Privacy policy
Last updated 21 September 2026
Tragym is a gym app. It shows how busy gyms are, which of your spotters are training, and lets you log workouts and share them. To do that it handles some personal data. This page says exactly what, why, who sees it, and how to get rid of it. It is written to be read, not skimmed past.
Who is responsible: Tragym (the "operator"), reachable at it@tragym.com. If you are in the EU/UK you have the rights described in the GDPR; if you are in California, the CCPA. Everyone gets the same rights here regardless.
What we collect and why
| Data | Why | Who can see it |
|---|---|---|
| Account: email, username, display name, password (hashed with Argon2, never stored in clear) | To create and secure your account and let spotters find you | Username and display name: other members. Email: only you and the operator. |
| Sign in with Google (optional) | If you sign in with Google we receive your email, name and a token that proves it's you. We keep the email and name; the token is used once and discarded. Google is told nothing about what you do in the app. | Same as an email account. You can set a password later and stop using Google. |
| Training profile (optional): sex, date of birth, height, goal, experience, how many days and minutes you train, what you focus on, injuries or limits you note, and your weigh-ins (weight, and waist if you add it) | Coach's readouts and plans, and the estimates on the Progress page: calories a session burned and what you burn in a day, your lifts rated for your size, a rough body-fat figure and waist-to-height, how much you lifted this week against usual, where your bodyweight and lifts are heading. All of these are worked out from these numbers and your log; they are estimates, not medical measurements, and are labelled as such. | Only you, and Coach (see "Who else touches the data"). Never shown on posts, never shared with other members. Leave any of it blank and the features that need it simply say so. |
| Profile photo and bio (optional) | So spotters recognise you | Other members |
| Location, including in the background | To notice when you arrive at or leave a gym in the directory, count you in the gym's headcount, and show your spotters where you're training. See "Location" below. | Headcounts are anonymous. Your name is shown only to accepted spotters, and only while you're at a gym, unless you turn on ghost mode. |
| Workouts: exercises, sets, weights, reps, duration, notes, effort, an optional photo | Your training history and, if you choose, a post on the board | Only you, unless you post it. Then: your spotters, or everyone, as you pick. You can hide the numbers. |
| Apple Health / Health Connect (optional; off until you connect it in the app) | With your permission the app writes your finished sessions and weigh-ins to your phone's health store; reads bodyweight that other apps or scales recorded so it can become a weigh-in here; reads the heart rate, calories and workouts your watch recorded so they can be attached to the matching session; and reads your resting heart rate and VO₂ max estimate for the Body page. Never used for advertising, never sold, never stored in iCloud by us. | Imported weigh-ins are saved to your account like any weigh-in you typed in. A session's heart rate (average, peak, low, and a 72-point trace of how it moved through the session) and calories are saved with that session so they follow you between phones; they are shown to nobody else unless you switch on "Show watch numbers" for that post, in which case whoever can see the post (its share cards and web page included) sees them. Resting heart rate and VO₂ max (one reading a day) are saved to your account too, so the Body page is the same on your next phone; they are never shown to other members. Turn sharing off per post, or the whole connection off, any time; what's already in the health store is yours to keep or delete there. |
| Posts, comments, bumps, saves, views | The social features | People who can see the post |
| Spotter links, requests, blocks, reports | To connect people and keep the place safe | Links: the two people involved. Blocks and reports: only the operator. |
| Push token (a device identifier from Apple or Google) | To deliver notifications you opted into | Nobody; it's a delivery address |
| Technical logs: request timings, error reports, crash reports from the app (with the app version and a description of the error, never your workouts or location) | To keep the service working | Only the operator; kept 30 days |
Location, in detail
Tragym asks for location permission, including "Always" / "Allow all the time", because its main feature is noticing when you arrive at a gym without you opening the app. Here is what that means in practice:
- The app registers the gyms in the directory near you as geofences with your phone's operating system. The phone wakes the app when you enter or leave one.
- While you're near a gym, the app sends your position to the server every few minutes so the headcount stays honest. When you're not near a gym, it doesn't send anything.
- The server keeps your latest position only, to work out which gym you're at. It does not keep a history of where you've been.
- Headcounts never carry names. Only people you've accepted as spotters see that it's you, and only while you're there.
- You can use Tragym with "While using" permission, or none at all. You'll be counted only while the app is open, or not at all. Everything else still works.
- Ghost mode (Settings) keeps you in the headcount but hides your name from spotters.
What we don't do
- No ads, no ad tracking, no selling or renting data to anyone.
- No third-party analytics SDKs. Usage statistics are computed on our own server.
- No reading your contacts, calendar, messages or other apps.
- No location history.
Who else touches the data
We use a few providers to run the service. They process data on our behalf and only for that purpose:
- Hosting and database: our own server (Hetzner-class VPS), running the API and PostgreSQL.
- Photo storage: an S3-compatible object store we operate. Uploaded photos are resized on our server before storage.
- Push notifications: Expo's push service, which hands messages to Apple (APNs) and Google (FCM).
- Maps and geocoding: OpenStreetMap / Nominatim, and Google Maps when configured, to look up gym addresses. Your own position is not sent to them.
- Website hosting: Vercel, for this site and the admin console.
- Coach (AI): OpenAI's API. When you open Coach, ask for a plan, or view Coach's take on a period, we send a digest: your training profile (age, sex, height, weight, goal, experience, limits), your last four weeks of training as numbers (sets by muscle group, best sets, the last session), the estimates above, your recent weigh-ins, and, if you connected a watch, its heart-rate and calorie summaries. Never your name, username, email, photo, gym, posts, comments or location. OpenAI does not use API data to train its models. We keep Coach's answer with your account and reuse it rather than asking again; the admin can switch Coach off for everyone. The same goes for Scan in the exercise picker: a photo you take of a machine is shrunk and sent to OpenAI so Coach can say what it is and which exercises suit it. We keep Coach's answer and a fingerprint of the photo (so the same picture isn't sent twice), not the photo itself. Frame the machine, not the people around it.
How long we keep things
- Your account and content: until you delete them.
- Your latest location: replaced by the next one; cleared when you sign out or delete your account.
- Presence sessions (which gym, when): 90 days, then deleted.
- Logs, error and crash reports: 30 days.
- Server backups: rotated within 30 days, so deleted data leaves backups within that window.
Deleting your account
In the app: You → Settings → Delete my account. You'll re-enter your password and everything listed above is deleted immediately: profile, workouts, posts, photos, comments, spotter links, devices. It cannot be undone. If you can't sign in, see how to request deletion.
Your rights
You can see and change your profile in the app. You can export your workouts by asking us. You can delete everything yourself. You can object to or restrict processing, and complain to your local data protection authority. For anything you can't do in the app, email it@tragym.com from your account's address; we answer within 30 days, usually much sooner.
Children
Tragym is not for anyone under 16. We don't knowingly keep accounts for children; tell us and we'll delete one.
Security
Traffic is encrypted (TLS). Passwords are hashed with Argon2. Sessions use short-lived tokens. Access to the database and admin console is limited to the operator. No system is perfect; if something goes wrong that affects you, we'll tell you.
Changes
If this policy changes in a way that matters, the app will tell you before it applies. The date at the top always shows the current version.