Privacy Policy
Last updated: May 3, 2026
1. Introduction
Gainlog (the “app”) is operated by Diego Soro, an individual developer based in Spain (the “developer”, “we”, “us” or “our”). This Privacy Policy describes how we collect, use, and protect personal information when you use the Gainlog mobile application on iOS and Android.
This policy applies to all users of the Gainlog mobile app. By using the app, you agree to the practices described below.
If you have any questions about this policy or your data, you can contact us at support@gainlog.org.
2. Information We Collect
2.1 Account Information (via Clerk)
When you create an account, our authentication provider (Clerk) collects:
- Email address
- First name and last name
- Profile photo (if you sign in via Apple or Google)
- A generated username
2.2 Workout & Activity Data
While using Gainlog, you may create or upload:
- Workouts logged in the app, including gym sessions with sets, reps and weight, as well as runs, rides, swims and other custom activities
- Custom exercises with names and notes
- AI-generated weekly plans
- Photos uploaded to share cards
- Social interactions: likes, comments and follows
2.3 Technical Data
We automatically collect a limited amount of technical information needed to operate the service:
- IP address (server logs)
- Push notification tokens (only if you enable notifications)
- Authentication tokens
- Device type and operating system version
3. How We Use Your Information
We use the information described above to:
- Provide and improve the Gainlog service
- Generate personalized AI workout plans
- Display social features such as the feed, follows and likes
- Send push notifications, if you have enabled them
- Detect and prevent fraud or abuse
4. Third-Party Services
Gainlog relies on a small number of trusted third-party services to operate. Each only receives the data strictly required to perform its function:
- Clerk — authentication and account management
- Cloudflare — database hosting and serverless backend
- Anthropic — Claude API for AI plan generation. Anthropic only sees the prompt sent for plan generation, not your full account
- ASCEND API via RapidAPI — exercise database. No personal data is shared with this service
- Apple Sign In and Google Sign In — only if you choose to authenticate via OAuth
5. Data Sharing
We do not sell your personal information. We share data only with:
- The third parties listed in section 4, as needed to operate the service
- Law enforcement or other authorities, if legally required
6. Data Retention
- Your account and workout data is retained while your account is active.
- You can delete your account and all associated data at any time via Settings › Profile › Delete Account.
- Backups may retain data for up to 30 days after deletion.
7. Your Rights (GDPR + CCPA)
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Export your data (please contact us)
- Opt out of marketing communications
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact support@gainlog.org.
8. Children
Gainlog is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will delete it.
9. Security
- All data is transmitted over HTTPS.
- Authentication tokens are stored in the iOS Secure Enclave or Android Keystore, depending on your device.
- Our backend is hosted on Cloudflare with industry-standard security practices.
- While no system can guarantee 100% security, we follow current best practices to protect your data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Continued use of the app after a change constitutes acceptance of the updated policy.
11. Contact Us
For any questions or requests related to this Privacy Policy or your data:
Email: support@gainlog.org