Who – Gym Partner Train better, together
Privacy - Who – Gym Partner

Privacy Policy

Last updated: August 2026

Who – Gym Partner is a local fitness coordination app. It helps you discover training venues, see the activities each one offers, plan or join workout sessions, and coordinate with confirmed training partners. This policy explains exactly what we process, what stays on your device, which service providers we use, and how you stay in control.

1. Introduction

Who – Gym Partner ("the App", "we", "our") is a mobile application for coordinating workouts. You browse fitness venues near you, look at the activities available at each one, join or create a workout session tied to a specific venue, activity, date and time, send a request to join, and — only after that request is accepted — coordinate privately with the other participant.

We designed the App so that the information it needs is minimal and, wherever possible, never leaves your device. Your training profile, saved places, sessions, requests and messages are stored locally. A small, clearly listed set of technical data is processed by service providers for crash reporting, analytics, push notifications and install attribution.

This policy applies to the Who – Gym Partner iOS application and the pages hosted alongside it.

2. Who Is Responsible

The publisher of Who – Gym Partner is the data controller for the processing described in this policy. For any privacy question, request or complaint, contact privacy@whogympartner.app. General questions can go to support@whogympartner.app.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

3. Data Stored On Your Device

The following is created by you inside the App and stored locally using iOS UserDefaults and the app sandbox. It is not uploaded to us:

  • Training profile: your first name, city and neighbourhood, short fitness introduction, and an optional profile photo.
  • Training interests: the activities you selected and the experience level you assigned to each one.
  • Training preferences: preferred session duration and intensity, group size, structured or flexible sessions, indoor or outdoor, training days, times of day, and maximum travel distance.
  • Goals: the goals you chose during onboarding or in your profile, such as improving consistency or preparing for an event.
  • Saved places: the venues you bookmarked.
  • Session activity: sessions you created or joined, your training calendar, and completed session history.
  • Join requests: requests you sent, requests you received, and whether you accepted or declined them.
  • Conversations: the messages exchanged with confirmed training partners.
  • Post-session check-ins: your private answers about whether a session took place, whether the information was accurate, whether you would train with the participant again, and whether there was a safety issue.
  • Trust and safety records: users you blocked and reports you filed.
  • App state: onboarding completion, community commitment acceptance, and interface preferences.

Deleting your account inside the App, or deleting the App itself, removes this data permanently from your device. We cannot restore it, because we never held a copy.

Profile stays on device No account server In-app deletion No data sale

4. Data Processed By Service Providers

To keep the App stable, understand how it is used, deliver notifications and measure which campaign an install came from, we use a small number of established providers. They act as processors on our behalf and receive technical data — never your training profile, your messages or your session content.

ProviderPurposeTypical data
Google Firebase Analytics Aggregate product analytics — which screens are opened, how features are used App instance identifier, device model, OS version, country, coarse event data
Google Firebase Crashlytics Crash and stability diagnostics Crash stack traces, device model, OS version, app version, installation identifier
Google Firebase Cloud Messaging Delivering push notifications Push registration token, device and OS version
Adjust Install and campaign attribution, fraud prevention Adjust device ID, IDFV, IDFA (only with your ATT permission), attribution parameters, app version
Apple App distribution, push delivery, App Tracking Transparency APNs token, standard App Store and system-level data

We do not sell personal information, and we do not share it with data brokers or advertising exchanges.

5. Location Data

Location is used for one purpose: showing which fitness venues and workout sessions are near you, and sorting them by distance.

  • Permission is optional. The App asks for "When In Use" location only, and only at the point where it is useful.
  • A manual alternative always exists. If you decline, or later revoke, location access, you pick a city and neighbourhood yourself. Every feature continues to work.
  • No background tracking. The App does not request "Always" location, does not track your movement, and does not build a location history.
  • Not transmitted. Your coordinates are used on the device to sort and filter venues. We do not upload your location to a server, and we do not share it with other users.
  • Never shared with participants. Other athletes see the venue of a session, never your position.

6. Camera, Microphone & Photos

The App may request these device permissions. Each is optional, each is used for a single stated purpose, and each can be revoked at any time from iOS Settings.

  • Camera: used for your own video preview during a one-to-one call with a confirmed training partner, and to take a profile photo. Nothing is recorded.
  • Microphone: used for one-to-one calls with a confirmed training partner. Audio is never recorded or stored.
  • Photo Library: used only to let you pick a profile photo. The photo you select is stored locally on your device and is not uploaded to us.

Denying a permission disables only the related feature. Venue discovery, sessions, requests and messaging all continue to work.

7. Sessions, Requests & Messages

Coordination in the App follows a deliberate order, and that order is also a privacy control:

  • Sessions are public within the App. A session you create shows its title, venue, activity, date, time, level, intensity, participant count and your first name. It never shows your contact details or your home location.
  • Requests come before contact. To join a session you send a request containing a short introduction and, optionally, your relevant experience. The organiser sees only that request and your training profile.
  • Messaging is gated. A conversation is created only when a join request is accepted, or when both people are confirmed participants in the same session. Nobody can message you out of the blue, and there is no way to start a conversation from a profile or from the Messages tab.
  • Messages are for coordination. Conversations are attached to a specific session and carry that context at the top of the thread.
  • Blocking cuts contact immediately. Blocking someone hides the conversation, prevents further contact and cancels pending requests in both directions.

In this release the session, participant and conversation content is simulated locally on your device for demonstration purposes and is not transmitted to a server.

8. One-to-One Calls

Calls are available only inside an existing conversation, which means only with someone whose join request you accepted or who accepted yours. There is no random calling and no way to be called by a stranger.

Calls are not recorded. No audio or video from a call is stored on your device or sent to us. Ending a call writes a short entry into the conversation — for example "Video call — No answer." — so both people can see what happened.

9. Advertising ID & App Tracking Transparency

On first launch iOS shows the App Tracking Transparency prompt. Your answer decides whether the advertising identifier (IDFA) can be read:

  • If you allow it: the IDFA may be shared with Adjust so an install can be attributed to the campaign it came from.
  • If you decline: no IDFA is read or shared. Attribution then relies only on non-personal, aggregate signals, and every feature of the App still works.
  • You can change your mind at any time in Settings > Privacy & Security > Tracking.

We do not display third-party advertising inside the App, and we do not build advertising profiles about you.

10. Push Notifications

With your permission, the App sends notifications about your own coordination activity — a session starting soon, a session tomorrow, a join request accepted, a session updated or cancelled. To do that, Apple and Firebase Cloud Messaging issue a push token tied to your app installation.

Notification permission is optional and can be withdrawn at any time in iOS Settings. Revoking it stops the notifications; nothing else changes.

11. What We Never Collect

Who – Gym Partner is a fitness coordination utility, not a dating or social discovery service. The App has no field, screen or database column for the following, and we never ask for them:

  • Relationship status, marital status or "looking for" preferences
  • Sexual orientation or romantic intent
  • Gender-based discovery or gender preference filters
  • Appearance ratings, attractiveness scores, likes received or popularity metrics
  • Health, medical or biometric records, injury history or diagnostic data
  • Your contacts, calendar, call history, SMS or browsing history
  • Precise background location or movement history
  • Payment card details — the App has no in-app purchases
Not a dating app No profile swiping No random matching No unsolicited messages

12. Legal Bases For Processing

Where the GDPR or comparable law applies, we rely on the following bases:

  • Performance of a contract: providing the coordination features you asked for — venue discovery, sessions, join requests and messaging.
  • Consent: location access, camera, microphone, photo library, push notifications and tracking (ATT). Each is asked for separately and each can be withdrawn without losing access to the App.
  • Legitimate interests: keeping the App stable and secure, diagnosing crashes, understanding aggregate feature usage, preventing abuse and fraud, and reviewing reports of misconduct — balanced against your rights and limited to what is necessary.
  • Legal obligation: responding to lawful requests and meeting our record-keeping duties.

13. How Long We Keep Data

  • On-device data is kept until you delete it in the App, use in-app account deletion, or uninstall the App. There is no server copy with its own lifetime.
  • Crash reports are retained by Crashlytics for up to 90 days.
  • Analytics events are retained in aggregate form for up to 14 months.
  • Attribution data is retained by Adjust for the period required to measure and validate a campaign, and no longer than 24 months.
  • Push tokens are discarded once they become invalid or when you revoke notification permission.
  • Reports of misconduct may be retained for as long as needed to review them and to keep the community safe.

14. Sharing & Disclosure

We share personal data only in these situations:

  • With the processors listed in section 4, limited to the technical data described there and bound by contract to use it only on our instructions.
  • With other users, only what you choose to publish: your first name, area, fitness introduction, training interests and levels, availability, participation signals, and the content of sessions and messages you send.
  • Where the law requires it, or to establish, exercise or defend legal claims.
  • To protect people, where disclosure is necessary to prevent serious harm or to respond to a credible safety concern.
  • In a corporate transaction, if the App is transferred to another entity, in which case this policy continues to apply until you are notified of any change.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

15. International Transfers

Our processors operate globally, so the limited technical data described in section 4 may be processed outside your country, including in the United States. Where that happens for users in the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses or another approved safeguard. Your training profile, sessions and messages are not transferred, because they stay on your device.

16. Security

Data stored by the App sits inside the iOS application sandbox and benefits from device-level encryption when your device is locked with a passcode, Face ID or Touch ID. Network requests made by the App use HTTPS. Our processors maintain their own technical and organisational security measures.

No system is perfectly secure. Keep your device locked and updated, and do not share personal contact details with someone you have not yet trained with.

17. Your Rights & Choices

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. Because your profile and coordination data live on your device, most of these you can exercise instantly and without asking us:

  • Access and correct: open Profile > Edit to see and change everything stored about you.
  • Delete: Profile > Trust and Safety > Delete Account removes your profile, saved places, sessions, conversations, blocks and reports from the device. Uninstalling the App has the same effect.
  • Withdraw consent: revoke location, camera, microphone, photo library, notification or tracking permission at any time in iOS Settings.
  • Object or restrict: write to privacy@whogympartner.app and we will act on requests relating to analytics, crash reporting or attribution.
  • Control contact: block or report any user from a conversation or profile; blocking cancels pending requests in both directions.

We answer verified requests within 30 days and never charge for them. We will not discriminate against you for exercising a privacy right.

18. Children's Privacy

Who – Gym Partner is not intended for children. You must be at least 16 years old to use the App, and if you are under 18 you should use it only with the knowledge and consent of a parent or guardian. We do not knowingly collect personal information from children under 16. If you believe a child has used the App, contact privacy@whogympartner.app and we will delete the associated data.

19. Changes to this Policy

We may update this policy as the App evolves or as legal requirements change. When we do, we update the "Last updated" date at the top, and we describe material changes inside the App before they take effect. Two commitments will not change: your training profile and conversations stay on your device, and we will never turn this into a dating product.

20. Contact

Privacy questions, data requests and complaints:

privacy@whogympartner.app

General help and safety concerns:

support@whogympartner.app

We aim to respond to safety reports within 48 hours and to privacy requests within 30 days.