The short version
We collect the account details you give us, the training data you log, and the photos you choose to scan. We use them to run the app and to generate your coaching plan. We do not sell your data, we do not track you across other apps or websites, and you can delete your account and everything in it from inside the app at any time.
1. Who we are
Gymeo (the “App” or the “Service”) is owned and operated by TELLURIOM LABS LLC, a limited liability company with its principal place of business in Miami, Florida, United States (“Tellurium Labs”, “we”,“us” or “our”). We are the data controller for the personal information described in this policy.
This Privacy Policy applies to the Gymeo iOS app and togymeo.app. It does not apply to third-party services you reach from the App, which have their own policies.
You can reach us about anything in this policy atsupport@telluriomlabs.com.
2. Information we collect
Information you give us
- Account information. Your email address and password, or the identifier returned by Sign in with Apple if you sign in that way. If you use Apple’s “Hide My Email” option, we only ever receive the relay address.
- Profile and training preferences. Your name or display name if you provide one, and details you enter to set up your plan — such as your training goal, experience level, available equipment, days per week and preferred units.
- Body metrics you choose to enter. For example height, body weight, age or sex, where you provide them so the Coach can size your sets and estimate your strength score. These fields are optional and you control whether to fill them in.
- Support communications. The contents of emails, bug reports and feedback you send us, and any attachments you include.
Information created when you train
- Workout data. Exercises performed, sets, reps, load, rest, session dates and durations, personal records, and the effort or reps-in-reserve signals you report after a set.
- Coaching output. The plans, adjustments, strength scores and rankings the App generates for you, and your history of them.
- Scan images. Photos you take of gym machines or equipment so the App can identify them. See Camera and photo access.
Information collected automatically
- Device and usage data. Device model, operating system version, App version, language and region, IP address, and in-app events such as screens opened, features used and errors encountered. We use this to keep the App working and to understand which features are worth building on.
- Diagnostics and crash data. Technical logs generated when the App fails, including the state of the App at the time of the crash. Crash reports delivered through Apple depend on the diagnostics setting you chose on your device.
Purchase information
When you subscribe, Apple processes the payment. We never receive or store your card number, bank details or full billing address. What we receive is the transaction receipt, the product you purchased, the currency, the start and renewal dates, and whether your subscription is active, in trial, cancelled or refunded.
3. How we use your information
- To run the Service. Create and secure your account, sync your data across sessions, and let you sign back in.
- To identify equipment. Analyse the photos you scan so we can return the machine name, the muscles it works and the technique guidance for it.
- To generate your coaching plan. Use your training history, effort signals and profile to size your weights, reps and rest, and to recalculate your strength score and rank.
- To manage subscriptions. Unlock paid features, verify entitlements, and handle trials, renewals and cancellations.
- To support you. Answer your questions, investigate bugs and restore data where we can.
- To improve the App. Analyse aggregated and de-identified usage to find where the App is slow, confusing or broken, and to test improvements.
- To keep the Service safe. Detect and prevent abuse, fraud, automated scraping and security incidents.
- To communicate with you. Send service messages such as security alerts, receipts, renewal reminders and material changes to this policy. If you opt in, we may also send product news and offers — you can unsubscribe from those at any time without losing access to the App.
- To meet legal obligations. Comply with tax, accounting and law-enforcement requirements, and enforce our Terms of Use.
We do not use your personal information to make decisions that produce legal or similarly significant effects about you without human involvement. The Coach’s training recommendations are suggestions you are free to ignore.
4. Legal bases for processing (EEA and UK)
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the App, your account, your training plan and your subscription.
- Consent — for camera and photo library access, for optional health and body metrics, and for marketing emails. You can withdraw consent at any time, in your device settings or in the App, without affecting processing carried out beforehand.
- Legitimate interests — to secure the Service, prevent abuse, understand how the App is used and improve it, where those interests are not overridden by your rights.
- Legal obligation — to retain financial records and respond to lawful requests from authorities.
5. AI features and your data
Gymeo uses third-party AI models to recognise equipment from your scans and to generate coaching guidance. We reach those models through OpenRouter, Inc., an AI gateway that forwards each request to an underlying model provider.
- What is sent. When you scan a machine, the image and the minimum context needed to answer — for example the exercise you are working on — are sent to OpenRouter, which routes them to the model provider that serves the model we have selected. The response comes back to your device.
- What is not sent. We do not include your name, email address, account credentials or contact details in these requests.
- Training. OpenRouter states that it does not use inputs or outputs for model training. Because requests are served by underlying providers whose practices differ, we configure our OpenRouter account toexclude providers that may train on submitted data.
- Retention. OpenRouter states that it does not persist image files beyond the time needed to route a request, except where required for abuse detection, security, billing or legal compliance. Model providers may retain content briefly for abuse monitoring under their own policies. We do not control those retention windows.
- Location. Processing takes place in the United States and may take place in the region where the selected model provider operates. SeeInternational data transfers.
- Which models. The models we route to change as better ones become available. For the current list of models and providers we use, emailsupport@telluriomlabs.com.
AI output can be wrong. Nothing the App generates is medical advice — see the health and safety section of our Terms of Use.
6. Camera and photo access
Gymeo asks for camera access so you can scan gym equipment, and for photo library access if you prefer to pick an existing image. iOS shows a permission prompt the first time, andthe App only opens the camera when you actively start a scan. Gymeo does not record audio or video in the background.
Scan images are uploaded to our servers and to the AI provider so the equipment can be identified, and are stored with your scan history so you can revisit past scans. You can revoke camera or photo access at any time in iOS Settings → Privacy & Security orSettings → Gymeo. Scanning will stop working, but the rest of the App will continue to function.
Please avoid photographing other people at the gym. If a scan captures someone else, delete it from your history — you are responsible for the images you upload.
7. Health and fitness information
Your workout logs and any body metrics you enter are health-related information, and some laws treat this as a sensitive or special category of data. We handle it accordingly:
- We use it only to deliver and improve your training experience inside Gymeo.
- We never use it for advertising, sell it, share it with data brokers, or disclose it to insurers, employers or marketing partners.
- Providing body metrics is optional; the App works without them, with less precision.
- Gymeo does not read from or write to Apple Health (HealthKit). Your Apple Health data stays on your device and is not accessible to us.
8. Who we share data with
We share personal information only with the service providers that make the App work. Each one is bound by contract to process data only on our instructions, to protect it, and not to use it for their own purposes.
| Provider | What it does | Data involved | Location |
|---|---|---|---|
| Supabase | Backend, database and authentication | Account credentials, profile, workout history, scan images and app content | United States |
| OpenRouter | AI gateway that routes requests to the underlying model providers | Scan images and the workout context needed to generate a response | United States, and the model provider's region |
| RevenueCat | Subscription and entitlement management | Anonymous app user ID, Apple transaction receipts, subscription status | United States |
| Apple | App distribution, payments and (optional) Sign in with Apple | Purchase and billing data, crash and performance diagnostics you opt into sharing | United States / global |
Beyond those providers, we disclose personal information only in these situations:
- Legal requirements. When we are required to by law, or in response to a valid subpoena, court order or government request.
- Protecting rights and safety. To investigate suspected fraud or abuse, to enforce our Terms, or to protect the rights, property or safety of our users, the public or us.
- Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
- With your consent. For anything else, we will ask you first.
9. We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) or comparable state laws. We have not done so in the preceding twelve months, including for anyone under 16.
Gymeo does not use advertising SDKs, does not build advertising profiles, and does not track you across other companies’ apps or websites. We therefore do not request permission under Apple’s App Tracking Transparency framework.
10. How long we keep your data
We keep personal information only as long as we need it for the purposes described above, then delete or anonymise it.
| Category | Retention period |
|---|---|
| Account, profile and workout history | For as long as your account is active. Deleted within 30 days of an account deletion request; encrypted backups are purged within 90 days. |
| Scan images and scan history | Kept with your account so you can revisit them; deleted with your account. |
| Usage analytics and diagnostic logs | Up to 24 months, then deleted or aggregated so you are no longer identifiable. |
| Purchase and subscription records | Up to 7 years after the transaction, because tax and accounting law requires us to keep them. |
| Support correspondence | Up to 24 months after your issue is resolved. |
We may retain information for longer where we have a legal obligation to do so, or where it is needed to establish, exercise or defend legal claims.
11. International data transfers
We are based in the United States and our service providers are located in the United States. Requests to AI models may additionally be processed in the region where the selected model provider operates. If you use Gymeo from outside the United States, your information will be transferred to and processed in these locations, whose data protection laws may differ from your own.
For transfers of personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) together with additional safeguards where needed. You can request a copy of the relevant transfer mechanism by emailingsupport@telluriomlabs.com.
12. How we protect your data
- Data is encrypted in transit with TLS and encrypted at rest by our hosting provider.
- Access to production data is restricted to the people who need it and is protected by multi-factor authentication.
- Authentication is handled by our identity provider; we do not store your password in a readable form.
- Database access rules are enforced so users can only read and write their own records.
No method of transmission or storage is completely secure. While we work to protect your information with commercially reasonable safeguards, we cannot guarantee absolute security. Use a strong, unique password and let us know immediately if you believe your account has been compromised.
13. Your privacy rights
Depending on where you live, you may have some or all of the following rights:
- Access — get a copy of the personal information we hold about you.
- Correction — fix information that is inaccurate or incomplete.
- Deletion — have your personal information erased.
- Portability — receive your data in a portable, machine-readable format.
- Objection and restriction — object to processing based on our legitimate interests, or ask us to limit how we use your data.
- Withdraw consent — at any time, where our processing is based on consent.
- Opt out of sale, sharing or targeted advertising — we do not do any of these, so there is nothing to opt out of.
- Non-discrimination — we will not degrade the Service or charge you a different price for exercising your rights.
To exercise a right, email support@telluriomlabs.com from the address on your account. We respond within 30 days, or within 45 days for CCPA requests where an extension is permitted. We may need to verify your identity before acting, and an authorised agent may submit a request on your behalf with written proof of authorisation.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first.
14. Deleting your account
You can delete your Gymeo account and all associated data from inside the App, under Settings → Account → Delete account. Deletion is permanent: your profile, workout history, scans, personal records and coaching history are removed and cannot be restored.
If you would rather we do it, emailsupport@telluriomlabs.com from your account address.
Deleting your account does not cancel your subscription. Apple manages billing, so you must cancel in iOS Settings → your name → Subscriptions to stop future charges. We also retain the purchase records described in Section 10 as required by law.
15. Children’s privacy
Gymeo is not directed to children. You must be at least 13 years old (or 16 in countries where that is the minimum age for consent to data processing) to use the App, and minors under the age of majority need a parent or guardian’s permission.
We do not knowingly collect personal information from children below those ages. If you are a parent or guardian and believe your child has provided us with personal information, contactsupport@telluriomlabs.com and we will delete the account and its data promptly.
16. Links to other sites
The App and this site may link to services we do not operate, such as the App Store or technique videos hosted elsewhere. We do not control those services and are not responsible for their content or privacy practices. Review their policies before sharing information with them.
17. Changes to this policy
We may update this Privacy Policy as the App evolves or the law changes. When we do, we will revise the “Last updated” date at the top of this page and post the new version here.
If the changes materially affect how we handle your personal information, we will give you advance notice by email or through a prominent notice in the App before they take effect, and, where the law requires it, ask for your consent.
18. Contact us
TELLURIOM LABS LLC
Miami, Florida, United States
Privacy and support:support@telluriomlabs.com
We aim to reply to every privacy request within 30 days.