Privacy Policy
Effective 8 September 2026The short version. Your workouts and training history are stored on your phone and nowhere else. What leaves the device is the text of your conversations with Rhino (sent to a server operated by the developer so a reply can be generated) and, if you use the My Gym feature, the name of your gym and the list of equipment it has, which is shared anonymously with other members of the same gym. Signing in and backing up are optional and off unless you ask for them. No analytics, no advertising and no third-party tracking.
Who this covers
This policy applies to the Gym Buddy iPhone app and to the pages at gymbuddyrhino.com. The app is developed and operated by an independent developer based in Australia (“we”, “the developer”). Write to support@gymbuddyrhino.com with any question about this policy or about the data we hold.
Data stored on your device
Everything you build up in the app lives in its private storage on your phone:
- Workouts: names, exercises, and the sets, reps and weights for each.
- Session history: the date, workout name and number of sets completed for each finished session. This is what drives your streak and the activity heatmap.
- Settings: your gym’s name and equipment list, unit and appearance preferences, and a random identifier the app generates on first launch (see My Gym below).
We never see this data. It is not uploaded, synced or backed up by us. It is included in any iCloud or computer backup you make of your phone, under Apple’s terms, in the same way as any other app’s data. Deleting the app deletes it.
Data sent to generate Rhino’s replies
Rhino is a large language model. It does not run on your phone. When you create a workout, ask Rhino to revise one, or send a chat message, the app transmits the following to a server operated by the developer, over an encrypted (HTTPS) connection:
- The messages in the current conversation, including everything you have typed into it and Rhino’s earlier replies.
- When you chat from inside a workout, or ask Rhino to revise one: that workout’s name, exercises, sets, reps and weights, and how far through it you are.
- When you create a workout: the names of your existing workouts, so the new one can be given a name that does not clash, and the equipment list of your gym if you have set one.
- When you ask Rhino to name a piece of equipment from a photo: that photo. It is used only to produce the name and is not stored.
- When you pick a gym on the My Gym page and nobody has listed its equipment yet: the gym’s name, so Rhino can suggest a list.
The server uses this text solely to generate the reply that is shown to you. It is not used to train models, is not sold, and is not shared with advertisers or data brokers. The server is hosted by the developer and the model runs there; your messages are not forwarded to a third-party AI provider.
Chat requests are not linked to an account, whether or not you have one. The app does not send your name, email address, contacts, location, device identifiers or advertising identifiers. As with any internet request, the server necessarily receives your IP address in order to send the response back; standard connection logs are kept only as long as needed for operating and securing the service.
Please do not type sensitive personal or medical information into the chat. Rhino does not need your name, your address or your medical records to help with a workout, and text you send cannot be edited or recalled afterwards.
My Gym and shared equipment lists
The app ships with a directory of gyms across Australia, built from OpenStreetMap (© OpenStreetMap contributors) and gym chains’ public location pages. Searching it happens entirely on your phone.
If you choose a gym and keep an equipment list for it, the app publishes that list to a server operated by the developer so other members of the same gym can start from it instead of typing it out. What is sent is the gym’s identifier, your equipment list, and a random identifier the app generated when it was first launched. That identifier lets the server replace your earlier list when you edit it and count how many people contributed; it is not linked to your name, email, Apple ID, device serial or advertising identifier, and it is reset if you reinstall the app. Lists are combined before they are shown to anyone. Other members see “3 members listed 24 items here”, never who listed what.
If your gym is missing you can add it (name, suburb and state); that entry becomes part of the shared directory for everyone. Please do not put personal information in a gym name.
Sharing workouts
You can share a workout as a link or a QR code. The whole workout (name, exercises, sets, reps and weights) is compressed and encoded inside the link itself; nothing is uploaded and no copy is kept on any server. Anyone who receives the link or scans the code can open the workout, so share it as you would share the workout itself. The page at gymbuddyrhino.com/w that opens when the app is not installed decodes the link in your browser and does not send its contents anywhere.
So that the app can tell you when someone has added a workout you shared (the “Buddy” app icon), the server keeps one small record per share: a short random share code, the random identifier of the phone that shared it, and the random identifier of each phone that added it, with the dates. The workout itself is never sent to the server. These identifiers are not linked to your name, email, Apple ID or account; what the server can see is that one installation shared something another installation added. If you are offline when you share, the link is made without a share code and nothing is recorded. Records of shares nobody added are deleted after a year.
Friend streaks (optional). After two phones have exchanged a workout, each can choose to keep a streak with the other. If you accept, your phone sends the server the calendar dates that count towards your own streak (trained days and covered rest days) for the last 60 days, and receives the same from your friend’s phone. The server holds those dates against the two random installation identifiers and nothing else: no names (you name your friend on your own phone and that name never leaves it), no times, no workouts, no heart rate. Either person can leave at any time, which deletes the pair and all of its dates for both. Nothing is shared until both have accepted.
Scanning a QR code uses the camera. Frames are processed on the device to find a code and are not saved or transmitted.
Apple Health and the lock screen
If you allow it, the app reads your heart rate from Apple Health during a workout, to show it live and record the average and peak for that session, and writes your completed workouts to Apple Health so they appear alongside other activity. Both are optional; the app works without them. Health data read from HealthKit stays on the device, is never sent to our server, and is not used for advertising or shared with anyone. Your rest timer can also appear on the lock screen as a Live Activity; that shows only the timer and exercise name and stays on your phone.
Signing in and cloud backup (optional)
You can use the whole app without an account, and nothing below happens unless you choose to sign in. If you do, Gym Buddy offers Sign in with Apple and Google Sign-In so your training can be backed up and restored: on a new phone, or after reinstalling.
- What signing in sends. Apple or Google gives the app a signed identity token, which is passed to our server to verify who you are. From it the server keeps only the stable, provider- specific identifier for your account and, if the token includes one, your email address. We never receive your Apple or Google password. Signing in with both providers links them to the same account.
- What a backup contains. Exactly what the app holds: your workouts, session history, settings and body-weight log. It is stored on the developer's own server, in Australia, and is used only to give it back to you.
- Backups are not automatic. Nothing is uploaded until you tap Back up now, and this is a backup rather than live sync between devices.
- Deleting your account. Settings → Account → Delete account removes the account, the linked sign-ins and every backup from the server, permanently and immediately. Your data stays on your phone unless you delete the app too.
Signing out leaves your data on the phone and on the server; deleting the account removes the server copy. We do not use any of it to train models, and it is never sold or shared with advertisers.
Purchases (optional)
Rhino Pro and the icon pack are sold through the App Store. When you buy or restore one, Apple handles the payment and tells us only that a purchase happened: which product it was, whether it is still active, and when it renews or expires. We never see your card, your Apple ID, your name or your email.
- What our server keeps. That purchase state, and the store notifications behind it, against the random identifier for your install. If you sign in for cloud backup, the purchase is attached to your account instead so it follows you to a new phone; that is the only way a purchase is ever linked to you.
- The free allowance. Without Pro, Rhino answers a fixed number of messages a week. The server keeps a count per week against the same identifier and nothing else about the messages.
- What we do with it. Unlocking what you paid for, and counting how many people start a trial and stay. Nothing is sold, and there are no advertising identifiers involved.
- Managing or cancelling. Subscriptions renew automatically until cancelled in your App Store account settings, at least 24 hours before the end of the current period. Refunds are handled by Apple.
What we do not do
- No account is required. Sign-in exists only for backup, and the app is fully usable without one.
- No usage tracking and no crash-reporting service. The only counting we do is of purchases and trials, described above.
- No advertising and no advertising identifiers.
- No third-party software development kits that report data to anyone.
- No access to your microphone, contacts or location. Camera and photo-library access is asked for only when you tap a feature that needs it (naming equipment from a photo, scanning a QR code), and Apple Health access only when you turn heart rate or workout saving on.
- No cookies or trackers on this website.
Health information
Training records such as exercises, weights and reps may be considered health-related information in some jurisdictions. Those records stay on your device. Anything you choose to tell Rhino about your body, injuries or health is transmitted as described above; it is your choice what to include, and we recommend keeping it general.
Nothing Rhino says is medical advice. Please read the disclaimer.
Children
Gym Buddy is not directed at children under 13, and we do not knowingly collect information from them. Unless you have signed in, we cannot identify individual users; if you believe a child has sent personal information through the chat, contact us and we will delete any corresponding server records we are able to locate.
Your rights
Your workouts and history are under your direct control: edit or delete them in the app, or delete the app to remove them entirely. Because we hold no account or identifier for you, we generally cannot connect a server-side request to a particular person; if you have a question about data you believe we hold, contact us and we will help where we can. Australian users may also complain to the Office of the Australian Information Commissioner; users in the EU or UK to their local supervisory authority.
Changes to this policy
Any change will be published at this address with a revised effective date. If a future version of the app sends additional data, or sends it somewhere new, this policy will be updated before that version is released and the change described plainly.
Contact
Questions about this policy can be sent to our support address.