This Privacy Policy explains what personal data the Gymtrack app collects, why, and the rights you have.
1. Who we are
The Gymtrack app is provided by Volodymyr Filon, an individual based in Poland. We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For any privacy question or request, email support@gym-track.io. We have not appointed a Data Protection Officer, as the scale of our processing does not require one under Article 37 GDPR.
2. What data we collect
Account data: your email address and a user identifier. If you use Sign in with Apple, you may choose to hide your email, in which case we only ever see Apple’s private relay address.
Workout data: the training information you enter — exercises, sets, reps, weights, routines, personal records, and bodyweight entries — and the weekly analytics we derive from it. This is fitness and performance data; it is not medical data, and we do not use it to infer health conditions.
Product analytics: how you use the app (screens viewed, features used), collected through PostHog and linked to your account identifier, to understand and improve the app and to run feature flags.
Notifications: if you enable them, a device push token so we can deliver the notifications you turned on.
On-device data: your session and a local cache are stored on your device (using secure storage and a local key-value store); they are not a separate collection by us.
Photos: when you tap "Save image", the app writes a workout share-image to your photo library. The app never reads or uploads your existing photos.
3. How we use your data, and our legal bases
Providing the app — creating and securing your account and storing your workouts so they sync across your devices. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
Product analytics — improving the app and running feature flags. Legal basis: our legitimate interest in improving the product (Article 6(1)(f) GDPR); where consent is required for storing or reading information on your device, we rely on your consent.
Notifications — delivering reminders and updates you switched on. Legal basis: your consent, given through the iOS notification permission (Article 6(1)(a) GDPR); you can turn them off at any time in your device settings.
4. Sign in with Apple
If you sign in with Apple, Apple handles authentication and, if you choose "Hide My Email", provides us a private relay address instead of your real email. Any email we send reaches you through Apple’s relay. Apple’s own privacy terms govern that service.
5. We do not track you across apps
We do not track you across other companies’ apps or websites, we do not use advertising identifiers, we do not show ads, and we do not sell or share your data with data brokers. This is why the app does not ask you for App Tracking Transparency permission.
6. Who we share data with
We do not sell your personal data. We share it only with processors who help us run the app:
Supabase — stores your account and workout data (hosted in the EU). PostHog — product analytics (hosted in the EU). Apple — authentication (Sign in with Apple) and notification delivery (APNs). Expo — app builds and push-notification relay.
7. International data transfers
Your account and workout data are stored with Supabase in the EU, and product analytics with PostHog are hosted in the EU. Where these providers’ US parent companies are involved, transfers rely on the European Commission’s Standard Contractual Clauses or, where the provider is certified, the EU–US Data Privacy Framework.
Apple and Expo are based in the United States; transfers to them rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. You can request a copy of the relevant safeguards from us.
8. How long we keep it
We keep your account and workout data for as long as your account exists. If you delete your account, we delete your personal data without undue delay, except anything we must keep to comply with the law.
Analytics data is retained for a limited period and in aggregated form thereafter.
9. Your rights and account deletion
You have the right to access, correct, erase, restrict, object to the processing of, and receive a portable copy of your personal data. Where processing relies on consent, you can withdraw it at any time.
You can delete your account and its data directly in the app under Settings. You can also email us to exercise any right; we respond without undue delay and within one month (Article 12(3) GDPR).
10. Security
Data is encrypted in transit and at rest by our providers. Your session credentials are held in your device’s secure storage. No system is perfectly secure, but we take reasonable measures to protect your data.
12. Children
The app is intended for users aged 16 and over. In Poland the age of digital consent is 16, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will delete it.
13. Automated decisions
The analytics we show you are descriptive. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
14. Changes to this policy
We may update this policy. If we make a material change, we will update the date and give notice in the app where appropriate.
15. Contact
This service is operated by Volodymyr Filon, an individual based in Poland.
For any question, request, or complaint, email support@gym-track.io. We aim to respond within 30 days.