Privacy Policy
Gym or Pay takes your privacy seriously. This policy explains what we collect, how we use it, who we share it with, and what rights you have under the General Data Protection Regulation (GDPR).
Who we are
Gym or Pay (gym-or-pay.com) is operated by Pedro [surname] as a sole trader registered in Portugal. For any privacy question or request, contact hello@gym-or-pay.com.
What data we collect
We collect only what is needed to run the service:
- Email address — one-time login codes and transactional emails (weekly summaries, receipts).
- Commitment details — weekly workout target, deposit amount, chosen charity or reward preference.
- Validated workouts — duration, average heart rate, source (e.g. HealthKit, Health Connect, Google Fit), start/end time, and a workout identifier. We do not collect steps, location, sleep, nutrition, or body-composition data.
- Payment records — Stripe customer ID, charge and refund history. We never see or store your card number.
- Wallet and redemption history — balance, payout and donation records via Tremendous.
- Push notification token — to send workout confirmations and weekly outcomes.
- Device platform — iOS or Android, so we route notifications correctly.
- Referral code — a short random code if you use invite-a-friend.
- Optional before photo — if you choose to take one during onboarding, it is stored on your device. An optional AI preview is generated by sending the image to Google's Gemini API; we do not permanently store the photo or preview on our servers.
- Optional dream reward text — if you describe a purchase goal during onboarding, that text may be sent to Gemini to look up product information. We store only the resulting product details you confirm.
We do not collect your name (unless you add a display name), phone number, address, contact list, calendar, or any device data beyond what is listed above.
Apple Health (HealthKit)
On iOS, health data is read on your device. We request access only to exercise sessions and heart rate associated with those sessions. The validated workout fact — identifier, duration, average heart rate, and timestamp — is sent to our server for goal tracking. We do not retain raw HealthKit objects on our servers. Health data is never sold, shared with advertisers, or used for profiling. You can revoke HealthKit access at any time in the iOS Settings app.
Google Health Connect (Android)
On Android, health data is read on your device via the Health Connect API. We request only Exercise session and Heart rate permissions — not steps, sleep, body composition, location, or any other Health Connect data type. The validated workout fact is sent to our server for goal tracking. Health data is never sold, shared with advertisers, or used for profiling. You can revoke Health Connect access at any time in the Health Connect app or Android Settings.
Google Fit
If you choose to connect Google Fit, we use Google's OAuth service to access your fitness activity data. We request these scopes only:
https://www.googleapis.com/auth/fitness.activity.read— read exercise session data (duration, heart rate, start/end time)openid,email,profile— identify your Google account during the connection flow
We use this data only to verify whether you met your weekly workout commitment. We do not read steps, location, sleep, nutrition, weight, or any other Google Fit data type. We do not use Google Fit data for advertising, sale to third parties, or profiling.
OAuth tokens are stored securely on our servers (Supabase, EU). Validated workout facts are stored in our database. You can disconnect Google Fit at any time from Settings → Integrations in the app, and revoke access from your Google Account permissions page. Disconnecting stops new imports; data already collected remains until you delete your account.
The OAuth redirect uses gym-or-pay.com/google-callback and is processed by our backend before returning you to the app.
Other optional integrations
You may optionally connect third-party fitness services (Fitbit, Polar, Garmin, Strava, MyFitnessPal, Hevy, and similar). These connections are entirely user-initiated. For each connected service we read only workout-related fields needed for validation: duration, heart rate, timestamps, and source identifier. OAuth tokens are stored securely on our servers. We do not access data from services you have not explicitly connected. You can disconnect any integration from Settings → Integrations.
How we use your data
- Authenticate you and run your weekly commitment.
- Validate workouts against your target.
- Process weekly deposits and refunds via Stripe.
- Issue wallet payouts, gift-card redemptions, and charity donations via Tremendous.
- Send transactional emails and push notifications.
- Generate optional AI previews or product lookups (Gemini) when you request them.
- Detect fraud and comply with legal obligations.
We do not use your data for advertising, profiling, or sale to third parties.
Who we share it with
We share data only with processors required to run the service:
- Supabase — database, authentication, and backend (EU, Ireland).
- Stripe — payment processing (EU primary).
- Tremendous — payouts, gift cards, and charity donations (EU and US).
- Resend — transactional email (EU).
- Expo Push — push notification delivery (US).
- Google (Gemini API) — optional AI image preview and product lookup when you request it. Images are processed transiently and not retained by us after the response.
- Cloudflare — DNS and hosting for this website.
- Connected fitness providers — only when you initiate a connection (Google Fit, Fitbit, etc.).
We do not use Google Analytics, advertising pixels, or similar tracking on this website. We do not sell your data.
International data transfers
Some processors (Tremendous, Expo Push, Google Gemini, Cloudflare) may process data in the US. Transfers are covered by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, with encryption in transit and at rest.
How long we keep data
- Active account data — while your account exists.
- Completed commitment history — up to 7 years where required by Portuguese tax and accounting law.
- Login codes (OTP) — about 10 minutes, then deleted automatically.
- Push tokens — while your device is registered, plus 30 days of inactivity.
- OAuth tokens — while the integration remains connected; deleted on disconnect or account deletion.
After you delete your account, identifying personal data is removed within 30 days, except pseudonymized financial records we must retain by law.
Your rights (GDPR)
You have the right to:
- Access — export your data from Settings → Export my data, or email us.
- Rectification — correct inaccurate data in the app or by email.
- Erasure — delete your account from Settings → Delete my account.
- Restriction and objection — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in machine-readable JSON.
- Complain — lodge a complaint with the Portuguese data protection authority (CNPD).
We respond to requests within 30 days. Email hello@gym-or-pay.com.
Account deletion
You can delete your account at any time from Settings → Delete my account. This removes your profile, push tokens, and integration connections within 30 days, closes any active commitment (with applicable refund rules), and cannot be undone. Some financial records are retained in pseudonymized form as required by law.
Children
Gym or Pay is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.
Security
- All data in transit is encrypted (TLS 1.2+).
- Data at rest is encrypted by Supabase (AES-256).
- Payment card data goes directly to Stripe — we never see it.
- User-scoped database tables use Row Level Security.
Cookies
The mobile app does not use cookies. This website uses no tracking cookies.
Changes
If we make material changes to this policy, we will notify you by email at least 14 days before they take effect. The date at the top of this page tracks every revision.
Questions? hello@gym-or-pay.com