Summary
GainLog stores your workout data locally on your device — it is never sent to our servers. The app uses Firebase to collect anonymous crash reports and usage analytics (no personal information is linked to these), and RevenueCat to handle future Pro subscriptions. If you have Android backup enabled, your workout history is automatically backed up to your Google account via Android Auto Backup.
Information We Collect
All of the following data is stored only on your device and is never transmitted to GainLog's servers.
Workout & fitness data
- Workout logs: exercise name, sets, reps, weight, duration, notes, and date
- Completed set details (individual rep and weight data within each set)
- Body weight entries: date, time, weight, and optional notes
- Workout templates: name, exercise list, and creation date
- Rest days: date and optional note
- Favourite exercises: exercise ID and name
Profile information (all optional)
- Name, age, height, and gender — entered by you during onboarding or in Profile settings
- These are stored in encrypted storage on your device and are not included in Google Drive backups (see Android Auto Backup section below)
App settings & preferences
- Weight unit preference (kg / lbs)
- Weekly and daily workout goals
- Workout reminder time
- Theme preference (Light / Dark / System)
- Biometric lock enabled/disabled state
- Notification preferences (reminders, PR alerts, streak alerts)
Exercise library cache
- Exercise names, muscle groups, animated GIFs, and instructions fetched from the ExerciseDB API are cached locally on your device for up to 24 hours to reduce network requests
Anonymous analytics & crash data
- Firebase Analytics collects anonymous app usage events (screen views, app opens) — no personally identifiable information is linked to these events
- Firebase Crashlytics collects crash reports containing device model, OS version, app version, and stack traces — no personal data is included
Permissions We Request
INTERNET
Required to fetch exercise data (names, GIFs, instructions) from the ExerciseDB API, and to send anonymous crash reports and analytics to Firebase.
POST_NOTIFICATIONS (Android 13+)
Required to display workout reminder notifications. This permission is optional — the app functions fully without it. You will be prompted to grant it only if you enable reminders.
RECEIVE_BOOT_COMPLETED
Required to reschedule your workout reminder alarm after the device restarts. Without this, reminders would stop working after a reboot.
SCHEDULE_EXACT_ALARM
Required to deliver workout reminders at the exact time you set. On Android 12 and above this is auto-granted on install; the system may fall back to an approximate alarm if you revoke it in Settings.
Biometric Lock
GainLog uses the Android Biometric API to optionally lock the app with your fingerprint or face unlock. This feature is disabled by default and only activates if you enable it in Profile → Security & Privacy.
Third-Party Services
Firebase Crashlytics (Google)
We use Firebase Crashlytics to automatically detect and report app crashes, which helps us fix stability issues quickly.
Data collected: Device model, OS version, app version, stack traces, and thread state at the time of the crash. No personally identifiable information is included in crash reports.
Data location: Processed on Google servers in the United States.
Retention: 90 days (Google default).
Firebase Analytics (Google)
We use Firebase Analytics to understand which features are used most, helping us prioritise improvements.
Data collected: App open events, screen views, and anonymous session data. IP addresses are anonymised. No personally identifiable information is linked to analytics events.
Data location: Processed on Google servers in the United States.
Retention: 14 months (Google default).
ExerciseDB API (self-hosted)
GainLog fetches exercise names, animated GIFs, muscle group information, and instructions from a self-hosted ExerciseDB API instance operated by the developer.
Data sent: Only the exercise query parameters (e.g. a search term or exercise ID). No personal data is transmitted.
Third parties: None — this API is self-hosted by the developer. No third-party company receives your data through this service.
Cache: Exercise data is cached on your device for 24 hours, then cleared and re-fetched on next use.
RevenueCat (Pro subscriptions — not yet active)
The RevenueCat SDK is installed in preparation for a future Pro subscription tier. The SDK initialises on app launch and may transmit anonymous device identifiers and app metadata to RevenueCat's servers. Purchases are not currently enabled and no purchase transaction data is collected at this time.
When the Pro tier launches, RevenueCat will be used to manage subscription status and will process purchase history and subscription status via Google Play. GainLog never sees your payment card details — all payment processing is handled by Google Play.
Google Play Billing (Google)
Applies only when Pro features are purchased. All payment processing is handled entirely by Google Play — GainLog never receives or stores payment card details.
Android Auto Backup & Google Drive
Android automatically backs up app data to your Google account when you have backup enabled in your device settings. This means a third party — Google — receives a copy of certain GainLog data.
What IS backed up to Google Drive
-
Your Room database (
workout_database) — containing all workout logs, body weight entries, templates, and the exercise library cache
What is NOT backed up
- Profile preferences (name, age, height, gender) — stored in encrypted storage using device-specific Android Keystore keys, which cannot be transferred between devices. These files are excluded from backup.
- In-progress workout session state — temporary data that is meaningless on a different device
- Image and network cache directories
You can disable Android Auto Backup at any time: Android Settings → Google → Backup → toggle off "Back up to Google Drive".
Google's handling of backup data is governed by the Google Privacy Policy.
Data Retention
- Local data (workouts, body weight, profile, settings): retained on your device until you delete it or uninstall the app
- Firebase Crashlytics crash reports: retained for 90 days (Google default)
- Firebase Analytics data: retained for 14 months (Google default)
- ExerciseDB cache: cleared automatically after 24 hours
- RevenueCat: purchase history retained as required by Google Play and applicable law (only when Pro is active)
Data Security
- Profile preferences (name, age, height, gender) are stored using Android EncryptedSharedPreferences with AES-256 encryption, backed by the Android Keystore
- All network requests (ExerciseDB API, Firebase) use HTTPS — enforced via the app's network security configuration
- Workout data in the Room database is protected by your device's encryption (Android full-disk or file-based encryption)
- The app supports an optional biometric lock requiring fingerprint or face unlock to open the app
- GainLog has no backend servers of its own — there is no GainLog account, no GainLog password, and no GainLog cloud storage
Your Rights
You have the following rights regarding your personal data. Because GainLog stores data locally on your device, most rights can be exercised directly within the app.
Automated decision-making
GainLog does not use automated decision-making or profiling that produces legal or similarly significant effects on you.
Legal basis for processing (GDPR)
- Local workout & profile data: Consent — you voluntarily provide this data by using the app. You may withdraw consent at any time by deleting your data via Profile → Security & Privacy → Delete Account.
- Firebase Crashlytics: Legitimate interest — crash data is necessary to maintain app stability and fix bugs
- Firebase Analytics: Legitimate interest — anonymous usage data helps us understand which features to improve
- RevenueCat (when Pro active): Contract performance — required to fulfil a subscription purchase
Data controller
The data controller for GainLog is Sahil (individual developer).
Contact:
teckrandom@gmail.com
California Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights.
Right to Know
You have the right to know what personal information we collect, use, disclose, and sell. This Privacy Policy describes all categories of personal information we collect and the purposes for which it is used.
Right to Delete
You have the right to request deletion of your personal information. You can delete all local data at any time via Profile → Security & Privacy → Delete Account. For Firebase Analytics and Crashlytics data (which is anonymous and not linked to you personally), uninstalling the app stops further collection.
Right to Opt Out of Sale
GainLog does not sell your personal information to any third party. We have not sold personal information in the preceding 12 months and have no plans to do so.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Exercising these rights will not result in denial of services, different prices, or any other penalty.
To exercise your California privacy rights, contact us at: teckrandom@gmail.com
Children's Privacy
GainLog is not directed at children under the age of 13 and is not intended for use by children. We do not knowingly collect personal information from anyone under 13.
If you are a parent or guardian and believe that a child under 13 has provided personal information through GainLog, please contact us immediately at teckrandom@gmail.com. If we discover that we have inadvertently collected data from a child under 13, we will take prompt steps to delete it.
International Data Transfers
GainLog itself does not transfer your data internationally — your workout data stays on your device.
However, our third-party service providers process data on servers located in the United States:
- Firebase Crashlytics & Analytics (Google) — crash reports and anonymous analytics events are transmitted to and processed on Google's servers in the US. Google participates in the EU-US Data Privacy Framework and provides appropriate safeguards under Standard Contractual Clauses.
- Android Auto Backup (Google) — if you have backup enabled, your workout database is stored on Google's servers. The storage location depends on your Google account settings and Google's infrastructure.
- RevenueCat — the SDK initialises on app launch and may transmit anonymous device identifiers to RevenueCat's servers in the US, even before any purchase is made. When Pro purchases are active, subscription data is also processed there. RevenueCat's international transfers are governed by Standard Contractual Clauses.
By using GainLog with these features enabled, you consent to these transfers under the terms of each provider's privacy policy.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make a material change — such as collecting a new type of data or adding a new third-party service — we will notify you via an in-app notice on the next app launch.
For minor clarifications, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of GainLog after a policy update constitutes your acceptance of the revised policy.
We are not responsible for the privacy practices of third-party services used by GainLog. We encourage you to review their privacy policies directly. If a third-party service we use materially changes its privacy practices in a way that affects you, we will update this policy to reflect those changes.
Governing Law
This Privacy Policy is governed by the laws of Australia/Western Australia. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of that jurisdiction.
Contact Us
For any questions, requests, or concerns about this Privacy Policy or how GainLog handles your data, please contact:
Sahil — GainLog Developer
Email:
teckrandom@gmail.com
We aim to respond to all privacy enquiries within 30 days.