Rai BoxingRai Boxing

Privacy policy

What we keep,
and what we don’t

Last updated 27 September 2026

Who we are

Rai Boxing is run by Rai Boxing, established in the United Kingdom. We are the data controller for the personal data described here. You can reach us at support@raiboxing.com.

This policy covers the Rai Boxing website and app at raiboxing.com and the emails we send. It applies to everyone who visits or signs up.

The short version

  • The camera never leaves your phone. The pose model runs on the device; no video is uploaded or stored.
  • We keep what you tell us and what you do in the app: your profile, your sessions, your scores, your chats with the coach.
  • A few companies see part of it to make the app work: Vercel and the AI model company it routes to (the coach's replies, the writing help and the read of your assessment), Resend (email), and our hosting provider. Analytics only if you allow them.
  • There is no advertising and nothing is sold. You can delete your account, and everything in it, from inside the app.

What never leaves your phone

The form check and the daily challenge read your movement with a pose model that runs in your phone’s browser. The video is never uploaded, never stored by us and never included in any analytics or recording. What is saved is numbers: rep counts, timings, joint angles and a small skeleton summary, so your scores can be shown again and compared over time. A replay of a shadow boxing clip is held in the phone’s own memory until you leave the screen.

What we collect

What you give us. Your username, email address and password when you sign up (the password is stored only as a scrambled hash we cannot read back); your name and date of birth if you add them; your profile (experience, fitness, goals, stance, kit, days a week, height and weight if you give them, and competition details if you tick that box); anything you type to the coach; workouts, photos and comments you choose to share; a profile picture and bio if you add them; captions, reactions and comments you post in the feed.

The feed. Who you follow, who follows you and who has asked to. Your profile is private until you make it public: your name, picture and bio can be seen by people signed in to Rai Boxing, but your workouts only by the followers you have said yes to. Make it public and anybody signed in can see them. Nobody who is not signed in sees your workouts, only a link you choose to share. The private note you write when you log a session is never shown to anyone else; only the caption you write for the feed is. You can keep any workout off the feed.

Food you log. What you ate, how much, which meal and which day, so your food diary is there when you come back. Only you see it; it is not on your profile, the feed or given to the coach, and it is deleted with your account. When you search for a food or look up a barcode, the words you typed or the barcode number are sent to USDA FoodData Central (United States) and Open Food Facts (France) to find it; nothing that identifies you goes with them.

Messages. Messages you send and receive, kept so the conversation is there when you come back. Only you and the person you are talking to can read them; people can only message each other when they follow each other. We do not read them. If one of you reports a conversation, the reported person’s recent messages in it are emailed to our admins so they can act on it. You can unsend your own messages, and all of your messages are deleted with your account.

What the app records as you use it. The sessions built for you and what you logged against them; activities you added; blocks you built; the scores and numbers from form checks and challenges; when you last used the app; whether the morning email is on and the last day one was sent; the day you were let in.

Signing up and signing in. A log of each time you sign up, sign in, ask for a sign-in link or set a password, including attempts that do not succeed (with the email or username that was typed, never the password), the kind of device, and each decision about your account (approved or not, when, and by whom). It is how we keep accounts secure and see who is trying to get in. It is kept for thirteen months and deleted with your account.

Emails we send you. A record of every email we send you (the sign-in link, being approved, the morning email, updates, and the emails telling you somebody asked to follow you or messaged you), with its subject and when. The message email includes the first words of the message. Updates we write ourselves are kept with their words; a sign-in link is recorded without the link. Deleted with your account.

How you use the app. When you are signed in, we record which screens of the app you open, when, and how long each stays on your screen, with the kind of device (phone, tablet or computer) and, for the first screen of a visit, the website you came from (its name only, never the full address). This is tied to your account so we can see how the app is used and improve it, and is kept for thirteen months. It uses no extra cookie and nothing is stored on your device for it. When you are not signed in, the same is recorded without anything that identifies you. If you allow analytics cookies, the analytics providers below collect more; see Cookies.

What Stripe tells us. If you pay for a subscription, Stripe handles your card and tells us your customer id, the status of your subscription, what it is worth a month and each invoice paid. We never see or store card numbers.

Weight is kept as context for choosing work. It is never used to work out a difference from a target, never shown as a progress figure, and the app never gives advice about making weight.

Why, and on what basis

UK data protection law asks us to say which legal basis we rely on for each use. Here they are.

  • To provide the service you signed up for (contract): building your sessions, running the clock, scoring your form and challenges, answering your questions, sending the sign-in link.
  • To run and improve the app (legitimate interests): recording how the app is used as described above, keeping the dashboard that shows us who is training and which parts of the app they use, fixing what breaks, keeping the service secure and approving accounts one by one.
  • To send the morning email (legitimate interests, with an unsubscribe in every one and a switch in your profile): a reminder of the day’s challenge and session.
  • To send you updates (legitimate interests, as somebody with an account; an unsubscribe in every one and a switch in your profile): new features, new workouts, a nudge if you have gone quiet. Emails about your account itself, such as being approved, are sent whatever you choose.
  • Analytics cookies (consent): only if you choose “allow” on the cookie banner, and you can change your mind on the Cookies page at any time.
  • To take payment (contract) once subscriptions exist.
  • To meet a legal duty (legal obligation): keeping the records the law requires, such as invoices.

Your profile includes information about your health and fitness. We use it only to choose work you can do safely and to keep unsuitable drills away from you, on the basis of your explicit consent given when you fill it in. You can leave any of it blank.

Who else sees any of it

  • Vercel (United States), through its AI Gateway, and the AI model company it passes the request to (Google, OpenAI, Anthropic or Mistral). When you talk to the coach, your message and the training context it needs (your level, kit, plan and recent sessions) are sent this way to write the reply. When you ask for help writing a caption, bio or comment, or open the read of your assessment, the facts it needs are sent the same way: the workout, the words you have typed, your profile answers, your assessment scores and the workouts open to you. Nothing from the camera is included. Vercel does not keep the words once the reply is written, and we only use models the gateway marks as never training on what is sent to them.
  • USDA FoodData Central (United States) and Open Food Facts (France), the free food databases. They receive the words you search for a food with, or a barcode number, and nothing else about you.
  • Resend (email delivery, servers in the EU). Handles your email address and the messages we send you: the sign-in link, the morning email, and the email that says you are in.
  • Stripe (payments) once subscriptions exist. Stripe’s own privacy policy covers what it collects to take your card.
  • Our hosting provider runs the server the app and its database live on.
  • Google Analytics and Microsoft Clarity, only if you allow analytics cookies. See Cookies for what each collects. Camera areas are masked from Clarity and are never recorded.

Nobody else. There is no advertising, no data broker and nothing is sold. We would disclose personal data if the law required it, and we would tell you unless the law forbade that.

Where a provider is outside the UK, the transfer is covered by the UK’s adequacy regulations or by the International Data Transfer Agreement / standard contractual clauses that provider offers.

Cookies

One essential cookie keeps you signed in for thirty days; there is no password. One remembers your cookie choice. Analytics cookies are set only if you allow them. The full list, and the switch, are on the Cookies page. The browser’s own storage also remembers a few settings on your device, such as the sound mode and whether you have seen the tour; that never leaves the device.

How long we keep it

  • Your account and everything in it: for as long as you have an account. Delete it and it all goes at once.
  • Sign-in links: fifteen minutes. Sign-in sessions: thirty days from last use.
  • An account that started onboarding and never finished: we may delete it after twelve months of no activity.
  • Which screens you used and for how long: thirteen months, then deleted automatically.
  • The sign-up, sign-in and decision log: thirteen months, then deleted automatically, and at once if you delete your account.
  • Daily visit totals: as numbers per day, with nobody identified, indefinitely.
  • Invoices and payment records: six years, as UK tax law requires, even after the account is deleted.
  • Nightly backups of the database: fourteen days, then overwritten.

Your rights

Under UK data protection law you can ask us to:

  • tell you what we hold about you and give you a copy (access);
  • correct anything that is wrong (rectification): most of it you can edit yourself on your profile;
  • delete it (erasure): the Delete my account button on your profile does this immediately and completely;
  • stop or limit what we do with it (restriction and objection), including the morning email and analytics, both of which have their own switches;
  • give you your data in a form you can take elsewhere (portability);
  • withdraw consent where we rely on it, such as analytics cookies, without affecting what came before.

Email support@raiboxing.com for anything the app does not let you do yourself and we will answer within a month. If you are not happy with how we handle it, you can complain to the Information Commissioner’s Office at ico.org.uk.

Security

Connections are encrypted (HTTPS). Passwords are stored only as a salted scrypt hash, so nobody, including us, can read yours; repeated wrong guesses are slowed down. Sign-in and reset links work once and are stored only as a keyed hash. The database is not reachable from the internet. Access to the server is by key, held by the people who run the app.

Age

Rai Boxing is for people aged 16 and over. We do not knowingly keep data about anybody younger; if you believe we have, tell us and we will delete it.

Changes

When the app changes in a way that changes what this page says, we update the page and the date at the top. If the change matters to you, we will say so in the app or by email before it takes effect.

Back