gymmit.

Privacy Policy

Effective: 25 February 2026 Version: 1.1 Governed by: nonch. development

Data is protected

Only what is necessary to run gymmit. is collected. Personal information is never sold to third parties.

Users are in control

Data can be accessed, updated, exported, or permanently deleted at any time from within the app.

Minimal sharing

Data is only shared with trusted service providers necessary to operate the platform — never for advertising.

Fitness data is sensitive

Health metrics, body stats, and nutrition data are treated with extra care and strict access controls.

Contents

  1. Who We Are
  2. Data Collected
  3. How Data Is Used
  4. Data Sharing
  5. Media & Uploaded Content
  6. Social Features & Visibility
  7. Data Retention
  8. Your Rights
  9. Security
  10. Children's Privacy
  11. Third-Party Services
  12. Changes to This Policy
  13. Contact
01

Who We Are

gymmit. is a fitness and social tracking application developed and operated by nonch. development. This Privacy Policy explains how personal information is collected, used, stored, and protected when gymmit. is used, and what rights users hold in relation to that data.

By creating an account and using gymmit., the user acknowledges that they have read and understood this Privacy Policy. This policy forms part of the Terms of Service.

02

Data Collected

Account & Profile Data

Onboarding & Fitness Profile

During onboarding, users may optionally provide:

This data is used to personalise the experience. It is not required to use the core app.

Workout & Activity Data

Nutrition & Food Data

Social & Content Data

Uploaded Media

Subscription & Purchase Data

gymmit. does not collect or store payment card details — all payments are handled entirely by Apple. The following subscription-related data is stored to determine which features an account can access:

This data is received via webhook from RevenueCat, our subscription management provider, and is stored securely on our servers. It is used solely to grant or revoke access to Gymmit Pro features.

Technical & Usage Data

03

How Data Is Used

Purpose Data Used Legal Basis
Providing the serviceAll account, workout, nutrition, and content dataContract performance
PersonalisationFitness profile, goals, historyContract / Legitimate interest
Social featuresProfile, posts, followsContract performance
Subscription managementSubscription status, entitlement data, billing periodContract performance
Content moderationUploaded media (scanned, not retained by moderation provider)Legitimate interest / Legal obligation
Push notificationsNotification token, activity triggersConsent
Bug reports & supportError logs, user-submitted descriptionsLegitimate interest
Security & fraud preventionAccount data, usage patternsLegitimate interest / Legal obligation
Legal complianceData as required by lawLegal obligation

Data is not used for advertising purposes. gymmit. does not display ads and does not share personal data with advertising networks or data brokers.

04

Data Sharing

Personal data is not sold. Data is shared only in the following limited circumstances:

Service Providers

Trusted third-party providers are used to operate gymmit. These providers only process data on behalf of nonch. development, according to its instructions, and are bound by strict data protection agreements:

Legal Requirements

Data may be disclosed if required to do so by applicable law, court order, or governmental authority, or to protect the rights, property, or safety of nonch. development, users, or the public.

Business Transfers

If nonch. development is involved in a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. Users will be notified via in-app notification or email if this occurs and given the opportunity to delete their account beforehand.

Public Content

Content marked as "Public" (posts, workout shares, username, profile picture) is visible to other gymmit. users. Privacy settings can be changed at any time to switch posts or a profile to private.

05

Media & Uploaded Content

Storage

Uploaded media is stored securely in cloud storage provided by Supabase. Access is restricted to authenticated users with the appropriate permissions. Signed, time-limited URLs are used to serve media.

Content Moderation

All uploaded images are passed through an automated AI moderation service (powered by OpenAI) to detect prohibited content. Images are analysed in real time and not stored by OpenAI — only the moderation result is retained.

What Is Stored About Media

Deletion

When a post or account is deleted, associated media files are queued for removal. Media may persist in backups for up to 30 days following deletion.

Other People's Media

Images or videos of other people must not be uploaded without their consent. If a user appears in content uploaded by another user and wishes to have it removed, contact details are in Section 13.

06

Social Features & Visibility

How data is visible to others depends on user settings:

DataDefault VisibilityChangeable?
Username & display namePublicVia profile settings
Profile photoPublicVia profile settings
PostsPublic or Private (chosen per post)Yes — per post toggle
Workout historyPrivate (only shown if shared in a post)Shared via post creation
Weight / body metricsPrivateVia settings toggle
Calorie data on feedVisible to followers (if post is public)Via settings toggle
Follow listVisible to followersLimited controls
Streak dataVisible if shared in a streak postVia post privacy settings
Subscription statusPrivateNot shared with other users

Privacy settings can be reviewed and updated at any time via Settings → Privacy.

07

Data Retention

Data is retained for as long as an account is active or as needed to provide the service:

When an account is deleted via Settings → Account Management → Delete Account, the deletion process begins immediately. Anonymised or aggregated data that cannot identify a user may be retained indefinitely.

08

Your Rights

Depending on location, users may hold the following rights in relation to their personal data:

Access

Request a copy of the personal data held.

Rectification

Correct inaccurate data via profile settings.

Erasure

Request deletion of personal data.

Portability

Request an export of data in a machine-readable format.

Restriction

Request limited processing in certain circumstances.

Object

Object to processing based on legitimate interests.

Withdraw Consent

Withdraw consent for processing relying on consent (e.g. notifications).

Complaint

Lodge a complaint with a local data protection authority.

To exercise any of these rights, contact nonch. development using the details in Section 13. Responses will be provided within 30 days.

In-App Controls

09

Security

Industry-standard security safeguards are implemented including:

No method of transmission or storage is 100% secure. While every reasonable precaution is taken, absolute security cannot be guaranteed. If an account is suspected to be compromised, the password should be changed immediately and nonch. development contacted.

Data Breach Notification

In the event of a data breach likely to result in risk to user rights and freedoms, users and applicable regulatory authorities will be notified as required by law, without undue delay.

10

Children's Privacy

gymmit. is not directed at children under the age of 13. Personal information is not knowingly collected from children under 13. If it is believed a child under 13 has created an account without parental consent, contact nonch. development immediately and the account and associated data will be deleted.

Users aged 13–17 are considered minors and must have parental or guardian consent to use gymmit. Parents are recommended to review the data their children share on the platform and use the available privacy settings to limit public visibility. In-app purchases by users under 18 require parental approval through Apple's Family Sharing controls.

11

Third-Party Services

gymmit. integrates with the following third-party services, each of which has its own privacy policy:

gymmit. is not responsible for the privacy practices of these third-party services. Data shared with them is limited to what is strictly necessary for their respective functions.

12

Changes to This Policy

This Privacy Policy may be updated from time to time to reflect changes in practices, legal requirements, or the services offered. When material changes are made, users will be notified via push notification, in-app alert, or email at least 14 days before the changes take effect.

Continued use of gymmit. after updates become effective constitutes acceptance of the revised policy.

13

Contact

For any privacy-related questions, data requests, or concerns:


nonch. development

In-app: Settings → Report a Bug

Email: gymmit@nonch.uk


Responses to all data rights requests will be provided within 30 days of receipt. For subscription billing issues, contact Apple directly at reportaproblem.apple.com. See the Terms of Service for the full conditions of using gymmit.