Privacy Policy

Effective September 15, 2026

This notice describes Gym Terminal 2.0.11 and later. Personal-cloud features become available when you install a version that includes them. For earlier releases, see the February 2026 privacy notice and legacy account requests.

Gym Terminal is provided by Harshvir Dhaliwal and is designed for local-first fitness tracking with optional online features you choose to use. This notice explains how the app handles information on your device and when a feature contacts another service. For privacy questions or requests, contact [email protected].

Data stored on your device

Workouts, profile details, nutrition entries, habits, medicines, conversations, and app settings are stored locally on your device. The local app database and backup exports are not encrypted by Gym Terminal.

Removing the app or clearing its storage may remove local data. Before doing so, keep an off-device backup or check that your chosen personal-cloud destination confirms a successful sync or recovery backup. Pending changes are not protected by an earlier backup.

Files you choose

Gym Terminal reads an import file only after you select it. A portable file export is created when you request one; you choose where to save or share it. File import restores data once and does not enable personal-cloud sync.

Backup exports are readable files that may contain sensitive fitness, nutrition, medicine, profile, and chat information. Keep them in a location you trust.

Optional personal-cloud sync

You can choose to sync saved data to your own Apple iCloud account using a private CloudKit database on iOS 17 or later, or to your Google account using Google Drive's hidden app data storage on Android. No Gym Terminal account is needed, and this sync feature does not send your saved database through a Gym Terminal sync server. Apple or Google provides the cloud storage and receives the uploaded content and the account and connection information needed to operate it under its own terms and privacy practices.

Sync includes saved workouts, templates, programs and progress, exercises and their images, weight and body measurements, nutrition and water entries, recipes, habits and completions, medicines and logs, saved conversations, dashboard layouts, profile details, and portable preferences. It excludes unfinished workouts, active timers, device permissions, notification registrations, credentials, and API keys. Opaque record, revision, and device identifiers, revision relationships, and timestamps accompany saved content so devices can reconcile changes and deletions.

Google Drive access uses the app-data permission, drive.appdata. The app uses the account email and identifier returned by Drive to display the connected account and prevent accidental account mixing. It does not request access to all files in your Drive.

Installing the app alone does not start a personal-cloud lookup. Choose Restore data and a cloud source to look for a previously completed sync or recovery backup, review the saved data, and confirm Restore and enable sync to restore with ongoing sync. Google may require account selection or authorization. iOS 16.4 supports offline use and file restore; automatic iCloud sync requires iOS 17 or later.

The iCloud and Google Drive datasets are separate. To move between iOS and Android, use a portable backup file. Once enabled, sync transfers saved changes during supported foreground and background activity. Background delivery is best-effort; review the connected account, sync status, and last successful sync before relying on another device's copy.

A cloud account change or loss of access pauses sync and preserves pending local work. Reconnection requires an explicit choice before data is associated with another account. Disconnecting sync stops the connection without deleting existing local or cloud copies.

Cloud recovery and deletion

Sync propagates saved edits and deletions. When personal-cloud access is enabled and available, the app also keeps dated recovery snapshots separately from live sync in that cloud account. Check the last confirmed off-device backup separately from sync status; opening a share sheet does not confirm a saved backup.

Deleted records, superseded content, and recovery snapshots have a 30-day recovery period. Expired content is removed on the next successful online maintenance pass, so cleanup may happen later when a device is offline or access fails. Unresolved saved conflict alternatives remain available until you resolve them. Minimal opaque deletion and lineage metadata can remain after content removal to stop older devices from restoring deleted records.

Delete permanently requests removal of the selected content from app-managed sync history, related assets, and recovery snapshots. Delete cloud data removes the app-managed cloud content and recovery backups while keeping this device's current records. Minimal deletion or reset markers may remain. The app tracks cloud deletion until the provider confirms it; connected devices reconcile changes when they next connect. Apple's or Google's own storage and retention practices also apply.

These controls do not remove independently exported files, copies shared with another service, or copies held by disconnected devices before they reconnect. Those copies remain under their respective storage controls. Restoring an explicitly permanently deleted record from a separate backup creates a new record identity.

AI Coach and your provider

AI Coach is optional. When you send a message without a saved provider connection, the app sends recent conversation messages, any saved conversation summary, and your language and unit preferences through the Gym Terminal coach server to OpenRouter and its configured model provider, currently Z.ai. The default model is GLM-5.3-Flash. The server uses a separate installation identity to authorize requests and enforce usage limits; opening the app does not start a coaching request.

You can instead add your own OpenAI, Anthropic (Claude), Google (Gemini), OpenRouter, or compatible HTTPS connection in Settings. Text requests then go directly to that endpoint using your provider API key and do not use the default coach allowance. A failed personal connection is not silently replaced with the default service.

Voice input uses supported on-device speech recognition. Only the resulting transcript is sent with the conversation context; the microphone recording is not uploaded to the coach server. Spoken replies use supported local speech playback. Voice is unavailable when the required local language support is absent, and microphone capture stops when you leave the app.

The default coach server keeps submitted chat content and full or partial replies in a private archive for troubleshooting and quality review. Its configured retention is seven daily archive periods, with scheduled cleanup while the service operates. The archive includes dictated text but no audio recordings. This cleanup does not automatically delete independently exported server copies, backups, or information held by model providers. Requests sent directly through a personal provider connection bypass this archive.

The coach service also stores installation credential hashes, conversation ownership identifiers, and usage and request metadata needed to authorize requests and prevent abuse. Installation credential records have no automatic expiry. Conversation ownership metadata expires after 30 days of inactivity, and duplicate-request metadata expires 30 days after its request. Web-server access logs can include IP addresses, requested paths, and request timing.

When you choose to share your latest workout, the app also sends a limited summary of that workout, including exercises, sets, weights, repetitions, distance or time, and totals. This summary excludes workout notes, local record identifiers, and custom exercise names. Anything you type into the conversation is included as message content, so share only information you want that provider to receive.

The default coach server receives your request and IP address. OpenRouter and its model provider receive the forwarded content; OpenRouter receives the server's connection information. A personally configured provider receives requests directly from your device. Provider retention, training, processing, and deletion practices depend on the provider, model, and account settings. Gym Terminal does not promise that providers keep no logs or never use submitted content for training.

On mobile, your API key is stored in protected device storage separately from app settings and backup exports. On web, the key uses browser session storage by default; choosing Remember on this browser stores it in that browser until you remove the connection or clear its storage. Browser storage is not mobile secure storage.

Saving a connection does not send a chat request. Test connection sends a small test prompt and your key to the configured provider; it does not send your workout history or conversations. Provider charges may apply.

Food lookup and exercise videos

Nutrition, barcode lookup, and meal-photo analysis are unavailable in this release. Existing nutrition records remain on your device and in supported backups, and are included if you enable personal-cloud sync. This release does not send food searches or meal photos to a lookup or analysis provider.

Exercise screens may refresh the catalog and load exercise animations from the Gym Terminal content service. Requests include catalog-version or exercise identifiers and normal connection information such as your IP address; they do not upload your saved workout database.

Exercise videos can open content hosted by third parties such as YouTube. Those services receive the information normally sent when loading their content and apply their own terms and privacy policies.

Diagnostics and app services

This release does not enable Supabase app accounts or database sync, subscriptions, advertising, or automatic analytics and crash reporting. Personal-cloud sync is optional as described above. Recent technical error summaries stay on your device. You can review, clear, or choose to share them from Diagnostics.

If a distributed build has over-the-air updates enabled, the update service may receive the connection and app-version information needed to check for and download an update. This is separate from workout tracking and does not upload your local workout database.

Device permissions

The app may ask for access needed for a feature you start, such as microphone access for a voice message, notifications, choosing an exercise image, or selecting files for import and export. Voice recording is user initiated and stops when you leave the app. Nutrition and barcode features are unavailable and do not request camera access.

You can review or change permissions in your device settings. Features that depend on a denied permission may be unavailable.

Your choices

You can edit or delete records inside the app, create a portable backup from Import & Backup, and manage personal-cloud sync, recovery, and deletion from its controls. Keep exported files in a location you trust.

Remove connection clears your personal AI credentials from this device or browser and returns subsequent coaching requests to the default service. It does not delete your local conversations or data already received by a provider. Delete local conversations in the app and use the provider's own controls for copies it holds. Files you save or share outside the app remain wherever you chose to send them.

Deleting local conversations or removing the app does not automatically erase server chat archives, cloud backups, or older account data. For requests concerning information held by the Gym Terminal service, email [email protected] with the app version and enough context to identify the request. Do not send passwords, API keys, or a complete health backup. We may need additional information to locate records and verify your request.

Earlier versions

Earlier releases, including those named Fit Terminal, may use different services. Refer to the notice supplied with your version or contact us. Updating the app does not itself delete information previously sent to a service. This notice does not establish that older Supabase accounts, records, or service logs have been deleted.