Privacy Policy — GymMind IA
Effective date: 10 October 2026 Last updated: 10 October 2026 Version: 1.0 Applies to: the GymMind IA mobile application for iOS and Android, its Apple Watch companion, and the related backend services.
Table of contents
- The short version
- Who is responsible for your data
- Why we process health data at all
- What we collect
- Apple Health (HealthKit)
- Apple Watch
- AI features and the AI provider
- Advertising
- Legal bases for processing
- Who we share data with
- International transfers
- How long we keep data
- Deleting your account
- Data stored on your device
- Your rights
- Children and young people
- Security
- Changes to this policy
- Contact
1. The short version
This summary is for your convenience. The detailed sections below are what govern.
- All training and nutrition content in GymMind IA is generated by artificial intelligence. No qualified professional reviews it before you see it. You must have it supervised by a doctor or another qualified professional.
- We are a tool that facilitates routines and personal progress tracking. We do not diagnose, treat, prescribe, or provide medical or nutritional care.
- We process health data about you — your weight, your height, your age, your allergies, what you eat, what you lift. Under EU law this is a special category of personal data. We only process it because you give us your explicit consent, and only to make the app work.
- Your Apple Health data never leaves your device, and is never used for advertising.
- We show non-personalised advertising only. We do not build advertising profiles about you, we do not track you across other companies’ apps and websites, and we never use your health or workout data for advertising.
- The text you type into the AI coach and chat is sent to an AI provider in the United States to produce a reply. That provider does not retain it. We explain exactly what is sent in section 7.
- We do not use analytics or crash-reporting trackers in the app.
- You can delete your account from inside the app. Section 13 explains precisely what that removes.
2. Who is responsible for your data
The data controller is:
| Controller | Daniel David Bernal Oropeza, a natural person resident in Spain who develops and operates GymMind IA independently |
| NIF/NIE | Z1341140S |
| Address | Cuesta Lozal 7, 2C, 23400 Úbeda (Jaén), Spain |
| Contact email for privacy matters and support | soporte@gymmindia.app |
| Website | https://gymmindia.app |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), www.aepd.es |
The controller has not appointed a Data Protection Officer, because the law does not require one for this service.
Your data is processed under the EU General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
“We”, “us” and “our” in this document mean the controller above. “You” means the person using the app.
3. Why we process health data at all
This section explains the purpose of the whole service, because it is the reason any of your health data is processed.
GymMind IA generates training routines and nutrition guidance using artificial intelligence, and gives you tools to track your own progress. That is the entire service.
To generate a routine or a recipe that is not actively unsuitable for you, the AI needs to know some things about your body: roughly how old you are, how much you weigh, how tall you are, how experienced you are with training, what you are trying to achieve, and what you cannot eat. That is why we ask for health data, and it is the only reason we process it.
Three things follow from this, and they are important enough that we repeat them in our Terms and Conditions:
- The content is machine-generated. A language model produces it. It is not written or checked by a doctor, a physiotherapist, a dietitian, or a certified trainer before it reaches you. It can be wrong, incomplete, or unsuitable for your particular body and circumstances.
- It must be supervised by qualified professionals. Our content is a starting point for a conversation with a doctor or a qualified professional, not a replacement for one. You should get medical clearance before you start any exercise or nutrition programme.
- We only facilitate. We provide routines and personal progress-tracking tools. We do not diagnose, we do not treat, we do not prescribe, and we do not provide medical or nutritional care. No doctor–patient or dietitian–client relationship is created by your use of the app.
4. What we collect
We only collect what the app actually uses. Below is the complete list, grouped by kind.
4.1 Identity and account data
Collected when you create an account and kept on our servers.
- Your email address.
- Your name, as your sign-in provider reports it. If no name is available, we derive a display name from the first part of your email address.
- Your profile picture URL, if your sign-in provider supplies one. We store the link, not a copy of the image.
- A Firebase user identifier, which links your account to the authentication service.
- Which sign-in provider you used.
- A technical record of the authentication response from your provider.
- Your account’s role, whether it is active, and the dates it was created and last updated.
We never receive or store your password. Sign-in is handled entirely by Google, Apple and Firebase Authentication. Our database has a password column for historical reasons, and for every account it holds a random value that is never used to log anyone in.
We also issue our own access and refresh tokens so the app can stay signed in.
4.2 Health and biometric data
This is special category data. Data concerning health is a special category of personal data under Article 9 of the General Data Protection Regulation. We process it only on the basis of your explicit consent, which you give during onboarding and can withdraw at any time. See section 9.
Stored on our servers as part of your profile:
- Age — stored as a whole number of years. We do not store your date of birth.
- Sex or gender —
male,femaleorother. Optional. - Weight, in kilograms.
- Height, in centimetres.
- Fitness level — beginner, intermediate or advanced.
- Your goal — for example losing weight, gaining weight, building muscle, or body recomposition.
- Your preferred units — metric or imperial.
- Dietary restrictions, chosen from a fixed list. This list includes allergen-related entries such as gluten-free, lactose-free, dairy-free, egg-free, peanut-free, nut-free, soy-free, fish-free, shellfish-free and sesame-free, and the entries halal and kosher.
- Allergy notes — free text, up to 280 characters, which you write yourself.
Note on
halalandkosher: selecting either may reveal your religious beliefs, which is also special category data under Article 9. We process these values solely to exclude foods from generated recipes, on the basis of the same explicit consent, and we never use them for advertising or any other purpose.
Also stored:
- A body-weight history: each entry holds a weight in kilograms, the date it applies to, whether you entered it directly or it came from your profile, and an optional free-text note.
- A daily record of your weight and your calorie total for a given day.
4.3 Workout and activity data
Stored on our servers:
- Workout sessions: a session identifier, an identifier generated by your device, the routine used and a snapshot of its name, the status (in progress, completed, abandoned), when it started and finished, how long it lasted, total volume lifted in kilograms, the total number of sets, and an optional free-text note you write.
- Set logs: for each set, the exercise, its position in the session, the set number, the weight in kilograms, the repetitions, the duration in seconds for timed exercises, whether it was a warm-up, the rest taken, when it was completed, the time your device recorded, and which device logged it — your phone or your watch.
- Routines you create or that are generated for you, including their names, descriptions, goals, estimated duration, the exercises in them, target sets, target repetitions, target rest, and any notes.
- Custom exercises you create.
We do not store heart rate, perceived exertion, or RPE/RIR values on our servers. The app has no field for them.
4.4 Nutrition data
Stored on our servers:
- Intake entries: for each entry, the date, the meal slot (breakfast, lunch, dinner or other), where it came from (a recipe, a manual entry, or the food catalogue), the recipe or food item, the quantity in grams or servings, and the calories, protein, fat and carbohydrates.
- Recipes generated for you, including which AI model produced them, the version of the prompt used, the ingredients, the steps and the nutritional values.
- Recipes you mark as favourites.
- Food searches that found no match — we store the name of the food you were looking for, together with your account and the date, so we can add missing foods to our catalogue.
Note on generated recipes: a recipe generated for you is stored in a shared catalogue, and if you have left your allergy notes empty it may later be shown to another user whose targets and restrictions match. The recipe content itself is served; your identity, your allergy notes and your profile are not.
4.5 AI conversation content
This is covered in full in section 7. In summary:
- Free-form AI chat messages are not stored by us. They are sent to our AI provider to generate a reply and are not written to our database.
- AI coach interview content is stored. When you set up a training plan, the coach asks you questions. We store your answers, including a free-text note in which you may describe injuries, limitations, muscles to prioritise, or exercises to avoid. We also store the conversation transcript — each message, whether you or the coach wrote it, and when — keeping the most recent 60 entries.
- Your coach notes are also copied onto the training plan we generate from them, and we store the plan and any coach suggestions made from it.
- Voice recordings. If you use voice entry to log food, the app records audio on your device and uploads it to our server, which holds it in memory only and forwards it to our AI provider for transcription. We do not store the audio, and our AI provider does not retain it (see section 7.3).
Because the free-text fields above can contain health information, anything you type into them is treated as special category data. Please only write what you are comfortable sharing.
4.6 Progress and gamification data
- Your experience points (XP), your current streak, your longest streak, and the date you were last active.
- An event log of how you earned XP: the type of event (a workout completed, a daily entry logged, a meal logged), the amount, the date, and a key that prevents double-counting.
Your level and rank are calculated from your XP; we do not store them separately.
4.7 Device and technical data
- The identifier your device generates for each workout session, so that offline work can be synced without being duplicated.
- The device clock time for logged sets, and which device recorded them.
- Your app language or locale.
- Daily AI usage counters — how many AI requests your account has made each day — so that usage limits can be applied.
- Server logs. We have not configured any log collection, storage, shipping or monitoring. Our API prints operational messages to the standard output of its container on our server. They exist only in the container runtime’s default output buffer, which the runtime discards on rotation or when the container is replaced (for example, at each deployment); we do not export, copy or keep them, and they are never sent to third parties. These messages do not contain IP addresses. They may contain your internal account identifier and your Firebase sign-in identifier, the name of a food item you typed, recipe titles and the photo search terms derived from them, the dates of body-weight entries, and technical values such as calorie targets and AI usage counts. They do not contain your AI messages or the AI’s replies, except that, when a recipe generation fails validation, a truncated excerpt of the model’s failed output may appear in these messages.
- If over-the-air updates are enabled, your app contacts Expo’s update service (Expo, United States) to check for a new version. That request reaches Expo with your device’s IP address and is subject to Expo’s own privacy practices.
4.8 Advertising identifiers
See section 8. In short: the Google Mobile Ads SDK, according to Google, collects device identifiers, diagnostic data and coarse location. We do not store advertising identifiers on our servers, and we hold no advertising profile about you.
4.9 What we do not collect
To be explicit, because their absence is itself a privacy fact:
- No analytics or product-tracking SDK. There is no Google Analytics, Firebase Analytics, Sentry, Crashlytics, Amplitude, Mixpanel, PostHog, Segment or comparable tool in the app. We use Firebase for authentication only.
- No crash-reporting service.
- No push notifications, and no push tokens — the app does not register for them.
- No camera or photo library access.
- No contacts, no precise location, and no address book access.
- No speech recognition on the device; transcription happens through our server (see section 7).
- No payment or card data. We have no purchase flow today. See section 8.4.
5. Apple Health (HealthKit)
This section is deliberately unambiguous, because Apple’s rules require it and because it matters.
What the app reads from Apple Health, on your iPhone, and only with your permission:
- Resting heart rate
- Active energy burned
- Step count
What the app writes to Apple Health: nothing from your iPhone. The iPhone’s Health integration is read-only by design. Your Apple Watch, separately, saves your completed strength-training workout to Apple Health (see section 6).
What we do with it: we display it to you inside the app, next to your own training data, so that you can see your resting heart rate, your active calories and your steps alongside your workouts. That is all.
And the commitments Apple requires us to make, which we make without reservation:
- Apple Health data is never used for advertising or marketing, by us or by anyone else.
- Apple Health data is never shared with advertising partners, data brokers, or any third party for advertising or marketing purposes.
- Apple Health data is never sold.
- Apple Health data read on your iPhone is not transmitted to our servers. It stays on your device and is used only to draw the screen you are looking at.
- Apple Health data is never used for any purpose other than showing it to you in the app, and we do not use it to improve or train any AI model.
- You can revoke the app’s access to Apple Health at any time in the iOS Settings → Privacy & Security → Health screen, or in the Health app itself. The app will simply stop showing those figures.
The permission text shown by iOS is: “To show you your heart rate, calories and steps alongside your workouts” and “To save your workouts to the Health app”.
6. Apple Watch
If you use the Apple Watch companion app:
What the watch reads from Apple Health, with your permission: your heart rate and your active energy burned, live during a workout.
What the watch writes to Apple Health: your completed workout, recorded as an indoor traditional strength-training session. This is saved to Apple Health on your device by the watch, in the ordinary way any workout app does.
Where heart rate and calories go:
- Live heart rate and calories are sent from your watch to your iPhone only, over Apple’s direct device-to-device connection, roughly every five seconds, so that the workout screen on your phone can display them. They are shown and then discarded.
- Your peak heart rate for a workout is kept in the watch app’s own local history, on the watch.
- Neither heart rate nor calorie data is ever sent to our servers. We have verified that no field for them exists anywhere in our backend.
What does reach our servers from the watch, by way of your iPhone, is the structure of the workout: the session identifiers, the timestamps, the sets you logged with their repetitions and weights, any time the session was paused, and whether the session was recorded without the phone present.
The watch also downloads exercise illustrations from the internet when it needs them (see section 10).
7. AI features and the AI provider
7.1 Who the provider is
The AI features in GymMind IA — the chat, the recipe generator, the food recogniser and the training-plan coach — are powered by a third-party AI provider.
That provider is Groq, Inc., a company based in the United States, reached at api.groq.com. The models used are open-weight models served by Groq:
| Feature | Model |
|---|---|
| AI chat and intent detection | openai/gpt-oss-20b |
| Recipe generation, food recognition, training-plan generation | openai/gpt-oss-120b |
| Voice transcription | whisper-large-v3-turbo |
The models can change. The AI endpoint and the model names are set by configuration, not fixed in the app, so the models named above may be updated without a new app release. If we change provider in a way that affects your data, we will update this policy and, where the change requires it, ask for your consent again.
7.2 What is sent to the AI provider
This is the part that deserves your attention, so we set it out feature by feature.
AI chat. We send the message you typed, word for word, together with a short context block containing your age, your weight in kilograms, your height in centimetres, your fitness level, and the date your profile was last updated. We do not send your name, your email, your account identifier, your sex, your workout history or your nutrition logs in the chat context.
Recipe generation. We send your per-meal calorie, protein, fat and carbohydrate targets (which are calculated from your profile), your goal, your full list of dietary restrictions, your allergy notes exactly as you wrote them, your language and the type of meal. We do not send your age, weight, height or account identifier.
Food recognition. We send the text you typed or dictated, word for word, along with our food catalogue so the model can match against it.
Voice transcription. We send the audio file you recorded.
Training-plan coach. We send your age, fitness level, goal and weight in kilograms; how many days a week you want to train, how long each session should be and where you will train; your free-text notes exactly as you wrote them — and these notes are where you may have described injuries or physical limitations; and a summary of your training history that we calculate ourselves from your logged loads and body-weight entries, consisting of your best lift per muscle group, how consistently you have trained, and your body-weight trend in kilograms per week. If one of your short answers cannot be parsed automatically, that answer is also sent to the model.
In every case, the data is sent in order to produce the output you asked for, and for no other purpose. We do not send your identity with it: the provider receives the content, not your name, your email or your account number.
7.3 What is stored, and what is not
- Free-form chat messages and the AI’s replies are not stored in our database. They exist for the length of the request.
- Coach interview answers and transcripts are stored, as described in section 4.5, together with the training plans and suggestions generated from them.
- Generated recipes are stored, along with the model and prompt version used to produce them.
- Audio recordings are not stored by our server; the file is held in memory for the length of the request and forwarded for transcription.
- We do not keep logs of your messages or the AI’s replies. The operational messages our API writes to its container output are described in section 4.7; they are not collected or kept in any log system. They do not contain your messages or the AI’s replies, except that, when a recipe generation fails validation, a truncated excerpt of the model’s failed output may appear in them.
- We do not use your content to train AI models.
What the AI provider does with it. Groq acts as our processor under its Customer Data Processing Addendum, which is incorporated into Groq’s Services Agreement that we accepted electronically. That addendum includes the European Commission’s Standard Contractual Clauses (Module 2, controller to processor) as the mechanism for transferring your data to the United States (see section 11). We have enabled Groq’s Zero Data Retention setting: Groq does not retain the inputs we send or the outputs it returns, and does not keep them in abuse-monitoring logs.
7.4 Other AI-adjacent third parties
Recipe photographs come from Pexels, a stock photography service. Our server searches Pexels using only the recipe’s title or ingredient names; no data about you is included in that search. The photograph itself is then loaded by your device directly from Pexels’ content delivery network, which means Pexels receives your device’s IP address. The photographer is credited in the app.
8. Advertising
8.1 Non-personalised ads only
GymMind IA shows advertising through Google AdMob (the Google Mobile Ads SDK, with Google’s User Messaging Platform for consent).
We request non-personalised advertising only. This is set in the app’s code as a fixed value: every ad request we make carries the non-personalised flag, and there is no configuration, no setting and no account state that can turn personalised advertising on.
We additionally tell Google, based on the age on your profile:
- to treat the request as child-directed if you are under 13;
- to treat you as under the age of digital consent if you are under 16;
- to cap the maximum ad content rating —
Gfor under-13s,PGfor under-16s, andTat most for everyone else.
If we do not know your age — for example before you have completed onboarding — we apply the most protective settings, not the least.
How ads are shown. We show interstitial and banner ads, at most 4 per app session and 8 per day. Ads are not shown on the screen of an active workout, except a banner on the rest timer and an ad at the transition between exercises.
8.2 Being honest about what “non-personalised” means
Non-personalised does not mean no data is involved, and we would rather say so than imply otherwise.
When a non-personalised ad is shown:
- An ad request is still made to Google’s servers. That request carries ordinary technical information such as your IP address, your device and operating system, your general app context, and your language.
- According to Google, its SDK collects device identifiers, diagnostic data and coarse location. Google may use device identifiers for purposes such as frequency capping, ad reporting and fraud prevention, even when the ad itself is not personalised.
- The ad you see is selected using contextual signals — such as coarse location and the kind of app you are using — rather than a profile built from your behaviour.
- That collection is Google’s, under Google’s terms, not ours.
What is never involved: your health data, your Apple Health data, your weight, your body measurements, your allergies, your workout logs, your nutrition logs, your AI conversations, or your email address. None of it is sent to Google for advertising, shared with any advertising partner, or used to select an ad.
8.3 Consent, and the choices you have
- On first launch, and whenever required, we show you Google’s User Messaging Platform (UMP) consent form. Your choices there are recorded by the UMP SDK.
- The app does not track you in the sense Apple defines: it does not link data collected in the app with data from other companies’ apps or websites for advertising. The app’s iOS privacy manifest declares that it does not track, and the app therefore does not show Apple’s App Tracking Transparency prompt.
- The AdMob app is not linked to Firebase, so no data passes between our authentication service and our advertising account.
- You can change or reset your advertising identifier, or ask the operating system to limit ad tracking, in your device’s own settings at any time.
- The whole advertising system is disabled entirely when no AdMob application identifier is configured, and there is a server-side switch that can turn ads off for everyone.
8.4 The planned ad-free option
We intend to offer a paid option to remove advertising in a future version. The app already has the technical means to record that an account is ad-free.
We are not announcing a price or a date, and nothing in this policy is a promise that this option will be released. If and when it is, we will update this policy to describe any payment data involved. Today, no purchase is possible and we hold no payment or card data whatsoever.
9. Legal bases for processing
We rely on the following legal bases.
| What we do | Data involved | Legal basis |
|---|---|---|
| Create and operate your account; authenticate you | Identity and account data (4.1) | Contract — GDPR Art. 6(1)(b). We cannot provide the service without it. |
| Generate training routines and nutrition guidance; show you your own progress | Health and biometric data (4.2); the free-text health information in your coach notes and allergy notes (4.5) | Explicit consent — GDPR Art. 9(2)(a), with Art. 6(1)(a). This is the only realistic basis for processing special category health data in a consumer fitness app. You can withdraw it at any time. |
| Record your workouts, nutrition and progress | Workout, activity and nutrition data (4.3, 4.4) | Contract — Art. 6(1)(b) for the tracking function itself; explicit consent under Art. 9(2)(a) to the extent the data reveals information about your health. |
| Send your content to the AI provider to generate a reply | AI conversation content (4.5) | Contract — Art. 6(1)(b); explicit consent under Art. 9(2)(a) where the content concerns your health. |
| Show you XP, streaks and ranks | Gamification data (4.6) | Contract — Art. 6(1)(b). |
| Keep the service running, secure and free of abuse, including AI usage limits | Device and technical data (4.7) | Legitimate interests — Art. 6(1)(f): operating a secure and reliable service. |
| Show advertising and request your advertising consent | Advertising identifiers (4.8) | Consent — Art. 6(1)(a), collected through the UMP consent form. |
| Improve our food catalogue from searches that found nothing | The unmatched food name you searched for | Legitimate interests — Art. 6(1)(f): improving the service. |
| Comply with legal obligations | As required | Legal obligation — Art. 6(1)(c). |
Withdrawing consent. You may withdraw your consent to health-data processing at any time by deleting your account, or by contacting us at soporte@gymmindia.app. Because the health data is what makes the routine and nutrition features work, withdrawing consent means those features can no longer be provided to you. Withdrawal does not affect processing that already took place lawfully.
10. Who we share data with
We do not sell your personal data. We do not share it for anyone else’s marketing. We share it only with the service providers below, only for the purposes stated.
| Recipient | What they receive | Why | Role |
|---|---|---|---|
| Google (Firebase Authentication) | Your email address, your name, your sign-in identifiers | To sign you in and verify your identity, and to delete your sign-in identity when you delete your account | Processor |
| Google (AdMob / Google Mobile Ads, User Messaging Platform) | Your IP address, device identifiers and technical ad-request data. Never any health, workout, nutrition or Apple Health data | To serve non-personalised advertising and collect advertising consent | Independent controller for its own advertising purposes; see Google’s own policies |
| Apple | Your sign-in identifiers when you use Sign in with Apple. Apple Health data read on your iPhone stays on your device and is not shared with us or anyone else | To sign you in | Independent controller |
| Groq, Inc. | The AI content described in section 7.2, which may include health information you typed, and voice recordings for transcription. Not your name, email or account number | To generate the AI output you requested | Processor, under the data processing addendum described in section 7.3 |
| Oracle (Oracle Cloud Infrastructure) | All data stored on our servers, as our infrastructure provider. Hosted in the Spain (Madrid) region, inside the European Economic Area | To host the service and its PostgreSQL database | Processor |
| Pexels | From our server: a recipe’s title or ingredient names only. From your device: your IP address, when a recipe photo is loaded | To illustrate recipes | Independent controller |
| jsDelivr | Your device’s IP address, when the app or the watch loads an exercise image | To deliver exercise illustrations | Independent controller |
| Expo | Your device’s IP address and an update check from your app | To deliver over-the-air app updates | Independent controller |
We may also disclose data where we are legally required to do so, to establish or defend legal claims, or to protect the rights and safety of our users or the public.
11. International transfers
Our servers and database are hosted in the European Economic Area (Oracle Cloud Infrastructure, Spain (Madrid) region). Some of the recipients above are outside the European Economic Area. In particular, our AI provider (Groq), our authentication and advertising provider (Google) and our over-the-air update provider (Expo) are established in the United States.
- Groq. Transfers to Groq, which may include special category health data such as your allergy notes and your coach notes about injuries and limitations, rely on the European Commission’s Standard Contractual Clauses (Module 2, controller to processor), included in Groq’s Customer Data Processing Addendum. With Zero Data Retention enabled, Groq does not retain that content after producing the reply.
- Other recipients. Where we transfer personal data outside the EEA to other recipients, we rely on the European Commission’s Standard Contractual Clauses and/or an applicable adequacy decision, including the EU–US Data Privacy Framework where the recipient is certified under it.
You may request a copy of the relevant safeguards by writing to soporte@gymmindia.app.
12. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | While your account exists. Deleted when you delete your account. |
| Workout, nutrition, body-weight and gamification data | While your account exists. Deleted when you delete your account. |
| Coach interview answers and transcripts, training plans and suggestions | While your account exists; the transcript keeps the most recent 60 entries. Deleted when you delete your account. |
| Generated recipes | Retained in a shared catalogue; your link to them is removed when you delete your account. |
| Food searches that found no match, and daily AI usage counters | While your account exists. Deleted when you delete your account. |
| Free-form AI chat messages | Not stored by us. Not retained by our AI provider. |
| Voice recordings | Not stored by us. Not retained by our AI provider. |
| Server logs | Not collected or kept in any log system. Operational messages exist only in the container runtime’s default output buffer on our server, which the runtime discards on rotation or when the container is replaced, for example at each deployment. We do not export, copy or keep them. |
| Your sign-in identity in Firebase Authentication | While your account exists. Deleted when you delete your account (see section 13). |
Inactive accounts. We do not automatically delete accounts that have not been used for a long time. Your data is kept until you delete your account, which you can do at any time from inside the app, or by asking us at soporte@gymmindia.app.
Backups. We do not currently make backups of our database. Data deleted from it is gone, and data lost through a server failure could not be restored. We may introduce backups in the future, and we will update this policy if we do.
13. Deleting your account
You can delete your account from the profile screen in the app. The description below is exactly what the software does today.
13.1 What is permanently deleted
In a single database transaction, we delete:
- Your user record: your email address, your name, your profile picture URL, your Firebase identifier, your provider record and your account flags.
- Your profile: age, sex, weight, height, level, goal, units, dietary restrictions and allergy notes.
- Your body-weight history and its notes.
- Your daily tracking records and all of your nutrition intake entries.
- All of your workout sessions and every set log within them.
- All of your routines and the exercises and sets inside them.
- Your gamification record and your entire XP event history.
- All of your coach sessions, including your interview answers and the full conversation transcript.
- All of your training plans, their days, and their notes — including the free-text notes about injuries.
- All of your coach suggestions.
- Your recipe favourites.
- Your unmatched food searches.
- Your daily AI usage counters.
- Your entitlement record, including the ad-free flag.
Then, once that transaction has completed, we delete your sign-in identity from Firebase Authentication and revoke its refresh tokens. If that step fails, it is queued for manual cleanup and the app tells you so. If the manual cleanup also cannot be completed, we will ask you to contact soporte@gymmindia.app so that we can finish it.
13.2 What is anonymised rather than deleted
- Custom exercises you created that other users are still using are kept, but the link to you is removed. They become ordinary catalogue entries belonging to nobody. Exercises nobody else is using are deleted outright.
- Recipes you authored or that were generated for you are kept in the shared recipe catalogue, with the author and “generated for” links to your account removed. The recipe survives; the connection to you does not.
We keep these because deleting them would destroy other users’ routines and logged history. Once the link to your account is removed, they are no longer personal data about you.
13.3 What deleting your account does not do
We would rather tell you this plainly than let you assume otherwise.
- It does not delete data from your phone or your watch. Your locally stored workout history, your offline queue of unsent work and your cached data stay on your device. To remove them, delete the app. See section 14.
- There is nothing to delete at our AI provider. With Zero Data Retention enabled, Groq does not retain the content we send it (see section 7.3).
- It does not delete data held by Google or Apple under their own terms — for example your Google or Apple account itself, or Google’s advertising records.
- It does not remove your workout from Apple Health. Workouts the watch saved there are yours, in your own Health app, and we have no access to delete them. You can delete them in the Health app.
- It cannot be undone. Because we do not keep backups, deleted data cannot be recovered.
You can also ask us to delete your account by writing to soporte@gymmindia.app. We will respond within one month, as section 15 describes.
14. Data stored on your device
The app keeps data on your phone so that it works offline and starts quickly.
Held in the device’s local app storage (MMKV):
- Your account profile object — not your tokens.
- A cached copy of your data so screens render instantly: your routines, the exercise catalogue, your workout history, your profile, your gamification record, your nutrition logs, your recipes and the food catalogue. This cache expires after 30 days, is keyed to your account, and is cleared when you sign out.
- Your in-progress and recent workout sessions, the sets you logged, and their sync status.
- An offline outbox of work that has not yet reached our servers.
- A cached copy of your routines.
- Your onboarding and setup progress.
- Records relating to advertising: your ad-free entitlement, an ad frequency counter, and a diagnostic record of the consent steps that ran.
Held in the device’s secure storage — the iOS Keychain or the Android Keystore:
- Your access token and refresh token. These are deleted when you sign out.
Two things about this are worth stating plainly:
- The local app storage is not encrypted by the app. It relies on your device’s own protections: operating-system app sandboxing and full-device encryption. Anyone with access to your unlocked device may be able to read it.
- Your local workout data is deliberately not cleared when you sign out. This is so that you never lose a session you logged offline. It means that on a shared device, workout history from a previous session can remain after sign-out, and other people who use the device could read it. Delete the app to remove it.
We recommend that you protect your device with a screen lock, and that you do not use the app on a device you share with other people.
On Android, the app sets allowBackup to false, so this data is not included in Android’s automatic cloud backups.
15. Your rights
You have the right to:
- Access your data, and get a copy of it.
- Rectify data that is wrong or incomplete — most of it you can edit directly in the app.
- Erase your data (the “right to be forgotten”) — see section 13.
- Restrict our processing in certain circumstances.
- Port your data: receive it in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Object to processing based on our legitimate interests.
- Withdraw your consent at any time, including your consent to health-data processing, without affecting the lawfulness of processing already carried out.
- Not be subject to a decision based solely on automated processing that has legal effects or similarly significantly affects you. We do not make such decisions. The AI generates training and nutrition suggestions for you to consider and to review with a professional; it does not decide anything about your legal rights or your access to any service.
- Complain to a supervisory authority. Ours is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. You may also complain to the authority where you live or work.
How to exercise them. Write to soporte@gymmindia.app. We will reply within one month, and will tell you if we need up to two further months because the request is complex. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.
Exercising these rights is free. We will only charge a reasonable fee, or refuse, if a request is manifestly unfounded or excessive — and we will explain why if we do.
United States state privacy laws such as the California Consumer Privacy Act do not apply to this service, because its provider does not meet their thresholds. In any case, we do not sell personal information, and we do not share it for cross-context behavioural advertising.
16. Children and young people
You must be at least 16 years old to use GymMind IA, or the age of digital consent in your country if it is higher. If you are under that age, please do not create an account.
16 applies everywhere, with no local exception. Some countries set the age of digital consent lower — Spain sets 14 — and GDPR Art. 8 lets member states go as low as 13. We do not operate those lower thresholds. 16 is the ceiling of that range, so a single floor of 16 is at or above the local age of consent in every EU member state, and the app enforces it uniformly: there is no route to an account below 16.
Your age is self-declared. You enter it during onboarding, and the app rejects any age below 16. We do not ask for a date of birth or any document, and we do not verify the age you enter. We rely on your declaration.
Because you may be 16 or 17 and still be a minor, section 6.1 of the Terms requires the consent of a parent or guardian for those users, and a parent or guardian may exercise your rights and request deletion on your behalf. The app does not record that consent separately; it relies on your confirmation that it has been given.
Because the content in this app is machine-generated and concerns exercise and nutrition, we consider parental and professional supervision especially important for anyone under 18. Exercise and dietary intervention during adolescence, when the body is still developing, should be overseen by a doctor.
We do not knowingly collect data from a child below the applicable age of consent without the required authorisation. If you believe a child has provided us with data, write to soporte@gymmindia.app and we will delete the account.
Advertising and age. As described in section 8.1, we never request personalised advertising for anyone, we tell Google to treat users under 16 as under the age of digital consent and accounts under 13 as child-directed, and we cap ad content ratings by age.
Parents and guardians may exercise all of the rights in section 15 on behalf of a child, by writing to soporte@gymmindia.app.
17. Security
We take the following measures to protect your data:
- Authentication is delegated to Google, Apple and Firebase Authentication. We never see or store your password.
- Session tokens are stored in your device’s secure hardware-backed store — the iOS Keychain or the Android Keystore — and are deleted when you sign out.
- All communication between the app and our servers uses encrypted connections (HTTPS/TLS).
- Our servers run on Oracle Cloud Infrastructure in the Spain (Madrid) region. The storage volumes are encrypted at rest by default by Oracle Cloud Infrastructure, with keys managed by Oracle.
- Only the controller has access to the servers, through SSH with a cryptographic key.
- Account deletion runs as a single database transaction, so a deletion either completes fully or not at all, and cannot leave your data half-removed.
- We do not keep the content of your AI conversations in any log, and we have not set up any system that collects or retains server logs (see section 4.7).
- Apple Health data read on your iPhone never leaves your device.
We do not currently make backups of our database. This means that a serious failure of our server could cause data to be lost permanently. We may introduce backups in the future, and we will update this policy if we do.
No system is perfectly secure, and we cannot guarantee absolute security.
Personal data breaches. Daniel David Bernal Oropeza is responsible for responding to any personal data breach. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Agencia Española de Protección de Datos within 72 hours of becoming aware of it, as required by GDPR Article 33. Where a breach is likely to result in a high risk to your rights and freedoms, we will also inform the affected users without undue delay, as required by GDPR Article 34.
18. Changes to this policy
We may update this policy as the app changes or as the law requires.
- We will post the new version in the app and at https://gymmindia.app/en/privacy/, and update the “Last updated” date at the top.
- For material changes — a new category of data, a new purpose, a new recipient, or a change of AI provider — we will notify you in the app before the change takes effect.
- Where a change requires your consent, including any change affecting how your health data is processed, we will ask you again. We will not rely on your silence.
- Previous versions are available on request from soporte@gymmindia.app.
19. Contact
| Controller | Daniel David Bernal Oropeza |
| NIF/NIE | Z1341140S |
| Postal address | Cuesta Lozal 7, 2C, 23400 Úbeda (Jaén), Spain |
| Privacy enquiries, rights requests and support | soporte@gymmindia.app |
| Website | https://gymmindia.app |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), www.aepd.es |
See also our Terms and Conditions.