Privacy Policy
Last updated: August 2026
Your privacy matters. This policy explains what data GymKynex collects, how we use it, and the choices you have. By using the app you agree to this policy.
1. Data we collect
We collect only what the app needs to work:
Account data (email, name), profile data you enter (goal, level, weight, height, training days, injuries), your workout logs, nutrition logs, body measurements, and coach conversations. If you choose to use them: photos you upload (meal photos for calorie estimates, progress photos, or a photo you send the coach), voice notes you record for the coach, and health data you import from Apple Health. All of these are optional. The app works without them.
2. How we use your data
Your data is used to run the app: build your plans, track progress, personalize the AI coach, and show your history. We do not sell your personal data to anyone.
3. Data isolation
Every account is fully isolated. Row-Level Security at the database level ensures no user can ever access another user's workouts, meals, measurements or conversations.
4. AI processing
When you use the AI coach or photo features, the relevant text or image is sent to our AI provider (Anthropic) to generate a response. When you send the coach a voice note, the audio is sent to our transcription provider (OpenAI) to convert it into text; only that text then goes to the coach. We do not keep a copy of the audio. This data is processed to give you a result and is handled according to each provider's data policies. Please avoid uploading sensitive personal documents unrelated to your fitness.
5. Storage and security
Your data, including photos and voice notes, is stored with our infrastructure provider (Supabase). It is encrypted at rest using AES-256 and encrypted in transit using TLS, always on. Photos are kept in private storage that requires an authenticated request tied to your account.
Row-Level Security means no other user can reach your data. In plain terms: your account is private, and only you can access it by signing in. One thing worth stating plainly: encryption at rest protects your data if the physical storage were ever compromised, but it does not make your data invisible to us as the operator. To run the app (show your photos, let the coach read your history) our systems have to be able to decrypt it. We access it only to operate and support the service, never to sell it. We support passkey sign-in (Face ID / fingerprint) for stronger account security.
6. Your rights
You can view and edit your profile data any time in Settings. You can request full deletion of your account and data. See our Data Deletion page.
7. Cookies
We use two kinds, and they work differently.
Keeping you signed in. One session cookie. Without it you would have to log in again on every screen, so it is always on and there is nothing to choose.
Making the app better (your choice). Two cookies of our own, gk_aid and gk_sid. They hold random numbers: one for the current visit, and one so that coming back tomorrow is not counted as a brand new person. They are not built from anything about you and they are not shared with anyone. There are no ads, no third parties, and no tracking across other sites. If you choose Essentials only, they are never set.
What they help us see: which screens get opened, which features actually get used, how far a page is read, and where the app breaks. What they never contain: your IP address, your full browser details, your coach conversations, your meal notes, or your photos. Your approximate country is worked out from the connection at our edge network, and the IP address itself is never stored.
These records are deleted after 90 days. Only anonymous daily totals, which cannot be traced to anyone, are kept longer. To change your answer, clear this site's cookies in your browser and the notice will ask again.
Counting visits without cookies. Separately from all of the above, we keep a simple count of how many times each page is opened. This runs for everyone, including if you choose Essentials only or never answer the notice at all. It records the date, the page, a rough device type (phone, tablet or computer), your approximate country, and whether the cookie notice had been answered.
It sets no cookies, reads nothing stored in your browser, and does not build a fingerprint from your device, screen, fonts or settings. Because there is no identifier of any kind, these records cannot be linked to each other, to you, or to your account — which also means we genuinely cannot tell how many different people visited, only how many pages were opened. We think that is the right trade: we can see that the site is being used without following anyone around. Declining analytics stops analytics; it is never worked around by other means.
8. Payments
Subscriptions run through Stripe. Your card details are entered on Stripe's own checkout page and never reach our servers. We keep only what is needed to run your subscription: a Stripe customer reference, which plan you are on, its status, and the renewal date.
Prices are shown and charged in US dollars with tax included, so the price you see is the price you pay. You can view invoices, change your card, or cancel at any time from your profile, which opens Stripe's own billing portal.
9. Contact
Privacy questions? Email soporte@gymkynex.com.