AIGymLabs logo AIGYMLABS
How It Works Screens FAQ
Lang EN / FR
EN FR
Get the App
Install

AIGYMLABS

Language

EN / FR
EN FR
How It Works Screens FAQ
Get the App

AIGymLabs - Workouts — Privacy Policy

Effective date
4 September 2026
Last updated
4 September 2026

This Privacy Policy describes how LaboGymIA inc., a Québec corporation operating AIGymLabs, processes personal information when you use the AIGymLabs - Workouts mobile app, visit aigymlabs.com, and contact us through support conversations.

This policy applies to account creation, training-program generation, workout logging, subscription validation, product reliability operations, and support workflows. Current version URL: https://aigymlabs.com/privacy.

1. The short version

  • We do not sell your personal information.
  • We do not use your data for advertising or audience brokerage.
  • We do not run third-party behavioral trackers in the app.
  • Apple and Google handle payment rails; we receive subscription status and transaction references, not full card numbers.
  • Training records are designed as on-device-first, with sync only for account continuity and service operation.
  • Primary infrastructure region is Canada (AWS Canada Central, Montréal).
  • An account is required to use cross-device sync and adaptive-program features.
  • Core app data categories are limited to account/identity data and training data, plus minimal technical logs for security/reliability.
  • Training-related inputs can constitute sensitive health-adjacent information and are handled with elevated access controls.
  • AIGymLabs is not a hospital, clinic, or licensed medical provider; outputs are fitness-program recommendations.
  • You can request export and deletion, and use in-app account deletion where available.

2. What we collect

2.1 Account information

Email address, account identifiers, language preference, and optional profile setup inputs you provide for training personalization.

Sign-in methods and associated data
Sign-in method Data received Important notes
Email + password Email, password verifier, account id Passwords are stored only as salted/hashed credentials.
Sign in with Apple Apple stable user identifier, optional relay email If you enable Hide My Email, we receive Apple relay addresses, not your direct inbox.
Sign in with Google Google account identifier and email Used only for authentication/account linkage, not ad targeting.

2.2 Authentication tokens

Session and refresh tokens required for secure sign-in continuity and API authorization.

Token types and storage controls
Token type Where stored Purpose
Access token Secure storage: iOS Keychain / Android Keystore Authorizes short-lived API calls for active sessions.
Refresh token Secure storage: iOS Keychain / Android Keystore Issues new access tokens without repeated login prompts.
PKCE verifier/challenge material Ephemeral auth flow state Protects public-client sign-in flows against interception/replay.

2.3 What you tell AIGymLabs - Workouts about your training

  • Goals (strength, hypertrophy, performance priorities), experience level, and split constraints.
  • Available equipment, exercise preferences, replacement choices, and movement limitations.
  • Program variables generated for you (sets, reps, load guidance, RIR, rest, tempo, volume progression).
  • Some entries may reveal health-adjacent context (injury notes or restriction patterns); these are treated as sensitive.

2.4 Your training history

Logged outcomes such as loads used, reps achieved, RIR entries, completed/missed sets, session completion markers, and block-level progression history used for adaptation.

2.5 Technical information

  • App version, OS version, device model, and reliability diagnostics.
  • Security and abuse-prevention telemetry needed to protect accounts and service integrity.
  • Operational logs necessary for sync conflict handling and incident response.

2.6 Our website

When you use aigymlabs.com, we process minimal request logs, anti-abuse/security events, and basic diagnostics. Standard web server logs are retained for up to 90 days unless longer retention is required for active security investigations or legal compliance.

2.7 Your subscription

For paid access, we receive product identifier, entitlement status, transaction reference identifiers, renewal/cancellation status, and store-country metadata required for entitlement support and accounting controls.

2.8 What we do not collect

  • No sale-ready audience dossiers and no disclosure to data brokers.
  • No disclosure of your training data to insurers or employers for profiling decisions.
  • No continuous background location tracking for advertising.
  • No contact-list scraping, microphone surveillance, or camera surveillance pipelines.
  • No full payment-card number storage.

3. No trackers, no ad business

AIGymLabs is not an ad-network product. We do not run third-party cross-app behavioral tracking in the app experience and we do not monetize personal information through advertising exchanges.

4. How your data is used

  • Generate and adapt evidence-based resistance-training programming.
  • Authenticate users, secure sessions, prevent abuse, and protect accounts.
  • Operate app reliability, sync integrity, and support workflows.
  • Validate subscription access and maintain legal/accounting records.
  • Comply with legal duties and enforce platform terms.

5. About automation and “AI”

AIGymLabs uses automated decision logic to generate and revise workouts from your inputs and logged outcomes. These outputs are fitness programming recommendations, not medical diagnosis, treatment, or regulated clinical decision-making.

6. Legal bases for processing

Legal bases used for personal data processing
Legal basis When it applies Examples
Contract To deliver app functionality you request Account login, program generation, sync
Legitimate interests Security, fraud prevention, reliability Operational diagnostics and incident handling
Legal obligation Where records are required by law Compliance, dispute-resolution records
Consent Only where law requires consent Optional processing controls

7. Where your data lives, and who can touch it

Primary application infrastructure is hosted in AWS Canada (Central) in Montréal. Access is role-limited and controlled under least-privilege principles.

At launch, the app is not distributed in the EEA, UK, or Switzerland. If data is transferred across borders in the future, we rely on available legal transfer mechanisms. Canada is recognized by the European Commission as providing an adequacy framework for certain commercial organizations.

Service provider roles
Provider type Role Data scope
Amazon Web Services (Canada Central, Montréal) Cloud hosting and managed infrastructure Application and storage operations data
Apple App Store / Google Play Subscription payment processing Entitlement status and transaction references
Support tooling User support and issue resolution Conversation content and account lookup fields

8. How long we keep it

  • Active account and training records: retained while your account is active.
  • Deleted-account operational buffers: retained only for bounded legal/security obligations, then deleted or de-identified.
  • Website server/security logs: up to 90 days by default unless needed longer for active incidents.
  • Support and billing compliance records: retained for statutory limitation and accounting windows.

9. Your rights

Subject to applicable law, you may request access, correction, portability/export, deletion, restriction, and withdrawal of consent where consent is the legal basis. You may also request de-indexing under Québec Law 25 where applicable and request information about automated-decision logic used to generate recommendations.

10. If the GDPR or UK GDPR applies to you

You may request access, rectification, erasure, restriction, objection, and data portability where legally available, and you may lodge a complaint with your local supervisory authority.

11. If you are in California

California residents may request disclosure of categories and specific pieces of personal information collected, deletion of eligible data, correction of inaccuracies, portability where applicable, and non-discrimination for exercising privacy rights. We do not sell personal information and do not share personal information for cross-context behavioral advertising.

12. Security

  • Role-based access controls, transport encryption, and security monitoring.
  • Password handling with salted hashing; no plaintext password storage.
  • PKCE-enabled sign-in flows for public-client OAuth hardening.
  • Secure token storage using iOS Keychain and Android Keystore.

13. Children

AIGymLabs is not intended for children below the age of digital consent required by applicable law. If you believe a child provided personal information, contact us for investigation and removal.

14. Changes

We may revise this policy for legal, technical, or product reasons. Material updates are posted on this page and may also be highlighted in-app.

15. Contact

LaboGymIA inc.

Brossard, QC, Canada

Privacy: [email protected]

Support: [email protected]

Policy URL: https://aigymlabs.com/privacy

LaboGymIA inc. · Brossard, Québec · Privacy: [email protected] · Support: [email protected]

AIGymLabs

Program once. Rewritten every week as you get stronger.

Available on iOS and Android

Explore

  • How It Works
  • Screens
  • Membership
  • FAQ

Legal

  • Privacy
  • Terms
  • Delete your account

Waitlist

Join the waitlist

Support information and legal notices are available in the app.

© 2026 AIGymLabs. Built for serious strength training.