Privacy Policy
최종 업데이트: 2026년 7월 23일
This Privacy Policy explains how SyzUp ("we", "us", "our", "the app") collects, uses, stores, and protects your personal data. SyzUp is operated from the European Union and serves users worldwide. This policy applies regardless of where you access the app from.
By using SyzUp, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the app.
1. Data Controller
For GDPR purposes, the data controller is the individual operator of SyzUp, contactable at the email above.
2. Information We Collect
2.1 Account Information
- Email address
- Display name (nickname)
- Profile avatar (if uploaded)
- Authentication data from Google Sign-In or Apple Sign-In
2.2 Fitness & Health-Related Data
Fitness and body measurement data may qualify as health-related data under certain laws (including GDPR Art. 9). By voluntarily entering this data, you provide explicit consent to its processing as described in this policy. You may withdraw consent at any time by deleting your data or account.
- Workout sessions (exercises, sets, reps, weight lifted)
- Training plans and preferences
- Personal records (PRs)
- Body weight entries
- Exercise progress, XP, and level data
- Workout statistics and history
- Muscle recovery estimates
2.3 Device & Usage Data
- Device type and operating system version
- App version and build number
- Crash reports and performance data (Firebase Crashlytics)
- Anonymized analytics events (Firebase Analytics)
2.4 Media & User-Generated Content
- Profile photos (camera or photo library)
- Personal record videos (optional)
- Social feed posts and comments
- Chat messages between users
2.5 Social Data
- Follow/follower relationships
- Public profile interactions (likes, comments)
2.6 Moderation & Safety Data
To keep the service safe, we process moderation data on the basis of our legitimate interest (GDPR Art. 6(1)(f)):
- Reports you submit about content or other users, and reports concerning your content
- Moderation decisions about your account or content (warnings, suspensions and bans), kept as described in Section 8
- Security logs used to detect and prevent abuse, including IP address (retained for 30 days)
3. Legal Basis for Processing
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process data under GDPR:
| Legal Basis | Data & Purpose |
|---|---|
| Contract (Art. 6(1)(b)) | Account and fitness data — necessary to provide the training tracking service. |
| Explicit consent (Art. 9(2)(a)) | Health-related data (body weight, workout metrics) — voluntarily entered. Withdrawable at any time. |
| Legitimate interest (Art. 6(1)(f)) | Crash reports, analytics, anonymized data for product improvement and research — to maintain, secure, and improve the app. |
| Consent (Art. 6(1)(a)) | Push notifications — opt-out available via device settings. |
For users outside the EEA, we process data as described in this policy and in accordance with applicable local laws.
4. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Workout tracking experience | Fitness data, account info |
| Social features (rankings, feed, chat) | Nickname, avatar, workout stats |
| Gamification (XP, levels, ranks) | Workout data, exercise progress |
| AI workout plan generation | Fitness preferences (server-side, not stored by AI provider) |
| Push notifications | FCM token, preferences |
| Bug fixing and improvement | Crash reports, anonymized analytics |
4.1 Anonymized & Aggregated Data
We may use anonymized, de-identified, and aggregated data (data that can no longer identify you personally) for any lawful purpose, including but not limited to:
- Product improvement, feature development, and research
- Training and improving machine learning models and AI features (e.g., better exercise recommendations, form analysis, technique improvement)
- Generating aggregate statistics and benchmarks (e.g., average performance by exercise)
- Business analytics and reporting
This anonymized data never includes your name, email, nickname, profile photo, or any information that could identify you. Once data is anonymized, it is no longer considered personal data under GDPR or other privacy laws, and this policy does not restrict its use.
SyzUp contains no advertising. We do not use your fitness data, workout history, or body measurements for advertising purposes, and we share no data with advertising networks.
5. User-Generated Content & AI Training
5.1 Videos & Media
When you upload personal record videos or other media to SyzUp, you grant us a license as described in our Terms of Service. In addition to displaying your content within the app's social features, we may use de-identified video content (with all personally identifying information such as faces, names, and metadata removed) for the purpose of training machine learning models to improve features such as exercise form analysis, technique feedback, and movement recognition.
We will never use your identifiable videos, images, or media in marketing materials, sell them to third parties, or make them available outside of SyzUp without your explicit, separate consent.
5.2 Workout & Performance Data
Anonymized workout statistics (e.g., exercise frequency, volume patterns, progression curves) may be used to improve AI-generated workout plans, develop new features, and create aggregate benchmarks. This data is stripped of all personal identifiers before use.
6. Third-Party Services
Authentication, Firestore, Cloud Storage, Crashlytics, Analytics, FCM, Cloud Functions, App Check. Data stored in EU (europe-west).
AI workout generation processed server-side. Fitness preferences sent to generate plans but not stored by OpenAI. No PII transmitted.
7. Data Storage & Security
Primary data storage: Firebase (Google Cloud), European Union.
- Firebase Security Rules — access restricted to data owners
- Firebase App Check — prevents unauthorized API access
- AES-encrypted local storage (Hive with platform keychain keys)
- Server-side rate limiting and security logging
- HTTPS/TLS for all network communication
- No plaintext password storage
International Transfers
Some services (Crashlytics) may process data in the United States. For EEA/UK users, these transfers are protected by Standard Contractual Clauses (SCCs). For all users, we ensure that transferred data receives substantially similar protections regardless of destination.
8. Data Retention
| Data Type | Retention |
|---|---|
| Account & fitness data | Until account deletion |
| Chat messages | Until deleted or account deletion |
| Crash reports | 90 days |
| Analytics | 14 months |
| Security logs | 30 days |
| After account deletion | Profile, workouts, plans, records, videos, messages and consent records are permanently removed within 30 days |
| Billing and commission records | 5 years from the end of the tax year |
| Record of your deletion request | 6 years — account identifier and date only |
| AI usage logs | 365 days |
| Moderation records | 6 years |
| Anonymized/aggregated data | Retained indefinitely (not personal data) |
9. Data Sharing
We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes.
- Social features: Nickname, avatar, rank, and stats visible based on your privacy setting (public/friends/private).
- Service providers: Third-party processors in Section 6, solely for service delivery under data processing agreements.
- Legal: If required by law, regulation, legal process, or governmental request.
- Anonymized data: De-identified, aggregated data may be shared for research, benchmarking, or business purposes, but this data cannot identify you.
10. Your Rights
10.1 All Users
Regardless of where you live, you can:
- Access and review your personal data within the app
- Correct your profile information at any time
- Delete your account and all associated data (Settings → Account → Delete Account)
- Opt out of push notifications via device settings
- Control your social visibility via privacy mode settings
- Contact us with any data-related request
10.2 European Economic Area, UK & Switzerland (GDPR)
You additionally have the right to:
- Access (Art. 15): Request a full copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request complete deletion.
- Restriction (Art. 18): Limit processing in certain cases.
- Portability (Art. 20): Receive data in a machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)): At any time, without affecting lawfulness of prior processing.
You may lodge a complaint with a supervisory authority. In Poland: Urząd Ochrony Danych Osobowych (UODO) — uodo.gov.pl. You may also contact the authority in your country of residence.
10.3 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: What personal information we collect, use, and disclose.
- Right to delete: Request deletion of your personal information.
- Right to opt out of sale: We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your rights.
- Right to correct: Correct inaccurate personal information.
- Right to limit use of sensitive personal information: You may limit use of health-related fitness data to what is necessary for the service.
To exercise these rights, contact us at the email in Section 1. We will verify your identity and respond within 45 days.
Categories of personal information collected (per CCPA §1798.110): Identifiers (email, nickname), health-related information (fitness data, body weight), internet/electronic activity (usage analytics, crash data), geolocation (country-level only), and audio/visual information (profile photos, PR videos).
10.4 Other Jurisdictions
If you reside in a jurisdiction with data protection laws (including but not limited to Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, Japan's APPI, South Korea's PIPA), we will honor your applicable rights upon request. Contact us at the email in Section 1.
11. Account Deletion
- In-app: Settings → Account → Delete Account
- By email: Subject "Account Deletion Request"
All personal data is permanently deleted within 30 days, including: profile, workouts, plans, chats, records, videos, and FCM tokens. Anonymized aggregate data that cannot identify you may be retained.
12. Children's Privacy
SyzUp is not intended for children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from children. If we learn a child has provided personal data, we will delete it promptly. Parents may contact us to request deletion.
13. Do Not Track
SyzUp is a mobile application and does not respond to browser "Do Not Track" signals. However, you can control data collection through the opt-out mechanisms described in this policy (ad personalization, push notifications, privacy mode).
14. Changes to This Policy
We will notify you of material changes via in-app notification at least 14 days before they take effect. Continued use after the effective date constitutes acceptance. If you disagree, delete your account before the effective date.
15. Contact
We aim to respond to all requests within 30 days (45 days for CCPA requests).
최종 수정: