Privacy and
Data Protection.
What we use across the website and apps, who receives it, and how to exercise your rights.
Last updated: September 29, 2026
1. Who handles your data
GymRat+ provides the web and mobile service and handles data associated with your account and use of the app. Contact security@gymratplus.com for access, correction, or deletion requests.
2. Data we receive
When you create an account, we receive your email, name, account identifier, credentials or sign-in provider identifiers and, if you provide them, profile photo, phone number, birth date, gender, language, and time zone. As you use features, we store goals, height, weight, body measurements, workouts, sets, effort, cardio, food, water, supplements, progress photos, messages, attachments, coach notes, and preferences. We also process subscription identifiers and payment status, push tokens, technical session data, errors, and service usage. If you contact us through a form, we receive the name, email, and message you provide.
3. Google and Apple sign-in
If you choose Google sign-in, we receive the account identifier, email, name, and profile photo when available; identity tokens verify the session. We do not request Gmail, Drive, Contacts, or Calendar access. This information lets us create or link your account, display your profile, and secure sign-in. Your name and, in coach features, linked students’ names or emails may be included in Kyro requests when a feature needs to identify them; those requests pass through the AI providers described below. We also share identity data with authentication and hosting infrastructure and with a coach you have linked. We do not sell data obtained from Google or use it for personalized advertising or to train general-purpose AI models. We handle Apple identity data you choose to share for the same features.
4. Purposes and legal bases
We use account data to authenticate you and provide the service; fitness and nutrition records to show history, metrics, and plans; payment data to manage access; and technical data for security, abuse prevention, diagnostics, and product improvement. Depending on the context, the legal basis may be performance of the requested service, your consent where required, or compliance with legal obligations. Optional data can be withheld, though some features may then be unavailable.
5. Health, body data, and Apple Health
Weight, measurements, body photos, activity, nutrition, and other information you provide may be sensitive. We use it only for the fitness features you request, including automated recommendations, and do not sell it. On iPhone, if you authorize Apple Health, the app may write workouts, energy, distances, water, nutrition, weight, and body-fat percentage; it may also read workouts to prevent duplicates. You can revoke these permissions in device settings. Apple Health data remains subject to Apple's controls; records created in GymRat+ may also be stored in our account.
6. Photos, camera, and files
The camera or photo library is used when you choose a profile, progress, or meal photo. Progress photos are stored in the cloud and the app limits who can retrieve them, but the current storage can generate hard-to-guess public URLs; do not upload images you would not trust to that storage. A profile photo may appear on public profiles or to other users. A meal photo sent to the scanner is transmitted to the AI provider to estimate foods and macros. Student-coach chats may contain text, images, audio, video, or documents you choose to attach. We do not activate the camera or microphone to capture content without your action and system permission.
7. Artificial intelligence
Kyro produces responses, routines, plans, summaries, and estimates from messages and relevant profile data; the meal scanner and progress analysis may also send images. Requests pass through Vercel AI Gateway and a model provider such as OpenAI. Outputs can be wrong and do not replace medical or professional advice. We do not use data received from Google APIs to develop, improve, or train general-purpose AI models. AI providers may have different retention terms; we do not claim every request is immediately deleted.
8. Integrations and payments
If you connect Strava, we access activities you authorize, such as type, date, distance, duration, pace and, when available, heart rate, elevation, power, or location data. We store connection credentials until you disconnect. Polar processes new subscriptions bought on the web; Apple or Google may handle older or store-based subscriptions. We receive transaction identifiers and status, not full card numbers. Cancellation and refund steps depend on the provider named on your receipt.
9. Who receives data
We use providers for authentication and database (Supabase), hosting, storage, and delivery (Vercel), AI (Vercel AI Gateway and the model provider), transactional email (Resend), error monitoring (Sentry), web analytics where applicable (Google Analytics and Vercel Analytics), notifications, payments (Polar and stores), and chosen integrations (Strava). They receive the data needed for their respective functions. If you link to a coach, that coach may access workouts, nutrition, progress, photos, messages, and notes needed for coaching. Content you publish on a profile or through a shared link is visible to people with access to it.
10. Cookies, analytics, and diagnostics
The website uses cookies or local storage needed for session, language, security, and preferences. Google Analytics depends on configuration and analytics consent; the web banner offers controls for optional categories. Vercel Analytics and Sentry may receive technical events, errors, traces and, where enabled, session replay to diagnose issues. Native apps may also use technical identifiers and notification tokens. We do not claim all diagnostics are controlled by the cookie banner.
11. Retention and deletion
We retain account data while the account exists and as needed to provide the service, manage legal obligations, payments, disputes, and security. You can request account deletion in the app using email verification or at security@gymratplus.com. The current feature deletes the account and related records from the main database; backups, technical logs, payment and authentication systems, and some externally stored files may need additional deletion or be retained where law permits. If you need residual files or data removed, identify them in your request. Disconnecting Strava stops future access but does not itself delete already imported records.
12. Security
We use HTTPS/TLS in transit, app access controls, authentication, and safeguards offered by our providers. Passwords are stored through hashing mechanisms managed by the authentication infrastructure. Some images, such as avatars, may be in public storage; we do not describe all files as private or offer end-to-end encryption. No system can guarantee absolute security.
13. Your rights and contact
You may request access, update, correction, portability where available, objection, consent withdrawal, and deletion, subject to legal exceptions. Write to security@gymratplus.com with your account and request; we may ask for reasonable identity verification. You may also complain to the competent data protection authority and exercise any rights provided by applicable law in your country.
14. Minors, transfers, and changes
The service is intended for people old enough to contract under their local law; it is not directed to minors without legally required authorization. The providers described may process data outside your country. If our practices materially change, we will update this policy and communicate changes where required.