Privacy Policy
Last updated: July 31, 2026
This policy explains what the MyoErgo iOS app (“MyoErgo”, “the app”, “we”) collects, why it is needed, how it is protected and the choices available to you. MyoErgo is a free bilingual training app for Workouts, Sport, Running, Walking, Cycling, Swimming, Habits, Fitness Assessments and optional social features.
1. Information We Collect
We collect only information needed to provide the app:
- Account information: email address, username, first and last name, authentication records and a password handled by our authentication provider. Passwords are never stored in clear text.
- Optional account and profile information: middle name, phone number, date of birth, sex, postal address and profile picture, when you choose to provide them.
- Social information: follower and following relationships, follow requests, blocks, reports, group memberships, announcements and polls.
- Training information: planned and completed Workout, Sport, Running, Walking, Cycling, Swimming and Fitness Assessment sessions, including dates, exercises, sets, repetitions, loads, duration, targets, notes and recorded results.
- Habit and body information: habits, all-day or time-window schedules, up to five daily time windows and their check-ins, height, weight and waist measurements you enter, and calculated trends or indicators. These indicators are informational and are not a medical diagnosis.
- Physical-activity pre-screening form: before a regular member plans a Workout, Sport, Running, Walking, Cycling or Swimming session when no valid current form is stored, the member must either complete the official CSEP Get Active Questionnaire in MyoErgo or import an official PDF that was already completed. In-app completion includes the questionnaire answers, current activity, first and last name, electronic signature and the server-recorded signing date; MyoErgo places that information into the original two-page official PDF and finalizes it. A finalized form is valid for one year from that signing date; after it expires, the current official version must be completed again before another eligible session can be planned. MyoErgo stores the finalized PDF rather than extracting its health answers into separate database fields.
- Messages, shared sessions and photos: direct and group messages, delivery/read states, polls, message photos and limited completed-session summaries you explicitly choose to send.
- Precise location: only after you start a GPS-tracked outdoor session, such as a run, walk or outdoor ride, to record the route and calculate distance and pace or speed. Tracking can continue while that active session is in the background or the screen is locked, and stops when the session ends. The app requests “While Using the App” access, not continuous “Always” access.
- Notification token and in-app notifications: only when notifications are enabled or generated, so the app can deliver and display relevant account, social and training updates.
MyoErgo does not use HealthKit, read Apple Health data, access contacts or use the microphone. Profile and message photos are selected with the iOS system photo picker, without requesting broad access to your photo library.
2. How We Use Information
- Create, secure and manage your account.
- Plan, display in weekly and daily calendars, record, synchronize and summarize your training and habits.
- Calculate progress, fitness-assessment and optional body-information displays.
- Confirm that a current official physical-activity pre-screening document was completed before an eligible session is planned and require renewal one year after its server-recorded signing date.
- Let you reuse your own completed result to plan a new session.
- Provide profiles, following, messaging, groups, announcements, polls and session summaries you explicitly share.
- Send service and training notifications you have enabled.
- Support users, investigate reports, prevent abuse and moderate user-generated content.
We do not use your information for advertising, behavioral profiling, cross-app tracking or third-party marketing. We do not sell or rent personal information and do not use third-party advertising or analytics SDKs.
3. Storage and Security
Account and app information is hosted by Supabase, our infrastructure provider, in a PostgreSQL database and private storage. Connections use TLS. Database access is limited with authentication and Row Level Security. Message photos and finalized CSEP pre-screening PDFs are stored in private buckets and displayed through short-lived, access-checked links. A cryptographic hash is recorded for each finalized pre-screening PDF so its integrity can be checked. Raw signature strokes are not stored separately from the finalized document. When you share a completed session, the server creates a limited, read-only summary from a session that belongs to you instead of accepting a client-written result. The app may also keep a local cache on your device for performance and limited offline use.
No online service can guarantee absolute security. We maintain safeguards designed for the nature of the information processed and limit administrative access to operating, supporting and moderating the service.
4. Visibility, Messaging and Moderation
- Other signed-in members can see the public profile information shown in the app, including username, name, profile picture, follower/following lists and limited completed-session statistics. They do not receive your email, phone number, address, birth date, raw body measurements, individual session records or GPS routes unless you deliberately send that member a limited completed-session summary in a one-to-one conversation.
- Conversation participants can see the messages, polls and photos in their conversations. A message photo becomes visible to those participants after upload; it is not published outside that conversation. A member who receives a completed-session summary can open its read-only details, which may include the recorded route and selected results, but this does not grant access to the rest of the sender’s account.
- Administrative review can occur after a photo is visible. The administrator can review, remove or take moderation action on photos and other reported content. Users can report content or members and block abusive accounts.
- Authorized administration can access member profile details, follower/following lists, conversations, message-photo reviews, in-app notifications and finalized physical-activity pre-screening forms when needed to operate, support or administer the service. Each administrative authorization to open a pre-screening form is recorded in an access log before a short-lived viewing link is issued. Administrative viewing does not change the member’s own message-read or notification-read state.
Removed or rejected photo-review material retained for moderation is permanently deleted no later than 30 days after it becomes eligible for purge. Blocking limits future interaction and may remove shared group access as implemented in the app.
5. Service Providers and Disclosure
Supabase processes information on our behalf as the hosting and authentication provider. Apple processes notification delivery through Apple Push Notification service (APNs) when notifications are enabled. We may disclose information if required by law, to protect users or the service, or with your direction or consent. We do not share information for advertising or commercial data brokerage.
6. Retention and Account Deletion
Information, including finalized physical-activity pre-screening documents, is generally kept while your account is active and for as long as needed to provide the features you use. Unfinished pre-screening drafts expire automatically. You can start account deactivation inside the app under Profile → Manage My Account → Deactivate My Account. Access is disabled immediately after confirmation, and account data and private files are scheduled for permanent deletion within a maximum of 30 days, subject to information we must retain for security, legal or abuse-prevention reasons.
You can also contact support@myoergo.app about deletion or a privacy request.
7. Your Choices and Rights
- Review and correct account and profile information in the app.
- Choose whether to provide optional profile and body information.
- Control location, photo-picker and notification permissions in iOS Settings.
- Report content, block members and leave conversations or groups where supported.
- Request access, correction or deletion as provided by applicable privacy law.
8. Children
MyoErgo is not directed to children under 13 and does not knowingly collect their personal information. Contact us if you believe a child has provided information so we can investigate and delete it where required.
9. Health and Safety Disclaimer
MyoErgo is a planning and fitness tool. It is not a medical device and does not provide medical advice, diagnosis or treatment. Plans, Fitness Assessments, body indicators and other results are informational only. Consult a qualified healthcare professional for guidance suited to you. If you may be experiencing a medical emergency, contact local emergency services.
10. Changes and Contact
We may update this policy as the app or legal requirements change. The latest revision date appears above, and material changes may also be communicated in the app.
Questions about this policy or your information can be sent to support@myoergo.app.