Skip to content

Effective July 21, 2026

RankUp privacy policy

This Privacy Policy explains what RankUp collects, how information is used and disclosed, how AI and camera features work, how long information is kept, and the choices available to you.

1. Who operates RankUp and what this policy covers

Arctic Aura Designs LLC, doing business as RankUp ("RankUp," "we," "us," or "our"), provides the RankUp websites, web application, mobile applications, APIs, board-preparation tools, competitive features, AI coaching, AGSU tools, support, and related services (collectively, the "Services").

This Policy applies when you use rankuparmy.com, app.rankupboard.com, the RankUp iOS or Android application, or otherwise interact with the Services. It does not govern third-party websites or services that have their own privacy policies.

Privacy contact: info@arcticauradesigns.com. Effective date: July 21, 2026. RankUp does not publish a mailing address for privacy requests.

2. Important privacy commitments

RankUp is designed to collect the information needed to provide preparation, coaching, competition, support, and security features. RankUp does not sell personal information, share personal information for cross-context behavioral advertising, serve behaviorally targeted ads, perform facial recognition, infer identity from images, or use AI output to make an official promotion, selection, induction, inspection, employment, or eligibility decision.

3. Information you provide

Depending on the features you use, you may provide the following information:

  • Account information, including your email address, authentication identifier, email-verification status, and records of accepting required notices.
  • Profile and preparation information, including a pseudonymous handle, primary and secondary preparation tracks, optional current rank, target date, time zone, daily goal, reminder settings, and leaderboard visibility.
  • Study information, including selected modes and topics, answers, written responses, answer accuracy, response times, bookmarks, source-review activity, mastery history, streaks, missions, achievements, and offline answer events after they sync.
  • Competition and community information, including match participation, answers, response times, results, ratings, tier, friend relationships, duel invitations, blocks, reports, and moderation-related information.
  • AI mock-board information, including session settings, selected question versions, transcript, response timing, evaluation report, optional derived camera observations, and consent state.
  • AGSU and rack information, including face-treated garment images you choose to upload, upload metadata, rule-set version, uniform findings, rack selections, arrangements, and exports.
  • Support and feedback information, including messages, content reports, accessibility reports, attachments you choose to provide, and related correspondence.
  • Notification and marketing choices, including enabled categories, quiet hours, device registration, and the time of any separate marketing consent.

4. Information collected automatically

When you use the Services, RankUp and its service providers may automatically process device and technical information such as IP address, browser and device type, operating system, app version, language, time zone, request identifiers, authentication events, network and API activity, crash information, limited performance traces, push-notification tokens, and security or abuse signals. RankUp configures Sentry not to send default personally identifying information, but diagnostic events may still include technical context needed to investigate an error.

5. Payment and subscription information

Stripe processes checkout, payment methods, invoices, fraud-prevention signals, cancellation, and subscription management. RankUp receives limited transaction and entitlement information, such as a Stripe customer or subscription identifier, plan, status, billing period, and payment-event status. RankUp does not receive or store complete payment-card numbers. If a future purchase is processed by Apple or Google, that store will process payment information under its own policy and provide RankUp limited purchase and entitlement information.

6. Sources of information

RankUp receives information directly from you; automatically from your browser, device, or use of the Services; from other members when they interact with or report you; and from service providers such as Firebase, Stripe, OpenAI, Cloudflare, Sentry, Apple, and Google when they return authentication, payment, AI, delivery, security, crash, or notification information needed to operate the Services.

7. How RankUp uses information

RankUp uses personal information for the following purposes:

  • Create, authenticate, secure, support, and delete accounts.
  • Deliver study sessions, offline synchronization, adaptive review, bookmarks, progress, achievements, exports, rack tools, and other requested features.
  • Operate matches, ratings, leaderboards, friendships, duels, reports, and moderation controls.
  • Provide AI mock boards, source-grounded study coaching, uniform observations, and the reports you request.
  • Process subscriptions, maintain entitlements, prevent duplicate charges, and respond to billing events.
  • Send service, security, study, match, achievement, content-update, and separately consented marketing notifications, subject to your settings and quiet hours.
  • Detect fraud, cheating, misuse, prohibited content, security incidents, service errors, and violations of the Terms or Community Guidelines.
  • Measure reliability, troubleshoot, maintain backups, improve accessibility and product performance, and develop features using aggregated or de-identified information where practical.
  • Comply with law, enforce agreements, protect rights and safety, and establish or defend legal claims.

8. AI mock boards and study coaching

With your action and microphone permission, mock-board audio is streamed to OpenAI for real-time interaction and transcription. RankUp does not store raw mock-board audio in its application database. RankUp receives and stores the resulting transcript, selected question versions, report, scores, and session metadata so you can review your history and so RankUp can enforce usage allowances.

RankUp sends transcripts, authored rubrics, source bundles, a pseudonymous safety identifier, and any optional derived visual observations needed to evaluate the session. OpenAI states that API data is not used to train its models unless the customer affirmatively opts in. Under standard API controls, abuse-monitoring logs may contain prompts or responses and may be retained by OpenAI for up to 30 days unless a legal obligation requires longer retention or stronger approved data controls apply.

AI output can be incomplete, inaccurate, or misleading. RankUp restricts factual corrections to stored sources and blocks official pass-or-fail language, but those controls do not make the output authoritative. Always verify information against your current MOI, chain of command, and cited primary publication.

9. Optional board-camera processing

Camera coaching is optional. When enabled, continuous video frames are analyzed locally on your device using a downloaded MediaPipe runtime and model. RankUp does not transmit or store the continuous board-camera video. The app may send limited derived indicators—such as framing, gaze, posture, or confidence-related observations—with your session for report generation. Those observations do not identify you, are not used for facial recognition, and do not change knowledge accuracy. Denying or revoking camera permission disables camera observations without preventing voice-only practice.

10. AGSU image processing

An AGSU photo check is optional and requires an affirmative upload action. Before upload, the app re-encodes each supported image to remove EXIF metadata, applies the selected face treatment, previews the outbound images, and asks you to confirm the upload. You are responsible for checking that no face or sensitive background information remains visible.

Three treated garment views are uploaded to a private Cloudflare R2 bucket using short-lived signed URLs and are sent to OpenAI for visual observations. Deterministic, versioned rules produce the final Likely correct, Review, or Unable to determine findings. RankUp schedules its R2 source-image copies for deletion in less than 24 hours and maintains a one-day storage-lifecycle safety net. Under the current AI-provider configuration, image inputs or outputs may remain in OpenAI application state or abuse-monitoring logs for up to 30 days. Before publication, configure and verify the intended OpenAI storage controls if RankUp will promise shorter provider retention. The findings, rule-set version, timestamps, and R2 deletion confirmation remain with your account until deletion or another applicable retention event.

11. When information is disclosed

RankUp may disclose information in these circumstances:

  • To other members: your handle, rating, tier, leaderboard placement when enabled, match activity needed to play, and limited profile or friend information. Do not use a handle that identifies you or implies official authority.
  • To service providers: Google Firebase for authentication and push; Stripe for billing; OpenAI for consented AI features; Cloudflare and R2 for network delivery and private object storage; Sentry for minimized error and performance telemetry; infrastructure providers for application hosting, PostgreSQL, Valkey, logs, and encrypted backups; and Apple Push Notification service, Firebase Cloud Messaging, or web push for notifications.
  • For on-device resources: camera coaching downloads the MediaPipe runtime and model from Google-hosted and jsDelivr delivery endpoints, which receive ordinary network information such as IP address and user agent.
  • For legal and safety reasons: when reasonably necessary to comply with law or valid process; enforce agreements; investigate fraud, abuse, or security events; or protect RankUp, users, or others.
  • For a business transaction: in connection with financing, due diligence, reorganization, sale, merger, or transfer, subject to appropriate confidentiality and applicable notice requirements.
  • At your direction or with consent: when you request an export, share a result, connect a service, or otherwise direct RankUp to disclose information.

12. Cookies, local storage, analytics, and privacy signals

RankUp uses browser or app storage, authentication tokens, IndexedDB or native encrypted storage, and similar technologies needed for sign-in, security, preferences, offline study, synchronization, and basic operation. RankUp does not currently use third-party advertising cookies or cross-site behavioral advertising.

Some browsers send Do Not Track signals, but there is no uniform industry response standard. RankUp does not change functionality in response to Do Not Track because it does not sell personal information or use cross-context behavioral advertising. Where legally applicable, RankUp will treat a recognized Global Privacy Control signal as an opt-out of sale or sharing; RankUp does not engage in either practice regardless of the signal.

13. Retention

RankUp keeps information only for as long as reasonably necessary for the disclosed purposes, subject to the following periods and retention criteria:

  • Account, profile, study, mastery, match, rack, transcript, report, uniform finding, preference, and entitlement records: generally while your account remains active, then deleted or de-identified through the account-deletion workflow except as described below.
  • Raw mock-board audio: not stored in RankUp's application database; OpenAI may retain API abuse-monitoring content for up to 30 days under standard controls.
  • Continuous mock-board camera video: analyzed locally and not stored by RankUp. Derived visual observations remain with the associated board session.
  • AGSU source images: scheduled for deletion in less than 24 hours, with a one-day bucket lifecycle as a safety net. Uniform findings remain with your account.
  • Account deletion: RankUp schedules deletion and de-identification of account data 30 days after a verified request. Copies of that data may remain in encrypted database backups for up to an additional 30 days while those backups rotate, so removal from RankUp-controlled application databases and backups may take up to 60 days from the request.
  • The deletion workflow removes direct email and handle identifiers and specified study, mastery, bookmark, board-session, uniform-check, rack, device-token, upload, friendship, duel, and user-to-user report records. Pseudonymous competitive-integrity, rating, progression-ledger, content-report, editorial, moderation, security, and audit records may remain when reasonably necessary to preserve system integrity, investigate abuse, document editorial actions, comply with law, or establish or defend legal claims.
  • Operational logs: retained according to the configured schedules of RankUp's infrastructure and diagnostics providers and only for as long as reasonably necessary for security, troubleshooting, reliability, abuse prevention, and legal compliance. RankUp minimizes and redacts logged personal information where practical.
  • Billing records: Stripe maintains payment, invoice, fraud-prevention, cancellation, and related billing records under Stripe's own retention practices and legal obligations. RankUp may retain limited customer, subscription, entitlement, webhook, payment-status, and billing-audit records for accounting, fraud prevention, dispute resolution, and legal compliance.
  • Third-party copies: RankUp sends deletion or expiration instructions where the provider supports them, but cannot directly control a provider's independent legal obligations, backup rotation, security logs, or other retention. Provider-retained information is governed by that provider's terms and privacy policy.

14. Security

RankUp uses administrative, technical, and organizational measures intended to protect information, including encryption in transit, private object storage, short-lived signed upload URLs, restricted service credentials, authentication and authorization controls, rate limits, minimized telemetry, log redaction, deletion jobs, and encrypted backups. No transmission or storage system is completely secure. You are responsible for protecting your sign-in method and notifying support if you suspect unauthorized access.

15. Your settings and choices

You can change eligible profile fields, leaderboard visibility, preparation tracks, reminder settings, push categories, quiet hours, and separate marketing consent in the app. You can deny or revoke microphone, camera, and notification permissions in device settings. You can download the available account export and request account deletion from Profile → Settings → Privacy. Some choices disable the related feature but do not prevent access to unrelated study tools.

16. Privacy rights and requests

Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; withdraw consent; and appeal a denied request. RankUp will not discriminate against you for exercising a privacy right.

Use the in-app export or deletion controls when available, or email info@arcticauradesigns.com from the address associated with your verified account. RankUp may request information reasonably necessary to verify identity and authority. An authorized agent may submit a request where permitted by law, but RankUp may require proof of authorization and direct identity confirmation. RankUp will respond within the period required by applicable law and will explain any denial and available appeal method.

17. California notice

For purposes of California law, the categories RankUp may collect are identifiers; customer-record information; commercial and subscription information; internet or electronic-network activity; approximate location inferred from IP address; audio, electronic, and visual information; professional information you choose to provide, such as current rank; inferences and progress indicators derived from activity; and account credentials or other information treated as sensitive personal information. The sources, purposes, retention criteria, and categories of recipients are described in this Policy.

RankUp does not sell personal information, share it for cross-context behavioral advertising, or use or disclose sensitive personal information for purposes that require a right to limit under the CCPA. RankUp has no actual knowledge that it sells or shares personal information of anyone under 16. California residents may request access, deletion, correction, or portability and may exercise applicable opt-out or limitation rights without discrimination. Because RankUp operates exclusively online, requests may be submitted through the verified account controls or info@arcticauradesigns.com.

18. Age limits

RankUp is intended only for people who are at least 18 years old and is not directed to children or minors. RankUp does not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information, contact info@arcticauradesigns.com so RankUp can investigate, disable the account, and delete the information as appropriate.

19. United States processing and third-party links

RankUp is offered for a United States launch. RankUp and its providers may process information in the United States and other locations where they operate, subject to their terms and applicable safeguards. Links to Army publications, app stores, billing pages, or other third-party resources are governed by those third parties' policies. RankUp selects and configures providers for the Services but cannot control a third party's independent privacy, security, legal-compliance, or retention practices.

20. Changes to this Policy

RankUp may update this Policy to reflect changes in the Services, providers, law, or practices. The updated Policy will show a revised date. RankUp will provide additional notice when required or when a change materially affects your rights, and will request consent when applicable law requires it. Previous versions should be archived for reference.

21. Contact and complaints

Email privacy questions, requests, or complaints to info@arcticauradesigns.com. This is RankUp's designated contact method for privacy matters. Include only the information needed to describe the request. Never email passwords, authentication tokens, full payment-card numbers, Social Security numbers, DoD IDs, classified information, controlled operational information, medical records, or personnel records. If RankUp cannot resolve a privacy concern, you may have the right to contact the privacy or consumer-protection authority where you live.