// System · Data Protocol

Privacy Policy

Effective · July 5, 2026

VoidRise ("the app") is built and operated by HJB CodeForge (Henning Botha, sole proprietorship, Ottawa, Ontario, Canada). This policy explains what data VoidRise handles and what we do — and don't do — with it.

The short version: your workout and nutrition data lives on your device. A few features send data to trusted services so they can work — food lookups (a search term or barcode), optional cloud sync, and the optional meal-photo scan (the photo). We don't sell data, we don't show ads, and we don't track you across other apps.

Data the app stores

On your device (always): your hunter profile (display name, sex selection, age, height, weight, fitness level, equipment, injury flags, training schedule) and your game/workout progress (sessions, sets, loads, reps, ranks, streaks, cosmetics, in-game currency) plus your Provisions food diary (the foods you log, portions, and the resulting calories/macros). This data stays in the app's private storage on your phone. Deleting the app deletes it.

Cloud sync (optional): if sync is enabled, the same profile and progress data (including your food diary) is stored with our backend provider Supabase so your progress can be restored or moved to a new device — keyed to your account, encrypted in transit (HTTPS/TLS), and used for nothing except providing sync. If sync is off, everything stays on your device.

Accounts (optional): you can play entirely as a guest with no account. If you choose to create one — with Google or an email + password, so your progress is backed up and follows you across devices — we store your email address, and, if you use Google, the display name your Google account provides. Sign-in is handled by Supabase. You can delete your account and all its data at any time (see section 06).

Health and fitness data

The workout data you log (exercises, sets, reps, loads, body weight, injury flags) is fitness data you enter yourself. It is used solely to generate your workouts and drive game progression, and it stays on your device.

Health Connect (future, when available): if a future version offers Health Connect integration and you choose to connect, VoidRise will request the minimum scopes it needs — reading steps/activity (so rest-day movement counts toward your streak) and writing your completed workouts. Health Connect data would be processed on your device, never used for advertising, never sold, and never shared with third parties. You could revoke access at any time in Health Connect settings, and disconnecting stops all reads/writes immediately. Our handling will comply with Google Play's Health Connect permissions policy.

Nutrition logging (Provisions): the foods, portions and calorie/macro totals you log are fitness data you enter yourself, stored exactly like the rest of your progress (on device, and in optional cloud sync).

Food databases: when you search for a food or scan a product barcode, the search term or barcode number is sent to two free public nutrition databases — USDA FoodData Central and Open Food Facts — to look up nutrition facts. These are food/product queries only; no personal or account information is sent.

Meal photo scan (optional): if you use the optional "scan a meal" feature, the photo you take is sent to Google's Gemini API to identify the foods and estimate portions. The image is transmitted over HTTPS, used only to return that analysis, and is not stored by us; Google processes it under its API terms. If you'd prefer not to send a photo off your device, use food search, barcode scan, or manual entry instead — they log the same data without a photo.

Subscriptions and payments

VoidRise offers an optional premium subscription (monthly or annual). Purchases are processed by Google Play Billing — we never see or store your payment card details. We use RevenueCat to validate and manage subscription status; it receives your purchase history and an app-user ID (your account id), not your payment details or the contents of your workouts.

What we DON'T do

Service providers

Data is shared only with the processors needed to run the app: Google Play (app distribution), Google Fonts (typeface delivery, bundled at build time), Supabase (optional cloud sync), USDA FoodData Central and Open Food Facts (food + barcode nutrition lookups — they receive only the food name you search or a barcode number), and Google's Gemini API (only when you use the optional meal-photo scan — it receives the photo you take in order to identify the foods). Each receives only what its function requires. For the optional premium subscription, Google Play Billing (payment processing) and RevenueCat (subscription validation/management) receive the purchase data described in section 03.

Data retention and deletion

On-device data is deleted when you uninstall the app (or use the in-app reset). If you created an account, you can delete your account and all cloud-saved data at any time: in the app, go to System → Account → Delete account, or follow the steps at hjbcodeforge.com/voidrise/delete. You can also email support@hjbcodeforge.com with any data request — we respond within 30 days.

Children

VoidRise is a fitness app intended for users 13 and older. We do not knowingly collect data from children under 13. If you believe a child has used the app, contact us and we will help remove any data.

Your rights

Depending on where you live (e.g. PIPEDA in Canada, GDPR in the EU, CCPA in California) you may have rights to access, correct, export, or delete your personal data. Email support@hjbcodeforge.com and we'll honor the request — since your data lives on your device, this is usually immediate and in your own hands.

Changes

If this policy changes materially, we'll update the effective date here and note it in the app's release notes.

Contact

HJB CodeForge · Ottawa, Ontario, Canada
support@hjbcodeforge.com · hjbcodeforge.com