Version: 2.2
Last updated: July 9, 2026
This policy explains how personal data is processed when you use the Holymp app.
The Data Controller is:
This policy applies to the Holymp mobile app and the connected backend services, including authentication, data synchronization, AI features, premium management, and optional integrations enabled by the user.
Depending on the features used, Holymp may process the following categories of data.
Only with the user’s consent and authorization, Holymp may read the following data from Health Connect:
This data is used for fitness/wellness summaries, activity analysis, personalized suggestions, and improvement of the user experience. Holymp uses this data only to provide features requested by the user in the fitness/wellness context.
The user can revoke Health Connect permissions at any time from Android settings or from the Health Connect app. Revocation may make some personalized features unavailable or less accurate.
Access to photos, videos, images, media, or files is optional, initiated by the user, and limited to features where the user explicitly chooses to capture or upload content.
Examples:
When you use Premium features or buy AI Coach credits, Holymp may process the data needed to manage access to the service and purchases, including:
Holymp does not store full card details or full payment method details. Payment is handled by the store or payment provider shown in the purchase flow.
Some of the data above, including weight, wellness status, declared injuries, workout data, nutrition data, and Health Connect data, may qualify as health-related data.
Depending on the features used, the app may request:
Permissions are requested by the operating system and can be revoked at any time from device settings. For Health Connect, revocation can also be managed from Android Health Connect settings.
Data is processed for:
Account creation, login, password recovery, profile management, provision of requested features, workouts, meals, synchronization, and premium.
Legal basis: Article 6(1)(b) GDPR.
Fitness/wellness summaries, activity analysis, personalized suggestions, and improvement of the user experience, including through Health Connect data when the user grants permissions.
Legal basis: Article 6(1)(b) GDPR for provision of the requested features and, where necessary, Article 9(2)(a) GDPR for health-related data based on explicit consent.
Management of purchases, subscriptions, AI Coach credits, and Premium features, including delivery of the purchased credit or feature, purchase status verification, support for payment or access issues, security, and prevention of fraud, abuse, or unauthorized reuse of receipts or tokens.
Legal basis: Article 6(1)(b) GDPR for performance of the service or purchase; Article 6(1)(c) GDPR for accounting, tax, or legal obligations; Article 6(1)(f) GDPR for security and fraud or abuse prevention.
Service security, abuse/fraud prevention, rate limiting, and technical incident management.
Legal basis: Article 6(1)(f) GDPR.
Legal, tax, and competent authority requirements.
Legal basis: Article 6(1)(c) GDPR.
Verification of the minimum age required to use the service in Italy, prevention of under-threshold use, and application of technical blocks required by applicable rules.
Legal basis: Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.
Data may be processed by external providers appointed, where required, as processors.
Holymp does not sell personal data to third parties and does not use third-party behavioral advertising in the app.
Some providers may process data outside the EU/EEA. In such cases, the Controller adopts the safeguards required by Articles 44 et seq. GDPR, such as standard contractual clauses where applicable.
Data is stored for the time necessary for the purposes listed above.
When we receive a valid account deletion request, we delete the associated data except data that must be retained due to legal obligations or defense of rights.
Account deletion is available in-app at:
Settings > General > Account > Delete account
The external channel required by app stores is also available:
Technical and organizational measures proportionate to the risk are adopted, including:
No system is completely invulnerable; measures are updated over time.
Under the GDPR you may exercise:
To exercise your rights, write to: privacy@holymp.app.
You also have the right to lodge a complaint with the Italian Data Protection Authority.
For the current release in Italy, Holymp applies a minimum use threshold of 14 years.
If we detect under-threshold use or data provided in violation of the limit, we adopt blocking measures and proceed, where requested and within technical/legal limits, with data deletion.
The app may generate automatic suggestions, such as nutritional estimates and workout optimizations.
These outputs are for informational support and do not replace professional medical, healthcare, nutrition, or personal training assessments.
In the future, Holymp may introduce additional processing to improve AI suggestion quality.
Before enabling new processing that is not compatible with this policy, the policy will be updated and, where necessary, dedicated consent will be requested.
This policy may be updated over time.
The updated version will be published at the same URL or on the dedicated language pages and, where necessary, notified in-app.
Terms of use and disclaimer for the service are available at:
https://gbb9.github.io/holymp-terms/