The Gym Journal

Privacy Policy

Draft

This document requires legal review before it is published as the final Privacy Policy.

Data controller
[OPERATOR NAME / FULL NAME]
Address
[ADDRESS]
Contact
[SUPPORT EMAIL]
01

Data the application may process

The scope below reflects the current implementation of The Gym Journal and the services used by the application.

Firebase Authentication

  • email address
  • Firebase UID
  • email verification status
  • technical authentication session data

Firestore

  • user profile information, including email, verification status, account creation date, onboarding and subscription-plan data
  • training memory, including goals, experience level, training location, repetition range, optional body weight, limitations and exercise preferences
  • workouts, including dates, status, duration, summaries, exercise count and order
  • training chat messages
  • exercises and sets, including name, weight, repetitions, time, distance and raw input text
  • exercise state and progress
  • information entered by the user about the current workout, such as pain or fatigue
  • usage information, including monthly workout and AI-message counts
  • user feedback
  • RevenueCat subscription cache, including plan, entitlement status, store, product ID and expiration date

Firebase Functions

  • Firebase UID obtained from the authentication token
  • messages sent to the assistant
  • workout identifiers
  • data required to enforce usage limits
  • technical logs, to the extent stored by the implementation

OpenAI

The backend may send the user's message and limited training context to OpenAI when this is required to generate an assistant response.

The current implementation avoids sending the user's email address and billing or subscription data to the model.

RevenueCat

  • Firebase UID used as appUserID
  • Pro entitlement status
  • product identifiers
  • purchase store
  • renewal, expiration, cancellation, refund and billing-issue information

Apple App Store and Google Play

In-app purchases are processed by the App Store or Google Play. The operator of The Gym Journal does not process the user's payment-card details.

Analytics

The code contains an analytics layer that may register events relating to the use of the application. It filters content such as messages, raw workout text, pain descriptions and email addresses.

No external analytics provider is currently connected in the reviewed implementation.

Crash reporting

No separate crash-reporting integration such as Sentry or Firebase Crashlytics was identified in the reviewed implementation.

02

Purposes of processing

  • creating and operating user accounts
  • saving workouts and conversation history
  • generating AI assistant responses
  • displaying workout history and progress
  • enforcing Free-plan usage limits
  • managing The Gym Journal Pro subscriptions
  • restoring purchases
  • security, diagnostics and abuse prevention
  • handling feedback and user contact
03

Legal bases

The legal bases for processing require final legal review. Depending on the category of data and purpose, they may include performance of a contract or pre-contractual steps, legal obligations, legitimate interests and consent where required.

LEGAL REVIEW REQUIRED — the appropriate legal basis for each category and purpose of processing must be confirmed before publication.

04

Data that may reveal health information

Users may voluntarily enter information about pain, fatigue, limitations or injuries. Such information may reveal health-related information.

The application does not require users to provide medical diagnoses.

LEGAL REVIEW REQUIRED — the applicable legal basis and obligations relating to this data must be verified before publication.

05

Service providers and international transfers

The Gym Journal uses or may use Firebase / Google Cloud, OpenAI, RevenueCat, Apple App Store and Google Play.

Data may be processed outside the European Economic Area.

LEGAL REVIEW REQUIRED — data-transfer mechanisms, processing agreements and required user disclosures must be verified.

06

Data retention

Account and training data are retained while the user's account remains active or for as long as necessary to provide the service, maintain security, handle billing or comply with legal obligations.

When an account is deleted, the current implementation removes the user's associated Firestore data and Firebase Authentication account.

Purchase history held by Apple, Google or RevenueCat may be subject to separate retention rules.

LEGAL REVIEW REQUIRED — retention periods for logs, feedback and subscription-related data should be defined more precisely.

07

Security

The application uses Firebase Authentication, Firestore Rules and a Firebase Functions backend. Operations requiring authorization are protected by Firebase token verification.

The application client should not be able to modify protected subscription or usage-limit fields directly.

08

User rights

  • access to personal data
  • rectification
  • deletion
  • restriction of processing
  • objection
  • data portability where applicable
  • withdrawal of consent where processing is based on consent
  • the right to lodge a complaint with the competent supervisory authority

LEGAL REVIEW REQUIRED — the final scope and process for exercising these rights must be legally verified.

09

Account deletion

Users may request deletion of their account. The current implementation deletes associated Firestore data and the Firebase Authentication account.

Data associated with purchases in RevenueCat, the App Store or Google Play may be subject to separate retention requirements.

10

Changes to this policy

This Privacy Policy may be updated as the application evolves. Material changes should be communicated to users in accordance with applicable law and platform requirements.

11

Contact

For privacy-related matters, contact: [SUPPORT EMAIL].