Gymmons Privacy Policy

Last updated: 28/09/2026

Gymmons is a workout motivation app that turns physical activity check-ins into progression for collectible creatures (Gymmons), GymEggs, private leagues between friends and a social feed. This policy explains what personal data we collect, why we use it, who we share it with and how you can delete it.

Who is responsible for your data

Gymmons is operated independently. Questions and requests to access, correct or delete data can be sent to marcoasjunior90@gmail.com.

What data we collect

We do not collect contacts, browsing history or payment data. We do not track location in the background, use location for advertising, sell this data or receive a continuous trail of your movements.

Closed beta waitlist

People who sign up through the closed beta page do not yet have an app account. In that signup, we collect only your email and which phone will be used for the test (Android, iPhone or both). We also store the date you gave consent and, when the link included that information, the channel through which you arrived (for example, a specific campaign). We do not ask for your name or any workout data at this stage.

This list is separate from app accounts: if you join the list and later create an account, they are different records, and deleting one does not automatically delete the other.

How we use this data

We do not use your data for advertising, and we do not sell data to third parties.

Who we share data with

Your data may be processed by the following service providers to operate the app, according to the purposes and policies described below:

If you sign in with Google or Apple, the app confirms your identity directly with them before creating or accessing your account — we do not send your data to Google or Apple; we only receive what is needed to confirm who you are.

Exact location is not sent to league members, the feed or sharing cards. If you enter a place name and choose to share it, only that name may appear to the corresponding league. Geoapify receives a rounded position, at a scale of tens of meters, only when you request suggestions for nearby places; advertising and location analytics providers do not receive this data.

Location permission

The app requests foreground location permission only when you tap to record a workout location. Before the system prompt, we explain the purpose inside the app. If you choose to search for a nearby gym, we use your position only for that one suggestion. You can deny or revoke permission in your device settings, or continue without location; this does not prevent check-ins, starting a workout or progression.

Apple Health and Health Connect

This integration is optional and is checked only after you tap to allow it inside the app and in your device system. It reads only exercise sessions completed on the current local day and never requests permission for steps, calories, heart rate, routes, sleep, health history or background delivery. You can ignore the suggestion, stop importing in Gymmons or revoke permission in Apple Health or Health Connect settings at any time.

Raw health records, titles, notes, device source and the native identifier are not sent to Gymmons. If you confirm the check-in, we send only the provider and an opaque session hash to prevent the same session from being recorded twice, along with the normal data you reviewed in the check-in. The import source does not appear to the league, in the feed or in shared images.

Security

All communication between the app and our servers uses HTTPS. Passwords are stored as hashes. Check-in photos are not exposed through public URLs — they are served only through an authenticated route to the user. Location coordinates are stored encrypted and are not returned in public league, feed or sharing resources.

Deleting your account and data

You can delete your Gymmons account at any time directly in the app, under Profile → Delete account (you must confirm by typing your account email). If you prefer, you can also request deletion by email at marcoasjunior90@gmail.com, using the email registered on the account. We process the request within 30 days.

Deleted immediately: your account record (name, email and password), avatar, check-in photos, Gymmons, GymEggs, workout and experience history, workout import hashes, location records and snapshots, participation in every league, and your reactions, comments and league chat messages.

What may remain: events you created in the feed and the collective knockout history of leagues you joined may remain visible to other members while the league exists, but anonymously. The system removes your name, email, direct account identifier, avatar and Gymmon nicknames from snapshots; it preserves only the structure needed to show the result and a generic event description (such as the activity type). Deleting the league removes that history with it.

If you sent feedback through the app, the report itself is kept so we can finish resolving it after deletion, but it is no longer linked to your account.

Removing only location

Even without deleting the workout, you can remove the location associated with a check-in through the app privacy flow. Removal deletes the coordinates, accuracy, capture time and place name for that record.

Your rights

Under Brazil’s General Data Protection Law (LGPD), you may request at any time access to the data we hold about you, correction of inaccurate data, account deletion and data portability. Write to marcoasjunior90@gmail.com.

Children

Gymmons is not directed at children under 13 and does not knowingly collect data from children in that age group.

Changes to this policy

We may update this policy as the app evolves. The date at the top of this page always indicates the most recent version.