Privacy Policy - Holymp
Version: 2.2
Last updated: July 9, 2026
This policy explains how personal data is processed when you use the Holymp app.
1) Data Controller
The Data Controller is:
- Full name: Gabriele Vaccargiu
- Service trade name: Holymp
- Contact location: Parma, Italy
- Privacy and data protection email: privacy@holymp.app
2) Scope
This policy applies to the Holymp mobile app and the connected backend services, including authentication, data synchronization, AI features, premium management, and optional integrations enabled by the user.
3) Categories of Data Processed
Depending on the features used, Holymp may process the following categories of data.
3.1 Account and Authentication Data
- Email.
- Authentication credentials managed with technical measures designed to protect their confidentiality and security.
- Authentication/session tokens.
- Technical data for password recovery, including OTP codes, expiry times, attempts, and technical metadata.
- Google Sign-In data, if used, such as email and profile name.
3.2 Profile and Wellness Data
- Profile data entered by the user, such as display name, sex, height, full date of birth, goals, and training focus.
- Weight and weight history.
- Integration or questionnaire parameters and preferences, such as available days, goals, level, any declared limitations/injuries, and notes.
3.3 Workout and Nutrition Data
- Workout sessions, exercises, sets, repetitions, loads, RPE, timers, and notes.
- Meal, food, macro, nutrition settings, and daily context data, such as short sleep, meal out, or sensitive cycle if entered.
- Data used for summaries, suggestions, and workout plan optimization.
3.4 Health Connect Data
Only with the user’s consent and authorization, Holymp may read the following data from Health Connect:
- steps;
- sleep data;
- exercise/workout data;
- distance.
This data is used for fitness/wellness summaries, activity analysis, personalized suggestions, and improvement of the user experience. Holymp uses this data only to provide features requested by the user in the fitness/wellness context.
The user can revoke Health Connect permissions at any time from Android settings or from the Health Connect app. Revocation may make some personalized features unavailable or less accurate.
3.5 Photos, Videos, Files, Images, and Voluntary Attachments
Access to photos, videos, images, media, or files is optional, initiated by the user, and limited to features where the user explicitly chooses to capture or upload content.
Examples:
- meal photos for AI or food analysis features;
- voluntary attachments to workout sheets;
- bug reports, screenshots, or images sent by the user;
- explicit uploads of supported files or media.
3.6 Premium, AI Coach Credits, and Purchase Data
When you use Premium features or buy AI Coach credits, Holymp may process the data needed to manage access to the service and purchases, including:
- the account’s Premium status;
- AI Coach credit balance;
- credits purchased, used, and remaining;
- technical purchase data, such as store/platform, product id, transaction id, purchase token or receipt, technical identifiers, and related technical representations or hashes when used for verification and security.
Holymp does not store full card details or full payment method details. Payment is handled by the store or payment provider shown in the purchase flow.
3.7 Technical, Security, and Log Data
- Internal User ID.
- Operation timestamps, session state, minimum diagnostics, and rate limit data.
- Technical events necessary for security, abuse prevention, and service continuity.
Some of the data above, including weight, wellness status, declared injuries, workout data, nutrition data, and Health Connect data, may qualify as health-related data.
4) App Permissions and Device Access
Depending on the features used, the app may request:
- Camera.
- Access to images, media, or files selected by the user.
- Notifications.
- Local notification scheduling, such as recovery timers.
- Foreground service for an active timer.
- Health Connect permissions to read steps, sleep, exercise/workout, and distance.
Permissions are requested by the operating system and can be revoked at any time from device settings. For Health Connect, revocation can also be managed from Android Health Connect settings.
5) Purposes and Legal Bases
Data is processed for:
-
Account creation, login, password recovery, profile management, provision of requested features, workouts, meals, synchronization, and premium.
Legal basis: Article 6(1)(b) GDPR. -
Fitness/wellness summaries, activity analysis, personalized suggestions, and improvement of the user experience, including through Health Connect data when the user grants permissions.
Legal basis: Article 6(1)(b) GDPR for provision of the requested features and, where necessary, Article 9(2)(a) GDPR for health-related data based on explicit consent. -
Management of purchases, subscriptions, AI Coach credits, and Premium features, including delivery of the purchased credit or feature, purchase status verification, support for payment or access issues, security, and prevention of fraud, abuse, or unauthorized reuse of receipts or tokens.
Legal basis: Article 6(1)(b) GDPR for performance of the service or purchase; Article 6(1)(c) GDPR for accounting, tax, or legal obligations; Article 6(1)(f) GDPR for security and fraud or abuse prevention. -
Service security, abuse/fraud prevention, rate limiting, and technical incident management.
Legal basis: Article 6(1)(f) GDPR. -
Legal, tax, and competent authority requirements.
Legal basis: Article 6(1)(c) GDPR. -
Verification of the minimum age required to use the service in Italy, prevention of under-threshold use, and application of technical blocks required by applicable rules.
Legal basis: Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.
6) Nature of Provision
- Data necessary for the account and main features is required to use the service.
- Optional data, such as notes, attachments, some preferences, optional AI features, photos/files, and Health Connect integrations, is provided freely.
- Failure to provide required data may prevent full or partial use of the app.
- Failure to grant or revocation of Health Connect permissions does not prevent general app use, but may limit features, summaries, or suggestions based on that data.
7) Third-Party Services and Data Recipients
Data may be processed by external providers appointed, where required, as processors.
- Federated authentication: Google, if the user uses Google Sign-In.
- Health Connect: Android platform used by the user to authorize reading of supported health/fitness data.
- Text/image AI, when the AI feature is used: providers configured on the backend, such as OpenAI and/or DeepSeek depending on the active configuration.
- External food database, when used: OpenFoodFacts.
- Technical emails, such as password reset: SMTP provider configured by the Controller.
- Technical infrastructure: backend hosting, database, storage, network/CDN of the service.
- Payment store: Google Play/Apple, depending on platform, for in-app purchase management.
Holymp does not sell personal data to third parties and does not use third-party behavioral advertising in the app.
8) Transfers Outside the EEA
Some providers may process data outside the EU/EEA. In such cases, the Controller adopts the safeguards required by Articles 44 et seq. GDPR, such as standard contractual clauses where applicable.
9) Retention Periods
Data is stored for the time necessary for the purposes listed above.
- Account/profile data: until account deletion, unless legal obligations apply.
- Workout/nutrition/weight/attachment data and Health Connect data imported or used by the app: until deletion by the user or account deletion.
- Password reset, OTP, or temporary token data: limited technical retention according to security configuration.
- Purchase, Premium, and AI Coach credit data: stored only for as long as necessary to provide the purchased service, handle support, technical checks, security and fraud or abuse prevention, and comply with accounting, tax, or legal obligations.
- Technical and security logs: 90 days.
- Backups: limited rolling retention: 30 days.
When we receive a valid account deletion request, we delete the associated data except data that must be retained due to legal obligations or defense of rights.
10) Account Deletion
Account deletion is available in-app at:
Settings > General > Account > Delete account
The external channel required by app stores is also available:
- External account deletion page URL: https://holymp.app/account-deletion/
- Account deletion page in Italian: https://holymp.app/account-deletion/it
- Account deletion page in English: https://holymp.app/account-deletion/en
11) Security
Technical and organizational measures proportionate to the risk are adopted, including:
- Encrypted connections in transit, HTTPS/TLS.
- Authentication and authorization controls.
- Data minimization.
- Logical separation of access and protection of environments.
- Account deletion and user content management procedures.
No system is completely invulnerable; measures are updated over time.
12) Data Subject Rights
Under the GDPR you may exercise:
- access;
- rectification;
- erasure;
- restriction;
- objection, where applicable;
- portability, where applicable;
- withdrawal of consent, without affecting the lawfulness of previous processing.
To exercise your rights, write to: privacy@holymp.app.
You also have the right to lodge a complaint with the Italian Data Protection Authority.
13) Minors
For the current release in Italy, Holymp applies a minimum use threshold of 14 years.
- During registration or first access, the full date of birth is requested.
- If the minimum threshold is not met, access is technically blocked and the user cannot use the app features.
- Any privacy consent given does not replace the minimum age requirement.
If we detect under-threshold use or data provided in violation of the limit, we adopt blocking measures and proceed, where requested and within technical/legal limits, with data deletion.
14) Automated Processes and AI Features
The app may generate automatic suggestions, such as nutritional estimates and workout optimizations.
These outputs are for informational support and do not replace professional medical, healthcare, nutrition, or personal training assessments.
15) Future Evolution of AI Features
In the future, Holymp may introduce additional processing to improve AI suggestion quality.
Before enabling new processing that is not compatible with this policy, the policy will be updated and, where necessary, dedicated consent will be requested.
16) Changes to This Policy
This policy may be updated over time.
The updated version will be published at the same URL or on the dedicated language pages and, where necessary, notified in-app.
17) Terms of Use and Disclaimer
Terms of use and disclaimer for the service are available at:
https://holymp.app/terms/