Last updated: 1 September 2026
Template — requires legal review before launch. This is written to match what the app actually does, but every [ ] must be completed and the whole document checked by counsel before you collect a single live user record.
This policy explains what QYPR (“we”) collects, why, who we share it with, how long we keep it, and the rights you have over it.
Data controller: [ legal entity, registered address ]. Contact: privacy@qypr.org. EU/UK representative: [ if required under GDPR Art. 27 ].
Plainly: yes, we collect data about you. Here is all of it.
| Category | Examples | Why | Legal basis |
|---|---|---|---|
| Account | Name, email (including Apple private relay), password hash if set, Apple subject, role | Create and secure your account | Contract |
| Date of birth | The date you enter at signup or after the first Sign in with Apple | Enforce our 17+ floor and apply age-appropriate protections. We keep the date rather than a yes/no so we can re-derive your age and prove the check happened. | Legal obligation / legitimate interests |
| Practice activity | ASVAB answers, AFQT and MAGE scores, timings | Score your practice tests and track progress | Contract |
| Fitness | Run times, repetition counts, workout logs you type, and — only if you connect Whoop — imported training-run sport, start, end, and duration | Track you against unofficial BMT talking targets | Explicit consent — see §3 |
| Location | ZIP code you enter, or approximate location | Find nearby stations and MEPS sites | Consent |
| Technical | IP address, device and browser type, error logs | Security, abuse prevention, fixing faults | Legitimate interests |
| Analytics | Pages viewed, features used, pseudonymised | Improve the product | Consent — off unless you opt in |
We do not sell your personal data, and we do not share it with data brokers.
Some features are powered by AI, which means certain content is processed by machine-learning systems, in some cases operated by third parties:
AI output can be wrong. Nothing produced by an AI feature here is official military guidance, medical advice, or a guarantee of any score or enlistment outcome. Confirm anything that matters with your recruiter or MEPS.
We do not use your personal content to train third-party foundation models. Where content is sent to an AI provider we use configurations that exclude it from that provider’s training data. [ Name the providers and confirm their zero-retention terms before launch. ]
You will not be subject to a decision with legal or similarly significant effects based solely on automated processing (GDPR Art. 22). Automated moderation outcomes are reviewable by a human on request.
Fitness measurements can qualify as health data — a special category under GDPR Art. 9. We collect it only with your explicit, separate consent, use it solely to show progress against published unofficial talking targets, and never share it with a recruiter, a chain of command, or any government body unless you explicitly instruct us to. Turning on “Share assessments on the global fitness board” is that instruction: your display name and scored events can appear on /leaderboard, and recruiters you follow (or a commander at your station) can see whether you are keeping up. That view is inside this product. It is not a Department of War system and we do not send the records to one. Turning the toggle off removes you from the board and that list. Withdrawing consent for the underlying logs deletes them. Whoop imports never count toward the board. Workout session counts (not times or reps) already appear on the public leaderboard when you log a counted session.
Connecting Whoop is optional and 17+. When you authorize it, WHOOP Inc. sends us workout records you allow: sport name, start, end, timezone offset, and score state. We store allowlisted running workouts as a cardio note (sport and clock duration) with source Whoop. We do not receive or store heart-rate series, GPS, sleep, strain as a score, or recovery. Those imported rows are training history, not a fitness test. Disconnecting Whoop revokes the token and deletes imported Whoop rows. Manual assessments stay.
QYPR is 17+. We ask for a date of birth at signup for every account type and reject anyone below the floor. Enlistment is possible at 17 with parental consent, so some of our users are minors, and where that is the case we apply high-privacy defaults in line with the UK Age Appropriate Design Code: profiles are not public by default, precise location is off by default, and we do not use engagement nudges to extend session time.
A self-declared date of birth is not identity verification. If we learn an account belongs to someone below the floor, we close it and delete the data.
Complete this table with your actual vendors before launch — an incomplete list is itself a compliance failure. Each processor is bound by a data processing agreement and may act only on our instructions.
| Processor | Purpose | Data | Location |
|---|---|---|---|
| [ Hosting ] | Application and Postgres hosting | All categories | [ Region ] |
| [ Email ] | Transactional email, 2FA | Name, email | [ Region ] |
| [ AI provider ] | Question generation, moderation | Practice content | [ Region ] |
| [ Analytics ] | Product analytics | Pseudonymised usage | [ Region ] |
| [ Maps ] | Station and MEPS lookup | Approximate location | [ Region ] |
Apple is not our processor for Sign in with Apple. If you use Sign in with Apple, Apple authenticates you and may share a name, an email (or a privaterelay.appleid.com address), and a stable subject. We store that email honestly. Apple does not send a date of birth; we collect it in-app before the account is usable.
Whoop is not our processor. If you tap Connect Whoop, you authorize WHOOP Inc. to share the workout fields above with us. Their privacy policy governs what they hold. We store encrypted access and refresh tokens on our servers so we can pull those workouts when you open /fitness. We do not send your QYPR account password to Whoop.
| Source you authorize | Purpose | Data we receive | Location |
|---|---|---|---|
| WHOOP Inc. | Import training runs you choose to connect | Sport, start, end, timezone, score state, OAuth tokens | United States (Whoop) / [ our hosting region ] |
Where data leaves the UK or EEA we rely on the UK IDTA or EU Standard Contractual Clauses plus a transfer risk assessment. Ask us for a copy at any time.
Strictly necessary cookies keep you signed in and remember your privacy choice; they cannot be switched off. Analytics and marketing cookies are off until you opt in, and you can change or withdraw that choice at any time via Cookie settings in the footer. Rejecting is one click, exactly like accepting.
Uploads are stored in private buckets. They are not publicly listable, and media is served through time-limited signed URLs rather than permanent public addresses.
Under UK and EU GDPR you may:
You can delete your account and its data from your account settings — the same number of steps it took to create one. Or email privacy@qypr.org and we will respond within one month.
California residents have comparable rights under the CCPA/CPRA to know, delete, correct, and opt out of “sharing”. We do not sell or share personal information as those terms are defined.
Unhappy with our answer? You may complain to your supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk.
Data is encrypted in transit and at rest. Passwords are hashed with bcrypt, sessions are stored as hashes rather than raw tokens, and authenticator-app 2FA is available on every account. Access is role-based, and privileged roles are granted only after out-of-band verification — never self-assigned at signup. If a breach puts your rights at risk we will notify the relevant regulator within 72 hours and tell you without undue delay.
If we materially change what we collect or why, we will tell you in the app and, where the law requires it, ask for consent again. The consent record is versioned, so a change re-prompts everyone rather than silently inheriting an old answer.
See also our terms of service.