1. Information we handle
This policy covers the MyMyo mobile app and mymyo.fit website. MyMyo is responsible for the personal information it handles to operate these services. Information comes from what you enter, the sign-in provider you choose and technical requests made when you connect to our services.
Account and sign-in information
Supabase handles your email address, account identifier, sign-in provider information, authentication events and session records. If you use Google sign-in, Google supplies the account identity and basic profile information authorised in its sign-in flow, which can include your name, email address and profile image. MyMyo does not receive your Google password. Standard email sign-in uses a link sent to your email address. Administrator-issued special-access accounts can instead submit an email address and password to Supabase for authentication. The app stores authentication tokens locally to maintain your session.
For Google and email-link access, the single-session login system links your account identifier to the admitted authentication session identifier. It checks this link at sign-in, session restoration or refresh and when the app returns to the foreground. Administrator-issued email-and-password sessions are exempt and can access the account concurrently. The system does not require a hardware device identifier or precise location.
Cloud profile and readiness information
Your Supabase profile stores your display name, date of birth, unit preference, selected body illustration, and any height or weight you provide. The body illustration selector chooses a bundled male or female image; it does not upload a personal photograph. Date of birth is used to calculate age and enforce the minimum planning age of 18.
If you submit readiness answers in Profile or during automatic planning, Supabase stores your answers about pregnancy, postpartum recovery, diagnosed medical conditions or medical exercise restrictions, current pain, injury or concerning symptoms, together with age/date of birth and the screening version and completion time. These answers can be sensitive health information. The questions collect broad circumstances, not a clinical history or diagnosis.
On-device training information
Planning goals and preferences, equipment and exercise choices, plans and training days, custom exercises, prescriptions, notes and any recorded workout sessions or set logs remain in the app’s local SQLite database. Records can include repetitions, load, rest, duration, distance and workout feedback. The device also stores derived readiness status and screening time, planning validation records, and the version and time of planning or manual-advice acknowledgements. Editing an exercise target does not by itself record a completed workout.
Technical requests, purchases and support
When the app connects to Supabase, or you visit the website or download pricing and legal content, the service providers receive technical request information such as IP address, request time, requested resource and browser or app information. Those providers may maintain operational and security logs.
Paid purchases are currently unavailable. If you later make a purchase through an offered payment provider, it processes your payment details. MyMyo’s billing system is designed to retain customer and transaction identifiers, product, price, amount, currency, subscription status and billing periods; it does not store full payment-card details.
If you contact us through a working support channel, we receive the contact details and information you choose to send. Avoid sending passwords, sign-in links or unnecessary health information. The current website contact form does not transmit its entries.
2. Purposes and readiness choices
We use account and session information to sign you in, enforce one active device per account, prevent unauthorised access and operate account features. Profile details support personal settings and age checks. Readiness answers determine whether automatic planning falls within the supported healthy-adult population. Local planning information selects and validates routines and supports your saved records.
Readiness questions are optional in Profile. You can browse the libraries without supplying readiness answers or creating an account. Automatic planning requires complete readiness answers; without them it cannot proceed. Adults may use the manual builder subject to its professional-advice acknowledgement. An eligibility result is a rule-based fitness precaution, not medical clearance or diagnosis, and no clinician monitors your answers.
We use sensitive readiness information for these readiness checks and related account functionality, not for advertising. Where consent is required to collect or use sensitive information, it must be obtained when that information is submitted; reading this policy or accepting the service terms is not blanket consent to other uses. Withdrawing consent or asking for readiness information to be deleted can make automatic planning unavailable.
We use technical information to deliver content and protect and maintain the service, billing information to administer purchases when offered, and support correspondence to respond to requests and resolve problems. We do not sell personal information or use readiness answers to target advertising. The current app and public website do not include third-party advertising, behavioural analytics or marketing-tracking integrations.
3. Local storage and account boundaries
Plans and workout logs are not uploaded to Supabase or automatically synchronised between devices. Cloud profile data can be loaded when you use your account on another device, but your local training data does not follow it. The app currently has no in-app training backup or export tool.
Training records belong to the app installation rather than a separate local store per account. Signing out or changing accounts does not delete them, and another signed-in person using the same installation may be able to access them. Clear app storage before sharing or transferring the device if you need to remove those records.
Current cloud profile fields are loaded into memory for the active account. Changing accounts discards that in-memory profile. Profile reads and writes require a network connection; there is no persistent offline cloud-profile cache or queued offline profile save. Older versions may have left personal or readiness fields in the local database; these legacy fields are not automatically uploaded or assigned to the next account.
Exercise artwork, fonts, catalogue and marketing copy ship with the app. Pricing, Terms and Privacy are downloaded from mymyo.fit and successfully validated copies are cached locally for offline use. This cache contains public content. Authentication tokens also persist on the device in local storage. On the public website, MyMyo does not set advertising or analytics cookies; Google or other external sign-in and linked services have their own storage practices.
5. International processing
Our hosting, authentication, identity and email providers operate internationally. Depending on their service configuration, your information may be processed or accessed outside the country where you live. Local-only training data is not sent to those providers by MyMyo. Device or operating-system backups are controlled separately by your device settings.
We apply the safeguards required by applicable law when arranging overseas handling of personal information. This policy does not ask you to waive protections for overseas disclosures. Provider policies describe their own international operations:
6. Retention and deletion
Local training records remain in app storage until you remove them through available app controls or clear the app’s storage. Signing out does not remove them. Uninstalling or clearing storage may erase local training records, cached public content and authentication tokens. Copies retained by an operating-system backup depend on its settings and must be managed there.
Confirming a Profile readiness update outside the supported population permanently deletes all saved plans and their training days on the current device, including manual plans. A confirmed date-of-birth change making you under 18 also deletes saved plans. Completed workout history is retained. Cancelling the confirmation leaves the saved profile and plans unchanged. Readiness expiry alone does not delete plans, and later becoming eligible does not restore deleted plans.
Cloud profile and account records persist independently of installation or sign-out. Removing the app or a local plan does not delete your account or readiness answers. In the app, sign in, open Profile, scroll to the end of the page and select Delete my account. You can also request deletion through the external account-deletion page. In-app deletion also erases MyMyo plans, workout history, custom exercises and preferences on the device used for deletion. Cloud deletion cannot remotely erase training records stored only on another device.
Cloud information is retained while needed to provide the account or for a legitimate legal, security, transaction or dispute-resolution purpose. When it is no longer needed, we will take reasonable steps to delete or de-identify it, subject to applicable retention requirements. Backup and security-log copies can remain until the relevant retention cycle ends. We do not promise immediate removal from all backups when an active record is deleted.
The Google or email-link session reservation is released when its authentication session is removed; an expired reservation can be replaced on the next successful session check. Password sessions do not take or require this reservation. Revoking a Google permission, signing out and deleting a MyMyo account are separate actions. If subscriptions become available, deleting the account will not itself cancel a store-managed subscription.
7. Security
MyMyo uses encrypted network connections to its production cloud and website endpoints, account authentication and row-level access controls for cloud profiles. Billing writes are reserved for trusted backend services. The single-session admission check restricts concurrent Google and email-link access; administrator-issued password sessions are intentionally exempt. These controls do not make the local training database a separate private vault for each account.
Use a device passcode, keep your operating system and app updated, protect access to your email and Google account, use a unique password for administrator-issued access, and do not share passwords or sign-in links. Device security and backup settings protect local data; MyMyo does not provide an additional app-specific encryption password for that database. No system can guarantee absolute security. We will notify affected people and regulators of a data breach when required by applicable law.
8. Access, correction and requests
You can view and edit your personal details and readiness answers in Profile when connected. Keep them accurate; saving an ineligible update has the plan-deletion consequences explained above. You can manage local plans and exercises using the available app controls or remove local records by clearing app storage.
You may request access to or correction of cloud personal information, request account or readiness-data deletion, withdraw consent where applicable, or raise a privacy complaint. Depending on the law that applies to you, you may also have rights to object to or restrict processing and receive a portable copy. These rights can be subject to legal exceptions; they do not mean MyMyo can retrieve training records held only on your device.
To protect your information, a request may require proportionate identity verification. We will consider requests under applicable law, explain any lawful refusal or retention requirement, and identify available complaint options. Do not include a password or sign-in token in a request. Account-deletion requests can be started through the app or the external account-deletion page.
9. Children and younger users
The exercise and muscle libraries can be browsed as a guest. Both planners are restricted to signed-in adults aged 18 or older, using the date of birth supplied in Profile. This is a planning restriction, not a claim that the app prevents every person under 18 from creating an account. Readiness information should not be submitted for another person.
If you are a parent or guardian concerned about information a child has supplied, you may request access, correction or deletion subject to appropriate verification and applicable law. The educational demonstrations do not establish that an exercise is suitable for a child or any other viewer.
10. Privacy contact and complaints
MyMyo service information is available on the contact page. Account-deletion requests can also be sent to support@mymyo.fit.
A privacy complaint should describe what happened and the outcome you seek without unnecessary sensitive detail. We will investigate complaints we receive and respond within the period required by applicable law. If you are dissatisfied with the response, you may contact the privacy regulator that has jurisdiction over your complaint.
For Australian privacy complaints within its jurisdiction, see the Office of the Australian Information Commissioner for the complaint process.
11. Policy updates
We will update this policy when the app or our data handling changes and show the new update date. Material changes will be communicated through the app, website or an available account contact channel as appropriate. Where a new use requires consent, a policy update alone will not replace that consent.
The app keeps the last successfully downloaded policy for offline reading. Visit the website while connected to read the current published version.
