SnapMyGym Back to app →

Privacy Policy

Last updated: June 17, 2026

Snap My Gym ("we", "us") is an AI-assisted strength-training planner. This policy explains what data we collect, why, who we share it with, and the choices you have. We wrote it to mirror how the app actually behaves — if anything below is unclear, email support@snapmygym.com and we'll explain.

1. Information we collect

Account information

  • Sign-in identifiers. When you sign in with Apple, Google, or email + password, we receive your email address and (if you share it) display name and profile photo. Apple's "Hide my email" relay address is supported.
  • Profile settings. Optional fields you enter yourself: preferred units (lbs / kg), height (used for bodyweight-adjusted leaderboards), and your training goals.

Workout and training data

  • Sets, reps, weights, RPE, rest times, and notes you log.
  • Programs you generate, activate, or import; the exercises and schedules within them.
  • Personal records and progress metrics derived from the above.
  • Optional bodyweight check-ins and journal entries.

Photos

When you use Snap My Gym (the gym photo flow) or Import Workout (the screenshot flow), the images you choose are uploaded to our object storage and may be sent to our AI providers for processing (see "Third parties" below). You can delete uploaded photos any time from the relevant screen.

Health and medical documents you upload

If you use Medical Notes, Labs / blood-work, or Body Composition, you can voluntarily upload your own medical records — which may include diagnoses, medications, vitals, lab values, and visit notes — plus the structured health summaries we derive from them. You supply this data yourself; we never receive it from a healthcare provider on your behalf, and we are not a HIPAA covered entity or business associate. Before any uploaded document is sent to a third-party AI provider for text extraction, we show an explicit, separate warning and record your versioned, timestamped consent; nothing is sent to AI until you accept. The structured summaries we store, and the AI memory derived from them, are envelope-encrypted at rest with AES-256-GCM. We do not use this data to train any AI model. This data is treated as "consumer health data" / "sensitive personal information" under the state laws described below.

Connected wearables (Whoop, Oura, Strava, Garmin)

If you choose to connect a wearable provider, you authorize it through that provider's own OAuth screen and we pull only the metrics you grant: recovery / readiness score, sleep, HRV, resting heart rate, strain, steps, active calories, and workout summaries. This data is shown only to you — it is never exposed to other users, leaderboards, or the community feed. The access and refresh tokens we store for each provider are encrypted at rest. Disconnecting a provider (Settings → Wearables) revokes our tokens and deletes every cached row for that provider in a single transaction.

Apple Health data (iOS only)

If you grant the permission, the iOS app reads the following from Apple Health to tailor your training: completed workouts, steps, active energy, exercise time, heart rate / HRV, and body weight. With your permission, we also write the workouts you complete in the app back to Apple Health so your activity rings stay accurate.

Apple Health data stays on your device unless you log a workout. The aggregated metrics we use to scale your next session (e.g. "resting HR is elevated → suggest a deload") are derived on-device. The workouts we write back are written to Health under your account. You can revoke either permission at any time in iPhone Settings → Privacy → Health → Snap My Gym.

Payments

  • Web. Stripe processes your card. We receive your subscription tier and billing status; we never see your full card number.
  • iOS. Apple In-App Purchase processes the transaction entirely. We receive a signed transaction receipt that tells us your tier and renewal date; we never see your Apple ID or payment method.

Technical data

  • Authentication session cookies (so you stay signed in across visits).
  • Server logs (IP address, user-agent, request path) retained for up to 30 days for security and abuse prevention.
  • Crash and error reports sent to Sentry — these contain stack traces and the request path that failed, but PII (email, display name, raw input) is stripped before sending.

2. How we use your data

  • Run the service: render your programs, save your workouts, sync across your devices.
  • Generate AI features you opted into: program suggestions, equipment detection from photos, weekly insight summaries.
  • Compute progress metrics, personal records, and (if you enable Friends) leaderboard placement.
  • Email you transactional messages — receipts, password resets, account warnings. We do not send marketing emails unless you opt in.
  • Investigate security incidents and fix bugs from crash reports.

We do not sell your data. We do not use your workout data to train third-party AI models for advertising.

3. Third parties

We share data with a small number of providers strictly to operate the service. Each one is bound by a data-processing agreement.

  • Anthropic and OpenAI — when you trigger an AI feature, the minimum text or image required for that feature is sent to one of these providers for inference. Health documents you upload are sent only to Anthropic (for one-time extraction, only after your separate consent) — they are never sent to OpenAI. OpenAI is used only for non-health AI features. Your own connected-wearable metrics (e.g. recovery, sleep, HRV) are sent only to Anthropic when relevant to a coaching or journal insight you triggered. Both providers are on a no-training / zero-retention API posture and contractually do not train on or retain your data beyond the request. Strava-sourced activity is never sent to any AI model, per Strava's API Agreement.
  • Google Cloud Storage — stores files you upload (photos and health documents).
  • Apple — Sign in with Apple and In-App Purchase. Apple's own privacy policy applies to those flows.
  • Google — Sign in with Google (if you choose it). Google's privacy policy applies.
  • Stripe — web payments. Stripe's privacy policy applies.
  • Sentry — error reporting with PII stripped.
  • Our hosting / database provider (Replit and the PostgreSQL it manages) — stores the workout, account, and health data described above.

Each subprocessor is bound by a Data Processing Agreement (DPA) and may use your data only to provide its service to us. A current, itemized subprocessor register (data category, purpose, location, and DPA/BAA status) is available on request at support@snapmygym.com.

4. Your rights and choices

  • Access & export. Email us and we will send you a copy of the data on your account within 30 days.
  • Delete. You can delete your account from Settings → Account → Delete account. Deletion is soft (recoverable for 30 days) and then permanent; backups age out within 90 days.
  • Revoke iOS permissions. Camera, Photos, and Health each have a dedicated toggle in iPhone Settings under the Snap My Gym entry.
  • EU / UK residents (GDPR). You also have the right to object to processing, restrict processing, lodge a complaint with your supervisory authority, and to data portability.
  • California residents (CCPA). You have the right to know what data we collect, to delete it, and to non-discrimination for exercising these rights. We do not sell personal information.

5. Consumer health data & U.S. state privacy laws

The medical, biometric, and wearable data described above is "consumer health data" under laws such as Washington's My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut Data Privacy Act, and "sensitive personal information" under California's CPRA. For residents of those and similar states: we process consumer health data only with your consent and only to provide the features you ask for; we never sell it or share it for cross-context behavioral advertising; we obtain separate opt-in consent before any health document is shared with our AI subprocessors; and you may request access to, deletion of, or a list of third parties we've shared it with, and may withdraw consent at any time. As MHMDA requires, we publish a separate Consumer Health Data Privacy Policy.

6. Data retention

Account and workout data are retained while your account is active. Uploaded medical documents and the health summaries derived from them are retained until you delete the note or your account; the original file is not retained by our AI providers beyond the extraction request. AI audit logs (a record of which documents were processed and when) are retained up to 12 months for security and abuse investigation, then purged. Cached wearable data is capped per provider — Oura for up to 60 days and Whoop for up to 180 days — and a daily job purges anything older; disconnecting a provider deletes its cached rows immediately. Server and security logs are kept up to 30 days. When you delete your account, all personal and health data tied to your user id is purged within 30 days, with backup copies aging out within 90 days. Anonymized usage metrics (e.g. "X workouts logged today") may be retained for analytics.

7. Data breach notification

If we discover a security incident that compromises your unsecured health or personal data, we will notify affected users and the relevant authorities without undue delay and in line with applicable law — including the FTC Health Breach Notification Rule, U.S. state breach-notification statutes, and, for EU/UK users, the GDPR 72-hour regulator-notification requirement. A reportable breach is any unauthorized acquisition of, or access to, identifiable health data that is not encrypted or otherwise rendered unusable.

8. Security

Data is transmitted over TLS, sessions are signed and HttpOnly, and passwords (when used) are hashed with bcrypt. Wearable OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. No system is perfectly secure — if you suspect your account has been compromised, email support@snapmygym.com and we will investigate.

9. International data transfers

We and most of our subprocessors operate from the United States. If you use the app from the EU, UK, or another region with cross-border transfer rules, your data is transferred to and processed in the U.S. Where required, we rely on the EU Standard Contractual Clauses (and the UK Addendum) or a recipient's Data Privacy Framework certification to safeguard these transfers.

10. Children

Snap My Gym is not directed at children under 13 (or under 16 in the EU/UK). We do not knowingly collect data — including health data — from anyone in those age ranges. If you believe a child has provided us data, contact us and we will delete it.

11. Changes

If we materially change this policy, we'll surface it inside the app and update the "Last updated" date above. Continued use after a change constitutes acceptance.

12. Contact

Questions, requests, or complaints: support@snapmygym.com.

Snap My Gym Privacy Terms Support © 2026 Snap My Gym