can see what

Other participants see your name, your position and your total distance for the challenge. They cannot see your daily activity, which days you moved, or anything about how you produced that total.

The person who organised the challenge sees exactly the same as everyone else, plus totals and any entries flagged for review. Organisers cannot see raw activity either. This is enforced in code: every read is scoped to the requesting user.

Our suppliers process data on our instructions only:

Railway handles hosting and the database in the EU region. Cloudflare R2 handles images in the EU. Sentry handles error reports in the EU, with all personal data channels disabled. Expo handles push notification delivery, token only, in the US. Apple handles Sign in with Apple under Apple's own policy.

Where your data lives

In the EU or UK. Our database is deployed to a European region, so your health data does not leave the UK and EU for ordinary processing. Push notification tokens reach Expo in the US under standard contractual clauses; those tokens contain no health data.

How long we keep it

Activity data: the challenge, plus 12 months so you can look back at what you did.

Account: until you delete it.

Error reports: 90 days.

Deleted account: erased within 30 days, including from backups on their normal rotation.

Your rights

You can ask us to show you everything we hold about you; correct anything wrong; delete it all; export it in a portable format; stop processing it or object to processing; and withdraw consent for health data at any time without giving a reason.

There is a delete button in the app. It removes your activity, your account and your leaderboard entries.

Email [privacy@domain] and we will respond within one month. You can complain to the Information Commissioner's Office at ico.org.uk.

Children

Scuttle is not for under-16s. We do not knowingly collect data from anyone under 16.

Businesses and clubs

If you are running a challenge for your organisation, you are a controller alongside us for your participants' membership of it. We provide a Data Processing Agreement covering the health data we process on your behalf. Ask at [privacy@domain].

Your staff's health data is not visible to you. You see totals and positions. This is deliberate, and it protects you as much as them.

Changes

If we change anything material we will tell you in the app before it takes effect.

Appendix A: Apple App Privacy answers

For the App Store Connect privacy questionnaire. Every answer below must match what the code actually does at submission.

Health and Fitness, name, email address, user ID, device ID and crash data are collected for app functionality. All except crash data are linked to the user. None is used for tracking.

Precise location, coarse location, purchases, usage data and contacts are not collected. Payment is on the web, not in the app.

Tracking: No, across every category. Declaring otherwise would require App Tracking Transparency and would be untrue.

Appendix B: What must be true before submission

A solicitor must review this document. The company name, contact email and ICO registration must be filled in. The policy must be hosted at a public URL and linked in App Store Connect. The HealthKit priming screen must link to this policy before the system permission prompt, and NSHealthShareUsageDescription must match what this document says we read.

Railway's API service and Postgres were verified on 16 August in the Amsterdam EU region. The account deletion endpoint exists, with eight tests proving activity rows are gone and that a deletion never touches another user's data. The in-app button is in Settings.

Land's End 0 mi Tintagel 60 mi Cheddar Gorge 135 mi Severn Bridge 250 mi Ironbridge 380 mi Shap Fell 505 mi Scottish Border 584 mi Loch Lomond 674 mi Glen Coe 752 mi Inverness 826 mi John o' Groats 874 mi

Be first
up the hill

Scuttle lands on iPhone and Android shortly. Leave your email and we will tell you the day it does, and nothing else.

Which phone

One email, on launch day. No newsletter, and we never pass it on.