Last updated 2 August 2026

Privacy policy

This policy explains what the Women Workouts app collects, what never leaves your phone, who processes the rest and how you can get it deleted. It is written to be read, not skimmed past.

The short version

Your body data stays on your phone. Weight entries, BMI history, body measurements, workout history and your plan are stored in the app's local database on your device. We do not upload them to a server and we cannot read them.

An account is optional. If you create one, we hold your email address and sign-in identifier so you can log back in. Nothing else.

We never sell your data. Not to advertisers, not to data brokers, not to anyone.

The rest of this page is the detail behind those three sentences: the analytics and crash reports we do collect, the companies that process them on our behalf, and what you can ask us to do about any of it.

Who we are

Women Workouts is a mobile application published by Mustafa Ali Dikcinar, an individual developer based in Türkiye. For the purposes of the EU and UK General Data Protection Regulation, and of the Turkish Personal Data Protection Law (KVKK No. 6698), that person is the data controller for the personal data described here.

Contact: womenworkoutsapp@gmail.com

"The app", "the Service", "we", "us" and "our" all refer to the Women Workouts mobile application on iOS and Android. "You" means the person using it.

What we collect

Account data — only if you sign in

Using the app does not require an account. If you choose to create one, we collect:

  • Your email address and, if you sign in with Google or Apple, the name and account identifier those providers return.
  • A Firebase Authentication user ID that links your sessions together.

You can sign in with an email and password, with Google, with Apple, or anonymously. If you use Sign in with Apple and choose Apple's Hide My Email option, we only ever see the relay address Apple generates — never your real one. We do not receive or store passwords for Google or Apple sign-in; those are handled entirely by the provider.

Profile and body data — entered by you

To build a plan the app asks for your age, height, weight, fitness level, goal and the areas you want to focus on. As you use it you may also record weight entries and body measurements such as waist, hips, thighs and arms.

This information is stored on your device only. See what stays on your device.

Usage and diagnostic data

The app reports anonymous usage events and crash diagnostics so we can find bugs and understand which features are actually used. This includes:

  • Screens opened and in-app actions taken, as event names without your body data attached.
  • Device model, operating system version, app version, language and approximate country.
  • A pseudonymous app-instance identifier generated by Google Analytics for Firebase, and a separate installation identifier used by Crashlytics. Neither is your advertising ID.
  • If the app crashes: the stack trace, the device state at the time, and the sequence of recent non-personal log entries.

We do not use this data to build an advertising profile of you, and the app contains no third-party advertising SDKs.

Subscription data

If you buy a subscription, the purchase itself happens on the App Store or Google Play. We never see your card number, billing address or any payment credential. Our subscription provider, RevenueCat, receives the store receipt, the transaction identifier, the product you bought, your subscription status and an app user identifier so the app knows whether to unlock premium features.

Notifications

Workout reminders are scheduled locally on your device and are not sent from a server. If you allow push notifications, Firebase Cloud Messaging assigns your installation a device token so we can send occasional service or update messages. You can revoke notification permission at any time in your device settings.

Feedback you send us

If you use the in-app feedback form, the message you write is sent to us through Wiredash together with your app version and device model, plus an email address and a screenshot only if you choose to add them. If you email us directly, we obviously receive whatever you put in that email.

What we do not collect

  • No precise or coarse location data.
  • No contacts, calendar, photos or camera access.
  • No data from Apple Health or Google Fit — the app does not connect to them.
  • No microphone recording. Audio is only played out, never captured.
  • No advertising identifier, no ad networks, no cross-app tracking.

What stays on your device

This is the part most fitness apps get wrong, so it is worth being explicit. The following is written to a local database and to local app storage on your phone, and is not transmitted to us:

  • Your weight history and BMI values.
  • Your body measurements and their dates.
  • Your workout history, completed plans and exercise progress.
  • Your active plan, goal, focus areas and daily calorie target.
  • Your app preferences, such as theme, language and units.

Because this data lives only on your device, two things follow. First, we cannot recover it for you — if you delete the app or lose the phone, that history is gone. Second, deleting the app deletes the data. There is no copy on our side to ask us about.

Sensitive values held by the app are kept in the platform's secure storage (Keychain on iOS, EncryptedSharedPreferences on Android).

Why we use it, and on what legal basis

For users in the EEA and the UK, these are our purposes and the GDPR legal bases we rely on.

WhatWhyLegal basis
Account dataCreating your account, signing you in, letting you contact support about itPerformance of a contract (Art. 6(1)(b))
Profile and body dataGenerating and adapting your workout plan and calorie target on your devicePerformance of a contract (Art. 6(1)(b)); processed locally only
Usage analyticsUnderstanding which features are used so we can improve the appLegitimate interests (Art. 6(1)(f)), or consent where local law requires it
Crash diagnosticsFinding and fixing bugs and stability problemsLegitimate interests (Art. 6(1)(f))
Subscription dataUnlocking premium features and honouring your purchase across devicesPerformance of a contract (Art. 6(1)(b))
Push notification tokenSending service and update messages you opted intoConsent (Art. 6(1)(a)) — withdrawable in device settings
Feedback messagesAnswering your question and fixing what you reportedLegitimate interests (Art. 6(1)(f))
Records of your privacy requestsProving we handled a deletion or access request properlyLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed them against your rights and freedoms. You can object to that processing at any time — see your rights.

Services that process data for us

We use a small number of established providers. Each acts as a processor under our instructions, is bound by a data processing agreement, and may only use the data to deliver its service to us.

ProviderUsed forData it receives
Google — Firebase AuthenticationAccount sign-inEmail address, sign-in provider, user ID
Google — Analytics for FirebaseAnonymous usage analyticsEvent names, device and app metadata, pseudonymous instance ID
Google — CrashlyticsCrash and error reportingStack traces, device state, installation ID
Google — Cloud MessagingPush notificationsDevice push token
Google Sign-InSigning in with a Google accountHandled by Google; we receive email and name
Apple — Sign in with AppleSigning in with an Apple accountHandled by Apple; we receive an identifier and a real or relay email
Apple App Store / Google PlayProcessing purchasesPayment handled entirely by the store; we receive only a receipt
RevenueCatSubscription management and entitlementsStore receipt, transaction and product IDs, subscription status, app user ID
WiredashIn-app feedbackYour message, app and device metadata, optional email and screenshot

Each provider maintains its own privacy documentation, which governs how it handles data as a controller in its own right where applicable. We review this list whenever we add or remove an SDK.

Sharing and selling

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. That is true under the California Consumer Privacy Act as amended by the CPRA, and under the equivalent provisions of other US state privacy laws.

Beyond the processors listed above, we disclose personal data only when:

  • The law requires it — for example a valid court order, or a lawful request from a public authority. We assess each request and disclose only what is strictly necessary.
  • It is needed to protect someone — to prevent or investigate wrongdoing connected to the Service, to defend our legal rights, or to protect the safety of users or the public.
  • The business changes hands — if the app is ever sold or transferred, account data may pass to the acquirer. We will post notice here before that happens and before any different privacy policy applies to you.

How long we keep it

DataKept for
Account dataUntil you delete your account, then removed within 30 days
Body and workout dataOn your device only, until you delete it or uninstall the app
Usage analyticsUp to 14 months, then deleted automatically by Firebase
Crash reportsUp to 90 days
Subscription recordsFor the life of the subscription plus the period required by tax and accounting law
Feedback and support emailUp to 24 months after the conversation ends

Where we are legally required to keep something longer — for example a purchase record for tax purposes — we keep only that record, and only for as long as the obligation lasts.

International transfers

We are based in Türkiye and our providers operate globally, so your data may be processed outside your own country, including in the United States and the European Union.

Where personal data leaves the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with supplementary technical measures such as encryption in transit and at rest. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that certification.

For users in Türkiye, transfers abroad are made in accordance with Article 9 of the KVKK.

Your rights

Wherever you live, you can ask us to do any of the following. We will not charge you for it and we will not treat you differently for asking.

Access
Get a copy of the personal data we hold about you.
Correction
Have inaccurate data fixed. Most profile data you can edit yourself in the app.
Deletion
Have your account and associated data erased. See deleting your account.
Restriction
Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
Portability
Receive the data you gave us in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests, including analytics.
Withdraw consent
Withdraw any consent you gave, without affecting processing that already happened.
Complain
Lodge a complaint with your data protection authority. In Türkiye that is the Kişisel Verileri Koruma Kurumu (KVKK); in the EEA it is your national supervisory authority; in the UK it is the Information Commissioner's Office.

California residents additionally have the right to know the categories of personal information collected and the purposes for collection, the right to delete and correct, the right to opt out of sale or sharing (we do neither), and the right to be free from discrimination for exercising these rights. You may use an authorised agent to make a request on your behalf.

To exercise any right, email womenworkoutsapp@gmail.com from the address on your account. We respond within 30 days. If we need longer because a request is complex, we will tell you why before that deadline passes. We may ask you to confirm your identity before acting, purely so that nobody else can request your data.

Deleting your account

You can delete your account from inside the app at any time: open Settings and choose Delete account. This removes your account record and its associated authentication data.

If you cannot access the app, email womenworkoutsapp@gmail.com from your registered address with the subject "Delete my account".

Remember that your body and workout data was never on our servers to begin with — deleting the app from your device removes it. Full step-by-step instructions, including what happens to an active subscription, are on the account deletion page.

Security

Traffic between the app and our providers uses TLS. Account credentials are handled by Firebase Authentication and are never stored by the app itself. Sensitive local values are kept in the platform keystore. Access to our provider consoles is limited to the developer and protected by two-factor authentication.

No system is perfectly secure, and we will not pretend otherwise. If a breach affecting your personal data occurs, we will notify the relevant supervisory authority within 72 hours where the law requires it, and notify you directly where the breach is likely to result in a high risk to your rights.

Children

Women Workouts is not directed at children. We do not knowingly collect personal data from anyone under 13, or under the higher minimum age that applies in your country — 16 in several EEA member states.

If you are a parent or guardian and believe your child has given us personal data, contact us and we will delete it. If we discover such data ourselves, we remove it without waiting to be asked.

Device permissions

The app asks for very few permissions, and each one is only requested when the related feature is used.

PermissionWhyRequired?
NotificationsWorkout reminders and occasional service messagesOptional
Network accessSigning in, restoring purchases, downloading exercise contentRequired for those features
VibrationHaptic cues during timed exercises and rest periodsOptional
Keep screen awakeStops the screen sleeping mid-workoutUsed only while a workout runs

Declining any optional permission does not prevent you from using the app.

Changes to this policy

We update this page when what we do changes. The "last updated" date at the top always reflects the current version.

If a change materially affects how we use your personal data, we will give you notice through the app or by email before it takes effect, so that you have a chance to object or delete your account first. Continuing to use the app after a change takes effect means the updated policy applies to you.

Contact us

Questions about this policy, or about anything we hold on you:

Email: womenworkoutsapp@gmail.com
Controller: Mustafa Ali Dikcinar, Türkiye

We read every message and aim to reply within a few working days.