Privacy Policy
Last updated 29 July 2026
Who we are
GymBro (“we”, “us”, “our”) is an AI-powered gym coaching application available on the web, iOS App Store, and Google Play Store. Our website is www.gymbro.com.au.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to all users of the GymBro website, iOS app, and Android app.
What data we collect
Account information. When you create an account we collect your email address and password. Your password is stored as a one-way salted hash by our authentication provider (Supabase Auth) and is never stored or transmitted in plain text.
Profile information. Information you provide during onboarding or in your profile settings — name, age, sex, body weight, height, training goal, experience level, training days per week, injuries, available equipment, and coaching style preference.
Workout and training data. Everything you log or upload — sets, reps, weights, RPE, rest times, exercise names, workout names, routines, session durations, and any notes you add.
Health data. If you grant permission, we read the following from Apple Health (iOS) or Google Health Connect (Android): step count; sleep duration and, where your device tracks them, sleep stages (light, deep, REM, and awake periods); dietary nutrition (calories, protein, carbohydrates, fat, and fibre — for example, synced from a nutrition app like MyFitnessPal); resting heart rate; heart rate recorded during your workouts (we store only the average and maximum per workout, not the raw samples); active energy burned during workouts; and workout sessions recorded by your device or watch. We only read the specific data types you authorise, and you can revoke access at any time in your device settings.
Health data we write. With your permission, we also save workouts you complete in GymBro back to Apple Health or Health Connect (the workout session and its energy burned), so your activity rings and health record stay accurate. We never modify or delete health data we did not create.
Apple Watch companion. If you pair the GymBro Apple Watch app, the watch runs a workout session during your training that records your live heart rate and energy burn on-wrist. The watch logs your sets to your GymBro account using a secure pairing token (we store only a hash of it), and the heart rate and energy it records are saved to Apple Health on your devices, where we read them back as described above. Live heart rate is shown on the watch face only — it is not streamed anywhere else.
Progress photos. If you use the progress photo feature, images you upload are stored securely and associated with your account. Photos are only visible to you and your assigned coach (if applicable).
Check-in and daily tracker data. Responses to check-in and onboarding questionnaires, daily nutrition logs (calories, macros, fibre), water intake, body weight entries, stress and motivation ratings, habit and goal tracking, and any other data you submit through the daily tracker. Some default questionnaire questions ask about sensitive topics — injuries and pain, medications and supplements, diagnosed medical conditions, food allergies and dietary requirements, alcohol consumption, and sources of stress. These questions are only asked if you have given health-data consent (collected during onboarding, changeable any time on your Account page). Your answers are stored so your coach (or the AI coach) can account for them; you can always skip a question or answer in as little detail as you like. If you use the AI meal planner, any health notes you provide (conditions, medications, allergies) are stored for the same purpose.
Body measurements. If you or your coach log body measurements (waist, hips, chest, arm, thigh, neck), they are stored with your account and visible to you and your assigned coach.
Messages and coaching content. Messages between you and your coach (including reactions), meal plans your coach assigns, exercise demo videos and check-in review videos your coach records for you, and appointment details.
Billing data. Payments are processed by Stripe. We never see or store your full card number — Stripe handles payment details under its own privacy policy. We store Stripe customer and subscription identifiers, and for coaches, Stripe Connect account identifiers, so we can manage subscriptions and coach billing.
Coach-client relationship data.If you are a coach, we store your business name, bio, brand colour, and contact email. If you are a coached client, we store the relationship between your account and your coach's account, including invite status and any notes your coach adds to your profile.
AI coaching data. When you request a training audit, workout debrief, in-session analysis, AI-generated plan, or use the chat feature — and, for coached clients, when we prepare the weekly summary your coach sees — we package the relevant data into a prompt and send it to our AI provider to generate a response. Depending on the feature, that packet can include your first name, profile details (goal, experience, injuries), training history and statistics, and your recent tracker and check-in data — sleep, steps, weight, resting heart rate, water, stress, motivation, nutrition, and your questionnaire answers (including sensitive ones such as medications, medical conditions, allergies, and alcohol). The prompt never includes your email address or payment details. Both the prompt and the response are stored in our database.
Push notification tokens. If you enable push notifications, we store the device push token issued by Apple or Google (via Firebase Cloud Messaging) so we can deliver reminders to your device, along with your notification preferences.
Device and usage data. Our hosting provider (Vercel) automatically records standard server logs including IP address, user agent string, and request timestamps. On our public marketing pages (the home page, the athletes and download pages, guides, the program checker, and the sign-up page) we use the Meta (Facebook) Pixel to measure our advertising: it records page visits — and an account-creation event when you sign up — may set cookies, and shares this with Meta. The pixel is not present anywhere inside the app or on signed-in product pages, and it never receives your training, nutrition, health, check-in, or coaching data. We run no other third-party analytics or fingerprinting scripts.
How we use your data
- To create and maintain your account and sign you in.
- To compute training statistics (volume, frequency, movement balance, progression trends) that drive the coaching experience.
- To generate AI coaching responses by sending packaged training data to our AI provider on your behalf.
- To enable coaches to view their clients' training data, assign programs, and provide coaching.
- To send transactional emails (password resets, coach invites).
- To process subscription and coaching payments through Stripe.
- To send push notifications for workout reminders, check-in reminders, and daily tracker nudges — only if enabled.
- To operate, maintain, and improve the service.
We do not sell your data. Apart from the Meta Pixel on our public marketing pages described above — which has no access to your account, training, or health data — we do not share your data with advertisers. We do not use your data to train any AI model of our own.
Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)) — account information, profile information, workout and training data, routines, messages, coaching relationships, and billing identifiers: the data needed to provide the service you signed up for.
- Explicit consent (Articles 6(1)(a) and 9(2)(a)) — health data. Answers about injuries, medications, medical conditions, allergies and alcohol, data read from Apple Health or Health Connect, sleep, heart rate, nutrition and stress entries, and the inclusion of any of this in AI coaching requests or in what your coach sees, are processed only with the explicit consent you give during onboarding. You can decline — the health-related questions are simply skipped and the rest of the app works normally — and you can withdraw consent at any time from your Account page, or by revoking device health permissions.
- Consent (Article 6(1)(a)) — marketing emails (opt-in, off by default) and push notifications.
- Legitimate interests (Article 6(1)(f)) — server logs, rate limiting, and fraud and abuse prevention: keeping the service secure and working.
- Legal obligation (Article 6(1)(c)) — records we must keep for tax, accounting, or other legal requirements.
US consumer health data
If you are a resident of a US state with a consumer health data law (such as Washington or Nevada), our Consumer Health Data Privacy Policy explains how we handle your consumer health data and the rights those laws give you.
Third-party service providers
We share data with the following providers, strictly for the purposes described. Each provider processes data under their own privacy policy and data processing terms.
- Supabase (database and authentication) — stores your account, profile, workout data, coaching reports, and all other application data. Passwords are stored only as hashes managed by Supabase Auth. Supabase also sends password-reset emails via their built-in email service.
- OpenAI(AI coaching responses) — receives packaged training data when you request an audit, debrief, analysis, or chat response. Your email address is not included in data sent to OpenAI. Under OpenAI's API data usage policy, API inputs and outputs are not used to train their models.
- Resend (transactional email) — delivers coach invite emails. Resend receives only the recipient email address and the email content.
- Vercel (hosting) — hosts the web application and processes all HTTP requests. Vercel records standard server logs (IP address, user agent, timestamps).
- Stripe (payments) — processes all payments: subscriptions, coach billing, and payments between coached clients and their coaches (via Stripe Connect). Stripe receives your payment details directly; we never see or store full card numbers.
- Apple (HealthKit)— if you grant permission on iOS, we read the health data types listed above (steps, sleep, nutrition, heart rate, workouts, active energy) from Apple Health, and write back workouts you complete in GymBro. This data is transmitted directly from your device to our servers. We comply with Apple's HealthKit guidelines: health data is not used for advertising, is not sold to data brokers, and is not shared with third parties for purposes unrelated to providing the service.
- Google (Health Connect) — if you grant permission on Android, we read the same health data types from Google Health Connect and write back completed workouts. The same restrictions as HealthKit apply.
- Apple (APNs) and Google (Firebase Cloud Messaging) — deliver push notifications to your device. They receive your device push token and the notification content.
- USDA FoodData Central(food database) — when you or your coach search for foods while building meal plans, the search terms are sent to the USDA's public food database. No account data is included.
- Apple and Google sign-in — if you sign in with Apple or Google, we receive your email address (and name, if you share it) from the provider to create or match your account.
We do not share your data with any other third parties. If this changes, we will update this policy and notify you before the change takes effect.
What your coach can see
If you are connected to a coach, your coach can view the training and health data needed to coach you: your workouts and logged sets, daily tracker entries (nutrition, steps, sleep, weight, water, stress, motivation, resting heart rate), check-in and onboarding answers, body measurements, progress photos, habits, and weekly AI summaries of this data. Your coach can also set your nutrition, water, and step targets, and export a progress report (weight trend and body measurements) as a PDF. Ending the coaching relationship ends this access.
Data storage and security
Your data is stored in Supabase-managed infrastructure. All data is encrypted in transit (TLS) and at rest. Access to production databases is restricted to essential personnel. Every database query filters by user ID — your data is never mixed with another user's in application logic.
Progress photos and coach-uploaded files are stored in Supabase-managed storage buckets with access controls that restrict visibility to the owning user and their assigned coach.
Data retention
- Account and training data is kept for as long as your account exists, or until you request deletion.
- AI coaching responses (audits, debriefs, chat messages) are stored for as long as your account exists. OpenAI does not retain API request data beyond their standard processing window (typically 30 days for abuse monitoring, zero days for training).
- Password-reset links expire automatically within one hour.
- Coach invite links are single-use and expire.
- Server logs are retained by Vercel on their default schedule (typically 30 days).
Your rights
Depending on your jurisdiction (including under the Australian Privacy Act 1988, the EU General Data Protection Regulation, and the UK GDPR), you may have the following rights:
- Access. Request a copy of all personal data we hold about you. We will provide it in JSON format.
- Correction. You can edit your profile, routines, and workout data directly in the app. For anything you cannot edit yourself, contact us and we will correct it.
- Deletion.Request permanent deletion of your account and all associated data. See the “Account deletion” section below for full details.
- Data portability. Request an export of your data in a structured, machine-readable format (JSON).
- Withdraw consent. You can withdraw your health-data consent at any time with the toggle on your Account page — health questions stop being asked and your health details stay out of AI coaching requests. You can also revoke HealthKit or Health Connect permissions through your device settings, and disable push notifications at any time.
- Complaint. You have the right to lodge a complaint with your local data protection authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC).
To exercise any of these rights, email info@gymbro.com.au. We will respond within 30 days.
Account deletion
You can request permanent deletion of your account at any time. Full details are on our account deletion page.
In summary:
- Email info@gymbro.com.au with the subject “GymBro account deletion request” from the email address on your account.
- We will confirm receipt within 3 business days and complete the deletion within 30 days.
- Deletion removes your account, profile, login credentials, all workout data, sets, routines, programs, check-ins, coaching reports, coach memory, progress photos, and any coach-client relationships.
- Deletion is permanent. There is no backup copy to restore from.
- We may retain standard server logs (IP, timestamp) on Vercel's retention schedule and any records required by law for legal, tax, or fraud-prevention purposes. Retained data cannot be used to access your account or training history.
You can request a data export before deletion by emailing the same address.
Children
GymBro is not intended for users under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has created an account, please contact us and we will delete it promptly.
International data transfers
Our service providers (Supabase, OpenAI, Resend, Vercel) may process data in countries outside your country of residence, including the United States. These transfers are necessary to provide the service and are covered by each provider's data processing agreements and, where applicable, Standard Contractual Clauses or equivalent safeguards.
Push notifications
We may send push notifications for workout reminders, check-in due dates, daily tracker nudges, and other service-related alerts. You can disable push notifications at any time through your device settings. We do not use push notifications for marketing or advertising.
Cookies and local storage
We use a single session cookie managed by Supabase Auth to keep you signed in. We do not use advertising cookies, tracking cookies, or third-party cookies. The app may use browser local storage for session state and UI preferences.
Changes to this policy
If we make material changes to what we collect or how we use it, we will update the “Last updated” date at the top of this page and notify account holders by email before the change takes effect. Continued use of the service after notification constitutes acceptance of the updated policy.
Contact
Questions, data export requests, deletion requests, or anything else — info@gymbro.com.au.
