Your information

Privacy Policy

Effective July 24, 2026

This policy explains how Gymnasou processes information when you use our website, mobile app, and services provided with participating gyms. A participating gym also handles the member information it needs to provide its services.

Information we process

The information involved depends on the features you use:

  • Account and profile. Your name, email address, phone number, profile photo, date of birth, gender, account role, language and appearance preferences, and, where relevant for a gym owner, business and tax details.
  • Gym activity. Your participating-gym relationships, membership and subscription details, entitlements and passes, class bookings, check-ins, QR credential status, gym news interactions, and related operational records.
  • Training and fitness. Training plans, exercises, workout sessions, set logs, weekly goals, weight, body-fat percentage, measurements, progress notes, and other information you choose to record.
  • Device and service data. Authentication and security information, app installation identifiers, push notification tokens and preferences, device platform and name, app version or variant, and technical request information needed to operate and secure the service.
  • Support requests. Your name, email address, preferred language, and the message you choose to send through the support form.
  • Optional product analytics. Only after you consent, selected page views and product actions, device and locale context, and sanitized first-touch campaign information. We exclude names, email addresses, phone numbers, free-text form content, arbitrary query parameters, and full referrer URLs from analytics.

Why we use information

We process information where needed to provide the service, meet our obligations, pursue legitimate operational and security needs, or act on your consent.

  • Create and secure accounts; connect members with participating gyms; manage memberships, bookings, check-ins, passes, training, workouts, and account preferences.
  • Send service messages, requested password or account assistance, gym updates, and push notifications you have enabled.
  • Authenticate users, prevent misuse, diagnose failures, protect accounts, and maintain reliable service operations.
  • Understand and improve Gymnasou when you have chosen to allow product analytics.
  • Comply with applicable law, resolve disputes, and establish or defend legal claims.

Who receives information

We share only what is relevant to provide and protect Gymnasou:

  • Participating gyms. A gym receives the member, membership, booking, check-in, pass, and training information it needs to provide and administer its services.
  • Supabase. Provides database hosting, authentication, storage, and related backend infrastructure.
  • Vercel. Hosts and delivers the Gymnasou web service and backend.
  • Expo. Supports mobile app delivery and routes push notifications when notifications are enabled.
  • PostHog. Processes consent-gated product analytics through its EU service.
  • We may disclose information where required by law, to protect people and the service, or as part of a business reorganization with appropriate safeguards.

We do not sell your personal information or use it for third-party advertising.

Your analytics choice

Gymnasou does not send product analytics while your choice is unknown, declined, or withdrawn. If you accept, PostHog EU helps us understand product journeys and improve the service.

Accepted activity may use an anonymous identifier before sign-in and your pseudonymous Gymnasou account identifier after sign-in. Analytics is not enriched with your name, email address, phone number, or free-text content.

You can enable or disable analytics below or in your account settings at any time. Disabling it stops future collection and resets the analytics identity on this device.

Analytics preferences

Choose whether Gymnasou may collect product-usage analytics. You can change this at any time.

Analytics are disabled.

Retention and account deletion

We keep information only for as long as needed for the service, security, legal, accounting, and dispute-resolution purposes that apply to it. Retention periods can differ by record and participating gym.

Account deletion removes your login, profile, personal measurements, push devices, notification state, analytics consent, and other identity-bound data. Gym-owned subscription, booking, check-in, archived training-plan, and completed-workout history may remain de-identified as “Deleted member” so the gym can maintain legitimate operational records; it cannot be used to restore or relink your identity.

Support requests are kept only as long as needed to respond, maintain the support history, protect the service, and meet applicable legal obligations.

Account deletion stops future account-linked analytics and resets the local analytics identity. Product analytics already collected with consent remains under a pseudonymous account identifier until removed under the normal PostHog retention configuration and is not used to reconstruct or relink a deleted profile.

Security

We use technical and organizational safeguards designed to protect information, including access controls and restricted service credentials. No online service can guarantee absolute security, so please use a unique password and contact support if you suspect unauthorized access.

Your choices and rights

Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a portable copy of your personal information, and you may withdraw consent without affecting earlier lawful processing. You can update some information and preferences in Gymnasou, change analytics consent above, or use the support link below.

You may also lodge a complaint with the data-protection authority where you live or work. We may need to verify your identity before completing a privacy request.

Contact and requests

Contact Gymnasou support with privacy questions or requests. If you want to erase your Gymnasou account, use the direct account-deletion flow.