Privacy Policy

2026-07-02 · v1.1-2026

At Gymia (hereinafter, 'the Service'), managed by Samuel Navasardyan Vardanyan as data controller in a personal capacity, we are committed to protecting our users' privacy. This Privacy Policy describes what personal data we collect, how we use it, with whom we share it, and what your rights are under the General Data Protection Regulation (GDPR, Regulation EU 2016/679) and applicable Spanish legislation (Organic Law 3/2018, LOPDGDD).

Personal Data We Collect

  • Account dataEmail address, necessary to create and manage your account, authenticate you, and send service communications (e.g., OTP verification codes).
  • Profile photosProfile picture uploaded voluntarily by the user. It is stored privately in Supabase Storage with restricted access.
  • Body photos — Fast ScanBody photographs submitted for a quick analysis are transmitted through our server and processed via Vertex AI (Google Cloud), contracted with Google Cloud EMEA Limited (Ireland), with processing in European Union data centers ('eu' multi-region) under the Google Cloud Data Processing Addendum (Cloud DPA). In accordance with those terms, submitted data is not used to train models and is not retained beyond the processing needed to return the response. These images are NOT stored in any Gymia system after the analysis is completed; they are permanently discarded once the result is obtained.
  • Body photos — Progress ScanIf the user has given explicit consent during the onboarding process, body photographs corresponding to progress scans are stored securely and privately in Supabase Storage. These photographs are not accessible by third parties or the Gymia team, except under legal requirement. The user can delete them at any time from their profile. IMPORTANT NOTE: Body photographs may constitute biometric data under Art. 9 of the GDPR when they allow the unique identification of a person. Their processing is based exclusively on the user's explicit consent (Art. 9.2.a GDPR), which can be withdrawn at any time.
  • Usage and training dataData relating to your training sessions, gym check-ins, points (GymPoints), weekly streak, and metrics derived from BodyScan analyses (symmetry scores, definition, V-Taper, Hourglass, etc.). These metrics are AI-generated visual approximations with no clinical validity and do not constitute medical information or a diagnosis.
  • Payment dataPayments are processed through the integrated purchase platforms of the Apple App Store and Google Play, with RevenueCat, Inc. as the purchase management infrastructure. Gymia does not store or have access to credit card details, bank accounts, or any sensitive financial data; billing is handled by Apple or Google as independent data controllers.
  • Technical access data (logs)Our backend server (hosted on Render, Frankfurt region, European Union) may automatically log technical data such as IP address, device type, operating system, and timestamps of requests made to the service. This data is used exclusively to ensure the security, stability, and diagnostics of the service, and is automatically deleted within a maximum period of 30 days. It does not contain sensitive user information.
  • Technical cookiesWe use strictly necessary cookies for the operation of the service: Supabase session cookie (authentication) and language cookie (NEXT_LOCALE). These cookies do not require prior consent as they are technically indispensable.
  • Usage analytics data (Umami)With your prior consent, we use Umami Analytics (Umami Software, Inc.) to measure how the service is used: pages visited, usage events (e.g., completing a scan), and approximate browser/operating system. Umami does not use cookies, does not track you across websites, and anonymizes the data, so individual users cannot be identified. You can review Umami's privacy policy at https://umami.is/privacy.

Legal Basis for Processing

  • Performance of a contract (Art. 6.1.b GDPR)We process your account and usage data to provide the service you have subscribed to.
  • Explicit consent (Art. 6.1.a and Art. 9.2.a GDPR)The processing of your body photographs and physical data using AI to generate the BodyScan analysis (including the Fast Scan), the storage of Progress Scan photographs, and the use of analytics (Umami) are based exclusively on your freely given, specific, and informed consent. You can withdraw this consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Legitimate interest (Art. 6.1.f GDPR)The recording of server technical logs is based on the legitimate interest of ensuring the security and proper functioning of the service.
  • Compliance with legal obligations (Art. 6.1.c GDPR)We may retain certain data when required by fiscal, commercial, or any other applicable regulations.

Third-Party Data Processors

Gymia works with the following providers who may process users' personal data on behalf of the Service or as independent controllers. Gymia reserves the right to replace or add new providers at any time. When such a change affects the processing of your personal data, you will be notified at least 15 days in advance and this section will be updated.

  • SupabaseDatabase, storage, and authentication · European Union (AWS eu-west-3)Acts as a data processor under a signed DPA.
  • Google Cloud EMEA LimitedBody image analysis using artificial intelligence (Vertex AI, Gemini model) · European Union ('eu' multi-region processing)Images are processed through Google Cloud's Vertex AI, contracted with Google Cloud EMEA Limited (Ireland), with processing in European Union data centers under the Google Cloud Data Processing Addendum (Cloud DPA). Submitted data is not used to train models and is not retained beyond the processing needed to return the response.
  • Umami Software, Inc.Usage analytics (Umami Cloud) · United States / European Union (with appropriate safeguards)Only active with prior user consent. Receives anonymized and aggregated usage data, without cookies or cross-site tracking. Acts as a data processor under a DPA.
  • RevenueCat, Inc.In-app purchase management · United States (with appropriate safeguards)Manages the status of purchases made through the Apple App Store and Google Play. Gymia does not receive or store card details or financial data; billing is processed by Apple or Google as independent controllers.
  • Render (Render Services, Inc.)Hosting of the backend server (NestJS) · Germany (Frankfurt, European Union)The backend server is hosted in the Frankfurt (EU) region. Render Services, Inc. is a US entity and acts as a data processor under a DPA with Standard Contractual Clauses. Technical logs are automatically deleted within a maximum of 30 days.

Retention Periods

  • Account data (email)While the account is active. Deleted within 30 days following an account deletion request.
  • Progress Scan photosUntil the user deletes them manually or deletes their account. There is no mandatory minimum retention.
  • Fast Scan photosNot stored. Permanently discarded after real-time processing.
  • Usage data and BodyScan metricsWhile the account is active or until deleted by the user.
  • Server technical logs (Render)Maximum of 30 days, automatically deleted.

Your Rights

As a resident user in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

  • Access (Art. 15)Request a copy of the personal data we process about you.
  • Rectification (Art. 16)Request the correction of inaccurate or incomplete data.
  • Erasure / 'Right to be forgotten' (Art. 17)Request the deletion of your data. You can do this directly from the app (settings → delete account) or by sending a request to contact@gymia.one.
  • Restriction of processing (Art. 18)Request that we restrict the processing of your data under certain circumstances.
  • Portability (Art. 20)Receive your data in a structured, commonly used, and machine-readable format.
  • Objection (Art. 21)Object to processing based on legitimate interest.
  • Withdrawal of consentWithdraw at any time the consent granted (e.g., for analytics or for the processing and storage of body photos) without retroactive effect.
  • Complaint to a supervisory authorityFile a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if you consider that the processing of your data violates current regulations.

To exercise any of these rights, contact us at contact@gymia.one indicating your name, registered email address, and the right you wish to exercise. We will respond within a maximum period of 30 calendar days.

Data Controller

The controller of your personal data is: Name: Samuel Navasardyan Vardanyan Trade name: Gymia Website: https://gymia.one Contact email: contact@gymia.one As Gymia is not incorporated as an independent legal entity at this time, the controller acts as an autonomous natural person in the exercise of this activity.

Data Protection Officer (DPO)

Gymia is not required to appoint a Data Protection Officer under Art. 37 of the GDPR, as it is not a public body, does not conduct systematic monitoring of data subjects on a large scale, and does not process special categories of data as its core activity on a large scale. For any inquiries regarding data protection, you can directly contact the data controller at contact@gymia.one.

Minimum Age Requirement

The Service is exclusively directed to individuals over 18 years of age. By registering, you confirm that you are at least 18 years old. If we become aware that a user is under 18, we will immediately delete their account and all associated data. If you are a parent or legal guardian and believe your minor child has created an account, please contact us at contact@gymia.one.

International Data Transfers

The Service's core infrastructure (database, storage, backend server, and AI processing) is located in the European Union. However, some providers are US entities or may process certain data outside the European Economic Area (e.g., Umami Software, Inc. or RevenueCat, Inc.). Such transfers are carried out under appropriate safeguards in accordance with Art. 46 of the GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission and, where the provider is certified, the EU-U.S. Data Privacy Framework (DPF).

Security Breach Notification

In the event of a security breach that may pose a risk to users' rights and freedoms, Gymia will notify the Spanish Data Protection Agency (AEPD) within a maximum period of 72 hours from becoming aware of it, in accordance with Art. 33 of the GDPR. If the breach entails a high risk for the affected users, they will be informed directly and without undue delay, in accordance with Art. 34 of the GDPR.

Data Security

We apply appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or accidental destruction, including: storage in private buckets with role-based access control (RLS) in Supabase, data transmission via HTTPS/TLS, and restricted access to photographs through short-lived signed URLs.

Cookies Policy

We use cookies and similar technologies. Technical cookies are necessary for the operation of the Service and do not require your consent. Usage analytics (Umami) will only be activated if you give your explicit consent through the cookie banner that appears on your first visit. You can modify your preferences at any time from the 'Manage cookies' link available in the footer of the site. For more information, please see our full Cookies Policy.

Changes to this Policy

We may update this Privacy Policy periodically. When we make substantial changes, we will notify you through an in-app notice or via email at least 15 days in advance. The date of the last update is always listed at the top of the document.

Contact

If you have any questions, doubts, or requests regarding this Privacy Policy or the treatment of your personal data, you can contact us at: Email: contact@gymia.one Website: https://gymia.one