Privacy Policy
Gymony Last updated: 26 June 2025 Effective date: 26 June 2025
Table of Contents
- Who We Are
- What Data We Collect and Why
- Third-Party Services
- Data Retention and Anonymisation
- Your Rights Under GDPR
- Data Security
- International Data Transfers
- Children
- Changes to This Policy
- Contact
1. Who We Are
Gymony is a fitness application operated by:
Dawid Stefański Softyal (trade name: Gymony) ul. Czermińskiego 28, 26-400 Przysucha, Poland VAT ID: PL5273143043 REGON: 540390313 Contact: legal@gymony.app
We are the data controller (the organisation responsible for deciding how your personal data is used) responsible for your personal data under the General Data Protection Regulation (GDPR) and applicable Polish data protection law. The supervisory authority for data protection in Poland is the Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl).
Gymony is not required to appoint a Data Protection Officer and has not done so. For all data protection enquiries contact legal@gymony.app.
2. What Data We Collect and Why
2.1 Account Data
What: Email address, first name, password, stored securely and never in plain text, date of registration, preferred unit system (metric or imperial). Why: To create and manage your account and provide the Service. Legal basis: Necessary to perform our contract with you.
2.2 Training Profile Data
What: Experience level, training goal, available equipment, preferred training days per week, session duration preference, gender. Why: To generate a personalised training plan tailored to your goals and circumstances. Legal basis: Necessary to perform our contract with you.
2.3 Workout and Progress Data
What: Workout logs (exercises performed, sets completed, weight lifted, reps logged, sessions skipped or missed), personal records, weekly volume statistics, streak data, exercise feedback. Why: To track your progress and adapt your training plan over time. Legal basis: Necessary to perform our contract with you.
2.4 Payment Data
What: Subscription plan, billing period, subscription status, payment history. We do not store your card number, CVV, or bank account details - all payment processing is handled directly by Stripe. We store a reference number from Stripe that links your account to your payment history. Why: To process payments and manage your subscription. Legal basis: Necessary to perform our contract with you, and to comply with our legal obligations under Polish accounting law.
2.5 Authentication Data (Google Sign-In)
What: If you register via Google, we receive your first name, email address, and Google account identifier. We do not receive your Google password. Why: To authenticate you without requiring a separate password. Legal basis: Necessary to perform our contract with you.
2.6 Technical and Usage Data
What: IP address, browser type, operating system, device type, pages visited, features used, error logs. Why: To maintain security, diagnose errors, and keep the Service running correctly. Legal basis: Our legitimate interest in operating a secure and functional service.
We use this data only to keep the service running securely. We have weighed this against your privacy and concluded the benefit is proportionate and does not override your fundamental rights.
2.7 Communications Data
What: Emails you send to legal@gymony.app and any feedback you provide. Why: To respond to your enquiries. Legal basis: Our legitimate interest in responding to users.
We use this data only to respond to communications you initiate. We have weighed this against your privacy and concluded the benefit is proportionate and does not override your fundamental rights.
3. Third-Party Services
The following third-party services process personal data in connection with Gymony. All services operating outside the EU do so under Standard Contractual Clauses (SCCs) approved by the European Commission (legal agreements that ensure your data receives EU-level protection even when handled outside Europe).
| Service | Purpose | Privacy Policy |
|---|---|---|
| Stripe | Payment processing and subscription management | stripe.com/privacy |
| Sentry | Error logs, stack traces, and device/browser information | sentry.io/privacy |
| Cloudflare R2 | Static application assets such as exercise images. No personal data is stored in Cloudflare R2. | cloudflare.com/privacypolicy |
| Resend | Transactional email delivery | resend.com/privacy |
| Authentication (Google Sign-In only) | policies.google.com/privacy | |
| Anthropic | Powering certain app features | anthropic.com/privacy |
| PostHog | Analytics and user behavior tracking (EU-hosted, consent-gated) | posthog.com/privacy |
| Hetzner | Cloud infrastructure and hosting - all application data is stored on Hetzner servers in Germany | hetzner.com/legal/privacy-policy |
Stripe: Stripe acts as an independent data controller for all payment-related data. Gymony has no access to your card details at any point in the transaction flow.
Anthropic: Relevant portions of your training profile (non-identifying data) may be transmitted to Anthropic's API when you use certain features. We do not send your name, email address, or payment information to Anthropic. Data transferred to Anthropic is subject to Standard Contractual Clauses (SCCs) approved by the European Commission.
4. Data Retention and Anonymisation
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g. financial records which may be retained for up to 7 years per Polish accounting regulations). Training logs and workout history are deleted together with your account.
When you delete your account, your personal data is irreversibly anonymised within 30 days. Your email address and name are replaced with non-identifying values that cannot be linked back to you by any means. Payment-related identifiers may be retained for up to 7 years where required for accounting, fraud prevention, or subscription dispute resolution purposes. Workout and progress data may be retained in anonymised form.
| Data Category | Retention Period |
|---|---|
| Account and profile data | Anonymised within 30 days of account deletion |
| Workout and progress data | Anonymised within 30 days of account deletion |
| Payment records | 7 years from transaction date |
| Error logs | 90 days |
| Email communications | up to 24 months from last contact |
5. Your Rights Under GDPR
| Right | How to Exercise |
|---|---|
| Access - request a copy of your personal data | Email legal@gymony.app |
| Rectification - correct inaccurate data | Account settings or email |
| Erasure - delete your account and anonymise your data | Your account settings |
| Data export (Portability) - receive your data in a machine-readable format | Email legal@gymony.app |
| Object - object to processing based on legitimate interests | Email legal@gymony.app |
| Restriction - request restriction of processing | Email legal@gymony.app |
| Withdraw consent - withdraw analytics consent at any time | Cookie settings |
We will respond to all requests within 30 days. We may verify your identity before processing your request.
You also have the right to lodge a complaint with UODO at uodo.gov.pl.
6. Data Security
We implement appropriate technical and organisational measures including:
- Passwords stored using one-way hashing - never in plain text
- All data in transit encrypted via HTTPS
- Database access restricted to application processes only
- Error monitoring and alerting via our error monitoring service
In the event of a data breach posing risk to your rights and freedoms, we will notify UODO within 72 hours and notify affected users by email as soon as practicable after we identify the breach, as required by GDPR.
7. International Data Transfers
Some third-party services listed in Section 3 are based outside the European Economic Area. We ensure appropriate safeguards are in place for all such transfers, primarily through Standard Contractual Clauses approved by the European Commission.
8. Children
Gymony is not intended for persons under 16. We do not knowingly collect personal data from children under 16. If you become aware that a child under 16 has created an account, please contact legal@gymony.app and we will anonymise their data promptly.
9. Changes to This Policy
We will notify you of material changes by email or in-app notice at least 30 days before changes take effect. Continued use of Gymony after changes take effect constitutes acceptance.
10. Contact
Email: legal@gymony.app Data Controller: Dawid Stefański Softyal, ul. Czermińskiego 28, 26-400 Przysucha, Poland