GymiaFit
gymia.fit
Back to home

Privacy Policy

Last updated: September 24, 2026

1. Introduction

Gymia ("we", "our", or "us") operates the GymiaFit mobile application, listed as GymiaFit on Google Play and the App Store, and the gymia.fit website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Data controller: Gymia, based in Italy. Contact: support@gymia.fit.

2. Information We Collect

Information you provide

  • Account: email address, password (hashed, never stored in plaintext), display name
  • Profile: optional profile photo, bio, gym membership
  • Health & fitness data: workout logs, sets/reps/weight, body measurements (weight, body fat, circumferences), meal logs, fitness goals, experience level
  • Media: exercise videos and photos you upload (used for AI exercise recognition and progress tracking)
  • Social: squad messages, posts, comments, challenge participations
  • Support: contents of any support request you send us

Information collected automatically

  • Device information: model, OS version, language, timezone
  • App identifiers: install ID, push notification token
  • Usage data: features used, session duration, in-app actions
  • Product analytics events: pages and screens viewed, buttons and links clicked, referring website, and marketing campaign parameters (UTM tags), processed via PostHog (see Section 5). On the gymia.fit website this is captured anonymously and cookielessly until you accept analytics cookies.
  • Website session recordings (gymia.fit only): once you accept analytics cookies, we record anonymized playback of your interaction with the marketing site (clicks, scrolls, navigation) to diagnose usability issues. All form fields and text you type are masked and never captured. The mobile app is never recorded.
  • Crash logs and performance data from the mobile app (via Sentry)

Information we do NOT collect

  • Precise location (GPS) — we do not track location
  • Contacts, SMS, calendar, or microphone (except when you explicitly record an exercise video)
  • Credit card or banking details — GymiaFit currently has no payment flow at all, so we never receive or store them

3. How We Use Your Information

  • Provide and personalize workout, nutrition, and challenge features
  • Run AI exercise recognition on videos you upload
  • Compute your rank, leaderboard position, and progress
  • Enable squad chat, posts, and social features
  • Send push notifications (workouts, challenges, squad activity) — you can disable per channel in app settings or device settings
  • Detect crashes, fix bugs, improve performance
  • Respond to your support requests
  • Comply with legal obligations

Legal bases (GDPR): performance of contract (Art. 6(1)(b) for account and workout features), consent (Art. 6(1)(a) for optional notifications and analytics, Art. 9(2)(a) for health data), legitimate interests (Art. 6(1)(f) for security, crash reporting, fraud prevention), legal obligation (Art. 6(1)(c) where a law requires us to retain something).

4. Health & Fitness Data

Gymia processes health and fitness data (workouts, body measurements, meal logs) under Article 9(2)(a) GDPR — with your explicit consent given at account creation. You may withdraw consent at any time by deleting your account (see Section 8). We do not share health data with third-party advertisers or data brokers.

Video-based exercise recognition runs on our own gym-tracker service. Your videos stay encrypted on our EU infrastructure and are never sent to a third-party model provider.

Our text-based AI features work differently and we want to be explicit about it. The AI coach chat, next-exercise and meal suggestions, and workout- or nutrition-plan import send the text you submit — plus the training context needed to answer it — to Google's Gemini API in the USA. See Section 5.

5. Third-Party Services

We share limited data with the following processors, each under a Data Processing Agreement:

Sentry (USA) — crash reporting (mobile app only)

Only the GymiaFit mobile app reports to Sentry; our backend services do not. Receives: anonymized crash stack traces, device model, OS version, app version, install ID. Personal data is scrubbed before transmission. sentry.io/privacy

Google (USA) — Sign-In, Push, Play Services

Sign in with Google (email, name, profile photo if you authorize), Firebase Cloud Messaging for push notifications (device token only), Google Play Services. policies.google.com/privacy

Google Gemini (USA) — AI coach and plan parsing

Powers the in-app AI coach chat, next-exercise and meal suggestions, and the parsing of workout or nutrition plans you import. Receives: the message or plan text you submit, plus the training and dietary context needed to answer it — which can include your experience level, primary goal, training location, recent exercises, and dietary preferences. Your email, name, uploaded media, and body measurements are not sent. This is health data under Article 9 GDPR and is processed on the explicit consent described in Section 4. Requests go to a Google Cloud project we control and are governed by Google's Gemini API terms, which set out how Google may use the content you send. ai.google.dev/gemini-api/terms

Apple (USA) — Sign-In, Push, App Store

Sign in with Apple (email or relay address, name), Apple Push Notification service, App Store. apple.com/legal/privacy

Hetzner (Germany / Finland) — hosting & storage

All Gymia servers, databases, and uploaded media are hosted on Hetzner data centers within the EU. hetzner.com/legal/privacy-policy

PostHog (European Union) — product analytics

Powers our understanding of how the gymia.fit website and the GymiaFit app are used. Receives: pages/screens viewed, clicks, referring website, UTM campaign parameters, an anonymous device/visitor identifier, approximate location derived from IP (city-level; the IP itself is not stored long-term), device and browser type. For logged-in app users it is also linked to your account ID, email, display name, username, and language, together with the coarse profile fields we segment activation and retention by: sex, training location, experience level, primary goal, activity level, and weekly training days. Your actual workout logs, body measurements, meal logs, and uploaded media are never sent to PostHog. On the website it additionally captures masked session recordings after you consent (form inputs are never recorded). Data is hosted on PostHog Cloud EU (Frankfurt, Germany) — no transfer outside the EU. posthog.com/privacy

Resend (USA) — transactional email

Delivers the account email we send you: address verification, password reset, and — only if you opted in to marketing — occasional re-engagement messages. Receives: your email address and the contents of that message. No workout, measurement, or meal data is included. resend.com/legal/privacy-policy

International transfers: Sentry, Google (including Gemini), Apple, and Resend process data in the USA. Those transfers rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Hetzner and PostHog process your data inside the EU only.

6. Data Retention

  • Account data: retained while your account is active. Deleted within 30 days of account deletion.
  • Workout, meal, and progress data: same as account.
  • Crash logs: retained 90 days by Sentry, then automatically purged.
  • Support tickets: retained 2 years after resolution.
  • AI coach prompts and responses: not retained by us beyond the conversation; Google retains API traffic per its Gemini API terms.
  • Backups: encrypted backups may persist up to 35 days after deletion before being overwritten.

7. Data Sharing

We do not sell or rent your personal data. We share data only:

  • With your consent: When you post in a squad, comment publicly, or join a leaderboard, your display name and selected data become visible to other members of that scope.
  • With community features: If you participate in squads, challenges, or leaderboards, other members in those groups can see your display name, rank, and relevant stats.
  • Service providers: The processors listed in Section 5.
  • Legal requirements: When required by law, court order, or to protect rights, property, or safety.

8. Account Deletion

You can delete your GymiaFit account at any time:

  • In the app: Profile → Settings → Danger zone → Delete account. Confirm with your password.
  • By email: Send a deletion request from your registered email to support@gymia.fit. We respond within 30 days.
  • Web: gymia.fit/account/delete

Deletion is irreversible. Your account, profile, workout history, squads memberships, posts, and uploaded media are permanently removed within 30 days.

9. Cookies and Tracking Technologies (website only)

The gymia.fit website uses limited cookies. The GymiaFit mobile app does not use cookies but uses local storage and secure storage for authentication tokens.

Cookies we use on the website

Essential Cookies

Necessary for the website to function. Cannot be switched off.

  • gymia-cookie-consent — Stores your cookie consent preferences (browser local storage)
  • Next.js framework cookies — Required for application functionality

Analytics Cookies (Optional)

We use PostHog (EU-hosted, see Section 5) to understand how visitors use the site. Before you accept, analytics runs in a cookieless mode (in-memory only) that counts anonymous page views and referrers without storing anything on your device. Only after you click "Accept analytics" do we set an analytics cookie and enable masked session recording; clicking "Decline" stops analytics entirely.

  • ph_…_posthog — stores an anonymous PostHog visitor ID so repeat visits are counted as one person (set only after consent)

Third-Party Services

  • Web fonts — self-hosted on gymia.fit; your browser makes no requests to Google Fonts or any other font provider

Managing cookies

  • Use the cookie consent banner to accept or decline
  • Change or withdraw your choice at any time via "Cookie settings" in the page footer
  • Clear browser cookies through browser settings
  • Enable "Do Not Track" in your browser

10. Data Security

We implement industry-standard security measures:

  • TLS 1.2+ encryption for all data in transit
  • At-rest encryption for databases and object storage
  • Passwords hashed with bcrypt; never stored in plaintext
  • Access tokens stored in device secure storage (Keychain on iOS, Keystore on Android)
  • Role-based access control with audit logs
  • Regular security reviews and dependency updates

No system is 100% secure. In the event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours, in accordance with Article 33 GDPR.

11. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights under the GDPR:

  • Access (Art. 15): obtain a copy of your personal data
  • Rectification (Art. 16): correct inaccurate data
  • Erasure (Art. 17): request deletion of your data ("right to be forgotten")
  • Restriction (Art. 18): limit how we process your data
  • Portability (Art. 20): receive your data in a machine-readable format
  • Object (Art. 21): object to processing based on legitimate interests
  • Withdraw consent (Art. 7(3)): at any time, without affecting prior processing
  • Lodge a complaint: with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, garanteprivacy.it) or your local supervisory authority

Access and portability (Art. 15 and 20) are self-serve. In the app, go to Profile → Settings → Download my data to get everything we hold about you as a JSON file, immediately and without asking us.

Erasure (Art. 17) is self-serve too — see deleting your account.

For any other right, contact support@gymia.fit. We respond within 30 days.

12. Children's Privacy

GymiaFit is for people aged 13 and over: the app does not accept a younger age, and we do not knowingly collect personal data from children under 13. In the European Union, each country sets the age from which you can consent on your own to the processing of your personal data online, between 13 and 16 (14 in Italy). If you are younger than that where you live, you may use GymiaFit only with the permission of a parent or legal guardian, who gives the consents described in this policy on your behalf. If you are a parent or guardian and believe your child uses GymiaFit without your permission, please contact us at support@gymia.fit and we will delete the account and its data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the app and email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

14. Contact

For privacy questions or to exercise your rights:

Email: support@gymia.fit

Postal: please request the postal address by email for formal correspondence.