Last updated: September 9, 2026
Mettle is a social fitness game: your real-world steps power heroes who battle monsters alongside your friends. This policy explains what data the app handles and where it goes. The short version: your steps and game progress are stored to make the game work, nothing is sold, and there are no ads or third-party trackers.
Your account. Mettle requires signing in with Apple or Google. From your provider we receive a unique account identifier and, depending on the provider and your choices, your name and email address (Sign in with Apple lets you hide your email — that works fine). The account exists only to anchor your game progress so it survives reinstalls and follows you across devices; your name and email let us contact you about your account and are never shown to other players. We store which provider you signed in with. Your email is never used for identity matching, never shared, and we do not send marketing email. We never see a password.
Health data (steps and walking distance). With your permission, Mettle reads your daily step count and walking distance from Apple Health on iPhone and from Health Connect on Android. Steps are converted into in-game damage. Your daily totals, and the damage they are worth, are shown to the members of any party you join, to anyone you duel, and on the global leaderboard, which every player of the game can see. Health data is used only for gameplay. It is never used for advertising, never sold, and never transferred to a third party.
On Android, Mettle also asks to read this data in the background. That permission exists for one reason: so the steps you walk with the app closed still damage your party's monster during the day, rather than only counting the next time you happen to open the app.
Mettle also reads your past daily totals, from further back than the last 30 days. This is used for one thing: the step chart on your profile, which you can page back through week by week to see what you have already walked. Nothing in the game's scoring ever looks further back than the current week, and past totals are read on your phone — reading them sends nothing anywhere.
You can withdraw either permission at any time in Apple Health or Health Connect's own settings, and Mettle keeps working — it simply stops counting steps, or stops showing earlier weeks, until you grant it again. Mettle never writes anything back to Apple Health or Health Connect.
Display name. The name you enter is shown to your partymates, on your leaderboard row, and to anyone you duel.
Game progress. Your heroes, coins, unlocks, and battle history are stored so the game works across your devices and after a reinstall.
Party data. Joining a party shares your display name, daily step totals, and in-game activity (deploys, claims, nudges) with that party's members. A party is not a private channel: what it holds is ordinary game data, and the app's rule that you only see the parties you are in is a rule of the game rather than a lock on the data. Nobody stumbles into your party by chance, though — the only way in is its unguessable invite code. Your phone's time zone is shared with the party too, so members spread across the world share one day and one midnight.
Leaderboard. The leaderboard ranks every player of the game, so a row on it is public to everyone who plays Mettle. Yours carries your display name, the hero fronting you, that day's steps and the damage they were worth, your lifetime totals, and your country — and tapping it opens your profile, where anyone can page back through your weekly step chart. It is the one place in Mettle where your walking is visible game-wide rather than inside a party. A day you walk nothing does not rank, but there is no way to play with the board switched off.
Duels. A duel is a walking contest between you and one other player — a partymate, or a stranger you challenged from the leaderboard. Its record holds both names, the hero each of you sent, and each side's step total for the days it runs, so both of you can watch the score. A duel is not private to the two of you the way a party is: its record is readable by signed-in players of the game.
Friends. Adding a friend stores a record naming the two of you and whether the request is pending, accepted, or declined. Only the two people on it can read it — a friend list is not public and nobody else can enumerate yours. Your friend code, the eight characters behind your friend link, identifies your account to anyone you give it to, and nobody can find you by it unless you share it. Declining a request tells the other person nothing.
App and device basics. Your player record also stores the app version you are running, your app language, and whether you first created a party, joined one with a code, or started solo. This is so we can tell how many people play and support them when something breaks. It is not linked to any advertising identifier and is never shared with anyone.
Country. Your leaderboard rows record the country your device's region setting names. This is a setting on your phone, not your location: Mettle never asks for location access and never reads it. It is stored so that leaderboards can be ranked by region, and — like everything else on a leaderboard row — other players can see it.
Notification token. If you allow notifications, the app stores your device's push token so gameplay alerts can reach your phone — issued by Apple Push Notification service on iPhone and by Firebase Cloud Messaging (a Google service) on Android. The token identifies the device, not you, and it is deleted when you sign out. The alert text is composed on your own device from a message key, so the words of a notification are never sent through the push service. We also keep a short technical log of the times a device's push token comes to belong to a different account, so we can find sign-ins that split one player into two by accident. It holds the token, the platform and the account and nothing else, and it is kept as a record after an account is deleted.
Game data is stored in a database we operate on Supabase, a hosted database service, on servers in the United States. Writes are locked to your own account, so nobody else can change your progress; what other players can read is what the game shares by design — your party's data, your leaderboard rows, and duels.
If you played Mettle before accounts were introduced (version 1.4.3), your earlier progress lives in Apple's iCloud (CloudKit), tied to your iCloud account. When you first sign in, the app copies that progress to our database once; the iCloud copy is not deleted by us and remains subject to Apple's privacy policy.
Health data is read from Apple Health or Health Connect on your device. Only daily totals (steps, distance) leave the device, and only to power the features above; the underlying health records never leave your phone. Mettle keeps no copy of your health data beyond those daily totals, and deleting your account deletes them.
If you use the in-app "Send feedback" form, your message — together with the name you entered and basic diagnostics (app version, OS version, device model) — is relayed to us as an email through Formspree, a form-forwarding service. This happens only when you tap Send.
If you allow notifications, the app sends gameplay alerts (a monster falls, a partymate nudges you, an encounter starts). You can turn these off in your phone's Settings at any time.
Game data persists so your progress survives reinstalls. You can delete your account at any time in Settings, on the Account page, with Delete account: this removes your account and your game records from our database immediately. What stays is the state a party shares — the parties themselves, their battles, and the monsters felled together — along with duels you have already fought, which keep both players' names and step totals, and the technical log above. Leaving a party stops sharing your steps with it. You can also email us at the address below with any deletion request. Full details, including everything that is and is not removed, are at walkmettle.com/delete-account.
Mettle is not directed at children under 13 and does not knowingly collect data from them.
If this policy changes materially, the updated policy will be posted here with a new date.
Questions or deletion requests: danielchungfung@gmail.com