Anxiety Fitness

Trust, Security & Privacy

Last updated 4 August 2026

Trust, security & privacy

Anxiety Fitness is a community for mental-health support, so looking after the people who use it comes first. Because it's a social platform — with profiles, communities, live rooms and payments — we collect more than just an email. Here's exactly what we collect, why, and how we protect it, in plain English with the technical detail underneath.

Two things worth knowing up front. Anxiety Fitness is for adults — you must be 18 or over to hold an account. And your journal is private to you: it is stored apart from community content, and it is not published, not shown in anyone's feed, and not readable by other members, space owners or moderators.

What we collect & why

We aim to collect what we need to run a safe, useful community — and to be clear about it. We are not a clinical record system: we don't hold NHS numbers, diagnoses, referrals or care plans.

WhatExamplesWhy we collect it
Account & identityFirst name, last name, email address, country, and the profile details you choose to addTo create and run your account, personalise your experience, and meet legal/age and regional requirements
Community contentPosts, comments, prompts, wins, events and chats you take part in, and media you uploadTo provide the community features you came for, and so you can manage your own contributions
PaymentsSubscription, purchase and (for creators) payout details — card data is handled by Stripe, not stored by usTo process memberships, creator products and payouts where you use them
Technical & security dataIP address, device and browser (user-agent), and a record of sign-in activityTo keep your account secure and protect the community from fraud, abuse and bad actors
Consent & preferencesYour cookie and marketing choices, recorded with a timestampTo honour your choices and evidence consent
Analytics & marketingUsage analytics and, where you opt in, marketing/affiliate signalsTo understand and improve the service — only in line with your consent
Under the hood: accounts are keyed on a Firebase user ID; your name, email and country are stored on your user record; community content is linked to your account so you can edit or delete it.

Keeping the community safe

A mental-health community can attract people who want to exploit or harm vulnerable members. To protect against fraud, impersonation, ban-evasion and abuse, we record technical signals such as your IP address, device/browser, and sign-in activity, and we collect your country at sign-up. We rely on this for our legitimate interest in keeping the platform safe and secure; we keep it proportionate and we don't use it to track you across other websites.

Under the hood: on sign-in we record the IP address, browser user-agent and a timestamp against your account, and keep a short history of recent sign-ins so we can spot ban-evasion and account takeover; sign-in is also protected by Firebase App Check (reCAPTCHA Enterprise).

Where your data lives

Our core application data is hosted in UK and European regions on Google Firebase. Some supporting providers operate outside the UK/EEA; where they do, transfers are covered by Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework.

Under the hood:Cloud Firestore, Cloud Storage and Cloud Functions all run in EU regions, and the website is served from EU regions only. Real-time chat and live rooms run on Stream's EU (Dublin) region. Video is delivered by Mux, a US provider, covered by the safeguards above.

Email and cookies

Marketing email is opt-in, and every marketing message carries a one-click unsubscribe. When we send one, we record whether it was delivered, whether you opened it and which links you followed — against you personally, not just as a total. We think you should be told that plainly rather than find it in a footnote; the Privacy Notice sets out what we do with it. You will still get service messages needed to run your account.

Cookie consent is handled by us directly, not by a third-party consent vendor. Nothing optional runs until you answer, refusing takes as many clicks as accepting, and you can change your mind at any time from the footer. See the Cookie Policy.

How we protect it

  • Encryption — your data is encrypted in transit and at rest.
  • Access control — access to your account and private spaces is enforced on our servers on a least-privilege basis, not just in the app.
  • Account protection — sign-in is protected against bots and abuse, and we monitor sign-in activity for suspicious access.
Under the hood: TLS in transit, managed encryption at rest; role/relationship-based authorisation via server-side Firebase security rules; App Check (reCAPTCHA Enterprise); server-side verification of identity tokens on sensitive actions.

Support, not a substitute for clinical care

Anxiety Fitness offers psychoeducation and peer community support. It does not diagnose, triage or make treatment decisions, it is not monitored by clinicians in real time, and it is not an emergency or crisis service. If you are in crisis, please contact 999, NHS 111, or Samaritans on 116 123.

Your privacy rights

Anxiety Fitness is operated by PFRJ Limited (company no. 11629871), which is registered with the UK Information Commissioner's Office (ICO) and has a named data-protection contact (Peter Ruppert). We operate on a privacy-by-design basis to support UK GDPR. You can manage your cookie and marketing preferences at any time, and you can ask to access, correct, export or delete your data — contact privacy@anxietyfitness.com.

For NHS & organisational use

We are working toward the relevant UK health-IT assurance standards — clinical safety (DCB0129/DCB0160) and the Digital Technology Assessment Criteria (DTAC) — so that NHS services can confidently signpost people to Anxiety Fitness or host educational content with us.

We describe these as in progress; we don't claim certification or NHS endorsement we haven't earned. Organisations evaluating Anxiety Fitness can request our information-governance and clinical-safety documentation.

Who we work with (sub-processors)

We use a small set of trusted providers to run the service. Analytics and marketing providers are used only in line with your cookie and marketing preferences.

ProviderUsed forRegionDPA / terms
Google Firebase / CloudAuthentication, database, file storage, server functions, push notificationsEU (Firestore eur3; Storage and Functions europe-west1)Firebase Data Processing Terms
VercelHosting and delivery of the websiteEU only (Paris, Stockholm, Dublin, London, Frankfurt)Vercel DPA
Stream (GetStream)Community chat, direct messages & live roomsEU (Dublin)Stream DPA
MuxVideo hosting, encoding & playbackUS (EU-US Data Privacy Framework)Mux DPA
StripePayments, subscriptions & creator payoutsGlobal; US-headquarteredStripe DPA
Postmark (ActiveCampaign)Sending email, and recording delivery, opens and clicksUS (SCCs)Postmark GDPR
Kit, MailerLite, Kajabi, ZapierWhere a creator connects their own external mailing list (with explicit consent at sign-up)US (SCCs)Provider DPAs
MetaConversion measurement for our own advertising (only with your consent)USMeta Data Processing Terms
Expo (EAS)Delivering updates to the mobile appUSExpo DPA
Apple, GoogleApp distribution and in-app purchasesGlobalProvider terms