Privacy Policy — Simple Gym
Last updated: 3 September 2026
Simple Gym (“the app”, “we”, “us”) is a workout-tracking app published by ThinkWorks SIA, which trades as King Digital. This policy explains what data the app collects, how it is used, and the choices you have. By using the app you agree to this policy.
1. Who is responsible for your data
ThinkWorks SIA, a company registered in Latvia and trading as King Digital, is the data controller for the personal data described in this policy. You can reach us about anything in it at thinkworkssia@gmail.com.
2. Data we collect
- Account data. When you sign in with Apple or Google, we receive your email address and an authentication identifier so we can create and secure your account. If you set a profile photo or @username, these are stored on our server as part of your account. Your profile photo is saved as a small image and is visible on your own profile, to friends you connect with, and on any workout you choose to share via a public link.
- Fitness data. The workouts, exercises, sets, reps, weights, body weight and body measurements you log. This is stored on your device and synced to our server so your data is available across your devices. Some of this can say something about your health, so we treat it as sensitive and process it only with your consent, which you give by choosing to log it.
- Progress photos & custom-exercise images. These are stored only on your device, encrypted at rest, and are never uploaded to our server or shared with anyone. If you turn on the optional iCloud photo backup, a copy of your progress photos is saved to your own private iCloud (Apple’s iCloud, under your Apple ID) so they survive reinstalling the app and sync across your Apple devices. That is your iCloud, managed and encrypted by Apple, not our server. It is off by default.
- Apple Health (HealthKit). With your explicit permission, the app may read your body weight and write completed workouts to the Health app. This data is exchanged only with Apple Health on your device, under Apple’s control.
- Advertising & device data. If you use the free version, we show ads through Google AdMob. AdMob and Google may collect your advertising identifier and device/usage information to serve and measure ads (see “Advertising” below).
- Product analytics. On iPhone, and only if you have agreed to it, we use Amplitude to understand how the app is used: app opens and sessions, which screens you visit and which controls you tap, plus basic device and app-version information. It is not used to build an advertising profile of you (see “Analytics” below).
- Anonymous tap map. The app reports where on a screen people tap, as a grid position on a named screen. These reports go to our own server and are added straight into a running count per grid square. No identifier, account link, IP or timestamp is stored with them, so the result cannot be traced back to you or to any individual device.
- Server logs. Our web server records the usual technical request logs, including IP address, for security and troubleshooting.
We do not use third-party crash reporters. Crash and performance diagnostics are handled by Apple’s on-device MetricKit only.
3. How we use your data, and our legal basis
| What we do | Legal basis (GDPR Art. 6, and Art. 9 where marked) |
| Create and secure your account, store and sync your training history, and provide Premium | Performance of our contract with you (Art. 6(1)(b)) |
| Store fitness, body-weight and body-measurement data, which can be health-related | Your explicit consent (Art. 9(2)(a)), which you can withdraw by deleting the data or your account |
| Show and measure ads in the free version, and personalise them where allowed | Your consent (Art. 6(1)(a)), collected through Google’s consent form and, on iOS, App Tracking Transparency |
| Product analytics (Amplitude) | Your consent (Art. 6(1)(a)) |
| Send local reminders and progress nudges (notifications you can turn off in your device settings) | Your consent, given through the notification permission (Art. 6(1)(a)) |
| Anonymous tap map, used to improve the layout of screens | Not personal data once stored, since it is aggregated on arrival and holds no identifiers |
| Keep the service secure, prevent abuse, and troubleshoot faults (server logs) | Our legitimate interest in running a secure service (Art. 6(1)(f)) |
4. Advertising
The free version of the app displays ads served by Google AdMob. Google acts as an independent controller of the advertising data it collects. Ads may be personalized (based on your advertising identifier and inferred interests) or non-personalized, depending on your choices:
- App Tracking Transparency (ATT). On iOS we ask whether the app may track you across other companies’ apps and websites. If you allow it, you may see personalized ads. If you decline, ads are non-personalized and the app works the same either way.
- EU/EEA & UK consent. If you are in the European Economic Area, the UK or Switzerland, we show Google’s consent form before any ads load, as required by GDPR.
- Changing your mind. Where the consent form applies to you, you can reopen it at any time in the app, under Profile > Settings > Privacy & ads, and change or withdraw what you agreed to. Withdrawing is as easy as agreeing, and it also stops product analytics. On iOS you can additionally change tracking permission in your device Settings, under Privacy & Security > Tracking.
- Buying Premium removes ads entirely. Premium accounts never load the ad SDK.
Who receives advertising data. Ads are not served by Google alone. If you consent, Google and the advertising partners listed in the consent form may store and read identifiers on your device and use them to select, deliver and measure ads. The full list of those partners, and a per-purpose and per-partner choice, is inside the form itself under “Manage options”. If you decline, ads are non-personalised and that sharing does not happen.
Learn how Google uses data from apps that use its services: policies.google.com/technologies/partner-sites. Google’s privacy policy: policies.google.com/privacy.
5. Analytics
On iPhone we use Amplitude as our product-analytics provider, to see which parts of the app people actually use. Amplitude acts as our processor and stores this data in its European Union region.
- Analytics is off until you have been asked. The SDK starts opted out and collects nothing until the consent flow above has run.
- If you are in a region where consent is required and you decline tracking, it stays off and nothing is sent.
- Session recording is not enabled. We do not record your screen, so your progress photos, body measurements and weights are never captured by analytics.
- The Android version of the app has no analytics SDK at all.
Amplitude’s privacy policy: amplitude.com/privacy.
6. How your data is shared
- Our server. Account and fitness data is stored on our own server (located in the EU) and is private to your account. We only ever return your own fitness data to you; there is no cross-user access to it. The one exception is your profile photo, @username and display name, which by design are visible to other users you connect with as friends, and your profile photo also appears on any workout you choose to share via a public link.
- Google AdMob and its advertising partners. Advertising and device data is processed by Google, and by the advertising partners you agreed to in the consent form, to serve and measure ads, as described above.
- Amplitude. Product-analytics events, where you have agreed to them, as described above.
- Apple and Google. Sign-in and purchases are handled by Apple and Google under their own privacy policies. We never see your payment details.
- Apart from the advertising partners described above, we do not share your personal data with third parties for their own marketing, and we never sell it.
7. Where your data goes
Our server and our Amplitude project are both in the European Union. Google may process advertising data outside the EEA, including in the United States, under the European Commission’s Standard Contractual Clauses and its own transfer safeguards, as set out in Google’s privacy policy.
8. Data retention & deletion
We keep your account and fitness data for as long as your account exists. You can delete your account from within the app at any time; this permanently removes your account, the fitness data stored on our server, and your server-stored profile photo. You can also request deletion at kingdigital.lv/apps/simple-gym/delete-account without installing the app.
Progress photos live only on your device and are removed when you delete them or uninstall the app, unless you turned on iCloud photo backup, in which case a copy stays in your private iCloud until you delete it (in the app, or from your iCloud storage in iOS Settings). Server access logs are kept for up to one month and then rotated away. Analytics and advertising data held by Amplitude and Google is retained under their own policies.
9. Your rights
Under the EU and UK GDPR you have the right to access your personal data, to correct it, to receive a copy in a portable format, to have it deleted, and to object to or restrict certain processing. Where we rely on your consent, you can withdraw it at any time without affecting what was done before you did.
- In the app: edit your profile and your logged data, change your ad and analytics consent in Profile > Settings > Privacy & ads (shown where the consent form applies to you), and delete your account under Profile > Account.
- By email: write to thinkworkssia@gmail.com for anything else, including a copy of your data. We answer within one month.
If you think we have handled your data badly, you can complain to your local data protection authority. In Latvia, where we are based, that is the Data State Inspectorate (Datu valsts inspekcija), www.dvi.gov.lv.
10. Security
Account access uses token-based authentication. Progress photos and custom-exercise images are encrypted on your device. Data in transit is protected with HTTPS.
11. Children
The app is not directed to children under 13 (or the minimum age required in your country, for example 16 in parts of the EEA), and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
13. Contact
Questions about this policy or your data? Email us at thinkworkssia@gmail.com.