MEM Academy
AI Tools

Home · Privacy

Privacy Policy

Last updated: 10 August 2026

1. Who we are

MEM Academy CIC ("MEM", "we", "us") is a Community Interest Company registered in England and Wales (Company No. 09702792). We are the data controller for personal data collected through this platform.

Contact: hello@memacademy.org.uk

This policy covers the MEM Academy website and the MEM mobile app (iOS and Android), including Train, Running Club, Nutrition, Mind Room, Be-Creative and MEM-Connect.

2. What data we collect

  • Account data: email address, name, role (member/coach/employer/gym partner/staff), authentication metadata, and any additional profiles you create.
  • Profile and social content: display name, handle, bio, avatar, and the posts, reels, comments, likes, follows and direct messages you create in MEM-Connect.
  • Training data: workouts logged, sets, reps, weights, streaks, XP, badges and programme progress.
  • Location data: precise GPS while a run or walk is being tracked, and approximate location when you ask us to show nearby parks, gyms or food places. Collected only with your device permission, only while those features are in use.
  • Health and fitness data: distance, pace, splits, heart rate, calories, weight and similar metrics you enter or sync from Apple Health, Google Health Connect, Garmin or a connected watch. This is special-category data and we treat it accordingly.
  • Nutrition data: meals and macros you log, food photos, and dietary preferences.
  • Camera, photos and microphone: only accessed when you record or upload media, or use voice input. Nothing is captured in the background.
  • AI prompts and outputs: what you send to the MEM advisor and the Be-Creative tools, plus the content generated back.
  • Purchases: subscription status and transaction metadata. We never see or store full card numbers.
  • Self-referrals (/get-started) and third-party referrals (/refer): name, contact details, situation, pathway interest and any context shared.
  • Outcome surveys: voluntary wellbeing (ONS4) and physical activity (IPAQ) responses for impact reporting.
  • Technical data: device and app version, session identifiers, crash and error logs, and push notification tokens if you enable notifications.

We do not track you across other companies' apps or websites, and we do not use your data for third-party advertising.

3. Lawful basis

We process personal data under one or more of: (a) consent (referral forms, marketing, analytics cookies, location access, health data syncing); (b) legitimate interests (running the platform, moderation and safety, fraud prevention, product improvement); (c) contract (subscriptions, gym partners, employers); (d) legal obligation (safeguarding, financial records). Health and fitness data is special-category data and is processed on the basis of your explicit consent, which you can withdraw at any time by disconnecting the source or deleting the data.

4. How we use your data

  • To run your training, running, nutrition and mind-room experience, and to personalise plans and recommendations.
  • To record activities, award XP, streaks, personal bests and Park Passport stamps.
  • To show nearby parks, gyms and food places when you ask for them.
  • To publish and deliver the content you post to the audience you chose, and to power follows, comments and messages.
  • To keep the community safe: moderation, reports, blocks and enforcement.
  • To provide AI features you invoke, and to send push notifications you have opted into.
  • To take payment and manage subscriptions.
  • To match you to the right MEM pathway and follow up.
  • To produce anonymised, aggregated impact reports for funders and the public.
  • To meet safeguarding and governance obligations.

5. Who we share data with

We never sell personal data. We share only with:

  • Sub-processors that host the platform, store media, send transactional email and push notifications, process payments (Stripe; Apple for in-app purchases), provide maps and place data, and provide the AI models behind our assistant and creative tools — all under written data-processing agreements.
  • Your coach or organisation, where you have joined their programme, so they can see the training data relevant to your coaching.
  • Other users, for anything you choose to publish in MEM-Connect.
  • Partner organisations (HMPPS, probation, gyms, employers) only where you have consented or there is a lawful basis.
  • Authorities, where required by law or to protect a vulnerable person.

Health, fitness and location data is never shared for advertising or sold to data brokers. Some sub-processors are outside the UK; where that happens we rely on UK adequacy regulations or the UK International Data Transfer Addendum to standard contractual clauses.

6. Your device permissions

The app only asks for a permission at the point you use the feature that needs it, and every one is optional — the rest of the app keeps working without it. You can change or revoke any of them in your device settings at any time.

  • Location: GPS tracking for runs and walks, Park Passport stamps, and nearby discovery.
  • Camera and photos: recording or uploading media for posts, reels and food logs.
  • Microphone: voice notes and voice input.
  • Health data: reading activity and workout data from Apple Health or Health Connect, and writing your MEM workouts back if you allow it.
  • Notifications: training reminders, streaks and social activity.

7. Data retention

We keep different categories of data for different periods, based on legal, funder and safeguarding obligations:

  • Account data (name, email, role, profile details): kept while your account is active and for up to 24 months after closure, then deleted or anonymised.
  • Payment records (invoices, transaction metadata; no card numbers are stored by us): kept for 6 years to meet UK tax and accounting requirements.
  • Training, activity and health data (workouts, runs, routes, splits, synced health metrics, nutrition logs): kept while your account is active so you keep your history, and deleted or anonymised when your account is deleted. You can delete an individual activity, route or log at any time.
  • Social content (posts, reels, comments, messages): kept until you delete it or your account is closed, except copies retained for moderation, safeguarding or legal reasons for up to 12 months.
  • AI prompts and generated output: kept for up to 30 days for abuse prevention and support, unless saved into one of your projects.
  • Safeguarding and community delivery records (session attendance, referrals, incident notes): kept for up to 6 years to meet funder, audit and safeguarding obligations, then deleted or anonymised.
  • Analytics and cookies: only loaded after you give consent. Aggregated analytics are retained for up to 26 months; cookie consent choices for up to 12 months.

Where we no longer need identifiable data, we either delete it or irreversibly anonymise it so it can no longer be linked to you.

Account deletion requests

You can request deletion of your account at any time from Account & Data. Requests enter a 30-day cooling-off period during which you can cancel from the same page. After 30 days your account is closed and personal data is deleted or anonymised, except records we are legally required to retain (e.g. payment and safeguarding records, as above).

8. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict or port your data, and to object to processing or withdraw consent. To exercise any right, email hello@memacademy.org.uk. You can also complain to the Information Commissioner's Office (ico.org.uk).

9. Security

Data is encrypted in transit and at rest. Access is restricted by role-based controls. We are working towards Cyber Essentials Plus certification.

10. Changes

We will update this page when our practices change and revise the "Last updated" date above.