1. Overview
Vimor (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Vimor mobile application and website (collectively, the “Service”).
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
2. Who we are
Vimor is the data controller responsible for your personal information — meaning we decide what information is collected and why. You can reach us through our contact form.
3. Information we collect
Information you provide in the app
- Account information — When you create an account we collect your email address and any optional profile details such as a display name or profile photo.
- Workout data — Exercise logs including exercise names, sets, reps, weight, duration, rest time, and any notes you add. This is the core data you create in the app.
- Body metrics — Body weight and profile stats (such as height) you optionally provide.
- Custom content — Custom exercises, routine names, and structures you create.
- Social information — Your unique Vimor ID, your friend connections and friend requests, the rooms you create or join for Live Sessions and the invitations you send, and any workouts, personal records, likes, or other content you choose to share to the Feed.
Information you provide on our website
- Contact form submissions — When you use our contact form we collect your name, email address, the topic you select, and the content of your message. We use this only to respond to you. Submissions are delivered to us by email through Resend (see section 6) and are stored in our email inbox.
Information collected automatically
- Device information — Device model, operating system version, unique device identifiers, and app version number.
- Website server logs — When you visit vimor.app, our hosting provider automatically records your IP address, browser user-agent, and the pages you request. We use this to operate and secure the site. We do not use cookies for advertising, and we do not run third-party advertising or behavioural tracking on our website.
- Usage data — Features you use, session duration, and in-app interactions. This helps us identify bugs and improve the experience.
- Crash and diagnostic data — Error logs and performance data automatically sent when the app crashes or encounters an error.
- Push notification token — If you enable notifications, we store a device push token so we can deliver workout reminders, friend requests, and activity alerts such as likes. You can turn these off at any time in Settings → Notifications or in your device settings.
Information we do not collect
We do not collect your precise location, your contacts, microphone audio, or camera images (unless you explicitly upload a profile photo). We do not buy personal information about you from data brokers, and we do not run advertising or behavioural-tracking software in the app or on the website.
4. How we use your information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Sync your data across your devices when you are signed in
- Calculate and display your progress, personal records, and analytics charts
- Power social features — connect you with friends, run Live Sessions in real time, and display your Feed
- Send push notifications you have enabled, such as workout reminders, friend requests, and likes
- Send important service notices such as security alerts and policy updates
- Diagnose technical problems and improve app performance
- Respond to your support requests and contact form submissions
We do not use your workout data to train machine-learning models or for any purpose beyond operating and improving the Service. The Vimor app does not include any artificial-intelligence or automated decision-making features, and we do not make decisions about you by automated means.
5. Health and fitness data
Some of what you enter into Vimor — your workout logs, body weight, and height — may qualify as health data under laws such as the UK GDPR and EU GDPR, which treat it as a special category requiring extra protection. We want to be explicit about how we handle it.
- You choose whether to enter this information. Body weight and height are optional, and the app is usable without them.
- Where the law requires a special basis to process this data, we rely on your explicit consent, which you give when you choose to record it. You can withdraw that consent at any time by deleting the entries, or by deleting your account.
- We do not share health or fitness data with advertisers, data brokers, insurers, or employers, and we never sell it.
- Workout information becomes visible to other people only when you choose to share it — by adding friends, joining a Live Session, or posting to the Feed. See section 6.
6. Information sharing and service providers
We do not sell, trade, or rent your personal information to third parties, and we do not share it for cross-context behavioural advertising. We share information only in the following limited circumstances:
Other users you connect with
Vimor includes social features that are designed to share information with other people. When you add friends, host or join a Live Session, or post to the Feed, information such as your Vimor ID, display name, profile photo, and the workouts or personal records you choose to share becomes visible to the friends or session participants you share it with. You decide what you post and who you connect with, and you can remove shared content or connections at any time.
Service providers
We rely on a small number of third-party companies to operate the Service. They process your information only on our instructions, only to perform the service described, and are bound by a data processing agreement. They are not permitted to use your information for their own purposes, and none of them sell it.
- Supabase — Hosts our database and handles account authentication. This is where your account details, workout logs, body metrics, custom content, and social data are stored. Project region: AWS eu-west-1 (Ireland).
- Sentry — Receives crash reports and error diagnostics from the app so we can find and fix bugs.
- Resend — Delivers email, including contact form submissions and account emails such as address confirmation.
- Vercel — Hosts the vimor.app website and records standard server logs.
- Apple and Google — Distribute the app and deliver push notifications through their notification services (APNs and FCM) when you have notifications enabled. Their own privacy policies govern the data they collect through the App Store and Google Play.
Legal requirements
We may disclose your information if required to do so by law or in response to a valid court order, subpoena, or government request.
Business transfers
If Vimor is acquired by or merges with another company, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
7. International data transfers
Your account and workout data is stored in the European Union. Our database is hosted by Supabase in AWS eu-west-1 (Ireland), so the information you create in the app — your account details, workout logs, body metrics, custom content, and social data — stays within the EEA at rest.
Some of the supporting providers in section 6 are US-based and may process limited personal information outside the EEA. This applies to crash diagnostics, email delivery, and website server logs, and to support staff at our providers who may access data from outside the EEA. It does not apply to the bulk of your workout data, which remains in Ireland.
Where personal information does leave the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, incorporated into our agreement with each provider. Transfers between the UK and the EEA are covered by the respective adequacy decisions. You can request details of the safeguards we rely on through our contact form.
8. Data retention
We keep your personal information only for as long as we need it:
- Account and workout data — Retained for as long as your account remains active. If you delete your account, we remove your personal information — including your friend connections, shared Feed posts, and Live Session history — from our active systems within 30 days.
- Contact form and support correspondence — Retained for up to 24 months after your enquiry is resolved, so we have a record of what was asked and how we responded.
- Crash and diagnostic data — Retained for up to 90 days.
- Website server logs — Retained for up to 30 days.
Anonymised, aggregated data that cannot be linked back to you may be retained indefinitely for analytical purposes. We may also retain information for longer where we are required to do so by law, or to establish, exercise, or defend a legal claim.
9. Security
We take reasonable measures to protect your information. Data is encrypted in transit using TLS, and our database provider encrypts stored data at rest. Access to production data is limited to those who need it to operate the Service, and accounts are protected by authentication managed by Supabase.
No method of electronic storage or transmission is completely secure. While we work to protect your data, we cannot guarantee absolute security, and we encourage you to use a strong, unique password for your account.
10. Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate or incomplete data.
- Deletion — Request deletion of your personal information through our contact form.
- Portability — Request a copy of your workout history through our contact form.
- Opt-out of marketing — We do not send marketing emails by default. Notification preferences are managed in Settings → Notifications.
- Withdraw consent — Where we rely on your consent, you can withdraw it at any time. This does not affect processing carried out before you withdrew it.
To exercise any of these rights, contact us through our contact form. We will respond within 30 days. We do not charge a fee, and we will not treat you differently for exercising any of these rights.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know — Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to delete — Request deletion of personal information we have collected, subject to certain legal exceptions.
- Right to non-discrimination — We will not discriminate against you for exercising any CCPA rights.
- Right to correct — Request correction of inaccurate personal information we hold about you.
- Do Not Sell or Share My Personal Information — We do not sell personal information, and we do not share it for cross-context behavioural advertising. This right therefore has no practical effect, but you may contact us to confirm.
- Limit the use of sensitive personal information — Health and fitness data you enter may be treated as sensitive personal information. We use it only to provide the Service as described in section 4, which is within the exemptions the CPRA permits, and never to infer characteristics about you.
You may use an authorised agent to submit a request on your behalf. To exercise California privacy rights, contact us through our contact formand mention “California Privacy Request” in your message.
12. UK and EEA rights (UK GDPR / EU GDPR)
If you are in the United Kingdom or the European Economic Area, you have the rights listed in section 10 and the following additional rights.
- Right to object — Object to processing we carry out on the basis of our legitimate interests.
- Right to restrict processing — Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Right to lodge a complaint— Complain to your local data protection authority. In the UK this is the Information Commissioner’s Office (ico.org.uk); in the EEA it is the supervisory authority of the country where you live or work.
Our legal bases for processing
- Performance of a contract — Creating and running your account, storing and syncing your workout data, and operating the social features you choose to use.
- Explicit consent — Health and fitness data you choose to record (section 5), and push notifications where you enable them. You can withdraw consent at any time.
- Legitimate interests — Diagnosing crashes, improving performance and reliability, responding to your support enquiries, and keeping the Service secure. We balance these against your rights, and you may object at any time.
- Legal obligation — Retaining records and responding to valid legal requests where the law requires it.
Providing your account email is necessary to use Vimor; without it we cannot create an account for you. All other information is optional and the app remains usable without it.
13. Children's privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from them. If we become aware that a child under 13 has provided us with personal information without parental consent, we will delete it promptly.
If you are in the European Economic Area or the United Kingdom, the minimum age at which you can consent to our processing your personal information is 16, or the lower age set by your country (which may be as low as 13). If you are under that age, a parent or guardian must consent on your behalf.
Vimor includes social features that let you connect with other people and share workouts. If you are a parent or guardian and believe your child has created an account or shared information through these features, please contact us through our contact form and we will remove it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you in the app or by email at least 30 days before the changes take effect. The “Last updated” date at the top of this page reflects the date of the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
VimorContact: our contact form
Website: vimor.app
We will respond to privacy-related inquiries within 30 days.