Privacy Policy

Last updated: 2026-07-17

In plain English: your account, your fights and your API usage live on our own servers in Germany. Your provider API keys are encrypted with a vault password only you know, which means we can't read them and nobody can recover them if you forget it, not even us. Prompts go to whichever AI provider runs the model you picked, and by default that inference happens in the US. We don't sell your data. We don't train models on it.

This policy describes how Fight Club (fightclub.pro), and the connected Knockout CLI and Ringside API products, collect and process personal data. We are the data controller for signed-up Fight Club and Knockout users. For the Ringside developer API, we are a data processor acting on behalf of the developer for their customers' data.

1. Data we collect

2. Why we process it

3. Sub-processors

See our sub-processor list for all third parties that process data on our behalf.

4. Where data is stored, and where inference runs

Storage. Primary database and application servers are in Germany (Hetzner, Falkenstein). Encrypted off-site database backups go to OVH in France (EU); the backup is encrypted on our server before it leaves, so OVH holds ciphertext only.

Inference routing. Storage in Germany and inference in the US are separate things. By default, prompts you send to a platform-pool model are processed in the US: the call routes through providers including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq, Mistral, DeepSeek and xAI, per thesub-processor list. EU-region routing is available on Ringside via region suffixes (for example @eu) on providers that offer EU regions, such as AWS Bedrock and Google Vertex; a region suffix is a routing instruction, not a legal residency guarantee, and no suffix means no residency guarantee. All US transfers run under Standard Contractual Clauses.

When you use BYOK (bring-your-own-key) with Knockout, your prompts are forwarded to the LLM provider you chose using your own key, under your agreement with them.

5. Retention

6. Your rights (EU / UK GDPR)

You have the right to:

7. Security

Passwords are hashed with a strong one-way function and per-user salts. Provider API keys are encrypted with a key derived from your vault password using strong primitives; we cannot decrypt them without you. Session cookies are HttpOnly, Secure and SameSite=Lax, scoped to.fightclub.pro, and expire after 1 hour of inactivity. Contact us atprivacy@fightclub.pro for architecture details.

8. Cookies

See our Cookie Policy.

9. Children

Fight Club is for adults only. You must be 18 or older to register. We do not knowingly collect data from anyone under 18; if you believe a child has registered, email privacy@fightclub.pro and we will delete the account.

10. Breach notification

We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach affecting your rights, and notify you without undue delay where the breach is likely to result in high risk.

11. Contact

Data controller: Fight Club (operating fightclub.pro). Contact: privacy@fightclub.pro.