Privacy Policy

Last updated: September 23, 2026

1. Introduction

Horsegirl (“Horsegirl,” “we,” “us,” or “our”) is operated by Piotr Morawski. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Horsegirl mobile application (the “App”), this website, and any related services (together, the “Service”).

By using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service.

2. Information We Collect

We collect information you provide directly, information generated by your use of the Service, and information from third-party services you choose to connect.

Account & authentication

We use Clerk, a third-party identity provider, to manage sign-up and sign-in. Depending on how you register, this includes your email address, a securely hashed password, your name, a phone number (only if you enable SMS-based multi-factor authentication), and identifiers from social sign-in providers (Google, Apple).

Rider profile

Information you provide about yourself as a rider, such as your general region, riding disciplines, experience level, years riding, goals, and how often you ride or compete.

Emergency (SOS) contact

If you enable our stand-still or fall-detection safety feature, you may provide an emergency contact's name and phone number, optionally selected from your device's address book. This information is stored so it can be displayed to you (or someone near you) during an SOS alert. It is not automatically transmitted to that contact, to emergency services, or to anyone else — the feature displays an on-screen alert that a person must act on.

Horse, stable, and care-provider records

Information you enter about your horses and stable, which may include: a horse's name and photos; ownership details; insurance provider and policy number; microchip, registration, and passport numbers; health information such as allergies, chronic conditions, medications, vaccination and health-visit records, and lab results; feeding plans and equipment; and the name, phone number, email, and clinic name of veterinarians, farriers, dentists, or other care providers you add. Some of this information may identify third parties (for example, a horse's owner or a care provider) whom you are responsible for having the appropriate basis to share with us.

Location data

When you record a ride, we collect precise GPS location (latitude, longitude, altitude, speed, and accuracy) for the duration of the ride, including while the App is running in the background, so the ride can continue recording if your device is locked or the App is minimized. If you set an address or drop a pin for your stable, we store that location and use it to provide weather forecasts and map display for that stable.

Health and fitness data

With your permission, we read heart-rate data from Apple Health or Google Health Connect during a recorded ride, and we support pairing a Bluetooth heart-rate monitor directly. We only read this data — the App never writes data back to Apple Health or Google Health Connect. We do not use, and will never use, this health data for advertising, marketing, or any other use-based data mining purpose, and we do not sell or share it with data brokers or advertising platforms.

Photos and files

Photos and documents you upload, such as horse or equipment photos, task attachments, and horse documents (for example, insurance or passport files).

Push notifications and usage/analytics data

We use OneSignal to deliver push notifications, which receives a device push token, an internal account identifier, and your name and email address so it can target and personalize notifications to your device. We use PostHog for product analytics, which receives in-app interaction events (for example, screens viewed or steps completed) together with an internal account identifier. Analytics events are designed to avoid free-text or precise-location content — for example, we record that you filled in an emergency contact, not its contents, and that you set a stable location, not its coordinates. Analytics and notification providers also automatically collect standard technical data as part of their normal operation, such as device type, operating system, app version, and IP-derived approximate location.

Purchase data

Subscriptions are purchased through the Apple App Store or Google Play and managed with RevenueCat, which receives an internal account identifier and your purchase/subscription status. We never receive or store your payment card details.

3. How We Use Your Information

  • To provide and sync the Service's core features (tasks, horses, rides, and stable management) across your devices, including while you are offline.
  • To operate on-device safety features, such as fall and stand-still detection during a recorded ride.
  • To send you notifications you have requested or enabled.
  • To provide weather forecasts for your stable and to look up addresses (using Open-Meteo and Mapbox, respectively).
  • To offer AI-assisted suggestions, such as identifying equipment from a photo or generating horse-care recommendations, using OpenAI's API. Inputs may include an equipment photo or horse profile attributes (such as weight, breed, or clip type); these suggestions are informational only and are not a substitute for veterinary or professional advice.
  • To process subscriptions and manage entitlements.
  • To maintain, secure, and improve the Service, including through product analytics.
  • To comply with legal obligations and enforce our terms.

4. Legal Bases for Processing (EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases: performance of a contract (to provide the Service you request), your consent (for example, for location tracking, health data access, and optional features), our legitimate interests (for example, securing the Service and understanding how it is used), and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time through your device or in-app settings, without affecting the lawfulness of processing before withdrawal.

5. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with the service providers who help us operate the Service, each acting on our behalf and under contractual confidentiality and data-protection obligations:

  • Clerk — authentication and account management.
  • OneSignal — push notification delivery.
  • PostHog — product analytics (hosted in the EU by default).
  • RevenueCat, together with the Apple App Store and Google Play — subscription and purchase management.
  • Amazon Web Services (S3) — encrypted, private file and photo storage. Files are not publicly accessible and are only ever served through short-lived signed links.
  • OpenAI — AI-assisted equipment recognition and horse-care suggestions.
  • Mapbox — address search and map display.
  • Open-Meteo — weather forecasts.

We may also disclose information if required by law, to protect the rights, safety, or property of Horsegirl or others, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this Privacy Policy or provide comparable protection.

6. International Data Transfers

We primarily store your data in the European Union (our file storage is located in Frankfurt, Germany). Some of our service providers listed above are based in, or process data in, the United States or other countries outside your own. Where we transfer personal information internationally, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to protect your information.

7. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. If you delete your account, we delete your rider profile, SOS settings, and notifications, and we delete your workspace data (tasks, horses, rides, health and training records, and related files) once no other member remains on that workspace. Some information may persist for a limited period in encrypted backups before it is permanently purged, and we may retain limited records where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

8. Your Privacy Rights

European Economic Area, UK, and Switzerland

If applicable data protection law gives you these rights, you may request access to, correction of, deletion of, or a copy of your personal information, and you may object to or request restriction of certain processing, or withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.

California (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion or correction of your personal information; and to non-discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under California law, so there is no opt-out to provide. You may submit a request, including through an authorized agent, using the contact details below.

Other jurisdictions

Regardless of where you live, you may contact us using the details below to ask what personal information we hold about you, request that we correct or delete it, or ask questions about this Policy, and we will respond in accordance with applicable law (including, where relevant, Canada's PIPEDA or Brazil's LGPD).

9. Children's Privacy

The Service is not directed to children under the age of 16 (or under 13 in the United States), and we do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

10. Security

We use industry-standard safeguards to protect your information, including encryption in transit (TLS), encryption at rest for stored files, private (non-public) file storage accessed only through short-lived signed links, and access controls limiting who can reach your data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Cookies and Similar Technologies

This website uses only the minimal cookies or local storage needed for it to function; we do not currently use cookies for cross-site advertising or tracking. Because there is no common industry standard for responding to browser “Do Not Track” signals, we do not currently respond to them differently. If this changes, we will update this Policy.

12. Automated Decision-Making

Suggestions generated using AI (for example, identifying equipment from a photo or care recommendations) are provided to assist you and are not used to make any decision that produces legal effects concerning you or similarly significantly affects you.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above, and if a change is material, we will provide additional notice through the App or by email.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of the rights described above, please contact:

Piotr Morawski
Email: piotr.morawski@syncflux.io