GymAnvil

GymAnvil Privacy Policy

Controller and contact

The data controller is Paweł Grzeszczak, address: Kazimierza Pułaskiego 3/33, 05-400 Otwock, Polska, email: [email protected]. This policy covers the PWA, iOS app and shared GymAnvil backend.

Data and purposes

We store your username, secure password hash, sessions, verified account recovery email, and document acceptance record: version, document text, language, channel, and server timestamp. One-time verification and password reset links are stored as expiring hashes. Google sign-in provides an account identifier and email; configured Cloudflare Access verifies access identity. We do not store your Google password.

Profile data includes weight, height, age, sex used for calculations, activity, training experience and goals. Training data includes plans, sets, loads, repetitions, time, distance, RPE, notes, custom exercises and uploaded images. We use it for storage, synchronization, statistics and estimates. Measurements and estimates may reveal health information.

Technical data such as a device identifier, IP address, request time and browser details supports operation and security. Do not enter health information about others. We do not sell training data, use it for advertising or send it to AI services.

Legal bases and choices

Operating your account and features relies on performing the contract; security and necessary claims on legitimate interests; legal duties on applicable law. Processing health data requires separate explicit consent, independent of accepting the terms.

Withdraw health-data consent by contacting [email protected]. Withdrawal does not affect previously lawful processing. The operator arranges deletion of this data and termination of features requiring it; withdrawal does not authorize continued calculations. Privacy information is not marketing consent.

Estimates are simple calculations on your inputs. We do not make solely automated decisions producing legal or similarly significant effects on you.

Device storage and recipients

Essential cookies store sessions, CSRF tokens and the one-time Google verification nonce. The server session does not expire automatically and remains active until sign-out or revocation. The PWA session cookie is automatically renewed while using the app. The PWA uses browser storage and cache for preferences, offline data and queued changes. iOS uses protected app files, device preferences and Keychain for sessions. Signing out may retain unsent account data.

Account and workout data is stored in managed PostgreSQL on Render in Frankfurt; Render also runs the application API. Cloudflare R2 stores private artwork and encrypted database backups. Access is limited to the operator and authorized infrastructure providers as necessary. Cloudflare handles network traffic and access protection. When Google sign-in is available, its script contacts Google on the sign-in screen. Selecting a video starts YouTube and contacts its provider. You choose the recipient of an export.

Google, YouTube, Cloudflare and Apple have their own privacy policies and may process infrastructure data outside the European Economic Area. Google and Cloudflare describe using the EU–US Data Privacy Framework and standard contractual clauses in their transfer policies. Contact [email protected] for information about recipients, applicable safeguards and how to obtain a copy. Provider policies: https://policies.google.com/privacy/frameworks and https://www.cloudflare.com/privacypolicy/. Render: https://render.com/privacy; Resend: https://resend.com/legal/privacy-policy; Zoho: https://www.zoho.com/privacy.html.

We use Resend to send email verification and password reset links and account change notifications. These messages contain the recipient address and link or notification, without workout data. Messages sent to the operator contact address are handled through Zoho Mail. We process sender details, content and attachments as needed to respond and fulfil your request. Do not send passwords or unnecessary medical information.

Retention and rights

Account and training data is retained while you use the service and until a deletion request is fulfilled, except data necessarily retained for legal duties or claims. Acceptance evidence is retained only as long as necessary to demonstrate the applicable contract.

The operator creates encrypted pre-migration backups. The app does not automatically rotate these backups by age. Deletion requests must include backups or isolation from further use and eventual deletion; restoring a backup must not restore a deleted account to ordinary use. Remove a local copy in PWA settings or by removing app data; export what you need first.

You may request access, correction, deletion, restriction and portability where applicable, and object to processing based on legitimate interests. Contact [email protected] without sending a password. We generally respond within one month and notify you of justified extensions. You may complain to the Polish President of the Personal Data Protection Office (UODO).