Privacy policy

Your progress is personal. Here is what stays on your devices, what optional features share, and how you stay in control.

Who is responsible

Giovanni Intini is responsible for Gio Trains and the personal data handled to provide it. For privacy questions or requests, email privacy@giovanniintini.it.

This policy covers the iPhone app, its Apple Watch companion, widgets and Live Activities, and this website. Gio Trains is intended for adult beginners.

Training on your devices

You do not need a Gio Trains account for the iPhone training campaign. The app stores your profile choices, exercise progress, confirmed sets and repetitions, session timing, achievements, schedule, preferences and any journal notes on your device.

The Watch companion exchanges workout and progress information with your paired iPhone. Widgets and Live Activities display selected progress on system surfaces; consider your device’s lock-screen settings if other people can see it. Reminders are scheduled locally.

We do not receive your training or journal contents through ordinary local use. Device backups managed by Apple may include app data according to your Apple settings; these are separate from Gio Trains cloud backup.

When you choose to share a Hero report, the app previews the summary and opens the system share sheet. You choose its recipient or destination. Private journal notes are excluded from that report. The destination’s privacy practices apply after sharing.

Gio Trains has no advertising, cross-app tracking or third-party analytics SDK. We do not sell your data or use training information for advertising. Apple may provide developers with diagnostics or beta feedback according to your Apple and TestFlight settings.

Apple Health is optional

With Pro, you can choose to let Gio Trains write completed workout records to Apple Health. Buying Pro does not grant Health permission. You must enable export and approve Apple’s permission request.

Exported records include the exercise, start and end times, pauses, movement variation and confirmed sets and repetitions. Gio Trains requests permission to write workouts; it does not request read access to your Health records. It does not measure heart rate or estimate calories.

You can turn export off in Gio Trains or revoke permission in Apple’s Health settings. Existing Health entries remain unless you delete them. While export is enabled, correcting a Gio Trains workout can update or remove the matching entry created by the app. Health permissions are not included in Gio Trains backup files.

Purchases

Apple handles payments and purchase restoration. We do not receive your payment-card details. Gio Trains uses Apple-signed purchase information to determine which features you own.

Lifetime Pro and the planned annual Cloud Backup subscription are separate products. For Cloud Backup, the service needs transaction identifiers, product and subscription status, expiry or revocation information, and an account identifier to associate a verified subscription with its owner. Cancelling a subscription is different from deleting a cloud account.

Backups and recovery

Encrypted files you manage

You can export an encrypted backup of your training campaign and journal, and later import it using your recovery code. You choose where to save the file. Any file provider or person you share it with has its own privacy practices.

Gio Trains encrypts backup contents on your device using AES-256-GCM. The recovery code is the decryption key. It is stored in the device Keychain and is not sent to our backup servers. Keep a separate safe copy: we cannot recover it for you. Anyone with both your file and recovery code can read the backup.

Optional cloud backup

Cloud backup is being prepared and is not available yet. The following describes the planned service. We will review this policy before activating it, including any changes to providers or data handling.

When available, cloud backup will require Sign in with Apple, a separate subscription and your explicit choice to enable uploads. Purchasing alone does not start automatic backup.

Apple sign-in provides an identifier for your account. The app does not request your name or email address for backup ownership; if Apple supplies an email or relay address in its identity response, the authentication provider may retain it. The service also handles authentication tokens, an app-generated device identifier and purchase information. A fresh Apple authorization is used to revoke access when you delete your account.

The servers store encrypted files plus information needed to manage them: account and backup identifiers, timestamps, file sizes, integrity hashes, a recovery-key fingerprint and which device may upload. They do not receive your recovery code or the readable training and journal contents. A recovery-key fingerprint identifies the required code; it is not the code itself.

Supabase is the primary provider. An independent encrypted recovery copy using Amazon S3 is planned but is not active. That copy would include encrypted account and backup-management information for recovery. Neither provider receives the key that decrypts your training contents.

Retention and deletion

Local training remains until you remove or replace it. Removing the app does not delete copies you exported, data already shared, Apple Health entries or a separate cloud account. Manage those copies at their respective destinations.

The planned cloud service retains the newest 30 committed backup versions while your subscription is active. After paid access or verified grace ends, new uploads stop and existing backups remain available for download for 90 days. Cancellation alone does not start that window while you still have paid access.

Older or expired versions are removed by maintenance, including the independent recovery copies. Account identity and subscription ownership records remain until account deletion. Notification identifiers used to avoid processing the same Apple event twice are retained for up to 180 days.

Cloud account deletion will be available in Backup & Recovery. It requires fresh Apple authorization, stops backup access and removes the account and its primary and independent copies. If a provider is unavailable, deletion remains pending and is retried; the app must confirm completion. This does not cancel an Apple subscription—manage subscriptions separately in your Apple account.

Providers may retain limited security logs and protected system backups under their retention policies. Such copies are not used to reactivate a deleted account. Files you exported and copies you sent to someone else remain under your or their control.

Service providers and locations

We use providers only as needed to deliver the features you choose, operate the website, handle requests and protect the service:

  • Apple: app distribution, purchases, optional Health integration, device services and Sign in with Apple. See Apple’s privacy policy.
  • Supabase: planned cloud authentication, subscription verification infrastructure and encrypted primary backup storage. The production and test databases and primary storage are configured in Ireland. See Supabase’s privacy policy.
  • Amazon Web Services (S3): independent encrypted recovery storage, with private buckets configured in Ireland. Cloud backup is not available yet. See AWS’s privacy notice.
  • GitHub Pages: this public information website. See GitHub’s privacy statement.

EU storage location does not mean every authentication request, support operation or security log is processed only in the EU. Providers can operate internationally. Where required, applicable data-processing terms and lawful transfer safeguards must cover transfers outside the EEA or UK. You can contact us for information about the safeguards relevant to your data.

We may disclose limited information when required by law or needed to investigate abuse or protect legal rights. We do not have a decryption key to provide for your training backups.

This website and privacy enquiries

On your first visit, a small script uses your browser’s language preferences to open a matching translation. If you choose a language, the site remembers that choice in this browser’s local storage. It is not sent to us and is not used for tracking. Clearing this site’s browser data removes the saved choice. The pages and language links also work without JavaScript.

This site uses no analytics scripts, advertising cookies, contact forms or embedded third-party media. Fonts and artwork are served with the site. GitHub logs visitors’ IP addresses for security purposes when serving GitHub Pages, including visitors who are not signed in. See GitHub’s explanation of Pages data collection.

If you email us, we receive your address and the information you choose to send. We use it to handle your request and keep correspondence only as needed to resolve the matter, document its resolution and meet any applicable obligations. Do not send your recovery code, Apple password or payment-card details.

Your choices and rights

Where the GDPR or UK GDPR applies, processing needed to provide an account and verify a requested paid service is based on performing that service contract. Optional Health export and backup uploads depend on your choice and consent. Security, abuse prevention and responding to enquiries rely on our legitimate interests; legally required processing relies on the relevant legal obligation.

Before cloud uploads are activated, we will ensure that consent covers any health-related information you choose to include. You can withdraw consent by disabling the optional feature; this does not affect earlier lawful processing. Disabling uploads stops new backups but does not delete existing versions—use account deletion to remove those.

Depending on the law that applies, you can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. You can also complain to the data-protection authority where you live, work or believe an infringement occurred. We may need to verify your identity before acting on a request.

Contact privacy@giovanniintini.it to exercise these rights. We can provide account information and encrypted backup files we hold; decrypting training contents requires your recovery code. You do not need to disclose that code to us.

We will update this page when data handling changes and revise the date above. Material changes to an optional feature will be explained before the new processing begins.