Who this is
GymBunny is a workout-tracking iOS app made by an independent developer. This policy covers the GymBunny iOS app (including its Apple Watch companion) and the account data it can optionally sync to the cloud. Questions? See Contact below.
Data stored on your device
By default, GymBunny keeps everything on your device only: your workout logs, programs, body measurements, custom exercises, and settings. If you use the app as a guest (no account), nothing ever leaves your device — there is no background upload to check.
Optional account & cloud sync
Signing in with Sign in with Apple or Google Sign-In turns
on optional cloud sync, so your data is backed up and can follow you to a new device. Once
you're signed in, GymBunny syncs to Cloud Firestore (Google Cloud), hosted
in the EU (region eur3). What syncs:
- Your email address and display name, from Apple/Google sign-in
- Your workout history (exercises, sets, reps, weights, dates, notes)
- Your programs, including any you've customized or created — private to your account unless you publish one as a share link, which is described below
- Body measurement entries you log — body weight in kilograms, plus any of the optional measurements you track (waist, chest, upper arm, thigh, forearm, hips, calf, neck, shoulders) in centimetres, and any goals you set for them
- Custom exercises you've added
- Achievements you've unlocked
- Your profile & goals — units, training goal, weekly workout goal, daily steps goal, active-calories goal, height, target weight, and — only if you choose to set it — sex
- A progress snapshot (carrots earned, rank, level, streak, personal records, daily quests, and your carrot transaction history) so those features work the same across devices
None of this requires a password we can see — sign-in is handled entirely by Apple or Google, and we never see or store your credentials.
Special-category data. Several of the items above — your body measurements (body weight and any of the optional measurements you track, such as waist, chest or arms), height, target weight, sex, and your training history — are health data under GDPR Article 9, a special category that needs its own legal basis to process. Ours is your explicit consent: every one of these fields is optional, GymBunny works fully as a guest with nothing leaving your device, and any of it only reaches our cloud because you chose to sign in and chose to enter it. You can withdraw that consent at any time by deleting your account (see Your controls: export & delete below), which erases the cloud copy right away.
Programs you publish as a share link
Everything above is stored for you alone. Publishing a share link is the one thing that
isn't, so it gets its own section. In the app you can put one of your programs behind a
six-character link (getgymbunny.com/p/AB3K7Q). Publishing uploads a copy of
that program — its name, training days, exercises, sets, reps and target weights — to the
same database described above. While the link is on, anyone who has the code can
read that copy, with or without a GymBunny account. There is no password on a
share link: the code is the only thing between the program and whoever it reaches.
The link carries the plan and nothing else — no workout history, no personal records, no body measurements, no achievements, no profile, and not your name. Someone opening your link cannot tell from it who wrote the program. The link counts how many people have added it, but not who they are; no record of an individual recipient is kept.
You can switch a link off in the app at any time, which stops it opening for anyone else, and deleting your account deletes the links you published along with the rest of your cloud data. Neither reaches a copy someone has already added: adding a shared program puts a copy in that person's own library, and that copy is theirs to keep. This is how the feature is built, not a gap in it — an added program is a copy, not a live view of yours, which is the same reason nothing you change afterwards reaches them. A link also expires on its own — at most 7 days after you publish it — though re-publishing the same program starts a fresh window. So treat publishing a link as making that version of the program public for as long as the link is on and unexpired.
Workout results you publish as a link
Separate from program links above, you can also share your workout results as a link. In
the app, finishing a workout (or picking several) and choosing "Share as a link" publishes
a rendered summary behind its own six-character code
(getgymbunny.com/w/AB3K7Q): the workout name(s) and date(s), total volume,
sets, minutes and personal-record count (and the same breakdown per workout), and each
exercise's name, muscle group, set count, and whether it was a personal record. If you're
on Pro and choose to include the full coach report, the link also carries per-set weights
and reps, your top set and estimated one-rep max, a comparison with your previous session,
your per-exercise effort rating and notes, and your current streak/weekly-workout context —
a free share never includes any of that, only the totals above. While the link is
on, anyone who has the code can open it, with or without a GymBunny account. There
is no password on it, same as a program link.
The link doesn't carry your name. There's nothing to add or import either — whoever opens it just sees the rendered page; nothing is written back to their own account, and no record of who viewed it is kept.
Unlike a program link, a workout link also expires on its own — at most 7 days after you publish it — and can't be edited or refreshed afterwards: sharing something new always mints a brand-new link. You can still switch a link off earlier, in the app, at any time, and deleting your account removes every workout link you published, the same way it removes your program links.
Apple Health data
If you grant Health access, GymBunny reads your step count, resting heart rate, active calories, and recent workout count from Apple Health to display them on your Home screen. These readings stay on your device — they are not included in the data described above and are never uploaded to our cloud sync.
Separately, when you finish a workout in GymBunny (on iPhone or Apple Watch), we write that workout — and its active-calorie total, if available — to Apple Health, if you've granted permission. That entry lives inside Apple's own Health app on your device; whether it syncs further (e.g. via iCloud) is controlled entirely by your own device settings, not by GymBunny.
Analytics
Anonymous usage analytics and crash reporting are off by default. You can turn on "Share anonymous usage" in Settings → Privacy & security, which enables Firebase Analytics and Crashlytics; turning it back off disables both immediately. This toggle never affects your workout data or account.
Your controls: export & delete
Export my data — from Settings → Privacy & security, you can generate a complete JSON file of your profile, goals, programs, workout history, body entries, and custom exercises, built right on your device, anytime.
Delete account & data — from the same screen, you can permanently delete your account. This immediately deletes all of your cloud data — every subcollection listed in How long we keep your data below, your profile document, and any program or workout links you published — then deletes your sign-in account and wipes the app's local data on your device. This is not a soft delete and there is no waiting period — it happens right away. (For your security, if it's been a while since you last signed in, the app may ask you to sign in again before it can complete this step.)
One thing deletion cannot reach: if someone added a program from a link you had published, their copy sits in their own library and stays there. Deleting your account takes down the link, not the copies — see Programs you publish as a share link.
How long we keep your data
If you sync to the cloud, we keep that data until you delete your account or ask us to — see Your controls: export & delete above. Deleting your account is immediate and permanent: it wipes every subcollection tied to your account (workout history, programs, body entries, custom exercises, achievements, daily quests and quest claims, your carrot ledger, Burrow Shields, and streak milestones), the profile document itself, and any program or workout share links you published, then deletes your sign-in account. There is no grace period and no soft-delete — once you confirm, it's gone.
Selling & advertising
We do not sell your personal data. GymBunny does not currently show ads.
Changes to this policy
If GymBunny's data practices change, we'll update this page and the effective date above.
Contact
Questions about this policy or your data? Contact us at support@getgymbunny.com.