GymtrackGymtrack
Legal

App Privacy Policy

Last updated

This Privacy Policy explains what personal data the Gymtrack app collects, why, and the rights you have.

1. Who we are

The Gymtrack app is provided by Volodymyr Filon, an individual based in Poland. We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).

For any privacy question or request, email support@gym-track.io. We have not appointed a Data Protection Officer, as the scale of our processing does not require one under Article 37 GDPR.

2. What data we collect

Account data: your name, your email address, and a user identifier. If you use Sign in with Apple, you may choose to hide your email, in which case we only ever see Apple’s private relay address. If you use Sign in with Google, Google also passes us the address of your profile picture.

Workout data: the training information you enter - exercises, sets, reps, weights, routines, personal records, bodyweight entries, the training goals and training days you choose during setup, and your streaks - together with the weekly analytics we derive from it.

Preferences and device settings: your time zone (read from your device rather than asked for), your language, your preferred weight unit, and which reminders you have switched on.

Technical data: your IP address and a description of your device and app version are recorded with each sign-in by the service that hosts our accounts, and are used to keep accounts secure.

Product analytics: how you use the app - which screens you open and which features you use - collected through PostHog and linked to your account identifier, to understand and improve the app and to run feature flags. When a search for an exercise returns no results, the words you typed are included, so that we can add what people are looking for; when the search does find something, only its length is recorded.

Crash and error reports: when something goes wrong, the error and the technical trace of where it happened are sent to PostHog along with your account identifier.

Notifications: reminders are scheduled and shown entirely on your device. We store only which reminder types you have switched on. No push token is created, and none is sent to us.

Notes from your trainer: if you accept a trainer, the dated notes they write about you are stored on your account. See "Sharing with your trainer" below.

On-device data: your session and a local cache are stored on your device (using secure storage and a local key-value store); they are not a separate collection by us. An unfinished workout is cleared from the device when you sign out.

Photos: when you share a workout image, the app opens the iOS share sheet. If you then choose "Save Image", iOS writes it to your photo library. The app never reads or uploads your existing photos.

3. How we use your data, and our legal bases

Providing the app - creating and securing your account and storing your workouts so they sync across your devices. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).

Product analytics, crash reports and feature flags - understanding how the app is used, finding what is broken, and improving it. Legal basis: our legitimate interest in improving the product (Article 6(1)(f) GDPR). You can object at any time by turning off "Share usage data" in Settings, which stops the app sending this data.

Keeping accounts secure - the technical data recorded at sign-in is used to detect and prevent abuse. Legal basis: our legitimate interest in a secure service (Article 6(1)(f) GDPR).

Sharing with a trainer - if you accept a trainer invitation, we make the data listed in "Sharing with your trainer" visible to that trainer. Legal basis: your explicit consent (Article 6(1)(a) GDPR), given on the screen that lists what will be shared. You can withdraw it at any time by ending the connection in the app, which stops the sharing.

Notifications - showing the reminders you switched on. Legal basis: your consent, given through the iOS notification permission (Article 6(1)(a) GDPR); you can turn them off at any time in your device settings.

4. Signing in with Apple or Google

If you sign in with Apple, Apple handles authentication and, if you choose "Hide My Email", provides us a private relay address instead of your real email. Any email we send reaches you through Apple’s relay. Apple’s own privacy terms govern that service.

If you sign in with Google, Google handles authentication and passes us your email address, your name, and the address of your profile picture. Google’s own privacy terms govern that service.

5. Sharing with your trainer

Gymtrack lets a trainer work with you inside the app. Nothing is shared until you accept an invitation from that trainer, on a screen that lists exactly what they will be able to see.

Once you accept, your trainer can see: your name and email address; every workout you finish, including the weight and reps of each set; all of your personal records; your complete bodyweight history, from your first entry; your streaks, weekly volume, muscle-group split and strength charts; and the notes you write on a workout.

Your trainer can also write dated notes about you, which you can read in the app. Your trainer is responsible for what those notes contain - see the App Terms of Use.

You can have one trainer at a time. Sharing stops as soon as either of you ends the connection, which you can do in the app at any time; ending it is also how you withdraw your consent to this sharing.

6. We do not track you across apps

We do not track you across other companies’ apps or websites, we do not use advertising identifiers, we do not show ads, and we do not sell or share your data with data brokers. This is why the app does not ask you for App Tracking Transparency permission.

7. Who we share data with

We do not sell your personal data. We share it with the service providers listed below, and - only if you accept a trainer invitation - with that trainer.

Supabase - stores your account and workout data (hosted in the EU). PostHog - product analytics and crash reports (hosted in the EU). Resend - sends our transactional email, such as the codes that confirm your sign-up or reset your password. Apple - authentication, if you use Sign in with Apple. Google - authentication, if you use Sign in with Google.

8. International data transfers

Your account and workout data are stored with Supabase in the EU, and product analytics with PostHog are hosted in the EU. Where these providers’ US parent companies are involved, transfers rely on the European Commission’s Standard Contractual Clauses or, where the provider is certified, the EU–US Data Privacy Framework.

Resend, Apple and Google are based in the United States; transfers to them rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. You can request a copy of the relevant safeguards from us.

9. How long we keep it

We keep your account and workout data for as long as your account exists. If you delete your account, we delete your personal data without undue delay, except anything we must keep to comply with the law.

Deleting your account also deletes your analytics profile and its event history at our analytics provider. Analytics events that are not tied to a deleted account are retained for a limited period and in aggregated form thereafter.

10. Your rights and account deletion

You have the right to access, correct, erase, restrict, object to the processing of, and receive a portable copy of your personal data. Where processing relies on consent, you can withdraw it at any time.

You can delete your account and its data directly in the app under Settings. You can turn off product analytics at any time under Settings, and you can stop sharing with a trainer by ending that connection in the app. You can also email us to exercise any right; we respond without undue delay and within one month (Article 12(3) GDPR).

11. Security

Data is encrypted in transit and at rest by our providers. Your session credentials are held in your device’s secure storage. No system is perfectly secure, but we take reasonable measures to protect your data.

12. Complaints to a supervisory authority

If you believe our processing of your personal data infringes data-protection law, you have the right to lodge a complaint with the Polish supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland - uodo.gov.pl.

13. Children

The app is intended for users aged 16 and over. In Poland the age of digital consent is 16, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will delete it.

14. Automated decisions

The analytics we show you are descriptive. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

15. Changes to this policy

We may update this policy. If we make a material change, we will update the date and give notice in the app where appropriate.

16. Contact

This service is operated by Volodymyr Filon, an individual based in Poland.

For any question, request, or complaint, email support@gym-track.io. We aim to respond within 30 days.

Looking for the Website Privacy Policy?Read the Website Privacy Policy