Your data, explained
Privacy policy
Effective date: September 12, 2026
Your rowing history stays on your device. Catch does not require a Catch account or upload your workout database to a Grayforge Labs account.
Connecting Concept2, making an Apple purchase, visiting this website or contacting support involves the services described below. We do not sell personal data or use your rowing history for advertising.
This policy covers the Catch iPhone app and its website, operated by Grayforge Labs (“we”, “us”). For privacy questions or requests, contact support@grayforgelabs.com.
1. Information handled by Catch
Rowing history and profile, stored locally
Catch stores the workouts you import or enter, along with the calculations it makes from them, in its on-device database. Depending on what your workout contains, this can include dates, distance, work and rest duration and distance, pace, power, stroke rate, calories, heart rate, drag factor, stroke counts and measured samples or splits.
It also stores profile information you choose to enter, such as age, weight and heart-rate settings; your app preferences and Insights layout; and voyage progress, discoveries, personal bests and purchase-unlock status. This information is used to display your history, personalise calculations, compare workouts and advance your voyages. Catch’s rowing analysis runs on your device.
Optional Concept2 connection
When you choose to connect your Concept2 Logbook, you sign in on Concept2’s authorisation page. Catch requests read access to your Concept2 user information and workout results. Your Concept2 password is entered with Concept2, not in a Catch form.
Catch uses a Grayforge Labs service hosted on Cloudflare to exchange an authorisation code for access and refresh tokens, and to refresh those tokens when needed. The service receives the code or refresh token, processes it with Concept2 and returns the result to your device. Your network IP address is used for request rate limiting and security. The token-exchange application does not write tokens to an application database or intentionally log request bodies.
On your device, connection tokens are stored using iOS Keychain through secure storage. Catch requests your user information and rowing results directly from Concept2 over HTTPS, then stores imported workouts locally. This connection does not give Catch permission to edit or delete workouts in your Concept2 Logbook.
Purchases
Apple processes in-app purchases and restores. Catch receives product and transaction information needed to recognise the content you own and stores the unlock status locally. We do not receive your payment-card details. Apple retains purchase records under its own policies.
Support messages
If you email us, we receive your email address, your message and any attachments you choose to send. We use them to answer your request, troubleshoot problems and handle privacy requests. Avoid sending passwords, connection tokens or workout exports unless they are necessary to your request. Our email service processes messages on our behalf.
Website and service requests
When you visit this website or use the token-exchange service, hosting and network providers process technical information needed to deliver and secure the service. This can include an IP address, requested URL, time, browser or device information and response or error information. Infrastructure logs may be retained by those providers for operation, security and abuse prevention.
This website does not add advertising trackers, marketing analytics, external font requests or a newsletter form. The app does not include an advertising or third-party behavioural analytics SDK. Apple may separately provide developer diagnostics or aggregate App Store statistics according to your Apple settings and its privacy policy.
2. Connected services and sharing
- Concept2: provides optional account authorisation and Logbook data. Its privacy policy applies to the account and workouts you maintain with Concept2.
- Apple: provides purchases, restore functionality, native map services and device-level storage or backups. Voyage maps represent a virtual route, not your physical location. Catch does not request your GPS position to advance a voyage. See Apple’s privacy information.
- Hosting providers: the connection service runs on Cloudflare; the website uses OpenAI Sites and Cloudflare infrastructure. They process network requests and technical information to host and protect the services. See Cloudflare’s privacy policy and OpenAI’s privacy policy.
- Recipients you choose: CSV exports and files are generated on your device. They leave Catch when you choose a destination using the system share sheet. The destination service’s privacy practices then apply.
We use service providers only for the functions described here and require providers processing personal information on our behalf to protect it consistently with this policy and applicable requirements. Independently operated services, such as your Concept2 or Apple account, are also governed by their own policies. We may disclose information we actually hold where required by law, to protect rights and safety, or in a business transfer subject to appropriate privacy protections. We do not provide rowing history to advertising networks, data brokers or external AI services.
3. Retention and deletion
- Local app data: workouts, profile information and progress remain on your device until removed. Deleting the app removes its ordinary local app data; offloading the app keeps that data. Device backups may retain copies under your Apple settings.
- Connection tokens: use Disconnect Concept2 before deleting the app to remove the tokens held in Catch’s secure storage. iOS Keychain items can survive app deletion, so uninstalling alone should not be relied on to disconnect the account.
- Token exchange: credentials are processed to complete the exchange, without an application database of user tokens. Hosting security logs and rate-limit information are handled separately under the provider’s operational retention practices.
- Support correspondence: we retain messages as needed to resolve requests, maintain relevant support records and meet legal obligations. You can ask us to delete correspondence we no longer need to retain.
- Third-party records and copies: Concept2 workouts, Apple transactions, device backups and exports saved elsewhere have separate retention controls. Deleting Catch does not delete those copies.
4. Your choices and controls
- Use Catch without connecting an account. Concept2 is optional. You can add rows manually.
- Disconnect Concept2. Go to Profile → Settings → Concept2 logbook → Disconnect Concept2. This deletes Catch’s locally stored connection tokens and stops further imports until you reconnect. Previously imported rows remain in Catch. You can also manage or revoke Catch’s access through Concept2; contact Concept2 if you need help with its account controls.
- Export your history. Go to Profile → Settings → Export all rows. You decide where the CSV is saved or shared.
- Remove local data. Disconnect Concept2, export anything you want to keep, then delete Catch through iOS. Choose Delete App, not Offload App. Manage any backups in your device or iCloud settings and delete exports separately.
- Request help with information we hold. Email support@grayforgelabs.com. We cannot remotely read, retrieve or erase the workout database on your device.
There is no separate Catch account to close. Deleting your Concept2 or Apple account is handled by the respective provider. Disconnecting or deleting the app does not cancel, refund or erase an Apple purchase record.
5. Privacy rights and international processing
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of personal information we hold, restrict or object to certain processing, withdraw consent, and complain to your local privacy regulator. Contact us to exercise these rights. We may need enough information to verify your request, and legal obligations may limit deletion of some records. Withdrawing consent does not affect processing that was lawful before withdrawal.
Where applicable, we process information to provide the features you request, with your consent for optional connections, for legitimate interests in responding to support and securing our services, and to meet legal obligations. Our providers may process information outside your province or country, including in Canada, the United States and other locations where they operate, subject to applicable safeguards. Information stored only on your device is not made available to us simply because you use Catch.
6. Security
Catch uses HTTPS for its connections and iOS secure storage for Concept2 tokens. The token-exchange service keeps the Concept2 client secret out of the app and limits requests. Keep your device protected and up to date. No system can guarantee absolute security, and files you export are subject to the protections of wherever you save them.
7. Children
Catch is designed for a general recreational-rowing audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13 through support or other services we operate. If you believe a child has provided personal information to us, contact us so we can investigate and delete it where appropriate.
8. Changes and contact
We will update this page and its effective date when our practices change. Material changes that need notice or consent will be communicated as required before they take effect.
Grayforge Labs
Catch privacy and support: support@grayforgelabs.com