Privacy, in plain language

Know what GymApp stores — and why.

A readable overview comes first. The complete policy remains available section by section below.

Effective August 15, 2026 · Чинна з 15 серпня 2026 року · Действует с 15 августа 2026 года

Support / Підтримка / Поддержка

English

The cards are a quick orientation, not a replacement for the complete terms below.

1. Who controls your data

GymApp is provided by Martynenko Eduard (“GymApp,” “we,” “us”). For privacy or support questions, email support@gymapptracker.com or use our support page.

This policy covers the GymApp iOS and Android apps, the browser/PWA version, and the optional Garmin Connect IQ companion. A feature or permission mentioned below applies only when it exists on the platform you use.

2. Data we process

DataExamples and sourceWhy
Account and contact dataEmail address, Supabase user UUID, and display name that you provide when creating or using an account. Supabase handles credentials; GymApp does not store your plaintext password.Account creation, confirmation, authentication, security, cloud sync, support, and deletion.
Workout and fitness dataWorkout dates, exercise names, sets, weights, repetitions, plans, completed sessions, volume, personal records, and derived XP, level, missions, achievements, and workout count.Workout logging, sync, progress, Smart Coach guidance, muscle-load views, and gamification.
User contentFree-form workout notes you enter.Save and display your workout history.
Friends and shared progressRandom friend/profile code, display name, friend requests and relationship/block/privacy state; optional XP, level, workout count, up to five date-only workout summaries and up to 100 entered exercise bests; and, only under a separate explicit owner setting that is off by default, read-only exercise names, weights, repetitions, and sets for those same up to five workouts. This also includes bounded exercise/planned-set invitations and, in an accepted two-person live room, the frozen plan plus each participant's committed set completion, entered weight, and repetitions.Let mutually confirmed, unblocked friends compare self-reported progress, view separately authorized workout detail, share an editable independent plan, or train together live. The global leaderboard is removed; friend progress is not presented as verified competition.
Notification delivery dataOnly when you enable optional system alerts: a random installation ID, platform/provider, APNs or FCM token or Web Push endpoint and subscription keys, locale/app version, and a minimal opaque event kind, room/object ID, and revision.Deliver optional friend, workout-invitation, and live-room lifecycle alerts. Per-set progress is not sent by push.
Legacy leaderboard safety reportsReporter account UUID, reported profile ID, time, and the fixed inappropriate_name category. New cross-account reporting is unavailable while competitive standings are disabled.Retain and finish reviewing reports submitted before the leaderboard was restricted.
Optional Garmin dataOpaque paired-device token, workout plans, sync status, and imported duration, calories, or heart-rate details when present.Pair a Garmin device, deliver plans, and import completed workout details.

The ordinary friend-profile API never returns email, Supabase Auth UUID, raw cloud state, historical set lists, workout notes, Garmin token, or heart-rate/calorie details. Separately, when the owner explicitly enables the default-off detailed-workout setting and keeps recent summaries enabled, a mutually confirmed, unblocked friend may open read-only exercise names, weights, repetitions, and sets for at most those same five recent workouts. This view has no edit, delete, copy, or share actions and never includes notes, raw cloud state, email, Auth UUID, Garmin token, or heart-rate/calorie data. Revoking either sharing setting, ending the friendship, blocking either account, or changing the active account closes the view and requires fresh authorization. A standard direct invitation contains only exercise names/identities and planned weight/repetition sets; after acceptance it opens as an independent editable local draft and later changes are not synchronized. A separate live invitation is limited to one accepted, confirmed friend. Its room shares the frozen plan and each participant's committed set completion, entered weight, and repetitions with the other participant, but no notes, email, Auth UUID, Garmin/health data, or credentials. Per-set updates travel only to the accepted room participants through Supabase Realtime, not through push.

3. Data that stays on your device

Depending on platform, your Training Profile — training split, 2–6 training days per week, goal, and energy balance — and any legacy locally blocked leaderboard-profile list are stored in first-party app preferences and are not uploaded. Local database/cache data, language/theme preferences, and local rest-timer notification scheduling also remain on the relevant device unless a workout field is included in the cloud state described above.

The phone apps do not ask for body weight, height, sex, location, contacts, camera, microphone, Photos, Motion & Fitness, or HealthKit access. Rest-timer alerts are optional local notifications. If optional system friend/live alerts are available on your platform, GymApp requests notification permission only when you choose to enable them and then registers the account-bound delivery token/endpoint described above. Garmin sensor/workout information is processed only when you use the optional Garmin feature and is also subject to Garmin's permissions and policy.

4. How we use data

  • provide, secure, troubleshoot, and maintain account and sync functions;
  • display workout history, progress, charts, muscle load, missions, achievements, ranks, and personalized training suggestions;
  • manage mutual friend requests, privacy choices, removals and blocks; show enabled self-reported progress and separately authorized read-only workout details only to confirmed friends; deliver bounded workout-plan invitations; and synchronize an accepted two-person live room;
  • when you enable them, deliver optional system alerts for bounded friend/invitation/live lifecycle events; direct set progress remains Realtime-only;
  • provide Garmin pairing and workout transfer when you choose to use it;
  • respond to support, privacy, and account-deletion requests; and
  • meet legal obligations and protect users and the service from abuse.

Where applicable, processing is necessary to provide the service you request, based on your choice to use optional Garmin/notification features, or necessary for security and legal compliance.

5. No tracking, advertising, or sale

GymApp has no advertising or third-party analytics SDK, does not access IDFA, and does not link GymApp data with data from other companies’ apps or websites for advertising or measurement. We do not sell personal data or share it with data brokers.

6. Service providers and optional integrations

We use Supabase to provide authentication, database, Realtime, and Edge Function infrastructure. Supabase processes data for us under its contractual and security terms. If you connect Garmin, information needed to pair and exchange workout data is also processed through the Garmin ecosystem under Garmin's privacy policy.

If you enable system alerts and the feature is available on your platform, delivery uses the platform/browser push provider, such as Apple Push Notification service, Firebase Cloud Messaging, or the push service selected by your browser. The provider receives the installation token/endpoint and a static localized alert with only a bounded event kind and opaque room/object ID and revision. The provider payload never includes a profile or workout name, exercise, weight, repetitions, notes, email, Auth UUID, session token, or arbitrary URL. Per-set live progress is not sent to a push provider.

We may disclose information when required by law, to protect rights or safety, or as part of a lawful business transfer with appropriate notice and safeguards. We do not permit providers to use GymApp data for their own targeted advertising.

7. Retention and account deletion

We retain active account and cloud data while your account exists so GymApp can sync and provide its features. A standard unanswered workout invitation expires after seven days. Its exercise/plan payload becomes eligible for tombstoning 24 hours after decline, cancellation, or expiry, or 30 days after acceptance; bounded cleanup runs when either participant next refreshes Friends or the invitation inbox, so a dormant row may retain its payload until that cleanup or account deletion. Its ID/status/revision/idempotency tombstone and other friend/request/block/privacy lifecycle records remain account data until removed by product lifecycle rules or account deletion.

A waiting or ready live room expires seven days after creation; an active room expires 24 hours after the owner starts it. Scheduled bounded cleanup runs every five minutes. The frozen plan, summary, and per-participant progress become eligible for purge 24 hours after cancellation/expiry or 30 days after completion. The terminal room and all dependent rows become eligible for deletion 31 days after it ends. Because each pass is bounded, a backlog can delay cleanup beyond an eligibility threshold.

A notification delivery address stays active while alerts are enabled and the signed-in client refreshes it. Authenticated revocation scrubs the raw token/endpoint and Web Push keys immediately. An active installation not refreshed for 180 days is scrubbed during bounded dispatcher cleanup; its scrubbed tombstone is eligible for deletion after 30 days once no delivery row refers to it. Completed, dead, or expired notification intents and their delivery rows are eligible for deletion 30 days after completion. Live join/start/finish/close alerts expire after one day; a live invitation may remain pending only until its seven-day invitation deadline, and no pending delivery window exceeds seven days.

Pending safety reports remain until review; resolved reports are normally removed within 90 days, and reports are also deleted when the reporter or reported profile is deleted. On iOS, permanently delete your account through Profile → Account, privacy & deletion → Delete Account and confirm the irreversible request. In another GymApp version without that control, contact support for deletion. A successful request deletes the Supabase Auth user and associated active cloud records, including user state, profile, private social graph/projections/invitations/live rooms, notification installations/outbox, reports, and Garmin cloud records. The app then clears the local account session and account data on that device.

Deleting the app from a device does not by itself delete the cloud account. Operational backups and security records may remain isolated until the service provider’s limited backup cycle expires, and information that law requires us to retain may be kept only for that required period. Such records are not restored as an active account or used for product personalization.

If in-app deletion cannot complete or you no longer have access to the account, contact support@gymapptracker.com.

8. Your choices and rights

You can edit or delete workouts, decline local or system notifications, choose not to connect Garmin, control each friend-visible category, decline or cancel requests/invitations, leave a live workout, remove or block a friend, export a workout backup, sign out, and delete your account. Turning off either recent-summary or detailed-workout sharing immediately closes any open read-only workout detail. Removing or blocking immediately denies that profile friend-detail access and closes pending workout invitations and any open live room between you; switching accounts also closes and clears the prior account's friend details. Depending on your location, you may also have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to a data protection authority. Contact us to exercise a right; we may need to verify the account before acting.

9. Security and international processing

GymApp uses HTTPS, access controls, Supabase Row Level Security, and protected platform storage where supported; the iOS app stores session secrets in iOS Keychain. No system is perfectly secure, so keep your credentials private and contact us if you suspect misuse. Providers may process data in countries other than yours; where required, we use contractual or other lawful transfer safeguards.

10. Children

GymApp is a general fitness log and is not directed to children under 13 or the higher minimum age required in their country. We do not knowingly collect a child’s data without the authorization required by law. Contact us if you believe a child has provided data improperly.

11. Changes

We may update this policy when GymApp’s features, providers, or legal obligations change. We will update the effective date and provide additional notice in the app when a change materially affects your choices.