← Back to QYPR

Last updated: 1 September 2026

Privacy Policy

Template — requires legal review before launch. This is written to match what the app actually does, but every [ ] must be completed and the whole document checked by counsel before you collect a single live user record.

This policy explains what QYPR (“we”) collects, why, who we share it with, how long we keep it, and the rights you have over it.

Data controller: [ legal entity, registered address ]. Contact: privacy@qypr.org. EU/UK representative: [ if required under GDPR Art. 27 ].

1. We collect user data

Plainly: yes, we collect data about you. Here is all of it.

CategoryExamplesWhyLegal basis
AccountName, email (including Apple private relay), password hash if set, Apple subject, roleCreate and secure your accountContract
Date of birthThe date you enter at signup or after the first Sign in with AppleEnforce our 17+ floor and apply age-appropriate protections. We keep the date rather than a yes/no so we can re-derive your age and prove the check happened.Legal obligation / legitimate interests
Practice activityASVAB answers, AFQT and MAGE scores, timingsScore your practice tests and track progressContract
FitnessRun times, repetition counts, workout logs you type, and — only if you connect Whoop — imported training-run sport, start, end, and durationTrack you against unofficial BMT talking targetsExplicit consent — see §3
LocationZIP code you enter, or approximate locationFind nearby stations and MEPS sitesConsent
TechnicalIP address, device and browser type, error logsSecurity, abuse prevention, fixing faultsLegitimate interests
AnalyticsPages viewed, features used, pseudonymisedImprove the productConsent — off unless you opt in

We do not sell your personal data, and we do not share it with data brokers.

2. We use artificial intelligence

Some features are powered by AI, which means certain content is processed by machine-learning systems, in some cases operated by third parties:

  • Practice questions and explanations. Items and the written explanations behind them may be generated or refined by large language models.
  • Content moderation. Submitted content may be screened automatically for abuse and safety concerns before a human reviews it.
  • Marketing media. The video and imagery on our landing page is AI-generated. It depicts no real, identifiable person and is not documentary footage.

AI output can be wrong. Nothing produced by an AI feature here is official military guidance, medical advice, or a guarantee of any score or enlistment outcome. Confirm anything that matters with your recruiter or MEPS.

We do not use your personal content to train third-party foundation models. Where content is sent to an AI provider we use configurations that exclude it from that provider’s training data. [ Name the providers and confirm their zero-retention terms before launch. ]

You will not be subject to a decision with legal or similarly significant effects based solely on automated processing (GDPR Art. 22). Automated moderation outcomes are reviewable by a human on request.

3. Health and fitness data

Fitness measurements can qualify as health data — a special category under GDPR Art. 9. We collect it only with your explicit, separate consent, use it solely to show progress against published unofficial talking targets, and never share it with a recruiter, a chain of command, or any government body unless you explicitly instruct us to. Turning on “Share assessments on the global fitness board” is that instruction: your display name and scored events can appear on /leaderboard, and recruiters you follow (or a commander at your station) can see whether you are keeping up. That view is inside this product. It is not a Department of War system and we do not send the records to one. Turning the toggle off removes you from the board and that list. Withdrawing consent for the underlying logs deletes them. Whoop imports never count toward the board. Workout session counts (not times or reps) already appear on the public leaderboard when you log a counted session.

Connecting Whoop is optional and 17+. When you authorize it, WHOOP Inc. sends us workout records you allow: sport name, start, end, timezone offset, and score state. We store allowlisted running workouts as a cardio note (sport and clock duration) with source Whoop. We do not receive or store heart-rate series, GPS, sleep, strain as a score, or recovery. Those imported rows are training history, not a fitness test. Disconnecting Whoop revokes the token and deletes imported Whoop rows. Manual assessments stay.

4. Under-18s

QYPR is 17+. We ask for a date of birth at signup for every account type and reject anyone below the floor. Enlistment is possible at 17 with parental consent, so some of our users are minors, and where that is the case we apply high-privacy defaults in line with the UK Age Appropriate Design Code: profiles are not public by default, precise location is off by default, and we do not use engagement nudges to extend session time.

A self-declared date of birth is not identity verification. If we learn an account belongs to someone below the floor, we close it and delete the data.

5. Third parties who process your data

Complete this table with your actual vendors before launch — an incomplete list is itself a compliance failure. Each processor is bound by a data processing agreement and may act only on our instructions.

ProcessorPurposeDataLocation
[ Hosting ]Application and Postgres hostingAll categories[ Region ]
[ Email ]Transactional email, 2FAName, email[ Region ]
[ AI provider ]Question generation, moderationPractice content[ Region ]
[ Analytics ]Product analyticsPseudonymised usage[ Region ]
[ Maps ]Station and MEPS lookupApproximate location[ Region ]

Apple is not our processor for Sign in with Apple. If you use Sign in with Apple, Apple authenticates you and may share a name, an email (or a privaterelay.appleid.com address), and a stable subject. We store that email honestly. Apple does not send a date of birth; we collect it in-app before the account is usable.

Whoop is not our processor. If you tap Connect Whoop, you authorize WHOOP Inc. to share the workout fields above with us. Their privacy policy governs what they hold. We store encrypted access and refresh tokens on our servers so we can pull those workouts when you open /fitness. We do not send your QYPR account password to Whoop.

Source you authorizePurposeData we receiveLocation
WHOOP Inc.Import training runs you choose to connectSport, start, end, timezone, score state, OAuth tokensUnited States (Whoop) / [ our hosting region ]

Where data leaves the UK or EEA we rely on the UK IDTA or EU Standard Contractual Clauses plus a transfer risk assessment. Ask us for a copy at any time.

6. Cookies

Strictly necessary cookies keep you signed in and remember your privacy choice; they cannot be switched off. Analytics and marketing cookies are off until you opt in, and you can change or withdraw that choice at any time via Cookie settings in the footer. Rejecting is one click, exactly like accepting.

7. How long we keep things

  • Account data — while your account is open, then 30 days after deletion.
  • Uploads and submitted content — removed from live systems within 30 days of deletion and purged from encrypted backups within 90 days. After that it is gone and cannot be restored.
  • Practice and fitness records — while your account is open, or until you delete them individually.
  • Security and audit logs — 12 months.
  • Records we must keep by law — for the statutory period only.

Uploads are stored in private buckets. They are not publicly listable, and media is served through time-limited signed URLs rather than permanent public addresses.

8. Your rights

Under UK and EU GDPR you may:

  • ask what we hold about you and get a copy;
  • correct anything inaccurate;
  • have your data deleted;
  • receive your data in a portable format;
  • restrict or object to processing, including profiling;
  • withdraw consent at any time, without affecting what we did lawfully beforehand.

You can delete your account and its data from your account settings — the same number of steps it took to create one. Or email privacy@qypr.org and we will respond within one month.

California residents have comparable rights under the CCPA/CPRA to know, delete, correct, and opt out of “sharing”. We do not sell or share personal information as those terms are defined.

Unhappy with our answer? You may complain to your supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk.

9. Security

Data is encrypted in transit and at rest. Passwords are hashed with bcrypt, sessions are stored as hashes rather than raw tokens, and authenticator-app 2FA is available on every account. Access is role-based, and privileged roles are granted only after out-of-band verification — never self-assigned at signup. If a breach puts your rights at risk we will notify the relevant regulator within 72 hours and tell you without undue delay.

10. Changes

If we materially change what we collect or why, we will tell you in the app and, where the law requires it, ask for consent again. The consent record is versioned, so a change re-prompts everyone rather than silently inheriting an old answer.

See also our terms of service.

QYPR is not affiliated with, endorsed by, or sponsored by the United States Space Force, the Department of the Air Force, or the Department of Defense. See the DOD disclaimer, privacy policy, terms, and accessibility statement.