Privacy
Privacy Policy
Effective date: 5 July 2026 · Version 1.0. Operated by Pittura FZ LLC, licensed in Ras Al Khaimah Economic Zone (RAKEZ), Ras Al Khaimah, United Arab Emirates. Contact: support@gymciety.net.
1. The short version
Gymciety is a platform that connects personal trainers, their clients, and gyms. To make coaching work, we store fitness and health information that you or your trainer enter — and we take that seriously.
- We collect only what the platform needs to deliver coaching and gym management. Nothing is harvested from your phone in the background.
- We do not collect your location, your contacts, or data from Apple Health / Google Fit. There are no advertising or behavioral-analytics trackers in Gymciety.
- We never sell your data, and we never share it with advertisers.
- Your most personal information — progress photos, meal logs, health details, private messages — is visible only to you and your trainer. Never to gym management, and never to other members.
- You can get a copy of your data, correct it, or delete your account and data at any time.
2. Who is responsible for your data
Gymciety is operated by Pittura FZ LLC ("Gymciety", "we", "us"), a company licensed in RAKEZ, Ras Al Khaimah, UAE. We comply with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL").
For most data on the platform, Pittura FZ LLC is the data controller — we decide what is collected and why.
One important exception: if your client account is connected to a gym, that gym is the controller of the client data processed in connection with its business (memberships, check-ins, sessions, payments), and Gymciety acts as the gym’s data processor under a data processing agreement. In practice this means the gym is responsible for how it uses your data within the platform, and Gymciety is responsible for storing and processing it securely on the gym’s instructions. Either way, your rights (section 12) work the same and you can always contact us directly.
3. If you are a client
Account & profile. Your email address and password (encrypted — nobody, including us, can read it), full name, phone number, date of birth (to confirm you’re 18+ and tailor your plan), gender (used to tailor training and nutrition targets and, where offered, to match you with a suitable trainer), and optional details you add: profile photo, bio, timezone, social links, and an emergency contact (name and phone) so your trainer or gym can reach someone if something happens during training.
Health & fitness information. This is sensitive personal data under UAE law, and we collect it only with your explicit consent, given at signup:
- Height, weight, and weight history — to track progress toward your goal.
- Fitness goals, fitness level, and activity level — so your trainer can program for you.
- Health conditions, injuries, and physical limitations — so your trainer can train you safely.
- Dietary restrictions, allergies, and food dislikes — so nutrition plans fit you.
- Your answers to your trainer’s intake and onboarding questionnaires.
- Body measurements over time: weight, body-fat percentage, muscle mass, and circumference measurements.
- Daily wellness metrics you choose to log: steps, sleep, stress, energy, soreness, motivation, water intake, resting heart rate, heart-rate variability, and blood pressure. Nothing is pulled automatically from your phone or wearable — every entry is manual.
- Progress photos — only if you give the separate, optional photo consent. Photos are stored in a private, access-controlled vault and are served only through short-lived secure links.
- Your responses to check-ins your trainer sends you, which may cover your week, energy, mood, or anything else your trainer chooses to ask.
Training data. Programs and workouts assigned to you; every session you log including sets, reps, weights, effort ratings, and notes; personal records; your schedule and training-day preferences; and training-load figures calculated from your sessions.
Nutrition data. Your calorie and macro targets, meal plans, recipes and shopping lists; meals you log, including photos of your food and foods you scan by barcode; and your trainer’s feedback on your meals.
AI meal analysis. If you log a meal by photo, the image is sent to our AI provider (Anthropic) to estimate calories and macronutrients. The provider processes it solely to return the analysis and does not use your photos to train its models. If you prefer, log meals manually — the AI step only happens when you choose photo logging.
Messages & reviews. Your chat messages and attachments with your trainer; reviews and ratings you write (you choose whether a review is visible to your trainer or only to gym management); and notifications we send you. Your trainer may also keep private coaching notes about you — professional observations that help them coach you.
Sessions & payments. Your bookings, session times, and cancellations. If you pay through Gymciety: your chosen plan or package, amounts, currency, payment status, and credit balance. Your card details never touch Gymciety — payment is handled by Stripe, Apple, or Google, and we store only their reference identifiers.
Insights we generate. The platform computes things like progress trends, safety flags (e.g. an exercise conflicting with a logged injury), engagement signals that help your trainer know when to check in, and AI-generated suggestions that your trainer reviews. These are derived only from the data described above — we never buy or import data about you from elsewhere, and no fully automated decision with significant effects is ever made about you without human review.
Who can see your client data
Gym management sees data only if your account is connected to a gym. Gymciety staff access data only where strictly necessary to operate, secure, and support the platform.
Gym-connected clients additionally: we store your gym, membership type and member number; your gym check-ins (time and method, so the gym can manage access and attendance); the classes and facilities you book, including waitlists; and your trainer assignment. If you join a gym after signing up, we notify you in the app when the connection happens.
- Profile basics (name, photo) — your trainer and gym management; never other members.
- Health details, measurements, and wellness logs — your trainer only.
- Progress photos — your trainer only, and only with your photo consent.
- Meal logs & nutrition — your trainer only.
- Chat messages — your trainer only.
- Workouts & session history — your trainer; gym management sees summary/status only.
- Bookings, membership, check-ins, and payments — gym management, and your trainer for their own sessions.
- Reviews you mark confidential — gym management only, not your trainer.
4. If you are a coach or personal trainer
Account & identity: as for clients — email, encrypted password, name, phone, date of birth, gender, and your public profile (photo, bio, timezone, social links).
Professional profile: your specializations, certifications, years of experience, hourly rate, packages, availability, working hours, and virtual meeting links — shown to clients and, if you work under a gym, to gym management (including certification expiry dates).
Leave requests: if you work under a gym, your leave requests and the reason you enter are visible to gym management for approval and planning. The reason field is free text — share only what you’re comfortable with management seeing.
Payouts: to get paid, you connect a Stripe account. Your bank and identity details are held by Stripe under its own privacy policy — Gymciety stores only the encrypted connection tokens and account references needed to route payouts.
Your work product: programs, workouts, and templates you build; notes you write about clients; meal feedback; session records; and your client assignments. Note that content you write about a client is also that client’s personal data and may be included if they exercise their right of access.
Reviews & performance data: clients can rate and review you; reviews a client marks confidential are visible to gym management but not to you. If you work under a gym, management can also see performance figures computed from platform activity — active clients, retention, satisfaction scores, revenue generated, session hours, cancellation rates. Independent trainers’ performance data is visible only to themselves. No automated decision with significant effects (such as deactivation) is made from these figures without human review.
5. If you are a gym owner or manager
Business data: your organization’s name, type, timezone, join code, branding (logos, colors, fonts, tagline, custom styling), facilities (names, locations, hours, pricing), and the membership plans, packages, and pricing you configure. Much of this is displayed to your members and staff as part of normal operation.
Your Gymciety subscription: your plan, billing status, trial and renewal dates, and payment provider references (Stripe/Apple/Google). Card details are held by the payment provider, never by Gymciety. Billing details are visible only to the Owner role.
Admin activity: administrative actions in your organization are logged (who did what, when) for security and accountability across your team.
Your personal account (as the human behind the owner account) is covered by the same identity, technical, and security-data practices as every other account.
6. If you don’t have a Gymciety account
We may hold a small amount of your data even if you never signed up:
- Invitations: if a trainer or gym invites you, we store your email address, gender (where provided by the inviter for matching), and their personal note — solely to deliver and manage the invitation. If you don’t join within 90 days, this data is deleted. Every invite email includes a link to this policy.
- Walk-in guests: if you visit a gym as a day-pass guest, the gym may record your name and phone number at the front desk for access management. The gym is the controller of this data; Gymciety stores it on the gym’s behalf.
- Emergency contacts: a client may name you as their emergency contact (name and phone), used only if something happens to them during training.
If you’re in any of these categories and want your data corrected or removed, email support@gymciety.net.
7. Technical data (all accounts)
To keep Gymciety working and secure, we process: push-notification tokens and your notification preferences (including quiet hours and timezone); app version, build, and platform (iOS/Android); your in-app settings; and a security audit log of account actions that records the IP address, device/browser identifier, and the content of the action — retained for 12 months and used solely for security, fraud prevention, and support. We request device permissions only for features you use: camera (QR check-in, meal and progress photos), photo library (uploads), notifications, and secure storage (keeping you logged in safely).
What we deliberately don’t do: no location/GPS collection, no contact-list access, no microphone access, no Apple Health or Google Fit sync, and no third-party advertising or behavioral-analytics SDKs.
8. Who we share data with
We share personal data only with the service providers ("sub-processors") required to run the platform, each bound by contract to protect it and use it solely to provide their service to us:
- Supabase — database, authentication, and file storage; receives platform data (encrypted in transit and at rest).
- Stripe — payments and trainer payouts; receives payment and payout details (they hold card/bank data).
- Apple / Google — in-app purchases; receive purchase and receipt data.
- Anthropic — AI meal-photo analysis; receives meal photos you submit for analysis.
- Expo — push-notification delivery; receives device push tokens and notification content.
- Resend — transactional email; receives recipient email, name, and invite/reset links.
Beyond this: we disclose data if required by law or a valid legal order; in a merger or acquisition your data may transfer to the successor under this same policy (we’d notify you); and gym-connected client data is shared with that gym as described in section 3. We never sell personal data and never share it with advertisers or data brokers.
9. International transfers
Some of our sub-processors store or process data outside the UAE. Where personal data leaves the UAE, we rely on the safeguards permitted by the PDPL, including contractual data-protection commitments with each provider and, where applicable, your explicit consent given at signup.
10. Security
We protect your data with encryption in transit (TLS) and at rest; passwords hashed with industry-standard algorithms (never stored in plaintext); private storage buckets for photos and documents, accessible only via short-lived signed links; role-based access enforced at the database level, so a user can only ever query data their role permits; application-layer encryption for high-sensitivity credentials; and security audit logging. No system is perfectly secure, but if a breach occurs that risks your rights, we will notify the UAE Data Office and, where required, notify you directly without undue delay.
11. How long we keep data
- Active accounts: for as long as your account exists.
- Deleted accounts: personal data is erased within 30 days of account deletion, except payment, payout, and tax records we’re legally required to retain; signed waivers and consent records, retained as legal evidence; and coaching content that forms part of another user’s history (e.g. a program a trainer built remains in the client’s history with the trainer’s identity minimized).
- Unaccepted invites: deleted after 90 days.
- Security audit logs: 12 months.
12. Your rights
Under the PDPL you can, at any time and free of charge:
- Access — request a copy of the personal data we hold about you, in a portable format.
- Correct — fix inaccurate or outdated data (most of it you can edit yourself in the app).
- Delete — erase your account and personal data (Settings → Delete Account, or by email).
- Withdraw consent — including the optional photo consent or your overall consent (which ends your use of the platform).
- Object or restrict — ask us to stop or limit specific processing.
To exercise any right, use the in-app tools or email support@gymciety.net with the subject "Data Request". We respond within 30 days and may need to verify your identity first. If your account is connected to a gym, we may coordinate with the gym as controller, but you can always start with us. If you believe we’ve mishandled your data, you can also lodge a complaint with the UAE Data Office, the federal data protection authority.
13. Children
Gymciety is for adults. You must be 18 or older to create an account, and we do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we will delete it. If you believe a minor is using Gymciety, contact support@gymciety.net.
14. Changes to this policy
When we change this policy, we’ll update the version and effective date at the top. For material changes — especially any new category of data collection — we’ll notify you in the app and, where the law requires it, ask for your consent again before the change applies to you. Previous versions are available on request.
15. Contact
Pittura FZ LLC (operating Gymciety), Ras Al Khaimah Economic Zone (RAKEZ), Ras Al Khaimah, United Arab Emirates. support@gymciety.net — please use subject "Privacy" or "Data Request" so we can prioritize it.