Yumi is a fitness tracking app with a collectible rewards mechanic. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and your rights regarding that data.
1. Overview
Yumi is a fitness tracking app with a collectible rewards mechanic. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and your rights regarding that data.
By creating an account or using Yumi, you agree to the practices described in this policy. If you do not agree, please do not use the app.
2. Who we are
Yumi is the data controller responsible for your personal data. References to "Yumi", "we", "us", or "our" in this policy mean the same.
If you have any questions about this policy or how we handle your data, contact us at contact@getyumi.fit.
3. Data we collect
3.1 Account information
When you create an account, we collect:
- Your name
- Your email address
- Date of birth (used to verify you meet the minimum age requirement of 14 years)
3.2 Authentication data
If you choose to sign in using Sign in with Apple or Sign in with Google, we receive a unique identifier and, depending on your settings, your name and email address from that provider. We do not receive your password from these providers. Their respective privacy policies govern how they handle your data:
3.3 Fitness and activity data
You may voluntarily log workout data including exercises, sets, repetitions, and weights. This data is used to power progressive overload tracking and to determine earned rewards within the app. We do not share this data with third parties.
3.4 App usage data
We may collect anonymised usage data to understand how the app is used and to improve performance. This includes session length, feature usage, and crash reports. This data is not linked to your identity where technically avoidable.
3.5 Subscription and payment data
Yumi offers a paid subscription. Payments are processed by Apple through the App Store — we never receive or store your payment card details. We receive your subscription status (for example, whether it is in a trial, active, or expired) so we can unlock subscriber features. We use RevenueCat to verify and manage subscription entitlements; RevenueCat processes this subscription data on our behalf under a data processing agreement.
3.6 Data we do not collect
We do not collect:
- Location data
- Contacts or social graph data
- Any content generated or uploaded by users (Yumi does not support user-generated media)
4. How we use your data
We use your data to:
- Create and maintain your account
- Authenticate your identity via third-party sign-in providers
- Track your workouts and calculate progressive overload
- Operate the collectible rewards mechanic (assigning and recording earned items)
- Process your subscription and provide access to paid features
- Send important service communications such as account verification and policy updates
- Improve app performance and fix technical issues using anonymised usage data
- Comply with legal obligations
We do not use your data for advertising. We do not sell your data to third parties.
5. Legal basis for processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process your data under the following legal bases:
- Contract performance: processing necessary to provide the Yumi service you have signed up for
- Legitimate interests: anonymised analytics to improve the app, provided these do not override your fundamental rights
- Legal obligation: processing required to comply with applicable law
Users aged 14–15 in EEA member states where the age of digital consent is 16: where required by applicable law, we will seek parental or guardian consent before processing your data. If you are in this age group and your jurisdiction requires parental consent, please have a parent or guardian contact us at contact@getyumi.fit before using the app.
6. Data retention
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it longer by law.
Anonymised analytics data that cannot be linked back to you may be retained indefinitely for statistical purposes.
7. Data sharing
We do not sell your personal data. We may share your data only in the following limited circumstances:
- Service providers: third-party infrastructure providers (such as cloud hosting and analytics) who process data on our behalf and are bound by data processing agreements
- Legal requirements: if required by law, court order, or regulatory authority
- Business transfer: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections
Where data is transferred outside your country of residence, we ensure appropriate safeguards are in place, including Standard Contractual Clauses where required by GDPR.
If you choose to sign in with Apple or Google, those providers also process your information under their own privacy policies, which may differ from ours. We do not control, and are not responsible for, the data practices of these third-party providers.
8. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: request that inaccurate data be corrected
- Deletion: request that your personal data be deleted ("right to be forgotten")
- Restriction: request that we limit processing of your data in certain circumstances
- Portability: request your data in a portable format
- Objection: object to processing based on legitimate interests
To exercise any of these rights, contact us at contact@getyumi.fit. We will respond within 30 days. You can also delete your account and all associated data directly within the app via Settings > Help & Support > Delete My Account.
If you are in the EEA or UK and believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority.
9. Children and minimum age
Yumi is intended for users aged 14 and over. We do not knowingly collect personal data from children under 14. If we become aware that a user is under 14, we will promptly delete their account and all associated data.
If you believe a child under 14 has created an account, please contact us at contact@getyumi.fit and we will investigate and act promptly.
10. Data security
We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.
11. Cookies and tracking
The Yumi mobile app does not use browser cookies. We may use equivalent device-level identifiers for session management and anonymised analytics. You can reset your device advertising identifier at any time through your device settings.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via the app or by email. The updated policy will include a revised effective date. Your continued use of Yumi after notification constitutes acceptance of the updated policy.
13. Contact us
For any questions, requests, or concerns about this Privacy Policy or how we handle your data:
Yumi
Email: contact@getyumi.fit