Privacy Policy
PEDIVO PRIVACY POLICY
Last Updated: 31 July, 2026.
1. INTRODUCTION
Welcome to Pedivo. Pedivo Ltd (“Pedivo”, “we”, “us”, “our”) is committed to protecting your privacy and safeguarding your personal data through transparent practices, appropriate technical and organizational security measures, and clear communication regarding how and why we process your information.
This Privacy Policy explains how we collect, use, store, disclose, transfer, and protect information when you access or use the Pedivo mobile application (the “App”), our website (if applicable), and any related features, community services, integrations, and reward systems (collectively, the “Services”). This Policy should be read together with our Terms of Service and any in-app notices that provide additional detail for specific processing activities.
Legal Compliance. This Policy is drafted to comply with applicable data protection laws and platform requirements, including where relevant: the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Nigeria Data Protection Regulation (“NDPR”) and the Nigeria Data Protection Act (as applicable), the California Consumer Privacy Act as amended (“CCPA”), and any implementing or successor legislation, together with the requirements of the Apple App Store and Google Play Store.
Medical Disclaimer. Pedivo is a fitness and lifestyle application and is not a medical device. We do not provide medical advice, diagnosis, or treatment. You should always seek professional medical advice regarding any medical condition or health concern and should not rely on the Services as a substitute for professional healthcare.
Scope. This Policy applies to information we process about Users and visitors. It does not apply to third-party services, even if they are linked to or integrated with the Services. Third parties have their own privacy policies which govern their processing of your data.
2. INFORMATION WE COLLECT
We collect and process certain categories of information in order to deliver the Services, maintain accuracy in activity tracking, support community features, prevent fraud, ensure security, and improve our product. The information we collect depends on how you use the Services, your device settings, and the permissions you grant.
A. Account Information
When you create or maintain an Account, we collect information necessary to administer your Account, authenticate you, and provide basic profile functionality.
- Registration Data: Name, username, and email address.
- Profile Data: Profile photo (optional) and country/region (to localize leaderboards).
- Device Identifiers: IP address, unique device ID (UUID), app version, and operating system details.
- Sign-In Providers: If you register or sign in using Google or Apple, we receive the identifier, name, and email address (or Apple’s private relay address) that the provider releases to us. We do not receive your password.
- Date of Birth (optional): Where you provide it, we use it to confirm you meet the minimum age for the Services and for age-restricted features.
- Install Attribution: On Android, we read the Play Install Referrer to determine whether you arrived through an invitation or referral link, so that the referring User can be credited.
- Session & Device Binding: An Account may be signed in on one device at a time. We record the device bound to your current session so that signing in elsewhere ends the previous session.
B. Health & Activity Data (Sensitive Information)
Pedivo processes certain health-related activity signals which may be treated as sensitive data under some laws. We process such data only where you provide explicit consent or where otherwise permitted by applicable law.
We process the following only with your explicit consent:
- Movement Data: Step counts, distance, and activity duration via your device sensors.
- Location & Verification Data: GPS or location signals used to verify movement, detect spoofing, and protect reward integrity (only when you enable location services).
- Calculated Metrics: Estimated calories burned.
- Third-Party Integrations: If you opt-in, we read “Steps” and “Active Energy” from Apple Health (HealthKit) or Google Fit.
- Daily Cycle: Steps reset automatically at 12:00 AM (local time). Historical totals are archived to maintain your “Virtual Coin” balance.
Important: You may withdraw consent at any time through your device permissions or in-app settings (where available). Withdrawal of consent may limit or disable core functionality of the Services (for example, step tracking, movement verification, and Virtual Coin awarding).
C. Contacts & Social Data (Optional)
Pedivo offers optional community features that enable social comparisons and participation in communities and leaderboards.
- Contact Discovery: With your permission, we access your contacts to find friends. We use one-way hashing; your raw contact list is never stored on our servers or used for marketing.
- Community Interaction: Information you share in communities or on leaderboards (e.g., username and step count) may be visible to other users based on the feature settings you choose.
- Posts & Comments: Text you post or comment within a community is visible to other members of that community, and to non-members on a read-only basis where the community is public. This content is retained in accordance with Section 7 and is subject to moderation.
- Member Profiles: Other members can view your public member profile, which may include your lifetime step total, current streak, and badge count.
- Uploaded Images: If you upload avatar or cover images for your profile or a community, we collect and process those images. Uploaded images are moderated before or while they are publicly displayed.
- Moderation & Safety Data: When you report content or members, block another user, or are subject to a report or ban, we record and process the associated information (including who reported whom and the reason given) for trust, safety, and integrity purposes.
- Discoverability & Suggestions: Your username, display name, and profile photo can be found by other Users through in-app search, and your profile may be suggested to other Users in features such as “Who to follow” and when a User is choosing someone to challenge. These suggestions are generated automatically from signals such as mutual connections and activity on the Services.
- Head-to-Head Records: Where you take part in a race or challenge against another User, we retain the result so that the running record between the two of you (for example “3–1”) can be displayed to both participants.
- Shareable Cards: The App can generate an image summarizing an achievement or a race result, including your username, profile photo, and the relevant statistics. If you choose to share it, it leaves the Services and is handled by whichever app or platform you send it to, under their policies rather than ours.
If you choose to participate in social features, you acknowledge that certain profile elements and activity summaries may be displayed publicly or to other users, as described in the Terms of Service.
D. Usage & Technical Data
We collect technical and usage information to maintain the Services, analyze performance, detect abuse, and improve reliability and user experience.
- Analytics: Feature usage, session duration, and navigation paths.
- Diagnostics: Crash logs and performance reports (processed via Firebase/Sentry).
- Push Notification Tokens: A device push token issued by Apple or Google, used to deliver notifications such as reminders, milestone and goal messages, challenge invitations, and race results. You can turn notifications off at any time in your device settings.
- Real-Time Connections: While you are using the App, it may hold an open connection to our servers so that leaderboards, races, challenges, and community feeds update live. We process the connection metadata needed to operate it, such as your session, the topics you are viewing, and connection timing.
- Feature Configuration: The App asks our servers which features are switched on for your Account. We use this for staged rollouts, testing, and to disable a feature quickly if it misbehaves. Which group you fall into is derived from your Account identifier; it is not used to build a marketing profile.
- Software Update Checks: The App checks for and downloads over-the-air updates to its own program code (see Section 6). This involves contacting our update provider with your app version, platform, and IP address.
E. Camera, Photos & Video (Optional)
Some features let you create or upload visual content. These permissions are requested only when you use the feature concerned, and you can decline or revoke them in your device settings.
- Camera & Photo Library: Accessed when you set a profile or cover photo, attach an image to a report, or record or select media for creator features.
- Video & Media Creation: Where you use creator features, we process the video or images you supply in order to produce the finished clip, including overlaying your activity statistics onto it. Processing happens on your device where possible; content is uploaded to our servers only where the feature requires it or where you choose to publish it.
- Saved Output: If you save a created clip or card, it is written to your device’s photo library. We do not gain access to the rest of your library by doing so.
F. Advertising & Tracking
The Services are supported in part by advertising. We display ads through Google AdMob, including ads in the reward area and optional rewarded ads that you can choose to watch in exchange for an in-app benefit. Watching a rewarded ad is always optional and never a condition of tracking your steps.
- Advertising Identifiers: Our advertising partner may process your device’s advertising identifier, IP address, coarse location derived from it, and ad interaction events in order to serve, cap, measure, and bill for ads.
- App Tracking Transparency (iOS): On iOS we ask for your permission before any tracking across other companies’ apps and websites takes place. If you decline, you will still see ads, but they will be non-personalized. You can change your answer at any time in iOS Settings.
- Android: You can limit ad personalization or reset your advertising ID in your Google account and device settings.
We do not share health or activity data with advertisers. Step counts, distance, calories, location, and any data read from Apple Health or Google Fit are never disclosed to our advertising partner and are never used to target ads.
3. HOW WE USE YOUR INFORMATION
We use your information only for legitimate, defined purposes aligned with the operation of the Services. In particular, we use your data for the following purposes:
- Service Provision: To operate the Services, authenticate your Account, track steps, calculate calories, verify movement (including using GPS/location signals where enabled), and convert eligible activity into Virtual Coins.
- Gamification: To manage rewards, challenges, streaks, achievements, and public leaderboards where you elect to participate.
- Integrity: To detect, investigate, prevent, and remediate fraud, cheating, abuse, or violations of our Terms (including step-cheating detection, validation, and GPS/location-based verification where enabled).
- Support: To respond to your inquiries, provide customer support, address disputes, and fix technical bugs.
- Security: To secure the App, prevent unauthorized access, and maintain network and information security controls.
- Improvement: To perform internal analytics, understand feature adoption, and enhance performance and user experience.
- Communications: To send push notifications and in-app messages relating to your activity and the Services, such as movement reminders, goal and milestone messages, challenge invitations and results, community activity, and important service notices. You can disable push notifications in your device settings; we may still send you essential service and security messages.
- Delivery & Configuration: To decide which features are enabled for your Account, to roll changes out gradually, and to deliver updates to the App’s program code.
- Advertising: To display and measure advertisements, as described in Section 2.F. We do not use health or activity data for this purpose.
Health Data Policy. We do not sell health data to third parties. We do not use health data for targeted advertising or profiling. Where we use analytics, we do so to improve the Services and enforce integrity, and we apply safeguards designed to minimize privacy impact.
4. LEGAL BASIS FOR PROCESSING
Depending on your location and applicable law, we process personal data on one or more lawful bases. The primary lawful bases relied upon include:
- Consent: For health data, contact access, and profile photos. You may withdraw consent at any time through your device settings or in-app controls (where available).
- Contractual Necessity: To provide the core app features you sign up for, including account services, step tracking, and Virtual Coin functionality.
- Legitimate Interests: For app security, fraud prevention, cheating detection, service integrity, and internal analytics (balanced against your rights and expectations).
- Legal Obligation: To comply with statutory and regulatory requirements (including NDPR/GDPR compliance obligations, lawful requests, and recordkeeping duties).
Where required by law, we will provide additional notices and obtain additional consents before processing certain categories of data.
5. DATA SHARING & DISCLOSURE
We do not sell your personal data. We disclose information only where necessary to operate the Services, comply with law, enforce our Terms, or protect users and the public. We may share data with:
- Service Providers: Vendors that provide services on our behalf such as cloud hosting (e.g., AWS), analytics (e.g., Firebase), crash reporting (e.g., Sentry), and payment processing. These providers are authorized to process data only under our instructions and are subject to contractual confidentiality and security obligations.
- Community: If you participate in communities or leaderboards, certain information such as your username and step totals may be visible to other users according to feature settings.
- Advertising Partners: Our advertising provider receives the technical and advertising identifiers described in Section 2.F in order to serve and measure ads. They do not receive your health or activity data.
- Legal Authorities: Where required by a valid court order, subpoena, or other lawful process, or where disclosure is reasonably necessary to comply with law or protect the rights, property, or safety of Pedivo, users, or others.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of the transaction, subject to applicable law and appropriate safeguards.
We may also share aggregated or de-identified information that cannot reasonably be used to identify you, for analytics and service improvement purposes.
6. THIRD-PARTY PLATFORMS & SERVICES
The Services may be distributed through or integrated with third-party platforms and services. Your use of those platforms is governed by their own policies. We encourage you to review those policies carefully.
Pedivo integrates with the following platforms and providers. Their use of data is governed by their own policies. This list may change as the Services evolve; we will update it accordingly.
| Service | Purpose | Privacy Policy |
|---|---|---|
| Apple App Store | App distribution | https://www.apple.com/legal/privacy/ |
| Google Play Store | App distribution | https://policies.google.com/privacy |
| Apple Health (HealthKit) | Steps and active energy, with your consent | https://www.apple.com/legal/privacy/ |
| Google Fit / Health Connect | Steps and active energy, with your consent | https://policies.google.com/privacy |
| Sign in with Apple | Authentication | https://www.apple.com/legal/privacy/ |
| Google Sign-In | Authentication | https://policies.google.com/privacy |
| Firebase (Cloud Messaging, Crashlytics, Analytics) | Push notifications, crash reporting, analytics | https://firebase.google.com/support/privacy |
| Google AdMob | Advertising and rewarded ads | https://policies.google.com/technologies/ads |
| Shorebird | Over-the-air updates to the App’s program code | https://shorebird.dev/privacy |
| Amazon Web Services | Cloud hosting and storage | https://aws.amazon.com/privacy/ |
| Sentry | Error and performance monitoring | https://sentry.io/privacy/ |
Over-the-Air Updates. Parts of the App’s program code can be updated without a new install from the App Store or Google Play. This is used to deliver fixes and improvements quickly. Updates change how the App behaves and may introduce new functionality; where an update materially changes how we handle your data, we will update this Policy and, where required, seek your consent before that processing begins. Updates never bypass the permission prompts your device shows you — a feature that needs the camera, your location, or your health data still requires the permission your operating system controls.
Where you connect Apple Health (HealthKit) or Google Fit, those platforms may have additional controls and terms. Pedivo does not control third-party processing conducted by those platforms.
7. DATA RETENTION & DELETION
We retain personal data only for as long as necessary for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
- Active Data: We retain account data as long as your account is active.
- Account Deletion: You can delete your account in the App Settings. Upon deletion, we remove or anonymize your data within 30 days, subject to legal and security requirements.
- Inactivity: Accounts inactive for more than 24 months may be anonymized or deleted, subject to applicable law and operational constraints.
Certain records may be retained for longer periods where required to comply with legal obligations, fraud prevention, dispute resolution, or the establishment, exercise, or defense of legal claims.
8. YOUR GLOBAL PRIVACY RIGHTS
Depending on your location and applicable law, you may have rights in relation to your personal data. These rights are not absolute and may be subject to legal exceptions.
- Access/Portability: Request a copy of your data in a digital format, and where applicable request transfer of your data to another provider.
- Correction: Request correction of inaccurate or incomplete personal information.
- Erasure: Request deletion of your personal data, subject to lawful grounds for retention.
- Withdrawal of Consent: Revoke permissions for Health or Contact data in your device settings (note: core functionality may be impacted).
- Lodge a Complaint: Contact the NDPC (Nigeria) or your local Data Protection Authority (EU/UK).
To exercise these rights, contact us using the details in Section 12. We may request reasonable verification to confirm identity before fulfilling a request.
9. DATA SECURITY
We implement technical and organizational safeguards designed to protect your information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
By way of example, we use industry-standard AES-256 encryption for data at rest and TLS/SSL encryption for data in transit. We restrict access to personal data to authorized personnel, contractors, and service providers who need access to perform their roles, and who are subject to confidentiality and security obligations.
No method of transmission over the internet or method of electronic storage is 100% secure. Accordingly, while we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
10. INTERNATIONAL DATA TRANSFERS
Pedivo is a global service. Your information may be transferred to, stored, and processed in countries other than your country of residence. These countries may have data protection laws that are different from those in your jurisdiction.
Where required by law, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms to protect cross-border transfers. We also implement additional technical and organizational measures where appropriate to ensure continued protection of your data.
11. CHILDREN’S PRIVACY
Pedivo is not intended for users under 13 years of age. In jurisdictions where a higher age threshold applies (such as 16 in certain regions), we do not intend the Services for users below that threshold. If we learn that we have collected personal data from a child under the applicable age threshold, we will take steps to delete such data promptly.
12. CONTACT INFORMATION
For privacy-related questions, to exercise your rights, or to contact our Data Protection Officer, you may reach us using the details below. We aim to respond within reasonable timeframes and as required by applicable law.
Email: privacy@pedivo.com
Website: www.pedivo.com
If you are located in Nigeria, you may also lodge a complaint with the Nigeria Data Protection Commission (NDPC). If you are located in the EU/UK, you may contact your local supervisory authority.