AIGymLabs - Workouts — Privacy Policy
Effective date: 4 September 2026 · Last updated: 4 September 2026
AIGymLabs - Workouts is a product of LaboGymIA inc., a company incorporated in Quebec, Canada ("we", "us"). AIGymLabs is the brand we trade under; LaboGymIA inc. is the legal entity accountable for your personal information.
This policy explains what we collect, why, where it lives, and what you can make us do about it. It applies to the AIGymLabs - Workouts mobile app, to aigymlabs.com, and to any support conversation you have with us.
The current version is always at https://legal.aigymlabs.com/privacy/.
The short version
- We do not sell your personal information, and we do not use it for advertising. Not to anyone, not in aggregate, not "anonymised".
- There are no third-party analytics tools or trackers in this app. Nothing in it reports what you do to another company.
- If you subscribe, Apple or Google takes the payment. We never see your card, and all we learn is whether your subscription is active.
- Your training data lives on your phone first. AIGymLabs - Workouts is built to work offline; the database on your device is the original, not a cache.
- Your data is stored in Canada (Montreal region), not the United States.
- An account is required to use AIGymLabs - Workouts, because your training history belongs to you across devices and reinstalls, and a subscription has to attach to someone. You can create one with Google, Apple, or an email address and password — your choice.
- We collect two things: what identifies your account, and what you log about your training. That is the whole list. There is no third category hiding further down this page.
- We treat your training data as sensitive health information, because in several places the law does, and because it is nobody else's business what you can lift.
- We are not a medical provider. AIGymLabs - Workouts builds training programs from numbers you give it. It does not diagnose, treat, or advise on any medical condition. See the Terms of Service.
- You can delete your account and everything in it from inside the app, at any time, without emailing anyone.
What we collect
Two categories, and they are the whole of it: who your account belongs to, and what you log about your training. Everything below is one of those two, plus the unavoidable technical traces of an app talking to a server.
1. Account information
You choose how to sign in, and what we receive depends on which you pick.
| How you sign in | What we receive |
|---|---|
| Email and password | Your email address, and a cryptographic hash of your password — never the password itself |
| Your email address, your Google account identifier, and your name where you allow it | |
| Apple | Your Apple account identifier, an email address, and your name if you choose to share it |
We never receive your Google or Apple password, and we never ask for it.
If you use Apple's "Hide My Email", we get a relay address that forwards to you and never see your real one. That works fine, and we recommend it. Two consequences worth knowing: if you turn the relay off in your Apple settings we can no longer reach you by email, and support replies come to that relay rather than your usual inbox.
Sign-in is operated for us by Amazon Cognito, in our Canadian region.
2. Authentication tokens
When you sign in, our identity provider issues your device three short strings that keep you signed in. They are personal information, so here is exactly what they are:
| Token | What it does | How long it lives |
|---|---|---|
| ID token | Tells our servers which account is asking | About an hour, then it is replaced |
| Access token | Authorises account actions — deleting your account, for instance | About an hour |
| Refresh token | Buys new tokens without making you sign in again | Up to 90 days of use |
What matters about them:
- They are stored on your device, in the operating system's secure credential store — the iOS Keychain or the Android Keystore — not in ordinary app files and not in a browser cookie.
- They identify your account to us and nothing else. They are not used to recognise you on other apps or websites, they carry no advertising identifier, and they are never shared with a third party.
- Signing out deletes them from your device and tells the identity provider to stop honouring the refresh token. Deleting your account destroys them permanently.
- We do not use them to track where you are or what else you do. There is no tracking technology in this app, in the sense Apple's App Tracking Transparency and the CCPA use that word.
Because the refresh token lasts up to 90 days, anyone with your unlocked phone can open the app as you. That is the trade for not having to type a password before every set. Use a device passcode.
3. What you tell AIGymLabs - Workouts about your training
To build a program we ask for:
- your training goal — build muscle, lose weight, cardiovascular fitness, lean strength, or a functional hybrid mix;
- your experience level, and on the hybrid-racing path, how far into racing you are;
- your sex or gender (woman, man, or prefer not to say);
- your date of birth;
- your body weight and your height, and whether you prefer kilograms or pounds, kilometres or miles;
- how active your day is outside training;
- how many days a week you train and how long a session runs, and — if you set your own split — how many of those days are upper-body days and how many are leg days;
- whether you want programmed cardio in your week;
- the equipment you have access to;
- the muscle groups you want to train, and which you want to prioritise.
These are the inputs to the training science, not a profile of you. Body weight, height, age and sex size your starting loads and your progression — for example, the strength standard that suggests you have outgrown a beginner program. Your date of birth is also the age check described under Children below. None of it is shared with anyone.
You can change any of these answers, at any time, from More → Profile.
4. Your training history
Every workout you log: exercises, sets, weights, repetitions, how close to failure each set felt, tempo, rest, session duration, and any notes you write on an exercise. This is the product. It is what makes next week's program different from last week's.
We treat this as sensitive health and fitness information. Under the GDPR, data about your body and your physical capability can be "data concerning health"; under California law it is "sensitive personal information". We do not argue about the label — we apply the stricter rule:
- It is used for one purpose: generating and adjusting your program. Not profiling, not advertising, not scoring you for anyone else.
- It is never sold, never shared for advertising, and never disclosed to an insurer, employer, or data broker. There is no circumstance in which we would, and no business model here that would want to.
- It is not combined with data from other sources about you. We have no other sources.
- We do not infer anything about your health beyond training variables — no risk scores, no diagnoses, no conclusions about conditions. The app is not a medical device and does not pretend to be one.
- In the EEA and the UK, we process it on your explicit consent, which you give by entering it and can withdraw at any time by deleting your account or the entries in question. See "Legal bases" below.
Body weight, goal, and experience level in the section above are part of this same category and get the same treatment.
5. Technical information
When the app talks to our servers we necessarily process your IP address and basic device and app version information, for security, abuse prevention, and diagnosing failures. This is our own server logging, not an analytics product — see "No trackers, no ad business" below.
6. Our website
aigymlabs.com serves information about the app and hosts these policies. Visiting it does not require an account and we do not track you across other sites. Our host records standard server logs — IP address, page requested, user agent — which we keep for 90 days for security.
If the site later uses analytics or any non-essential cookie, this section will name it and the site will ask for consent before setting it. Nothing in this policy authorises advertising cookies, because we do not intend to use any.
7. Your subscription
If you subscribe to Premium, Apple or Google handles the payment and we receive only what we need to unlock the features you bought:
- whether your subscription is active, which plan (monthly or yearly), and when the current period ends;
- an anonymous purchase identifier from the store, so we can tell that a renewal belongs to the same subscription;
- whether you have already used a free trial, which the store determines.
We do not receive your card number, your billing address, your bank, or your full name from the store. We could not charge you if we wanted to.
The store keeps its own records of the transaction under its own privacy policy, and cancelling or requesting a refund happens there — see section 6 of the Terms of Service.
8. What we do not collect
- No payment card details. If you subscribe, Apple or Google processes the payment and we receive only whether your subscription is active.
- No contacts, photos, microphone, precise location, or advertising identifiers.
- No health data from Apple Health or Google Fit.
- No progress photos, and no body measurements beyond the body weight and height above — no circumferences, no body-fat percentage, no scans.
- No third-party trackers, advertising SDKs, or social-media pixels in the app. Nothing in it reports your activity to another company.
- Nothing at all from your Google or Apple account beyond the sign-in fields in the table above — no contacts, no calendar, no Drive, no iCloud.
No trackers, no ad business
This is short on purpose.
- No third-party analytics. No Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude, no Segment, no equivalent. None.
- No advertising SDKs, no ad networks, no attribution or install-tracking kits, no social-media pixels. The app contains no such code.
- No advertising identifiers. We do not read Apple's IDFA or Android's advertising ID, and we do not ask for permission to track you, because we have nothing to track you with.
- We never sell your personal information. Not for money, not for anything else of value — which is what "sell" means under California law.
- We never share it for advertising. Not for targeted ads, not for cross-context behavioural advertising, not for building audiences or look-alikes, not "anonymised" or "aggregated" for a marketing partner.
- No data brokers, insurers, or employers. We do not disclose your training data to them, and there is no arrangement under which we would.
- No profiling of you for anyone else. Your data is used to build your program, and for nothing else.
The people who necessarily process data for us are the short list in "Where your data lives" below — hosting, sign-in, and app-store billing. They act on our instructions, and none of them is an advertising business relationship.
This is a promise about how the app is built today, and we intend to keep it. If we ever add crash reporting or product analytics, we will name the provider in this policy before it ships, make it opt-in, and never make it a condition of using the app. We will not quietly add a tracker and update a date at the top.
How your data is used
We use it to:
- Build and adjust your program. This is automated: your logged performance drives next week's sets, loads, and whether a deload is scheduled. There is no human reviewing your workouts.
- Keep your history available across reinstalls and devices.
- Operate and secure the service, including preventing abuse of our servers.
- Answer you when you contact support.
- Manage your subscription, if you have one.
- Comply with law, when we are legally required to.
About automation and "AI"
The app's programming is algorithmic: a defined set of training-science rules — volume landmarks, progression logic, fatigue management — applied to the numbers you enter. It is deterministic, not a chatbot, and your data is not used to train any machine-learning model. If we later add a feature that sends your data to a third-party AI service, we will name that service here and ask before doing it.
Because the program is generated automatically, you always have the right to question a recommendation and to change any of it. Nothing AIGymLabs - Workouts produces has a legal or financial effect on you.
Legal bases for processing
Where the GDPR, the UK GDPR, or Quebec's Law 25 applies, we rely on:
| What | Basis |
|---|---|
| Your account, sign-in, and keeping you signed in | Performance of a contract (GDPR Art. 6(1)(b)) — without an account there is no app to provide |
| Your training data, and generating your program from it | Your explicit consent (Art. 9(2)(a)), because we treat this as health data. Contract alone is not a sufficient basis for that category, so we ask for consent rather than assume it |
| Security, abuse prevention, fixing crashes | Legitimate interests (Art. 6(1)(f)) |
| Anything optional — analytics, marketing email | Consent, withdrawable at any time |
| Records we must keep | Legal obligation |
Withdrawing consent for your training data means the app cannot do its job, so withdrawing it and deleting your account are effectively the same act, and the app offers exactly that in one place. Withdrawal is not retroactive to programs already generated, and it never affects the lawfulness of what we did before you withdrew.
We ask for that consent up front, in plain words, before you enter anything — not buried in a checkbox you cannot find again.
Where your data lives, and who can touch it
Your data is stored in Amazon Web Services' Canada (Central) region, in Montreal. We chose a Canadian region deliberately.
Our service providers:
| Provider | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosting, identity, video delivery | Canada (Montreal); video is cached on a global content network |
| Apple, Google | Sign-in, app distribution, subscription billing | Their own infrastructure, under their own privacy policies |
Exercise demonstration videos are licensed content served from our own storage. Streaming one requires a short-lived, signed link tied to your app; the files are not publicly reachable, by us or anyone else.
If you sign in with Google or Apple, that provider necessarily learns that you use AIGymLabs - Workouts. We cannot prevent that, and it is the trade-off for not having to create another password.
Where we offer the app. At launch, AIGymLabs - Workouts is not distributed in the European Economic Area, the United Kingdom, or Switzerland. We have therefore not appointed a representative under GDPR Article 27. If we expand into those markets we will appoint one, name them here, and update this policy before the app becomes available there.
If you use the app from outside Canada, your data is transferred to and stored in Canada. For anyone in the EEA, the European Commission recognises Canada as providing adequate protection for personal data handled by commercial organisations.
How long we keep it
- Your account and training history: until you delete them. Your history is the point of the app; we are not going to quietly age it out.
- After you delete your account: removed from our live systems promptly and purged from backups within 30 days.
- Support conversations: kept for two years, then deleted.
- Server logs: kept for 90 days for security purposes.
- Authentication tokens: an hour for the working tokens, up to 90 days for the one that renews them. Signing out ends all of them immediately.
- Subscription records: for as long as you have an account, plus whatever period tax and accounting law requires us to keep a record of a sale. Apple and Google keep their own records of the transaction under their own policies, and we cannot delete those for you.
Deleting the app from your phone does not delete your account. Deleting your account does delete your history, everywhere, permanently.
Your rights
Wherever you live, you can:
- know what we hold about you and why;
- get a copy of it in a portable format — AIGymLabs - Workouts has a built-in "Export my data" that produces a machine-readable file without asking us;
- correct anything inaccurate;
- delete your account and its contents, from inside the app;
- object to or restrict processing that relies on our legitimate interests;
- withdraw consent for anything optional;
- not be discriminated against for exercising any of this. There is no reduced-functionality tier for people who exercise their privacy rights.
Under Quebec's Law 25 you also have the right to de-indexing — to require that we stop disseminating personal information — and the right to be informed about automated decisions, which the section on automation above addresses.
How to exercise them: email privacy@aigymlabs.com or use support inside the app. We will acknowledge within 10 business days and respond within 30 days. We may ask you to confirm you control the account's email address — we are not going to hand your training history to whoever asks for it. There is no fee.
If we get it wrong, you can complain to the Commission d'accès à l'information du Québec or to the Office of the Privacy Commissioner of Canada, and to your own local privacy regulator wherever you are.
If the GDPR or UK GDPR applies to you
You have all of the above as statutory rights: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Two more specifics:
- Automated decision-making. Your program is generated automatically. It has no legal or similarly significant effect on you — it suggests sets and weights — and you can change or ignore any part of it. You can ask us how a recommendation was reached, and the section on automation above is the honest answer: published training rules applied to your own numbers.
- Complaints. You may complain to your national data protection authority, or to the UK Information Commissioner's Office.
See "Where we offer the app" above for our Article 27 position.
If you are in California
We honour the CCPA/CPRA rights below for every user, wherever they live, rather than gating them by address.
- Categories collected: identifiers (email address, account identifier); characteristics of protected classifications under California or federal law (age and sex or gender, as described above); sensitive personal information (health and fitness data, as described above); commercial information limited to whether your subscription is active and which plan it is; internet activity limited to the technical information above. Nothing else — no geolocation, no biometrics, no payment card or other financial-account information, no inferences drawn for profiling.
- Sources: you; Google or Apple if you sign in with them; Apple or Google for subscription status if you subscribe.
- Purpose: providing the app. That is the entire list.
- We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising — the CCPA's defined terms for both. We have never done either, in the past 12 months or ever.
- We do not use or disclose sensitive personal information beyond what is necessary to provide the app, so the "right to limit" has nothing to limit. We tell you this instead of offering a link that would do nothing.
- Your rights: to know, to access, to correct, to delete, to portability, and not to be retaliated against for using them. Exercise them at privacy@aigymlabs.com or from inside the app — deletion and export are both buttons, not requests.
- Response time: we acknowledge within 10 days and respond within 45 days, extendable once by 45 more if we tell you why.
- Authorised agents may act for you with written permission; we will still verify with you directly before deleting anything.
Security
Passwords are hashed and never stored in a form we can read. Data is encrypted in transit and at rest. Access to production systems is restricted and requires multi-factor authentication. Video content is served only over signed, expiring links.
Specific to signing in:
- The app never handles your password for Google or Apple sign-in, and for email sign-in the password goes to our identity provider, not through our own servers.
- Sign-in happens on a page served by our identity provider, over HTTPS, using the industry-standard authorization code flow with PKCE — which means the app proves each sign-in attempt is its own, and there is no shared secret buried in the app for someone to extract.
- Tokens live in the iOS Keychain or the Android Keystore, encrypted by the operating system and tied to your device.
- If you think someone has access to your account, change your password (or revoke our access in your Google or Apple account settings) and sign out on your devices. Signing out invalidates the stored tokens.
No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects you, we will notify you and the relevant regulators as the law requires.
Children
AIGymLabs - Workouts is not intended for anyone under 18, and the app enforces that: onboarding asks for your date of birth and will not let you continue if it puts you under 18. We do not knowingly collect information from anyone younger. If you believe a minor has created an account, write to us and we will delete it.
Progressive resistance training in a growing body is a subject for a professional who can see the person. That is another reason for the age line.
Changes
If we change this policy materially, we will tell you in the app before the change takes effect — not by quietly updating a date at the top. The effective date above always reflects the current version.
Contact
- LaboGymIA inc., trading as AIGymLabs
- 130-5645 boul Grande Allée, Unit #240
- Brossard, QC J4Z 3G3, Canada
- Privacy requests: privacy@aigymlabs.com
- Support: support@aigymlabs.com
Our Privacy Officer is reachable at privacy@aigymlabs.com. Law 25 and PIPEDA require us to publish the role and how to reach it, which is what this is; we will give you the individual's name on request.