STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/STAGING/
d94a9f1 · localhost
Privacy Center

Your data,
in plain English.

Rowbot is built for clubs, and clubs own their members' data. We just run the platform. We don't sell your data, and we don't train AI on it. This page explains how it all works - and what you can control.

Last updated: April 2026

The 60-second version
  • Your club owns most of your data. Your membership, attendance, lineups, coaching notes - that's all controlled by your club, the same way it would be in a paper file or spreadsheet.
  • Rowbot only controls your login. Your email, password, and account profile - the bits you need to sign in to any club you belong to.
  • Sensitive stuff is opt-in, always. Heart rate, fitness data, AI features, photo tagging - none of it happens unless you switch it on, and you can switch it off any time.
  • Hosted in London, encrypted everywhere. Your data sits on AWS servers in the UK, encrypted in transit and at rest. We never sell it. Nothing is used to train AI models.

Who's in charge of what

Different bits of your data are controlled by different people. Here's the split.

Your club controls

Your club is the data controller for everything stored about you in Rowbot for club purposes.

  • • Contact details and emergency contacts
  • • Membership type, dates, status
  • • Squad and group assignments
  • • Attendance and availability
  • • Lineups and crew selections
  • • Coaching notes and certifications
  • • Equipment allocations
  • • Invoices and payment status
Got a question about how your club uses this data? Ask your club directly - they set the rules.

Rowbot controls

We're only the data controller for the bits that make your account work across clubs.

  • • Your email address
  • • Your password / login tokens
  • • Your name and profile photo
  • • Login security alerts
  • • Technical logs (errors, IP for security)
Questions about your account or platform-level data? privacy@rowbot.app

You control (opt-in)

Sensitive features are off by default. They only turn on when you say so, and you can switch them off again any time.

  • • Connecting Strava, Concept2 or Apple Health
  • • Sharing health and activity data with coaches
  • • Photo tagging / facial recognition
  • • AI-powered training recommendations
Manage these in Settings → Privacy inside the app.

A note on the legal terms. Where we say "your club controls" we mean your club is the data controller under UK GDPR - they decide what gets entered and why. We're the processor: we run the platform and follow their instructions. Even for opt-in things like health data and AI, your club is still the controller - the difference is the law requires an extra layer of your consent because the data is more sensitive. So you get a personal switch.

The sensitive stuff is yours to switch on

These features all start off. They only process your data once you opt in, and you can opt out at any time from your account settings.

Health & fitness data

If you connect Strava, Concept2, or Apple Health - or log workouts manually - Rowbot can show your training data alongside the rest of your club life.

Default: Private. Not connected.

Who sees it: Only you and the coaches your club gives access to - and only after you opt in.

Turn it off: Disconnect the integration in Settings. Sync stops immediately. You can request deletion of previously synced data.

AI features

Some clubs enable AI for things like training suggestions, reporting, and natural language queries. AI runs on data you've already shared with your club.

Default: Off, club-wide. Your club has to enable it.

Where it runs: AWS Bedrock in London. Anthropic (Claude) is the model provider but never receives your data directly.

Training: Your data is never used to train AI models - not by us, not by AWS, not by Anthropic.

Photo tagging

Optional facial recognition that automatically tags members in club photos. Uses AWS Rekognition, hosted in London.

Default: Off. Your club must enable it, and you must give explicit consent for your face.

Withdraw consent: Anywhere, any time. Your facial recognition data is deleted immediately and existing tags are removed.

Wrong tag? You can correct or remove any tag yourself.

How we keep your data safe

Security isn't a feature, it's the default. Here's what that looks like in practice.

Encrypted everywhere

TLS in transit, encryption at rest. Your data is never moved or stored in the clear.

Hosted in London

All your data lives on AWS in eu-west-2 (London, UK). AI runs in the same region.

Tenant isolation

Each club's data is logically separated. One club can never see another club's data.

Role-based access

Inside a club, your data is only visible to people with the right permissions - set by your club, not us.

We're the data processor for your club, which means we have a contract (a Data Processing Agreement) that legally requires us to do all of this. We also notify clubs of any data breach within 72 hours.

Where your data lives

We don't run our own servers - we use a small set of trusted services to keep things reliable. Here's the full list of who touches your data and where.

ServiceWhat it doesLocation
AWSHosting, database, file storageLondon, UK
PostmarkSending login & notification emailsUnited States
StripeCard paymentsUnited States
GoCardlessDirect debit paymentsUnited Kingdom
AWS BedrockAI onlyRuns Claude (Anthropic) for AI featuresLondon, UK
AWS RekognitionPhoto tagging onlyFacial recognitionLondon, UK

Where data is transferred outside the UK (Postmark, Stripe), we use the legal safeguards required by UK GDPR - Standard Contractual Clauses or adequacy decisions. The full list is in our Data Processing Agreement.

Your rights, in one list

Under UK GDPR you have a set of rights over your personal data. Here's how to actually use them.

See what we hold about you

Request a copy of your account data.

Email privacy@rowbot.app

See what your club holds

Your club is the controller for club data, so they handle the request - we'll help them.

Talk to your club admin

Correct anything inaccurate

Update your profile in your account, or ask your club to fix club data.

Open Settings

Delete your account

We delete your account data within 30 days. Club data is handled by your club.

Settings → Account

Withdraw consent

For health sync, AI, or photo tagging - turn it off any time. Effects are immediate.

Settings → Privacy

Export your data

Get a structured copy of your data so you can take it elsewhere.

Email privacy@rowbot.app

Common questions

Can my coach see my heart rate?+
Only if you've connected a fitness service like Strava, Concept2 or Apple Health and your club's permission settings give your coach access. Health data is private by default. If in doubt, ask your club who has access - they decide, not us.
What happens to my data if I leave my club?+
Your access to that club's data ends. The club itself decides whether to keep your historical record (e.g. for past membership) or delete it - they're the controller. Your Rowbot account stays active for any other clubs you belong to, and you can delete it any time.
What happens if my club leaves Rowbot?+
The club can export their data, then we delete it within 30 days of their departure. Individual members can also request deletion at any point.
Is my data used to train AI?+
No. Not by us, not by AWS, not by Anthropic. We use AWS Bedrock with model providers contractually barred from training on your data. AI features only run when your club enables them.
Does Rowbot read my private messages or photos?+
We don't look at your data except to keep the platform running, respond to a specific support request from you or your club, comply with the law, or investigate a clear breach of our terms. We don't mine your content for any other purpose.
I'm under 16 - can I use Rowbot?+
Rowbot isn't intended for under-16s without parental consent. If your club registers junior members, they're responsible for getting that consent.
Where do I complain if something goes wrong?+
Tell us first - privacy@rowbot.app. We'd like the chance to fix it. You also have the right to complain directly to the UK's Information Commissioner's Office at ico.org.uk.

The full policies

The plain-English version above is a summary. The legal documents below are what actually binds us, your club, and you.

Still have questions? Email us at privacy@rowbot.app. If your question is about how your specific club uses your data, your club is the best first stop.

Rowbot is operated by Experiential Technologies Ltd, registered in England and Wales (Company No. 12585767).