Privacy Policy
Last updated: April 1, 2025
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
1. Interpretation and Definitions
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Application refers to gymii., the software program provided by the Company.
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Gymii LLC, 350 West 53rd Street, New York City, NY 10019.
Country refers to: New York, United States
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
Food Dataset refers to anonymized collections of food images, user corrections to AI analysis, and associated metadata that We may compile and license to third parties for artificial intelligence development purposes.
Health and Fitness Data refers to physical activity data, step counts, and calorie burn information collected from Apple Health, Google Fit, or other fitness tracking services that You choose to connect to the Service. This data is used solely for providing You with personalized nutrition recommendations.
Personal Data is any information that relates to an identified or identifiable individual.
Service refers to:
The gymii. mobile Application available on iOS and Android platforms
Our website at https://site.gymii.ai
While our primary service is the mobile Application, some provisions of this Privacy Policy also apply to visitors of our website.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
Initial Consent and Notice
When you first create an account with our Service, we obtain your explicit consent for various aspects of data collection and processing. During the sign-up process, you will be asked to review and acknowledge several important privacy choices. Regarding food data collection and commercial use, you'll be informed that your food photos may be included in commercial datasets licensed to AI companies, with the option to opt out at any time without losing app features. For health data access, you can choose whether to connect Apple HealthKit or Google Fit, with the assurance that this health data is never sold or included in datasets. You'll also have control over marketing communications, with the ability to choose whether to receive updates and offers. All of these preferences can be modified at any time through your account settings or by contacting us.
2. Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
Email address
First name and last name
Phone number
Usage Data
Health and Fitness Data (For Service Personalization Only)
To provide you with the most accurate nutrition recommendations, we collect certain health and fitness data through Apple HealthKit and Google Fit, including step counts, active calorie burn data, and physical activity levels. This data is used exclusively to enhance your personal experience by calculating your daily caloric needs, adjusting nutrition recommendations, and providing personalized meal planning. We want to emphasize that your health and fitness data is never sold, shared with third parties, or included in any commercial datasets. You maintain full control over this data and can disconnect access at any time through your app settings.
Apple HealthKit Integration: When you choose to connect Apple HealthKit, we adhere to strict privacy requirements established by Apple. We only access the specific health data types you explicitly authorize, and this information is used solely for service personalization. In accordance with Apple's guidelines, we never use this health data for advertising or commercial purposes, nor do we share it with any third parties. You retain complete control and can revoke access to your HealthKit data at any time through your device settings.
Google Fit Integration: Similarly, our Google Fit integration follows stringent privacy practices. When you connect Google Fit, we limit our access to only the data types you specifically authorize. This information is used exclusively for personalizing your nutrition recommendations and is never shared with third parties or used for commercial purposes. As with HealthKit, you can manage or revoke your Google Fit data access at any time through your Google Fit settings.
We understand the sensitive nature of health and fitness data and maintain these strict privacy practices to ensure your information is used only for improving your personal experience with our service. Our commitment is to handle your health data with the utmost care and transparency, using it solely for the purpose of providing you with accurate, personalized nutrition guidance.
4. Food Related Data
As part of our service, we collect and process certain food-related data that may be included in commercial datasets. This includes food photos you upload, your corrections to AI-generated food analysis, portion size information, ingredient identifications, and meal categorizations. We may use this collected data to create commercial datasets that are licensed to third parties for AI development and improvement of food recognition technology.
Our food-related datasets are licensed exclusively to artificial intelligence companies, machine learning research institutions, and technology companies developing food recognition systems. The purpose of these commercial datasets is specifically to improve AI technology for food recognition and nutritional analysis, helping advance the field of computer vision and artificial intelligence.
When your food-related data is included in commercial datasets, we implement comprehensive privacy protection measures. All personal identifiers are thoroughly removed from the data, including your account information, device data, and time stamps. The data is then aggregated and anonymized to ensure no connection can be maintained to your individual account. It's important to note that your health and fitness data is never included in these commercial datasets.
During account creation, we will explicitly notify you about our data practices. You will be informed that your food photos and related corrections may be included in commercial datasets and that these datasets will be licensed to third parties for AI development. We emphasize that you can opt out of this data collection at any time, and opting out will not affect your ability to use the app's core features.
Organizations receiving our commercial food datasets must adhere to strict contractual requirements. They are permitted to use the data solely for AI/ML development in food recognition and must maintain the anonymization of all data. Recipients are expressly prohibited from attempting to re-identify individuals and are required to implement appropriate security measures. They must report any potential data incidents immediately and comply with all applicable privacy laws. Additionally, they may not transfer or sublicense the data without our explicit permission. We maintain the right to audit compliance with these requirements and may terminate access to our datasets for any violations.
We believe in giving you full control over how your food-related data is used. You can choose to opt out of having your data included in commercial datasets at any time through our simple opt-out process. This can be done either by using the "Dataset Opt-Out" toggle in your app settings or by emailing us at hello@gymii.ai. When you choose to opt out, we ensure that your food photos and AI corrections will not be included in any future commercial datasets, and your existing data will be removed from future dataset compilations. The core features and functionality of the app will remain completely unchanged.
This opt-out process is designed to be simple and immediate, giving you full control over your data while maintaining your access to all app features and services. We process all opt-out requests promptly to ensure your privacy preferences are respected.
5. Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
6. Information Collected while Using the Application
While using Our Application, we collect several categories of information with your prior permission. For basic account functionality, we collect essential personal information including your email address, first name, last name, and phone number. This information is necessary to create and maintain your account and provide our core services.
To enable the full functionality of our nutrition tracking features, we require specific device permissions. These include camera access, which is essential for taking food photos for nutrition tracking and analysis, and photo library access, which allows you to upload existing food photos and save your nutrition progress photos. These permissions are fundamental to providing our food tracking and analysis services.
We also collect certain device-related information to ensure optimal app performance and security. This includes your mobile device type and model, operating system version, unique device identifiers, and IP address. For users who visit our landing page website, we collect IP address information to maintain security and provide regional customization where appropriate.
You maintain full control over these permissions through your device settings at any time. While you can modify or revoke these permissions, please note that limiting certain permissions may affect some app functionality. We strive to maintain essential services even with limited permissions while being transparent about any resulting functionality restrictions.
7. Analytics and Third-Party Services
We utilize Supabase for analytics and data management services. Through this partnership, we collect and process usage statistics, app performance metrics, user interaction data, and technical diagnostics. This data is processed in accordance with Supabase's privacy policy and our data processing agreement. We use this information to improve app performance, identify and fix technical issues, analyze feature usage, and enhance the overall user experience. For more information about Supabase's data practices, please visit https://supabase.com/privacy.
Data Storage and Security
Your data is stored on Amazon Relational Database Service (Amazon RDS) servers located in the United States. We implement comprehensive industry-standard security measures to protect your information. These include robust encryption of data both in transit and at rest, regular security updates and maintenance procedures, strict restricted access controls, and frequent security audits. While we use commercially reasonable security measures to protect your data, we acknowledge that no method of transmission over the internet or electronic storage is 100% secure.
For food-related data used in commercial datasets, we implement additional layers of security protection. This includes a sophisticated automated system for removing all personal identifiers, a multi-step anonymization process to ensure data privacy, regular audits of anonymized datasets to maintain compliance, and secure transfer protocols for dataset licensing. These enhanced security measures are specifically designed to protect your privacy while allowing us to advance food recognition technology through our commercial datasets.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
To provide and maintain our Service, including to monitor the usage of our Service.
To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.
To manage Your requests: To attend and manage Your requests to Us.
For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
We may share Your personal information in the following situations:
With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, to contact You.
For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
With business partners: We may share Your information with Our business partners to offer You certain products, services or promotions.
With other users: when You share personal information or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside.
Retention of Your Personal Data
The Company will retain Your Personal Data indefinitely for the purposes set out in this Privacy Policy or until You request deletion. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
You may request deletion of your personal data at any time, however:
Previously anonymized data in existing commercial datasets cannot be removed
We may need to retain certain information for legal compliance
Backup copies may persist in encrypted form for a limited time
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
Our Service may give You the ability to delete certain information about You from within the Service.
You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
Comply with a legal obligation
Protect and defend the rights or property of the Company
Prevent or investigate possible wrongdoing in connection with the Service
Protect the personal safety of Users of the Service or the public
Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
3. Children's Privacy
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
App Store Compliance
iOS App Store
Our application fully complies with Apple's App Tracking Transparency framework, ensuring your privacy across digital platforms. Before engaging in any activity tracking across other companies' apps and websites, we will explicitly request your permission. In accordance with Apple's privacy guidelines, we maintain transparent data collection practices, which are detailed in our App Store listing under the "App Privacy" section. All data collection and usage strictly adheres to both this Privacy Policy and our App Store listing disclosures, ensuring consistency and transparency in our privacy practices.
Google Play Store
For our Android users, we maintain strict compliance with Google Play's ecosystem requirements. We request only those permissions that are essential for core app functionality, as detailed in our Google Play Store listing. Our practices fully align with Google Play's Developer Program Policies regarding user data privacy and protection. For comprehensive information about our data collection and handling practices on Android, we encourage you to review our Data Safety section on the Google Play Store listing, which provides detailed insights into how we protect and manage your information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA). These rights are designed to give you control over your personal information and ensure transparency in our data practices.
Your Right to Know encompasses comprehensive access to information about our data collection and usage practices. You can request detailed information about the personal information we collect about you, how we use it, and who we share it with. We will provide you with specific details about the personal information we've collected, explain how your data is used in our datasets, and disclose the categories of third parties who may receive your information.
The Right to Delete enables you to request the deletion of your personal information from our systems. While we will honor such requests, there are certain exceptions where we may need to retain some information, such as when it's necessary to provide you with our services or comply with legal obligations.
Your Right to Opt-Out of Sales gives you control over the commercial use of your data. You can choose to opt out of all data sales, with separate opt-out options available for different types of data. We process these opt-out requests within 48 hours, and importantly, exercising this right will not impact the quality or availability of our core services.
The Right to Non-Discrimination ensures that exercising your privacy rights will not result in any discriminatory treatment. We will not deny you services, charge different prices, or provide a different quality of service based on your privacy choices.
Regarding our commercial food datasets, we maintain strict boundaries: we only sell or license food-related data, never health or personal data. You can opt out of data sales while continuing to use our service, and you can request comprehensive information about how your food data has been used.
To exercise your CCPA rights, you can either email us at hello@gymii.ai or use the privacy controls in our app settings. We will respond to your requests within 45 days. To protect your privacy, we will verify your identity before processing any requests, which may require additional verification information.
European Privacy Rights (GDPR)
For users in the European Economic Area (EEA), the General Data Protection Regulation (GDPR) provides specific rights regarding your personal data. Our processing of your data is based on clear legal grounds: explicit consent for food photo collection and commercial datasets, contractual necessity for core services, and legitimate interests for app improvement and security measures.
The Right to Access gives you comprehensive visibility into your data. You can request information about what personal data we hold, how we use it, who we share it with, and how long we retain it. We provide this information in a clear, portable format to ensure transparency.
Through the Right to Rectification, you can ensure your data remains accurate and complete. We will correct any inaccuracies in your personal data upon request and notify relevant third parties of these corrections where possible.
The Right to Erasure, or "right to be forgotten," allows you to request deletion of your personal data. We process these requests within 30 days, though some exceptions apply for legal compliance. Note that previously anonymized data in existing datasets may not be removable due to technical limitations.
The Right to Restrict Processing provides additional control over how your data is used. You can request limits on data processing while we verify accuracy or as an alternative to deletion. We will notify you before lifting any processing restrictions.
With the Right to Data Portability, you can receive your data in a structured, common format and transfer it to other service providers. Where technically feasible, we can transfer your data directly to another provider at your request.
The Right to Object empowers you to oppose certain types of data processing. You can object to processing based on legitimate interests, opt out of direct marketing, and object to processing for research purposes, all without affecting your access to core services.
We maintain special considerations for different data types. For commercial food datasets, we require explicit consent and provide opt-out options, ensuring anonymization before commercial use. Health and fitness data receives enhanced protection, is never included in commercial datasets, and is used solely for personalized recommendations with revocable access.
To exercise your GDPR rights, contact us at hello@gymii.ai or use our in-app privacy settings. We respond to requests within 30 days. For verification purposes, we may request additional information, but we limit this to what's necessary to confirm your identity.
Regarding cross-border transfers, we prioritize data storage within the EU where possible. All transfers are protected by appropriate safeguards, including Standard Contractual Clauses, and recipients must comply with GDPR requirements.
Contact Us
If you have any questions about this Privacy Policy, You can contact us at hello@gymii.ai