Last updated: June 17, 2026
Snap My Gym ("we", "us") is an AI-assisted strength-training planner. This policy explains what data we collect, why, who we share it with, and the choices you have. We wrote it to mirror how the app actually behaves — if anything below is unclear, email support@snapmygym.com and we'll explain.
When you use Snap My Gym (the gym photo flow) or Import Workout (the screenshot flow), the images you choose are uploaded to our object storage and may be sent to our AI providers for processing (see "Third parties" below). You can delete uploaded photos any time from the relevant screen.
If you use Medical Notes, Labs / blood-work, or Body Composition, you can voluntarily upload your own medical records — which may include diagnoses, medications, vitals, lab values, and visit notes — plus the structured health summaries we derive from them. You supply this data yourself; we never receive it from a healthcare provider on your behalf, and we are not a HIPAA covered entity or business associate. Before any uploaded document is sent to a third-party AI provider for text extraction, we show an explicit, separate warning and record your versioned, timestamped consent; nothing is sent to AI until you accept. The structured summaries we store, and the AI memory derived from them, are envelope-encrypted at rest with AES-256-GCM. We do not use this data to train any AI model. This data is treated as "consumer health data" / "sensitive personal information" under the state laws described below.
If you choose to connect a wearable provider, you authorize it through that provider's own OAuth screen and we pull only the metrics you grant: recovery / readiness score, sleep, HRV, resting heart rate, strain, steps, active calories, and workout summaries. This data is shown only to you — it is never exposed to other users, leaderboards, or the community feed. The access and refresh tokens we store for each provider are encrypted at rest. Disconnecting a provider (Settings → Wearables) revokes our tokens and deletes every cached row for that provider in a single transaction.
If you grant the permission, the iOS app reads the following from Apple Health to tailor your training: completed workouts, steps, active energy, exercise time, heart rate / HRV, and body weight. With your permission, we also write the workouts you complete in the app back to Apple Health so your activity rings stay accurate.
Apple Health data stays on your device unless you log a workout. The aggregated metrics we use to scale your next session (e.g. "resting HR is elevated → suggest a deload") are derived on-device. The workouts we write back are written to Health under your account. You can revoke either permission at any time in iPhone Settings → Privacy → Health → Snap My Gym.
We do not sell your data. We do not use your workout data to train third-party AI models for advertising.
We share data with a small number of providers strictly to operate the service. Each one is bound by a data-processing agreement.
Each subprocessor is bound by a Data Processing Agreement (DPA) and may use your data only to provide its service to us. A current, itemized subprocessor register (data category, purpose, location, and DPA/BAA status) is available on request at support@snapmygym.com.
The medical, biometric, and wearable data described above is "consumer health data" under laws such as Washington's My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut Data Privacy Act, and "sensitive personal information" under California's CPRA. For residents of those and similar states: we process consumer health data only with your consent and only to provide the features you ask for; we never sell it or share it for cross-context behavioral advertising; we obtain separate opt-in consent before any health document is shared with our AI subprocessors; and you may request access to, deletion of, or a list of third parties we've shared it with, and may withdraw consent at any time. As MHMDA requires, we publish a separate Consumer Health Data Privacy Policy.
Account and workout data are retained while your account is active. Uploaded medical documents and the health summaries derived from them are retained until you delete the note or your account; the original file is not retained by our AI providers beyond the extraction request. AI audit logs (a record of which documents were processed and when) are retained up to 12 months for security and abuse investigation, then purged. Cached wearable data is capped per provider — Oura for up to 60 days and Whoop for up to 180 days — and a daily job purges anything older; disconnecting a provider deletes its cached rows immediately. Server and security logs are kept up to 30 days. When you delete your account, all personal and health data tied to your user id is purged within 30 days, with backup copies aging out within 90 days. Anonymized usage metrics (e.g. "X workouts logged today") may be retained for analytics.
If we discover a security incident that compromises your unsecured health or personal data, we will notify affected users and the relevant authorities without undue delay and in line with applicable law — including the FTC Health Breach Notification Rule, U.S. state breach-notification statutes, and, for EU/UK users, the GDPR 72-hour regulator-notification requirement. A reportable breach is any unauthorized acquisition of, or access to, identifiable health data that is not encrypted or otherwise rendered unusable.
Data is transmitted over TLS, sessions are signed and HttpOnly, and passwords (when used) are hashed with bcrypt. Wearable OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. No system is perfectly secure — if you suspect your account has been compromised, email support@snapmygym.com and we will investigate.
We and most of our subprocessors operate from the United States. If you use the app from the EU, UK, or another region with cross-border transfer rules, your data is transferred to and processed in the U.S. Where required, we rely on the EU Standard Contractual Clauses (and the UK Addendum) or a recipient's Data Privacy Framework certification to safeguard these transfers.
Snap My Gym is not directed at children under 13 (or under 16 in the EU/UK). We do not knowingly collect data — including health data — from anyone in those age ranges. If you believe a child has provided us data, contact us and we will delete it.
If we materially change this policy, we'll surface it inside the app and update the "Last updated" date above. Continued use after a change constitutes acceptance.
Questions, requests, or complaints: support@snapmygym.com.