PRIVACY POLICY — MUSCLE APP MOBILE APP

Last updated August 12, 2026

When we make material changes to this policy, we will update the "Last updated" date above and, where required, notify you or ask for your consent again.

This Privacy Policy explains how Muscle App("we," "us," "our") collects, uses, and protects your personal data when you use the Muscle App mobile applicationfor iOS and Android (the "App"). We are committed to processing your data lawfully, fairly, and transparently, in accordance with the EU General Data Protection Regulation (GDPR) and Spanish data protection law.

1. WHO WE ARE (DATA CONTROLLER)

The data controller responsible for your personal data is:

For any question about this policy or about how your data is processed, you can write to the email address above.

2. SCOPE OF THIS POLICY

This policy covers the mobile App. Our website at https://www.muscleapp.fit has its own Privacy Policy, which additionally covers website-only features such as trainer accounts, the public trainer marketplace, and payments. The App and the website share the same account and the same backend: data you record in one is visible in the other.

3. WHAT DATA WE PROCESS

3.1 Account data

When you create an account we process your email address, name, username, and (if you add one) your avatar image. If you sign in with Apple or Google, we receive the identifiers needed to authenticate you (see Section 9).

3.2 Health and fitness data

Depending on what you choose to record in the App:

  • Body weight and body measurements
  • Fitness goals
  • Workout logs and training history
  • Nutrition and meal logs
  • Progress photos

This data can reveal information about your health and is treated as a special category of personal data. See Section 6.

3.3 Social data

If you use the social side of the App, we also process:

  • Your posts: the text, any images you upload, and — if you choose so when posting — the summary of the linked workout
  • The likes and comments you give and receive
  • Your follow graph: who you follow, who follows you, and pending follow requests in both directions
  • Your list of blocked users
  • The notifications these actions generate (new follower, follow request, request accepted, like, comment)

Who can see each of these is explained in Section 8.

3.4 Messaging

If you are subscribed to a trainer, messages exchanged with that trainer through the platform are stored so we can deliver them and display your conversation history. If you block the other person, the conversation is deactivated and can no longer be used, but the messages already sent are kept.

3.5 Device and technical data

  • Push notification token:if you enable push notifications, the App registers your device's notification token so we can send them (see Section 4).
  • App settings: your language, units, theme, and notification preferences.

4. DEVICE PERMISSIONS

The App asks for the following device permissions. All of them are optional — the App works without them — and you can change them at any time in your device settings:

  • Camera: to scan food barcodes in the nutrition section and to take photos you choose to upload (avatar, posts, progress photos). Barcode scanning happens on your device: only the barcode number is sent to the food database (see Section 9); camera frames are not stored or uploaded.
  • Photo library: to pick images you choose to upload. We only receive the images you select.
  • Notifications: for reminders and push notifications. Some reminders (rest timer, daily workout reminder) are scheduled locally on your device and never leave it.
  • App Tracking Transparency (iOS): see Section 7.

5. PURPOSES AND LEGAL BASES

We process your data for the following purposes, on the following legal bases:

  • Providing the App (account, workout/nutrition tracking, social features, messaging): performance of a contract (Art. 6(1)(b) GDPR).
  • Processing your health and fitness data (workouts, measurements, nutrition, progress photos): your explicit consent (Art. 9(2)(a) GDPR). See Section 6.
  • Sending push notifications: your consent (Art. 6(1)(a) GDPR), given when you enable notifications. You can disable them at any time.
  • Measuring ad campaigns (install attribution): your consent (Art. 6(1)(a) GDPR), given through the iOS tracking permission. See Section 7.
  • Keeping the platform secure (authentication, abuse prevention): our legitimate interest in protecting the Services and their users (Art. 6(1)(f) GDPR).
  • Complying with legal obligations (responding to lawful requests): Art. 6(1)(c) GDPR.

We do not sell your data. See Sections 7 and 9.

6. HEALTH AND FITNESS DATA (SPECIAL CATEGORY)

Data about your body, workouts, and nutrition can reveal information about your health. Under Article 9 GDPR, this is a special category of personal data and we process it only with your explicit consent, which you give when you choose to record this data in the App.

  • You decide what health and fitness data you record. None of it is mandatory to have an account.
  • If you subscribe to a trainer, that trainer can see the data needed to coach you while the subscription is in force (including the payment-overdue period before cancellation): your athlete profile, your workout sessions, your progress metrics and body measurements, and your nutrition targets and logs. When the subscription is no longer in force, that access ends.
  • Your progress photos are visible only to you. They are not visible to your trainer or to any other user.
  • You may withdraw your consent at any time by deleting the data in question or deleting your account (see Sections 12 and 13). Withdrawal does not affect the lawfulness of processing before withdrawal.

7. AD CAMPAIGN MEASUREMENT (APP TRACKING TRANSPARENCY)

To know whether our advertising campaigns work, the App can use the Meta (Facebook) SDK to attribute installs to campaigns. This measurement:

  • Only runs with your permission.On iOS we ask first through Apple's App Tracking Transparency prompt. If you decline — or simply never grant it — the measurement SDK stays off and no data is shared with Meta.
  • If you allow it, the events shared with Meta Platforms are limited to campaign measurement: app install, app launch, and registration completed, together with the device advertising identifier.
  • We use this exclusively to measure campaigns. We do not sell your data and we do not show third-party ads in the App.
  • You can change your choice at any time on iOS under Settings → Privacy & Security → Tracking.

Apart from this optional measurement, the App uses no third-party analytics.

8. PROFILE AND CONTENT VISIBILITY

8.1 Your profile inside the App

Muscle App works like a social network. Anyone with an account can find your profile by searching for your username or your name, and see your profile card: username, name, profile picture, whether your account is private or public, your follower counts, and the number of your posts that this particular person is allowed to see. Note that your profile picture is stored in public storage: anyone holding the image URL can open it without signing in.

Other users cannot read your email address, phone number, or privacy settings. Making your account private does not hide the profile card or the follower counts; what it hides is the content: posts and workout statistics.

8.2 Private account and followers

  • Relationships are follows, not friendships: following someone does not make them follow you.
  • With private account on (Settings → Privacy), anyone who wants to follow you must send a request you accept or reject. Only accepted followers see your content. If you turn it off, every pending request is accepted automatically.
  • Your follower and following lists are visible only to you. Other users see the counts only, never the names.
  • When you follow someone or send a request, that person gets a notification with your username. You can unfollow, withdraw a request, or remove a follower at any time.

8.3 Post visibility

When you publish a post you choose who can see it:

  • Public: anyone with a Muscle App account. If your account is private, this option is labelled "Followers" and only accepted followers can see it.
  • My trainer only: only the trainer you are subscribed to with an active subscription.
  • Only me: nobody but you.

No post is visible to people without an account. Likes and comments follow the visibility of the post. Post photos are not stored in public storage: they are served through temporary signed links generated only for viewers who are already allowed to see the post, and those links expire.

8.4 Workout visibility

In Settings → Privacy you choose who sees your workout statistics (number of completed workouts, weekly streak, and activity calendar): Public, Followers only, or Private. If your account is private, being an accepted follower is required on top of that.

8.5 Blocking another user

You can block any user from their profile. When you block someone:

  • Your conversation (if any) is deactivated: the messages already sent are kept, but neither of you can keep writing.
  • Both follow relationships are deleted, in both directions.
  • That person stops seeing your profile, posts, and statistics, cannot like or comment on your posts, and cannot follow you again. They stop appearing in your searches and suggestions.

Blocking does not notify the other person, and only you can see your own block list. If you unblock someone, the deleted follow relationships are not restored.

9. WHO WE SHARE DATA WITH

We share your data only with the service providers (processors) we need to run the platform:

  • Supabase — database, authentication, and file storage.
  • Google and Apple — only if you choose to sign in with your Google or Apple account (optional sign-in).
  • Meta Platforms — only if you allow tracking on iOS, and only for the campaign measurement described in Section 7.
  • Open Food Facts — when you scan a food barcode, the barcode number is sent to the Open Food Facts database to look up nutrition information. No personal data is sent with it.

These providers process your data under agreements (including the safeguards described in Section 11) that require them to protect it with the same or equal protection as described in this policy.

In addition, if you subscribe to a trainer, that trainer receives the data described in Section 6. Beyond that, the only data of yours that other users see is what Section 8 describes, and you control it through your privacy settings and the visibility of each individual post.

We do not sell your data. We may disclose data where required by law or to competent authorities under a valid legal request.

10. PAYMENTS

The App currently does not process paymentsand does not collect or store card details. Subscriptions offered on our website are handled there by Stripe under the website's Privacy Policy and Terms.

11. INTERNATIONAL DATA TRANSFERS

Our service providers may process data outside the European Economic Area (EEA). Where that happens, the transfers are protected by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs) entered into with those providers. You may request more information about these safeguards using the contact details in Section 1.

12. DATA RETENTION AND ACCOUNT DELETION

We keep your personal data for as long as your account is active. You can delete your account directly in the App (Settings → Account). If you delete your account, we will delete your personal data within a reasonable period, except for data we must keep to comply with legal obligations or to establish, exercise, or defend legal claims.

You can also request deletion by emailing legal@muscleapp.fit from the address associated with your account.

13. YOUR RIGHTS

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interest
  • Restrict processing in the cases provided by law
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, email legal@muscleapp.fit. We may ask you to verify your identity before acting on a request.

If you believe your rights have been infringed, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD): www.aepd.es.

14. LOCAL STORAGE (NO COOKIES)

The App does not use cookies. It stores your session and your app preferences locally on your device so you stay signed in and keep your settings. This local data is removed when you sign out or uninstall the App. The website's use of cookies is described in the Cookie Policy.

15. SECURITY

We apply technical and organizational measures appropriate to the risk, including encrypted connections (HTTPS), authenticated access, and database access rules that restrict each user's data to that user. No system is completely secure; if we become aware of a breach affecting your data, we will act in accordance with our GDPR obligations, including notification where required.

16. MINORS

The App is intended for people aged 18 or over. We do not knowingly process data of minors. If you believe a minor has created an account, contact us and we will delete it.

17. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where the change requires it, notify you through the App or by email and ask for your consent again where legally required.

18. CONTACT AND COMPLAINTS

For any privacy question, request, or complaint, contact: legal@muscleapp.fit

This policy should be read together with the App's Terms of Use.

Muscle App | Madrid, Spain

We use essential cookies to keep you logged in and process payments securely. No analytics or marketing cookies are used. Learn more