Gymdeed Privacy Policy
Draft — this text is still being reviewed before launch.
Version 1 · effective [date of publication]
1. Who we are
Gymdeed is an iPhone app that counts your reps and coaches your form with the camera. It is made and run by Halil Kaan Karan, an individual developer in Istanbul, Türkiye, who is the data controller for the personal data described here ("we", "us").
- Data requests and privacy questions: [email protected]
- Everything else: [email protected]
- EU representative (GDPR Art. 27): [EU representative — to be appointed]
- UK representative: [UK representative — to be appointed]
If you are in Türkiye, the separate KVKK information notice at gymdeed.com/tr/kvkk also applies to you.
2. The short version
- Your video never leaves your phone. The camera picture is turned into body points on the phone and thrown away. No video, no photo and no body points are stored or sent. The app works in airplane mode.
- The coach knows only what is in your log. There is no hidden profile. What Deed writes is based on your numbers, which you can see in History.
- Nothing is backed up until you say yes, and nothing goes to an AI until you tap "Write my comment".
- "Wrong count?" sends stick-figure points only when you tap, one set at a time, and they are deleted after 90 days. (Today the button only fixes the count on your phone; sending a set is not in the app yet.)
- We don't sell your data, we don't show ads, and we don't track you across other apps or websites.
- You can delete everything from Settings, any time.
3. What stays on your phone
| What | Why it stays |
|---|---|
| The camera picture | processed frame by frame in memory, then discarded |
| Body points (pose landmarks) | used live to count and check form; never stored, never sent |
| Your injury answers (knee, lower back, shoulder, wrist) | used only to pick exercises; never backed up |
| The notes you write under a coach's log entry | never backed up, never sent to an AI |
| Everything else, if you never sign in and never agree to a backup | your workouts, plan, profile and settings live only in the app |
Your iPhone's own iCloud or computer backup includes the app's data. That backup is yours, under Apple's terms; we never see it.
Notifications are scheduled on the phone. We don't ask for a push token.
4. What leaves your phone, when and why
| What | When | Why | Where it goes |
|---|---|---|---|
| A random install id, your iPhone model and iOS version | automatically, the first time you open the app | to create a guest account, keep the free first-workout gift to one per install, and tune the camera to your phone | our server |
| App version and language | each time you open the app | to send the right settings and messages | our server |
| Your IP address | with every request to our server | it is how the internet works; our own logs don't record it, our host's network may | our host |
| Your Apple account id (a random code from Apple; no name, no email) | when you sign in with Apple | to recognise you on a new phone | our server |
| Your backup: workouts, sets and reps as numbers, corrections, records, streak days, the coach's log entries, your plan, settings, and profile answers (goal, level, schedule, equipment, time zone, and height and weight if you gave them); the phone model and app version for each workout | only after you agree to the backup and sign in | so a new phone can have everything back | our server |
| One set's numbers (reps, timing, form scores), the previous set's, your coach intensity and language | only after you tap "Write my comment", and then for each comment until you turn it off | so Deed can write a comment about your set | our server, then Anthropic |
| Usage events: which screens you open, how workouts and sets go, as counts and categories, under a random id that is not linked to your account and changes if you say no later. They can say that you marked an injury, never which | only if you said yes to usage data | to find what is confusing or broken | PostHog (EU) |
| Crash reports | when something breaks on our server (later also in the app) | to fix it | Sentry (EU) |
| Purchase status: an anonymous id and what you bought | when subscriptions launch | to unlock Gymdeed Plus on your devices | RevenueCat |
| Where you heard about us: an Apple campaign code, or the answer you tap | when attribution launches | to know which channels work | our server |
| A "wrong count?" report: the body points of that one set | only when you tap to send that report | to improve counting | Cloudflare (EU) |
| Emails you send us | when you write | to answer you | our mailbox |
Deed's comments never receive your name, your Apple id, a note you wrote, a picture or video.
Our website (gymdeed.com) uses no cookies. It counts visits without cookies (PostHog, cookieless mode), and Cloudflare, which serves the site, sees your IP address to deliver the page.
5. Why we're allowed to (legal bases)
| Purpose | Legal basis |
|---|---|
| Running the app: the guest account, sign-in, settings sent at launch, subscriptions | performing our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| The backup, Deed's written comments, "wrong count?" reports | your explicit consent, because we treat workout numbers, height and weight as health data (GDPR Art. 9(2)(a); KVKK Art. 6(2)) |
| Usage data | your consent (GDPR Art. 6(1)(a); KVKK Art. 5(1)) |
| Stopping abuse of the free gift, keeping costs in check, security logs, crash reports | our legitimate interest in a safe, working service (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Keeping a record of the data requests we answer | legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
Giving us this data is not required by law. Without the install id the app cannot start; without the others you can still train.
6. Who helps us, and where
We use a few companies to run Gymdeed. They process data only on our instructions, under data processing agreements that require the same protection we give it.
| Company | What they do | Where the data is |
|---|---|---|
| Railway (Railway Corporation, US) | hosts our server and database | EU region (Amsterdam). Railway is a US company and may access it from the US |
| Anthropic (Anthropic PBC, US) | writes Deed's comments | United States |
| Sentry (Functional Software, Inc., US) | crash reports | EU (Frankfurt); account details in the US |
| Cloudflare (Cloudflare, Inc., US) | website, domain, email forwarding, report storage | EU storage for reports; the website and email pass through its global network |
| PostHog (PostHog, Inc.) — when usage data launches | usage data | EU |
| RevenueCat (RevenueCat, Inc., US) — when subscriptions launch | subscription status | United States |
| Google (Gmail) | the mailbox behind our email addresses | United States / global |
Apple is not our processor. Sign in with Apple, the App Store (payments, refunds) and Apple's ad attribution are Apple's own services under Apple's privacy policy.
Transfers abroad. Our vendors are outside Türkiye, and some are outside the EU. For people in the EU and the UK we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) in each vendor's agreement. For people in Türkiye we use the safeguards of KVKK Article 9: [the standard contract approved by the Personal Data Protection Board, notified to the Authority — route per vendor to be confirmed].
7. How long we keep it
| Data | How long |
|---|---|
| Your account and backup | until you delete your account |
| A guest account (install id, phone model) that never signed in | deleted after 13 months without opening the app |
| Daily usage counters (for limits) | 90 days |
| Sign-in sessions | 30 days after they expire |
| Server logs (they include an account id, never your IP or your data) | [30] days |
| Database backups | deleted data leaves our backups within [7] days |
| Comment requests at Anthropic | up to 30 days (up to 2 years only if flagged for misuse) |
| Crash reports | [90] days |
| Usage data | 12 months |
| "Wrong count?" reports | 90 days. If a set becomes a test case for our counting, we keep it without any link to you |
| Emails to us | [2 years] after the conversation ends |
| Our AI cost ledger (model, tokens, cost, day) | kept; the link to you is removed when you delete your account |
8. Your rights, and how to use them
You can ask us to: tell you whether we hold data about you and give you a copy; correct it; delete it; restrict or object to how we use it; hand it over in a machine-readable form; and tell you who received it. If we rely on your consent, you can withdraw it at any time, which does not undo what happened before.
- In the app: History shows what the coach knows. Settings lets you edit your profile, turn Deed's written comments and usage data off, and delete everything.
- By email: write to [email protected]. Because we don't know your name or email, please include the account code shown in Settings → Account, so we can find your data. We answer within 30 days, free of charge.
- Complaints: you can complain to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, kvkk.gov.tr), to the data protection authority where you live in the EU, or to the ICO in the UK. We'd like the chance to fix it first.
9. Deleting your account
Settings → Delete account and data.
- If you signed in: we delete your account and every record on our server first (the backup, reports and counters), end your Sign in with Apple link to Gymdeed, and only then wipe the phone. Our AI cost ledger keeps the cost and token counts with no link to you. Deleted data leaves our database backups within [7] days.
- If you never signed in: the phone is wiped. The small guest record on our server (a random install id and phone model, with no workout data) is deleted automatically after 13 months.
- Your subscription is Apple's. Deleting the account doesn't cancel it: cancel in iOS Settings → your name → Subscriptions.
- Deleting your Apple Account also deletes your Gymdeed account. Turning off "Sign in with Apple" for Gymdeed in your Apple settings signs you out but keeps your backup; delete it in the app or write to us.
10. Children
Gymdeed is not directed at children under 16, and you must be 16 or older to use it. If you believe a child under 16 has given us data, write to [email protected] and we will delete it.
11. Security, breaches and changes
- Connections are encrypted (HTTPS). Your Apple sign-in token is encrypted by us before it is stored. Access to the server, the database and our vendor accounts is limited to the developer. Our logs keep a fixed short list of fields and never a request's content.
- If a breach puts your data at risk, we tell the authorities within 72 hours of learning of it, and we tell you without delay when the risk to you is high.
- When this policy changes in substance, we'll tell you in the app and here before it applies. When it changes something you agreed to, the app asks you again.
Gymdeed Privacy Policy, version 1. Questions: [email protected].