Privacy Policy

GymOrigin gym-management app · Effective 22 July 2026

This Privacy Policy explains how GymOrigin ("we", "us", "the app"), operated by Dilip Kumar (sole proprietor), handles information in the GymOrigin gym-management application (package com.gymorigin.app). By creating an account or using the app, you agree to this policy.

1. Who this policy is for

GymOrigin is a tool for gym owners and their staff to run a gym. Two kinds of people are involved:

For gym members' personal data, the gym owner is the data controller / fiduciary and GymOrigin acts as a data processor that stores and processes it on the gym owner's instructions. Gym owners are responsible for having a lawful basis to enter their members' details.

2. Information we collect

a) Account information (owner & staff)

b) Member information (entered by the gym owner)

c) Diagnostic information

What we do NOT collect: We do not use advertising SDKs or third-party analytics/tracking. We do not collect location, contacts, or device identifiers for tracking. The camera is used only to scan member check-in QR codes and is never used to record or upload video. We do not store card or bank-account numbers — subscription payments are handled manually over UPI/WhatsApp (see §5).

3. How we use information

We do not sell your data or your members' data, and we do not use it for advertising.

4. Service providers (sub-processors)

ProviderPurposeData involved
SupabaseDatabase, authentication, and file storage (member photos)All account, member, and diagnostic data above
Google PlayApp distribution and updatesInstall/purchase data handled by Google
WhatsApp (Meta)Opens only when you tap to message a member or to contact us for payment; the message content is what you choose to sendOnly the phone number and message you choose to send

Each processes data only to provide these services. We do not share data with any other third parties except where required by law.

5. Payments

Your subscription to GymOrigin is paid manually: you contact us over WhatsApp, pay via a UPI QR code we share, and we activate your plan. The app does not collect or store your card, UPI, or bank-account details. Any payment figures shown in the app (for your gym members) are amounts you type in yourself for your own records.

6. Data security

No system is perfectly secure, but we take reasonable measures to protect your information.

7. Data retention & deletion

We keep your data for as long as your account is active. You can delete your account and all associated data at any time from within the app: Settings → Delete account. This permanently erases your gym, all members, plans, payments, attendance records, your profile, and your login — this action cannot be undone. Staff who delete their account remove only their own access, not the gym's data.

You may also request deletion by contacting us (see §11) or via our web deletion page: gymorigin.in/legal/delete-account.html.

8. Your rights

Subject to applicable law (including India's DPDP Act, 2023), you may:

Gym members whose data was entered by a gym should contact that gym owner first, as the owner controls that data.

9. Children's data

GymOrigin is intended for gym owners and staff, not for children. We do not knowingly collect personal data directly from children. Gym owners are responsible for any member details they enter, including obtaining consent from a parent/guardian where a member is a minor.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Effective" date above and, where appropriate, notifying you in the app.

11. Contact us