Introduction
GymDesk ("we", "our", or "the app") is a gym management application developed by Sumant Mourya. It is used by a gym owner and their front-desk staff to manage members, attendance, plans and payments.
GymDesk is unusual in one important way: the phone is the original copy of your data, not a cache of a server. Everything the app does — registering members, taking payments, scanning entry passes, running reports — happens in a database on the device. Nothing is uploaded during normal use.
Two kinds of people in this policy
This policy covers two distinct groups, and it matters which one you are:
- The gym owner — the person who signs in to the app. Their email address and their app subscription are the only account data GymDesk holds.
- Gym members and staff — people whose details the owner enters. They do not have accounts and never sign in. Their data belongs to the gym, and the gym is the data controller for it. GymDesk is the tool the gym uses to hold it.
If you are a gym member with a question about your data, please contact your gym — they control it, and they can edit or delete it in the app.
Information the app holds
Owner account: the email address used to create the account, and the status of the optional backup subscription.
Entered by the gym, stored on the gym's device:
- Member details — name, phone, email, gender, date of birth, address, emergency contact, notes
- Membership plans, start and end dates, freeze status, trial and referral flags
- Attendance records — which member checked in or out, and when
- Payments, renewals, transfers and generated invoices
- Leads — enquiry details, source, notes and follow-up dates
- Team members — trainers and staff with a scan card and attendance log
- Gym settings — name, address, opening hours, UPI id, message templates
The app does not read your contacts, your SMS messages, your call log or your photo library.
Where the data lives
All of it is written to an encrypted SQLCipher database on the device. The database is deliberately stored in a hidden folder on shared storage rather than the app's private folder, so that it survives an app uninstall and reinstall — a gym should not lose its member list because someone cleared an app.
A marker file beside the database holds a hash of the account that owns it. If a different account signs in on the same phone, access is refused before any record is read.
The optional cloud backup
Cloud backup is an optional paid feature. Without it, no gym data ever leaves the device. With it enabled, a daily sync copies the gym's records to Google Cloud Firestore, in a subtree keyed to the owner's own account id.
- The backup is a mirror, not a merge: a member deleted on the phone is deleted from the copy too, rather than being resurrected by a later restore.
- Only the owner's account can read or write that subtree. This is enforced by a server-side security rule, not just by the app.
- "Restore from cloud" is a deliberate, destructive action shown with a before/after comparison and a confirmation.
- Cancelling the subscription stops the sync. Existing backup data can be removed on request.
What needs an internet connection
Exactly two things:
- Creating an account or signing in — the authentication provider has no offline equivalent.
- The optional backup, if you have subscribed to it.
Everything else — adding members, taking payments, checking people in, running the scanner, editing plans, working the leads pipeline, reading reports — works with the phone in airplane mode.
Permissions
| Permission | Purpose |
|---|---|
| Camera | Scan member entry passes (QR / barcode) at the desk |
| Internet / Network state | Sign in, and run the optional cloud backup |
| Storage | Hold the encrypted local database and generated pass / receipt images |
| Notifications | Local reminders for follow-ups and expiring memberships |
| Location (optional) | Only when you use the map picker to set the gym's address |
Third-party services
- Firebase Authentication — the owner's email and password sign-in
- Firebase Cloud Firestore — the optional backup only
- Google Play Billing — the backup subscription. Purchases are verified on-device; the developer never sees your payment details, which are handled entirely by Google Play.
- Google AdMob — advertisements on the free tier
- Google Maps — optional, only if you use the map picker for the gym address
These are operated by Google and governed by Google’s Privacy Policy.
Advertising
The free tier shows advertisements supplied by Google AdMob — a banner on the scanner screen and an occasional rewarded ad after a period of idle time. Ads are not shown over member data entry or payment screens. AdMob may collect an advertising ID, device information, IP address and ad interaction data.
Retention & deletion
- Deleting a member moves them to a separate bin rather than erasing them, so an accidental deletion at a busy desk can be undone. A member with time left on their plan is archived rather than deleted.
- Clearing the app's data or deleting the local database removes the gym's records from the device permanently. If you have no backup, this cannot be undone.
- Deleting the owner account removes the backed-up copy. Some records may persist briefly in backups before being overwritten.
To request deletion of a backed-up copy, email SumantKushwaha.dev@gmail.com. Requests are actioned within 30 days.
If you run a gym
You are entering other people's personal information into this app. That makes you responsible for it under whatever data protection law applies where you operate. In practice:
- Tell members what you record about them and why.
- Only collect what you actually need — the emergency contact and date-of-birth fields are optional.
- Keep the device locked, and use device encryption.
- Remove members' data when you no longer have a reason to keep it.
GymDesk gives you the tools to do these things. It cannot do them for you.
Children's privacy
The app is intended for use by gym owners and staff, not by children. If a gym registers a member under 13, the gym is responsible for obtaining any consent their local law requires from a parent or guardian.
Security
The local database is encrypted with SQLCipher. Backup data in transit is protected with TLS, and at rest is restricted by a server-side rule limiting each account to its own subtree. Subscription purchases are verified against the app's own licence key on-device.
Because the primary copy of the data lives on the phone, physical device security matters: a screen lock and device encryption are your first line of defence.
Changes to this policy
This policy will be updated as GymDesk moves from development to release. Changes are published here with a revised "Last updated" date.
Contact us
Email: SumantKushwaha.dev@gmail.com
© 2026 Sumant Mourya. All rights reserved.
