Privacy Policy

Updated 2026-10-08

Draft for the beta, written from how the software handles data. It has not yet been reviewed by a lawyer.

Who is responsible

Each gym decides how it uses its members’ data and is responsible for it. [TwoQM legal entity name] runs GymOS and processes that data on the gym’s behalf. For gym owners’ and staff accounts, we are responsible. Contact: [privacy email].

What we collect

Account details: name, email, phone, language, and a password stored only as a salted hash. Optional two-factor secrets are encrypted.

Gym records: memberships, bookings, check-in times and locations, signed agreements (with the exact text and time), payments and refunds (card details stay with Stripe), messages with gym staff.

Members under 18: birthdate and the guardian who manages the account.

Fitness data a member chooses to log: workouts, measurements, goals and progress photos. This is private by default; a trainer sees it only if the member grants access, and the member can revoke it.

Staff: time punches and, only if the gym enables it, a one-time location check at clock-in. Location is never tracked continuously.

Technical data: IP address and browser/device type for sign-in sessions, security logs and consent records.

How it is used

To run the gym’s services (memberships, bookings, check-in, billing, notifications), to keep accounts secure, and to meet legal and accounting duties. We do not sell personal data or use it for advertising.

Who we share it with

Service providers that run parts of GymOS: Stripe (payments, for gyms that connect it), an email provider, Expo/Apple/Google (push notifications), Twilio (SMS, if the gym enables it) and our hosting and storage providers. [List of providers and locations to be completed.]

How long we keep it

While the gym’s account is active, plus what the gym configures (for example, check-in and message history). Security and operations logs are deleted after 90 days; backups are kept 35 days. Financial and signed-agreement records are kept as the law requires.

Your choices and rights

Members can download their data and ask to delete their fitness data or their account from their account settings, or ask their gym. Gyms can export all their data. [Rights under applicable law, such as access, correction and objection, and how to complain to a regulator, to be completed by counsel.]

Security

Each gym’s data is isolated in the database, connections use TLS, passwords are hashed, sensitive secrets are encrypted, staff permissions are role-based, and sensitive actions are audited.

Changes

We will post updates here and tell gyms about material changes in advance.

Terms · Privacy