LEGAL

Privacy Policy

How we collect, process, and protect personal data under the GDPR.

Effective:July 27, 2026Jurisdiction:EEA (Czech Republic & Slovakia)

1. Introduction and Operator Identity

This Privacy Policy governs the collection, processing, and protection of personal data by the GainSync platform, including its backend GraphQL API, web and mobile applications, and related services (collectively, the "Service").

The Service is operated by Richard Pokuta, an independent entrepreneur (OSVČ) registered under IČO: 29650712, with a registered office at Orlová, Moravskoslezský kraj, Czech Republic ("GainSync", "we", "us", or "our"). We strictly adhere to the General Data Protection Regulation (EU) 2016/679 ("GDPR").

This Privacy Policy is governed by Czech law. Where the data subject is habitually resident in the Slovak Republic, the mandatory consumer-protection provisions of the Slovak Republic shall apply to the extent required by applicable EU law.

3. Data Inventory: What We Collect

We apply strict data minimization. Based on the functionality of our platform, we process the following categories:

3.1 Data Collected from Coaches (GainSync = Controller)

Identity & Account Data: Full name, email address, username, cryptographically hashed passwords (bcrypt), Google OAuth ID tokens (if using single sign-on), profile avatars, bank account number, role (TRAINER/CLIENT), and online/offline presence status.

Authentication & Session Data: JWT access and refresh tokens, password-reset tokens, device tokens (iOS, Android, WEB), logout/logoutAll events, and fixed-window rate-limit counters stored in Redis.

Financial Data: Billing status, Paddle subscription records, tax identifiers, and bank account details used to generate one-off or recurring payment requests to Clients and to track their status.

Practice Data: Invite codes, join-request resolutions, trainer dashboard metrics (total clients, active clients, pending join requests, recent clients), custom exercise and meal libraries, versioned training plan and meal plan templates, client notes, scaling suggestions, and payment-request templates.

3.2 Data Processed on Behalf of Coaches (GainSync = Processor)

Client Identity & Communication: Names, email addresses, Google OAuth ID tokens, join-request statuses, invite-code usage, and chat messages (one-to-one and group) including text, images, documents, workout references, meal references, and payment messages, together with read receipts, typing indicators, and presence status.

Health, Biometric, and Visual Data (Special Category): Body weight, body fat percentage, muscle mass, up to fourteen body-part circumference measurements, progress photos (front, side, back, other poses), meal images, exercise videos, and avatars.

Training Data: Training plan templates and assignments, weekly workout grids, day exercises, planned sets (reps ranges, target weight, toFailure, myoRepMatch, dropset, target RPE/RIR-style fields), client-side tweaks, completed workout sessions, logged sets (weight, reps, RPE, toFailure), session feedback (WAY_TOO_EASY, EASY, SPOT_ON, HARD, WAY_TOO_HARD), and weekly activity summaries.

Nutrition Data: Nutrition goals (calories, protein, carbohydrates, fat, target weight, instructions), meal library entries and versions, meal plan templates and assignments, weekly slots and options, custom meal logging, meal plan record logging, and per-day nutrition aggregation.

Check-In Data: Self-reported mood, energy level, sleep duration, and muscle soreness, together with reminders and alerts generated for the Coach.

Payment & Notification Data: One-off and recurring payment requests (amount, currency, variable symbol, due date, status transitions, manual paid marking, overdue scheduler output), and notification preferences/history across up to nineteen in-app notification types delivered via FCM push, Resend email, and in-app feeds.

Data Export Records: User-initiated full data export requests and the resulting email delivery.

3.3 System and Technical Data (Automated Collection)

IP addresses and online/offline presence status; HTTP request metadata; and fixed-window rate-limit counters stored in Redis.

FCM (Firebase Cloud Messaging) device tokens for push notification delivery, together with invalid-token pruning logs.

Structured application logs produced by Pino, crash reports, BullMQ job queue metadata, Prometheus metrics, Redis cache and pub-sub records, and PostgreSQL database records distributed per service.

Media processing metadata such as image optimization results (sharp, jpegtran), video remux results (ffmpeg), PDF validation results (pdf-lib), and ClamAV malware scan results.

4. Lawful Basis for Processing (GDPR)

Contractual Necessity (Art. 6(1)(b)): To provision the Service, authenticate users through the JWT lifecycle, manage Coach subscriptions, process payment requests, deliver notifications, and enforce our Terms of Service.

Legitimate Interests (Art. 6(1)(f)): To monitor security, prevent API abuse via Redis rate-limiting, optimize platform performance, prune invalid device tokens, generate aggregated usage analytics, and maintain infrastructure reliability.

Explicit Consent (Art. 9(2)(a)): Processing Client biometric data, body measurements, sleep/mood/soreness metrics, progress photos, meal images, exercise videos, and other visual media requires explicit, affirmative consent. Clients grant this consent directly to their Coach. Clients may withdraw this consent at any time, compelling the cessation of processing and deletion of the applicable health data and visual media.

5. Sub-Processors and Data Disclosure

We utilize vetted Sub-processors bound by strict confidentiality agreements. Data is shared exclusively for operational execution:

Infrastructure and Databases

PostgreSQL databases (per service) for persistent structured data; Redis for caching, pub-sub, session state, invite codes, and fixed-window rate-limiting; BullMQ for job queues; and Prometheus/Pino for metrics and structured logging.

Object Storage and Media Processing

Supabase/S3-compatible object storage with signed URLs for uploads and downloads of progress photos, meal images, exercise videos, avatars, group icons, chat images, and documents. Image optimization (sharp, jpegtran), video remuxing (ffmpeg), PDF validation (pdf-lib), and malware scanning (ClamAV).

Communications

Resend for transactional email delivery (password resets, payment alerts, welcome emails, data-export delivery), and Firebase Cloud Messaging (FCM) for push notifications.

Merchant of Record

Paddle acts as our authorized Merchant of Record (MoR) for Coach subscription billing, payment processing, tax calculation, and remittance.

Coach Access

All Client data is directly and immediately accessible to the connected Coach through the trainer dashboard, client overview, and related tools, solely for the purpose of managing training, nutrition, progress, payments, and communication.

Legal Compliance

We will disclose data only if legally compelled by a binding court order or enforceable request from competent authorities within our jurisdiction.

Behavioral Analytics

Microsoft Clarity (Microsoft Ireland Operations Limited / Microsoft Corporation) for behavioral analytics, heatmaps, and session recording on our marketing website, web application, and mobile applications. Data is transferred to the United States under the EU Standard Contractual Clauses. Session recordings are retained for 30 days; aggregated heatmap data for up to 13 months.

6. Commercial Rights to Anonymized Data

We may aggregate and de-identify data collected through the Service (including workout history, check-in metrics, and logged sets) for the purposes of improving Scaling Suggestions and platform analytics. Where such data cannot reasonably be re-identified, either alone or in combination with other data we hold, we treat it as anonymized and outside the scope of GDPR. Where de-identified data could still be re-linked to an individual (pseudonymized data), we continue to treat it as personal data and process it only on the legal bases described in Section 4.

7. Cookies and Authentication

We utilize essential local storage mechanisms (such as JWT access and refresh tokens) strictly necessary for user authentication, API authorization, and session security. These are exempt from prior-consent requirements under the ePrivacy Directive.

We also use Microsoft Clarity, a behavioral analytics tool that uses cookies and session storage to record heatmaps, click patterns, and session recordings on our marketing website, our web application, and our mobile applications. Clarity is non-essential and requires your consent before it activates for visitors in the EU, EEA, UK, and Switzerland. On the web, you may accept or decline this tracking via the cookie banner and withdraw consent at any time via the cookie settings link. On mobile, you may toggle Clarity on or off via the in-app privacy settings. We deploy zero third-party advertising cookies.

8. Age Restriction (Minors)

The Service is intended for users who are at least 16 years old. Coaches are strictly prohibited from processing the personal data of individuals under 16 through the Service without verifiable parental or guardian consent. If we learn that we have collected personal data from a child under 16 without such consent, we will delete that data promptly.

9. Data Security and User Responsibility

We implement appropriate technical and organizational measures, including bcrypt password hashing, JWT-based authentication with access and refresh tokens, role-based guards (TRAINER/CLIENT), signed URLs for media transfers, Redis-backed rate limiting, structured Pino logs, ClamAV scanning, and encrypted data in transit.

You are responsible for maintaining the confidentiality of your credentials, using logout or logoutAll when appropriate, and for any activity that occurs under your account. GainSync is not liable for unauthorized access caused by credential sharing, weak passwords, or failure to revoke access using the tools we provide.

10. Data Retention

We retain your personal data only for as long as necessary to provide the Service and fulfill the purposes described in this Policy. Active account data is retained for the life of the account. Deactivated accounts are soft-deleted and permanently erased within 30 days, except where EU or Member State law requires retention of specific records (e.g., billing records).

Media files associated with deleted accounts are removed from object storage in accordance with the same schedule. Redis cache, rate-limit counters, and BullMQ job metadata are pruned automatically according to their configured time-to-live policies.

11. Your Data Subject Rights (GDPR)

Depending on your jurisdiction, you may have the right to access, rectify, erase, restrict, object to, or port your personal data, as well as the right to withdraw consent for Special Category processing.

Because Clients' health, training, nutrition, progress, and check-in data are processed on behalf of the Coach, Clients should generally exercise these rights through their Coach. Where applicable, you may also execute these rights via the Service's data-export feature or by emailing [email protected]. Data export requests are fulfilled by generating a downloadable copy and delivering it via email.

You also have the right to lodge a complaint with a supervisory authority, in particular the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz), or the supervisory authority of your habitual residence or place of alleged infringement.

12. Policy Modifications

We can and will change this Privacy Policy at any time to reflect new features or legal requirements. Material changes will be communicated through the Service or via email. Your continued use of the Service after such changes constitutes acceptance of the updated Policy.

← Back to home