GymPilot

Legal

Privacy Policy

What GymPilot collects, why, who processes it, how long it is kept, and how to have it deleted. Written to describe the app as it actually works.

Last updated

The short version

GymPilot stores your account, your training profile and the workouts you log. It has no analytics, no advertising and no trackers. It never sees your card details. AI plan generation sends your training attributes but not your name, email or account id. You can have everything deleted by emailing us.

Who this policy covers

This policy explains how GymPilot Fitness (“GymPilot”, “we”, “us”) handles personal data in the GymPilot mobile app, published on Google Play under the package id com.gympilotfitness.app, and on this website.

GymPilot is a strength-training app. It builds a weekly training programme around what you tell us about your goals and equipment, and records the workouts you log against it. Everything below describes that product as it works today.

Information you provide

You give us this information directly. Everything below is required to create an account and generate a programme, with one exception: logging your body weight over time is entirely optional, and GymPilot works without it.

Email address
Used to create and sign in to your account, to verify it, and to reach you about your account or a deletion request.
Password
Handled by our authentication provider and stored only as a cryptographic hash. GymPilot never sees or stores your password in readable form.
Your name
Entered at sign-up and shown back to you in the app. Any name you like; we do not verify it.
Age, sex, height and body weight
Collected during onboarding. These are used to size your programme and to suggest sensible starting weights. Sex is offered as male or female because that is what the starting-weight calculation uses.
Training goal and experience level
For example building muscle or improving strength, at beginner, intermediate or advanced level.
Training location and available equipment
Commercial gym, home equipment or bodyweight only, plus which equipment you have. This decides which exercises can appear in your plan.
Days per week and session length
How your programme is split across the week.
Physical limitations
Chosen from a fixed list of body areas (for example knee or shoulder) so exercises that would aggravate them can be avoided. This is a selection from a list, not a free-text medical history — there is nowhere in GymPilot to type a diagnosis.
Body weight entries
If you log your weight over time, each entry is stored with its date and unit.

Information generated by using GymPilot

This is created as you train, rather than typed into a form.

Workout sessions
When a workout started and finished, which routine day it belonged to, and any notes you add.
Logged sets
For every set: the exercise, the number of repetitions, the weight and its unit, an optional RPE (how hard it felt), and optional notes.
Personal records
Calculated from the sets you have logged rather than stored separately. They exist because your set history does.
Routines and plans
The programmes saved to your account, the training days inside them and the exercises on each day, including plans produced by AI generation.
In-session adjustments
Extra sets you add to a given day, and any exercise you swap for another during a workout. These are recorded against that session and do not change the underlying plan.
Unit preference
Whether you work in kilograms or pounds.
AI generation records
A timestamped row each time you generate a plan, used to enforce a per-account rate limit. See AI workout-plan generation.

What GymPilot does not collect

This section is as important as the two above it. GymPilot contains no analytics, advertising, attribution or crash-reporting software of any kind. Specifically, we do not collect:

  • Advertising identifiers, and we do not serve ads or run any advertising network code.
  • Location data of any kind. The app requests no location permission.
  • Your contacts, calendar, photos, camera, microphone or files. None of these permissions is requested; the storage permissions are explicitly removed from the Android build.
  • Health or fitness data from Google Fit, Apple Health, wearables or any other connected device or service. GymPilot has no such integration.
  • Behavioural analytics, session recordings, heat maps or usage funnels.
  • Your payment card number, expiry or security code. See Subscriptions and payments.

The only Android permissions GymPilot declares are internet access and vibration, the latter for rest-timer feedback.

How we treat fitness and body data

Some of what GymPilot stores — your body weight, your height, your age, the body areas you have asked us to work around — is personal and, depending on where you live, may count as sensitive personal information. We treat it that way: it is only ever used to build and adjust your training, it is never sold, and it is never used for advertising.

We want to be equally clear about what this data is not. GymPilot is a fitness product, not a medical one. It does not create or hold medical records, it is not a covered entity or business associate under HIPAA, and nothing in it is a diagnosis, treatment or clinical assessment. The limitations you select are a list of body areas used to filter exercise selection — nothing more.

GymPilot is not medical advice

The programmes, exercise descriptions and demonstrations in GymPilot are general fitness information. They are not a substitute for advice from a doctor, physiotherapist or other qualified professional. Talk to one before starting a new training programme, especially if you have an injury, a health condition, or are pregnant or recovering from surgery.

How we use your information

We use the information above to:

  • Create your account and sign you in securely.
  • Generate a weekly training programme that fits your goal, experience, schedule, equipment and the areas you have asked us to work around.
  • Suggest starting working weights appropriate to you.
  • Record your workouts and show your history, progress charts and personal records.
  • Let you adapt, reschedule or regenerate your programme using what you have actually been doing.
  • Determine whether you have an active GymPilot Pro subscription and unlock the features it includes.
  • Apply a fair-use limit to AI plan generation, so one account cannot exhaust the service for everyone.
  • Respond to your support and account-deletion requests.
  • Keep the service secure and investigate abuse.

We do not use your data to build advertising profiles, and we do not sell it or share it with data brokers.

AI workout-plan generation

When you generate or update a programme, GymPilot sends a request to our own server function, which calls the OpenAI API to produce the plan. We have been deliberate about what leaves our systems.

What is sent

Only the training inputs needed to build a programme, as structured values:

  • Age, sex, height and body weight.
  • Goal, experience level, training location, available equipment, days per week and session length.
  • Selected limitation areas, from the fixed list.
  • When updating an existing plan: the current programme name, a count of recent sessions, the exercises you train most often, and exercises you have repeatedly swapped away from.
  • A shortlist of exercises from the GymPilot catalogue for the model to choose from. This is our content, not your data.

What is not sent

  • Your email address, your name, and your account identifier are not sent. The request carries training attributes only.
  • No end-user identifier is attached to the API call, so the request is not linked to you at the provider.
  • Free text never reaches the model. Every value is validated against a closed list or clamped to a numeric range before the request is built, and any text carried over from a previous plan is stripped of characters that could alter the instructions.

Why, and what happens to the result

The processing exists to produce your programme. The generated plan is returned to the app and saved to your account as a routine, its training days and their exercises — so it is your data from that point on, and it is deleted with your account. We also store a timestamped record of each generation request against your account, used solely to enforce the rate limit.

On the AI provider's own handling

OpenAI processes the request under its own terms as our service provider. We do not make representations here about how long OpenAI retains API request data or what contractual commitments apply, because those are its terms to state and not ours to paraphrase. What we can tell you is exactly what we send, which is the list above.

Subscriptions and payments

GymPilot Pro is sold as a subscription through Google Play. Two things follow from that, and both matter for your privacy.

GymPilot never sees your payment details

Your purchase is made and billed by Google Play using the payment method on your Google account. Card numbers, expiry dates and security codes are entered into Google’s systems, never into GymPilot. GymPilot does not receive, process or store card or bank details at any point. Google holds your purchase and billing history under its own privacy policy.

How we know you are subscribed

We use RevenueCat to tell us whether your subscription is currently active. When you sign in, the app tells RevenueCat your GymPilot account identifier — a random identifier (a UUID), not your email or your name — so that a subscription follows you to a new phone or after a reinstall. RevenueCat receives purchase events from the app store and returns a simple answer: whether the Pro entitlement is active. Your training data is never sent to RevenueCat.

Deleting your GymPilot account does not cancel a Google Play subscription. See Delete your account.

Service providers

GymPilot is a small product and relies on a short list of providers. These are the only ones that handle data on our behalf.

Supabase
Authentication, database, file storage and the server function that generates plans. Supabase holds essentially all GymPilot account and training data.
OpenAI
Generates workout plans from the training attributes listed above. Receives no identifiers.
RevenueCat
Tells the app whether a subscription is active. Receives your account identifier and store purchase events; no training data.
Google Play
Distributes the app and processes all payments. Google is the merchant of record for subscriptions.

Exercise videos and images are hosted in our own Supabase storage and served through short-lived signed links to signed-in users. There is no third-party media network or content-delivery provider involved, and the app does not embed third-party players or trackers.

Where your data is processed

GymPilot’s database, authentication and server functions run in the United States (a Supabase project hosted in the AWS US West region). Our other providers may process data in the United States and elsewhere.

If you use GymPilot from outside the United States, your information will be transferred to and processed there. Data-protection law in the United States may differ from the law where you live. Where a transfer mechanism is required for your country, we rely on the safeguards offered by the providers listed above.

Security

The measures below are the ones actually in place today.

  • All traffic between the app and our servers uses HTTPS/TLS. Data is encrypted in transit.
  • Passwords are stored only as cryptographic hashes by our authentication provider.
  • Every table holding user data enforces row-level security, so a signed-in account can read and write only its own rows. This is enforced by the database itself, not just by the app.
  • Plan generation authenticates the caller server-side before doing any paid work, and applies a per-account rate limit.
  • Exercise media sits in private storage and is reachable only through short-lived signed links issued to signed-in users.
  • Values sent for AI processing are validated against closed lists and numeric ranges, so free text cannot reach the model.
  • Sign-in tokens are held in your device’s app-private storage.

No service can promise perfect security, and we do not. If you believe your account has been accessed by someone else, contact us at info@gympilotfitness.com.

How long we keep your data

We keep your account data for as long as your account exists. You can end that at any time, and we distinguish carefully between three different things.

Active account data

Your profile, training profile, routines, workout history, logged sets and body-weight entries live in the production database until your account is deleted. When a deletion request is completed they are removed from production, permanently and together.

Records we may need to keep

A limited record may outlive the account where it is genuinely needed for a legal, tax, accounting, fraud-prevention, security or dispute purpose. Anything kept on this basis is limited to the minimum required, is not used to rebuild your training history, and is kept only for as long as that specific purpose lasts. Purchase and billing records are held by Google Play under Google’s own policies and are not ours to delete.

Backups

Deleting data from the production database does not instantly rewrite historical backups. A deleted account may persist in encrypted backup copies until those copies cycle out through our hosting provider’s normal backup rotation, after which they are overwritten. Backups are never used to restore an individual deleted account, and are only ever restored wholesale in a disaster-recovery situation.

Deleting your account and your rights

You can permanently delete your GymPilot account at any time, for any reason. The quickest way is in the app, under Profile → Delete Account: the deletion happens immediately and nothing is queued.

If you no longer have the app or cannot sign in, our support team will do it for you - you do not need to be signed in to ask. Email info@gympilotfitness.com from the address on your GymPilot account, with the subject GymPilot Account Deletion Request. We may reply to confirm the request is yours. We aim to complete verified deletion requests within 30 days. The full process, and the complete list of what is removed, is on the Delete your account page.

Depending on where you live, you may also have the right to access a copy of your data, to correct it, to object to or restrict certain processing, or to complain to your local data-protection authority. Much of your data is already visible to you inside the app; for anything else, write to us at the address above and we will help.

Children and age

GymPilot is listed on Google Play for an audience of 18 and over, and it is not directed at children. You must be at least 18 to create an account.

GymPilot does not verify age, and we do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, contact us at info@gympilotfitness.com and we will delete it.

Changes to this policy

If GymPilot changes what it collects or how it is used, this policy is updated and the date at the top of the page changes with it. For a change that materially affects your rights, we will give notice in the app or by email to the address on your account before it takes effect.

Contact us

Questions about this policy, your data, or a deletion request go to info@gympilotfitness.com. A person reads every message.