Subprocessors
GymWasp uses the third parties below to run the service. Each one receives only the data listed against it, and only for the stated purpose. This list is maintained alongside the code: adding an outbound integration requires adding it here, and an automated check runs on every change to flag integrations in our codebase that are missing from this page.
For how we use personal data generally — including AI processing and health data — see our Privacy Policy.
Third parties that process personal data on behalf of GymWasp.
| Processor | Data received | Purpose | Location | Data protection | Their policy |
|---|---|---|---|---|---|
| Anthropic | Athlete profile, goals, injuries and health conditions, training session logs, and free-text you write to the coach. | AI coaching, workout plan generation, and parsing what you type into structured training data. | United States | Standard commercial terms; zero-retention not contracted. | Privacy policy |
| Mixpanel (product analytics) | Governed, scrubbed server-sent analytics events: the event name and time, your canonical user id, governance metadata, and validated event-specific enum, boolean, and numeric properties. Unknown properties, malformed values, direct identifiers, and free-form text are discarded before temporary queue storage and checked again before delivery. Delivery requires the current policy and your current sharing consent at the time of egress. Withdrawing consent stops future delivery; events already delivered may remain with Mixpanel until deletion or the end of its applicable retention period. | Product analytics, to understand how the app is used. The browser Mixpanel SDK and session replay are disabled; the browser does not send recordings or analytics directly to Mixpanel. | United States | Standard commercial terms. | Privacy policy |
| Resend | Your email address and name. Colony coach-summary emails additionally carry AI-generated content derived from your training and health data. | Sending transactional and summary email. | United States | Standard commercial terms. | Privacy policy |
| Honeycomb | Your user id, username, email address, account role, the pages you request, and application telemetry. When diagnostic prompt capture is enabled, telemetry also carries the verbatim text of AI prompts, which can include your health data. | Application observability, debugging and performance monitoring. | European Union | Standard commercial terms. | Privacy policy |
| Google (sign-in) | The identity linkage between your GymWasp account and your Google account when you choose to sign in with Google. | Authentication. | United States | Standard commercial terms. | Privacy policy |
| Google (YouTube onboarding video) | Your IP address, browser user agent, the referring page, and any Google cookies already in your browser — sent when the dashboard's onboarding video embed loads. | Playing the embedded onboarding video. | United States | Standard commercial terms. | Privacy policy |
| Railway | Everything stored by the platform: the full application database, its backups, and application logs. | Application and database hosting. | United States | Standard commercial terms. | Privacy policy |
| Apple (APNs) and web push services | Your device push token, plus the type and timing of the notification. Notification copy is static — it carries no training or health detail. | Delivering push notifications to your device or browser. | United States | Standard platform terms. | Privacy policy |
Anthropic
- Data received
- Athlete profile, goals, injuries and health conditions, training session logs, and free-text you write to the coach.
- Purpose
- AI coaching, workout plan generation, and parsing what you type into structured training data.
- Location
- United States
- Data protection
- Standard commercial terms; zero-retention not contracted.
- Their policy
- Privacy policy
Mixpanel (product analytics)
- Data received
- Governed, scrubbed server-sent analytics events: the event name and time, your canonical user id, governance metadata, and validated event-specific enum, boolean, and numeric properties. Unknown properties, malformed values, direct identifiers, and free-form text are discarded before temporary queue storage and checked again before delivery. Delivery requires the current policy and your current sharing consent at the time of egress. Withdrawing consent stops future delivery; events already delivered may remain with Mixpanel until deletion or the end of its applicable retention period.
- Purpose
- Product analytics, to understand how the app is used. The browser Mixpanel SDK and session replay are disabled; the browser does not send recordings or analytics directly to Mixpanel.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Resend
- Data received
- Your email address and name. Colony coach-summary emails additionally carry AI-generated content derived from your training and health data.
- Purpose
- Sending transactional and summary email.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Honeycomb
- Data received
- Your user id, username, email address, account role, the pages you request, and application telemetry. When diagnostic prompt capture is enabled, telemetry also carries the verbatim text of AI prompts, which can include your health data.
- Purpose
- Application observability, debugging and performance monitoring.
- Location
- European Union
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Google (sign-in)
- Data received
- The identity linkage between your GymWasp account and your Google account when you choose to sign in with Google.
- Purpose
- Authentication.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Google (YouTube onboarding video)
- Data received
- Your IP address, browser user agent, the referring page, and any Google cookies already in your browser — sent when the dashboard's onboarding video embed loads.
- Purpose
- Playing the embedded onboarding video.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Railway
- Data received
- Everything stored by the platform: the full application database, its backups, and application logs.
- Purpose
- Application and database hosting.
- Location
- United States
- Data protection
- Standard commercial terms.
- Their policy
- Privacy policy
Apple (APNs) and web push services
- Data received
- Your device push token, plus the type and timing of the notification. Notification copy is static — it carries no training or health detail.
- Purpose
- Delivering push notifications to your device or browser.
- Location
- United States
- Data protection
- Standard platform terms.
- Their policy
- Privacy policy