Legal

Privacy
Policy

Last updated: March 2025

1. Data Controller

Milltech Consulting Group — Argentina

Email: gymbro@milltechcg.com

If you have any questions about this Privacy Policy or about the processing of your personal data, you can contact us at the address indicated above.

2. Applicable Legal Framework

The processing of personal data carried out by Gymbro is governed by the Argentine National Law No. 25.326 on Personal Data Protection and its implementing regulations.

Users located in the European Union are additionally entitled to the rights recognized by the General Data Protection Regulation (GDPR — EU Regulation 2016/679).

3. General Principles

We process your personal data in a minimal, lawful and transparent manner, only to the extent necessary to:

  • Provide you with the Gymbro service
  • Improve the user experience of the App
  • Comply with legal obligations

We delete or anonymize data when it is no longer necessary for the purposes for which it was collected.

4. Information We Collect

4.1 Information You Provide

When you create your profile in Gymbro, we collect:

DataPurpose
NamePersonalization of the experience
AgeGeneration of the personalized plan
Weight and heightGeneration of the personalized plan
Biological sexPhysiological calculations
GoalDirection of the AI plan
Training focusType of training
Available daysWeekly distribution
EquipmentExercise adaptation
InjuriesExclusion of exercises
Sunday feedbackAdjustment of the weekly plan

Legal basis: Performance of the subscription contract (Law No. 25.326, Art. 5).

Retention: While the account remains active. Upon account deletion, data is removed within 30 business days.

4.2 Usage Data and Training History

We automatically record:

  • Sessions marked as completed
  • Selected plan option (A or B)
  • Muscle groups worked per session
  • App usage frequency

Purpose: Feed the AI's weekly memory to improve plan personalization.

4.3 Technical and Device Data

  • Anonymous device identifier
  • Operating system and version
  • App version
  • Error logs
  • Usage timestamps

Legal basis: Legitimate interest. Retention: Logs deleted after 7 days. Identifiers anonymized after that period.

4.4 Email Data

When you sign up, we collect your email address for authentication, service notifications and communications related to your subscription.

5. Use of Artificial Intelligence

Training plans are generated by an artificial intelligence large language model (LLM). To do so, we send the model your full profile and training history as a structured prompt.

AI providers used:

Anthropic (Claude) — Primary provider
OpenAI (GPT) — Fallback provider

Both providers act as data processors under data processing agreements. Your data is not used to train these providers' general AI models.

6. Third Parties and Service Providers

To operate Gymbro, we use the following third-party services:

ProviderFunction
Firebase (Google)Authentication, database and backend
RevenueCatSubscription and payment management
App Store / Google PlayDistribution and payment processing
AnthropicAI plan generation
OpenAIAI plan generation (fallback)

Your data may be transferred to servers located outside Argentina (including the United States). In such cases, we ensure that appropriate safeguards are in place to protect your information.

7. Push Notifications

The App sends push notifications for:

  • Sunday (6:00–8:00 PM): weekly feedback reminder and generation of the next plan
  • Day 28 of trial: notice of free trial expiration
  • Day 30: notice that the free trial has ended (no automatic charge is made; subscribing is optional)

You can disable push notifications from your device settings at any time.

8. Data We Do NOT Collect

Gymbro does not collect or access:

  • Real-time health data (heart rate, sleep, etc.)
  • Integration with wearables (Apple Watch, Garmin or others)
  • GPS location data
  • Camera or microphone content
  • Sensitive biometric data beyond what is declared in the profile
  • Device contact data

9. Your Rights

In accordance with Law No. 25.326 and, where applicable, the GDPR, you have the following rights:

AccessKnow what personal data of yours we process and for what purpose.
RectificationCorrect inaccurate or incomplete data directly from your profile in the App.
ErasureRequest the deletion of your data when it is no longer necessary or when you withdraw your consent.
RestrictionRequest restriction of processing in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interest.

To exercise any of these rights, write to us at gymbro@milltechcg.com. We will respond within the applicable legal timeframes.

10. Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encrypted communications (HTTPS/TLS)
  • Secure authentication via Firebase Authentication
  • Restricted access to backend system data
  • Hashed password storage

No security system is infallible. In the event of a security breach affecting your data, we will notify you as required by applicable regulations.

11. Account Deletion

You can request the deletion of your account and all your data from Profile → Manage account → Delete account, or by sending an email to gymbro@milltechcg.com. Data will be deleted within 30 business days following the request.

12. Changes to This Policy

We may update this Privacy Policy at any time to reflect changes in our practices or in applicable regulations. We will notify you with reasonable advance notice before the changes take effect. The current version will always be available in the App and on our website.

13. Contact and Complaints

For inquiries, exercise of rights or complaints regarding the processing of your personal data:

Email: gymbro@milltechcg.com

If you believe your rights have been violated, you may also file a complaint with the Agencia de Acceso a la Información Pública (AAIP) of Argentina.

arrow_back Back to home MillTech CG