Privacy Policy
Last updated: September 9, 2026
The redesigned social profiles, session posts, uploaded social photos and live camera-counted competitions described here are available from GymWars 2.0.0. Earlier versions may not include these features.
You choose what to share. A completed workout stays in your training history unless you choose to publish it. Shared workouts, photos, comments and competitions use our backend. The competition camera counts repetitions on your phone; its footage is not uploaded or shown to opponents. Google ML Kit sends separate diagnostic and usage information. This policy also explains our existing analytics, subscription and advertising services.
1. Information we collect
This policy covers the GymWars app and its account, training, social and competition services.
- Account and profile information: your account identifier, email address, sign-in provider, username, display name and any country, bio, social handles or profile image you choose to provide.
- Training information: workout sessions, exercises, sets, weights, repetitions, time, effort ratings (RPE), notes, personal records, training preferences and body measurements you enter. We use this information for workout history, progress, ranks and character features.
- Shared activity: the completed workout snapshot you choose to publish, its audience, optional caption and photo, Respect reactions, comments, friendships, friend requests and blocks. A shared snapshot includes its session statistics, exercises and sets.
- Competition information: invitations, participants, readiness, match timing, repetition scores, completion or cancellation state, results, records, streaks and cosmetic crown status.
- Service information: push notification tokens and preferences, support messages, reports, moderation decisions, purchase and subscription status, and technical records needed to operate and secure the service.
- Diagnostics and measurement: app and device information, identifiers, product interactions, performance measurements and crash reports, described below.
3. Photos, avatars and the competition camera
Photos you choose to upload
You can select a workout photo or a profile photo, or use the app's character artwork. Uploaded social photos are stored in private Supabase storage and are served only after access checks. Photos submitted for sharing are held for moderation before being shown to other people. Photos attached only to an Only me post are not placed in the routine photo-review queue.
If you edit a personal avatar, we may store an editing source image accessible only to your account and the finished avatar that eligible viewers can see. Character stickers are positioned by you. They do not use face recognition or establish your identity.
Live repetition counting
Camera permission is used when you set up a camera-counted competition. Camera frames and temporary pose landmarks are processed on your device to estimate repetitions. GymWars does not record or upload the competition footage or pose landmarks, stream your camera to an opponent, or capture microphone audio. The repetition score and match state are sent to our backend to run the competition.
Google ML Kit performs pose detection on the device. Separately, its SDK sends Google device and app information, installation identifiers, configuration, performance measurements and error or usage events for diagnostics and usage analytics. Android pose detection also uses Firebase installation and remote-configuration services. These SDK diagnostics are distinct from your camera footage. See Google's disclosures for iOS and Android.
You can deny or revoke camera and photo permissions in your device settings. Camera-counted competitions need camera access; you can use the training log without entering one.
4. How we use and share information
We use your information to provide account access and syncing; keep training history and calculate progress; display content to its permitted audience; connect friends; run competitions; deliver notifications; manage subscriptions; answer support requests; and detect or address abuse, security issues and technical failures.
Authorized moderators can access submitted social photos and reported content when needed to review it against our Community Guidelines. Reports and moderation records are not public. A post that was shared and reported can remain available to an authorized reviewer for the investigation even if its author later changes its audience to Only me. The identity of a reporter is not displayed to the reported person.
- Supabase: account authentication, databases, private media storage and backend services.
- RevenueCat: purchase validation, subscription status, entitlement management and the advertising measurement integration described in section 6.
- Apple and Google: sign-in when selected, store payments, and notification delivery through platform services.
- Firebase (Google): product analytics, crash reporting and push notification services.
- Google ML Kit: local pose detection and the SDK diagnostics described in section 3.
- Meta Platforms: advertising measurement as described in section 6.
Service providers may process data in countries other than your own. We restrict access through account permissions and use encrypted connections for data sent to the service. No system can guarantee absolute security.
We do not sell your personal data. We may disclose information when required by law or when necessary to investigate abuse, protect people or defend legal rights. Content you choose to share is disclosed to the audience you select.
5. Product analytics and diagnostics
Firebase analytics and crash reporting are enabled in release builds. They collect app interactions, onboarding and feature-use events, device and app information, performance data and error reports. When you are signed in, we associate these records with your GymWars account identifier so we can understand and resolve account-specific problems. They are not described as anonymous.
ML Kit collects its own SDK diagnostics when used, as explained in section 3. Your camera footage is not included in these diagnostics by GymWars.
Contact us if you want to ask about your diagnostic records or exercise an applicable privacy right. Your device's advertising-tracking control governs advertising permission; it is separate from the operational analytics described here.
6. Advertising and measurement
We advertise GymWars on Meta's platforms, including Facebook and Instagram. Where advertising measurement is enabled, we use limited information to understand which advertising leads to installs and subscriptions:
- Hashed email: for a signed-in account, the Meta SDK can hash the email address for matching with information Meta already holds. A hash is a matching identifier, not anonymous data. Apple Hide My Email relay addresses are excluded from this matching.
- Device and advertising identifiers: identifiers and install or app-use events used for attribution. Access to the iOS advertising identifier requires App Tracking Transparency permission.
- Subscription events: trial, purchase and renewal events, together with the amount paid, can be sent through RevenueCat's server integration.
We do not send your workout history, body measurements, ranks, friends, social photos, captions, comments, camera footage or competition scores to Meta for advertising.
Your controls
From GymWars 2.0.0, the iOS app enables the Meta integration only after App Tracking Transparency authorization and a separate region eligibility check. Without authorization, it does not initialize the Meta SDK or send new Meta activation events, matching email or attribution identifiers. You can manage permission in Settings → Privacy & Security → Tracking. The app checks again when it returns to the foreground and stops further Meta event calls if authorization was revoked.
Server-side subscription measurement is a separate integration. Our RevenueCat integration now requires authorized ATT consent for iOS subscription events sent to Meta, using the consent status most recently received from the app. Records sent by earlier versions or before a permission change are not automatically erased. A permission change made while the app is closed reaches our subscription provider when the app next communicates with it. Contact ultasdevelopment@gmail.com to ask us to stop advertising measurement associated with your account or request deletion of related records.
Regional and platform restrictions
GymWars disables the device Meta app-events integration when the device region or time zone indicates the European Economic Area, United Kingdom or Switzerland, and does not request tracking permission in those regions. This check does not use GPS location. From version 2.0.0 the Android app does not include the Meta SDK.
The regional device control does not retroactively erase attribution records already held by a provider. For example, a previously attributed account moving into an excluded region can still have server-side subscription events matched using previously saved identifiers while the provider records authorized consent. Contact us to request that existing account-level measurement stop. Regional controls do not disable the account, payment or diagnostic services needed by the app.
7. Retention and deletion
We keep account and training data while it is needed to provide your account and features. You can delete your account in the app's settings, or contact us if you cannot access it. Account deletion removes associated account, workout and social data from the active service; any remaining deletion work is normally completed within 30 days, except records we must retain for a legal obligation or a specific unresolved safety or security issue.
- Deleted posts and comments: access is removed and the deleted caption, comment text and shared workout snapshot are cleared from active records. A minimal technical record may remain to prevent duplicate session posts and maintain references; it does not preserve the deleted photo, caption or workout snapshot. Deleting a shared post does not delete the original workout from your private training history.
- Social photos: deleted or replaced photos are queued for permanent removal. Removal normally completes within 24 hours; service outages can delay cleanup and failed deletions are retried. Uploads that are abandoned before being attached to a post or profile are eligible for cleanup after 24 hours.
- Reports and moderation: pending reports are accessible only to authorized personnel. When a report is resolved, its text and links to the people and content involved are removed. A nonidentifying audit of action types and counts is retained for 90 days after resolution. Photo approval records remain while an approved photo is in use. Personal photo-review metadata is removed after the associated file is erased, normally within the same 24-hour cleanup period. An appeal should include the relevant context because we do not keep a personal copy of a resolved report for that purpose.
- Backups and technical logs: residual copies can remain in restricted backups until normal backup rotation, and records needed to secure or restore the service may outlast removal from the live app. They are not used to keep deleted content visible in the feed.
Deleting an account does not automatically cancel an App Store or Google Play subscription. Manage the subscription with the store. We do not control copies that another user saved outside GymWars or records a payment provider must keep.
8. Your choices and privacy requests
You can edit your profile, remove optional social handles, choose the audience for shared activity, change profile visibility, block people and manage notification or device permissions. You can also request access, correction or deletion of your information by contacting us. Other rights, including objection, restriction or portability, may apply under the laws where you live. We may ask for information needed to verify that a request relates to your account.
We do not use the competition camera for identifying people or create a facial-recognition profile. Do not upload someone else's personal information without their permission. If you believe a child or another person has provided information without appropriate permission, contact us so we can investigate.
9. Subscriptions and payments
Apple or Google processes payment details. GymWars does not receive your full payment-card number. RevenueCat and GymWars receive purchase, subscription and entitlement information needed to manage premium access and restore purchases.
10. Contact and policy changes
GymWars is operated by UltasDev, a trade name of YUSUF EMİR ULUTAŞ, a sole proprietorship. For a privacy request, email ultasdevelopment@gmail.com. Include your GymWars username and the request; do not send your password or payment-card details.
We will update this page when our practices change and revise the date above. The GymWars Support page explains reporting, blocking and account deletion.