Last updated: August 2026 · Version 2026-08-c
This Privacy Policy explains how Ryse Athletic Club (“Ryse,” “we,” “us”) handles personal information when you visit our website, sign up for a membership or day pass, use our member portal, or use the Ryse mobile app. We have written it to describe what our systems actually do. If you find something here that does not match your experience, please tell us so we can correct it.
1. Information we collect
What we hold depends on how you interact with us.
Everyone who joins
- ▸Contact and account details: name, email, phone, and date of birth. Home address is optional and used for billing records.
- ▸Emergency contact: a name and phone number you give us so we can reach someone if you are hurt at the gym.
- ▸For members under 18: a parent or guardian's name, email, and phone.
- ▸Membership records: your tier, sign-up date, waiver, visit history, and door-access activity.
- ▸Consent records: whether you agreed to marketing email or texts, exactly what you agreed to, and the date, time, and IP address when you agreed. We keep these to prove we had your permission.
Identity checks at the front desk
When you first come in, our staff look at your physical government ID to confirm you are who you say you are. We do not photograph, scan, copy, or store your ID.We record only which type of ID was checked (for example, driver's license), who checked it, and when.
Your profile photo
Our staff take a photo of you at the front desk and store it on your account. Its only purpose is so staff can confirm that the person coming in matches the membership. It is an ordinary photograph. We do not run facial recognition on it, and we do not create or store a faceprint, face template, or scan of your facial geometry. Nothing in our system identifies you automatically from your face.
Payment information
Membership payments are handled by ABC Fitness, our billing provider. Card details are entered on their secure payment page, not ours. We never see or store your full card number. From their records we keep a payment history that includes the amount, date, card brand, and the last four digits.
Health and fitness information (mobile app and training services)
This is the most sensitive information we hold, so we want to be specific about it. If you use the Ryse mobile app or buy training services, we may collect:
- ▸Workout data you log: exercises, sets, weights, and session history.
- ▸Health metrics from a wearable or phone, only if you connect one and grant permission. For example steps, resting heart rate, heart-rate variability, blood-oxygen level, respiratory rate, sleep, and estimated VO2 max.
- ▸Body-composition results, if you book a body scan. For example weight, body-fat percentage, lean mass, and body measurements.
- ▸Nutrition and food logging, if you use those features.
- ▸Notes and goals recorded by a personal trainer you work with.
You control this. Connecting a wearable is optional and you can disconnect it at any time in your device settings. We do not sell health data, share it with advertisers, or use it to make decisions about your membership or pricing. We do not currently use member health data for research or share it with researchers.
What you post in the mobile app
If you post in the app, we store what you post: photos, videos, captions, comments, and direct messages, along with who posted them and when. Who can see a post depends on where you posted it and on your privacy settings; accounts belonging to members under 18 are private by default. Direct messages are stored so they can be delivered and shown to you and the person you sent them to, and so we can act on a report.
Reports you make about other members, and reports made about you, are stored and read by staff. We never tell the person reported who reported them.
Automated checking of photos
Photos posted to the app are checked by an automated safety classifier before other members can see them. This check looks for prohibited content, not people: it performs no facial recognition, creates and stores no scan of face geometry or other biometric identifier, and cannot identify anyone. Images are processed transiently for this purpose and are not used to train AI models. The classifier is Google's Gemini API; the only thing kept is a text verdict about the photo. See Section 3 for our position under Illinois' biometric privacy law.
Location and other metadata in what you upload
Photos taken on a phone can carry hidden metadata, including the GPS coordinates of where they were taken.
- ▸Photos: we remove location and other metadata on our servers AFTER the photo is uploaded, not on your phone. For JPEG and PNG photos this works and the stored copy carries no location. For HEIC photos — the default format an iPhone camera produces — we do NOT currently remove it, so a HEIC photo you post may still contain the location it was taken at. We are telling you this plainly rather than implying otherwise; if that matters to you, turn off location tagging for your camera in your phone's settings, or set your camera to save photos as JPEG.
- ▸Videos: we do NOT currently remove metadata from videos. A video you post may still contain the location it was filmed at. We are telling you this plainly rather than implying otherwise; if that matters to you, turn off location tagging for your camera in your phone's settings before filming.
Push notifications
If you allow notifications, we store a push token for your device so we can send them. It identifies the device, not you personally, and it is deleted when you sign out.
Information we deliberately do not hold
The app's protocol tracker — where a member can record TRT or other prescribed compounds — never leaves your phone. It is stored in your device's secure keychain, it is excluded from device backups, it is never sent to us, and it is never sent to any AI model. We hold no copy of it, which means there is no copy of it to lose.
Website usage
Basic analytics such as pages visited, approximate device and browser type, and how you arrived at the site. This runs only if you accept analyticsin the banner shown on your first visit. If you choose “Essential Only,” no analytics or session recording loads at all. The signed-in areas (the member portal, staff admin, and trainer portal) are never recorded, whatever you chose.
Information about other people
Some information we hold is about people who never signed up themselves: the emergency contact you name, a parent or guardian for a member under 18, and guests you sign in. We use it only for the purpose you gave it to us for. If you are one of those people and want to know what we hold, contact us and we will tell you.
2. How we use your information
- ▸Create and manage your membership, day passes, and account.
- ▸Confirm your identity at the desk and provision your door access.
- ▸Process payments and billing through ABC Fitness.
- ▸Send you messages about your account: billing and past-due notices, receipts, password resets, and security alerts. These are part of having a membership and are not marketing.
- ▸Send you promotional email or texts, only if you opted in. You can opt out at any time and it takes effect everywhere.
- ▸Show you your own workout, health, and progress data in the app.
- ▸Keep the gym and our systems secure, investigate incidents, and meet legal, tax, and insurance obligations.
We do not sell your personal information, and we do not share it with third parties for their own advertising.
3. Biometric information
We do not collect biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act (740 ILCS 14).
Specifically: we do not take fingerprints or handprints, we do not scan faces, irises, retinas, or voices, and we do not create or store any faceprint, template, or mathematical representation derived from your face or body. Door access uses a mobile credential or key card, not your body. The profile photo described in Section 1 is a photograph, which that statute expressly excludes from the definition of a biometric identifier, and we run no recognition on it.
If that ever changes, we will obtain your written consent before collecting anything biometric, publish our retention and destruction schedule, and update this Policy first.
4. How we share information
We share personal information only with providers that help us run the gym, only as needed, and only for the purposes described here:
- ▸ABC Fitness: membership billing, payments, and member records.
- ▸Openpath / Avigilon Alta: door access control. Receives your name, email, phone, and door-entry activity.
- ▸Supabase and Vercel: database, file storage, authentication, and website hosting.
- ▸Resend: sending our email. Twilio: sending our text messages, if you opted into them.
- ▸PostHog: website analytics, only if you accepted analytics. Website only — the mobile app does not use PostHog.
- ▸Stripe: used only to pay our trainers. Member payments do not go through Stripe.
Providers used by the mobile app
- ▸Expo: app builds, over-the-air updates, and delivering push notifications.
- ▸Google (Gemini API): the automated photo safety check described in Section 1, and generating Ryse Coach responses.
- ▸OpenRouter: routing Ryse Coach requests. To answer usefully, the request includes health information about you — your first name, age, sex, height, current body weight and recent weight trend, along with what you have logged (food, workouts, and goals).
- ▸Sentry: crash and error reports. Receives a member ID so we can tell whether a crash hit one person or everyone. It does not receive your email address.
- ▸USDA FoodData Central and Open Food Facts: nutrition lookups. These receive the food being searched for and no personal information about you.
We may also disclose information if required by law or valid legal process, to protect the safety of members or staff, or in connection with a sale or transfer of the business.
5. How long we keep information
We keep your membership record for as long as you are a member and afterward as needed for billing, tax, insurance, and dispute purposes.
- ▸Door-entry history: 7 years, then automatically deleted. This runs on a schedule, not by hand.
- ▸Signed waivers: kept indefinitely. A waiver is our record of an agreement about physical injury, and it has to outlive the membership to be worth anything.
- ▸Text-message consent records: kept while you are on our list and for a period afterward, because if you ever ask whether we had permission to text you, we are the ones who must prove it.
- ▸Cancellation emails you send us: kept with your member record so we have an accurate history of your request.
- ▸Staff action logs: kept so we can investigate if something goes wrong with an account.
We keep less than we could. Holding personal data we no longer need only widens the group of people we would have to notify if we ever suffered a breach.
Your health and training history
We keep your health and training history for as long as your account is open, so you can look back over years of progress in full detail. You can delete any period of your health data whenever you like, from Settings, and deleting your account deletes all of it.
We want to be straight about the trade-off, because it is a deliberate choice and not an oversight. Nothing expires on a timer. There is no job that thins your old data into monthly averages and no automatic purge. A member who trains for ten years should be able to open the app and see exactly what their resting heart rate, sleep and HRV were on a given day in year one, next to the workout they did. Averaging that away, or deleting it, would be a decision made foryou about your own body. The cost of that choice is that we hold day-by-day health data indefinitely, which is more to lose in a breach — so the controls above are real ones you can use at any time, not a formality.
Deleting a post, and deleting your app account
- ▸Deleting a post removes both the post and its photo from our systems, not just the entry in your feed.
- ▸Deleting your app account removes your stored photos and profile pictures as well as your account records.
- ▸Deleting your app account does not cancel your gym membership and does not stop your dues. Membership billing is handled by ABC Fitness and has to be changed separately — talk to us at the desk.
Deletion from our live systems happens when you ask for it. Encrypted backup copies persist for a short period afterwards before they age out of our backup cycle. While they exist they are not used for anything, are not searchable, and are only ever restored in a disaster. We would rather describe this accurately than tell you deletion is instant and permanent everywhere, which for any service that keeps backups is not true.
A few things are deliberately kept when an app account is deleted:
- ▸Reports other members filed about you. A complaint should not be erasable by deleting the account it is about.
- ▸Food items you contributed to the shared database, because other members' logs reference them. Your name is removed from them.
- ▸A dated record that the account was deleted, so we can answer questions about it later.
6. How we protect information
- ▸Data is encrypted in transit, and our database and file storage are encrypted at rest by our infrastructure providers.
- ▸Access to member records requires a staff account with a specific permission, and staff actions on member records are logged.
- ▸Financial information is restricted to the owner.
- ▸Staff accounts that reach the admin panel require a second authentication step.
- ▸Uploaded files are stored in private, non-public storage.
No system is perfectly secure. If a breach affecting your personal information occurs, we will notify you and the appropriate authorities as required by Illinois law (815 ILCS 530), without unreasonable delay.
7. Your choices and rights
- ▸Marketing email: opt out with the unsubscribe link in any promotional email. It applies across our whole system, not just the one list.
- ▸Marketing texts: reply STOP to any marketing text. Reply HELP for help. Message and data rates may apply.
- ▸Account and service messages: these continue while your account is open, because they are part of the membership. They stop when you close your account.
- ▸Analytics: choose "Essential Only" in the cookie banner, or clear it in your browser to be asked again. Enabling Do Not Track in your browser also prevents analytics.
- ▸See your data: members can download a copy of their information from the member portal, under Account. It downloads immediately, you don't have to ask us.
- ▸Export from the app: you can export your app data from inside the app. It is generated on the spot and handed to your phone's share sheet — we do not store a copy of it and there is no link that could be found by anyone else.
- ▸Delete your app account: you can do this from inside the app, without asking us. See Section 5 for exactly what that removes and what it does not.
- ▸Correct your data: update your details in the member portal, or ask the front desk.
- ▸Connected health apps: disconnect a wearable at any time in your device settings.
- ▸Ask us to delete your information: see below for how this works.
How to make a privacy request
Send your request through our contact page or ask at the front desk, and say what you want: a copy of your information, a correction, or deletion. Requests go to the owner of Ryse Athletic Club, who reviews each one personally.
We will respond within 30 days. Most requests are answered much sooner. We may need to confirm your identity first, so that nobody else can request your information or have it deleted.
If you ask us to delete your information, we will tell you clearly what we deleted and what we kept. Some records we cannot delete on request:
- ▸Your signed waiver, which is our record of an agreement about physical injury and has to outlive the membership to mean anything.
- ▸Billing and payment records we are required to keep for tax and accounting purposes.
- ▸Records we need to keep for an open dispute, insurance claim, or legal obligation.
- ▸Proof that you agreed to receive texts, for as long as you are on that list. If you ever ask whether we had your permission, we are the ones who have to prove it.
If your membership is billed through ABC Fitness, closing your account with us does not by itself end that billing agreement. Talk to us at the desk and we will walk you through it.
8. Children and members under 18
Memberships: you must be 18 or older to sign up for a membership online. Memberships for minors are set up in person, with a parent or guardian providing their information and agreeing to the waiver and Terms.
The mobile app: you must be 16 or older to create an app account, and you must give a valid date of birth. Accounts belonging to members under 18 are private by default: their posts are not public, only accepted friends can message them, and they do not appear in member search. The system enforces this itself rather than relying on a setting being chosen correctly.
We do not knowingly collect information from children under 13.
9. Where your information is handled
Ryse operates in Illinois and our members are primarily Illinois residents, so Illinois law governs how we handle your information. Our website and database are hosted in the United States by providers whose facilities may be located in other states.
10. Changes to this Policy
We may update this Policy. When we make a material change we will update the version and date at the top of this page, and ask members to review and accept the updated Policy the next time they sign in to the member portal. We keep a record of which version you accepted and when.
11. Contact us
Ryse Athletic Club · 5328 Grand Avenue, Gurnee, IL 60031. For any question about this Policy, to see or correct your information, or to make a privacy request, reach us through our contact page or at the front desk. We answer privacy requests as quickly as we can.
This Policy describes our practices and is provided for general information. It is not legal advice.
