This policy explains how the GymFactor team (“we,” “us,” or “our”) handles personal data in GymFactor. It is written for a consumer fitness app, not as medical or legal advice. Apple Health data is never used for marketing or advertising and is never sold.
Questo documento è disponibile solo in inglese.
Who is responsible
The data controller (and, where Apple processes data solely on your device or in your iCloud account, the party offering the app) is the GymFactor team.
Email: info@gymfactor.app
GymFactor does not require you to create an account with us. You can use the app as a guest. We do not operate a social network.
Data we process
2.1 Information you enter
Depending on how you use the app, this may include name or display name, training goal, experience, days per week, split, units, bar weight, gender, body weight, height, and the workouts and sets you log (exercises, weight, reps, rest, notes associated with a session).
This data is stored on your device using Apple's on-device database (SwiftData). If you are signed into iCloud and CloudKit sync is available, Apple may mirror that store to your iCloud account so it can appear on your other Apple devices. We do not operate a separate cloud copy of your workouts.
2.2 Apple Health (HealthKit)
If you choose to connect Health, the iPhone app may read (with your permission):
- Body mass (weight)
- Height
- Date of birth
- Biological sex
The Apple Watch app may, during an in-progress workout and with your permission:
- Read heart rate and active energy
- Write a strength-training workout to Apple Health when the Watch session ends
Health access is optional. You can deny or later revoke it in iOS Settings → Privacy & Security → Health, or in the Health app. HealthKit data is used only to set up your profile, show live Watch metrics, and save the Watch workout to Health — not for advertising, not sold, and not used for other apps' marketing.
2.3 Camera and photos (plate scan)
If you use scan, you may capture a photo or pick one from your library. The image is sent to estimate weight. Scan photos are not saved in your workout database. The scan service holds the image in memory for the request and does not keep a photo archive. The image is processed by OpenAI to return a weight estimate. OpenAI's processing is subject to OpenAI's privacy policy.
You should not scan photos of other people or anything you do not have the right to process.
2.4 Purchases
If you subscribe to GymFactor Pro, Apple processes the payment. We receive subscription status (for example, whether Pro is active and an expiration date) through RevenueCat, using Apple's purchase receipts — not your card number.
2.5 Diagnostics, configuration, and notifications
We use Google Firebase for:
- Crashlytics — crash and non-fatal error reports, device/app metadata, and optional breadcrumbs so we can fix bugs. We may attach a technical identifier; we do not ask Crashlytics to store your name or workout history.
- Remote Config — feature flags such as whether scan is enabled and minimum app version.
- Cloud Messaging — a push token so we can deliver remote notifications if you allow them. Local notifications (for example a rest timer) stay on device.
We do not currently use a separate Firebase Analytics marketing SDK in the app code. Google's Firebase services may still process technical data as described in Google's documentation.
2.6 Device permissions
The app may request camera, photo library, Health, notifications, and (in development) local network access for a scan server. iOS system prompts explain each request. You can change permissions in Settings.
Why we use data
- Provide logging, last-session memory, routines, progress charts, and Watch companion features
- Import profile fields from Health when you ask
- Estimate weight from a scan you start
- Unlock GymFactor Pro and restore purchases
- Send rest-timer or other notifications you enable
- Keep the app working (crash reports, remote flags, force-update thresholds)
- Respond to privacy or support emails you send us
We do not sell your personal information and we do not use HealthKit data for advertising.
Legal bases (EEA/UK and similar)
Where GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Service you request (logging, subscriptions you buy)
- Consent — Health, camera/photos, and notifications (you can withdraw in iOS Settings)
- Legitimate interests — security, crash diagnostics, and keeping the Service reliable, balanced against your rights
- Legal obligation — if we must retain or disclose information
Health and scan images can be special-category or sensitive data. We process them only with your permission and for the fitness features you invoke.
Who we share with
We share data only as needed to run the Service:
- Apple — App Store, iCloud/CloudKit (your account), HealthKit (your Health database), Push
- OpenAI — scan images and related prompts, for weight estimation only
- Google (Firebase) — Crashlytics, Remote Config, Cloud Messaging
- RevenueCat — subscription entitlement status
We may disclose information if required by law or to protect rights, safety, or the Service. If the product is transferred, data practices will remain subject to this policy or a successor notice.
Processors may be located in the United States or other countries. Where required, we rely on appropriate transfer tools offered by those vendors, such as Standard Contractual Clauses.
Retention
- On device — until you delete the data in-app (where available) or uninstall the app
- iCloud — until you delete the app's iCloud data via Apple's iCloud settings, or your Apple ID no longer syncs it
- Apple Health — remains in Health until you delete those samples in the Health app
- Scan images — not stored by us after the request; OpenAI retains data per its policy
- Crash and config — kept by Firebase for their standard product periods
- Purchases — Apple and RevenueCat keep records needed to provide and restore subscriptions
- Emails you send us — as long as needed to handle your request
The app does not currently offer a CSV export or in-app “delete all cloud data” button. Uninstalling removes local data on that device. To request access, correction, or deletion of information we hold (for example email correspondence), contact us. We cannot delete data that exists only in your Apple ID, iCloud, or Health without you using Apple's tools.
Security
We rely on Apple's device encryption, App Transport security, and vendor security for cloud processors. No method of transmission or storage is 100% secure. Do not photograph sensitive documents when scanning plates.
Your rights
EEA/UK/Switzerland: you may request access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior processing. You may complain to your local supervisory authority.
California and similar US state laws: we do not sell or share personal information for cross-context behavioral advertising as those terms are commonly defined. You may request access, deletion, and correction of personal information we hold, and we will not discriminate against you for exercising rights. Health and precise location are not used for ads. We do not have actual knowledge of selling the personal information of consumers under 16.
To exercise rights, email info@gymfactor.app. We may need to verify your request. We will respond within the time required by applicable law.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it. Users 13–15 should use the app with a parent or guardian where local law requires.
Automated decisions
Scan uses an AI model to estimate weight. That estimate is not used to legally or similarly significantly affect you; you confirm or override it before logging. Training plans are rule-based templates from the profile you enter, not credit or employment decisions.
Changes
We may update this policy. The effective date will change. Material changes will be posted here and, where required, noted in the app. Continued use after the effective date means you accept the updated policy where the law allows.
Contact
Privacy questions and requests: info@gymfactor.app
Email info@gymfactor.app — see also the Terms & Conditions.