Privacy Policy
Last updated: 2026-08-07
In plain English: your account, your fights and your API usage live on our own servers in Germany. Your provider API keys are encrypted with a vault password only you know, which means we can't read them and nobody can recover them if you forget it, not even us. Prompts go to whichever AI provider runs the model you picked, and by default that inference happens in the US. We don't sell your data. We don't train models on it.
This policy describes how Fight Club (fightclub.pro), and the connected Knockout CLI, Ringside API and Genie products, collect and process personal data. We are the data controller for signed-up Fight Club, Knockout and Genie users. For the Ringside developer API, we are a data processor acting on behalf of the developer for their customers' data.
The data controller is Saasplex Limited, trading as Stratus5, a company registered in Ireland under company number 452917, registered office 36 Abbotts Hill, Malahide, County Dublin, Ireland. Our supervisory authority is the Irish Data Protection Commission, and you have the right to lodge a complaint with them at dataprotection.ie.
1. Data we collect
- Account: email, username, password hash (hashed with a strong one-way function), avatar URL, role, owner type.
- Vault: encrypted provider API keys (encrypted with a key derived from your vault password using strong primitives, we never store the vault password in plaintext and cannot recover it).
- Usage: fight transcripts, Knockout session messages, wallet transactions, cost attribution. For Ringside, we store full prompt and response content where you use Conversations or response caching, plus usage metadata for billing.
- Support: questions and answers from the in-app assistant, and the model responses. Approved answers may be added, after review, to a general help knowledge base served to other users. Messages that look like card numbers, national ID numbers, passwords or API keys are redacted before storage.
- Technical: IP address (rate limiting + fraud), user agent, request IDs, server logs.
- Abuse records: where a request to the platform appears to be criminal, we keep the IP address it came from, the account and email address it belongs to, the timestamps, the request itself and the surrounding conversation. See section 4a.
- Payment: Stripe handles all card data; we store only the Stripe customer/payment method IDs. We never see your card number.
2. Why we process it
- Contract (GDPR Art. 6(1)(b)): to provide the platform you signed up for.
- Legitimate interest (Art. 6(1)(f)): fraud prevention, rate limiting, security audit logs, product analytics.
- Consent (Art. 6(1)(a)): marketing communications, cookies beyond strictly necessary.
- Legal obligation (Art. 6(1)(c)): tax records, law enforcement requests with valid court order.
- Legitimate interest (Art. 6(1)(f)): detecting and reporting criminal use of the platform, and protecting the people it would be used against. Recital 50 GDPR treats preventing and reporting crime as a legitimate interest, and our assessment is that it outweighs the interests of an account holder who is using the service to commit an offence.
3. Sub-processors
See our sub-processor list for all third parties that process data on our behalf.
4. Where data is stored, and where inference runs
Storage. Primary database and application servers are in Germany (Hetzner, Falkenstein). Encrypted off-site database backups go to OVH in France (EU); the backup is encrypted on our server before it leaves, so OVH holds ciphertext only.
Inference routing. Storage in Germany and inference in the US are separate things. By default, prompts you send to a platform-pool model are processed in the US: the call routes through providers including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq, Mistral, DeepSeek and xAI, per thesub-processor list. EU-region routing is available on Ringside via region suffixes (for example @eu) on providers that offer EU regions, such as AWS Bedrock and Google Vertex; a region suffix is a routing instruction, not a legal residency guarantee, and no suffix means no residency guarantee. All US transfers run under Standard Contractual Clauses.
When you use BYOK (bring-your-own-key) with Knockout, your prompts are forwarded to the LLM provider you chose using your own key, under your agreement with them.
4a. Criminal use, and what we give the police
Illegal activity on the platform is a matter for the police. Where we find that the service has been used to commit an offence, or somebody asks us to build something plainly criminal, we disclose the abuse record described in section 1 to the Garda Síochána or to whichever authority has jurisdiction. We also disclose where a valid court order, warrant or statutory request requires it.
Lawful basis. Logging and keeping the record is legitimate interest under Art. 6(1)(f), for detecting criminal use and protecting the people it targets (see Recital 50). Disclosing it is Art. 6(1)(f) for a report we make on our own initiative, and Art. 6(1)(c) where a court order or statute compels us. Where the record contains special-category data the additional condition is Art. 9(2)(f), establishment, exercise or defence of legal claims.
Retention. Abuse records are kept for 24 months from the date of the event, then deleted, except where they relate to an ongoing investigation or legal proceedings, in which case they are kept until it concludes. They survive deletion of the account for that period; the rest of the account is deleted as described below.
Notice. We do not normally tell the account holder before making a disclosure, because doing so would defeat the point, and where a court order forbids it we cannot. You still have the right to complain to the Data Protection Commission.
5. Retention
- Active account data: retained for the lifetime of your account.
- Fight transcripts, Knockout sessions: retained for the lifetime of your account; deleted on account erasure.
- Ringside usage events: retained for the lifetime of your account, removed when the account is deleted.
- Webhook deliveries: 30 days. Client tokens: 7 days. API run records: 30 days.
- Admin action logs: 365 days. Operational logs (worker, crash and server request logs): retained for the lifetime of the account.
- Backups: 30 daily rolling, encrypted before they leave our servers.
- Abuse records (section 4a): 24 months, or until any investigation or proceedings conclude.
- Financial records (invoices, payments, what was charged): 10 years, required by Revenue, and not deletable on request.
- Genie accounts: deletion is immediate and irreversible. Applications, code, data, backups and conversations go at once, with no retention period and no recovery.
- Deleted account data: removed or anonymised within 30 days of erasure request.
6. Your rights (EU / UK GDPR)
You have the right to:
- Access: Ringside developers can export their account data directly with
GET /v1/account/export(machine-readable JSONL). Fight Club and Knockout users: email privacy@fightclub.pro and we will provide an export within 30 days. A self-serve export in the app is in progress. - Rectification: update your profile in the app; for fields you can't edit, email privacy@fightclub.pro.
- Erasure: email privacy@fightclub.pro to delete your account and we will action it within 30 days. Billing records are retained in anonymised form for tax compliance.
- Portability: the Ringside export is JSONL; for Fight Club and Knockout, request a machine-readable copy at the email above.
- Object / restrict / withdraw consent: email privacy@fightclub.pro.
- Complain to a data protection authority (in the EU, your local DPA; in the UK, the ICO).
7. Security
Passwords are hashed with a strong one-way function and per-user salts. Provider API keys are encrypted with a key derived from your vault password using strong primitives; we cannot decrypt them without you. Session cookies are HttpOnly, Secure and SameSite=Lax, scoped to.fightclub.pro, and expire after 1 hour of inactivity. Contact us atprivacy@fightclub.pro for architecture details.
8. Cookies
See our Cookie Policy.
9. Children
Fight Club is for adults only. You must be 18 or older to register. We do not knowingly collect data from anyone under 18; if you believe a child has registered, email privacy@fightclub.pro and we will delete the account.
10. Breach notification
We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach affecting your rights, and notify you without undue delay where the breach is likely to result in high risk.
11. Contact
Data controller: Fight Club (operating fightclub.pro). Contact: privacy@fightclub.pro.