GymLeap

Privacy Policy

Last updated: September 25, 2026

GymLeap ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application ("the App"). By using GymLeap, you agree to the collection and use of information in accordance with this policy.

Information We Collect

We collect the following types of information:

How We Use Your Information

We use the information we collect to:

Third-Party Services

We use the following third-party services that may collect data:

Each third-party service operates under its own privacy policy. We encourage you to review their respective policies.

Notifications

GymLeap can send local notifications such as rest-timer alerts, workout reminders, and body-weight check-in reminders. These notifications are generated and scheduled on your device — we do not send push notifications from our servers. You can disable notifications at any time from your device's system settings, and the App will continue to function without them.

Data Storage and Security

Your workout data, body measurements, and preferences are stored locally on your device using encrypted local storage. If you subscribe to GymLeap PRO, this data is additionally synced to your private Cloud Firestore document, accessible only to your authenticated account. Account credentials are securely managed through Firebase Authentication. Feedback and bug-report submissions are stored in Cloud Firestore and Firebase Storage and are only readable by our development team. Progress photos are the exception: they are stored only on your device and are never uploaded to the cloud. We implement industry-standard security measures to protect your data, but no method of electronic storage is 100% secure.

Health Connect (Android)

On Android devices, GymLeap can optionally connect to Health Connect — Google's on-device store for health and fitness data — so your training can flow between GymLeap and your other health apps. This integration is off by default and only becomes active after you enable it and grant permission through the Android Health Connect permission screen.

When enabled, GymLeap uses the following Health Connect data types:

All Health Connect access happens locally on your device between GymLeap and Health Connect. We do not receive, transmit, or store your Health Connect data on our servers, and we never use it for advertising. You remain in control: you can turn the integration off inside GymLeap, or revoke GymLeap's access at any time from the Health Connect settings on your device. Google's handling of data in Health Connect is governed by Google's own privacy policy.

Community Programs and Public Sharing

GymLeap includes an optional community feature. Browsing and downloading programs shared by other users does not require an account.

If you publish one of your own custom programs to the community, the following becomes publicly visible to all GymLeap users and is stored in our public Cloud Firestore catalog and Firebase Storage:

Publishing is entirely optional and always your choice — programs you do not publish are never shared. You can remove a program you have published at any time from within the App, which deletes it from the public catalog; copies other users have already downloaded may remain on their devices.

If you report another user's program, we receive the reported program's identifier, the author's account ID, and the reason you provide so that our team can review it.

Community Profiles, Following and the Feed

Joining GymLeap Community is optional and separate from having an account. When you join, you choose a handle and may add a display name, a short bio, a city and a training goal.

Visible to any signed-in GymLeap user who knows or searches your handle, whether your account is private or public: your handle, display name, bio, city, training goal, profile picture, and your follower and following counts.

Visible to your accepted followers — and, if you set your account to public, to any signed-in user: a rolling summary of your training (weekly volume, sessions, personal records and your best lifts for the standard barbell movements, and — only if you pin it to your profile yourself — your most recent body weight), and the activities you publish (completed workouts, personal records, streak milestones, programs you share, any photos you choose to publish, and any statistics charts you choose to post).

We screen handles, display names, bios and the captions of statistics posts automatically on your device before they are sent; that check is best-effort and can be circumvented. Photos you publish are screened on our servers by Google Cloud Vision before they appear, and a photo that fails is not published. Nothing else in the community is pre-screened, and the report and block tools are what we ask you to use when something is wrong.

We do not upload or match your phone contacts.

Finding Friends from Your Contacts

Contact matching is optional, is never started for you, and is separate from the rest of Community.

When you choose Allow access in the Find friends tab, GymLeap reads the names, email addresses and phone numbers in your device's address book. Nothing else is read — not photos, postal addresses, birthdays, notes or organisations.

Your address book is never uploaded and never stored. Each email address and phone number is turned on your device into an irreversible cryptographic hash, and only those hashes are sent to us. We compare them against our index and return only the accounts that match. The comparison keeps nothing, so running it again leaves no record of the first.

So that others can find you, we store a salted hash of your own verified email address and, only if you turn on phone matching, a salted hash of the phone number Google has verified for your account. We ask Google for that number with your explicit permission and never accept a number typed into the App, so nobody can claim a number that is not theirs. Your actual address and number are never stored, and the salt is held separately from the index so the stored hashes cannot be reversed.

Photos

Body-progress photos you take inside GymLeap are stored on your device and are never uploaded.

Posting to the community feed — a single photo with an optional caption, or a before/after pair of your progress photos — is a separate, explicit act you take one post at a time. It uploads the image or images to a public storage location, where anyone holding the link can fetch them, and shows them, with any caption, to the audience described above. Photo posting stays off until you turn on "Photos" in your Community settings. That setting only enables the action; it never publishes anything on its own, and there is no automatic photo sharing. Before a post appears, every image in it is screened on our servers by Google Cloud Vision, and a post that fails screening is not published and is not stored. Location and other information embedded in a photo file is removed before the photo is stored. Deleting the post removes the card and the uploaded images.

AI-Generated Program Covers

GymLeap PRO subscribers can optionally generate an AI cover image for a workout program. This feature is entirely optional and only runs when you choose to generate a cover.

When you use it, we send a short text description of the program to Google Cloud Vertex AI to create the image. That description is derived from the program's goal, its first exercise, and the age range and gender recorded in your profile. It does not include your name, email, photo, or any facial likeness — the generated athlete is a generic figure, not a depiction of you. Each generated image is automatically screened by Google Cloud Vision for unsafe content before it is saved; images that fail screening are discarded.

Cover images you generate are stored in your private cloud storage as part of the program. If you later publish that program to the community, its cover image becomes publicly visible, as described in "Community Programs and Public Sharing" above.

Exporting and Importing Your Data

You can export your complete workout history to a CSV file at any time from the App's settings. The file is created on your device and handed straight to your system's share sheet, so you decide where it goes. We never receive a copy of it, and exporting does not send anything to our servers.

You can also import a workout history from a file you choose — either a GymLeap export or an export from another fitness app, such as Hevy. Everything happens on your device: the file is read locally, exercise names are matched against the GymLeap exercise library on the device, and the resulting workouts are saved to your local storage. If you subscribe to GymLeap PRO, imported workouts then sync to your private cloud storage like any other workout. GymLeap is not affiliated with, endorsed by, or sponsored by any app you import from.

Data Retention and Deletion

Your workout data is stored locally on your device for as long as the App is installed. If you create an account, your account information and any cloud-synced data are retained until you delete them.

You can delete your account at any time from Settings → Account → Delete account inside the App. This permanently removes your sign-in account, your community profile and handle, every activity you published and every cheer you left, your followers and the people you follow on both sides, the members you have blocked, all cloud-synced workout, body-measurement and program data, any feedback or bug reports you submitted including attached screenshots, and the images you uploaded. It also clears the copies held on the device you delete from. Workout data on any other device you have used is removed when you uninstall the App there.

You can still request deletion by email at wovidev@gmail.com if you prefer; we process those requests within 30 days.

Two things survive a deletion, deliberately: reports you filed about other members, which we keep so they remain useful for handling abuse, and copies of programs other users downloaded before you deleted, which remain on their devices. Server backups roll off on their own schedule and are not used to restore deleted accounts.

Children's Privacy

GymLeap is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. The Community features are available only to users aged 18 or older: before you join, the App asks for your date of birth once. The date you enter there stays on your device — with your Community profile we store only a confirmation that you are 18 or older. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at wovidev@gmail.com so we can take appropriate action.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy within the App and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at wovidev@gmail.com.