Privacy Policy
Last updated : September 30, 2026
This policy describes how BEABLE2 PTE. LTD. ("BeAble2", "we") processes your personal data when you use the GYMAURA app and the gymaura.ai website.
1. Data controller
The data controller is BEABLE2 PTE. LTD., a company registered in Singapore (UEN 202602606R), with its registered office at 9 Raffles Place #29-05 Republic Plaza, Singapore 048619.
For any question about your data, contact us at [email protected].
2. What the app does
GYMAURA brings three things together in a single app:
- Access to your gym and club life: your access credential, plus your gym's news and announcements.
- Training tracking, provided by our SPORT engine: sessions, sets, records, and camera-based posture correction.
- Nutrition tracking, provided by our NUTRITION engine: meals, targets, food search.
Both engines are separate technical services operated by BeAble2 on GYMAURA's behalf. They are necessary to run the service: what is sent to them is set out under "The SPORT and NUTRITION engines".
3. Data we collect
Account data. You create your account on the GYMAURA website, with an email address and a password, or through "Sign in with Apple" or "Sign in with Google". Through Apple or Google we receive an identifier and an email address (which may be an Apple relay address), along with your name if you provide it. Your password is handled by our authentication provider, which keeps only a cryptographic hash of it: it is readable in clear by neither us nor your gym.
Phone number. When SMS verification is offered to you, we collect your number and send you a one-time code.
Profile data. What you add to your profile: display name, optional photo, date of birth, sex, height, weight, goal.
Gym access data. A digital access credential (such as a QR code) linked to your account, and entry records (date, time and gym visited) used to manage access, security and your membership.
Training data. Your sessions, exercises, sets, loads, repetitions, durations and records.
Nutrition data. Your meals, foods, quantities, calorie and macronutrient targets, hydration and fasting periods where applicable.
Health data. What you allow us to read from Apple Health or Google Health Connect — see the dedicated section below.
Voice recordings. When you dictate a meal, the recording is sent to be transcribed into text — see "Voice dictation".
Usage measurement. Events describing your journey through the app — see "Usage measurement".
Technical data. Device information, the app version and crash reports needed to operate and secure the service — see "Crash reports".
4. Health data
With your explicit permission, granted from your phone's settings, GYMAURA exchanges certain measurements with Apple Health (iPhone) or Google Health Connect (Android). Each one has a specific purpose; the app asks for nothing else.
What GYMAURA reads, and why:
- Weight, height, body fat, lean mass (Apple Health and Health Connect): to fill in your profile and body measurements, which your nutrition targets are computed from.
- Body water (Health Connect) and waist circumference (Apple Health): to complete those same measurements.
- Sex and date of birth (Apple Health only): to fill in your profile.
- Active energy burned over the last seven days (Apple Health and Health Connect): to suggest your activity level when you create your profile.
- Steps (Apple Health only): to check that access is still granted, which Apple does not report otherwise. Steps are neither displayed nor stored.
What GYMAURA writes, and why:
- Weight, height, body fat, lean mass, and waist circumference on iPhone: when you correct them in the app, so your other apps hold the same figures.
- Your completed workout sessions (type, title, start and end): so they appear in your activity history. On iPhone only, we also write the estimated energy burned for the session; on Android, the session is written without any energy figure.
- Your logged meals (energy, protein, carbohydrates, fat): so your health app knows your intake. Meals from other apps are never read.
Measurements that are read are kept in your GYMAURA profile as if you had entered them; you can change or delete them at any time.
Health data is a special category of data under Article 9 GDPR. We process it solely on the basis of your explicit consent, given through the permission you grant the app in your phone's settings. You can withdraw it at any time from those same settings: reading and writing stop immediately, and this does not prevent you from using the rest of the app.
We do not share your health data with any advertiser, data broker or insurer.
5. Camera and posture analysis
Posture correction uses your phone's camera to analyse your movement during an exercise.
The analysis runs entirely on your device. The pose-detection model is bundled inside the app: no image, no video and no video stream is sent to our servers or to any third party. Our servers only receive the fact that a posture session was started or abandoned, never its content.
Scanning a product barcode also uses your camera. The code is read on your device and only its number is used to look the product up, exactly as if you had typed it: no image is sent.
6. Voice dictation
When you dictate a meal instead of typing it, the audio recording is sent to our transcription service, which relies on an artificial-intelligence provider (see "Artificial intelligence"). It returns the corresponding text. We keep the text of your entry and its result, not the audio recording, which is not stored beyond the processing of the request.
7. Artificial intelligence
We use artificial-intelligence models provided by third parties to:
- transcribe your voice dictations into text;
- interpret a meal description and derive the foods and quantities from it;
- estimate a portion, correct an ambiguous entry and translate food labels.
What is sent is limited to the content of the entry concerned (the meal's text or audio) and the necessary context. We do not send your name, your email address, your phone number or your account identifier to these providers.
These processes assist your entry; they produce no automated decision with legal effect or similarly significant effect on you within the meaning of Article 22 GDPR. You can correct or delete any suggested result.
We choose these providers on quality, cost and data-protection grounds, and they change over time. None of them is permitted to reuse your data to train its own models. To know which ones are in use at a given date, write to us.
8. Gym access and entry records
To give you access to your gym, the app generates a digital access credential (such as a QR code) linked to your account. Each entry may be recorded (date, time and gym concerned) in order to manage access, ensure security and administer your membership.
Your access credential is personal. Sharing it with a third party may lead to its suspension.
9. The SPORT and NUTRITION engines
When you create your GYMAURA account, we create a technical account for you in each of the two engines.
These accounts are pseudonymous: the engine receives a technical identifier that designates you, and nothing else. Your name, email address, phone number, photo and gym are not sent to them. An identifier is still personal data, because we can trace it back to you: that is what lets us delete your sessions and your meals when you delete your account.
The SPORT engine receives your training sessions: exercises, sets, loads, repetitions, durations, records, and the preferences used to generate a session (goal, level, available equipment, frequency). Posture analysis data stays on your phone; the engine receives the fact that a session took place, never an image or a video.
The NUTRITION engine receives your meals and their composition, your calorie and macronutrient targets, your hydration and fasting periods where applicable, plus the physical characteristics needed to calculate a target: age, sex, height, weight, activity level. When you dictate a meal, the audio recording passes through this engine to be transcribed.
The engines in turn rely on the artificial-intelligence providers described above. None of them is permitted to reuse your data to train its own models.
10. Your gym and its management space
Your gym has a management space that lets it welcome you as a member. There it sees:
- Your identity and contact details: first and last name, email address, phone number, profile photo.
- Your membership: plan, options, dates, status, and the gyms you are attached to where the club has several.
- Your visit history: date, time and gym for each entry.
- The internal notes and tags its staff adds to your record, as part of membership follow-up and front-desk service.
It has no access to the content of your meals, the content of your sessions, or your health data. That data stays between you, the app and the technical engines.
Searches of the member file and changes made to your record are logged: who, when, which action. These logs contain neither your name, nor your email address, nor the content of your record.
Your gym decides how it uses your member record within your membership. For any question about that use, contact it directly; you can also write to us and we will pass it on. It may also be required to keep certain items under its own obligations, in particular accounting obligations for amounts invoiced: those retentions are its responsibility and follow its own legal periods.
Your gym's access to your record does not amount to agreement to receive messages. SMS, email and offers from your gym's commercial partners are the subject of three separate agreements, which you give or refuse separately and change at any time in the app's settings. Refusing them changes nothing about what the app does for you.
11. Usage measurement
We record events describing your journey: app opened or closed, screen viewed, meal logged or corrected, session generated, started, completed or abandoned, sets logged, posture analysis started or abandoned, onboarding step reached, and the display of and taps on the pop-up announcements your gym shows when the app opens.
These events are attached to your account, with a date, the name of the action and a few technical values (an item or exercise identifier, a duration, a count). They travel inside the synchronisation request the app already sends. They do not carry the content of your entries: neither what you eat, nor the loads and repetitions of your sets, nor your health data. They are used to understand what works, fix what blocks, and measure the reach of your gym's announcements. We do not use them for targeted advertising and do not sell them.
This measurement rests on our legitimate interest. You can object to it at any time by writing to [email protected]: we then stop recording your events.
12. Crash reports
When the app crashes or encounters an error, a minimal technical report is sent automatically to Sentry, our crash-reporting processor. It contains information about the device, the app version, the technical sequence of the error and your account identifier, and nothing else: no logs, no history of your actions and no content of your entries. This automatic report cannot be turned off from the app's settings.
Only a more detailed report, which also includes the app's recent logs and your latest actions, is optional: it is sent if you enable "Send crash reports automatically" in the settings, or when you yourself send a bug report from the app.
13. Legal basis (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the service: account, gym access, training and nutrition tracking | Performance of the contract |
| Health data read from and written to Apple Health / Health Connect | Explicit consent (Art. 9(2)(a)) |
| Transmission to the SPORT and NUTRITION engines, your gym maintaining your record | Performance of the contract |
| Phone number verification | Consent |
| Marketing communications by SMS, email or through the club's partners | Consent, withdrawable at any time |
| Access security, fraud prevention, diagnostics and improvement | Legitimate interest |
| Log retention and accounting obligations | Legal obligation |
14. Hosting and processors
Supabase: authentication and database, hosted in the European Union.
Railway: hosting of our backend services, in the European Union.
Twilio: delivery of verification SMS messages.
Sentry: collection of crash reports.
Artificial-intelligence providers: transcription and interpretation of entries, with no identifying data (see "Artificial intelligence").
We do not sell your personal data.
15. International transfers
Your account, access, training and nutrition data are hosted in the European Union.
Some processing involves a transfer outside the European Union: the artificial-intelligence providers, the delivery of SMS messages and the collection of crash reports. These transfers are covered by appropriate safeguards, in particular the European Commission's standard contractual clauses or an equivalent mechanism.
As BeAble2 is established in Singapore, some administrative operations may involve processing in Singapore, covered by the same safeguards.
16. Retention
Your data is kept for as long as your account is active. When you request deletion of your account, it is deactivated immediately and you are signed out. For 30 days, you can reactivate it by signing back in (see "Deleting and recovering your account"). After that period, your identifying personal data (email address, name, identifier, phone number where applicable, profile photo) is permanently erased and account access is disabled.
Some non-identifying data (such as usage or entry records) may be kept in anonymised form, not linkable to you, for security, statistics and service improvement, or where a legal obligation requires it. Technical logs and entry records are kept for a limited period.
17. Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time, without affecting the lawfulness of processing already carried out.
To exercise these rights, write to [email protected]. If you reside in the EEA, you may also lodge a complaint with your data protection authority (in France, the CNIL).
18. Deleting and recovering your account
You can delete your account directly from the app: in your profile, choose "Delete my account", then confirm. You can also ask us at [email protected]. These steps are also explained, without signing in, on the Delete your account page.
Deletion happens in two stages:
- Immediate deactivation (30-day grace period): as soon as you ask, your account is deactivated and you are signed out. For 30 days, you can cancel the deletion and recover your account by signing back in, by whichever means you normally use; your account and data are then restored.
- Permanent anonymisation (after 30 days): without a sign-in within that period, your identifying personal data is erased and account access is permanently disabled. This operation is irreversible.
The deletion request is relayed to the SPORT and NUTRITION engines, so that your sessions and your meals are deleted too. Your member record and the internal notes attached to it are deleted along with your account, in the same database.
19. Security
We implement reasonable technical and organisational measures to protect your data against unauthorised access, loss or alteration: encryption in transit, role-based separation of database access, and logging of operations performed in your gym's management space.
20. Children's data
GYMAURA is not intended for people under 16, and we do not knowingly collect their data. If you believe a minor has provided us with data, contact us so that we can delete it.
21. Changes to this policy
We may update this policy. The date of the latest update appears at the top of the page; in case of a significant change we will inform you by an appropriate means and, where the law requires it, ask for your agreement again.
22. Contact
BEABLE2 PTE. LTD. — 9 Raffles Place #29-05 Republic Plaza, Singapore 048619.
For any question about this policy: [email protected].