LEGAL
Privacy policy Terms of service
Last updated
June 23, 2026
PRIVACY

Privacy policy

Gymbora is a workout app, so the data it holds is your training data. This page says what's collected, why, who else sees it and how to get rid of it — written from what the app actually does, in plain language.

Who we are and what this covers

Gymbora is made by Gymbora LLC ("Gymbora", "we", "us"), a company in the United States. We are the data controller for the personal data described here. Questions about anything on this page go to support@gymbora.com.

This policy covers the Gymbora app for iPhone and Android, the Apple Watch app and home-screen widgets, workout pages you share at gymbora.com/w/…, and this website. It doesn't cover Apple, Google or any other company's services, even where we link to them — they have their own policies.

By using Gymbora you agree to the practices described here. If you don't agree, please don't use the app; if you already have an account, you can delete it at any time (see Your rights).

What the app collects

Only what a training log needs. Here is the full list, grouped by where it comes from.

THINGS YOU GIVE US
Account details
Your email address and how you signed in — a code we email you, Sign in with Apple, Google or Facebook. Those services share your name, email and (Google and Facebook) profile photo with us; they never share your password. You can use the app without an account: in that case nothing here leaves your phone except coach messages (see below).
Profile
A display name, an optional profile photo, and — if you choose to enter them during setup — your birth date, gender, height and weight. The height and weight step is skippable, and you can edit or remove any of this later.
Training data
Your training days and goal, the plan and routines built for you, every workout you log (exercises, sets, weight, reps, rest, duration, notes), personal bests, and cardio sessions (run, ride, swim). This is the app's purpose, and it's what lets the coach answer about your training.
Cardio routes
If you turn on location for a run or ride, the route is saved with that session as a reduced set of GPS points. Location is only used while the app is open and a session is recording — never in the background.
Health measurements you enter
Weight, water intake and mood check-ins — only what you type in. In several jurisdictions this counts as sensitive personal data, which is why it's kept for the app's function and nothing else.
Progress photos
Only if you add them. They're stored privately in your account and are never shown to other users.
Coach conversations
Your messages and the coach's replies are saved so you can come back to a thread. To generate a reply, your message and relevant workout history are sent to Google's Gemini API — see Who else sees it.
Feedback and support messages
Anything you send us in-app or by email, including your email address so we can reply.
THINGS WE READ FROM YOUR PHONE — WITH YOUR PERMISSION
Steps
From Apple Health (iPhone) or Health Connect (Android). We ask before reading, and you can turn it off at any time in your phone's settings. Step counts power the health dashboard and step-goal reminders and are not used for anything else.
Workouts written back
When you finish a session we write it to Apple Health, so your rings and other health apps stay accurate. Only with your permission.
Motion
The phone's pedometer, to count steps and estimate distance during treadmill and indoor sessions.
Camera and photo library
Only when you choose to add a profile or progress photo.
Notifications
If you allow them, we store a push token for your device so we can send workout reminders on training days, step-goal alerts, hydration and mood reminders, a heads-up before a trial ends, and a check-in if you've been away. Each one can be turned off in Settings.
COLLECTED AUTOMATICALLY
Device and app information
App version, operating system and version, device model, language, timezone and country, and which store you subscribed through.
Usage analytics
Which screens are opened and which features are used — for example that a workout was started, a plan was built, the paywall was shown or a trial began. Collected through Firebase Analytics and, while you're signed in, linked to your user ID so we can see where people get stuck and what's worth building. You can switch analytics off in Settings.
Crash and performance reports
Through Firebase Crashlytics: device model, OS version and what the app was doing when it crashed. Used to find bugs.
Subscription data
Your subscription status, product (monthly or yearly), trial start and end dates, and the store's transaction identifier, received from Apple or Google when you buy, renew or cancel. We never receive your card number or billing address.
Engagement metrics
Computed from your own data: first and last workout dates, total workouts completed, streaks, and whether you finished setup.
Security signals
Firebase App Check attestation, which confirms requests come from the genuine Gymbora app, and one-time sign-in codes that expire after ten minutes.

Using Gymbora as a guest. Without an account, your plan, workouts, check-ins and preferences stay on your phone and are not sent to our servers. The exception is coach messages, which are answered using a random guest identifier so we can apply the free-message allowance. Create an account later and we move that history into it; delete the app as a guest and the data is gone.

What we deliberately don't collect. No contacts, no location outside cardio sessions, no advertising identifiers, no cross-app tracking, no card numbers, no heart-rate, sleep or nutrition data. If the app ever starts reading a new type of health data it will ask you first, and this page will be updated.

How we use it

To run the app
Build your plan, show your last numbers next to the set you're about to do, keep your history, sync between your phone, watch and widgets, and answer coach questions with your real training context.
To keep your account working
Sign you in, restore purchases, apply the free-workout allowance and unlock Pro.
To send notifications you asked for
Workout reminders, step-goal alerts, hydration and mood reminders, a heads-up before a trial ends, and a check-in if you've been away. All optional.
To improve Gymbora
Understand which features are used, where people drop off during setup, and which crashes to fix first. This uses aggregated analytics; we don't read individual workouts to do it.
To answer you
When you write to support or send feedback.
To keep the service safe
Detect abuse of the coach, block fake clients, enforce our terms and meet legal obligations.

We do not use your data to build advertising profiles, we don't show ads, and we don't sell or rent personal data to anyone.

If you are in the EEA, UK or Switzerland, our legal bases are: performance of our contract with you (running the app and your subscription); your consent (reading health data, location, notifications, analytics, and the optional body metrics you enter); our legitimate interests (improving and securing the app, preventing abuse, communicating with you about your account); and legal obligation (tax and accounting records for purchases). You can withdraw consent at any time in the app or your phone's settings without affecting the rest of the service.

Health data, specifically

Data from Apple Health, Health Connect and your phone's motion sensors is treated as sensitive. Our rules for it:

Permission first
We only read it after you grant permission in the system dialog, and only the types listed above — steps.
Never for advertising
Step counts are not sold, not used for advertising or marketing, and not shared with third parties.
Written back only when you say so
Workouts go to Apple Health only when you finish a session and only if you allowed it.
You can revoke it any time
iPhone: Settings → Health → Data Access & Devices → Gymbora. Android: Health Connect. The app keeps working without it.

We comply with Apple's HealthKit and Google's Health Connect developer policies, which prohibit using this data for advertising, data brokering or any purpose other than providing the feature you asked for.

The AI coach

When you message the coach, or ask it to build a plan or routine, your message goes to our servers (Firebase Cloud Functions), which add the context needed to answer — your recent workouts, the lifts that have stalled, your training days and goal — and send it to Google's Gemini models through the Gemini API. The reply comes back the same way and is stored in your chat history.

What Google gets
The message and the training context needed to answer it. Never your email address, name, photos or payment data. Google processes it as our service provider under its Gemini API terms; we don't permit it to be used for advertising.
It can be wrong
The coach is a language model, not a medical professional. Treat its answers as suggestions, not instructions, and don't paste medical records or anything you wouldn't want processed by an AI service.
You control the history
Delete any conversation from the chat screen. Deleting your account deletes all of them.
Abuse limits
To prevent abuse we keep a count of messages and their cost per user. For guests this is tied to a random identifier, not to you.

Who else sees it

We don't sell your data and we don't share it for advertising. These providers process it so the app can work, and aren't allowed to use it for anything else:

Google Firebase / Google Cloud
Sign-in, the database your history is stored in (Firestore), file storage for photos, cloud functions, push notifications, analytics, crash reporting and App Check.
Google Gemini API
Generates the coach's replies and plans. Your message and the workout context needed to answer it are sent for that purpose (see The AI coach).
Apple and Google
Sign in with Apple / Google if you use them, and all subscription billing through the App Store and Google Play. They tell us whether you have an active subscription; we never see your card details.
Meta
Only if you choose Facebook to sign in — it provides your name, email and photo.
Zoho ZeptoMail
Delivers the sign-in code emails and the transactional emails we send you.

We may also disclose data if the law requires it, to protect the safety of a user or the public, to enforce our terms, or — with notice to you — if Gymbora is ever acquired or merged, in which case this policy keeps applying until you're told otherwise.

These providers operate globally, so your data is stored and processed in the United States and may be processed in other countries. Where required, transfers from the EEA, UK or Switzerland rely on the providers' Standard Contractual Clauses or the EU–US Data Privacy Framework.

What other people can see

Leaderboard
If you take part, other users see your display name, profile photo, points and rank tier. Nothing else — not your workouts, weight or email. Change your name and photo in Settings.
Shared workouts and routines
When you tap Share, we create a public page at gymbora.com/w/… showing the workout's title and exercises, plus a share card built from your numbers (volume, sets, top lifts). Anyone with the link can open it. Your email and other profile data are never included. Shared pages are removed when you delete your account.

Everything else in your account is private to you.

How long it's kept

Your account and history
For as long as your account exists — a workout log is only useful as a record over time, so we don't expire it. Accounts not opened for 24 months may be deleted after we email you a warning.
When you delete your account
Your profile, workouts, plans, routines, check-ins, photos, coach conversations, push tokens, leaderboard entry and shared pages are deleted immediately by an automated process. Copies in encrypted backups are overwritten within 30 days.
Sign-in codes
Expire after ten minutes.
Crash reports and analytics
Kept by Firebase for up to 90 days (crash data) and 14 months (analytics), then deleted or aggregated.
Purchase records
Records we're legally required to keep for tax and accounting are retained for the period the law requires, separated from your deleted account.
Support emails
Kept for up to two years so we can follow up on the same issue.

Security

Data is encrypted in transit (TLS) and at rest on Google Cloud. Firebase security rules restrict access to your own account, and every request must pass App Check to prove it comes from the genuine app. There are no passwords to leak: sign-in uses one-time emailed codes or Apple, Google and Facebook sign-in. Access to production systems is limited to the people who need it to run the service.

No system is perfectly secure. If we learn of a breach that affects your data, we'll notify you and the relevant authority as the law requires.

Your rights and choices

Wherever you live, you can:

See and edit
Your profile, body metrics, plan and history — inside the app.
Delete your account
Settings → Login & security → Delete account. Immediate and irreversible.
Get a copy of your data
Email us and we'll send it in a machine-readable format within 30 days.
Turn things off
Analytics (Settings), notifications (Settings or your phone), health access and location (your phone's settings).
Delete individual items
Workouts, routines, photos, check-ins and coach conversations, from the screens where they appear.

Depending on where you live you may also have the right to correct or restrict processing, to object to processing based on legitimate interests, to withdraw consent, to data portability, and to complain to a supervisory authority. To exercise any right, email support@gymbora.com from the address on your account. We respond within 30 days and never charge for it; we may ask you to confirm you own the account first.

We don't make decisions about you with legal or similarly significant effects using automated processing. The coach's suggestions are exactly that — suggestions.

Region-specific notices

European Economic Area, United Kingdom and Switzerland
You have the rights under the GDPR and UK GDPR described above, and the right to lodge a complaint with your local data protection authority. Our legal bases are listed under How we use it. We don't have an establishment in the EU; send GDPR requests to the address under Contact.
California and other US states
Under the CCPA/CPRA and similar state laws you have the right to know what personal information we collect and how we use and share it (this page), to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; we also don't use or disclose sensitive personal information (such as health data) for anything other than providing the features you asked for. An authorized agent can make a request for you by emailing us with proof of authorization.
Brazil
You have the rights under the LGPD, including confirmation of processing, access, correction, anonymization, portability and deletion. Requests go to the same address.

Children

Gymbora isn't intended for children under 13, and we don't knowingly collect their data. In the EEA and UK, where the law sets a higher age of digital consent (up to 16), you must be at least that age to create an account. If you believe a child has created an account, email us and we'll remove it.

Changes

When we change how the app handles data, we update this page and the date in the sidebar. For material changes — new data types, new sharing, new purposes — we'll also say so in the app or by email before they take effect. Continuing to use Gymbora after that means you accept the updated policy.

Contact

Gymbora LLC
Privacy questions and requests: support@gymbora.com

Gymbora is a small team, so the email goes to the people who build the app. You'll usually hear back within two working days.

Gymbora Gymbora

Training plans, logging and a coach that reads your numbers. Built for iPhone, Android and Apple Watch.

PRODUCT
Features App Store Google Play
HELP
Support FAQ Contact
LEGAL
Privacy policy Terms of use
© 2026 Gymbora LLC. All rights reserved.