Last updated [last updated date]
Trust, security & privacy
Anxiety Fitness is a community for mental-health support, so looking after the people who use it comes first. Because it's a social platform — with profiles, communities, live rooms and payments — we collect more than just an email. Here's exactly what we collect, why, and how we protect it, in plain English with the technical detail underneath.
What we collect & why
We aim to collect what we need to run a safe, useful community — and to be clear about it. We are not a clinical record system: we don't hold NHS numbers, diagnoses, referrals or care plans.
| What | Examples | Why we collect it |
|---|---|---|
| Account & identity | First name, last name, email address, country, and the profile details you choose to add | To create and run your account, personalise your experience, and meet legal/age and regional requirements |
| Community content | Posts, comments, prompts, wins, rooms and chats you take part in, and media you upload | To provide the community features you came for, and so you can manage your own contributions |
| Payments | Subscription, purchase and (for creators) payout details — card data is handled by Stripe, not stored by us | To process memberships, creator products and payouts where you use them |
| Technical & security data | IP address, device and browser (user-agent), and a record of sign-in activity | To keep your account secure and protect the community from fraud, abuse and bad actors |
| Consent & preferences | Your cookie and marketing choices, recorded with a timestamp | To honour your choices and evidence consent |
| Analytics & marketing | Usage analytics and, where you opt in, marketing/affiliate signals | To understand and improve the service — only in line with your consent |
Under the hood: accounts are keyed on a Firebase user ID; your name, email and country are stored on your user record; community content is linked to your account so you can edit or delete it.
Keeping the community safe
A mental-health community can attract people who want to exploit or harm vulnerable members. To protect against fraud, impersonation, ban-evasion and abuse, we record technical signals such as your IP address, device/browser, and sign-in activity, and we collect your country at sign-up. We rely on this for our legitimate interest in keeping the platform safe and secure; we keep it proportionate and we don't use it to track you across other websites.
Under the hood: on sign-in the app records the IP address, user-agent and timestamp against your account (users/{uid}/ipAddresses,lastKnownIp) for security and abuse-prevention; sign-in is also protected by Firebase App Check (reCAPTCHA Enterprise).
Where your data lives
Our core application data is hosted in UK and European regions on Google Firebase. Some supporting providers operate outside the UK/EEA; where they do, transfers are covered by Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework.
Under the hood: Cloud Firestore, Cloud Storage and Cloud Functions (europe-west1) run in EU regions; video is delivered by Mux and real-time chat/rooms by GetStream (both US providers covered by the safeguards above).How we protect it
- Encryption — your data is encrypted in transit and at rest.
- Access control — access to your account and private spaces is enforced on our servers on a least-privilege basis, not just in the app.
- Account protection — sign-in is protected against bots and abuse, and we monitor sign-in activity for suspicious access.
Under the hood: TLS in transit, managed encryption at rest; role/relationship-based authorisation via server-side Firebase security rules; App Check (reCAPTCHA Enterprise); server-side verification of identity tokens on sensitive actions.
Support, not a substitute for clinical care
Anxiety Fitness offers psychoeducation and peer community support. It does not diagnose, triage or make treatment decisions, it is not monitored by clinicians in real time, and it is not an emergency or crisis service. If you are in crisis, please contact 999, NHS 111, or Samaritans on 116 123.
Your privacy rights
Anxiety Fitness is operated by PFRJ Limited (company no. 11629871), which is registered with the UK Information Commissioner's Office (ICO) and has a named data-protection contact (Peter Ruppert). We operate on a privacy-by-design basis to support UK GDPR. You can manage your cookie and marketing preferences at any time, and you can ask to access, correct, export or delete your data — contact privacy@anxietyfitness.com (confirm).
For NHS & organisational use
We are working toward the relevant UK health-IT assurance standards — clinical safety (DCB0129/DCB0160) and the Digital Technology Assessment Criteria (DTAC) — so that NHS services can confidently signpost people to Anxiety Fitness or host educational content with us.
We describe these as in progress; we don't claim certification or NHS endorsement we haven't earned. Organisations evaluating Anxiety Fitness can request our information-governance and clinical-safety documentation.
Who we work with (sub-processors)
We use a small set of trusted providers to run the service. Analytics and marketing providers are used only in line with your cookie and marketing preferences.
| Provider | Used for | Region | DPA / terms |
|---|---|---|---|
| Google Firebase / Cloud | Hosting, authentication, database, storage, functions, push notifications | UK/EU | Firebase Data Processing Terms |
| Mux | Video hosting & playback | US (EU-US Data Privacy Framework; EU ingest available) | Mux DPA |
| GetStream | Community chat & live rooms | US | GetStream DPA |
| Stripe | Payments, subscriptions & creator payouts | US/EU | Stripe DPA |
| Postmark | Transactional / notification email | US (SCCs) | Postmark GDPR |
| Kit, MailerLite, Kajabi, Zapier | Creator email lists & automations (with explicit consent at sign-up) | US (SCCs) | Provider DPAs |
| Sanity | Content management | EU/US | Sanity DPA |
| Iubenda | Consent & policy management | EU | Iubenda DPA |