Legal

Privacy Policy

How we handle personal data — both our customers' and their members'.

Draft pending legal review This page accurately describes how the software handles data, but it is not yet a finalised legal document. The legal entity details, Grievance Officer contact and per-category retention periods are still being completed with counsel. For anything contractual, email support@gymos.app and we'll give you the current position in writing.

Two different relationships

It matters which one applies to you, because the answers differ.

  • If you're a gym using GymOS, you decide what member data to collect and why. You are the data fiduciary for it. We process that data on your instructions, to provide the service.
  • If you're a member of a gym that uses GymOS, your relationship is with your gym. They decide what to collect and how long to keep it. Requests about your data should go to your gym first — the member app has a privacy section, and gyms running the compliance pack have a grievance inbox with a 90-day response clock.
  • For our own customer records — the gym owner's name, contact details, billing history and support correspondence — we are the fiduciary.

What the software collects about members

Every field is mapped to a stated purpose, and gyms can see that mapping. The broad categories are:

  • Membership services: name, phone, email, date of birth, gender, photo, branch, guardian details for minors, and optionally a masked government-ID document.
  • Health and fitness: medical notes, body measurements, workout and diet plans. Medical notes are encrypted at rest.
  • Marketing: only where the member has opted in.
  • Progress photos: only where the member has consented separately.
  • Operational records: check-in timestamps, class bookings, payments and invoices.

We never collect Aadhaar numbers. There is no field for one anywhere in the system, by design.

When you fill in a form on this website

The contact, demo and support forms on this site are ours, not a gym's — here we are the controller. This section covers exactly what those three forms record, because it is more than what you type into them.

  • What you enter: your name, and a phone number or email address (at least one, so we can reply). Your message, if you write one. On the demo form, your gym's name, city, member count, number of branches, current software and best time to call. On the support form, your gym's name and how urgent it is.
  • What your browser sends: your IP address, your browser's user-agent string, the page you submitted from, and the page that referred you to us.
  • Campaign tags: if you arrived through a link carrying utm_source, utm_medium or utm_campaign values, we record them so we know which of our own pages and posts actually work. These are read on our server, so this happens whether or not you block client-side tracking.

We use it to reply to that enquiry and to understand which pages bring people here. We do not add you to a marketing list, sell it, or pass it to a third party. Ask us at support@gymos.app and we will delete it.

There are no advertising or analytics scripts on this website, no session recording and no cookie-consent banner, because there is nothing to consent to. The forms carry a hidden field that only automated submissions tend to fill; if it is filled, we discard the submission without storing anything.

Consent

Where a gym has the compliance pack enabled, consent is captured against a versioned notice, in English or Hindi, and recorded in an append-only ledger. Consent records cannot be edited or quietly overwritten — a change of mind creates a new record rather than replacing the old one. Members under 18 require guardian consent.

How data is protected

  • Each gym's data is isolated from every other gym's, enforced structurally in the application and checked in our build pipeline.
  • Medical notes are encrypted at rest.
  • Members sign in to the member app with a PIN issued by their gym, stored only as a hash — we cannot read it, and neither can gym staff. Signing in needs the PIN as well as a phone number and member code.
  • Photos, documents and ID uploads are stored on private storage, reachable only through authorised, audited routes — never from a public URL.
  • Access is least-privilege: 57 granular permissions, with trainers scoped to their own assigned members.
  • An append-only audit trail records authentication, record changes, the money lifecycle, exports, permission changes, and sensitive views such as opening medical notes.
  • Where our staff access a gym's account to provide support, that access is logged server-side against the individual.

We describe controls rather than certifications because we hold no third-party security certification. Our Trust page says so plainly and lists what we haven't built yet.

Payments

GymOS does not process payments and never handles card details. Gyms record that a payment occurred — cash, UPI, card or bank transfer — and we store that record. No card numbers enter the system.

Retention and erasure

Audit records are retained for more than a year. Financial records are retained as long as tax and financial law requires. When a gym runs an erasure request for a member, personal data is removed and only legally-required financial records are retained in a de-identified form.

Per-gym retention configuration is not yet available; retention currently follows platform-wide defaults. This is one of the gaps listed on our Trust page.

Exercising your rights

Members should contact their gym — the gym holds the relationship and the decision-making authority over their data. Gym owners can contact us at support@gymos.app for access, correction or erasure of their own account data, or for help servicing a member request.

Grievance Officer details will be published here on completion of legal review. In the meantime, support@gymos.app reaches a person, not a queue.

Changes to this policy

When this policy changes materially, we'll date the change here and tell existing customers directly rather than relying on you to re-read the page.

Last reviewed: August 2026. Draft — pending legal review.