AIGymLabs

AIGymLabs - Workouts — Privacy Policy

Effective date: 4 September 2026 · Last updated: 4 September 2026

AIGymLabs - Workouts is a product of LaboGymIA inc., a company incorporated in Quebec, Canada ("we", "us"). AIGymLabs is the brand we trade under; LaboGymIA inc. is the legal entity accountable for your personal information.

This policy explains what we collect, why, where it lives, and what you can make us do about it. It applies to the AIGymLabs - Workouts mobile app, to aigymlabs.com, and to any support conversation you have with us.

The current version is always at https://legal.aigymlabs.com/privacy/.


The short version


What we collect

Two categories, and they are the whole of it: who your account belongs to, and what you log about your training. Everything below is one of those two, plus the unavoidable technical traces of an app talking to a server.

1. Account information

You choose how to sign in, and what we receive depends on which you pick.

How you sign inWhat we receive
Email and passwordYour email address, and a cryptographic hash of your password — never the password itself
GoogleYour email address, your Google account identifier, and your name where you allow it
AppleYour Apple account identifier, an email address, and your name if you choose to share it

We never receive your Google or Apple password, and we never ask for it.

If you use Apple's "Hide My Email", we get a relay address that forwards to you and never see your real one. That works fine, and we recommend it. Two consequences worth knowing: if you turn the relay off in your Apple settings we can no longer reach you by email, and support replies come to that relay rather than your usual inbox.

Sign-in is operated for us by Amazon Cognito, in our Canadian region.

2. Authentication tokens

When you sign in, our identity provider issues your device three short strings that keep you signed in. They are personal information, so here is exactly what they are:

TokenWhat it doesHow long it lives
ID tokenTells our servers which account is askingAbout an hour, then it is replaced
Access tokenAuthorises account actions — deleting your account, for instanceAbout an hour
Refresh tokenBuys new tokens without making you sign in againUp to 90 days of use

What matters about them:

Because the refresh token lasts up to 90 days, anyone with your unlocked phone can open the app as you. That is the trade for not having to type a password before every set. Use a device passcode.

3. What you tell AIGymLabs - Workouts about your training

To build a program we ask for:

These are the inputs to the training science, not a profile of you. Body weight, height, age and sex size your starting loads and your progression — for example, the strength standard that suggests you have outgrown a beginner program. Your date of birth is also the age check described under Children below. None of it is shared with anyone.

You can change any of these answers, at any time, from More → Profile.

4. Your training history

Every workout you log: exercises, sets, weights, repetitions, how close to failure each set felt, tempo, rest, session duration, and any notes you write on an exercise. This is the product. It is what makes next week's program different from last week's.

We treat this as sensitive health and fitness information. Under the GDPR, data about your body and your physical capability can be "data concerning health"; under California law it is "sensitive personal information". We do not argue about the label — we apply the stricter rule:

Body weight, goal, and experience level in the section above are part of this same category and get the same treatment.

5. Technical information

When the app talks to our servers we necessarily process your IP address and basic device and app version information, for security, abuse prevention, and diagnosing failures. This is our own server logging, not an analytics product — see "No trackers, no ad business" below.

6. Our website

aigymlabs.com serves information about the app and hosts these policies. Visiting it does not require an account and we do not track you across other sites. Our host records standard server logs — IP address, page requested, user agent — which we keep for 90 days for security.

If the site later uses analytics or any non-essential cookie, this section will name it and the site will ask for consent before setting it. Nothing in this policy authorises advertising cookies, because we do not intend to use any.

7. Your subscription

If you subscribe to Premium, Apple or Google handles the payment and we receive only what we need to unlock the features you bought:

We do not receive your card number, your billing address, your bank, or your full name from the store. We could not charge you if we wanted to.

The store keeps its own records of the transaction under its own privacy policy, and cancelling or requesting a refund happens there — see section 6 of the Terms of Service.

8. What we do not collect


No trackers, no ad business

This is short on purpose.

The people who necessarily process data for us are the short list in "Where your data lives" below — hosting, sign-in, and app-store billing. They act on our instructions, and none of them is an advertising business relationship.

This is a promise about how the app is built today, and we intend to keep it. If we ever add crash reporting or product analytics, we will name the provider in this policy before it ships, make it opt-in, and never make it a condition of using the app. We will not quietly add a tracker and update a date at the top.


How your data is used

We use it to:

  1. Build and adjust your program. This is automated: your logged performance drives next week's sets, loads, and whether a deload is scheduled. There is no human reviewing your workouts.
  2. Keep your history available across reinstalls and devices.
  3. Operate and secure the service, including preventing abuse of our servers.
  4. Answer you when you contact support.
  5. Manage your subscription, if you have one.
  6. Comply with law, when we are legally required to.

About automation and "AI"

The app's programming is algorithmic: a defined set of training-science rules — volume landmarks, progression logic, fatigue management — applied to the numbers you enter. It is deterministic, not a chatbot, and your data is not used to train any machine-learning model. If we later add a feature that sends your data to a third-party AI service, we will name that service here and ask before doing it.

Because the program is generated automatically, you always have the right to question a recommendation and to change any of it. Nothing AIGymLabs - Workouts produces has a legal or financial effect on you.


Where the GDPR, the UK GDPR, or Quebec's Law 25 applies, we rely on:

WhatBasis
Your account, sign-in, and keeping you signed inPerformance of a contract (GDPR Art. 6(1)(b)) — without an account there is no app to provide
Your training data, and generating your program from itYour explicit consent (Art. 9(2)(a)), because we treat this as health data. Contract alone is not a sufficient basis for that category, so we ask for consent rather than assume it
Security, abuse prevention, fixing crashesLegitimate interests (Art. 6(1)(f))
Anything optional — analytics, marketing emailConsent, withdrawable at any time
Records we must keepLegal obligation

Withdrawing consent for your training data means the app cannot do its job, so withdrawing it and deleting your account are effectively the same act, and the app offers exactly that in one place. Withdrawal is not retroactive to programs already generated, and it never affects the lawfulness of what we did before you withdrew.

We ask for that consent up front, in plain words, before you enter anything — not buried in a checkbox you cannot find again.


Where your data lives, and who can touch it

Your data is stored in Amazon Web Services' Canada (Central) region, in Montreal. We chose a Canadian region deliberately.

Our service providers:

ProviderWhat they doWhere
Amazon Web ServicesHosting, identity, video deliveryCanada (Montreal); video is cached on a global content network
Apple, GoogleSign-in, app distribution, subscription billingTheir own infrastructure, under their own privacy policies

Exercise demonstration videos are licensed content served from our own storage. Streaming one requires a short-lived, signed link tied to your app; the files are not publicly reachable, by us or anyone else.

If you sign in with Google or Apple, that provider necessarily learns that you use AIGymLabs - Workouts. We cannot prevent that, and it is the trade-off for not having to create another password.

Where we offer the app. At launch, AIGymLabs - Workouts is not distributed in the European Economic Area, the United Kingdom, or Switzerland. We have therefore not appointed a representative under GDPR Article 27. If we expand into those markets we will appoint one, name them here, and update this policy before the app becomes available there.

If you use the app from outside Canada, your data is transferred to and stored in Canada. For anyone in the EEA, the European Commission recognises Canada as providing adequate protection for personal data handled by commercial organisations.


How long we keep it

Deleting the app from your phone does not delete your account. Deleting your account does delete your history, everywhere, permanently.


Your rights

Wherever you live, you can:

Under Quebec's Law 25 you also have the right to de-indexing — to require that we stop disseminating personal information — and the right to be informed about automated decisions, which the section on automation above addresses.

How to exercise them: email privacy@aigymlabs.com or use support inside the app. We will acknowledge within 10 business days and respond within 30 days. We may ask you to confirm you control the account's email address — we are not going to hand your training history to whoever asks for it. There is no fee.

If we get it wrong, you can complain to the Commission d'accès à l'information du Québec or to the Office of the Privacy Commissioner of Canada, and to your own local privacy regulator wherever you are.

If the GDPR or UK GDPR applies to you

You have all of the above as statutory rights: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Two more specifics:

See "Where we offer the app" above for our Article 27 position.

If you are in California

We honour the CCPA/CPRA rights below for every user, wherever they live, rather than gating them by address.


Security

Passwords are hashed and never stored in a form we can read. Data is encrypted in transit and at rest. Access to production systems is restricted and requires multi-factor authentication. Video content is served only over signed, expiring links.

Specific to signing in:

No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects you, we will notify you and the relevant regulators as the law requires.


Children

AIGymLabs - Workouts is not intended for anyone under 18, and the app enforces that: onboarding asks for your date of birth and will not let you continue if it puts you under 18. We do not knowingly collect information from anyone younger. If you believe a minor has created an account, write to us and we will delete it.

Progressive resistance training in a growing body is a subject for a professional who can see the person. That is another reason for the age line.


Changes

If we change this policy materially, we will tell you in the app before the change takes effect — not by quietly updating a date at the top. The effective date above always reflects the current version.


Contact

Our Privacy Officer is reachable at privacy@aigymlabs.com. Law 25 and PIPEDA require us to publish the role and how to reach it, which is what this is; we will give you the individual's name on request.