Privacy Policy
How we collect, use and protect your personal data under the GDPR and Greek law.
Last updated: 25 June 2026
This Privacy Policy explains how Breukers Willem Albertus E.E. ("we", "us") collects and processes your personal data when you use the GymGate website and mobile application, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Greek Law 4624/2019.
1. Data controller
Breukers Willem Albertus E.E.Valaoritou 1, TK 10671, Athens, Greece
GEMI: 186520701000 · VAT: 802973201
Email: [email protected]
2. What data we collect
- Account & authentication: your email address and name. If you sign in with Apple or Google, we receive a unique identifier and your email from that provider (with Apple, this may be a private relay address); from Google we also receive your name and profile photo. For email sign-ups we store only a hashed version of your password, never the password itself.
- Profile: your username (handle), display name, weekly training goal, chosen character, and how you heard about us.
- Fitness & activity data: the workout sessions you log, such as split type, duration, exercises, sets, reps and weights, plus derived stats such as streaks, weekly points and personal records, and any training schedule and gym you set. Depending on context this may relate to your health, so we treat it with particular care (see §3).
- Session focus telemetry: to power your stats and the leaderboard, each session records signals such as how long you trained, how much of that time your phone stayed locked away, how many times you unlocked, and how many apps you had locked. These are counts and durations only, not a record of which apps you used.
- Location data (including background/precise): if you enable the home-zone feature, we use your device's location to set your home zone and to detect when you leave for the gym. We store the home zone you set (its coordinates and, where available, a derived address) and may record the location where you finish a session to help detect your gym. If you turn on automatic locking, the app monitors a geofence around your home in the background; the live coordinates used for this are processed only as needed and not otherwise retained. You can disable location access at any time in your device settings.
- App-locking selections: you choose which apps to lock, and how this is stored depends on your platform. On iOS, locking uses Apple's Family Controls (Screen Time) system picker: your selections are opaque tokens held on your device and within Apple's framework, so we never receive or store the identities of the apps you pick — only a count of how many you selected. On Android, there is no equivalent system picker, so the app shows your installed apps and stores the package names you choose to lock in your account settings, in order to apply the block. On both platforms the block is enforced entirely on your device, and we never collect your app-usage history or which apps you actually open.
- Push notification tokens: if you allow notifications, we store your device's push token and platform so we can send the reminders and social alerts you opted into.
- Social data: your friend connections and friend requests. Your username, character and leaderboard score are visible to other users on shared leaderboards.
- Payment data: for Pro subscriptions and the lifetime offer, your email, subscription/purchase status, transaction identifiers, amounts and the Stripe customer/subscription IDs. Card details are entered directly on Stripe's secure checkout and are never seen or stored by us.
- Technical data: IP address, device and app version information, and server logs, including anti-abuse signals from Cloudflare Turnstile on the website.
- Waitlist (website only): if you join the waitlist, your email address and your position in the queue.
- Cookies (website only): see our Cookie Policy.
3. Why we use it and our legal bases
- To provide your account and the core service (sign-in, sessions, leaderboards, friends, schedule, gym): performance of a contract (Art. 6(1)(b) GDPR).
- To record your fitness & activity data: your consent (Art. 6(1)(a)), and, to the extent it constitutes health data, your explicit consent (Art. 9(2)(a) GDPR). You provide this data voluntarily and can delete it at any time.
- To run the home-zone and background app-locking: your consent (Art. 6(1)(a)), which you can withdraw by disabling location or auto-lock at any time.
- To send push notifications: your consent (Art. 6(1)(a)), withdrawable in the app or your device settings.
- To process payments and keep tax/accounting records: performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)).
- To secure the service and prevent fraud and abuse: our legitimate interests (Art. 6(1)(f)).
4. Recipients and processors
We share data only with service providers acting as processors on our instructions, under data-processing agreements:
- Stripe: payment processing and subscription billing.
- Apple & Google: native sign-in and app distribution; Apple additionally provides the on-device Screen Time framework.
- Vercel: application hosting and delivery.
- Expo: delivery of push notifications.
- Resend: transactional and account emails.
- Gym location lookup: when you search for your gym, the query is sent to a mapping provider (komoot Photon, or Google Maps Platform where configured) to return matching places.
- Cloudflare: Turnstile bot protection on the website.
Your account and fitness data are stored in a MongoDB database we operate ourselves. Session caching and rate limiting use Redis on the same self-hosted infrastructure. These systems are operated directly by us, not by third-party database or cache providers.
5. International transfers
Some providers process data outside the European Economic Area (e.g. in the United States). Where that is the case, transfers are safeguarded by an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or by the European Commission's Standard Contractual Clauses with supplementary measures, providing a level of protection essentially equivalent to that within the EU.
6. Retention
We keep your account, profile and fitness data for as long as your account exists. When you delete your account in the app, your personal data is deleted, except records we must keep by law. Purchase and invoicing records are retained for as long as required by Greek tax law (generally up to ten years). Your saved home zone and session locations are kept with your account and sessions until you delete them or your account; the live coordinates used for background geofencing are processed transiently and not otherwise retained. Technical logs are kept only as long as needed for security.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy;
- have inaccurate data rectified;
- have your data erased. You can delete your account and all associated data directly in the app (Profile → Delete account);
- restrict or object to processing;
- data portability;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these rights, contact us at [email protected].
8. Right to complain
You may lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece. Website: www.dpa.gr. You may also complain to the supervisory authority in your EU country of residence.
9. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Leaderboard rankings are a simple ordering of activity and have no such effect.
10. Security
We apply appropriate technical and organisational measures, including encryption in transit, hashed passwords, scoped access tokens and access controls. No method of transmission over the internet is completely secure, however, and we cannot guarantee absolute security.
11. Children
GymGate is not directed at children. In Greece, information society services may be offered to minors aged 15 or over on the basis of their consent; for younger children, consent must be given by the holder of parental responsibility.
12. Changes
We may update this Privacy Policy from time to time. The effective date above reflects the latest version, and material changes will be communicated where appropriate.