Gym+ Gym+

EN Languages

Privacy policy

Version 1.0Effective 21 September 2026Applies to the Gym+ app and this website

Gym+ is a training log. Most of what you record never leaves your device, and the health data the app reads — heart rate, calories and steps — never does. This document explains exactly what is read, what for, what leaves the device and what you can require of us.

1. Who is responsible

The Gym+ app is published and operated by ALAS TECHNOLOGY LLC, a company registered in the United States under IRS Employer Identification Number (EIN) 93-3927200.

Under the GDPR we are the controller of the data described here. Under Brazil's LGPD we are the controlador.

Data protection officer (LGPD, art. 41): the officer's official channel is privacy@gymplus.life. That address receives any request, question or complaint about personal data, and it is the channel through which we deal with data protection authorities when needed.

2. Health data

This is the part that matters most, so it comes first.

What the app reads

If — and only if — you allow it, Gym+ reads from Apple Health (HealthKit) on iPhone and from Health Connect on Android:

And it writes back a single thing: the workout session you have just finished, so it counts towards your activity for the day and shows up in the system health app's history.

What for

To show, inside the workout you logged, what your body did while it was happening, and to display charts and trends of that same data. Those charts and trends are calculated on the device itself. There is no other purpose — not statistical, not commercial, not recommendation.

What never happens to it

How to withdraw permission

Withdrawing permission does not erase what is already in your health app — that history is managed by the system itself, and that is where it gets deleted. Gym+ simply stops reading.

3. What stays on the device

The following stays on your device, in the app's private storage, and is not sent to us:

If you uninstall the app, this data is removed from the device along with it. We hold no copy of it to give back. When you export a backup or share a workout, the file goes wherever you choose, on your own initiative.

4. What leaves the device

Only what is described below, and each item only when you use the corresponding feature.

4.1 Your account

The account is created with Sign in with Apple or Sign in with Google. There is no Gym+ password. When you sign in, Apple or Google hands the app a signed proof of identity, and the app sends it to our server, which checks the signature against the provider's published keys. From that we receive:

The name Apple may show on your first sign-in stays in the app's memory only and is not sent to us. The session credentials our server returns are kept in memory only and are discarded when you sign out or close the app.

4.2 Subscription verification

To know whether your subscription is valid, the app sends our server the purchase identifier issued by the store (Apple or Google) and the product identifier. The server checks with the store itself and keeps the result: the plan (Aluno or Coach), the subscription state (free trial, active, grace period, expired, revoked), the expiry date and the date of the last check, linked to your account. The store also notifies our server when the subscription changes state — renewal, cancellation, refund.

We do not receive or store card numbers, bank details, billing address or any means of payment. The store charges you, and the store keeps that.

4.3 The weekly review

When you ask for the weekly review, and only then, the app sends our server:

Twelve numbers, a language and a goal. No exercise names, loads, reps, photos, measurements, notes, raw history or any health data. The current week is deliberately left out, because it has not closed yet. The server writes the review text, returns it to the app and does not keep those numbers.

4.4 The referral programme

If you use invite-a-friend, the server keeps your invitation code, who invited whom and what stage each invitation is at. To stop a single device from creating several accounts just to collect rewards, the app sends an installation identifier that it generates at random itself. It is neither a hardware nor an advertising identifier, it changes if you reinstall the app, and the server stores it only as a keyed cryptographic digest. When you claim a month you have earned, we use your account email to arrange how it reaches you.

4.5 Messages you send us

If you write to one of our email addresses, we receive the message, your address and whatever you decide to include, such as screenshots. We use that only to reply and resolve the request.

5. Who we share with

We do not sell personal data. We do not trade personal data for services, discounts or any other consideration. The only third parties involved are the ones that make the app possible:

Third parties that process Gym+ data
WhoWhat they receiveWhy
Apple and Google (stores) Your purchase and the subscription state They sell, charge for and manage the subscription. They process that data as controllers in their own right, under their own privacy policies.
Apple and Google (sign-in) The fact that you signed in to Gym+ with their account They authenticate you and hand us the proof of identity. They process that data as controllers in their own right, under their own privacy policies.
Cloudflare Account identifier, email, subscription state, referral programme data, the twelve weekly-review numbers while the review is generated, and the IP address and technical data of anyone reaching the server and this website Hosting of our server and database (Cloudflare Workers and D1), hosting of this website and forwarding of email sent to @gymplus.life addresses, as a processor engaged by us.
Google (Google Workspace) The messages you send us by email The company mailbox where we read and answer them, as a processor engaged by us.

We may also share data when there is a court order, a request from a competent authority or a legal obligation — and, where the law allows us to tell you, we do.

6. How long we keep it

Retention periods
WhatPeriod
Health dataWe do not keep it. It never leaves the device.
Log, profile, photos, measurements, notesWe do not keep them. They stay on the device until you delete them or uninstall.
Account (identifier and email)For as long as the account exists. Once the account is deleted, they are erased.
Subscription stateFor as long as the account exists. Once the account is deleted, the link to you is erased.
Tax record of the paymentFor the period required by the applicable tax legislation.
Referral programme (code and installation markers)For as long as the account exists. Once the account is deleted, they are erased and open invitations are closed.
Used-purchase marker (tombstone)Indefinitely. It is an irreversible cryptographic digest of the account identifier and the purchase key, with no email and no name.
Twelve weekly-review numbersWe do not keep them. They are used to generate the review and discarded.
Email messagesFor as long as needed to resolve the request and, after that, for the period the law requires to evidence how it was handled.

The purchase marker exists for one specific reason: to stop a subscription that has already been used from being transferred or reused on another account after the first one is deleted. It cannot be used to re-identify you or to recover anything that was yours.

7. LGPD — your rights in Brazil

Legal bases

Legal bases under the LGPD
ProcessingLegal basis
Account, subscription, weekly review and referral programmePerformance of a contract — art. 7, V
Reading heart rate, calories and steps (sensitive health data)Specific and highlighted consent — art. 11, I
Tax record of the paymentCompliance with a legal obligation — art. 7, II
Used-purchase marker and installation marker, against fraudLegitimate interest — art. 7, IX
Replying to messages and requestsPerformance of a contract and exercise of rights — art. 7, V and VI

What you can require

At any time, free of charge, you can request (LGPD art. 18):

To exercise any of them, write to privacy@gymplus.life. We reply within 15 calendar days. There is a direct path inside the app to delete your account, described in Delete account.

If you believe we have mishandled your data, you can complain to Brazil's National Data Protection Authority (ANPD).

8. GDPR — your rights in Europe

Gym+ has an interface in 16 languages and is sold on the Apple and Google stores in countries of the European Economic Area. If you are in the EEA, the United Kingdom or Switzerland, the rules below also apply.

Legal bases (art. 6 and art. 9)

International transfers

The controller is a company registered in the United States, and our server, the database, this website and email forwarding run on Cloudflare's infrastructure, which may process data in data centres outside your country, including in the United States. Account, subscription and referral programme data may therefore be transferred outside the EEA.

Cloudflare is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) and incorporates the Standard Contractual Clauses approved by the European Commission (art. 46(2)(c)) into its data processing agreement. Google, which hosts our mailbox, offers the same safeguards. You can ask us for a copy of the applicable safeguards.

It is worth stating what is not transferred: no health data. It does not leave the device, so there is no international transfer of special-category data.

Your rights

Requests: privacy@gymplus.life. We reply within one month, as the GDPR requires, and usually much sooner.

Automated decision-making

The weekly review is an arithmetic comparison across four weeks, not a profile of you. We make no automated decision that produces legal effects or similarly significantly affects you, within the meaning of art. 22.

9. Children and teenagers

Gym+ is not intended for anyone under 13 and we do not knowingly collect data from anyone below that age. In countries where the minimum age to consent is higher — in the EEA it can be up to 16 — the local age applies, and use requires permission from whoever holds parental responsibility. If you learn that a child created an account without that permission, write to privacy@gymplus.life and we will delete it.

10. Security

No system is unbreakable. If a security incident creates a relevant risk, we will notify you and the competent authorities within the deadlines the LGPD and the GDPR require.

11. This website

This website uses no advertising or analytics cookies, loads no font, script or image from another domain and builds no profile of visitors. Its only cookie is gp_lang, set by the site itself: it is created only when you pick a language in the selector, and it keeps that choice for up to one year so the site opens in the same language next time. Cloudflare, which hosts the site, logs the IP address and technical request data for as long as needed to deliver the page and protect the infrastructure.

12. Changes to this policy

When this policy changes, the effective date at the top changes with it and the previous version stops applying from then on. If the change materially affects what we do with your data, we will tell you inside the app before it takes effect.

13. How to reach us

ALAS TECHNOLOGY LLC · EIN 93-3927200