Back to main page

Privacy Policy

Information pursuant to Art. 13 and 14 GDPR in conjunction with § 25 TDDDG — Last updated: July 2026

Deutsche Fassung: Datenschutzerklärung (DE)

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) for the website gymtion.app and the Gymtion app is:

GPSFactory Kempf & Lang GbR
Represented by: Andreas Lang, Marcel Kempf
Wiesenweg 4
74248 Ellhofen
Germany

Email: info@gymtion.app
Phone: +49 7134 5101379

Data protection officer

We are not legally required to appoint a data protection officer (§ 38 BDSG) and have not appointed one. For all data protection matters, please contact us directly at the address above.


2. Scope of this policy

This privacy policy covers three separate offerings. It is structured accordingly so that you only need to read the part relevant to you:

  • Part A — our website at gymtion.app
  • Part B — our Gymtion mobile app for iOS and Android
  • Part C — our profiles on social networks

The concluding sections 4 to 9 apply to all three areas alike.

We process personal data only where necessary to provide our services or where you have given consent. Processing takes place exclusively where a legal basis under Art. 6 GDPR exists. The applicable legal basis is stated for each processing activity.


3. Your rights

With regard to your personal data you have the following rights:

  • Access to whether and which data we process about you (Art. 15 GDPR)
  • Rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR)
  • Erasure of your data, unless a statutory retention obligation applies (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

Right to object under Art. 21 GDPR

Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.

Exercising your rights

An informal message to info@gymtion.app is sufficient. We will respond without undue delay and at the latest within one month.

Right to lodge a complaint with a supervisory authority

Irrespective of the above, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority competent for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
www.baden-wuerttemberg.datenschutz.de
Part A

Website gymtion.app

This part describes the processing that takes place when you visit our website. The website is deliberately kept lean: it sets no cookies, embeds no analytics or tracking tools, and does not analyse your behaviour.

A1. Hosting and server log files

netcup GmbH (hosting)

Our website runs on servers in Germany. We operate the server ourselves; netcup provides the infrastructure.

Provider and location
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. Server location: Germany. Privacy policy
Data processed
Automatically recorded in server log files:
  • IP address of the requesting device
  • Date and time of access
  • URL accessed and volume of data transferred
  • HTTP status code
  • Referrer URL (previously visited page)
  • Browser type, browser version and operating system
Purpose
Providing the website, ensuring stability and operational security, defending against and investigating attacks.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in the secure and trouble-free operation of the website.
Third-country transfer
None. Processing takes place exclusively in Germany.
Retention
Log files are deleted or truncated by the IP address after no more than 7 days. Longer retention occurs only where a specific security incident requires it; the data concerned is then kept until the matter is resolved.
Data processing agreement
We have concluded a data processing agreement with netcup pursuant to Art. 28 GDPR. netcup processes data solely on our instructions and not for its own purposes.

A2. Cookies and local storage

This website sets no cookies and stores no information on your device (such as via local storage or session storage) that would require consent under § 25(1) TDDDG. A cookie banner is therefore not required.

No reach measurement, no web analytics and no cross-site tracking take place. We do not create usage profiles.

Note: The German Telecommunications Digital Services Data Protection Act (TDDDG), in force since 14 May 2024, replaced the former TTDSG; the provision on the protection of privacy in terminal equipment is unchanged and now found in § 25 TDDDG.


A3. Mapbox (map display)

Mapbox, Inc.

We display an interactive map on the website. We serve the library (Mapbox GL JS) from our own server. The map tiles and map styles are, however, loaded directly from Mapbox servers; your browser establishes a direct connection to Mapbox in doing so.

Provider and location
Mapbox, Inc., 740 15th Street NW, Washington, DC 20005, USA. Privacy policy
Data processed
  • IP address of your device
  • Date and time of the request
  • Browser type, browser version and operating system
  • Referrer URL
  • Map tiles requested, zoom level and the map section displayed — this allows the geographic region you are viewing to be inferred
  • Our public Mapbox access token
Purpose
Displaying the interactive map showing participating gyms.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in presenting our offering in an appealing and functional way.
Third-country transfer
USA. Mapbox is certified under the EU-U.S. Data Privacy Framework; the transfer is based on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). In addition, Mapbox has concluded the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, which continue to apply even if the adequacy decision were to lapse. Certification notice
Retention
Determined by Mapbox on its own responsibility; we have no influence over this. Please refer to Mapbox's privacy policy for details.

A4. Supabase (Gym Wars statistics)

Supabase, Inc.

The Gym Wars statistics shown on the website are loaded live from our database. Your browser establishes a direct connection to our Supabase instance for this purpose. Only aggregated statistics are retrieved — no personal data of other users is served.

Provider and location
Supabase, Inc., 970 Toa Payoh North, Singapore 318992 (headquarters), with an office in San Francisco, USA. Privacy policy
Server location
Frankfurt am Main, Germany (AWS region eu-central-1). Our database and all content stored in it reside exclusively within the European Union.
Data processed
  • IP address of your device
  • Date and time of the request
  • Browser type and operating system (user agent)
  • Database function called and parameters passed (season or period)
Purpose
Displaying current Gym Wars rankings and season statistics.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in presenting current content on our website.
Third-country transfer
Data is held in the EU. Access from third countries (USA, Singapore) by Supabase staff in the course of maintenance and support cannot be entirely ruled out. For such cases we have concluded the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR with Supabase. Data processing agreement
Retention
Platform access logs are deleted by Supabase in accordance with the periods set out in the data processing agreement.

A5. ClickUp form for gym operators

ClickUp (Mango Technologies, Inc.)

Gym operators can open a contact form via a link on our website. This form is not embedded in our website: only when you click the link do you leave our site and get redirected to ClickUp. Until you click, no data whatsoever is transmitted to ClickUp.

Provider and location
Mango Technologies, Inc. d/b/a ClickUp, 350 Tenth Ave, San Diego, CA 92101, USA. Privacy policy
Data processed
The details you enter in the form (in particular name, email address, gym name and message text) as well as technical connection data such as IP address, time of access and browser identification.
Purpose
Receiving and handling enquiries from gym operators.
Legal basis
Art. 6(1)(b) GDPR — performance of pre-contractual measures; additionally Art. 6(1)(f) GDPR — legitimate interest in handling business enquiries.
Third-country transfer
USA. The transfer is based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the data processing agreement concluded with ClickUp. Data processing agreement
Retention
Until your enquiry has been conclusively handled, then deleted at the latest after 3 years at year end — unless commercial or tax retention obligations require longer storage.

A6. Contact by email

If you write to us at info@gymtion.app, we process the personal data contained in your message in order to handle your request.

  • Data processed: your email address and all details you provide voluntarily (name, phone number, message content, attachments)
  • Purpose: handling and responding to your enquiry
  • Legal basis: Art. 6(1)(b) GDPR for contractual or pre-contractual matters, otherwise Art. 6(1)(f) GDPR
  • Recipients: internal use only, plus our email host as a processor
  • Retention: until the matter is concluded, then deleted at the latest after 3 years at year end, subject to statutory retention obligations

Providing your data is voluntary. Without an email address, however, we cannot reply to you.

Part B

Gymtion app for iOS and Android

This part describes the processing of personal data in our mobile app. The app processes considerably more data than the website — in particular location data, since automatic workout detection is Gymtion's core function.

B1. Overview of processing activities

For orientation, we first present the main processing activities in overview. Details follow in the sections below.

Processing Purpose Legal basis Section
Account and sign-in Providing a personal user account Art. 6(1)(b) GDPR B2
Profile and master data Displaying your profile Art. 6(1)(b) GDPR B3
Location data Detection of gym visits Art. 6(1)(b) GDPR, consent via system dialog B4
Location transfer to geo server Reviewing streak restorations, error analysis Art. 6(1)(a) GDPR B5
Workouts and streaks Core function: workout history and streaks Art. 6(1)(b) GDPR B6
Friends, stories, Stronger Together Social features of the app Art. 6(1)(b) GDPR B7
Push notifications Reminders and notifications Art. 6(1)(a) GDPR B8
Subscriptions Processing and managing Gymtion Pro Art. 6(1)(b) GDPR B9
Invitation and deep links Friend invitations, attribution Art. 6(1)(b) and (a) GDPR B10
Crash diagnostics App stability, fixing crashes Art. 6(1)(a) GDPR B12
Usage analytics Improving the app Art. 6(1)(f) GDPR B13
Advertising Funding the free version Art. 6(1)(f) GDPR B14
Support and reports Handling your requests Art. 6(1)(b) and (f) GDPR B15

B2. Account, registration and sign-in

You need a user account to use Gymtion. Account management runs via Supabase Auth on our own database instance in Frankfurt.

Supabase (database, authentication, file storage)

Supabase is our central database. All content data in the app — your profile, your workouts, your friendships — is stored here.

Provider and location
Supabase, Inc., 970 Toa Payoh North, Singapore 318992 (headquarters), with an office in San Francisco, USA.
Server location
Frankfurt am Main, Germany (AWS region eu-central-1). Your account and content data is stored exclusively within the EU.
Data processed (account)
  • Internal user identifier (UUID)
  • Email address
  • Sign-in method used (Apple, Google or email)
  • Time of registration, last sign-in and last change
  • Session and refresh tokens
  • IP address and device identifier on each database access
Purpose
Providing and securing your personal account, associating your data, preventing abuse.
Legal basis
Art. 6(1)(b) GDPR — performance of the user agreement. The app cannot be used without an account.
Third-country transfer
Data is held in the EU. Access from the USA or Singapore by Supabase staff in the course of maintenance and support cannot be entirely ruled out; the Standard Contractual Clauses agreed with Supabase under Art. 46(2)(c) GDPR apply to such cases.
Retention
Until you delete your account (see section 6). Your data is then erased unless statutory retention obligations apply.

Anonymous use during onboarding

On first launch the app creates an anonymous session so that you can complete onboarding before registering. A random identifier is generated that is not yet attributable to any person. Once you complete registration, this identifier is linked to your account.

Sign in with Apple

Provider and location
For users in the EEA: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Privacy policy
Data processed
Transmitted from Apple to us: your Apple user identifier, your email address (at your choice as an anonymised relay address of the form …@privaterelay.appleid.com) and — only on the very first sign-in and only if you agree — your first and last name. Transmitted to Apple: your IP address, device data and the fact that you are signing in to Gymtion.
Purpose
Secure registration and sign-in without a separate password.
Legal basis
Art. 6(1)(b) GDPR — performance of the contract at your initiative.
Third-country transfer
The contracting party is the Irish Apple entity; onward transfer to Apple Inc. in the USA takes place under Apple's intra-group arrangements.

Sign in with Google

Provider and location
For users in the EEA: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy
Data processed
Transmitted from Google to us: your Google account identifier, your email address, your display name and your profile picture. Transmitted to Google: your IP address, device data and the fact that you are signing in to Gymtion.
Purpose
Secure registration and sign-in without a separate password.
Legal basis
Art. 6(1)(b) GDPR — performance of the contract at your initiative.
Third-country transfer
USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR). The Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.

B3. Profile and master data

We store the following details in your profile. All data resides in our Supabase database in Frankfurt (see B2).

Publicly visible profile data

  • Display name — freely chosen by you
  • Profile picture — if you upload one
  • Friend identifier (add ID) — an identifier others can use to add you as a friend
  • Selected gyms as well as your current streak to date

Using the visibility settings you decide for yourself who may see your profile, your stories, your streaks, your workouts and your training plan.

Non-public master data

  • Date of birth — if provided by you; this entry is optional
  • Gender — if provided by you; this entry is optional
  • Onboarding status and time of account creation
  • Notification and reminder settings

Note on date of birth & gender: this entry is optional. It is not transmitted to third parties and is used solely for personalisation within the app.

Profile pictures and image uploads

Uploaded images are stored in the file storage of our Supabase instance in Frankfurt. Please note: the image URLs are constructed such that they are retrievable without additional authentication by anyone who knows the exact address. Please therefore do not upload images containing particularly sensitive information.

Legal basis: Art. 6(1)(b) GDPR (performance of contract); gender: Art. 6(1)(a) GDPR (consent)

B4. Location data and workout detection

Automatic detection of your gym visits is Gymtion's core function. For it to work without any action on your part, the app processes your location even when the app is not open or is running in the background. We explain this point in particular detail because it is the most intrusive part of our processing.

How detection works

We place a virtual boundary (geofence) around your gym. When your device enters or leaves this area, the operating system triggers an event. The app then evaluates, based on the gym polygon, your movement speed and the accuracy of the signal, whether a workout has actually started or ended.

Which location data is collected on your device

  • Geographic coordinates (latitude and longitude) and altitude
  • Location accuracy, speed and heading
  • Timestamp of the measurement
  • Detected activity type (on foot, running, cycling, in vehicle, still) with confidence value
  • Total distance travelled (odometer)
  • Battery level and charging state of the device
  • Indication of whether the location was simulated (mock location detection)
  • Geofence events (enter and exit) with the identifier of the gym concerned

Where this data stays — the most important point

This raw data remains exclusively on your device. It is stored in a local database and automatically deleted after 14 days. It is not transmitted automatically to us or to third parties — automatic synchronisation of the location module we use is explicitly disabled in our app.

What is transmitted to our database is solely the result of the evaluation, i.e. that a workout started or ended at a particular time at a particular gym. No movement profile is created and no route is stored.

Raw data is transmitted in one case only: when you actively select a period in the support form and consent to the transfer. That case is described separately in section B5.

Diagnostic logs

The location module additionally keeps a technical log of its own operation. This log also remains on your device and is automatically deleted after 14 days.

Map data for gyms

To determine gym boundaries we use polygons — precise outlines of the gym premises. These polygons are stored in our database. If you draw a polygon for a gym yourself or correct an existing one, it is stored together with your user identifier so that we can trace the change and revert it if necessary. Polygons you draw may, after review by us, also benefit other users.

Legal basis and your control

We base the processing of your location data on Art. 6(1)(b) GDPR, since automatic workout detection is the principal service Gymtion owes contractually. Accessing your device's location function additionally requires your permission via the iOS or Android system dialog; this simultaneously constitutes your consent within the meaning of § 25(1) TDDDG.

You can withdraw location permission at any time in your device settings. Automatic workout detection will then no longer work.

Legal basis: Art. 6(1)(b) GDPR in conjunction with § 25(1) TDDDG (permission via system dialog)

B5. Transfer of location data to our geo server

There is exactly one case in which your raw location data leaves your device: when you report a matter relating to workout detection via the support form — for instance because a workout was not detected and you would like your streak restored — you can select one or more periods and consent to the transfer of the associated location data.

Gymtion geo server (our own server)

The geo server is our own server. The data is not passed on to the manufacturer of the location module or to any other third party.

Operator and location
Operated by us (GPSFactory Kempf & Lang GbR) on infrastructure of netcup GmbH in Germany. Address: geo.external.gymtion.gps-factory.app
Data transmitted
For the periods you select:
  • All location points with coordinates, accuracy, altitude, speed and heading
  • Timestamps of measurement and of recording
  • Detected activity type and confidence value
  • Battery level and charging state
  • Odometer reading and movement status
  • Flag for simulated locations (mock)
  • Unique identifier of each record (UUID)
  • Geofence events with identifier, centre, radius and polygon of the gym
  • Your user identifier — so that we can associate the data set with your support ticket
Purpose
Understanding why a workout was not detected or was detected incorrectly; reviewing a requested restoration of your streak; improving our detection algorithms and gym polygons.
Legal basis
Art. 6(1)(a) GDPR — your explicit consent. The transfer takes place only if you actively select periods in the support form and confirm the transfer. Without this consent no data set is transmitted.
Withdrawal
You can withdraw your consent at any time by informal message to info@gymtion.app. We will then delete the transmitted location data without undue delay. The lawfulness of processing carried out up to that point remains unaffected.
Third-country transfer
None. The server is located in Germany and operated by us.
Retention
90 days after final resolution of the associated support ticket; deleted automatically thereafter.

B6. Workouts, streaks and gym assignment

We store the following data in our database in Frankfurt in order to provide the app's core functions.

Workout sessions

  • Your user identifier and the identifier of the gym
  • Start and end of the workout, each with time zone offset
  • Type of start and end (automatically detected or manually triggered)
  • A validation code protecting against manipulated entries
  • Time the record was created

Gym assignment and streaks

  • The gyms assigned to you and which of them is active
  • Your current streak and your longest streak to date per gym
  • Time of assignment

Training plans and absences

  • Weekly goals, cycle length and period of your training plan
  • Your planned training days
  • Absences with type (such as holiday or illness) and start and end

Note: If you state illness as the reason for an absence, this entry may constitute health data within the meaning of Art. 9 GDPR. We process this entry solely in order to pause your streak and do not pass it on to third parties. The entry is optional; you can choose a neutral category instead.

Legal basis: Art. 6(1)(b) GDPR; for entries relating to illness additionally Art. 9(2)(a) GDPR (explicit consent)

B7. Friends, stories and Stronger Together

Friendships

You can connect with other users. We store the identifiers of both accounts involved, the respective status of the relationship (requested, confirmed) and the time.

Data from another source (Art. 14 GDPR): When another person sends you a friend request, we receive their details not from you but from that person. Conversely, the other person receives your display name and profile picture through your request.

Stories

Stories are short-lived posts you share with your friends. Our database records only that and when you created a story — we store just your user identifier and the timestamp. The image content itself is kept on your device and is accessible via the story archive in the settings. Your visibility setting determines who can see your stories.

Stronger Together

This feature lets you work out together with others. We store the identifiers of the participating users, the identifier of the inviting person, the gym, start and end of the joint session, the group assignment and whether the invitation was accepted.

Gym community

When you select a gym, you become part of its community. Other users of the same gym are shown your display name, your profile picture and your streak in the gym view — even if you are not friends with those people.

Your visibility settings govern this: using profile visibility and streak visibility you control whether and with which details you appear in this list. Please review these settings if you do not wish to be visible to other members of your gym.

Gym Wars

Gyms compete against each other in rankings. For this purpose your workouts are aggregated into gym statistics. The rankings published on our website and inside our app show only aggregated gym figures, never personal individual data.

Legal basis: Art. 6(1)(b) GDPR (performance of contract); visibility to other users according to your settings

B8. Push notifications (Firebase Cloud Messaging)

Firebase Cloud Messaging (Google)

We send push notifications, such as you or your friends being in the gym, friend requests. Technical delivery runs via Firebase Cloud Messaging.

Provider and location
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, Mountain View, CA, USA.
Data processed
  • Push token of your device (a device identifier issued by Google)
  • Your user identifier — to associate the token, stored in our database
  • Time of registration and last update of the token
  • The content of the relevant message, as well as any accompanying data such as the name of the studio, the name and profile picture of the person making the enquiry, or the start time of the training session.
Purpose
Delivering the notifications you have enabled.
Legal basis
Art. 6(1)(a) GDPR — your consent, given via your device's system dialog and the notification settings in the app. You can withdraw it at any time in your system settings.
Third-country transfer
USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.
Retention
We store the push token for as long as you have notifications enabled, at the longest until your account is deleted. Tokens that have become invalid are removed.

B9. Subscriptions (RevenueCat, app stores)

Gymtion Pro is a paid subscription. Payment is processed exclusively via Apple's App Store or Google Play — we receive no payment data such as credit card numbers or bank details.

RevenueCat, Inc.

RevenueCat manages the status of your subscription across both platforms on our behalf.

Provider and location
RevenueCat, Inc., 300 Delaware Ave, Suite 210, Wilmington, DE 19801, USA. Privacy policy
Data processed
  • Your user identifier — used as the identifier at RevenueCat
  • Your email address
  • Your display name
  • Your Branch identifier (see B10)
  • App Store or Google Play purchase receipts, purchase and renewal times, trial periods, cancellations and refunds
  • Device type, operating system version, app version, country and IP address
Purpose
Verifying purchase receipts, cross-platform management of your subscription status, unlocking Pro features, supporting purchase-related enquiries.
Legal basis
Art. 6(1)(b) GDPR — performance of the subscription contract.
Third-country transfer
USA. The transfer is based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the data processing agreement with RevenueCat. Data processing agreement
Retention
For the duration of the subscription and beyond, for as long as commercial and tax retention periods require.

Apple App Store and Google Play

When you purchase a subscription, Apple and Google act as independent controllers. We have no influence over their processing.

Provider and location
Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland  ·  Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Data processed
Your store account identifier, payment data, purchase history, billing address, family sharing status as well as device and connection data. From Apple and Google we receive only anonymised sales reports and — mediated via RevenueCat — the status of your subscription.
Purpose
Processing the purchase, billing, managing renewal and cancellation.
Legal basis
Art. 6(1)(b) GDPR. Apple's and Google's own privacy policies apply to their independent processing: Apple, Google.
Third-country transfer
According to Apple's and Google's own arrangements; we have no influence over this.

B10. Invitation and deep links (Branch)

Branch Metrics, Inc.

Branch generates the invitation links you use to invite friends to Gymtion and ensures that a link leads to the right place after the app is installed.

Provider and location
Branch Metrics, Inc., 1400 Seaport Blvd, Redwood City, CA 94063, USA. Privacy policy
Data processed
  • Your friend identifier (add ID) — it forms part of the invitation link
  • Your display name — stored as the link title so recipients can see who is inviting them
  • Device and session identifiers issued by Branch
  • IP address, device model, operating system and version, language, time zone, screen resolution
  • Time of installation, first open and click on a link
  • The identifier of the inviting person (referrer) if you came to us via an invitation
Purpose
Creating and resolving invitation and deep links, associating friend invitations, routing to the right content after installation.
Legal basis
For the core function (creating and resolving links) Art. 6(1)(b) GDPR — it is a necessary component of the invitation feature. For measurement and attribution beyond that, Art. 6(1)(a) GDPR — your consent.
Your control
On iOS we tie attribution to your answer in the App Tracking Transparency dialog (see B12). If you do not consent, Branch is set to the lowest level and performs no measurement; invitation links continue to work.
Third-country transfer
USA. The transfer is based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR.
Retention
According to Branch's own policies; please refer to their privacy policy for details.

Data from another source (Art. 14 GDPR): If you came to Gymtion via another person's invitation link, we receive that person's identifier via Branch in order to establish the friendship.


B11. Maps in the app (Mapbox)

Mapbox, Inc.

We display maps in the app so that you can find gyms and draw gym boundaries.

Provider and location
Mapbox, Inc., 740 15th Street NW, Washington, DC 20005, USA.
Data processed
  • IP address of your device
  • Map tiles requested and zoom level — from which the map section you are viewing follows
  • Device type and operating system, our Mapbox access token
Purpose
Map display, drawing and reviewing gym boundaries.
Legal basis
Art. 6(1)(b) GDPR — providing the app's map features.
Third-country transfer
USA. Mapbox is certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.
Local caching
Map tiles that have already been loaded are cached on your device so the map loads faster and less data is transferred. You can clear this cache via your device settings.

B12. Crash diagnostics (Firebase Crashlytics)

Firebase Crashlytics (Google)

If the app crashes or a serious error occurs, we receive a technical report so we can fix the cause.

Provider and location
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, Mountain View, CA, USA. Firebase privacy information
Data processed
  • Error message and call stack (stack trace) at the time of the crash
  • Installation identifier of the device issued by Firebase
  • Device model, operating system and version, memory and storage usage, battery level
  • App version and time of the error
  • Device orientation and whether the app was in the foreground
  • Your user identifier and the identifier of the gym concerned — sent along by us for better attribution
  • Technical log messages we set describing the course of the error
Purpose
Detecting, tracing and fixing crashes and errors.
Legal basis
Art. 6(1)(a) GDPR — your consent.
Third-country transfer
USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.
Retention
Crash reports are retained by Google for 90 days by default and then deleted.

B13. Usage analytics (Firebase Analytics)

Google Analytics for Firebase

We record which areas of the app are used in order to understand which features resonate and where users get stuck.

Provider and location
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, Mountain View, CA, USA.
Data processed
  • Installation identifier issued by Firebase (app instance ID)
  • Pages and screens opened and actions triggered (such as opening the calendar, starting a workout, tapping buttons)
  • Time and duration of use, number and frequency of sessions
  • Device model, operating system and version, app version, language setting
  • Approximate location at country level, derived from the IP address
  • First open of the app and source of the installation
Not collected
Your precise location coordinates, your name and your workout content are not transmitted to Firebase Analytics.
Purpose
Understanding usage, identifying misoperation and drop-offs, developing the app further.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in improving our app in line with actual needs.
Third-country transfer
USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.
Retention
User-level usage data is deleted automatically after 14 months; aggregated reports are retained.

B14. Advertising (Google AdMob)

Google AdMob

We display advertising in the free version in order to fund the app. No advertising is shown in Gymtion Pro.

Provider and location
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, Mountain View, CA, USA. Information on AdMob
Type of advertising
Non-personalised advertising only. We have configured AdMob so that all users are treated as persons below the age of consent. As a result, Google and its advertising partners may not serve personalised advertising, your device's advertising identifier is not transmitted for advertising purposes, and only advertising rated for general audiences is served.
Data processed
  • IP address (used by Google for coarse geographic assignment and truncated)
  • Device model, operating system and version, language setting, screen size
  • App version and identifier of our ad unit
  • Delivery, viewability and clicking of the ad
  • A short-lived, non-persistent identifier for frequency capping and fraud detection
Not processed
Your device's advertising identifier (IDFA on iOS, Advertising ID on Android) is not transmitted for advertising purposes as a result of the configuration described above. No profiling and no cross-app recognition for advertising purposes take place.
Purpose
Funding the free version of Gymtion.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in funding our free offering. Since only non-personalised advertising without an advertising identifier is served, the interference is limited to what is technically necessary for delivery.

To the extent that the advertising module stores and reads information on your device for frequency capping and fraud detection, this requires consent under § 25(1) TDDDG, as it goes beyond what is strictly necessary for the feature you requested. We obtain this consent together with the consent for crash diagnostics and usage analytics (see B12 and B13).
SKAdNetwork (iOS)
Apple's SKAdNetwork is configured on iOS. It allows advertisers to measure success without access to personal data: Apple reports only aggregated values that cannot be attributed to individual users.
Third-country transfer
USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.
Ad-free use
No advertising is served with a Gymtion Pro subscription.

B15. Support and reports (ClickUp)

ClickUp (Mango Technologies, Inc.)

You can report matters to us via the support form in the app. Each report is created as a ticket in our ClickUp workspace.

Provider and location
Mango Technologies, Inc. d/b/a ClickUp, 350 Tenth Ave, San Diego, CA 92101, USA.
Always transmitted
  • Your display name
  • Your user identifier
  • Your email address
  • The category of the matter you selected
  • Your free-text description of the matter
Additionally, depending on the type of matter
  • Reporting a user: identifier and display name of the reported person
  • Bug report: the app screen concerned
  • Workout detection: the periods you selected and the identifier of the gym concerned — the associated location data goes to our own geo server, not to ClickUp (see B5)
  • Gym change: identifier of the gym and the new address you propose
Purpose
Receiving, assigning and handling your request; for user reports: reviewing breaches of our terms of use.
Legal basis
Art. 6(1)(b) GDPR — handling requests under the user agreement; for reports about other users additionally Art. 6(1)(f) GDPR — legitimate interest in a safe and compliant platform.
Third-country transfer
USA, based on the Standard Contractual Clauses under Art. 46(2)(c) GDPR as part of the data processing agreement with ClickUp.
Retention
Until the ticket is conclusively handled, then deleted at the latest after 3 years at year end.

Data from another source (Art. 14 GDPR): If another person reports you via the support form, we process your display name and user identifier as part of that ticket. The source of the data in this case is the reporting person. We inform you here in general terms about this possibility; individual notification is omitted where it would frustrate the review of the matter (Art. 14(5) GDPR).


B16. Further connections to third parties

Beyond the services described above, the app establishes further connections in certain situations. We list them for the sake of completeness.

Google favicon service

Provider
Google Ireland Limited / Google LLC, USA (t2.gstatic.com)
Data processed
IP address of your device and the website address of the respective gym whose icon is being loaded. Google thereby learns which gyms are shown to you.
Purpose
Displaying a gym's website icon in lists and push notifications.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in a clear presentation.
Third-country transfer
USA, based on the adequacy decision and additionally Standard Contractual Clauses.

Location module (Transistor Software)

For background location detection we use a module from Transistor Software Inc. We have disabled automatic transmission to the manufacturer's servers. No location data is transmitted to Transistor Software; the module operates exclusively locally on your device.


B17. Storage on your device

The app also stores data locally on your device. This data does not leave your device unless stated otherwise in this policy. Storage and reading take place under § 25(2) no. 2 TDDDG to the extent strictly necessary for the feature you have requested.

What is stored What for How long
Raw location data and geofence events Evaluating workout detection on the device 14 days, then deleted automatically
Diagnostic log of the location module Troubleshooting workout detection 14 days, then deleted automatically
Sign-in data (session and refresh tokens) Keeping you signed in Until sign-out; held in secure system storage
App settings and onboarding status Remembering your settings Until uninstallation
Cache for gym and workout data Use on poor connections, less data usage Until uninstallation or cache clearing
Map tile cache Faster map rendering Until the cache is cleared
Image cache Faster display of profile pictures Until the cache is cleared
Scheduled notifications Reminders even without an internet connection Until triggered or deactivated

When you uninstall the app, all locally stored data is deleted with it. Your account in our database is unaffected — separate deletion is required for that (see section 6).


B18. Device permissions

The app requests the following permissions. You can withdraw each of them at any time in your device settings; the dependent feature will then no longer be available.

Permission What it is needed for Consequence if declined
Location (while using the app) Finding gyms nearby, drawing gym boundaries Gym search only via address entry
Location (always / background) Automatic workout detection even when the app is closed Workouts can't be recorded
Motion & fitness / activity recognition Distinguishing whether you are walking, standing or in a vehicle — prevents false detections Workout detection becomes less accurate and uses more battery
Notifications Reminders, streak alerts, friend requests No notifications
Camera Scanning QR codes, taking a profile picture QR code feature and camera capture unavailable
Photos / media library Choosing a profile picture or a story image Images cannot be selected from the library
Tracking Transmitting crash reports and attributing invitation links No crash reports, no attribution — the app remains fully usable
Part C

Profiles on social networks

This part concerns you only if you visit one of our profiles on a social network. It is irrelevant for using the app or our website.

C1. Our social media profiles

We maintain profiles on social networks in order to provide information about Gymtion and to engage with those interested. We embed no content from these networks on our website or in the app — there are no like buttons, no embedded posts and no tracking pixels. Data is transferred only once you visit the respective network yourself.

Joint controllership

If you visit one of our profiles, the respective provider processes your data on its own responsibility. According to case law of the Court of Justice of the European Union, we are jointly responsible with the provider within the meaning of Art. 26 GDPR for part of that processing — in particular the generation of statistics about visitors to our page.

We have no influence over the providers' processing and receive only aggregated statistics (such as reach, number of views, age group and country distribution). We cannot access personal individual data of visitors.

Data processed

  • Your interactions with our posts (views, reactions, comments, shares)
  • Usage profiles generated by the networks, partly across networks and even if you do not have an account with the respective provider
  • Your messages to us if you contact us via the network
  • IP address, device data and cookies set by the provider

Legal basis

Art. 6(1)(f) GDPR — legitimate interest in public relations and communication with those interested. Where the providers set cookies or build usage profiles, these are based on the consent you have given to the respective network.

Third-country transfer

All of the providers named also process data outside the EU, in particular in the USA. Transfers are based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) or on Standard Contractual Clauses (Art. 46(2)(c) GDPR). In the case of TikTok, access from China and Singapore cannot be ruled out.

Our profiles and the respective providers

Network Provider for the EEA Privacy information
Instagram Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland privacycenter.instagram.com
Facebook Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland facebook.com/privacy/policy
TikTok TikTok Technology Ltd., 10 Earlsfort Terrace, Dublin 2, Ireland tiktok.com/legal/privacy-policy-eea
LinkedIn LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland linkedin.com/legal/privacy-policy
Reddit Reddit Ireland Ltd., 70 Sir John Rogerson's Quay, Dublin 2, Ireland reddit.com/policies/privacy-policy

You can assert your data subject rights both against us and against the respective provider. Since the providers have direct access to your data, we recommend addressing access and erasure requests to them directly. If you send your request to us, we will forward it.

Common provisions

Provisions applying throughout

The following sections apply equally to the website, the app and the social media profiles.

4. Transfers to third countries

Some of the service providers we use are established outside the European Union. A transfer takes place only where a mechanism under Chapter V GDPR ensures an adequate level of protection. The following overview summarises which data goes where.

Service Data location Third country Basis for the transfer
netcup (website and geo server hosting) Germany No third-country transfer
Supabase (database, accounts, files) Frankfurt, Germany (eu-central-1) USA / Singapore only for maintenance and support Standard Contractual Clauses, Art. 46(2)(c) GDPR
Google (Firebase, AdMob, sign-in) Global USA Adequacy decision (DPF), Art. 45 GDPR; additionally Standard Contractual Clauses
Apple (sign-in, App Store) Global USA Contracting party is the Irish entity; intra-group arrangements
Mapbox (maps) USA USA Adequacy decision (DPF), Art. 45 GDPR; additionally Standard Contractual Clauses
RevenueCat (subscriptions) USA USA Standard Contractual Clauses, Art. 46(2)(c) GDPR
Branch (invitation links) USA USA Standard Contractual Clauses, Art. 46(2)(c) GDPR
ClickUp (support) USA USA Standard Contractual Clauses, Art. 46(2)(c) GDPR

Note on the level of protection in the USA

By decision of 10 July 2023 the European Commission determined that certified US companies under the EU-U.S. Data Privacy Framework offer an adequate level of protection. The General Court of the European Union confirmed that decision by judgment of 3 September 2025; an appeal against it is pending before the Court of Justice of the European Union. We point out that US authorities may, under certain conditions, access data under US law, and that you may not have legal remedies against such access comparable to those available in the EU. Where certification does not exist or should lapse, we base the transfer additionally on the European Commission's Standard Contractual Clauses, which continue to apply independently of the adequacy decision.


5. Retention periods at a glance

We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations.

Data Retention period
Website server log files At most 7 days
Raw location data on your device 14 days, then deleted automatically
Account, profile and workout data Until you delete your account
Location data transferred to the geo server See the note in section B5
Crash reports 90 days
Support tickets Until resolved, then at most 3 years at year end
Email correspondence Until resolved, then at most 3 years at year end
Billing-related records Up to 8 years under § 147 AO and § 257 HGB

6. Deleting your account

You can delete your account yourself at any time. You will find the deletion function in the app under Settings → Delete account. Alternatively, an informal message to info@gymtion.app is sufficient.

Deletion removes in particular:

  • Your account and sign-in data including your email address
  • Your profile data, your profile picture and your master data
  • Your workout history, streaks, training plans and absences
  • Your friendships and stories
  • Your push token

Only data we are legally required to retain remains — in particular billing-related records for subscriptions. Such data is blocked from further use and deleted once the periods expire.

Please note: you cancel your subscription not through us but in your App Store or Google Play account. Deleting your Gymtion account does not automatically end a running subscription.


7. Minors

We do not set our own minimum age for using Gymtion and we do not carry out any age verification ourselves. What applies is the age rating in the App Store and on Google Play: Apple and Google carry out age verification on a country-by-country basis.

A date of birth you provide is an optional entry and is not used for age verification (see B3).

Where we base processing on your consent — for example for error diagnostics and usage analysis (see B12 and B13) — Art. 8 GDPR in conjunction with § 25 BDSG applies: in Germany, a child's consent is valid only from the age of 16. For younger users, consent must be given or authorised by the holder of parental responsibility.

We serve non-personalised advertising only. All users are treated towards AdMob as persons below the age of consent, so that no advertising identifier is transmitted and no profiling takes place (see B14).

If you hold parental responsibility and believe that your child has provided us with data without your consent, please contact info@gymtion.app. We will delete the data without undue delay.


8. No automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR does not take place.

Automatic workout detection, streak calculation and the Gym Wars rankings are based on automated evaluations, but they produce no legal effects concerning you and do not similarly significantly affect you. If in your view an automatically generated assessment is incorrect — for instance because a workout was not detected — you can request a manual review by us via the support form.


9. Changes to this policy

We amend this privacy policy when the legal situation, our offerings or the nature of the data processing change. The version published on this page applies in each case.

In the event of material changes — in particular where processing requires your consent — we will additionally inform you in the app or by email and obtain your renewed consent where required.

Version date: July 2026

This English version is provided for convenience. In the event of discrepancies, the German version prevails.