Updated · February 18, 2025

Privacy Policy

How we collect, use and protect your personal data. NOEX is operated by Gympiper Kft. and complies with the GDPR.

Overview

Updated at 2025-02-18

NOEX (referred to as “NOEX,” “we,” “us,” or “our”) is owned and operated by Gympiper Ltd. We respect your privacy and are committed to safeguarding your personal information. This Privacy Policy outlines how we collect, use, and share your personal data when you use our mobile application, NOEX.

When we say “personal data” or “personal information”, we are referring to information related to you. Such information is not limited to what directly identifies you, such as your name. In fact, you own and have legal rights to anything that speaks of you: the data you enter about your fitness experience, your aim for using the Product, and even the way you use the Product itself. To avoid legalese, we can also use “your data” or “your information” in the same meaning.

This notice is meant to provide you with all the relevant information to make an informed choice to use the Product. It also serves to inform you of your rights and how you can exercise them. Contact us if you have any questions or concerns.

This Notice was written in English. to the extent a translated version of the Notice conflicts with the English version, the English version prevails.

Information We Collect

We collect the following types of personal information when you use NOEX:

Personal Information

  • Your name
  • Email address
  • Username
  • Unique app identifier

You provide us with this information when you register for the Service, purchase our physical products, subscribe to our newsletters , or contact us by any other means.

Commercial information

When you make a payment through the Service, you’ll need to provide your payment details, such as your credit card number, to our third-party payment processors. We don’t collect or store your full credit card number, but we may receive some basic information, such as a secure token, purchase details (like the product, amount, and date), and partial digits of your card number.

Health data from Apple HealthKit, including

  • Body measurements
  • Date of birth
  • Gender
  • General activity data

Workout data, including

  • Exercises performed
  • Sets
  • Reps
  • Weight
  • Duration

Food and nutrition data, including

  • Meals eaten
  • Calories consumed
  • Macronutrients

User-Generated Content

The NOEX application allows users to share their own content, such as workout logs, images, and other information on the community platform. By uploading content to the platform, you acknowledge and accept that such content may be accessible to other members of the NOEX community, depending on your chosen privacy settings.

  • Users are responsible for the content they upload, including images, comments, and other media.
  • NOEX reserves the right to moderate or remove content that violates community guidelines or is deemed unlawful.
  • If users choose to share their workout data (e.g., progress, weight changes, transformation photos), they do so voluntarily and can delete the uploaded content at any time.
  • Users acknowledge that if they comment on a post or interact with other content, their interaction will also be visible to other users .

User-Generated Content & AI Features

  • NOEX AI analyzes user-generated content (e.g., uploaded videos, workout logs, and progress photos) to improve feedback quality.
  • AI-powered form feedback features use image/video recognition to detect movement patterns, but NOEX does not store or use biometric data for other purposes.
  • NOEX may anonymize and aggregate user data to improve AI recommendations and system efficiency.

Privacy & Data Protection (GDPR & AI Compliance)

  • NOEX uses AI-powered features to analyze workout patterns, performance metrics, and user preferences to provide personalized training recommendations.
  • By using the Service, you consent to the collection and processing of fitness-related data (e.g., workout progress, exercise logs, recovery status, and engagement levels) to optimize AI-generated recommendations.
  • Users can manage AI-driven data collection preferences via Privacy Settings in the NOEX app.

How AI Uses Your Data

Personalized Workouts: AI adjusts exercise recommendations based on past activities, preferences, and recovery status.

Habit Tracking & Optimization: AI suggests routines, badges, and streaks to enhance consistency.

Real-time Adjustments: NOEX AI adapts set/rep schemes and intensity based on progress.

Injury Prevention Alerts: AI detects potential overtraining patterns based on user inputs.

Opt-Out Option: Users may disable AI data collection at any time in account settings.

Image and Video Uploads

  • Users can upload images and videos related to their workouts, progress, or other fitness-related content.
  • Uploading images and videos is optional , and users can delete them at any time.
  • NOEX does not use uploaded images for advertising purposes without the user’s explicit consent .
  • Users are responsible for ensuring they have permission from any individuals who appear in the uploaded images before posting them.

Privacy Settings for Shared Content

  • NOEX allows users to control the visibility of their shared content.
  • The following privacy settings are available:
  • Private: Workout data and images are visible only to the user.
  • Restricted Sharing: Workout data and images are visible only to selected followers or friends.
  • Public: Workout data and images are visible to all NOEX users.
  • Users can modify their privacy settings at any time within the app.

Right to Delete and Withdraw Consent

  • Users can delete their uploaded images, videos, or workout data at any time using the appropriate feature in the app.
  • When a post is deleted from the community section, it is immediately removed from public view .
  • In NOEX’s backup system , deleted data may be stored for up to 90 days before being permanently erased.
  • Users can withdraw their consent for uploading images or sharing content at any time.

Prohibited Content and Moderation

NOEX reserves the right to remove any uploaded content that falls under the following categories:

  • Offensive, harassing, or intimidating content.
  • Unauthorized disclosure of personal data (e.g., phone numbers, addresses, or personal information of others).
  • Illegal, copyrighted, or unlawful content.
  • Explicitly sexual, violent, or hate-promoting material.
  • Images of minors without parental or legal guardian consent.

Content moderation is conducted through automated and manual review processes , and any content that violates these guidelines will be removed.

Location Information

Your location when you use the app to search for nearby gyms. This information is used to provide you with relevant results.

Data about how you use the app, such as

  • The features you access
  • The frequency of your use
  • The device you use

Information about your device, such as

  • Device name
  • Operating system
  • Unique identifiers

Apple ID account

  • When you sign in with your Apple ID to create an account in the app, we receive some personal information from your Apple account. This may include your name and verified email address. You can choose to share your actual email address or an anonymous one through Apple’s private email relay service. Apple will provide you with more detailed privacy information on the “Sign in with Apple” screen. You can learn more about signing in with Apple here .

Apple Health Kit (and Apple Motion & Fitness API) or Google Fit (together the “Health App”)

  • With your explicit permission on your device, we may access (read) or share (write) data related to your activity with the Health App. In some of our apps, you can choose to allow us to read information such as the number of steps, distance covered, weight, dietary energy, and other data you’ve selected on the consent screen. If you allow us to share data with the Health App, we will send information about your workouts, weight, and calories consumed. The specific data that will be shared with the Health App will be shown to you by Apple or Google in their native pop-up screens, which we do not control.
  • Before sharing your data, we encourage you to review the privacy policies of the Health App, as your information will be governed by those policies. For more information, you can check Apple’s HealthKit at www.apple.com/ios/health/ or Google Fit at www.google.com/fit/ . You can also revoke our access to read/write data from the Health App at any time directly through the Health App.

Advertising ID’s

  • We collect your Apple Identifier for Advertising (IDFA) or Google Advertising ID (AAID), depending on your device. You can reset these IDs in your device settings, but we do not control this process.
  • We may add your email address to our marketing list, provided we receive consent or otherwise establish legal basis for sending you marketing communications. As a result, you will receive information about our products, such as for example, special offers. If you do not want to receive marketing emails from us, you can unsubscribe following instructions in the footer of the marketing emails.

Cookies and Tracking Technologies

  • Our products use cookies and other technologies to enhance your experience, optimize ads, and analyze traffic. These technologies are activated when you use our services, visit our website, or use features like chats. Disabling them may affect some features, but the app will still be functional.

Additional Information Collected by Third-Party Services

Several third-party services used by GymStreak may collect additional information, such as:

  • Firebase: Analytics data, including app usage statistics and crash reports
  • Crashlytics: Crash reports to improve app stability
  • Instabug: Feedback and bug reports
  • Resend: Email opening and click-through rates for marketing campaigns
  • Mapbox: Location data for map functionality
  • Facebook App Events: Analytics data for targeted advertising
  • Posthog: Analytics data for app usage and user behavior
  • Kochava Tracker: Attribution data for marketing campaigns
  • Mixpanel: Analytics data for app usage and user behavior
  • Gleap SDK: Analytics data for app usage and user behavior

We use your personal information to

  • Provide you with the features and functionality of GymStreak
  • Generate personalized workouts based on your body metrics and fitness goals
  • Track your progress and provide you with insights into your workouts and nutrition
  • Send you push notifications and updates about your workout progress and other features
  • Improve the app and develop new features
  • Analyze how you use the app to personalize your experience
  • Deliver targeted advertising
  • Respond to your inquiries and provide customer support
  • We track how you interact with our service, such as which parts of the app you use, the features you engage with, your workouts, their duration, meditation activities, and your subscription orders. All this to improve your experience.
  • We collect data from your mobile device, such as language settings, IP address, device model, operating system, and mobile carrier. If you allow it, we may also collect geolocation data, like running routes.
  • We communicate with you, for example, by push notifications. These may include reminders and motivational messages encouraging you to follow your training and nutrition plan, or other information about the Service, password resets or account updates. As a result, you may, for example, receive a push notification every day at a particular time reminding you to work out. To opt out of receiving push notifications, you need to change the settings on your device.
  • We may also communicate with you regarding important updates or changes to our Service, to gather feedback on our Service or to respond to any inquiries or complaints you may have.
  • This helps us to better understand our business, analyze our operations, maintain, improve, innovate, plan, design, and develop the Service and our new products. We also use data for statistical analysis purposes, to test and improve our offers. This enables us to better understand what features and training plans of the Service our users like more, what categories of users use our Service. As a consequence, we often decide how to improve the Service based on the results obtained from this processing. For example, if we discover that users more often engage in workouts designated for legs, we may develop and introduce a new workout for this area into the Service.
  • We and our partners, use your personal data to tailor ads and possibly even show them to you at the relevant time. For example, if you have installed our Service, you might see ads of our products, for example, in your Instagram’s feed.
  • We use personal data to enforce our agreements and contractual commitments, to detect, prevent, and combat fraud. This may involve verifying user identities, monitoring transactions for suspicious activities, and taking appropriate action to protect our users and our platform from fraudulent activities.

How We Share Your Information

We may share your personal information with the following third-party service providers:

  • Firebase: Cloud storage, analytics, and crash reporting services
  • Crashlytics: Crash reporting service
  • Instabug: Feedback and bug reporting service
  • SendGrid: Email sending service
  • Mapbox: Map functionality service
  • Facebook: Targeted advertising service
  • Poshog: Analytics service
  • Kochava: Attribution service
  • Mixpanel: Analytics service
  • Gleap SDK: Analytics service

We may also share your personal information with other third-party service providers in the following circumstances:

  • To comply with applicable laws and regulations
  • To respond to requests from law enforcement
  • To protect our rights and interests
  • To protect the safety of our users

We will not sell or rent your personal information to any third party without your consent.

With whom we share your personal data

General classification

We engage partners to carry out specific services or business functions on our behalf using their technologies and resources, based on our instructions. This cooperation may involve, in particular, processing your data using their software development kits (SDKs), APIs, cookies, and other technologies. Consequently, your information is transferred and processed on their servers (usually without a partner's direct access to the specific pieces of information) on our behalf for our purposes.

Such type of processing of personal data may be regarded as sharing of information with third parties. We strive to conclude specific data processing agreements with all such parties to establish the rules for processing of your data specifically on our behalf and limited to it. Our partners help us operate, provide, improve, integrate, customize, support, and market our Service.

The types of third parties we share information with include, in particular:

Third-party services providers

We share personal data with third parties that we hire to provide services or perform business functions on our behalf, based on our instructions. All third-party service providers with whom we share personal data are subject to legally binding agreements that ensure compliance with GDPR and other applicable data protection regulations.

We process your personal information using the following types of service providers (and in certain cases, their subprocessors):

  • Cloud storage providers
  • To host personal data and enable our Service to operate and be distributed we use Amazon Web Services , which is a hosting and backend service provided by Amazon. You may read more on Amazon’s security practices on its website . Learn more about Amazon Web Services security practices on the AWS official website .
  • Google Cloud Services : Some of our data storage and processing operations are handled through Google Cloud Services , providing fast and secure data access.
  • Find details on Google Cloud security policies on the Google Cloud official page .

Our servers are primarily located in the European Union. For data transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission.

Product Monitoring Service Providers

To ensure the stability and performance of our application, we use various monitoring services:

  • Crashlytics (provided by Google): A monitoring service that helps us track and analyze app crashes to improve performance. Learn more about its Data Collection Policy .
  • Firebase Performance Monitoring & Firebase Crash Reporting (provided by Google): These services allow us to monitor app performance, detect crashes, and analyze issues in real time. For more details, visit Google’s Privacy Policy and Firebase Privacy & Security .

Additionally, we use

  • Sentry (provided by Functional Software Inc.): A monitoring tool that helps us detect and resolve errors across different platforms, including JavaScript, Python, Ruby, Java, and React .
  • Sentry automatically captures unhandled exceptions and relevant diagnostic data, such as:
  • Device information
  • App version
  • User feedback
  • Breadcrumbs (user actions before an issue occurred)
  • We can also manually report errors with custom tags and context data.
  • Sentry provides performance monitoring, alerts, and dashboards , allowing us to prioritize and fix issues more efficiently.

These services help us ensure a smooth and reliable user experience by proactively identifying and resolving issues.

Communication services providers

Intercom We use Intercom to provide messaging and customer service tools that allow us to communicate with you within the service. When you chat with us through the in-app chat, some of your information is processed by Intercom on our behalf. This processing is necessary for us to identify you (if you’ve shared any name-related information) and communicate with you. Intercom uses this data to provide its services and enable some features of our app, as outlined in their terms of service. Intercom is EU-US Privacy Shield certified. You can learn more about their approach to privacy in their Privacy Policy. Intercom is EU-US Privacy Shield certified . Read more about Intercom’s approach to privacy in its Privacy Policy .

Marketing services providers

  • Meta. We use Meta Ads Manager together with MetaMeta Custom Audience , which allows us to choose audiences that will see our ads on Facebook or other Facebook’s products (for example, Instagram). Through MetaMeta Custom Audience we may create a list of users with certain sets of data, such as an IDFA, choose users that have completed certain actions in the App (for example, installed it). As a result, we may ask Facebook to show some ads to a particular list of users. As a result, more of our ads may show up while you are using Facebook or other Facebook’s products (for example, Instagram). You may learn how to opt out of advertising provided to you through Facebook Custom Audience here .

Facebook also allows its users to influence the types of ads they see on Facebook. To find how to control the ads you see on Facebook, please go here or adjust your ads settings on Facebook .

  • Google Ads is an ad delivery service provided by Google that can deliver ads to users. In particular, Google allows us to tailor the ads in a way that they will appear, for example, only to users that have conducted certain actions with our App (for example, show our ads to users who have purchased a subscription). Some other examples of events that may be used for tailoring ads include, in particular, installing our App, finishing a workout program. Google allows its users to opt out of Google’s personalized ads and to prevent their data from being used by Google Analytics .

Health Apps

In some of our Apps, you may decide to allow us to write data to (share with) Health App, we will transfer to Health App information on your workouts, weight, and dietary energy (calories intake). Google Fit (together the “Health App”)

Your Choices

You have the following choices regarding your personal information

  • Access: You can request a copy of your personal information from us
  • Correction: You can request that we correct any inaccurate personal information about you
  • Deletion: You can request that we delete your personal information or you can delete it yourself through the settings section in the app
  • Portability: You can request that we provide you with your personal information in a portable format
  • Restriction: You can request that we restrict the processing of your personal information
  • Withdrawal of Consent: You can withdraw your consent to our processing of your personal information at any time
  • Do Not Track: You can enable the “Do Not Track” setting in your web browser or device settings

Please note that we may need to retain certain information for legal or administrative purposes. For example, we may need to retain your information if it is necessary to resolve a dispute or enforce our agreements.

Data Retention

We will retain your personal information for as long as necessary to provide the GymStreak app and to fulfill the purposes described in this Privacy Policy. We will also retain your information for as long as is necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Security

We take reasonable steps to protect your personal information from unauthorized access, use, disclosure, alteration, and destruction. These steps include:

  • Using physical, technical, and administrative security measures to protect your information
  • Employing encryption techniques to protect your data
  • Accessing your account information only through secure login portals
  • Limiting access to your personal information to authorized employees and contractors

However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee the absolute security of your personal information.

Children's Privacy, Age Limitations

NOEX is not intended for children under the age of 18. We do not knowingly collect personal information from children under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us using the contact information provided below.

Your California Privacy Rights

If you are a California resident, California Civil Code Section 1798.120 permits you to opt-out of the sale of your personal information to third parties. Currently, NOEX does not sell your personal information to third parties and as such no opt-out of the sale of such personal information is necessary. Although NOEX does not sell your personal information, NOEX does provide a general opt-out right to all of our users as described in our Privacy Policy. Furthermore, as NOEX already complies with Canadian and EU privacy laws, the rights provided by law to Californian residents are already provided for in our general Privacy Policy .

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated Privacy Policy on our website. The updated Privacy Policy will be effective immediately upon posting to our website. Please review this Privacy Policy periodically to stay informed of our current practices. If we decide to make material changes to this Privacy Policy, you will be notified through our Service or by other available means and will have an opportunity to review the revised Privacy Policy. By continuing to access or use the Service after those changes become effective, you agree to be bound by the revised Privacy Policy.

Other Privacy and GDPR informations

1. GDPR and Data Protection Laws Compliance

This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR)and Hungarian Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Infotv.).

2. Principles of Data Processing

The data controller commits to processing personal data in compliance with the following principles:

  • Lawfulness, Fairness, and Transparency – Personal data is processed lawfully and transparently.
  • Purpose Limitation – Data is collected and processed only for specified, explicit, and legitimate purposes.
  • Data Minimization – Only necessary and relevant data is collected and stored.
  • Accuracy – Personal data is kept accurate and up to date.
  • Storage Limitation – Data is retained only as long as necessary for its intended purpose.
  • Integrity and Confidentiality – Appropriate security measures protect data from unauthorized access or disclosure.

3. Data Controller Information

  • Controller Name: Gympiper Ltd.
  • Company Registration Number: (if applicable, add here)
  • Registered Address: Kalocsai út 25., Dunapataj, 6328, Hungary
  • Authorized Representative: (if applicable, add name here)
  • Email Contact: koller@noextraining.com
  • Phone Contact: (if applicable, add here)

NOEX processes personal data based on the following legal grounds

  • Consent (Article 6(1)(a) GDPR) – e.g., for marketing communications.
  • Performance of a Contract (Article 6(1)(b) GDPR) – e.g., to provide app services.
  • Legal Obligation (Article 6(1)(c) GDPR) – e.g., financial and accounting records.
  • Legitimate Interests (Article 6(1)(f) GDPR) – e.g., fraud prevention and security measures.

The purposes of data processing include

  • Providing and maintaining the NOEX app functionality.
  • Enhancing user experience and personalization.
  • Sending marketing communications (if consent is given).
  • Complying with legal and contractual obligations.

5. Cookie Policy and Tracking Technologies

The NOEX app and website use cookies and tracking technologies for the following purposes:

  • Essential Cookies – Required for app operation.
  • Analytics Cookies – Help analyze app usage.
  • Marketing Cookies – Assist in targeted advertising.

Users can adjust or disable cookies in their browser settings.

Under the GDPR, data subjects have the following rights

  • Right to Information – Request details about data processing.
  • Right of Access – Obtain a copy of their personal data.
  • Right to Rectification – Correct inaccurate data.
  • Right to Erasure (“Right to be Forgotten”) – Request data deletion if no longer necessary.
  • Right to Data Portability – Receive data in a structured, machine-readable format.
  • Right to Object – Object to data processing.
  • Right Against Automated Decision-Making – Request human intervention in automated decisions.

Complaint Process

If a user believes their data is being processed unlawfully, they can file a complaint with:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9-11.

Phone: +36 (1) 391-1400

Email: ugyfelszolgalat@naih.hu

Website: www.naih.hu

Users may also pursue legal action in a competent court.

Personal data is stored for the following durations

  • User Account Data – Until the account is deleted.
  • Billing and Financial Records – Retained for 8 years as required by law.
  • Marketing Data – Until consent is withdrawn.
  • Log Files and Analytics Data – Typically retained for 12 months.

9. Third-Party Data Transfers

Personal data is only transferred to third parties when legally justified, such as:

  • To authorities or courts if required by law.
  • To contractual partners (e.g., payment processors) necessary for app operations.

Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us using the following information:

Email: koller@noextraining.com

The controller responsible for processing with regard to the Product is Gympiper Ltd, with its registered address at Kalocsai út 25. Dunapataj, 6328, Hungary.

View the full, official version →