Privacy Policy
Last updated: 2026-07-17
In plain English: your account, your fights and your API usage live on our own servers in Germany. Your provider API keys are encrypted with a vault password only you know, which means we can't read them and nobody can recover them if you forget it, not even us. Prompts go to whichever AI provider runs the model you picked, and by default that inference happens in the US. We don't sell your data. We don't train models on it.
This policy describes how Fight Club (fightclub.pro), and the connected Knockout CLI and Ringside API products, collect and process personal data. We are the data controller for signed-up Fight Club and Knockout users. For the Ringside developer API, we are a data processor acting on behalf of the developer for their customers' data.
1. Data we collect
- Account: email, username, password hash (hashed with a strong one-way function), avatar URL, role, owner type.
- Vault: encrypted provider API keys (encrypted with a key derived from your vault password using strong primitives, we never store the vault password in plaintext and cannot recover it).
- Usage: fight transcripts, Knockout session messages, wallet transactions, cost attribution. For Ringside, we store full prompt and response content where you use Conversations or response caching, plus usage metadata for billing.
- Support: questions and answers from the in-app assistant, and the model responses. Approved answers may be added, after review, to a general help knowledge base served to other users. Messages that look like card numbers, national ID numbers, passwords or API keys are redacted before storage.
- Technical: IP address (rate limiting + fraud), user agent, request IDs, server logs.
- Payment: Stripe handles all card data; we store only the Stripe customer/payment method IDs. We never see your card number.
2. Why we process it
- Contract (GDPR Art. 6(1)(b)): to provide the platform you signed up for.
- Legitimate interest (Art. 6(1)(f)): fraud prevention, rate limiting, security audit logs, product analytics.
- Consent (Art. 6(1)(a)): marketing communications, cookies beyond strictly necessary.
- Legal obligation (Art. 6(1)(c)): tax records, law enforcement requests with valid court order.
3. Sub-processors
See our sub-processor list for all third parties that process data on our behalf.
4. Where data is stored, and where inference runs
Storage. Primary database and application servers are in Germany (Hetzner, Falkenstein). Encrypted off-site database backups go to OVH in France (EU); the backup is encrypted on our server before it leaves, so OVH holds ciphertext only.
Inference routing. Storage in Germany and inference in the US are separate things. By default, prompts you send to a platform-pool model are processed in the US: the call routes through providers including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq, Mistral, DeepSeek and xAI, per thesub-processor list. EU-region routing is available on Ringside via region suffixes (for example @eu) on providers that offer EU regions, such as AWS Bedrock and Google Vertex; a region suffix is a routing instruction, not a legal residency guarantee, and no suffix means no residency guarantee. All US transfers run under Standard Contractual Clauses.
When you use BYOK (bring-your-own-key) with Knockout, your prompts are forwarded to the LLM provider you chose using your own key, under your agreement with them.
5. Retention
- Active account data: retained for the lifetime of your account.
- Fight transcripts, Knockout sessions: retained for the lifetime of your account; deleted on account erasure.
- Ringside usage events: retained for the lifetime of your account, removed when the account is deleted.
- Webhook deliveries: 30 days. Client tokens: 7 days. API run records: 30 days.
- Admin action logs: 365 days. Operational logs (worker, crash and server request logs): retained for the lifetime of the account.
- Backups: 30 daily rolling, encrypted before they leave our servers.
- Deleted account data: removed or anonymised within 30 days of erasure request.
6. Your rights (EU / UK GDPR)
You have the right to:
- Access: Ringside developers can export their account data directly with
GET /v1/account/export(machine-readable JSONL). Fight Club and Knockout users: email privacy@fightclub.pro and we will provide an export within 30 days. A self-serve export in the app is in progress. - Rectification: update your profile in the app; for fields you can't edit, email privacy@fightclub.pro.
- Erasure: email privacy@fightclub.pro to delete your account and we will action it within 30 days. Billing records are retained in anonymised form for tax compliance.
- Portability: the Ringside export is JSONL; for Fight Club and Knockout, request a machine-readable copy at the email above.
- Object / restrict / withdraw consent: email privacy@fightclub.pro.
- Complain to a data protection authority (in the EU, your local DPA; in the UK, the ICO).
7. Security
Passwords are hashed with a strong one-way function and per-user salts. Provider API keys are encrypted with a key derived from your vault password using strong primitives; we cannot decrypt them without you. Session cookies are HttpOnly, Secure and SameSite=Lax, scoped to.fightclub.pro, and expire after 1 hour of inactivity. Contact us atprivacy@fightclub.pro for architecture details.
8. Cookies
See our Cookie Policy.
9. Children
Fight Club is for adults only. You must be 18 or older to register. We do not knowingly collect data from anyone under 18; if you believe a child has registered, email privacy@fightclub.pro and we will delete the account.
10. Breach notification
We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach affecting your rights, and notify you without undue delay where the breach is likely to result in high risk.
11. Contact
Data controller: Fight Club (operating fightclub.pro). Contact: privacy@fightclub.pro.