Gymora AI Fitness Coach Privacy
Your training data should not be a mystery.
Effective August 17, 2026. This policy explains what Gymora stores locally, what is processed when you choose connected features, and the controls available to you.
The short version
Gymora is local-first. Core workout, progress, nutrition, planning, voice-direction, and preference data stays on your device unless you choose a connected feature. Creating an account is optional and enables a manual, account-linked cloud backup.
Gymora does not include an advertising SDK, does not sell personal data, and does not use data for cross-app tracking.
Information stored on your device
- Training profile, goals, experience, equipment, schedule, units, and constraints you enter.
- Workout plans, completed sessions, set logs, records, favorites, planner items, challenges, measurements, food entries, barcodes, nutrient targets, and hydration logs.
- Date-based step totals reported by the device pedometer and your step goal. A manual cloud backup includes this local state only if you explicitly create one.
- Preferences including appearance, reminders, notification choices, voice-guidance settings, connection state, and leaderboard opt-in.
The optional step counter requests Motion & Fitness permission only when you enable it. On iPhone, Gymora can retrieve the current day and up to the available seven-day history. On Android, it records only steps reported while Gymora is active and labels that limitation. Web browsers cannot provide pedometer data to Gymora.
Gymora includes sample training data so the interface is understandable before you log a real session. You can reset local data in Settings.
Information processed when you use connected features
- Optional account information: account identifier, name, email address, and session credentials for sign-in.
- Manual cloud backup: when you tap Back up this device, Gymora sends a copy of local app state tied to your account ID with a revision, checksum, and timestamp.
- AI features: equipment photos, workout inputs, exercise-visual prompts, Coach questions, and the relevant context you choose to use are sent to hosted AI services to return a result.
- Food discovery: search text or scanned barcode digits are sent through Gymora’s server to Open Food Facts for product matches.
- Service operations: hosting providers may process IP address, device or browser information, request metadata, cookies, and security logs.
Camera permission does not upload a live feed. Vision sends only the still image you select or capture after you request analysis. The barcode scanner reads supported codes on-device, then sends barcode text for lookup.
How Gymora uses information
Gymora uses information to provide workouts, logs, progress summaries, step progress, nutrition totals, reminders, connected account and backup features, requested AI responses, food-product information, security, abuse prevention, and service operations. AI-generated output may be incomplete or inaccurate and is not medical diagnosis or treatment.
Gymora is delivered as a Manus-hosted Space. Manus / Butterfly Effect Pte. Ltd. provides hosting, authentication, databases, request security, and built-in AI orchestration. Third-party AI providers used by Manus may process connected-feature inputs. Open Food Facts provides food and barcode results. Apple, Google, and device operating-system services provide app delivery, permission controls, device pedometer data, local text-to-speech, and notifications where applicable.
Retention, deletion, and your choices
Local Gymora data remains until you reset it in Settings, uninstall the app, clear storage, or your operating system removes it. A cloud backup exists only after an authenticated user manually creates one; new backups replace the prior revision for that account.
You can use Gymora without an account, decline or revoke camera, notification, or Motion & Fitness permission, avoid AI and food lookup, edit local data, reset local data, delete a cloud backup, or request hosted account and service-data deletion. Hosted security and request records may be retained only for operational, legal, fraud-prevention, or dispute-resolution needs.
Security, children, and contact
Gymora uses HTTPS, validates server inputs, scopes cloud backups to the authenticated account, and uses revision checks to reduce accidental overwrites. No system is completely secure; local data may be accessible to someone who controls an unlocked or compromised device.
Gymora is not directed to children under 13. Fitness and nutrition features are educational, not medical care. Do not use Gymora to diagnose or treat a condition or to store medical records.
For Gymora support, contact ghislaintabe9@gmail.com. For hosted account, authentication, AI, or cloud-service privacy requests, use privacy@manus.im and identify the Gymora Space. See the Manus Privacy Policy and Open Food Facts Privacy Policy for provider details.