Last updated: 27 August 2026
GymGo is run by me, one person. I do not sell your data and I do not hand it over so anyone can chase you with someone else's advertising. What follows is the complete, concrete list of what I keep, why, and how to ask me to delete it.
The controller is GymGo, a project run by its founder from Paraguay. The contact point for anything to do with personal data is soporte@gymgo.online. I answer you, not a form.
I only ask for what the application needs to work. This is the complete list:
| Data | When I get it | What for |
|---|---|---|
| Name | When you create your account | To greet you inside the app and to know who I am talking to if you write to support. |
| Email address | When you buy, when you create the account or when you finish the quiz on the site | To send you your access, to let you back in if you lose your phone, to send you your plan and to answer you. Also app notifications, which you can switch off. |
| Passkey | When you register with fingerprint or face | Signing in. I only store the public key: your fingerprint or your face never leaves your phone and I never see them. |
| Your workouts | While you use the app | Routines, sets, reps, weights, times and your body weight if you log it. This is the product: without it there is no progression and no stats. |
| Quiz answers | If you take the quiz at gymgo.online/en/plan | Goal, level, where you train, days, duration, sore spots, age range, sex and weight if you give it. They are used to build your plan and to understand what the people who arrive and do not buy actually need. |
| How far you get through the quiz | If you take the quiz at gymgo.online/en/plan | Which screens you saw, how long you spent on each and how you arrived, together with a random identifier stored in your browser. It does not carry your name, your email or your phone, and it is not cross-referenced with them. It serves one purpose: seeing which question people leave on, and fixing it. The last 3,000 quizzes are kept; the rest is deleted automatically. |
| Purchase data | If you buy | Hotmart passes me your name, email and phone so I can give you access and look after you. Your card details never pass through my servers: Hotmart handles them. |
| Technical data | When you use the site or the app | IP address, browser type and a session cookie. To keep your session open, to measure usage in aggregate and to stop abuse. |
Only the providers this needs to work at all. Each one gets the minimum for its job:
| Provider | What for | What it gets |
|---|---|---|
| Hotmart | Payment and invoicing | Handles the payment directly with you; passes me back name, email and phone. |
| Resend | Your address and the content of the emails I send you or you send me. | |
| PostHog | Usage measurement | Navigation events and technical data. I do not send it your workouts. |
| Meta (Facebook / Instagram) | Ad measurement | Events from the website. Where there is an email or phone, they go hashed with SHA-256, never in the clear. |
| Anthropic | Building your plan with AI | Training preferences only. See point 5. |
| Hostinger | Server | Hosts the application and your data. |
| Cloudflare R2 | Backups | Encrypted copies that only I can open. |
The English funnel does not ask for a phone number, so nothing goes to a WhatsApp CRM. That only happens on the Spanish side, where the number is asked for and given willingly.
Some of these providers are outside your country and handle data in other jurisdictions. All of them are established commercial services, with their own privacy policies and their own security commitments.
When you ask the AI to build you a plan, only this is sent to the model: how many days you train, your goal, where you train, your level, the sore spots you ticked and the list of exercises it is allowed to choose from.
Your name is not sent, nor your email, nor your user id, nor your workout history. The model does not know who you are and cannot know. Your answers are not used to train third-party models.
On top of that, the safety filters do not depend on the model: the exercises that could hurt you given what you ticked are discarded beforehand in code, and the server checks it again before saving anything.
I do not use my own advertising cookies and I do not follow you around other sites. What there is, is this:
At any time, and without explaining yourself, you can ask me to:
Write to soporte@gymgo.online from your account address. I commit to answering you within 7 days.
No system is infallible. If there were ever a breach that affects you, I tell you by email, plainly and as soon as possible.
GymGo is not meant for under-16s and I do not knowingly collect data from anyone below that age. If you are a parent or guardian and believe I hold a minor's data, write to me and I delete it immediately.
If I change something important in this policy, I update the date above and, if it really affects you, I tell you by email. I will not make retroactive changes to data already collected without telling you.
Any question, complaint or request about your data: soporte@gymgo.online.