Privacy
First things first, because it is the point: we do not sell your data, we do not pass it on and we do not analyse it. There is no tracking, no advertising IDs, no analytics services. This is not a statement of intent — it is how the app is built.
This English version is a translation. If it differs from the German version, the German version applies.
Who processes
GymJourney is a private, non-commercial project. Questions about privacy: datenschutz@gymjourney.de
What is stored
| Data | Purpose | Legal basis |
|---|---|---|
| Email, password (hashed) | Login | Art. 6 (1) (b) GDPR — contract |
| Body data (weight, height, age, sex) | Calorie and macro calculation | Art. 9 (2) (a) GDPR — your consent |
| Nutrition and training log | The purpose of the app | Art. 6 (1) (b) GDPR |
| Progress photos (optional) | Before-and-after comparison | Art. 9 (2) (a) GDPR — consent |
| Login events (IP, time) | Protection against break-ins | Art. 6 (1) (f) GDPR — legitimate interest |
| Subscription term | Access control | Art. 6 (1) (b) GDPR |
Health data. Weight, body measurements and photos are special categories of personal data (Art. 9 GDPR). They are processed only because you use the app for this — and exclusively to show you your own numbers. There is no analysis across several users.
Where the data is
On a server in Germany (Hetzner Online GmbH, processor under Art. 28 GDPR). It does not leave the EU. Progress photos are stored outside the web directory and are only delivered through an endpoint that checks the owner — a guessed URL is of no use to anyone.
What goes to third parties
Open Food Facts (open food database): When you scan a barcode, that barcode is looked up — nothing else. No link to you, no identifier.
Push notifications (only if you switch them on): Your browser's push service (Apple, Google, Mozilla) delivers the message. The content is end-to-end encrypted — the service cannot see it.
AI coach (Anthropic PBC, USA), only with your consent: If you switch on the AI coach, the app sends an extract of your data to Anthropic with every chat message: sex, age, height, weight and weight history, goal, training plan, reported complaints, habits and notes, and the chat history. Your name, email address and photos are not sent. This is health data (Art. 9 GDPR); the transfer to the USA is based on your explicit consent (Art. 49 (1) (a) GDPR), which you can withdraw in the app at any time. By its own account, Anthropic does not use data sent via the API to train its models. Without consent the chat is switched off; all other functions keep running. We store your chat messages together with the answers for 12 months in the AI log; the operator can view them.
Guard against misuse: Fixed rules check inputs into AI features and forum posts for attempts to get at other people's data, insults, extremist content, hacking and phishing. Matches are stored with a short excerpt and reported to the operator (legitimate interest in secure operation, Art. 6 (1) (f) GDPR); misuse can lead to the account being blocked.
Food by photo (Anthropic PBC, USA), only with its own consent: If you use photo recognition, the app sends only the respective photo of your meal to Anthropic so that the food and the amount can be estimated. No profile data, no name, no email address. We store the photo and the estimate for 12 months in the AI log so that misuse can be detected. The transfer to the USA is based on your explicit consent (Art. 9 (2) (a), Art. 49 (1) (a) GDPR), separate from the consent for the AI coach and revocable in the app at any time.
Usage statistics: So that we can see which parts of the app are used and whether an account is still in use, we store per day which areas you opened (e.g. "Training", "Diary") – without content, without click trails, without IP address. The entries are deleted after 400 days and are only visible to the operator (legitimate interest, Art. 6 (1) (f) GDPR).
Friends and leaderboard (only with its own consent): If you connect with friends via your personal code, they see your nickname and – depending on what you share – your training days and your weight history (only the change or the exact values). Never your login name, never your email address; nobody can search for nicknames. The legal basis is your explicit consent (Art. 9 (2) (a) GDPR). If you withdraw it, friendships, requests and your code are deleted immediately.
Nobody else. No analytics services, no advertising networks, no fonts from external servers. The fonts are on our server; loading them from Google would send your IP address there.
How long
- Your data stays as long as your account exists — even if the subscription has expired. We do not delete anything to get you back.
- Login events: 90 days.
- Account deleted: everything is deleted, immediately and completely (cascading deletion in the database).
Your rights
Access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), withdrawal of consent (7 (3)).
You can exercise two of them yourself, without asking us: In the app's settings there is "Export data" (everything as JSON) and "Delete account" (permanently). Both also work if your subscription has expired — the right to your data does not end with payment.
Right to lodge a complaint with a supervisory authority: Art. 77 GDPR.
Cookies
None. Login uses a token in your browser's local storage (not a cookie, not sent along automatically, no tracking possible). That is why there is no cookie banner here — there would be nothing to ask.
Last updated: October 2026