Privacy
Privacy Policy
Last updated September 2026
PostSpar records sparring, which means it holds video of you training, and often of the people you train with. This page says exactly what we collect, why we have it, who else touches it, and how to make us delete it.
Who is responsible
PostSpar is operated by DIAPP LTD, a company registered in England and Wales under number 13930414, with its registered office at Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, England, BH16 6FA. We are the data controller for the information described here, under the UK GDPR and, where it applies to people in the European Union, the EU GDPR.
For anything on this page, including a request to see or delete your data, write to contact@diapp.tech.
What we collect
Your account
An email address, or a phone number if you sign in by phone, or the name and email your Apple or Google account gives us when you use those. Plus the display name, username and profile photo you choose.
What you tell us about your boxing
Your bout record, wins, losses and draws, and the physical details you enter such as weight, height, reach and stance. Coaches additionally provide the gym and coaching details on their profile. All of it is optional, and you decide who can see it.
What you record and write
Sparring video and the clips cut from it, thumbnails, notes and ratings your coach leaves, chat messages including voice messages, and anything you post to the feed. Video and audio are uploaded to storage so they can reach your coach and survive a reinstall.
Heart rate
If you pair a Bluetooth chest strap, we store the readings from your sessions, the zones they fall into, and your maximum recorded rate. This is health data. We collect it only while a session is running, only from a strap you paired yourself, and never from Apple Health or Google Fit.
Location
Approximate or precise location, only when you use the gym map or attach a place to something. We do not track you in the background.
Device permissions
Camera and microphone for recording, photo library for choosing footage, Bluetooth for a heart-rate strap, location for the gym map, and notifications. Each is asked for when the feature needs it, and refusing one only turns off that feature.
Technical and usage data
A device push token, app version and device model, crash reports, and how the app is used. We use analytics tools that measure how people move through the app, which can include anonymised recordings of app usage, so we can see where people get stuck and fix it.
Payments
If a coach sells reviews, Stripe handles their identity checks and payouts. Card details are entered into Stripe and never reach our servers. We keep only the record of what was ordered and what it cost.
The test on this website
If you take the reaction test on the home page, we store a one-way hash of your email address rather than the address itself, together with the bout record and the score you entered. The hash is what stops one person taking the test repeatedly, and what lets us fill in your profile if you later sign in with the same address. Sign in and it is attached to your account. Never sign in and it stays an unlinked hash.
Why we hold it, and on what basis
Most of it exists because the app cannot work otherwise, which is the performance of our contract with you: there is no sparring review without the sparring video. Heart-rate data is health data, and we process it only on your explicit consent, given when you pair a strap. Crash reporting and analytics rest on our legitimate interest in the app working properly. Location and the device permissions rest on the consent your operating system asks you for, and you can withdraw any of them in system settings.
Improving the app and our models
We use what the app collects to make it better, and that includes training, testing and improving the models behind our own features, such as the ones that find the boxers in footage, cut it into clips and describe what happened. This rests on our legitimate interest in a product that keeps getting more accurate. Material used this way stays inside our own systems. We do not sell it, and we do not hand your content to another company to train theirs. Where the law asks for your consent first we ask for it, and health data from a heart-rate strap is not used this way at all.
If you would rather your content was left out of this, write to contact@diapp.tech and we will exclude it going forward. A model that has already learned from something cannot unlearn it, so this applies from the point you ask.
Who else touches it
We do not sell your data, and we do not use it for advertising. It reaches these companies because they run part of the service:
- Google Firebase hosts the accounts, the database, the video storage, the server code, push notifications and crash reporting. Production data is stored in Google's European multi-region.
- Google Maps and Google's geocoding render the gym map and turn addresses into coordinates.
- Apple and Google confirm who you are when you use Sign in with Apple or Google.
- Stripe verifies coaches who take payment and moves the money.
- Analytics providers process app usage data on our behalf so we can measure and improve how the app performs.
- Tenor answers GIF searches in chat. Your search terms go to them, nothing else.
Some of these are in the United States, so data leaves the United Kingdom and the European Economic Area. Those transfers rely on an adequacy decision where one covers the recipient, and otherwise on the UK's international data transfer agreement or addendum, and the European Commission's standard contractual clauses.
The pose and object detection that finds the boxers in your footage runs entirely on your phone. That footage is not sent anywhere for analysis.
Who else can see it inside the app
Your coach sees what you send them, and an accepted coach can see the record and physical details you would otherwise keep private. Clips stay between you and the people you send them to. Nothing reaches the public feed unless you put it there. Blocking someone cuts both directions.
How long we keep it
Your account data and content stay while the account exists. Delete your account and we remove it, and the copies in our backups age out within 30 days. Reports made about content are kept up to 12 months so repeat behaviour can be recognised. Web test results are kept while they are useful for ranking, and you can ask us to remove yours.
Your rights
If you are in the United Kingdom or the European Economic Area you can ask for a copy of your data, correct it, delete it, restrict or object to how it is used, take it elsewhere, and withdraw any consent you gave. Write to contact@diapp.tech and we will answer within one month. You can delete your account from inside the app without asking anyone.
If you think we have handled something badly, tell us first at contact@diapp.tech. Most things we can put right quickly, and we would rather hear it from you. You also have the right to raise the matter with a data protection authority: the Information Commissioner's Office in the United Kingdom, or the authority in your country if you are in the European Economic Area.
Age
PostSpar is not for children under 16. If you are under 16 you may use it only with a parent or guardian's consent, where the law of your country allows that. If we learn we hold data on a child without it, we delete the account.
Security
Traffic is encrypted in transit and data is encrypted at rest. Access to production data is limited to the people who need it. Server rules decide what any account is allowed to read, so one user cannot reach another's footage. No system is perfect, and we will tell you and the relevant authority if a breach puts you at risk.
Changes
If this policy changes in a way that matters we will say so in the app before the change takes effect. The date at the top always reflects the current version.
Contact
Questions, requests, or a complaint: contact@diapp.tech.