Privacy Policy
CalGym
This Privacy Policy explains what information CalGym (operated by Erebos Lab) collects, how it is used, who it is shared with, and the choices you have. By using CalGym you agree to the practices described here.
Data-safety summary
At a glance, here is the data the app collects, whether it is linked to your identity, and whether it is used to track you across other companies’ apps and websites.
| Data category | Linked to you | Used for tracking | Purpose |
|---|---|---|---|
| Health & Fitness (on-device only) | No | No | Provide workout tracking, history, and progress — the core function of the app. This data is stored only on your device (local SQLite) and is never transmitted to us or any third party. Finished workouts are written back to Apple Health only with your permission. |
| App Preferences (on-device only) | No | No | Remember your preferences and fire local rest-timer alerts. Stored on your device; no push tokens are collected and no remote notifications are sent. |
What we collect
Health & Fitness (on-device only)
- Workouts, exercises, sets, reps, and weights you log
- Bodyweight and progress measurements
- Heart rate and active energy read from Apple Health during a workout (iOS, only if you grant HealthKit access)
Provide workout tracking, history, and progress — the core function of the app. This data is stored only on your device (local SQLite) and is never transmitted to us or any third party. Finished workouts are written back to Apple Health only with your permission.
App Preferences (on-device only)
- Settings, units, and rest-timer preferences
Remember your preferences and fire local rest-timer alerts. Stored on your device; no push tokens are collected and no remote notifications are sent.
What we do NOT do
- CalGym has no account and no backend — your workout data never leaves your device except when you explicitly export it or hand it to CalDesk.
- We do not use analytics, advertising, or any third-party tracking SDKs.
- Apple Health data is read and written only on your device with your permission and is never uploaded.
- We do not sell your personal information.
Third parties who process your data
We share data only with the processors below, each bound to use it only to provide their service to us. Items marked "unverified" are placeholders we must confirm and name before this policy is treated as final.
- Apple Health (HealthKit) — On-device only — reads heart rate / active energy during a workout and writes finished workouts to the Fitness app, with your permission. HealthKit data never leaves your device through CalGym.
- CalDesk (app-to-app deep link) — Optional: tapping “Add to CalDesk” hands a workout summary to the CalDesk app on the same device via a deep link. There is no shared backend; nothing is sent to a server.
How we use your information
- Operate and personalize the app and its core features.
- Maintain your account, authenticate sessions, and provide support.
- Process payments and manage subscriptions/entitlements.
- Keep the service secure and prevent fraud and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Improve the product through aggregated, de-identified analytics.
Data retention
We keep personal information only as long as needed to provide the service. Account data is retained while your account is active and for a short recovery window after deletion, then deleted or anonymized. Billing records are retained as required by tax and accounting law. Backups are purged on a rolling basis.
Your rights and choices
Depending on your jurisdiction you may access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. You can delete your account and its server-side data from within the app, or by emailing us. We respond within 30 days.
Children’s privacy
The app is not directed to children under 13 (under 16 in the EEA/UK) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, least-privilege access, and audit logging. No system is 100% secure; please use a strong, unique password.
Changes to this policy
We may update this policy. Material changes will be reflected by a new "Last updated" date and, where required, announced in the app.
Contact
Privacy questions? Email [email protected].