1. Who this policy is from
Gym-OS is gym management software. It comes in two parts: a desktop application your gym runs at its front desk, and the Gym-OS mobile app that members and trainers install on their phones. This policy covers the Gym-OS Android app published as com.gym_os.app, the matching iOS app, and the connected desktop and server software. It is written mainly for the mobile app, because that is the part you installed yourself.
Two organisations handle your data, and it matters which is which:
- Your gym. It decides who becomes a member, what a membership costs, which classes run and who may attend. It holds your membership record. Under the GDPR your gym is a controller of your data.
- Gym-OS. We write the software and operate the servers your gym's records live on. For your app account and the training data you record for yourself, we are a controller too — a joint controller with your gym. For records the gym creates about you, we act on the gym's instructions.
Gym-OS is operated by the Gym-OS development team. The developer account named on the app's store listing is the same party responsible for this policy. You can reach us about anything on this page at [email protected]. If your question is about your membership, your bill or a class, your gym will answer faster, but you may always come to us instead and we will pass it on.
2. The short version
- We collect what the app needs to work, and nothing to sell.
- There are no advertising SDKs and no third-party analytics or tracking libraries in the app. We have never sold personal data and will not.
- Your workouts, measurements, attendance and check-ins are health data. We treat them as the sensitive category the law says they are.
- Your fingerprint and face are never sent to us. Your card number is never sent to us.
- Location is only read while the app is open and you are looking for a gym, and it is never kept.
- You can export your data and request deletion from inside the app, in Settings, without asking anyone.
3. What we collect, and why
Account and identity
When you create an account or claim a membership your gym already set up, we collect your first and last name, a username, your email address, gender, date of birth, an optional phone number, and an optional profile photo. Your password is stored only as a bcrypt hash — we cannot read it, and neither can your gym.
We need this to give you an account, to let gym staff recognise you as the member standing at the desk, and to email you about bookings, membership and payments. Gender and date of birth come from the membership record gyms keep and are used for age-restricted classes and the gym's own reporting.
Health and fitness data — a special category
The app records, when you use those features:
- Workout logs — exercises, sets, reps, weights, session duration and any notes you write.
- Body measurements — body weight, body fat percentage, chest, waist, hip and bicep measurements, and your notes against each entry.
- Class bookings and attendance — what you booked, whether you turned up.
- Check-in history — when you scanned in and out at your gym, and the streaks and weekly summaries the app calculates from that.
This is data concerning health under Article 9 of the GDPR, and it gets stricter protection than the rest. Our lawful basis for processing it is your explicit consent under Article 9(2)(a), which you give by choosing to log a workout, save a measurement, book a class or scan in. You can withdraw that consent at any time by deleting the entries, by leaving the gym in the app, or by deleting your account — withdrawing does not undo processing that already happened.
If a trainer at your gym is assigned to you, that trainer can see the logs and measurements you record at that gym. That is the point of having a trainer, but you should know it before you type.
Location
The app asks for approximate and precise location, and only ever while you are using the app — there is no background location access, and the app cannot read your position when it is closed. It is used in one place: the Discover screen, to find gyms near you and sort them by distance.
Your coordinates are sent with that search so the server can calculate distances, and they are used for that calculation only. We do not store them against your account and we do not build a location history. If you decline the permission, Discover still works — the list simply is not sorted by distance.
Camera and photo library
The camera is used for two things: scanning the QR code at your gym to check in and out, and taking a profile photo if you want one. QR codes are decoded on your device; what reaches our server is the gym identifier and the time, never an image. The camera preview is not recorded and nothing from it is uploaded.
Photo library access is requested only when you choose an existing picture as your profile photo. We read the one image you pick. The app does not browse, scan or index your gallery.
Biometrics — these never reach us
You can protect sensitive settings with your fingerprint, Face ID or iris. This runs entirely inside your phone's operating system: the device checks your biometrics against what is enrolled on it and tells the app one thing, yes or no.
Gym-OS never receives, sees, stores or transmits your fingerprint, face or iris data. It never leaves your device, it is not sent to our servers, and there is nothing for us to hand over or lose. Turning the feature off changes nothing about the biometrics themselves — they were never ours.
Push notifications
If you allow notifications, the app registers a push token issued by Expo's push service and sends it, along with your platform (iOS or Android), to our server, where it is stored against your user record. It is an address for your app installation, not an identity — but it is personal data, so we say so.
We use it for booking reminders, class changes and cancellations, membership and payment notices, and messages from your gym or trainer. Turn notifications off in your phone's settings and the token stops working; deleting your account removes it.
Payments
Payments in the app — memberships, invoices and the gym store — are processed by PayPal. Checkout opens PayPal's own pages inside the app. Everything you type there, including card numbers, PayPal credentials and CVV, goes to PayPal directly.
Gym-OS never receives, processes or stores your card number, CVV or bank details. What we do store is the payment record: the amount, the currency, the date, the status (completed, declined, refunded), the PayPal order identifier and what the payment was for. Your gym needs that to know your membership is paid, and tax law requires it to be kept.
PayPal is an independent controller for the payment it handles, under its own privacy statement. Read it at paypal.com.
Reviews you write
If you review a class, the rating and text are visible to other members of that gym and to the gym's staff, shown next to your name. You can delete your own reviews in the app.
What is kept on your device
Your login token and a cached copy of your profile are stored in your phone's secure storage — the iOS Keychain or the Android Keystore — not in ordinary app files. Preferences such as your theme, your favourite gyms, your check-in goal and, if you asked to be remembered, your login identifier are stored locally on the device. Signing out clears the token.
Technical data
Our servers log the usual request metadata — IP address, timestamp, which endpoint was called, and whether it failed — to keep the service running, debug faults and detect abuse. When you open the gym map, the map tiles are rendered by the platform's own maps SDK (Google Maps on Android, Apple Maps on iOS), which sees the map request.
4. Our lawful bases, in one place
- Performance of a contract (Article 6(1)(b)) — your account, memberships, bookings, check-ins, payments and the notifications that go with them.
- Explicit consent (Article 9(2)(a)) — all health and fitness data: workouts, measurements, attendance, check-in history.
- Consent (Article 6(1)(a)) — location, camera, photo library and push notifications. Each is a permission you grant and can revoke in your phone's settings.
- Legitimate interests (Article 6(1)(f)) — keeping the service secure, preventing fraud and abuse, and fixing faults. We balance this against your rights and keep it to what security actually needs.
- Legal obligation (Article 6(1)(c)) — keeping payment and invoice records for the period tax and accounting law requires.
5. Who else sees your data
- Your gym. Staff at the gym you belong to can see your profile, membership and plan, bookings and attendance, check-in history, payment records, and the training data you record at that gym. Staff at other gyms cannot — access is scoped to the gym you joined.
- PayPal. Payment processing, as described above.
- Railway. Our hosting provider. The application and the database run in Railway's European region, and Railway holds the data at rest on our behalf as a processor.
- Expo. Delivers push notifications to your device and serves over-the-air updates to the app. It handles the push token and the message payload.
- Our email provider. Delivers transactional email — password resets, verification codes, booking and membership notices.
- Authorities, where we are legally required to disclose, and only to the extent required.
That is the whole list. We do not sell personal data, we do not share it with advertisers or data brokers, and there is no advertising or analytics SDK in the app to do so behind our backs.
6. Where your data is stored
Application servers and the database are hosted on Railway in the European Union (Europe West). Data stays in the EEA except where a provider above necessarily operates internationally — PayPal, Expo and the platform maps SDKs — in which case the transfer rests on the safeguards in Chapter V of the GDPR, such as the European Commission's standard contractual clauses.
7. How long we keep it
- Account, profile and training data — for as long as your account exists.
- After a deletion request — removed within 30 days.
- Payment and invoice records — kept for the retention period tax and accounting law imposes on your gym, which is longer than the rest and survives account deletion. The amount, date and status remain; there is no card data in them to keep.
- Push tokens — replaced when they change, removed with the account.
- Server logs — only as long as they are useful for security and debugging.
8. Your rights, and how to use them
Under the GDPR you have the right to:
- Access — get a copy of the data we hold about you.
- Rectification — correct anything wrong. Most of your profile is editable in the app.
- Erasure — have your data deleted.
- Portability — receive your data in a machine-readable format.
- Restriction and objection — have processing paused, or object to processing we base on legitimate interests.
- Withdraw consent — for health data, location, camera, photos or notifications, at any time.
- Complain — to your national data protection authority, wherever you live or work in the EEA.
Two of these you can exercise yourself, right now, without contacting anyone. In the app, open Settings:
- Export my data downloads a CSV containing your profile, your class bookings and your workout logs.
- Delete my account registers a deletion request. We confirm it by email and remove your data within 30 days.
For anything the in-app export does not cover — a complete copy, a correction, an objection — write to [email protected]. We answer within one month, as Article 12 requires. Because your gym is a joint controller, you may also raise any of this with your gym directly; whichever of us you ask, you get an answer.
Google Play also requires an external web resource for account deletion. Use Delete your Gym-OS account and data if you cannot open the app or need the Play Console deletion link.
9. Children
The Gym-OS app is not directed at children under 16 and we do not knowingly create accounts for them. Do not sign up if you are under 16. Where a gym enrols a minor as a member, it is the gym's responsibility to obtain and hold the consent of a parent or guardian under Article 8. If you believe a child has an account, tell us at [email protected] and we will delete it.
10. How we protect it
- All traffic between the app and our servers runs over HTTPS.
- Passwords are stored as bcrypt hashes and are never readable, by us or by your gym.
- Login tokens live in the operating system's secure storage — Keychain or Keystore — rather than in ordinary app storage.
- Access is scoped by role and by gym, so staff only reach the members of the gym they work for.
- Card data never enters our systems, so it cannot leak from them.
No system is perfectly secure. If a breach ever affects your data, we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.
11. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the change relies on consent we will ask again rather than assume.
12. Contact
Privacy questions, rights requests and complaints: [email protected]. Everything else about your membership, your classes or your bill: your gym, which will reach us if it needs to.