Health Permissions
Last updated 7 August 2026
What this page is
GymBro asks for permission to read and write specific health data, and asks a small number of health questions during onboarding. This page lists every single one of them — exactly what we request, exactly why, who can see your answers, and how it's kept secure. Nothing here is requested speculatively: every permission and every question ties to a feature you can see and use in the app.
This page focuses specifically on health data. Our Privacy Policy covers everything GymBro collects; our Consumer Health Data Privacy Policy covers the additional rights US state health-privacy laws give you.
Health Connect and Apple Health data we read
With your permission, GymBro reads the following from Google Health Connect (Android) or Apple Health (iOS). We ask device permission for each of these individually — the OS lets you grant or decline them one at a time.
- Steps
READ_STEPS— shown as daily activity on your tracker and Trends chart. - Sleep
READ_SLEEP— duration and, where your device records them, sleep stages (light, deep, REM, awake), shown as recovery context on your tracker. - Nutrition
READ_NUTRITION— calories, protein, carbohydrates, fat, and fibre. Auto-fills your daily nutrition log, for example if you sync a food app like MyFitnessPal. - Active heart rate
iOS only— recorded during your workouts (Apple Health). We compute the average and maximum per session to show how hard that workout was; the raw per-second samples are never stored. The Android app does not request or read heart-rate data. - Resting heart rate
iOS only— powers the recovery and fatigue trend on your tracker, and, for coached clients, a recovery flag your coach can see (Apple Health). The Android app does not request or read heart-rate data. - Workouts
READ_EXERCISE— workout sessions recorded by your phone or watch, auto-filling your training log. - Active calories burned
READ_ACTIVE_CALORIES_BURNED— shown alongside your workout sessions as energy burned.
What we write back
With your permission, GymBro also writes to Health Connect / Apple Health — never anything you didn't create in GymBro, and never anything that isn't your own workout data:
- Workouts you log in GymBro
WRITE_EXERCISE— saved back as a workout session, so your device's activity rings and health record stay accurate. - Calories burned in those workouts
WRITE_ACTIVE_CALORIES_BURNED— so the energy from GymBro-logged workouts counts toward your device's daily totals.
We never modify or delete health data we did not create, and we never write anything other than the two record types above.
Only what we use
GymBro requests exactly the nine permissions listed above — seven read, two write — and nothing else. We do not request weight, height, body fat, blood pressure, blood glucose, distance, VO2 max, or any of the other data types Health Connect and Apple Health support, because no GymBro feature reads or writes them. Body weight in GymBro is entered manually in the tracker; it is never read from Health Connect or Apple Health. If a feature that uses one of these permissions is ever removed, we remove the permission request in the same release rather than leaving it declared unused.
Health questions we ask during onboarding
Separately from device health data, onboarding asks a handful of optional questions about your health, so your coach — or GymBro's AI, if you don't have a coach — can build programming that fits your body. You can skip any of them, in as much or as little detail as you like:
- “Do you have any injuries, chronic pain, or mobility limitations?” — used to build programming around what your body can currently do. Your answer is also saved to your profile's injuries field, which flags GymBro's AI to be conservative about that area when writing coaching.
- “Are you currently taking any medications or supplements?” — gives your coach context on anything that might affect training or recovery.
- “Do you have any diagnosed medical conditions your coach should be aware of?” — same purpose: context for programming you safely.
- “Do you have any dietary requirements or food allergies?” — used when building or adjusting meal plans, including the AI meal planner.
GymBro's AI is not a doctor, physiotherapist, or medical professional, and it never diagnoses anything. If you report sharp pain, chest pain, dizziness, numbness, a severe injury, or other medical symptoms, it will tell you to stop training and see a qualified professional.
Your consent, your control
Before any of the questions above are asked, onboarding shows a dedicated screen explaining exactly what saying yes means: your answers, plus any sleep, heart rate, stress, or nutrition data you track, personalise your coaching, are shared with your coach if you have one, and are included in requests to our AI provider when it writes your coaching. Saying no skips those questions — everything else in the app works normally.
You can change your mind at any time from Account — turning health-data consent off stops the questions being asked again and keeps your health answers out of future AI coaching requests. This is separate from the Health Connect / Apple Health device permission itself, which lives in your phone's settings: both Android and iOS let you grant or revoke individual permission types — say, just heart rate, or just steps — without needing an app update.
Who can see this data
- Your coach, if you have one — the same health questionnaire answers and injuries field described above, so they can coach you safely. This is the same access they have to your other training data, and it ends when the coaching relationship ends.
- Our AI provider, OpenAI— only if you've consented, and only the relevant parts of this data, when GymBro's AI generates an audit, debrief, plan, or chat response. Your email address is never included. Under OpenAI's API data usage policy, this data is not used to train their models.
We do not sell this data, use it for advertising, or share it with anyone else.
Why sending data to AI is safe
It's a fair thing to be wary of — “AI” and “my health data” in the same sentence make a lot of people nervous. Here's exactly what happens, and what OpenAI's own policy commits to.
GymBro uses OpenAI's API — a business product with contractual data-handling rules, not the consumer ChatGPT app most people picture. Those rules are stricter than what a consumer AI product typically offers:
- Not used to train models.Under OpenAI's API data usage policy, data sent through the API is not used to train their models, and this is the default — not something we had to opt into.
- Short retention, then deleted.OpenAI retains API request data only long enough to monitor for abuse — typically 30 days — then it's deleted. There is no long-term archive of what we send.
- Encrypted, independently audited infrastructure. OpenAI encrypts data in transit and at rest, and maintains SOC 2 Type II compliance — an independently audited security standard.
- Not shared onward. OpenAI does not sell this data or share it with advertisers or other third parties.
On our side, we only send what a specific coaching feature actually needs — never your email, never payment details — and only if you've consented to sharing health data in the first place. You can turn that off entirely, at any time, from Account.
How it's kept secure
- Health data is sent from your device to our servers over an encrypted connection (TLS), then stored in Supabase-managed infrastructure, encrypted at rest.
- Every database query is scoped explicitly to your account — your data is never mixed with anyone else's, and access to production databases is restricted to essential personnel.
- Heart-rate samples are read on your device only long enough to calculate a workout's average and maximum — the raw per-second samples are never stored or transmitted.
- If you use the GymBro Apple Watch app, its pairing token is stored only as a one-way hash, never in plain text.
Deleting your data
You can delete your account, and every piece of health data described on this page, at any time. See our account deletion page for the full process.
More detail
For the complete list of everything GymBro collects, every third-party provider we share data with, data retention periods, and your full legal rights, see our Privacy Policy. If you're a resident of a US state with a consumer health data law, see our Consumer Health Data Privacy Policy. Questions about any of this — info@gymbro.com.au.
