Privacy Policy for Gym Snap
Effective Date: October 7, 2025
Last Updated: October 7, 2025
Introduction
Gym Snap ("we," "our," or "us") is operated by Alchemy Technologies (Muhammad Usman Khan, sole proprietorship). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our mobile application (the "App"). By using Gym Snap, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Password (encrypted and securely stored)
- Fitness goal (Build Muscle, Lose Fat, or Stay Fit)
- Gym experience level (Beginner, Intermediate, or Advanced)
Body Analysis Photos
When you use our workout generation feature:
- You provide two photographs of yourself (front and back views)
- These photos are temporarily processed by our AI service provider (Google Gemini API)
- Photos are NOT stored on our servers or in our database
- Photos are transmitted directly to Google's Gemini API for analysis only
- After analysis is complete, photos are not retained by us
Workout Plans
We store:
- AI-generated workout plans associated with your account
- Workout plan history for your reference
- Timestamps of when plans were generated
Technical Information
We automatically collect:
- Device information (operating system, app version)
- Usage data (features accessed, errors encountered)
- IP address for security purposes
How We Use Your Information
We use your information to:
- Create and manage your account
- Generate personalized workout plans based on your photos, goals, and experience level
- Store your workout history for your reference
- Improve our AI analysis and app functionality
- Communicate with you about your account or the service
- Ensure security and prevent fraud
Third-Party Service Providers
Google Gemini API
- We use Google's Gemini API (paid tier) to analyze your body photos and generate workout recommendations
- Your photos are sent to Google for AI analysis purposes only
- Under Google's paid tier terms, your photos and prompts are NOT used to train Google's AI models
- Google processes this data in accordance with their Data Processing Addendum
- Google may temporarily log your photos for abuse detection only, not for product improvement
- For more information, see Google Gemini API Terms
Supabase
- We use Supabase for authentication and database services
- Your account information and workout plans are stored on Supabase's secure infrastructure
- Supabase processes data in accordance with their privacy policy and security standards
Data Retention
- Photos: Not stored. Processed in real-time and immediately discarded after analysis
- Account Information: Retained until you delete your account
- Workout Plans: Retained until you delete your account or request deletion
- Usage Data: Retained for up to 12 months for analytics purposes
Your Rights
You have the right to:
- Access your personal information stored in our database
- Update your account information at any time
- Delete your account and all associated data
- Request a copy of your workout plan data
- Withdraw consent for data processing (by deleting your account)
To exercise these rights, contact us at support@atalchemy.com.
Data Security
We implement appropriate technical and organizational measures to protect your data:
- Passwords are encrypted using industry-standard hashing
- All data transmission uses HTTPS encryption
- API keys are stored securely and never exposed in the app
- Database access is restricted and monitored
- Regular security audits and updates
Age Restrictions
Gym Snap is only available to users who are 18 years of age or older. We do not knowingly collect information from individuals under 18. If we discover that a user under 18 has provided personal information, we will delete it immediately.
Data Processing Infrastructure
Your data is processed and stored using third-party service providers (Supabase for authentication and database services, and Google Gemini API for AI analysis) in accordance with their respective security and privacy standards. By using the App, you consent to data processing by these service providers.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy in the App
- Updating the "Last Updated" date
- Sending an email notification for material changes
Your continued use of the App after changes constitutes acceptance of the updated policy.
No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@atalchemy.com
Business Name: Alchemy Technologies (Muhammad Usman Khan, sole proprietorship)
Website: atalchemy.com/gymsnap
GDPR Compliance (For European Users)
If you are in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
To exercise these rights, contact us at support@atalchemy.com.
California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Opt-out of the sale of personal information (we do not sell data)
- Request deletion of personal information
- Non-discrimination for exercising your rights
Contact us at support@atalchemy.com to exercise these rights.