Personal Data Processing Policy
This is a translation. In case of discrepancy, the Spanish version prevails. Versión en español
This policy is issued in compliance with Colombia's Statutory Law 1581 of 2012 (Habeas Data) and Decree 1377 of 2013. It is in force from its publication until it is replaced by a later version.
1. Data Controller
| Controller (Responsable del Tratamiento) | Leonardo Sierra (natural person) |
|---|---|
| Address | Carrera 7 # 67-35, Bogotá D.C., Colombia |
| Email for exercising your rights (Habeas Data) | ziorus@gmail.com |
| Safety / adverse event channel | ziorus@gmail.com and the in-app screen “Report a safety issue”, in Settings |
Because the Controller is a natural person, the Controller is not required to register in the National Registry of Databases (RNBD) with the Superintendence of Industry and Commerce (SIC), Colombia's data protection authority (Decree 090 of 2018).
2. What data we process, why, and on what basis
We process the data needed for the app to work and, to detect failures and improve it, technical diagnostic and usage data (see the table). We do not use advertising or track your activity across apps or websites. The legal basis for all processing is your authorization (consent) —prior, express and informed— given during onboarding or, for sensitive data, on a separate consent screen (see section 3). Usage analytics is optional and is also authorized separately (see the table).
| Data | Purpose | Where it lives |
|---|---|---|
| Your account's name and email (from Google or Apple), user identifier | Creating your account, signing you in, identifying you | Firebase Authentication / Firestore |
| If you sign in with Apple: a token issued by Apple | Revoking, when you delete your account, the “Sign in with Apple” permission you gave the app | Firestore, accessible only from the server; deleted when you delete your account |
| Training preferences: goal, level, days/week, minutes, equipment, units, coach voice | Building and adjusting your routine and the experience | Firestore |
| Coach style preference: the app language and, if you use the app in Spanish, the country or language variant you choose for how the coach speaks (by default, your phone's region if it is among the available countries; otherwise, neutral Spanish) | Adapting the coach's language, vocabulary, form of address and, where possible, accent | Only on your phone (see the paragraph below this table) |
| Points and progress: repetitions, form, session, date, balance, streak | Gamification with verified points; showing your progress | Firestore |
| Video and audio of the live coaching session | So the AI coach can see your technique and correct you in real time | Transmitted to Google (Gemini); see section 4. We do not store them. |
| Record of your consents (by purpose and version) | Legal proof of your authorization | Firestore |
| (If you take out Premium) Purchase and subscription: the purchase history and the ownership of your subscription —which plan you have, whether it is active, when it renews or expires, the product identifier, the store and the purchase environment | Managing your Premium subscription: activating paid access, checking whether it is still active, and applying the free-plan limit | A mirror of the payment status on our servers, accessible only from the server; the purchase history is managed by RevenueCat (U.S.), linked to your user identifier (see the paragraph below this table and section 8). Payment is charged by Apple; we do not process your card data |
| (Optional) Health profile that you write | So the coach can adapt to your health context | Only on our servers, separate from your identity; retention: 365 days from its last use |
| (Optional, within the health profile) What you write in its chat | Suggesting the data for your profile; you confirm what is saved | Sent to Google (Gemini) at that moment, through our server; the chat is not stored (Google may retain it briefly for abuse monitoring, as in section 4) |
| (Optional) Physical Activity Readiness Questionnaire for Everyone (PAR-Q+) | Knowing whether you should consult a professional before training, and adjusting your plan | Only on your phone: your answers are not stored; what is stored is whether you answered or skipped it and, if any answer was “Yes”, a signal of that. None of this leaves your phone |
| (Optional, with the health permission) Whether you felt pain or discomfort at the end of a session | Recommending that you consult a professional if there was pain | Not stored: it is used only at that moment, on your phone, and never leaves it |
| (Optional) Body scan: photos of your body → body composition estimate (% fat, muscle mass) | Estimating your body composition for tracking | See section 5. The photo is not stored; the estimate is, with retention (section 7) |
| Crash reports: when and where the app failed, with technical data about the device | Detecting and fixing failures | Google (Firebase Crashlytics), with an installation identifier and without your account; Google may process them in the U.S. and in other countries |
| (Optional) Usage analytics: usage events (for example, that you opened the app, that a session started or ended, how many repetitions were counted or an error code), with technical data about the device | Knowing how the app is used in order to improve it | Google (Google Analytics for Firebase), with an installation identifier and without your account, only if you turn it on (when you create your account or in Settings → Privacy) and until you turn it off. Google may process them in the U.S. and in other countries |
About the coach style preference. It is a style preference, not your nationality, and you can change it at any time. It lives only on your phone: when each session starts, it is sent to our coach server solely to compose the instructions that Google (Gemini) receives, which Google handles like the rest of the session (see section 4). It is not stored on our servers or used for advertising, and it is deleted when you delete your account. The accent is not guaranteed: it is an AI voice and may sometimes sound more neutral.
About your Premium subscription (RevenueCat). If you take out the paid plan, payment is charged by Apple (which acts as the seller): we do not receive or process your card data. To manage the subscription we use RevenueCat, Inc. (a United States company) as a data processor: we send it your app user identifier, and RevenueCat keeps the purchase history associated with that identifier (which plan, renewals, cancellations and refunds) to tell us whether your paid access is active. This involves an international transfer of data (see section 8). When you delete your account, we ask RevenueCat to delete your subscriber record; that request is best-effort and, if RevenueCat did not respond, some residual purchase history could remain in that service. Premium may also be granted through a promo code, which involves no payment and no RevenueCat intervention.
3. Sensitive data and its optional nature
Some data is sensitive under Article 5 of Law 1581 because it reveals your health status: the body composition estimate, the health profile you enter, any sign of pain or discomfort in the post-session feedback (which is not stored), and the PAR-Q+ questionnaire signal that some answer was “Yes” (only on your phone).
- You are not required to provide them. Article 6 of Law 1581 prohibits making a service conditional on providing sensitive data. The app works without them: the body scan, the health profile and the PAR-Q+ questionnaire are optional features that are activated only if you give specific consent for each of them.
- Separate consent for each purpose, which states what is collected, for what purpose, and the international transfer.
- You can revoke your authorization at any time (see section 6). For the PAR-Q+, the signal kept on your phone is deleted when you delete your account or uninstall the app.
4. The live AI coach (Google Gemini)
Real-time correction is performed by Google's Gemini technology. To do this, the video and audio of your session are transmitted to Google's servers while you train.
- We do not store the video or the audio: they are processed in real time and are not saved in our systems.
- Google, as our processor (encargado), does not use your video/audio to train its models. It may keep them for a short period (up to 55 days) solely to detect abuse of its service, under the terms of the paid Gemini API; after that, they are deleted. They are not used for any other purpose.
- Google may process them in the United States and in other countries where it operates: the Gemini API does not guarantee a region (see section 8).
- If you turn on coach memory (optional, subject to separate consent, in the Coach tab), when each session starts or resumes, we also send to Google, together with the rest of the session, what you did last time in that exercise: when it was, how many repetitions, how your technique was, your personal best and your streak. It does not include your health data or your points, and it is not stored separately: it comes from your progress. You can turn it off at any time.
5. The body scan (optional)
If you turn on the scan and give your consent for it:
- You take or upload photos of your body, which are sent securely to our server and from there to Google's model, which returns an estimate of your body composition in ranges.
- The original photo is not stored on our servers (Google may retain it briefly for abuse monitoring, as in section 4).
- We only keep the estimate (the ranges and the date), as sensitive health data, so you can see your trend over time.
- It is an indicative estimate, not a medical diagnosis, and it does not replace an assessment by a health professional.
- You can delete all your scan data —and revoke your consent for the scan— with a button in the app.
6. Your rights (Habeas Data) and how to exercise them
As the data subject (titular), you have the right to know, update and rectify your data; request proof of your authorization; be informed of how it is used; file complaints with the SIC; revoke your authorization and request deletion where applicable (Article 8, Law 1581).
- From the app: account deletion and body scan deletion are available in the app itself, and usage analytics can be turned on or off in Settings → Privacy.
- By email: by writing to ziorus@gmail.com.
Response times (Law 1581): queries are answered within 10 business days (extendable by 5 more) and claims within 15 business days (extendable by 8 more). Revoking consent for a purpose does not erase the proof that you gave it at the time, but it stops processing for that purpose going forward.
7. Retention and minimization
- Sensitive data (scan estimate, health profile) is kept for up to 365 days (counted from when each estimate was made and from the last use of the health profile), or until you delete your account, revoke your authorization or request deletion, whichever comes first. The scan history shown in the app is limited to the 12 most recent.
- Your account and preferences data is kept for as long as the account exists.
- Your purchase and subscription data is kept for as long as your account exists: the mirror on our servers is deleted when you delete your account and, at that moment, we ask RevenueCat to delete your subscriber record (best-effort; see sections 2 and 8).
- When you delete your account, we delete your profile, your consents, your points, your health data, your scans and the rest of the data linked to your account. Three technical traces remain for a limited time: database recovery copies, for up to 7 days, used only to recover from an incident; Google Cloud's technical access logs, which may include your account identifier, for 30 days; and an audit log of access to sensitive data, for 400 days, with a pseudonymous identifier that changes every day and without your email or account identifier, used only for security and accountability.
- Diagnostic and usage data is not linked to your account (it uses an installation identifier), so it is not deleted when you delete your account: Google keeps it for a limited time, according to Firebase's policies and settings.
- Scan photos and the coach's video/audio are not stored by us.
8. International data transfer
Your data is processed on Google servers located in the United States (Google Cloud region us-east1). In addition, Google may process in the United States and in other countries where it operates: the coach's video and audio (section 4), what you write in the health profile chat, the scan photos while they are analyzed (section 5), the crash reports and, if you turn it on, the usage analytics. The United States is on the SIC's list of countries with an adequate level of data protection (External Circular 005 of 2017); for other countries, the transfer is based on your express and unequivocal authorization, which includes these destinations. Our infrastructure and AI provider is Google (Firebase, Google Cloud and the Gemini API), which acts as data processor (encargado del tratamiento) under Google's Cloud Data Processing Addendum (which incorporates Standard Contractual Clauses for international transfers). If you are in the European Union, the transfer of your data to Google relies on those Standard Contractual Clauses, not only on your authorization.
For subscription management we add a second processor, RevenueCat, Inc., based in the United States, which processes your user identifier and your purchase history (see section 2). The United States is on the SIC's list of countries with an adequate level of data protection (External Circular 005 of 2017) and, for this transfer, we also rely on your express and unequivocal authorization, which includes this destination.
9. Security
- All communications are encrypted in transit (HTTPS/TLS).
- The sensitive data we store on our servers —the scan estimate and the health profile— can be accessed only by the server; the app cannot read them directly. The PAR-Q+ questionnaire signal stays on your phone.
- Per-user isolation and an audit log of access to sensitive data.
- Our coach server and our server functions only serve the genuine app: each request carries proof from Apple (App Attest, through Firebase App Check), and requests without it are rejected.
10. Minors
Trainer is intended for people aged 18 or older. The app applies an age check and is not intended for minors.
11. Changes to this policy
We may update this policy. We will publish the current version at this same address, with its “last updated” date. Substantial changes regarding sensitive data will be communicated to you and, when the law requires it, we will ask for your authorization again.
12. Contact
For any matter concerning your personal data: ziorus@gmail.com. You may also turn to the Superintendence of Industry and Commerce (SIC) as the data protection authority in Colombia.