1. Controller and contact
This Privacy Policy explains how GymPT processes personal data under KVKK, GDPR/AVG, e-commerce, app store, and platform rules. The controller is the GymPT operator identified in the legal pages. The panel record must contain the final legal name, registered address, trade registry/tax details, and privacy contact before production.
2. Data categories
GymPT may process identity and contact data, account credentials and verification logs, device identifiers, language and region, onboarding answers, goals, training level, limitations, equipment, body photos or videos, posture and body analysis outputs, AI prompts and responses, workout plans, exercise interactions, wearable or health-sync data if connected, payment and credit records, support messages, crash and security logs, consent records, and marketing preferences.
3. Purposes and legal bases
Data is processed to create and secure accounts, provide the requested digital service, generate AI analysis and training plans, manage credits and subscriptions, prevent abuse, provide support, improve reliability, meet legal/accounting duties, send service messages, and where separately permitted, send commercial communications. Legal bases may include contract performance, legal obligation, legitimate interest, consent, and explicit consent for special category health/body data.
4. Special category data
Body photos, visual body analysis, health limitations, sensor-derived health signals, injury notes, and similar data may be special category personal data. GymPT processes this data only where the feature requires it and where the user provides explicit consent or another lawful basis applies. You may withdraw consent, but doing so may disable body analysis, health-sync, and personalized program features that need this data.
5. Recipients and transfers
Data may be shared with hosting providers, cloud storage, authentication providers, AI/model providers, analytics and crash reporting tools, payment processors, email/SMS/push providers, customer support tools, app stores, legal/accounting advisors, and authorities where legally required. Some providers may process data outside Türkiye, the EU, or the Netherlands. Where required, GymPT relies on explicit consent, adequacy mechanisms, standard contractual safeguards, or other lawful transfer mechanisms.
6. Retention
Personal data is kept only as long as needed for the purpose collected, active account use, consent evidence, accounting, legal limitation periods, security, dispute handling, and service continuity. Body analysis media may be deleted earlier according to product settings or user request unless retention is necessary for security, legal claims, or audit evidence.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, information about processing, information about recipients, withdrawal of consent, and complaint to a supervisory authority. Withdrawal does not automatically make earlier lawful processing unlawful.
8. Security
GymPT uses technical and administrative measures such as access controls, protected special fields, tokenized sessions, audit logs, transport security, provider controls, and minimized internal access. No system is perfectly secure, so you must keep your account credentials and devices safe.
9. Automated processing and AI
GymPT may use automated systems and AI to personalize analysis, training content, equipment matching, and recommendations. These outputs are not medical decisions and are not intended to produce legal or similarly significant effects without human choice. You can ignore, edit, regenerate, or seek support about recommendations.
10. Children and sensitive uploads
GymPT is not designed for children without appropriate permission. Do not upload another person’s data, children’s images, unlawful images, or health information you are not authorized to share.