Throvy is built by an independent developer based in the Netherlands. This document explains what data the app collects, where it is stored, what we do and don't do with it, and what rights you have.
What we collect
When you create an account
- Email address (for login).
- A handle and display name (for the social features).
- Optional: name, date of birth, gender, weight, fitness goal, training experience, dietary preferences.
When you use the app
- Workouts you create — exercises, sets, reps, RPE, weight.
- Completed sessions — date, exercise data, total volume.
- Nutrition log entries — food name, macros, timestamp.
- Saved meals — favourites list.
- Supplement list and intake log.
- Supplement reminders you create — which supplements, the time or trigger, and how often they repeat.
- Notification preferences.
- An optional profile photo.
- Feed posts you share with friends — workout summary, optional caption, optional photo.
- Friend connections and group memberships.
- Groups you create — name, whether they're private or public, and a join code.
- If a group creator bans you from their group, we record that so the ban holds.
When you use the AI features
- Your message text is sent to Anthropic for processing by Claude.
- For food photo analysis, the photo (or its description) is sent to Anthropic.
- A short conversation history accompanies each request so the coach can follow up sensibly.
Where data is stored
| Component | Provider | Region |
|---|---|---|
| Account, profile, workouts, sessions, nutrition, supplements, social | Supabase (Postgres + Auth) | EU |
| Backend API (stateless) | Railway | EU |
| AI requests (chat, plan generation, food vision) | Anthropic (Claude API) | US |
| Subscription payments (Pro / Premium) | Google Play Billing (Google Ireland Ltd.) | EU / Ireland |
| Transactional email (sign-up confirmation, password reset) | Resend | EU / US |
| Advertising (free tier only) | Google Ireland Ltd. (AdMob) | EU / Ireland |
Per Anthropic's public API privacy policy at the time of writing, API inputs are not used to train their models.
What we do NOT do
- We do not sell your data to anyone.
- We do not share your training or nutrition data with third parties for marketing.
- We do not store your photos or chat messages anywhere other than what's described above.
- We do not show ads to paying users (Pro / Premium) — only free-tier users see ads, and Pro/Premium remove them entirely.
Third parties we use
- Supabase — authentication and database (EU region).
- Anthropic — AI coach, plan generator, food vision (US-based; API data not used for model training).
- Railway — backend hosting (EU region).
- Expo / Apple / Google — sign-in providers (only when you use those buttons) and push notification delivery.
- Google Play Billing — subscription billing for Pro / Premium plans. Payment is completed entirely inside your Google Play account; no payment screen we control is ever involved and Throvy never sees or stores card details. We receive only a purchase token and the resulting tier. Google processes the payment under their own privacy policy.
- Resend — delivers our transactional emails (sign-up confirmation, password reset). It processes your email address solely to send those messages, under its own privacy policy.
- Google AdMob (Google Ireland Ltd.) — serves ads to free-tier users only. See the "Advertising" section below for what is collected, the legal basis, and how to opt out.
Advertising (free tier)
Free accounts see two ad types, both supplied by Google AdMob:
- A short interstitial after you submit or share a workout.
- An optional rewarded video you can choose to play to earn one Throvy credit.
What AdMob and its partners may collect
Google and the ad-tech vendors it works with may receive, depending on your consent choice:
- An advertising identifier (AAID on Android, IDFA on iOS) — a resettable device-level ID, not your name or email.
- Coarse IP-derived location (city / country level).
- Device + OS information, screen size, network type, app version.
- Ad interaction data (impressions, clicks, video completion).
- For personalized ads only: a derived advertising profile based on your activity in this and other apps that use the same ID.
Throvy itself never sees this data — it stays inside Google's SDK and is sent directly to Google's ad servers. Throvy doesn't share your account email, training data, nutrition data, photos, or chat history with AdMob.
Legal basis (GDPR Art. 6)
- Consent (Art. 6(1)(a)) — for personalized advertising and for the use of an advertising identifier for measurement and frequency capping. Collected via Google's Consent Management Platform dialog on first launch.
- Legitimate interests (Art. 6(1)(f)) — for non-personalized advertising (showing an ad that isn't tailored to you, only to detect basic ad fraud). You can object at any time; doing so removes the ads entirely (and removes a small revenue source).
Withdrawing consent / opting out
- In-app: go to Profile → Privacy → Ad preferences at any time to re-open the consent dialog and change your choice. Withdrawing personalization is immediate and does not affect anything else in the app.
- Device-level: Android → Settings → Google → Ads → "Reset advertising ID" or "Opt out of Ads Personalization". iOS → Settings → Privacy & Security → Tracking → turn off "Allow Apps to Request to Track".
- Remove ads entirely: upgrade to Pro or Premium. Paying users see zero ads.
Data retention (AdMob)
Google retains advertising data for its own analytics and fraud-detection purposes under its own retention schedule — see Google's advertising privacy notice and Google's ad partner list. The advertising identifier on your device can be reset by you at any time in your phone settings, which severs the link to historical data.
Children
Throvy is for users 16 and over. AdMob is configured to never request personalized ads for accounts where age cannot be established as 18+. If you suspect a child has registered an account, contact throvygymsupport@gmail.com.
Notifications we send
Two categories. Locally-scheduled notifications never leave your phone. Server-pushed social notifications are routed via Expo's push service — composed on our backend, no data you didn't already share with the friend who triggered it. Each one can be toggled off from Settings → Notifications.
Locally-scheduled
- Morning workout encouragement — a "good luck with your session" nudge at the time you set, only on days a workout is planned.
- Workout not logged — a single evening reminder if a planned workout still hasn't been logged.
- Supplement reminders — as many as you create, each naming the supplements you picked. A reminder fires either at a time you choose (daily, weekdays, weekends, or specific days) or shortly after you complete a workout. You can set one to keep nudging every 30 or 60 minutes until midnight; it stops the moment you tick everything off. Reminders on the same minute arrive as one notification, not several.
- Bodyweight reminder — one nudge at the time you set, encouraging you to log your bodyweight so the trend chart stays meaningful.
- Streak reminder — an evening nudge only on a night your active workout streak is at risk (a 2+ day streak with nothing logged that day yet).
- Weekly recap — a Sunday-evening summary of the week's logged sessions and total volume.
- Birthday — an annual greeting on your date of birth.
- Test notification — fires five seconds after you tap "Send test", so you can verify delivery works on your device.
Server-pushed (from friends' actions)
- New like — when a friend likes one of your feed posts.
- New comment — when a friend comments on one of your feed posts.
- New reply — when someone replies to a comment you left, on any post.
- Friend request — when another user sends you a request.
- Friend request accepted — when a user accepts a request you sent.
- Group invite — when a friend invites you to one of their groups.
- Friend shares a workout — when a friend posts a workout to the feed.
- Leaderboard passed — when a friend overtakes you and you were in the top 3.
To deliver these we store an Expo push token on your profile; you can clear it by revoking notification permission in your phone settings. A burst of likes/comments is debounced server-side so you receive at most one push per friend per hour.
Your rights under the GDPR
You have the right to:
- Access the data we hold about you.
- Correct data that's inaccurate.
- Delete your account and all associated data.
- Export your data in a portable format.
- Object to processing or restrict it.
To exercise any of these rights, email throvygymsupport@gmail.com. Account deletion can also be requested in-app.
California residents (CCPA / CPRA)
If you live in California, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA:
- Right to know what personal information we collect about you — the "What we collect" and "Where data is stored" sections above cover this in full.
- Right to delete your account and its personal information — request in-app, or by email.
- Right to correct inaccurate personal information — email the address below.
- Right to opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising.
- Right to non-discrimination — exercising these rights won't cause us to reduce your service or charge you a different price.
Throvy does not sell your personal information for money. However, the AdMob advertising described in the "Advertising on the free tier" section involves what the CPRA defines as "sharing" personal information (device identifier and coarse location, forwarded to Google's ad-partner network for cross-context behavioural advertising to free-tier users).
To opt out of that sharing:
- In-app: on first launch a US-states privacy notice appears where you can decline. You can re-open it any time via Profile → Privacy → Ad preferences.
- Device-level: iOS → Settings → Privacy & Security → Tracking → turn off "Allow Apps to Request to Track". Android → Settings → Google → Ads → "Opt out of Ads Personalization".
- Remove ads entirely: upgrade to Pro or Premium. Paying users see no ads, so no personal information is shared with the ad network at all.
For any CCPA/CPRA request, or if we can't verify your identity from your account details, email throvygymsupport@gmail.com. You may also designate an authorised agent to submit a request on your behalf.
Children
Throvy is intended for users aged 16 and over. If you are under 16, please do not use the app without the explicit consent of a parent or legal guardian.
Data retention
- Account, workout, nutrition data — kept until you delete them or the account.
- AI chat history — lives on your device for the duration of the conversation; the content is sent to Anthropic only at request time.
Changes to this policy
If we change this policy, the "Last updated" date at the top will change. Material changes will also be flagged in the app on the next launch.
Contact
The controller for your personal data is:
- Throvy, an independent developer in the Netherlands trading as throvygym
- Stoofweg 4, 4306 NC Nieuwerkerk, Netherlands
- KvK 42067059 · VAT NL005471562B05
- +31 6 13493355
- throvygymsupport@gmail.com
For data subject requests, complaints under the GDPR, or any privacy question, use the email above. We aim to respond within 30 days.
Not happy with how we handled it? You can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in your own EU country.