Privacy Policy
Last updated: 19 August 2026
1. Personal data controller
1.1. The controller of personal data is IT SERVICES KRYSTIAN JARMOSZKA, Armii Krajowej 6B/6, 50-541 Wrocław, Poland, Tax ID (NIP): 7471860332 (the "Company"). Contact: contact@gympher.com.
1.2. The controller takes all due care to protect the personal data and privacy of the users of the Gympher.com Service: the Gympher mobile applications (iOS and Android) and the internet service at https://gympher.com (the "Service").
What data do we process?
- Account data: e-mail address, username and display name, date of birth, optionally gender, and country (taken from the device region settings, editable in the profile).
- Health and fitness data: described in a separate section below.
- Content you add: your own food products and meals, your own exercises and workout plans, and uploaded photos (e.g. profile photo, photos of products and meals).
- Technical data: the IP address in server logs and, if the app crashes, an automatic error report containing the device model, system and app version, and the technical sequence of events preceding the error (see Sentry in the recipients section).
- Subscription data: described in a separate section below.
What we do NOT collect: we do not collect precise location (GPS), we do not use third-party analytics or advertising tools, and we do not track your activity for marketing purposes. The camera is used solely for scanning barcodes. The camera image is processed on the device and is neither stored nor sent anywhere; only the decoded barcode number reaches our servers.
Why and for what purposes do we process your data?
We process your data on the following legal bases (Art. 6 GDPR):
- Performance of a contract (Art. 6(1)(b) GDPR) – processing necessary to provide the services under the Terms of Service, including maintaining the account, storing workout, nutrition and measurement data, and handling subscriptions.
- Legitimate interest (Art. 6(1)(f) GDPR) – ensuring the security of the services, preventing abuse (including the register of used free trials), diagnosing and fixing application errors, and handling user requests.
- Consent (Art. 9(2)(a) GDPR) – with respect to health-related data, described in the "Health and fitness data" section.
- Legal obligation (Art. 6(1)(c) GDPR) – for tax and accounting purposes required by applicable law.
How long do we process the data?
- Account data and content: until the account is deleted. After a deletion request the account is deactivated and the data is permanently erased after a 30-day grace period (during which the deletion can be cancelled by signing in again).
- The hashed e-mail address in the trial register: also after account deletion, solely to prevent re-use of the free trial (details in the subscriptions section).
- Server logs (including IP addresses): short-term, for security and diagnostics.
- Data required by tax and accounting regulations: for the period required by law.
What rights do you have as a data subject?
Under the GDPR you have the following rights:
- The right of access to your data and to obtain a copy of it,
- The right to rectification,
- The right to erasure ("right to be forgotten"),
- The right to restriction of processing,
- The right to data portability (Art. 20 GDPR),
- The right to object to processing based on legitimate interest,
- The right to withdraw consent at any time (without affecting the lawfulness of prior processing),
- The right to lodge a complaint with a supervisory authority; in Poland this is the President of the Personal Data Protection Office (uodo.gov.pl).
To exercise these rights, write to: contact@gympher.com.
Who do we share data with?
We do not sell your data and we do not share it with advertising companies. We entrust data only to processors that provide technical services for us:
- Railway Corporation (USA) – hosting of the application servers and database.
- Cloudflare, Inc. (USA) – storage and serving of files, including uploaded photos (the R2 service).
- Functional Software, Inc. (Sentry, USA; data processed in the EU region) – automatic application error reports.
- Sinch (Mailgun; EU region) – transactional e-mails (e.g. e-mail address confirmation, password reset).
- RevenueCat, Inc. (USA) – subscription management (details in the subscriptions section).
- Apple Inc. and Google LLC – Apple/Google sign-in and subscription billing via the App Store/Google Play.
Data may also be disclosed to entities authorised to obtain it by law, e.g. law enforcement authorities.
Health and fitness data
The Service processes data concerning the user's physical activity, including workout logs, exercise history, body measurements and training progress, as well as nutrition data: the food diary (logged products and meals), calorie and macronutrient goals, target body weight, height and activity level. Although this data may constitute health data within the meaning of Art. 9 GDPR, it is processed on the basis of explicit consent given at registration (Art. 9(2)(a) GDPR). Consent can be withdrawn at any time by deleting the account. Health data is not shared with third parties for marketing or advertising purposes and is used solely to provide and improve the core features of the Service.
Food products and the Open Food Facts database
Nutrition information for packaged food products comes from the Open Food Facts database (https://openfoodfacts.org), available under the Open Database License (ODbL). When you scan a barcode or search for a product, our servers query Open Food Facts using only the barcode number or the typed phrase. No account data, personal identifiers or device information reach Open Food Facts. Retrieved product data is stored on our servers to make the Service faster. Product photos are available under the Creative Commons Attribution-ShareAlike licence (CC-BY-SA 3.0). Open Food Facts privacy policy: https://world.openfoodfacts.org/privacy
To show food products relevant to your market, we also process your country, taken from the device region settings and editable in the profile.
International data transfers
Some of the providers listed above are based in the United States (Railway, Cloudflare, Sentry, RevenueCat, Apple, Google). Transfers of data outside the European Economic Area are safeguarded by Standard Contractual Clauses (SCC) approved by the European Commission (Art. 46(2)(c) GDPR) and, for providers certified under the EU-US Data Privacy Framework, also by that mechanism. A copy of the safeguards can be obtained by contacting contact@gympher.com.
The mobile app and cookies
The Gympher mobile application does not use cookies. A signed-in session is maintained by an authentication token stored in the device's secure storage and removed on sign-out. The gympher.com website uses only strictly necessary cookies required for its operation. We do not use analytics or marketing cookies.
Subscriptions and payment data
When you purchase a paid plan, the following entities process data in connection with the transaction:
Apple Inc. and Google LLC act as independent data controllers with respect to billing data (payment method, billing address, transaction history) collected at the time of purchase or renewal of a subscription via the App Store or Google Play. The Company does not receive your payment card details. The privacy policies of these entities apply to this data:
- Apple: https://www.apple.com/legal/privacy/
- Google: https://policies.google.com/privacy
RevenueCat, Inc. (1110 Synott Rd, Suite 300, Sugar Land, TX 77498, USA) acts as our processor and provides the infrastructure for managing in-app subscriptions, verifying purchase receipts and synchronising subscription status with our servers. RevenueCat receives: (a) your user identifier in the Service, (b) an anonymised identifier of your App Store / Google Play account, (c) the product identifier, transaction identifier, expiry date and subscription status (active, cancelled, expired, billing issue, paused), (d) the device platform (iOS / Android). RevenueCat does not receive your name, e-mail address, payment card details or health/workout data. RevenueCat privacy policy: https://www.revenuecat.com/privacy/
The Company processes the subscription status returned by RevenueCat to grant or deny access to paid features. The legal basis for this processing is the performance of a contract (Art. 6(1)(b) GDPR).
Anti-abuse mechanism: To enforce the one-free-trial-per-person rule, the Company stores a hashed (SHA-256) form of your e-mail address in a separate "trial claim" register. The hash does not allow the original e-mail address to be reconstructed. The hash is retained also after account deletion, solely to prevent re-use of the free trial through repeated registrations. The legal basis for this processing is the Company's legitimate interest in preventing fraud (Art. 6(1)(f) GDPR).
Sign-in with Google and Apple
When you register or sign in with a Google or Apple account, we receive from the respective provider only your e-mail address (for Apple "Hide My Email" this is a relay address) and, where shared, your full name. We do not request any other data from the Google or Apple account. External sign-in can be unlinked at any time in the profile settings.
Contact
For any matters concerning personal data, write to: contact@gympher.com.