Privacy Policy

Last updated: 2026-08-07

In plain English: your account, your fights and your API usage live on our own servers in Germany. Your provider API keys are encrypted with a vault password only you know, which means we can't read them and nobody can recover them if you forget it, not even us. Prompts go to whichever AI provider runs the model you picked, and by default that inference happens in the US. We don't sell your data. We don't train models on it.

This policy describes how Fight Club (fightclub.pro), and the connected Knockout CLI, Ringside API and Genie products, collect and process personal data. We are the data controller for signed-up Fight Club, Knockout and Genie users. For the Ringside developer API, we are a data processor acting on behalf of the developer for their customers' data.

The data controller is Saasplex Limited, trading as Stratus5, a company registered in Ireland under company number 452917, registered office 36 Abbotts Hill, Malahide, County Dublin, Ireland. Our supervisory authority is the Irish Data Protection Commission, and you have the right to lodge a complaint with them at dataprotection.ie.

1. Data we collect

2. Why we process it

3. Sub-processors

See our sub-processor list for all third parties that process data on our behalf.

4. Where data is stored, and where inference runs

Storage. Primary database and application servers are in Germany (Hetzner, Falkenstein). Encrypted off-site database backups go to OVH in France (EU); the backup is encrypted on our server before it leaves, so OVH holds ciphertext only.

Inference routing. Storage in Germany and inference in the US are separate things. By default, prompts you send to a platform-pool model are processed in the US: the call routes through providers including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq, Mistral, DeepSeek and xAI, per thesub-processor list. EU-region routing is available on Ringside via region suffixes (for example @eu) on providers that offer EU regions, such as AWS Bedrock and Google Vertex; a region suffix is a routing instruction, not a legal residency guarantee, and no suffix means no residency guarantee. All US transfers run under Standard Contractual Clauses.

When you use BYOK (bring-your-own-key) with Knockout, your prompts are forwarded to the LLM provider you chose using your own key, under your agreement with them.

4a. Criminal use, and what we give the police

Illegal activity on the platform is a matter for the police. Where we find that the service has been used to commit an offence, or somebody asks us to build something plainly criminal, we disclose the abuse record described in section 1 to the Garda Síochána or to whichever authority has jurisdiction. We also disclose where a valid court order, warrant or statutory request requires it.

Lawful basis. Logging and keeping the record is legitimate interest under Art. 6(1)(f), for detecting criminal use and protecting the people it targets (see Recital 50). Disclosing it is Art. 6(1)(f) for a report we make on our own initiative, and Art. 6(1)(c) where a court order or statute compels us. Where the record contains special-category data the additional condition is Art. 9(2)(f), establishment, exercise or defence of legal claims.

Retention. Abuse records are kept for 24 months from the date of the event, then deleted, except where they relate to an ongoing investigation or legal proceedings, in which case they are kept until it concludes. They survive deletion of the account for that period; the rest of the account is deleted as described below.

Notice. We do not normally tell the account holder before making a disclosure, because doing so would defeat the point, and where a court order forbids it we cannot. You still have the right to complain to the Data Protection Commission.

5. Retention

6. Your rights (EU / UK GDPR)

You have the right to:

7. Security

Passwords are hashed with a strong one-way function and per-user salts. Provider API keys are encrypted with a key derived from your vault password using strong primitives; we cannot decrypt them without you. Session cookies are HttpOnly, Secure and SameSite=Lax, scoped to.fightclub.pro, and expire after 1 hour of inactivity. Contact us atprivacy@fightclub.pro for architecture details.

8. Cookies

See our Cookie Policy.

9. Children

Fight Club is for adults only. You must be 18 or older to register. We do not knowingly collect data from anyone under 18; if you believe a child has registered, email privacy@fightclub.pro and we will delete the account.

10. Breach notification

We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach affecting your rights, and notify you without undue delay where the breach is likely to result in high risk.

11. Contact

Data controller: Fight Club (operating fightclub.pro). Contact: privacy@fightclub.pro.