GymPeak — Legal

Public legal documents for the GymPeak iOS app

View the Project on GitHub GymPeakApp/gympeak-legal

GymPeak Privacy Policy

Last updated: May 29, 2026

This policy describes how your personal data is processed when you use the GymPeak mobile application (the “App”) for iOS. It complies with the EU General Data Protection Regulation 2016/679 (“GDPR”) and the Spanish Organic Law 3/2018 on Data Protection and Digital Rights.

1. Data controller

We do not have a Data Protection Officer (DPO), as our processing activities do not meet the thresholds set in Article 37 GDPR.

2. Personal data we process

GymPeak is designed under the principle of data minimization: the App does not send data to any server we control. All data is stored locally on your device. The only data categories are:

2.1 Profile data you provide

2.2 Data generated by your use of the App

2.3 Technical subscription data

When you purchase or restore a subscription, we receive only:

We do not receive banking details, card number, billing address, or Apple ID. Apple processes the payment, not us.

3. Purposes of processing

Purpose Data type
Providing App functionality (showing your profile, saving routines, tracking workouts) Profile and generated data
Syncing your data across your own devices via iCloud (if enabled in iPhone Settings) Profile and generated data
Verifying your subscription status and unlocking paid features Technical subscription data

We do not perform: profiling, advertising, behavioral analytics, automated decision-making with legal effects, or selling data to third parties.

5. Recipients

Your data is not shared with third parties except in the following cases, all necessary for the technical operation of the App:

6. Retention periods

7. Your rights

As a data subject, you can exercise the following rights under Articles 15-22 GDPR:

To exercise them, write to appgympeak@outlook.com with the subject “GDPR Rights” and indicating the right you wish to exercise. We will respond within a maximum of one month from receipt of the request.

8. International transfers

Subscriptions are processed on Apple infrastructure, which may involve transfers to the United States. Apple provides adequate safeguards through EU Standard Contractual Clauses (see Apple’s Privacy Policy for details).

9. Children’s data

The App is intended for users aged 13 and over. If you are between 13 and 16, you must have authorization from a holder of parental responsibility. If we discover we have processed a minor’s data without such authorization, we will delete it without delay.

10. Security

Data is stored on your device under iOS sandbox protection and, optionally, in iCloud under Apple’s encryption system. We do not transmit data to servers of our own, so there are no risks associated with breaches of our infrastructure.

11. Changes to this policy

We may update this policy to reflect changes in the App or in regulations. We will notify you via an in-App notification or a visible change to the “Last updated” date at the top of the document. Previous versions are archived upon request.

12. Complaints

If you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es. However, we encourage you to contact us first to resolve the matter directly.


Last updated: May 29, 2026 · Version 1.0