← Back to home

Privacy policy

Last updated: 27 August 2026

GymGo is run by me, one person. I do not sell your data and I do not hand it over so anyone can chase you with someone else's advertising. What follows is the complete, concrete list of what I keep, why, and how to ask me to delete it.

  1. Who handles your data
  2. What data I collect and why
  3. Why I am allowed to handle it
  4. Who I share it with
  5. What the AI sees
  6. Cookies and measurement
  7. How long I keep it
  8. Your rights
  9. Security
  10. Minors
  11. Changes
  12. Contact

1. Who handles your data

The controller is GymGo, a project run by its founder from Paraguay. The contact point for anything to do with personal data is soporte@gymgo.online. I answer you, not a form.

2. What data I collect and why

I only ask for what the application needs to work. This is the complete list:

DataWhen I get itWhat for
Name When you create your account To greet you inside the app and to know who I am talking to if you write to support.
Email address When you buy, when you create the account or when you finish the quiz on the site To send you your access, to let you back in if you lose your phone, to send you your plan and to answer you. Also app notifications, which you can switch off.
Passkey When you register with fingerprint or face Signing in. I only store the public key: your fingerprint or your face never leaves your phone and I never see them.
Your workouts While you use the app Routines, sets, reps, weights, times and your body weight if you log it. This is the product: without it there is no progression and no stats.
Quiz answers If you take the quiz at gymgo.online/en/plan Goal, level, where you train, days, duration, sore spots, age range, sex and weight if you give it. They are used to build your plan and to understand what the people who arrive and do not buy actually need.
How far you get through the quiz If you take the quiz at gymgo.online/en/plan Which screens you saw, how long you spent on each and how you arrived, together with a random identifier stored in your browser. It does not carry your name, your email or your phone, and it is not cross-referenced with them. It serves one purpose: seeing which question people leave on, and fixing it. The last 3,000 quizzes are kept; the rest is deleted automatically.
Purchase data If you buy Hotmart passes me your name, email and phone so I can give you access and look after you. Your card details never pass through my servers: Hotmart handles them.
Technical data When you use the site or the app IP address, browser type and a session cookie. To keep your session open, to measure usage in aggregate and to stop abuse.
What I do not do I do not sell your data. I do not hand it to third parties for their own advertising. I do not read your workouts out of curiosity: when I look at the platform, I look at aggregate numbers (how many people train, which exercises get used most). I only go into one person's history if you ask me to, to help you with a problem.

3. Why I am allowed to handle it

4. Who I share it with

Only the providers this needs to work at all. Each one gets the minimum for its job:

ProviderWhat forWhat it gets
HotmartPayment and invoicingHandles the payment directly with you; passes me back name, email and phone.
ResendEmailYour address and the content of the emails I send you or you send me.
PostHogUsage measurementNavigation events and technical data. I do not send it your workouts.
Meta (Facebook / Instagram)Ad measurementEvents from the website. Where there is an email or phone, they go hashed with SHA-256, never in the clear.
AnthropicBuilding your plan with AITraining preferences only. See point 5.
HostingerServerHosts the application and your data.
Cloudflare R2BackupsEncrypted copies that only I can open.

The English funnel does not ask for a phone number, so nothing goes to a WhatsApp CRM. That only happens on the Spanish side, where the number is asked for and given willingly.

Some of these providers are outside your country and handle data in other jurisdictions. All of them are established commercial services, with their own privacy policies and their own security commitments.

5. What the AI sees

When you ask the AI to build you a plan, only this is sent to the model: how many days you train, your goal, where you train, your level, the sore spots you ticked and the list of exercises it is allowed to choose from.

Your name is not sent, nor your email, nor your user id, nor your workout history. The model does not know who you are and cannot know. Your answers are not used to train third-party models.

On top of that, the safety filters do not depend on the model: the exercises that could hurt you given what you ticked are discarded beforehand in code, and the server checks it again before saving anything.

6. Cookies and measurement

I do not use my own advertising cookies and I do not follow you around other sites. What there is, is this:

7. How long I keep it

8. Your rights

At any time, and without explaining yourself, you can ask me to:

Write to soporte@gymgo.online from your account address. I commit to answering you within 7 days.

Completely straight with you about deletion There is still no "delete my account" button inside the app: today I do it by hand when you ask. It works and it is just as final, but it depends on me carrying it out. It is on the list of what I am building next.

9. Security

No system is infallible. If there were ever a breach that affects you, I tell you by email, plainly and as soon as possible.

10. Minors

GymGo is not meant for under-16s and I do not knowingly collect data from anyone below that age. If you are a parent or guardian and believe I hold a minor's data, write to me and I delete it immediately.

11. Changes

If I change something important in this policy, I update the date above and, if it really affects you, I tell you by email. I will not make retroactive changes to data already collected without telling you.

12. Contact

Any question, complaint or request about your data: soporte@gymgo.online.