Privacy Policy — GymApp

Last updated: June 8, 2026 · Operator: CleverAI Apps (Rafael Araujo, sole developer) · Contact: cleveraiapps@gmail.com

GymApp is a fitness tracking Progressive Web App (PWA) and Android application that helps you log workouts, automatically adjust weights, and visualize muscle group balance. This policy explains what data we collect, why, where it is stored, who it is shared with, and how you can delete it. We follow GDPR (EU), LGPD (Brazil), and CCPA (California) principles.

1. Data We Collect

1.1 Account & profile (only if you sign in)

When you sign in with Google or Microsoft, the OAuth provider returns to us:

We do not receive your password from any provider. We do not request access to your contacts, calendar, photos, or any other Google/Microsoft data beyond basic profile.

1.2 Workout & profile data you enter

1.3 Optional: photos and videos

If you use the Smart Vision feature to identify gym machines, the photo or video you submit is sent to OpenAI's API (gpt-4o vision) for one-time identification. It is not retained on our servers and OpenAI's API policy commits to not training on submitted images.

1.4 Device sensors

If a future smartwatch BLE rep-counter feature is enabled, accelerometer data is processed locally on your device only. Aggregated rep counts (not raw sensor data) are saved to your workout log.

1.5 What we do NOT collect

2. How We Use Your Data

We do not sell, rent, or trade your data. We do not use your data for advertising.

3. Where Your Data Is Stored

StorageWhatProvider
Your device (localStorage)Workout logs, settings, cached community data — namespaced per emailYour browser / Android Trusted Web Activity
Cloudflare D1 (cloud sync)Account, workouts, community memberships, AI usage countersCloudflare (region: automatic edge)
OpenAI API (transient)Vision photos and Coach prompts — sent and discarded per requestOpenAI

We do not transfer personal data to jurisdictions that lack adequate protection. Cloudflare and OpenAI are based in the United States and comply with applicable standards (SCCs, DPF).

4. Data Sharing

We share data only with the third parties listed below, and only as strictly necessary to operate the app:

We do not share your data with advertisers, data brokers, or analytics firms.

5. Your Rights

6. How to Delete Your Account & Data

You can delete your account and all associated data at any time:

  1. Open GymApp.
  2. Go to Profile > Me > Danger Zone.
  3. Tap "Delete all data and start over".
  4. Confirm. This action permanently deletes your account from our cloud database (Cloudflare D1) AND your device.

If you no longer have access to the app, email cleveraiapps@gmail.com from the address registered on your account, asking for account deletion. We will confirm within 7 business days.

7. Data Retention

8. Children's Privacy

GymApp is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us data, email cleveraiapps@gmail.com and we will delete it promptly.

9. Security

All connections use HTTPS/TLS. Authentication tokens are validated server-side. Database access is restricted via Cloudflare's bindings. We do not store passwords (all auth is delegated to Google or Microsoft).

10. Changes to This Policy

We may update this policy. The "Last updated" date at the top reflects the latest revision. Material changes will be announced in-app.

11. Contact

Questions, concerns, or requests:

This privacy policy is provided in English for legal clarity. Translations may be added in the app interface.