Privacy Policy
Last updated: August 25, 2026
Showup ("we," "our," or "us") operates the Showup mobile application for iOS and Android and the website at www.showupcounts.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who else can see it, and what you can do about it.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
To create an account you must provide the following, including when you sign up with a social login:
- Email address
- Username (globally unique and visible to other users)
- Display name
- Date of birth
- Gender
- Country
As you use the Service, we also collect:
- Fitness data: workout scores, personal records, and benchmark results, together with the workouts and sessions you create
- User-generated content: posts, comments, reactions, and photos or videos you upload to a Space
- Community data: the Spaces you belong to, your role in each, join requests, invitations you send, and users you block
- Booking and membership data: class bookings and cancellations, waitlist entries, the membership plan assigned to you by a Space, your membership start and end dates, membership holds, your credit balance and the record of credits used in each period, and a membership history trail. Booking records also note whether an administrator booked or cancelled on your behalf.
- Purchase data: your subscription plan and status, billing period, store transaction identifiers, renewal and expiry dates, billing-failure status, and any promotional offer you redeem
- Support communications: your account email, a reply-to email address you type in, your name, your message, and diagnostic details such as app version and subscription plan
- Content reports: if you report content, we collect your identity as the reporter, what you reported, the reason, and your description
- Preferences: unit preferences (weight, distance), language, notification settings, and your profile privacy switches
Showup does not host a profile photo that you upload. If a profile picture appears, it is a link supplied by the sign-in provider you used.
1.2 Information We Receive from Your Sign-In Provider
When you sign in with a third-party account, we receive a limited profile from that provider:
- Sign in with Apple (iOS): a stable Apple user identifier, your name if you choose to share it, and your email address or an Apple private-relay address
- Google Sign-In: your Google account identifier, name, email address, and profile picture URL
- Naver Sign-In (available in Korea): your Naver user identifier, name, and email address. We store a permanent mapping between your Naver identifier and your Showup account so that you can sign in again.
1.3 Information Collected Automatically
- Device identifier: on iOS, a random identifier we generate and store in the device Keychain, which persists if you delete and reinstall the app; on Android, the system-provided Android ID. We use it to enforce a limit of two registered devices per account, a cooldown between device changes, and the ability to sign a device out remotely.
- Device details: device model name, operating system version, app version, and the time each device was registered and last active
- Push notification tokens: one per device, so we can deliver notifications
- Usage data: in-app events and screen views collected through Google Analytics for Firebase (see Section 4)
- Crash reports and performance diagnostics: on iOS, collected through Firebase Crashlytics and linked to your account identifier (see Section 4)
- Device integrity signals: the app asks Apple's App Attest service (iOS) or Google Play Integrity (Android) to attest that it is a genuine, unmodified copy of Showup, and sends the resulting token to Firebase App Check. This is used to block abuse of our servers.
1.4 Information About Other People
If you invite someone to a Space, you provide us with their email address, and optionally their name or username. We store that invitation and send an email to the address you gave us, naming you and the Space. If the person never had a Showup account, we hold their email address only for the purpose of delivering and tracking that invitation. Anyone who receives an invitation they did not want can contact us at the address in Section 14 and we will delete the invitation and their address.
The same applies in reverse: if you ask to join a Space, the administrators of that Space receive your name, username, email address, and any message you write.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate you
- Provide, operate, and maintain the Service
- Enable Spaces, leaderboards, PR boards, and social interactions
- Record and display workout scores, personal records, and benchmarks, including deriving your age from your date of birth and publishing your age and gender alongside your results so that boards can be filtered by category, gender, and age group
- Operate class booking: reserve and cancel places, manage waitlists, apply membership plans, and track credit balances
- Send push notifications about workouts, bookings, community activity, and account changes
- Send transactional emails, such as Space invitations and replies to support requests
- Process in-app purchases, determine which features your plan unlocks, and manage subscriptions
- Enforce the two-device limit, the device-change cooldown, and remote sign-out
- Detect, prevent, and address abuse, fraud, and technical problems, including device attestation
- Review content reports and enforce our Terms and community guidelines
- Monitor and improve the Service through aggregate usage analytics and crash diagnostics
3. How Your Information Is Shared
3.1 Visibility Within the Service
Showup is a community product, and much of what you record is meant to be seen by other people. Within the Service, the following is readable by signed-in Showup users, and not only by members of the Spaces you belong to:
- Your profile record, including your username, display name, email address, date of birth, gender, and country
- Your workout scores, personal records, and benchmark results, each of which carries your name, your gender, and your age
- Posts, comments, reactions, and any photos or videos uploaded to a Space
- Your notification and language preferences and your registered device list, including push notification tokens
Whether a username is already taken can also be checked without signing in — that is how the sign-up screen tells you a name is free. The profile privacy switches in the app control whether your stats, personal records, benchmarks, and Space list are displayed on your profile to other members; they do not narrow the access described above.
We are working to narrow this access so that it follows the Spaces you belong to. We will update this section as we do; this policy always describes the access that is actually in force.
3.2 Space Administrators
A Space is run by its own administrators, who are other Showup users and not our staff. If you join a Space, its administrators and staff can:
- See your display name, username, email address, join date, and role
- See your membership plan, start and end dates, holds, full credit ledger, and membership history
- See your bookings and cancellations for that Space, and book or cancel classes on your behalf, choosing whether the credit is returned
- Assign or change your membership plan, create or backdate a hold, and remove you from the Space
- Write a free-text note about you on your membership record. You can read this note too.
Whether other members can see who is booked into a class is set per class by the Space. The default is that only administrators and staff can see the participant list, and the waitlist is always visible only to them.
Space administrators are responsible for how they handle their members' information. We provide the tools; we do not control what an individual Space does with them.
3.3 Service Providers
We use the following third parties to operate the Service:
- Google (Firebase and Google Cloud): authentication, database and file storage, server functions, push notification delivery, app analytics, crash reporting, and App Check anti-abuse attestation
- Apple: Sign in with Apple, App Store purchase and subscription processing, App Attest device attestation, and push notification delivery on iOS
- Google Play: purchase and subscription processing and Play Integrity device attestation on Android
- RevenueCat, Inc. (United States): subscription and entitlement management. RevenueCat receives your Showup account identifier together with your store purchase and transaction history. We do not send it your name, email address, or any profile data.
- NAVER Corp. (Republic of Korea): Naver Sign-In, for users who choose it. The Naver SDK is initialised when the app starts.
- Our email delivery provider: delivers Space invitations, support-request emails, and content-report notifications, and therefore processes the addresses and message contents involved
- GitHub, Inc. (United States): hosts the Showup website (see Section 5)
- YouTube (Google): if a Space links a YouTube video, playing it or displaying its thumbnail loads content from Google's servers, which receives your IP address and user agent and may set its own identifiers. This is governed by Google's privacy policy.
These providers process your data on our behalf or, where they are independent controllers, under their own privacy policies. We require them to provide protection for your data at least equivalent to that described in this policy.
3.4 Legal Requirements
We may disclose your information if required to do so by law, or in response to valid legal requests by public authorities.
3.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
3.6 No Sale of Data
We do not sell, rent, trade, or share your personal information for advertising or for third-party marketing purposes, and we never have.
4. Analytics, Diagnostics, and Advertising
The Service contains no third-party advertising. We do not use advertising SDKs, attribution SDKs, or cross-app tracking, and we do not track you across other apps or websites. We do not use Apple's App Tracking Transparency prompt because we have nothing to ask you for.
We do use two Google diagnostic tools inside the app:
- Google Analytics for Firebase is enabled on both iOS and Android. It records app usage — screens viewed, sessions, and automatically collected events — along with device and app metadata and a Google-generated app instance identifier. We use it in aggregate to understand which parts of the app are used. On Android, the analytics library also declares the advertising-identifier permission; we do not use an advertising identifier, do not run ads, and do not build advertising profiles.
- Firebase Crashlytics is enabled on iOS only. It records crashes and non-fatal errors, and we attach your account identifier to those reports so that we can investigate a problem you report to us.
If you are in the European Economic Area or the United Kingdom and do not want this processing, contact us at the address in Section 14 and we will disable analytics and diagnostics collection for your account.
5. The Showup Website
The website at www.showupcounts.com is a set of static pages. It runs no analytics, no advertising, and no tracking scripts, sets no cookies, and has no forms — the contact page is a plain email link. It stores two values in your browser's local storage, "theme" and "lang", purely to remember your appearance and language choice. Both are strictly necessary for the preference you set, which is why the site shows no consent banner.
Two third parties are involved in serving the site:
- GitHub, Inc. hosts the pages and generates server access logs that contain visitor IP addresses. We cannot read or erase those logs; they are handled under GitHub's privacy statement.
- jsDelivr serves one additional typeface on the home page only, and likewise receives your IP address and user agent.
6. Automated Processing
Some things happen on our servers on a schedule, without anyone reviewing them:
- Memberships that have reached their end date are marked expired once a day
- Subscriptions that have lapsed are downgraded to the free plan once a day, which also reduces the limits applied to Spaces you own and to their members
- Reminders are sent seven days and one day before a subscription expires
- Waitlist places that are not claimed in time are released, and the held credit is returned or forfeited according to the Space's rules
- Classes that do not reach their minimum booking count are cancelled automatically, credits are returned, and participants and managers are notified
- When a place frees up, the next person on the waitlist is promoted automatically
- When a Space creates or widens a membership hold, bookings and waitlist entries inside the held period are cancelled automatically, and credits may be forfeited under the Space's rules
None of these produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR. If you believe an automated action was wrong, contact us and a person will look at it.
7. Data Storage and Security
Your account data, fitness records, community content, and uploaded media are stored on Google Cloud infrastructure through Firebase. Your subscription and purchase history is additionally held by RevenueCat, and your crash reports by Firebase Crashlytics. All data is encrypted in transit using HTTPS/TLS and encrypted at rest by the provider.
The app also caches your data on your own device so that it works offline. Signing out or deleting the app removes that cache.
While we use industry-standard security measures to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. Please also read Section 3.1, which describes the access that is currently in force.
8. Data Retention and Account Deletion
You can delete your account at any time from Account settings in the app. If you cannot reach the app, email us from your account's email address with the subject "Delete my account" and we will verify ownership and process it. Deletion is queued and carried out by our servers rather than instantly; it normally completes within minutes and always within 30 days. If you have an active subscription bought through the App Store, you must cancel it with Apple before the app will let you delete the account.
8.1 What Deleting Your Account Removes
- Your account and sign-in credentials, including the mapping to any Google, Apple, or Naver login
- Your profile record, your username reservation, and your app settings, including your registered devices and push tokens
- Your personal records, benchmark records, and workout scores
- Posts you authored, together with their media, comments, and reactions
- Comments you wrote on other people's workouts, scores, and posts
- Your membership record in every Space, and your notifications
8.2 What Is Retained After Deletion
The following are not removed by the deletion process, and you should assume they persist:
- Spaces you created that still have other members are archived, not deleted, so the remaining members keep their own history
- Your booking and credit history in Spaces you belonged to
- Support tickets you sent us, and content reports you filed
- Invitations you sent and join requests you made
- Your reactions on other people's content, and media or workouts you contributed to a Space you did not own, which remain part of that Space's records
- Membership history entries in a Space that name you
- Purchase and transaction records held by us, by RevenueCat, and by the app store, retained for the period required by tax, accounting, and consumer law
- A record that a deletion was requested and completed, kept as proof that we honoured your request
- Crash reports already collected
If you want any of the retained items removed, contact us at the address in Section 14 and we will remove what we are not legally required to keep.
8.3 Retention Periods
- Account, profile, fitness, and community data: kept while your account is active, then removed as described in Section 8.1
- Booking, credit, and membership records: kept for as long as the Space they belong to exists
- Invitations: kept until accepted or withdrawn; an unaccepted invitation is deleted on request
- Support tickets and content reports: kept for as long as needed to handle the request and to defend against repeat abuse
- Purchase and transaction records: kept for the period required by applicable tax, accounting, and consumer protection law
- Analytics and crash diagnostics: kept for the retention period set by Google for Firebase
- Backups: deleted data may persist in backups for a limited period before being overwritten
Anonymised or aggregated data that cannot identify you may be retained indefinitely.
9. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
- Contract: creating and running your account, recording your fitness data, operating Spaces and bookings, and processing your subscription
- Legitimate Interests: keeping the Service secure and free of abuse, device attestation and the device limit, crash diagnostics, aggregate usage analytics, handling support requests and content reports, and delivering invitations you ask us to send
- Consent: push notifications, and access to your photo library
- Legal Obligation: retaining transaction records and responding to lawful requests
Where we rely on legitimate interests, you can object at any time using the contact details in Section 14.
10. Your Rights and Choices
10.1 Rights for All Users
- Access: Request a copy of the personal information we hold about you
- Correction: Update your profile in the app, or ask us to correct anything you cannot edit yourself
- Deletion: Delete your account from Account settings in the app, subject to Section 8
- Notifications: Turn off push notifications in the app or in your device settings
- Analytics: Ask us to disable analytics and crash diagnostics for your account
- Withdraw Consent: Withdraw any consent you have given, and stop using the Service at any time
10.2 Additional Rights for EEA/UK Users (GDPR)
If you are located in the EEA or the United Kingdom, you also have the right to:
- Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format
- Restrict Processing: Request that we limit the processing of your personal data under certain circumstances
- Object to Processing: Object to processing based on legitimate interests
- Lodge a Complaint: File a complaint with your local data protection supervisory authority
10.3 Rights for Users in the United States
Depending on your state of residence, you may have the right to know what personal information we collect, use, and disclose; to obtain a copy of it; to correct it; to delete it; to appeal a decision we make about your request; and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we do not use or disclose sensitive personal information for purposes that require an opt-out. Because the Showup website runs no advertising or analytics, there is nothing for an opt-out preference signal such as Global Privacy Control to act on.
10.4 Rights for South Korean Users (PIPA)
If you are located in South Korea, under the Personal Information Protection Act you have the right to access, correct, delete, or suspend the processing of your personal information, to be informed of its collection and use, and to withdraw your consent. You may also refuse consent to non-essential collection, though this may limit parts of the Service.
Categories of personal information we collect, the purposes, and the retention periods are set out in Sections 1, 2, and 8. Processing we entrust to third parties, and the transfers of personal information outside Korea that this involves, are set out in Sections 3.3 and 12. When personal information reaches the end of its retention period or its purpose is achieved, we destroy it without delay: electronic files are deleted irrecoverably, and any printed material is shredded or incinerated.
Personal Information Protection Officer: Showup — support@showupcounts.com
You may also report concerns to the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), the Korea Internet & Security Agency Privacy Complaint Centre (privacy.kisa.or.kr, 118), or the Personal Information Protection Commission (pipc.go.kr).
To exercise any of these rights, use the in-app settings or contact us at the email address in Section 14. We will respond within the timeframe required by applicable law, generally within 30 days.
11. Children's Privacy
The Service requires you to be at least 13 years old, and we do not knowingly collect personal information from children under 13. Where the law of your country sets a higher age for consenting to online services on your own — 16 in parts of the EEA and the UK, and 14 in South Korea — you may use the Service below that age only with the consent of a parent or guardian. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact us and we will delete it.
12. International Data Transfers
Showup is operated from the Republic of Korea. We have no establishment in the European Union. Your personal data is processed on Google Cloud infrastructure and may be handled in the regions where Google, Apple, RevenueCat, and our other providers operate facilities, including the United States.
For EEA and UK users: transfers of personal data to the Republic of Korea rely on the European Commission's adequacy decision for Korea, adopted on 17 December 2021 and confirmed on its first periodic review on 23 July 2026, under which no additional safeguards are required. Personal data received from the EEA is handled under Korean law as supplemented by the Personal Information Protection Commission's Supplementary Rules. Transfers to providers in the United States rely on the EU–US Data Privacy Framework and the UK Extension where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
For Korean users: personal information is transferred outside Korea to Google (United States and other Google Cloud regions) for infrastructure, analytics, crash diagnostics, and push delivery; to Apple (United States) for sign-in, purchases, and push delivery; and to RevenueCat, Inc. (United States) for subscription management. The items transferred, the purposes, and the retention periods are those set out in Sections 1, 3.3, and 8. You may refuse these transfers, but because they are necessary to run the Service, refusing means you cannot use it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about our data practices, please contact us at:
For EEA/UK users: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.