Subprocessors
GymWasp uses the third parties below to run the service. Each one receives only the data listed against it, and only for the stated purpose. This list is maintained alongside the code: adding an outbound integration requires adding it here, and an automated check runs on every change to flag integrations in our codebase that are missing from this page.
For how we use personal data generally — including AI processing and health data — see our Privacy Policy.
Third parties that process personal data on behalf of GymWasp.
| Processor | Data received | Purpose | Location | Data protection | Their policy |
|---|---|---|---|---|---|
| Anthropic | Athlete profile, goals, injuries and health conditions, training session logs, and free-text you write to the coach. | AI coaching, workout plan generation, and parsing what you type into structured training data. | United States | Standard commercial terms; zero-retention not contracted. | Privacy policy |
| Mixpanel (product analytics) | Server-sent events: your user id, username, and the event payload. Separately, your browser sends events and session recordings directly to Mixpanel, which therefore also receives your IP address, device, browser, referring page and current URL. Session recordings have all text and all form inputs masked. | Product analytics and masked session replay, to understand how the app is used. | United States | Standard commercial terms. | Privacy policy |
| Resend | Your email address and name. Colony coach-summary emails additionally carry AI-generated content derived from your training and health data. | Sending transactional and summary email. | United States | Standard commercial terms. | Privacy policy |
| Honeycomb | Your user id, username, email address, account role, the pages you request, and application telemetry. When diagnostic prompt capture is enabled, telemetry also carries the verbatim text of AI prompts, which can include your health data. | Application observability, debugging and performance monitoring. | European Union | Standard commercial terms. | Privacy policy |
| Google (sign-in) | The identity linkage between your GymWasp account and your Google account when you choose to sign in with Google. | Authentication. | United States | Standard commercial terms. | Privacy policy |
| Google (YouTube onboarding video) | Your IP address, browser user agent, the referring page, and any Google cookies already in your browser — sent when the dashboard's onboarding video embed loads. | Playing the embedded onboarding video. | United States | Standard commercial terms. | Privacy policy |
| Railway | Everything stored by the platform: the full application database, its backups, and application logs. | Application and database hosting. | United States | Standard commercial terms. | Privacy policy |
| Apple (APNs) and web push services | Your device push token, plus the type and timing of the notification. Notification copy is static — it carries no training or health detail. | Delivering push notifications to your device or browser. | United States | Standard platform terms. | Privacy policy |
Anthropic
- Data received
- Athlete profile, goals, injuries and health conditions, training session logs, and free-text you write to the coach.
- Purpose
- AI coaching, workout plan generation, and parsing what you type into structured training data.
- Location
- United States
- Data protection
- Standard commercial terms; zero-retention not contracted.
- Their policy
- Privacy policy
Mixpanel (product analytics)
- Data received
- Server-sent events: your user id, username, and the event payload. Separately, your browser sends events and session recordings directly to Mixpanel, which therefore also receives your IP address, device, browser, referring page and current URL. Session recordings have all text and all form inputs masked.
- Purpose
- Product analytics and masked session replay, to understand how the app is used.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Resend
- Data received
- Your email address and name. Colony coach-summary emails additionally carry AI-generated content derived from your training and health data.
- Purpose
- Sending transactional and summary email.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Honeycomb
- Data received
- Your user id, username, email address, account role, the pages you request, and application telemetry. When diagnostic prompt capture is enabled, telemetry also carries the verbatim text of AI prompts, which can include your health data.
- Purpose
- Application observability, debugging and performance monitoring.
- Location
- European Union
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Google (sign-in)
- Data received
- The identity linkage between your GymWasp account and your Google account when you choose to sign in with Google.
- Purpose
- Authentication.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Google (YouTube onboarding video)
- Data received
- Your IP address, browser user agent, the referring page, and any Google cookies already in your browser — sent when the dashboard's onboarding video embed loads.
- Purpose
- Playing the embedded onboarding video.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Railway
- Data received
- Everything stored by the platform: the full application database, its backups, and application logs.
- Purpose
- Application and database hosting.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Apple (APNs) and web push services
- Data received
- Your device push token, plus the type and timing of the notification. Notification copy is static — it carries no training or health detail.
- Purpose
- Delivering push notifications to your device or browser.
- Location
- United States
- Data protection
- Standard platform terms.
- Their policy
- Privacy policy