Athlnet logoAthlnet

Privacy Policy

Last updated: July 29, 2026

This policy describes the personal data Athlnet processes, why, how long it is kept, who can access it, and the rights you can exercise. It is written under Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.

1. Data controller

The data controller is Sid-Ali Benchoubane, publisher of Athlnet, reachable at contact@athlnet.app.

No data protection officer has been appointed to date. Any request concerning your personal data should be sent to contact@athlnet.app.

2. Who may use Athlnet

Athlnet is strictly limited to adults. Signing up requires a date of birth, and access is refused below the age of 18.

No processing of minors' data is intended. If we learn that an account was created by a minor, it is deleted.

3. Data you provide

Account: email address or phone number and, where applicable, the data supplied by Google or Apple when signing in through those services.

Profile: first name, date of birth, gender, description, photos, sports, city and approximate location coordinates, display and privacy preferences.

Content: text and voice messages, shared photos and media, activities you create, groups you join, polls, and replies to invitations.

Identity verification (optional): front and back photographs of an identity document and a selfie. See section 6.

Reports and support: the category, message, and technical context you submit.

4. Data collected automatically

Technical data required to operate the service: session identifiers, device type, operating system, app version, language, push notification token, sign-in and error logs.

Athlnet uses no audience measurement tool, no advertising tracker, and no behavioural analytics service. The athlnet.app website sets no cookies other than those strictly necessary to display it.

5. Live position sharing

When you start a group outing, Athlnet collects your precise location, including when the app is in the background or closed. This collection happens only during an active outing, never outside one.

Your position is visible live to the members of the group concerned for the duration of the outing.

The raw points of your route are deleted after 30 days. Only the outing summary (distance, duration, pace, simplified track) is kept and remains visible in the group history.

An Athlnet administrator may review an ongoing outing for safety and supervision purposes. Each such review is recorded in an internal audit log.

Sharing can be stopped at any time from the app, and an inactive outing is closed automatically.

6. Identity verification

Identity verification is entirely optional. It exists solely to display a badge on your profile and is required for no feature.

Submitted documents are stored in a private area, inaccessible to other users, and reviewed visually by a person. No automated biometric processing is performed: there is no facial recognition and no automated comparison between the selfie and the identity document.

Documents are permanently deleted as soon as the request is decided, and within 24 hours at the latest. A request left unreviewed is automatically cancelled and its documents deleted after 90 days.

After deletion, only the verification status, its date, and — where refused — the stated reason remain.

Every consultation of a document by an administrator is recorded in an internal audit log, naming the person concerned.

7. Purposes and legal bases

Providing the service — account creation and management, profile, activities, groups, messaging, notifications: performance of the contract formed by the terms of use (Article 6(1)(b) GDPR).

Live position sharing: your consent, obtained before any activation and withdrawable at any time (Article 6(1)(a)).

Identity verification: your consent (Article 6(1)(a)).

Security, prevention of fraud and abuse, moderation of reports, audit logging of administrator access: our legitimate interest in protecting users and the service (Article 6(1)(f)).

Improving the service and fixing defects from error logs: legitimate interest (Article 6(1)(f)).

Compliance with our legal obligations, in particular retention and responses to lawful requests: Article 6(1)(c).

Retention of proof of acceptance of the terms and policy: our legitimate interest in being able to establish the agreement reached, the burden of that proof lying with us (Article 6(1)(f)).

8. Retention periods

Account and profile: kept for as long as the account exists. An account inactive for 3 years is deleted.

Raw position points: 30 days. Outing summary: kept with the group history.

Identity documents: deleted when the request is decided, within 24 hours at the latest, or after 90 days if never reviewed.

Reports and support exchanges: 3 years after closure.

Technical and sign-in logs: 12 months.

Messages: kept for as long as your account exists. Messages you sent in a conversation or group, including voice messages, remain visible to their recipients after your account is deleted, so that conversations other people took part in stay coherent. They are then no longer attached to an active profile.

Administrator action audit log: 3 years.

Proof of acceptance of contractual documents: the record of your acceptances (identifier, document, version fingerprint, date, language) is kept for 5 years, including after your account is deleted, on the basis of Article 17(3)(e) GDPR. It contains no profile data and is no longer attached to an active account.

9. Who accesses your data

Other users, within the limits of your settings: your public profile, the content you share, and your position during an outing for members of the group concerned. Your exact address is never displayed.

The publisher and persons authorised to administer the service, for moderation, support, and security, with named authentication and logging of access to sensitive data.

The processors listed in section 10, within the scope of their services.

Judicial or administrative authorities, upon a lawful request.

Your data is never sold, rented, or transferred for advertising purposes.

10. Processors and transfers outside the European Union

Supabase — hosting of the database, files, and authentication. Data stored in the European Union (Ireland, AWS eu-west-1 region). No transfer outside the EU for this hosting.

Google (Firebase Cloud Messaging) — delivery of push notifications. United States.

Resend — delivery of transactional emails. United States.

Mapbox — map display and location services. United States.

Vercel — hosting of the athlnet.app website. United States.

Apple and Google — application distribution and related authentication services.

Transfers to the United States are governed by the European Commission's standard contractual clauses and, where the provider is certified under it, by the EU–US Data Privacy Framework.

11. Profile and activity suggestions

Athlnet suggests profiles and activities based on simple criteria: the sports you declared, approximate geographic proximity, display preferences, and activity availability.

These suggestions produce no legal effect and do not constitute automated decision-making within the meaning of Article 22 GDPR. No advertising profiling is carried out.

12. Security

Exchanges are encrypted in transit. Data access is partitioned at database level by row-level security rules, and identity documents are stored in a private area reachable only through short-lived signed links.

Administrator access to identity documents and routes is authenticated by name and logged.

In the event of a data breach likely to result in a risk to your rights and freedoms, the CNIL is notified within 72 hours and you are informed where the law requires it.

13. Your rights

You have the right of access, rectification, erasure, restriction of processing, objection, and data portability.

Where processing relies on your consent — live position, identity verification — you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

You can delete your account directly from the app: Profile > Delete my account.

For any other request, write to contact@athlnet.app. You will receive a reply within one month, extendable by two months for complex requests. Proof of identity may be requested in case of reasonable doubt.

You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.

14. Changes to this policy

This policy may change to reflect developments in the service or in applicable law. The date of the latest update appears at the top of this page.

In the event of a substantial change, you are informed in the app and asked to accept the new version.