Privacy Policy
Last updated: 22 August 2026 Version: 3
Welcome to Orusta. This Privacy Policy explains how Challenge Arena Software FZCO ("we", "our", "Orusta") collects, uses, shares and protects your personal data when you use our mobile application and the related services (the "Services").
Orusta is a social fitness application. By its very nature, it processes information relating to your physical activity and your athletic performance. Some of this information is considered health data, that is, a special category benefiting from enhanced protection. We set out below exactly what we do with it, and the control you have over it.
We designed Orusta around a simple principle: nothing sensitive is collected without your explicit consent, and you can revisit each of your choices at any time from within the app.
1. Data controller and contacts
Challenge Arena Software FZCO Free zone limited liability company (FZCO), licence no. 80218 issued by the Dubai Integrated Economic Zones Authority (DIEZA) IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates
- Questions relating to your data: privacy@orusta.com
- Legal enquiries: legal@orusta.com
Representative in the European Union (Art. 27 GDPR). As Orusta offers its Services to residents of the European Economic Area, a representative established in the Union is designated as the point of contact for supervisory authorities and data subjects:
Steeve Langlet, France Contact: legal@orusta.com
2. Scope
This policy applies to the Orusta mobile application, to its features (video challenges, prize-bearing challenges, live battles, workouts and routines, messaging, clubs, sports meet-ups, shop and subscriptions) and to the associated websites and web pages. It does not apply to third-party services that the application may link to and that have their own policies.
Some features described here are not yet open in every version of the application. A feature that is absent from your version gives rise to no processing at all: this policy describes what we do when you use it, never in anticipation.
3. Categories of data we collect
3.1 Account and profile data
Email address, Google ID (where you sign in with Google), username, profile picture; date of birth, gender, height, weight, sports practised, training level, goals. Some of this information is optional.
3.2 Health and athletic performance data
Repetitions counted, duration and intensity of sessions, progress, personal records, leaderboards and ranks. This data is treated as health data (see section 5).
3.3 Motion data (skeletal points)
In order to count your repetitions, the application analyses your posture in real time on your device. This analysis produces skeletal points (motion coordinates, known as "keypoints"). By default, this processing remains local to your phone and is not transmitted. It is captured and sent to our servers only if you expressly consent (the "Detection Improvement" purpose, see section 4).
3.4 User-generated content
Challenge videos, messages exchanged in chats, battles and clubs, meet-up posts, votes, customisation content (avatar, cosmetics).
3.5 Location data
Approximate city only, never precise coordinates on a continuous basis, and only when you voluntarily use the sports meet-up feature.
3.6 Payment and subscription data
Purchase history, status of the Orusta VIP subscription and of the VIP Pass, virtual currency transactions and balances (Tickets, Coins, Carats). We neither receive nor store your bank card numbers: payments are processed by Apple, Google and our subscription provider (see section 9).
3.7 Technical and usage data
Device identifier, device model, application version, operating system, language, IP address, and usage logs and technical detection quality logs. The IP address is used to derive an approximate country and is then not retained in our analytics data.
3.8 Health data from Apple Health (iOS)
With your permission, Orusta reads the workouts recorded in Apple Health (swimming, running, fitness, etc.) in order to automatically validate certain sessions without you having to film them, and can write back your Orusta sessions to Apple Health so as to centralise your sports history. These exchanges involve health data (section 5). Access is managed by Apple: nothing is read or written without your permission, which you can revoke at any time in your iOS settings.
3.9 Notifications
If you enable them, we send you push notifications (activity, challenges, social and, if you consent to this, promotions). A notification token is processed by the delivery service in order to deliver them to you.
3.10 Entry into a prize-bearing challenge
When you enter a challenge rewarded with a real prize, we process your account identifier, your performance and the video submitted, in order to run the challenge and determine the winner. Only if you win, we additionally process the details needed to deliver the prize (identity and delivery address), passed to the partner providing the prize and to the carrier for that sole purpose. The details are set out in the Contest Rules.
We collect no advertising tracking data and integrate no intrusive third-party advertising or analytics SDK (Firebase Analytics, Meta SDK, Mixpanel, etc.). Our telemetry is first-party (our own servers). We use no crash reporting tool (no Sentry, no Crashlytics, no equivalent), and therefore collect no crash data.
4. Purposes, legal bases, consent and retention periods
We tie each processing operation to a specific purpose and legal basis. The purposes marked "consent" are switched off by default and are activated only by your explicit choice, which can be withdrawn at any time in Profile > Data & Privacy.
| # | Purpose | What it covers | Legal basis | Default |
|---|---|---|---|---|
| 1 | Essential | Account, challenges, scores, leaderboards, messaging, moderation, anti-cheat and integrity | Performance of the contract (Art. 6.1.b); legitimate interest for anti-cheat | Always on |
| 2 | Product Analytics | Usage measurement and technical detection quality, without body data; pseudonymised | Legitimate interest (Art. 6.1.f), with a right to object | On (opt-out) |
| 3 | Performance Statistics | Body-related statistics (repetitions, performance, progress); aggregate and retention analyses | Explicit consent (Art. 9.2.a) | Off |
| 4 | Personalisation | Adaptive difficulty based on your performance | Explicit consent | Off |
| 5 | Detection Improvement | Capture of skeletal points to improve the counting models | Explicit consent | Off |
| 6 | Data Sharing | Inclusion of individual data in datasets shared with partners | Explicit consent | Off |
| 7 | Marketing Communications | Promotional notifications and messages | Consent | Off |
Withdrawal of consent. Withdrawing is as easy as giving consent, with no consequence for your access to essential features. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out beforehand. The effects for each purpose (collection stops, exclusion from future datasets, retroactive deletion for the capture of motion points) are set out in section 13.
Retention periods. See section 10.
5. Health data and special categories (Art. 9 GDPR)
Your athletic performance data, your body measurements and your motion points fall within the special categories of data within the meaning of Article 9 of the GDPR. Their processing relies on your explicit consent, given separately and specifically through the system described in section 4.
- This data is never used for monetisation purposes in respect of people under 18 (see section 14).
- It is pseudonymised in our analytics systems (see section 7).
- You can withdraw your consent at any time, which stops the corresponding collection.
The motion points analysed are not used to identify you: Orusta carries out no facial recognition and no biometric identification. This data serves solely to count and assess your athletic movements.
6. Monetisation, subscriptions and payments
Orusta offers three optional purchases: the Orusta VIP subscription, Carat packs, and activation of the VIP Pass. Carats are the only virtual currency sold for real money; Tickets and Coins are never sold and are earned by playing. The contractual detail is set out in our Terms of Service.
- Payments are processed by Apple (App Store), Google (Google Play) and our subscription management provider. From them we receive a transaction and subscription status, never your full payment card details.
- We retain the history of your purchases and of your virtual currency balances in order to provide the service, handle disputes and comply with our accounting obligations.
- The contractual terms of these purchases (renewal, cancellation, refunds, the absence of monetary value of virtual currencies) are set out in our Terms of Service.
7. Pseudonymisation (and what it is not)
Your analytics data is pseudonymised. Concretely: the events we record do not carry your account identifier but a separate random identifier, dedicated to analytics. That identifier is not derived from your account data, it is drawn at random, and the correspondence between the two is stored separately.
Pseudonymisation is not anonymisation, and we do not claim otherwise. Because we hold that correspondence table, re-association remains technically possible on our side. This data therefore remains personal data within the meaning of the GDPR, protected as such, and your rights (section 12) apply to it in full. It is also why we declare it as linked to your identity in the app stores' privacy forms: we prefer the accurate answer to the flattering one.
What pseudonymisation actually provides: someone with access to the analytics data alone could not trace it back to you, and our statistical processing runs without ever handling your identity.
When you delete your account, the correspondence is destroyed and the residual analytics data is purged or permanently dissociated, which makes re-association impossible, including for us. This data is used only for the purposes described in section 4.
8. Data sharing and anonymisation
We do not sell or rent your personal data. As of today, no data is shared with partners for commercial purposes.
The Data Sharing purpose, which is switched off by default and offered only in your settings, covers the possible inclusion of your data in datasets shared with partners. Until you switch it on, nothing is shared. Were such sharing to be put in place, it would concern only those people who have explicitly switched it on, never people under 18, and you would be informed in advance.
9. Recipients and processors
Your data is processed by providers that are strictly necessary for the operation of the service. We present them by category; the up-to-date list of our processors, by name, is available on request from privacy@orusta.com.
| Category of recipient | Role | Transfer outside the EU |
|---|---|---|
| Hosting and database | Secure storage of your data | No (European Union) |
| Media storage and delivery | Videos, images, cosmetics | Yes, global CDN network (SCC) |
| Real-time streaming | Audio/video for live battles | Yes (SCC) |
| Authentication | Optional sign-in (OAuth) | Yes (SCC) |
| Subscription management | In-app purchases and subscriptions | Yes (SCC) |
| Push notifications | Delivery of notifications | Yes (SCC) |
| Transactional email | Confirmations and sign-in links | Varies (SCC) |
| Technical monitoring | Availability and security logs | No (European Union) |
Payments are processed directly by Apple and Google through the app stores, which never pass your bank card data on to us.
We carry out no sale of identifying personal data to third parties (see section 8).
10. Retention periods
- Account and profile data: retained for as long as your account is active; deleted within 30 days of a deletion request.
- Content (videos, messages): retained until deleted by you or by moderation.
- Health and performance data (analytics): retained in pseudonymised form for 13 months, then deleted automatically.
- Motion points (where consented to): deleted retroactively if consent is withdrawn.
- Payment / billing data: retained for the period required by our accounting and legal obligations.
- Banned accounts: certain minimal technical identifiers may be retained after a ban, in order to enforce the sanction and prevent an account from being recreated (legitimate interest in the integrity of the service).
- Technical logs: retained for 14 days by our monitoring tool, then deleted automatically.
11. International data transfers
Challenge Arena Software FZCO is established in Dubai (United Arab Emirates). Some data may be processed in the UAE, the European Union and the United States.
The United Arab Emirates does not benefit from an adequacy decision of the European Commission. Transfers to the UAE therefore rely on appropriate safeguards within the meaning of Article 46 of the GDPR, namely the Commission's standard contractual clauses, supplemented by technical measures (encryption in transit, pseudonymisation of analytics data).
The same applies to our providers established outside the Union, except where they are covered by an adequacy decision (for example the United Kingdom or Switzerland, or the United States for organisations certified under the EU-US Data Privacy Framework).
You can obtain a copy of the safeguards put in place by writing to privacy@orusta.com.
12. Your rights
Under the GDPR (EEA residents) and the UAE personal data protection law (Federal Decree-Law no. 45 of 2021), you have the following rights:
- Access to your data;
- Rectification of inaccurate data;
- Erasure (the "right to be forgotten"), available directly in the app;
- Portability: export of your data from the app;
- Restriction of and objection to processing on legitimate grounds;
- Withdrawal of consent at any time for the processing that depends on it;
- Complaint to a supervisory authority (the UAE Data Office for the UAE; the CNIL in France; the competent authority of your country within the EEA).
To exercise these rights: privacy@orusta.com, or directly through the export and deletion features in the app.
We respond to your requests within one month (extendable for complex requests, with notice to you). We may need to verify your identity before acting on a request, in order to protect your account against fraudulent requests.
13. Consent: management and withdrawal
You manage your consents purpose by purpose in Profile > Data & Privacy. When you sign up, a single screen allows you to accept everything or to decline, without this conditioning your access to the app. Certain sensitive purposes are offered only at the relevant moment (for example when the feature concerned is used for the first time), never all bundled together at sign-up.
Effects of withdrawal, by purpose:
- Product Analytics / Performance Statistics: collection stops immediately; the data already collected remains lawful and is excluded from subsequent aggregate processing; erasure is possible on request.
- Personalisation: stops; adaptive difficulty reverts to the default settings.
- Detection Improvement: stops and the captured motion points are deleted retroactively.
- Data Sharing: stops, with exclusion from all future datasets.
- Marketing: promotional communications stop.
14. Minors
Orusta is restricted to people aged 16 or over. This floor is the maximum that Article 8 of the GDPR allows a Member State to set for consent to information society services. Since no EEA State goes beyond it, no parental consent is required for the accounts we accept, and we therefore do not collect any.
People under 18 are excluded from all monetisation purposes (Performance Statistics, Detection Improvement, Data Sharing), which is checked automatically from the date of birth and opens up at the age of majority.
We do not knowingly collect data concerning people under 16. Parents and guardians can write to us at privacy@orusta.com for any deletion.
15. Permissions on your device
Orusta requests certain permissions, only at the point where the corresponding feature needs them, and you can revoke them at any time in your phone's settings:
- Camera: filming your challenges, video feed for battles, and posture analysis to count your repetitions.
- Microphone: audio for live battles.
- Photos: choosing your profile picture and saving your videos.
- Approximate location (while using the app only): sports meet-up feature (city level).
- Apple Health (iOS): see section 3.8.
- Notifications: sending push notifications.
Declining a permission does not prevent you from using the rest of the app; only the feature concerned becomes unavailable.
16. Social visibility and live battles
Orusta is a social application. By design, certain information is visible to other users:
- Public profile: username, avatar, level, XP, ranks, badges.
- Content: your approved challenge videos, your votes, your meet-up posts (with the city).
- Leaderboards: your position and your performance may appear on them.
- Messaging and clubs: your messages are visible to their recipients. They are not end-to-end encrypted and may be reviewed by moderation if reported.
Live battles. During a battle, your camera and microphone feed is broadcast in real time to your opponent and, where applicable, to authorised spectators. This feed is not recorded permanently (only an explicit video submission is retained).
You stay in control: profile settings, blocking a user, reporting, and deleting your content at any time.
17. Automated decisions and the fight against cheating
Counting and detection. The application uses automated processing (posture analysis) to count your repetitions and assess the quality of execution. This processing produces a sporting result, with no legal effect.
Integrity and anti-cheat. In order to preserve fairness, we automatically detect cheating signals (replayed videos, simulated movements, inconsistencies). These signals may trigger a review, but significant sanctions (cancellation of scores, suspension, ban) are subject to human intervention: they are never issued by an algorithm alone.
Moderation. Content moderation is triggered by a report or by automatic detection. Any decision to remove content or to impose a sanction is taken by a human, never by an algorithm alone.
Your rights (Art. 22 GDPR). You can request human intervention, express your point of view and contest an automated decision or a moderation decision by writing to legal@orusta.com.
18. Security
We implement appropriate technical and organisational measures: encryption in transit (HTTPS/TLS), restricted and logged access, strong authentication, pseudonymisation of analytics data. As no system is infallible, we encourage you to protect your credentials.
In the event of a data breach likely to result in a risk to your rights and freedoms, we inform the competent supervisory authority and, where the risk is high, the data subjects, in accordance with Articles 33 and 34 of the GDPR.
19. Cookies and trackers
The mobile application uses no advertising cookies and no third-party trackers. The only technical identifiers used are necessary for its operation (session, security) or fall within the first-party audience measurement described in section 4.
20. Changes to this policy
We may amend this policy. In the event of a substantial change (new category of data, new purpose, new recipient, new transfer, amended retention period), we will inform you through the app or by email, before the new processing takes effect.
This information does not constitute a fresh acceptance on your part: this policy is an information document, not a contract. However, if a change were to introduce a new purpose relying on your consent, that consent would be requested from you separately and specifically, through your consent settings, and never presumed.
The date of the last update appears at the top of the document, and the version in force is always available in the app and at https://orusta.com/en/privacy.
21. Contact and complaints
- Personal data: privacy@orusta.com
- Legal enquiries: legal@orusta.com
- Representative in the European Union (Art. 27 GDPR): Steeve Langlet (France), legal@orusta.com
You can also lodge a complaint with the competent supervisory authority (see section 12).