Privacy Policy
Effective date: 4 September 2026
Last updated: 4 September 2026
This Privacy Policy explains what personal data Gymothy ("we", "us", "the App") collects when you use the Gymothy mobile application, why we collect it, how it is stored, and the rights you have over it. Gymothy is a workout-tracking and fitness-social app. We built it to be small, honest, and boring about your data: we do not sell it, we do not run ads, we do not embed ad-tech, and we do not track you across other apps or websites.
This policy is written to comply with the EU General Data Protection Regulation (GDPR). If you are outside the EU, the same protections apply to you — we do not offer a lesser standard elsewhere. If you are in the United States, see §15 for the rights that apply to you specifically.
1. Who is responsible for your data (data controller)
The data controller is the individual operator of Gymothy. Full legal identity and contact details are published in the Impressum, as required for services offered to users in Germany. There is no separate data protection officer — the operator handles privacy requests personally.
2. What data we collect
We collect only what the App needs to function:
| Category | Examples | Why we collect it |
|---|---|---|
| Account data | Email address, password (stored hashed by our authentication provider, never in plain text), username, display name, bio, avatar image | To create and secure your account, and to let friends recognize you |
| Workout data | Exercises logged, sets, reps, weight, RPE, workout start/end times, personal records (PRs), notes | This is the core function of the App — tracking your training and detecting PRs |
| Fitness profile data | Body weight, goal weight, height, birth year, sex, experience level, activity level, calorie and macro targets | Optional profile values you enter (or sync from Apple Health) so the App can show progress and estimate calorie needs |
| Nutrition data | Meals you log (name, portion, calories, macros), water intake, supplements you track | To run the nutrition and hydration tracker |
| Health data from Apple Health (optional, opt-in) | Your most recent body-weight (body mass) reading | Only if you switch Health sync on. Gymothy also writes finished strength workouts and body-weight entries back to Apple Health. See §4 |
| Workout heart-rate data (optional) | Average and peak heart rate, active energy, and an effort value for a workout tracked with the Gymothy Apple Watch companion | Only if you track a workout on the watch — to show effort and heart-rate stats alongside that workout |
| Social & activity data | Friend connections, blocks, posts, comments, "respect" reactions, witness attestations (confirmations that a friend witnessed a PR), reports you file | To power the friends feed, PR verification, and safety features |
| Photos | Images you choose to upload to a workout post or set as an avatar; meal photos you submit to the AI estimator (transient — see §5) | Only uploaded if you explicitly attach a photo |
| Gamification data | XP events and level, achievements earned, weekly missions and their progress, streak tokens, unlocked and equipped avatar cosmetics | To run the RPG-style progression layer — all of it is derived from your own training and social activity, none of it from tracking you |
| Location data (optional, opt-in) | For a saved gym: a label, coordinates, and a check-in radius. For a workout check-in: one GPS coordinate fix, its reported accuracy, the computed distance to your nearest saved gym, an Android "mock location" flag, and a verified/unverified/flagged verdict | Only if you create a saved gym and grant location permission — to verify (anti-cheat) that a workout happened at your gym, for a small XP bonus. See §3 |
| AI feature data (optional, consent) | The meal photo or meal description you submit, and aggregated training statistics for the weekly coach or a suggested training split | Only if you have enabled AI features. Sent to our AI provider for processing; photos are transient and not stored by us. See §5 |
| Product analytics (on by default, switchable off) | Event names (e.g. "workout_finish"), screen names, app version, platform (iOS/Android/web), and a pseudonymous user identifier | To see where people get stuck or drop off so we can fix the App. Never used for ads or profiling. See §6 |
| Two-factor authentication (2FA) data | If you enable 2FA: a TOTP (authenticator-app) secret, held entirely by our authentication provider (Supabase Auth) — never stored or seen by the App itself | To add an optional second layer of login security |
| Push notification token | A device token issued by Apple/Google/Expo's push service | To deliver notifications (friend requests, comments, witness requests) to your device |
| Technical/session data | Auth session tokens, timestamps of account/content creation | To keep you signed in and to operate the database correctly |
We do not collect: continuous or background location, your contacts or address book, advertising identifiers (no IDFA, no Android Advertising ID), browsing history outside the App, biometric identifiers, or clinical/medical records. Gymothy shows no advertising, so no ATT (App Tracking Transparency) prompt is needed and none is shown.
Some of the data above — body weight, workout and nutrition entries, heart rate, and anything a meal photo reveals — is health-related data in the sense of Art. 9 GDPR. We treat every one of those features as optional and consent-based (see §3, §4 and §5), and we never use them for advertising, scoring you against other users' health, or any purpose beyond the feature you switched on.
3. Location data (gym check-in)
Gymothy has one optional feature that uses your device location: gym check-in. It verifies that a workout actually happened at a gym you saved — a small anti-cheat measure that grants a modest XP bonus for a verified check-in. This is the only feature that uses location, and it is strictly opt-in. If you never save a gym, Gymothy never requests or reads your location at all.
Opt-in, twice over. Location is used only if both are true: (1) you have created at least one "saved gym" in Settings, and (2) you have granted the App "while using the app" (foreground) location permission. We never request background or "always" location, and the App is technically configured so that it cannot collect location in the background — no background location, no geofencing service, no foreground service.
When we read your location — and how often. We take a single, one-shot GPS fix at two moments only:
- when you tap to save your current location as a gym in Settings (to store that gym's coordinates); and
- when you finish a workout, and only if you already have a saved gym and have already granted permission — one fix, compared against your saved gym. It never prompts you at workout finish and never blocks finishing.
There is no continuous tracking, no route recording, no background collection, and no location read at any other time.
What we store. For a saved gym: the label you choose, its coordinates, and a check-in radius (80–300 m). For a workout check-in: the single coordinate fix, its reported accuracy, the computed distance to your nearest saved gym, a "dwell" flag (whether the workout lasted long enough to be plausible), the Android mock-location flag (see below), and a verdict of verified, unverified, or flagged. The verdict is computed on our server, never by your device — the App cannot mark its own check-in as verified.
Android mock-location disclosure. On Android, the operating system exposes a flag indicating whether a location reading was produced by a mock-location (GPS-spoofing) app. We read and store this flag solely to flag potentially faked check-ins for anti-cheat review. We do not use it for any other purpose. (iOS does not expose an equivalent flag.)
Legal basis. Consent (Art. 6(1)(a) GDPR). You give consent by saving a gym and granting the OS-level permission, and you can withdraw it at any time: revoke location permission in your device settings and/or delete your saved gyms in Gymothy (Settings → gyms), which stops all future location use.
Retention & deletion. Saved gyms and check-in records last as long as the account (or the associated workout) they belong to. Deleting a saved gym removes that gym definition. Deleting a workout deletes its check-in. Deleting your account deletes all of your saved gyms and all of your check-in records via the same server-side cascade as the rest of your data (see §13). Location data is never shared with third parties and never leaves our EU-hosted database.
One purpose only. To say it plainly: location data exists in Gymothy solely to verify gym check-ins. It is never used for advertising or analytics, never combined with other data for profiling, and never sold.
4. Apple Health (HealthKit)
Health sync is optional and off by default. You turn it on in Settings → Apple Health, and iOS asks you separately which categories you allow.
What Gymothy reads. One category only: your most recent body mass (body weight) sample, used to prefill the weight in your fitness profile. That synced value is then stored in your Gymothy account (in our EU database) like any other profile value. No other Health samples are read, and raw Health data otherwise stays on your device.
What Gymothy writes. Finished strength workouts (as an Apple Health workout of type traditional strength training) and body-weight entries you log in the App, so your Apple Fitness history and weight trend stay complete.
What we never do with Health data. As required by Apple's HealthKit rules, and as our own commitment:
- Health data is never used for advertising, marketing, or any similar service — Gymothy has no advertising of any kind.
- Health data is never sold, rented, or disclosed to data brokers, insurers, employers, or any other third party.
- Health data is never shared beyond your own account: it is not posted to the feed, not shown to friends, and not visible to other users.
- Health data is never used for XP, levels, ranks, duels, leaderboards, or any competitive scoring.
- Health data is not used for AI features unless you separately enable them (see §5), and it is not written to iCloud by Gymothy.
Legal basis. Explicit consent (Art. 6(1)(a) together with Art. 9(2)(a) GDPR), given by switching the toggle on and granting the iOS Health permission. Withdrawing consent: switch Health sync off in Gymothy Settings, and/or revoke access in iOS Settings → Privacy & Security → Health → Gymothy. Withdrawal stops all future reads and writes; the body-weight value already stored in your fitness profile is removed when you delete your account (§13) and can be edited by you at any time.
5. AI features (meal estimates, weekly coach, training plans)
Gymothy has three optional features that use a third-party AI model:
- Meal estimation — you submit a photo of a meal and/or a text description, and get an estimated calorie and macro breakdown that you can edit before saving.
- Weekly coach — aggregated statistics from your recent training (and, if present, your body-weight trend) are summarised into highlights and suggestions.
- Training plan suggestion — a short description you write is turned into a suggested training split built from Gymothy's own exercise catalogue.
Nothing is sent until you agree. All three features are behind a single in-app consent gate. Before the first use, Gymothy shows you a consent screen explaining what is sent and to whom; if you decline, nothing is transmitted and manual logging works exactly as before. Your consent is recorded on your profile, and the server refuses AI requests when it is absent.
Who processes it. Requests are routed through our own Supabase edge function (so our API keys never ship inside the App) to Google's Gemini API (Gemini 2.5 Flash), operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with Google LLC (United States) as a sub-processor. We keep a configured fallback to Anthropic PBC (Claude, United States) so the feature can stay available if the primary provider fails; if we make Anthropic the standing provider we will update this policy and the in-app consent notice. In either case the provider acts as our processor.
What is sent. Only what the feature needs: the meal photo and/or meal description you submitted, or the aggregated training statistics described above. We do not send your email address, your username, your social content, your friends list, or your location.
What happens to it. Meal photos and descriptions are transient — we transmit them for the estimate and do not store the image; what is stored is the meal entry you choose to save, which you can delete at any time. At the provider, the request is processed under Google's API data-processing terms; Google states that data submitted through the paid Gemini API is not used to train its models and is retained only briefly for abuse monitoring. We pass that on as the provider's own commitment — it is what those terms say, not a guarantee we are in a position to independently verify. We also apply a daily per-user request cap.
Legal basis. Consent (Art. 6(1)(a) GDPR), and — because a food photo or body-weight trend can reveal health information — explicit consent under Art. 9(2)(a) GDPR. Withdrawing consent: Settings → Withdraw AI consent. Withdrawal is immediate and blocks any further AI request server-side. It does not affect processing that already lawfully happened, and it does not delete meals you already saved (you can delete those individually).
Transfers. See §10 — the AI provider chain involves a United States entity, and we rely on the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework for that leg.
6. Product analytics
Gymothy measures how the App is used, never who you are. The goal is behavioural and diagnostic: which onboarding step loses people, which screen they bounce out of, which feature nobody finds. It is explicitly not a profiling or ad-targeting system, and it feeds no advertising ecosystem of any kind.
Two layers, both minimal.
- First-party events, written into our own Supabase database in the EU. Each row holds an event name from a fixed, typed list, a small property bag (screen name, feature key, plan id), the platform (
ios/android/web), the app version, and your account id. It never contains free text you typed, your email, your name, your workout or meal content, your photos, or your location. - PostHog, a product-analytics service used as our processor, running on PostHog EU Cloud in Frankfurt, Germany (PostHog, Inc. / its EU-hosted service). PostHog receives exactly the same shape of data: event names, screen names, app version, platform, and a pseudonymous user identifier. It receives no email address, no name, no workout, meal, photo, health or location data.
What we deliberately do not switch on. No session replay (we never record your screen), no autocapture (only the events we explicitly write are sent), no advertising identifier, no device fingerprinting, no cross-app or cross-site tracking, and no ad-network or data-broker integrations. Nothing collected here is combined with data from other services to build a profile of you.
Legal basis. Legitimate interest (Art. 6(1)(f) GDPR) — our interest in understanding and fixing our own product, balanced against your interests by keeping the data pseudonymous, minimal, EU-hosted, free of any advertising use, and switchable off in one tap. You may object at any time (Art. 21 GDPR); the switch below is the fastest way to do that.
Your switch. Settings → Analytics. It is on by default and turning it off stops both layers — no further events are collected or transmitted, from either the first-party pipeline or PostHog.
§ 25 TDDDG (device storage). Product analytics needs an identifier stored on your device to recognise repeat events from the same install. We do not claim that this storage is strictly necessary within the meaning of § 25(2) TDDDG. It is used solely for the pseudonymous product analytics described here, never for advertising or cross-service recognition, and switching the Analytics toggle off stops it being stored or read.
Retention. Analytics events are kept no longer than 12 months and are then deleted or aggregated. If you delete your account, your first-party analytics rows are detached from your identity (the user reference is nulled) so that aggregate funnels survive while the history stops being attributable to you.
7. Signing in with Apple or Google
You can create an account with an email address and password, or with Sign in with Apple or Sign in with Google. Sign-in is handled by our authentication provider (Supabase Auth); we never see or receive your Apple or Google password, and we get no access to those accounts beyond what sign-in returns.
- Sign in with Apple. We receive a stable Apple user identifier and an email address. On the first sign-in only, Apple may also pass the name you chose to share. Apple's "Hide My Email" is fully supported: if you use it, we only ever receive Apple's private relay address, never your real one, and everything we send you goes through that relay. You can revoke Gymothy's access at any time in iOS Settings → your name → Sign-In & Security → Sign in with Apple.
- Sign in with Google. We receive a Google user identifier, your email address, and, where Google provides them, your name and profile picture. You can revoke access at any time in your Google Account's third-party connections settings.
We use this data solely to create and authenticate your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
8. How we use your data (purposes & legal basis)
- To provide the service (Art. 6(1)(b) GDPR — performance of a contract): storing your workouts, computing PRs, rendering your feed, running the XP/level/achievement/mission progression, running the nutrition tracker, authenticating you, and sending notifications you'd expect from a social fitness app.
- To keep the community safe (Art. 6(1)(f) — legitimate interest): processing reports, enforcing blocks, allowing moderator review of reported content, and reviewing check-ins flagged by the anti-cheat system.
- To secure your account (Art. 6(1)(f)): authentication, session management, abuse prevention, per-user request caps.
- To understand and improve the App (Art. 6(1)(f)): the pseudonymous product analytics in §6, which you can switch off.
- With your consent (Art. 6(1)(a), and Art. 9(2)(a) where health data is involved): push notifications, uploading a photo to a post, Apple Health sync (§4), the AI features (§5), and the optional gym check-in location feature (§3). You can withdraw any of these at any time.
We do not use your data for advertising, for automated decision-making with legal or similarly significant effects, or for any purpose beyond operating the App as described above. We do not sell, rent, or trade your personal data to any third party.
9. Who can see your data
Gymothy is a friends-only social app, enforced by server-side access rules (Row Level Security), not just app-side logic:
- Your workouts, sets, PRs, XP, nutrition entries, body weight, gym check-ins, and location data are private to you unless you post them (and location, check-in and health data is never posted).
- Posts are visible to your confirmed friends only (or to nobody, if you mark a workout "private"). Your achievements and equipped cosmetics are visible to your confirmed friends.
- If you block someone, all content between you becomes mutually invisible — this is enforced at the database level, not just hidden in the UI.
- A designated moderator account (the app operator) can view content you report, content someone reports about you, and check-ins the anti-cheat system has flagged, solely to resolve reports and investigate suspected cheating.
10. Where your data is hosted, and international transfers
The core of Gymothy stays in the EU. All account, workout, nutrition, social, gamification, health-profile and location data is hosted on Supabase, running in the eu-central-1 (Frankfurt, Germany) AWS region. Product analytics sent to PostHog stays in the EU as well, on PostHog EU Cloud in Frankfurt. The public website (gymothy.de) is served by Cloudflare and holds no account data at all.
Some processing necessarily involves entities outside the EU:
| Transfer | What leaves the EU | Safeguard |
|---|---|---|
| Push notification delivery | Your push token and the notification text, routed via Expo's push service and then Apple (APNs) or Google (FCM) | EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework where the recipient is certified |
| AI features (only if you consented, §5) | The meal photo/description or aggregated training statistics you submitted | Contract with Google Ireland Limited; onward transfer to Google LLC (US) under EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework. Same for the Anthropic PBC (US) fallback |
| Product analytics (unless you switched it off, §6) | Pseudonymous events, stored in Frankfurt; PostHog, Inc. is a US company and may access the EU instance for support | EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework |
| Website delivery | The website only — no account data | Cloudflare, Inc. (US): EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework |
Where we rely on Standard Contractual Clauses, you may request a copy of the relevant terms using the contact details in the Impressum.
11. How long we keep your data
We keep your data for as long as your account exists. If you delete your account (see §13), your data is deleted immediately and permanently — there is no "soft delete" grace period, no backup retention window we can restore from, and no way for us or you to undo it. Individual items you delete yourself (a workout and its check-in, a saved gym, a meal, a post) are removed at the moment you delete them. Product analytics events are kept no longer than 12 months (§6). Meal photos submitted to the AI estimator are not stored by us at all (§5).
12. Your rights
Under GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data (most of this you can already edit yourself in Settings).
- Erasure ("right to be forgotten") — delete your account and all associated data, in-app, at any time (§13).
- Restriction & objection — ask us to limit or stop certain processing, including objecting under Art. 21 GDPR to anything we base on legitimate interest (such as the product analytics in §6, which you can also simply switch off).
- Data portability — request your workout data in a structured, machine-readable format.
- Withdraw consent — for anything based on consent (push notifications, photo uploads, Apple Health sync, AI features, gym check-in location), at any time, without affecting past lawful processing.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any right not available directly in-app, contact us using the details in the Impressum. We answer within one month, as GDPR requires.
13. Deleting your account (in-app)
You can permanently delete your Gymothy account at any time from Settings → Delete account. You will be asked to type your username to confirm. On confirmation, your account and all data linked to it — profile, fitness profile, workouts, sets, PRs, nutrition entries, posts, comments, reactions, attestations, friendships, blocks, reports you filed, notifications, XP events, achievements, missions, cosmetics, saved gyms, and gym check-in records — are deleted immediately via a server-side cascade. This action cannot be undone and we cannot recover the data afterward, so please be certain.
14. Children
Gymothy is not directed at children. You must be at least 16 years old (or the age of digital consent in your jurisdiction, if that is higher) to create an account and use the App.
We do not currently verify age at sign-up. The birth year you may enter during onboarding is used only to estimate calorie needs and heart-rate zones — it is not an age check, and it is optional. If we learn that an account belongs to someone below the applicable minimum age, we delete that account and its data. If you are a parent or guardian and believe a child has created an account, contact us using the details in the Impressum and we will delete it.
15. Users in the United States
If you are a resident of California or another US state with a comprehensive privacy law (Colorado, Connecticut, Virginia, and others), the following applies in addition to everything above — we apply one standard worldwide rather than a weaker one outside the EU.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months and have no plans to. There is no "Do Not Sell or Share My Personal Information" mechanism because there is nothing to opt out of.
- No targeted advertising and no profiling that produces legal or similarly significant effects.
- Sensitive personal information (health and fitness data, precise geolocation) is collected only for the optional features you switch on, and used only to provide those features — never to infer characteristics about you, and never disclosed for anyone else's purposes.
- Your rights: to know/access what we collect and why, to delete it, to correct it, to obtain a portable copy, and to be free from discrimination for exercising any of these rights. We will not degrade the service because you exercised a right.
- How to exercise them: deletion is instant and self-service in-app (Settings → Delete account, §13). For access, correction, or portability, email us at the address in the Impressum. We verify requests by checking that you write from the email address on the account, and we respond within 45 days. An authorised agent may act for you with written proof.
16. Ads, tracking, and every third party we use
No ads. No ad-tech. No cross-app tracking. No sale of your data. Gymothy embeds no advertising SDK, no ad network, no attribution or ad-measurement SDK, no tracking pixel, and no advertising identifier. Nothing in the App tracks you across other apps or websites, which is why iOS never shows you an App Tracking Transparency prompt. We share nothing with data brokers.
What we do use is privacy-friendly, EU-hosted product analytics that you can switch off (§6), plus the processors the App needs to run. Here is the complete list:
| Processor | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | Everything in §2 that is stored server-side | EU (eu-central-1, Frankfurt) |
| Expo (push service) | Relays push notifications to Apple/Google | Push token, notification title and text | US — see §10 |
| Apple (APNs) / Google (FCM) | Deliver the push notification to your device | Push token, notification title and text | US/global — see §10 |
| Apple / Google (sign-in) | Sign in with Apple, Sign in with Google | The sign-in exchange described in §7 | US/EU — see §7 |
| Google (Gemini API) | AI meal estimates, weekly coach, plan suggestions — only with your consent | The meal photo/description or aggregated training stats you submitted (§5) | Google Ireland Limited (IE), sub-processor Google LLC (US) |
| Anthropic PBC | Configured fallback AI provider for the same features, used only if the primary fails | Same as above | US |
| PostHog | Product analytics — switchable off | Event names, screen names, app version, platform, pseudonymous user id (§6) | PostHog EU Cloud, Frankfurt |
| Open Food Facts | Barcode lookup when you scan a food product | The barcode number only — no account data, no personal data | EU (open database, France) |
| Cloudflare | Hosting for the public website gymothy.de — the website only, not the App | Standard web request data for the website | Global edge — see §10 |
All of these act as processors on our instructions (or, for Apple/Google sign-in and push delivery, in their own defined roles as platform operators), not as independent controllers who may use your data for their own purposes.
17. Changes to this policy
If this policy changes materially, we will update the "Last updated" date above and, where required, notify you in-app. Where a change concerns processing based on your consent, we will ask for consent again rather than assume it.
18. Language versions
A German-language version of this Privacy Policy (Datenschutzerklärung) is available in-app and at privacy-policy.de.md. If the two versions ever conflict, the English version governs for legal interpretation, but we intend them to say exactly the same thing.
19. Contact
See the Impressum for the legally responsible party and contact details.
Terms of Service (ToS / EULA)
Effective date: 4 September 2026
Last updated: 4 September 2026
These Terms of Service ("Terms") are a legal agreement between you and the operator of Gymothy (see the Impressum) governing your use of the Gymothy mobile application ("Gymothy", "the App"). By creating an account or using the App, you agree to these Terms. If you do not agree, do not use the App.
We've tried to write these in plain language rather than dense legalese, so that they're actually useful to a German consumer as well as anyone else. Where plain language and precise legal meaning conflict, the plain-language intent controls.
1. What Gymothy is
Gymothy is a workout tracker and social fitness app: you log your training, the App detects personal records (PRs), and you can share your progress with friends who can react, comment, and "witness" (verify) your PRs. It also includes optional nutrition tracking and optional AI-assisted estimates, described in the Privacy Policy.
Gymothy is offered free of charge. There are currently no in-app purchases, no subscriptions, and no advertising.
2. Eligibility & account access
- You must be at least 16 years old, or the minimum age of digital consent in your country if that is higher.
- Account creation currently requires a valid invite code. This may change; if we open registration, these Terms continue to apply unchanged in every other respect.
- You are responsible for keeping your login credentials confidential and for all activity under your account.
- One person, one account. Do not create accounts on behalf of someone else or impersonate anyone.
3. Your content (User-Generated Content / UGC)
You keep ownership of everything you post — workout data, photos, captions, comments, PR claims ("Your Content"). By posting Your Content, you grant Gymothy a limited, non-exclusive, royalty-free license to store, process, and display it to the audience you chose (friends, or nobody, per your visibility setting) solely to operate the App. We do not license Your Content to third parties, and we do not use it for advertising.
You are solely responsible for Your Content. You represent that you have the rights to post it and that it does not violate these Terms or any law.
4. Objectionable content & acceptable use — zero tolerance
Gymothy has zero tolerance for objectionable content and for abusive users. Photo posts are not pre-moderated before publishing — they go straight to your friends, because Gymothy is built for small, trusted circles. That means the safety of the community depends on you following these rules, and on the report/block/moderation system as the backstop. You agree not to post or send, via the App:
- Nudity, sexually explicit material, or content primarily intended to be sexually gratifying.
- Content depicting or promoting violence, self-harm, eating disorders, or dangerous/unsafe training practices presented as advice.
- Hate speech, harassment, bullying, or content that threatens, demeans, or discriminates against any person or group.
- Illegal content of any kind, including content that infringes another person's intellectual property or privacy rights.
- Spam, scams, or commercial solicitation unrelated to your personal training.
- Impersonation of another person, or intentionally false claims presented as fact.
Posting any of the above is a material breach of these Terms, and there is no warning quota: a single serious violation is enough to have your content removed and your account terminated.
5. Reporting, blocking, and enforcement
- Report. Any user can report a post, a comment, or a user, with a reason, at any time — from the "⋯" menu on any post or from a user's profile. No account setting or special status is needed.
- Block. You can unilaterally block any user. Blocking hides all content between you and them in both directions, immediately, enforced at the database level, without needing operator involvement.
- Our response. Reports are reviewed by a moderator. We act on reports within 24 hours — removing content that violates §4 and ejecting the user who provided it where warranted. Confirmed violations may result in content removal; repeated or severe violations result in account suspension or deletion.
- Contacting us. You can reach the operator directly at the email address in the Impressum, including to appeal a moderation decision. We normally reply within a few business days.
6. The witness-honesty clause (PR verification)
Gymothy lets you tag a friend as a "witness" to a personal record, and that friend can confirm or decline the request. A confirmed witness attestation is displayed as a verified badge next to your PR.
By requesting a witness confirmation, you represent that the lift actually happened as logged, in front of (or verifiably known to) the witness you tagged.
By confirming a witness request, you represent that you actually witnessed the lift, or have a good-faith basis to believe it happened as described, and are not confirming it as a favor, joke, or automatic reflex.
Knowingly false PR claims or knowingly false witness confirmations are a violation of these Terms and may be reported like any other objectionable content, with the same enforcement consequences. Gymothy's witness system is a social trust mechanism, not a cryptographically verified one — we rely on the community using it honestly, and we reserve the right to remove badges or restrict accounts that abuse it.
7. No professional advice
Gymothy displays exercise information (muscle groups, equipment, instructions), your own logged numbers, and — if you enable them — AI-generated estimates and suggestions. None of this is medical, nutritional, or professional fitness advice. AI-generated calorie and macro estimates in particular are approximations and can be wrong; you can and should edit every number before saving it. Consult a qualified professional before starting any new training or nutrition program, especially if you have a pre-existing health condition. You use the App's exercise library, nutrition features, and AI features at your own risk.
8. Account termination
By you: you may delete your account at any time, in-app, via Settings → Delete account. This immediately and permanently deletes your data (see the Privacy Policy §13) — it cannot be undone.
By us: we may suspend or delete your account if you materially violate these Terms (see §4), for legal compliance reasons, or to protect the safety of other users, with notice where reasonably possible.
9. Availability & changes
Gymothy is currently operated as a free, small-scale service with no in-app purchases and no advertising. We do not guarantee uninterrupted availability, and features may change, be added, or be removed as the App evolves. We will not charge you money without clear advance notice and your explicit agreement — there is no hidden billing.
If we change these Terms materially, we will update the date above and, where required, notify you in-app before the change takes effect.
10. Disclaimer of warranties & limitation of liability
The App is provided "as is," without warranties of any kind to the extent permitted by applicable law. To the maximum extent permitted by law, the operator is not liable for indirect, incidental, or consequential damages arising from your use of the App. Nothing in these Terms excludes liability that cannot be excluded under German or EU consumer protection law (e.g. liability for intent or gross negligence, for injury to life, body or health, or statutory rights you have as a consumer), and nothing in these Terms limits any rights you have under mandatory law where you live.
11. Apple App Store terms
This section applies where you obtained the App from Apple's App Store. It reflects the minimum terms Apple requires of any third-party end-user licence agreement.
- These Terms are between you and us only, not Apple. Apple is not a party to this agreement and is not responsible for the App or its content.
- Licence scope. Your licence to use the App is a non-transferable licence to use it on any Apple-branded device you own or control, as permitted by the Usage Rules in the Apple Media Services Terms and Conditions.
- Maintenance and support. We — not Apple — are solely responsible for providing any maintenance and support for the App. Apple has no obligation to furnish any maintenance or support services.
- Warranty. To the maximum extent permitted by applicable law, Apple has no warranty obligation with respect to the App. If the App fails to conform to any applicable warranty, you may notify Apple, and Apple will refund the purchase price for the App to you. The App is free of charge, so that refund amount is zero. Apple has no other warranty obligation whatsoever with respect to the App.
- Claims. We — not Apple — are responsible for addressing any claims relating to the App or your possession and use of it, including product liability claims, claims that the App fails to conform to a legal or regulatory requirement, and claims arising under consumer protection, privacy, or similar legislation.
- Intellectual property claims. If a third party claims the App infringes their intellectual property rights, we — not Apple — are solely responsible for the investigation, defence, settlement, and discharge of that claim.
- Legal compliance. You represent that you are not located in a country subject to a U.S. Government embargo or designated as a "terrorist supporting" country, and that you are not listed on any U.S. Government list of prohibited or restricted parties.
- Third-party beneficiary. Apple and Apple's subsidiaries are third-party beneficiaries of these Terms and, upon your acceptance, have the right (and are deemed to have accepted the right) to enforce these Terms against you as a third-party beneficiary.
12. Governing law and consumer rights
These Terms are governed by the laws of Germany, without prejudice to any mandatory consumer-protection rights you have under the law of your country of residence. If you are a consumer in the EU, you keep every protection your home country's law gives you, and you may bring proceedings in the courts of your place of residence.
If you are a consumer in the United States, nothing in these Terms waives any right you have under mandatory state or federal law. We do not require binding arbitration, we do not ask you to waive a jury trial, and we do not ask you to waive participation in a class action.
We are not obliged and not willing to participate in dispute resolution proceedings before a consumer arbitration board (§ 36 VSBG).
13. Contacting us
You can reach the operator of Gymothy at the email address published in the Impressum — for support, moderation appeals, privacy requests, or legal notices. We normally reply within a few business days.
14. Language versions
A German-language version of these Terms (Nutzungsbedingungen) is available in-app and at terms.de.md. If the two versions ever conflict, the English version governs for legal interpretation, but we intend them to say exactly the same thing.