Privacy Policy
1. INTRODUCTION
Welcome to Gloox (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring you have a positive experience when using our fitness app with an AI coach feature (“App”) and our website (“Website”).
This Privacy Policy explains our practices regarding the collection, use, and disclosure of your information through your use of our App and Website, and sets out your privacy rights. We recognize the importance of protecting your personal information and are committed to handling it responsibly and in accordance with applicable data protection laws, including the UK Data Protection Act, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable international privacy laws.
Our App is available worldwide, and we are committed to complying with local privacy laws in the countries where our users are located. In the event of any conflict between this Privacy Policy and local laws, local laws will prevail to the extent necessary.
By downloading, accessing, or using our App or Website, you agree to the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our App or Website.

2. COMPLIANCE WITH GOOGLE PLAY POLICIES
Our app complies with the Google Play Developer Content Policy and other platform requirements. By using our app downloaded via Google Play, you also agree to comply with the Google Play Terms of Service and the Google Privacy Policy.
2.1 Security and Privacy
We adhere to Google Play’s security and privacy requirements:
  • We do not collect sensitive data without the user’s explicit consent
  • We use secure methods of data transmission and storage
  • We do not share personal data with third parties without consent, except as described in this Privacy Policy
  • We comply with child protection requirements and do not collect data from users under the age of 16
2.2 Payment Processing
All payments in our app are processed through Google Play Billing in accordance with their security and privacy policies. We do not store payment card data on our servers.

3. INFORMATION WE COLLECT
Data Minimization Statement: We collect and process only the personal data that is strictly necessary to provide and improve our services. We regularly review our data collection practices to ensure compliance with the principle of data minimization.
We collect the following categories of information:
3.1 Information You Provide to Us
  • Account Information: When you register an account, we collect your name and email address. Legal basis: Performance of a contract
  • Profile Information: Information you provide in your user profile, including your height, age, and weight. Legal basis: Explicit consent
  • Workout Data: Information about your workouts, exercise programs, fitness goals, and progress. Legal basis: Explicit consent
  • Messages: Information you provide when you contact us for support or communicate with us. Legal basis: Legitimate interests
  • Payment Information: If you subscribe to our premium services, payment information is processed by Google Play Billing. Legal basis: Performance of a contract
3.2 Information We Collect Automatically
  • Device Information: Information about the Android device you use to access our App, including device type, operating system, and unique device identifiers. Legal basis: Legitimate interests
  • Usage Information: Information about how you use our App, including features used, time spent in the App, and other usage statistics. Legal basis: Legitimate interests
  • Location Information: With your consent, we may collect precise location information from your device. Legal basis: Consent
  • Log Information: Information automatically recorded by our servers when you access our App, including your IP address, browser type, referral/exit pages, and timestamps. Legal basis: Legitimate interests
  • Device Identifiers and Similar Technologies: We use device identifiers and similar tracking technologies to collect information about your activity in our mobile app. Legal basis: Consent for non-essential features; Legitimate interests for essential features
3.3 Information from Third Parties
  • Analytics Providers: We use Google Analytics and Firebase to collect information about how you use our App. Legal basis: Legitimate interests
  • Social Media Platforms: If you choose to connect your social media accounts, we may receive information from those platforms. Legal basis: Consent
  • Google Play Services: We may receive information via Google Play Services to improve app functionality. Legal basis: Legitimate interests
3.4 Fitness Devices and Health Sensors
If you use our App with fitness devices or health sensors, we collect the following health-related data with your explicit consent:
  • Heart Rate Data: We collect heart rate information during workouts to provide real-time feedback and optimize your training. Legal basis: Explicit consent
  • Calorie Data: We collect information about calories burned during workouts to track your progress. Legal basis: Explicit consent
  • Activity Data: Information about steps, distance traveled, and other activity metrics from compatible devices. Legal basis: Explicit consent
This data is collected through compatible fitness devices and sensors. In accordance with our privacy principles:
  • We access this data only with your explicit permission, which you can revoke at any time via the app settings
  • We never sell your health data to advertising platforms, data brokers, or information resellers
  • We never use your health data for advertising, marketing, or other usage-based data mining purposes
  • We never disclose your health data to third parties without your explicit consent
You can control which health data our App can access by configuring privacy settings in the app.
Special Notice Regarding Health Data: Some of the data we collect, such as your weight, height, heart rate, calories, and workout data, may be considered health-related data under certain data protection laws. We process this data only with your explicit consent, which you can withdraw at any time.

4. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
4.1 To Provide and Maintain Our Services
  • Setting up and managing your account Legal basis: Performance of a contract
  • Providing AI coach functionality Legal basis: Performance of a contract and Explicit consent for health data
  • Tracking your fitness progress Legal basis: Performance of a contract and Explicit consent for health data
  • Processing transactions via Google Play Billing Legal basis: Performance of a contract
  • Responding to your comments, questions, and requests Legal basis: Legitimate interests
4.2 To Improve and Develop Our Services
  • Understanding how users interact with our App Legal basis: Legitimate interests
  • Identifying usage trends and determining the effectiveness of our promotional campaigns Legal basis: Legitimate interests
  • Developing new features, products, and services Legal basis: Legitimate interests
  • Debugging to identify and fix errors Legal basis: Legitimate interests
  • Ensuring compatibility with new versions of Android Legal basis: Legitimate interests
4.3 To Personalize Your Experience
  • Providing personalized content, such as workout recommendations Legal basis: Performance of a contract and Explicit consent for health data
  • Remembering your preferences and settings Legal basis: Legitimate interests
  • Providing targeted advertising (with your consent where required by law) Legal basis: Consent
4.4 To Communicate with You
  • Sending administrative messages about our services Legal basis: Performance of a contract
  • Providing customer support Legal basis: Performance of a contract
  • Sending marketing communications (with your consent where required by law) Legal basis: Consent
  • Responding to your inquiries Legal basis: Legitimate interests
4.5 To Ensure Security and Compliance
  • Detecting, investigating, and preventing fraudulent activities and other illegal actions Legal basis: Legal obligation and Legitimate interests
  • Protecting the rights, property, or safety of you, us, or others Legal basis: Legal obligation and Legitimate interests
  • Complying with legal obligations and Google Play policies Legal basis: Legal obligation
4.6 Profiling and Automated Decision-Making
Our App uses AI technology to analyze your workout data, physical parameters, and fitness goals to create personalized training plans. This process involves profiling and automated decision-making. The AI considers factors such as:
  • Your past workout history and performance
  • Your physical parameters (height, weight, age)
  • Your stated fitness goals
  • Your reported limitations or injuries
  • Your heart rate and calorie data from fitness devices (if you use this feature)
AI Decision Logging and Transparency: All automated decisions made by our AI coach are logged for audit and transparency purposes. Users may request a summary of AI decisions affecting their training plans and can contact us to request human review of any automated recommendation.
You have the right to human intervention, to express your point of view, and to contest any decision made by our automated systems. To exercise these rights, please contact us using the information in Section 15.

5. HOW WE SHARE YOUR INFORMATION
We may share your information with the following categories of third parties:
5.1 Service Providers
We share information with third-party vendors, consultants, and other service providers who perform services on our behalf, such as:
  • Cloud Storage Providers: Amazon Web Services (AWS) – stores user data and app infrastructure
  • Payment Processors: Google Play Billing – processes subscription payments
  • Analytics Providers: Google Analytics and Firebase – analyze app usage and performance
  • Customer Support Services: Zendesk – manages support tickets and customer communications
These service providers are contractually obligated to use your information only in accordance with our instructions and in compliance with this Privacy Policy.
Important Note About Health Data: We do not share any health data collected via fitness devices with any service providers or third parties without your explicit consent.
5.2 Google Play Services
Certain information may be shared with Google via Google Play Services for:
  • Processing payments and managing subscriptions
  • Providing analytics and app performance reports
  • Ensuring security and preventing fraud
  • Compliance with Google Play policies
This data sharing is governed by the Google Privacy Policy.
5.3 Business Partners
With your consent, we may share information with business partners who offer joint promotions or products. These partners include fitness equipment manufacturers, supplement companies, and sportswear brands that may provide special offers to our users.
We never share your health data (heart rate, calories) with any business partners under any circumstances.
5.4 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., a court or government agency).
5.5 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you by email and/or by a prominent notice in our App of any change in ownership or use of your personal information, as well as any choices you may have regarding your personal information.
5.6 With Your Consent
We may share your information with third parties if you have given us your consent to do so.

6. DATA RETENTION
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. When your personal information is no longer needed, we securely delete or anonymize it.
Clarification on Backup Data Retention: Personal data deleted by users will be removed from all backup systems within 90 days. During this period, backup data is not available for routine processing and is restored only in the event of a disaster recovery scenario.
When determining the retention period, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, and applicable legal requirements.

7. YOUR PRIVACY RIGHTS
Depending on your location, you may have certain rights regarding your personal information. We are committed to honoring these rights regardless of your location, although the specific legal basis may vary.
7.1 Rights under the GDPR (EU and UK Users)
If you are located in the European Union or the United Kingdom, you have the following rights:
  • Right of Access: You have the right to request a copy of the personal information we hold about you.
  • Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal information.
  • Right to Erasure: You have the right to request that we delete your personal information under certain circumstances.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information under certain circumstances.
  • Right to Data Portability: You have the right to request that we transfer your personal information to another service provider in a structured, commonly used, and machine-readable format.
  • Right to Object: You have the right to object to the processing of your personal information under certain circumstances, including processing for direct marketing or profiling.
  • Right to Withdraw Consent: You have the right to withdraw your consent at any time if we rely on consent to process your personal information.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law.
7.2 Rights under the CCPA (California Residents)
If you are a California resident, you have the following rights:
  • Right to Know: You have the right to request information about the personal information we collect, use, disclose, and sell.
  • Right to Delete: You have the right to request that we delete your personal information, subject to certain exceptions.
  • Right to Opt Out of Sale: You have the right to opt out of the sale of your personal information. However, we do not sell your personal information.
  • Right to Non-Discrimination: You have the right not to be discriminated against for exercising your privacy rights.
7.3 Rights under Other Privacy Laws
Users in other jurisdictions may have similar rights under their local laws, such as:
  • Brazil (LGPD): Rights similar to those under the GDPR
  • Canada (PIPEDA): Rights to access, correction, and withdrawal of consent
  • Australia (Privacy Act): Rights to access and correction
  • Japan (APPI): Rights to disclosure, correction, and cessation of use
We are committed to honoring these rights in accordance with applicable local laws.
7.4 How to Exercise Your Rights
To exercise your privacy rights, please contact us using the contact information provided in Section 15. We will respond to your request within the timeframes required by applicable law (30 days for GDPR requests, 45 days for CCPA requests, and similar timeframes for other jurisdictions).
You can also manage health data permissions directly through the app settings. To manage which health data our App can access:
  1. Open our app on your Android device
  2. Go to “Settings” → “Privacy”
  3. Select “Health Data Permissions”
  4. Enable/disable specific categories of health data you want to allow or restrict
We may need to verify your identity before processing your request. We will use the information you provide in your request solely to verify your identity and to process your request.

8. DATA SECURITY
We implement appropriate technical and organizational measures to protect your personal information from unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
  • Encryption: We use AES-256 encryption for data at rest and TLS 1.2+ for data in transit
  • Access Controls: We enforce strict access controls and authentication mechanisms, including multi-factor authentication for our staff
  • Regular Security Audits: We conduct regular security assessments and penetration testing
  • Employee Training: We provide regular training for our employees on data protection and security
  • Incident Response Plan: We maintain a comprehensive incident response plan to address potential data breaches
  • Enhanced Protection for Health Data: We apply additional security measures to health-related data, including heart rate and calorie data from fitness devices
  • Google Play Compliance: We comply with all Google Play security requirements to protect user data
However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

9. DATA BREACH NOTIFICATION
Data Breach Notification: In the event of a data breach that may pose a risk to your rights and freedoms, we will notify affected users and relevant authorities without undue delay and, in any case, within 72 hours of discovering the breach, in accordance with applicable law. We will also notify Google Play in accordance with their requirements.

10. INTERNATIONAL DATA TRANSFERS
As a global app, your personal information may be transferred to and processed in countries other than your country of residence. In particular, our servers are located in the United States, Ireland, and Singapore, and our third-party service providers and partners operate worldwide.
We have implemented appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy during international transfers. These safeguards include:
  • Implementing the European Commission’s Standard Contractual Clauses for transfers of personal information between our group companies and our third-party service providers and partners
  • Ensuring that recipients of your personal information are bound by data protection terms in our contracts with them
  • Conducting regular assessments of data protection laws in the countries to which we transfer data
  • Implementing any additional safeguards required by local laws in various jurisdictions
  • Complying with Google Play requirements for international data transfers
You may request a copy of our Standard Contractual Clauses by contacting us using the information in Section 15.

11. CHILDREN’S PRIVACY
Our App is not intended for children under the age of 16, and we do not knowingly collect personal information from children under 16. We implement the following measures to prevent data collection from children:
  • Age verification during registration
  • Immediate deletion of any account and associated data if we discover that a user is under 16
  • Verification of parental consent for users aged 16 to 18
  • Compliance with Google Play child protection requirements
If you believe we may have any information from or about a child under 16, please contact us immediately at support@gloox.app, and we will take steps to delete such information as soon as possible.

12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or by other means, such as email, at least 30 days before the changes take effect. The notice will include a summary of the changes and information on how to access the previous version of the Privacy Policy.
Your continued use of our App after the effective date of the revised Privacy Policy signifies your consent to the changes. If you do not agree with the revised Privacy Policy, you should stop using our App.
We encourage you to periodically review this Privacy Policy to stay informed about our information practices.

13. THIRD-PARTY SERVICES
Our App may integrate with or provide access to third-party services (such as fitness devices, social networks, Google Services, etc.). Your use of such services is governed by their terms and privacy policies.
When you connect our App to third-party services (such as Google Fit, fitness devices, or social media platforms), we may share data with those services. Data sharing depends on the specific integration and your settings both in our App and in the third-party service.
We are not responsible for the content, accuracy, policies, practices, or reliability of third-party services. We do not endorse or guarantee third-party content available through the app.
We encourage you to review the privacy policies of any third-party services you access or connect to through our App.

14. AI FUNCTIONALITY AND DATA PROCESSING
Our App includes an AI coach feature that provides personalized workout recommendations and fitness guidance. Here is how we process your data for this functionality:
14.1 Data Used by Our AI Coach
Our AI coach uses the following data to generate personalized recommendations:
  • Your profile information (height, weight, age)
  • Your fitness goals and preferences
  • Your workout history and performance
  • Your reported limitations or injuries
  • Your heart rate and calorie data from fitness devices (if you use this feature)
14.2 How Our AI Works
Our AI coach uses machine learning algorithms to analyze your data and generate personalized training plans. The system:
  • Analyzes patterns in your workout history to identify effective exercises for your goals
  • Adjusts workout intensity based on your performance and feedback
  • Takes your physical parameters into account to ensure proper exercise selection
  • Adapts recommendations based on your progress over time
  • Uses heart rate data to optimize workout intensity and recovery periods
  • Tracks calorie expenditure to help you achieve your fitness and weight management goals
14.3 Training and Improving the AI
To improve our AI coach, we may use anonymized and aggregated user data to train our algorithms. This process includes:
  • Removing all personally identifying information
  • Aggregating data from multiple users
  • Using technical safeguards to prevent re-identification
You may opt out of the use of your anonymized data for AI training by contacting us at support@gloox.app.
We never use health data (heart rate, calories) for AI training without your explicit consent, and we never use such data for advertising or marketing purposes.
14.4 Important Limitations
Please note the following important information about our AI functionality:
  • Not Medical Advice: The AI coach functionality is intended to provide general fitness recommendations and is not intended to provide medical advice, diagnosis, or treatment.
  • Inherent Limitations: While we strive to provide accurate and helpful recommendations, our AI technology has inherent limitations and may occasionally make errors or provide recommendations that are not optimal for your specific circumstances.
  • Use Your Judgment: Always use your own judgment when following AI-generated recommendations and discontinue any activity that causes pain or discomfort.
  • Consult Healthcare Providers: Consult healthcare providers before starting any new fitness program, especially if you have pre-existing conditions.

15. CONTACT US
15.1 Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: support@gloox.app
Postal Address:
Stoney Works
8 Stoney Lane
London, England
SE19 3BD
15.2 EU Representative
You can contact our representative in the European Union for data protection matters at support@gloox.app.
If you are located in the European Union or the United Kingdom and have concerns about our processing of your personal information that we cannot resolve, you have the right to lodge a complaint with the data protection authority where you reside.
15.3 Mobile App Permissions and Push Notification Policy
Our mobile app may request the following permissions on your Android device:
  • Camera: Used for scanning QR codes and taking progress photos
  • Location: Used for tracking outdoor workouts and finding nearby fitness centers
  • Storage: Used to save workout data and progress photos locally
  • Microphone: Used for voice commands and audio feedback during workouts
  • Motion Sensors: Used to track movement during exercises
  • Notifications: Used for workout reminders and updates.
  • Push Notification Policy: We use push notifications to send you workout reminders, motivational messages, and important service updates. You may opt out of non-essential notifications at any time via your device settings or the app’s notification settings.
  • Access to Fitness Data: Used to access heart rate and calorie data from compatible fitness devices
You can manage these permissions through your device settings at any time.
15.4 Google Play-Related Questions
For Google Play-related questions (payments, refunds, platform technical issues), you can also contact Google Play Support.
15.5 Special Health Data Controls
Our App integrates with fitness devices to access heart rate and calorie data. You have full control over this integration:
  • You can allow or deny our App access to specific types of health data in the app settings
  • You can view all health data that our App has accessed in the “Privacy” section of the settings
  • You can revoke our App’s access to your health data at any time
We are committed to respecting your privacy choices regarding your health data and will access only the data you explicitly allow.
Social:
© 2025 — Gloox
Address:
Stoney works 8 stoney lane, London, England, SE19 3BD
Des & dev: