Privacy Policy

Last updated: August 21, 2026 · ENYX by H-G, s.r.o.

This Privacy Policy explains what personal data the ENYX mobile application (the “App”) and the website at enyx.store (the “Site”) process, why we process it, who it is shared with, and what rights you have. It is written to meet our obligations under Regulation (EU) 2016/679 (“GDPR”) and Slovak data protection law.

1. Who is responsible for your data

The data controller is H-G, s.r.o., the provider of ENYX. You can reach us about anything in this policy — including any request to exercise your rights — at app.enyx@gmail.com.

Company: H-G, s.r.o.
Email: app.enyx@gmail.com

We have not appointed a Data Protection Officer, because we are not required to. Your requests are handled by us directly at the address above.

2. The short version

We only process what the App needs in order to work. In particular, and to be explicit about the things people usually worry about:

  • We do not sell, rent or trade your personal data, ever.
  • We do not show advertising and we do not use advertising or tracking identifiers.
  • We do not use analytics or behavioural profiling products in the App.
  • The Site sets no cookies and runs no analytics.
  • Your training data is yours; you can export it or delete your account at any time.

3. What we process

We process the following categories of data. Everything here is provided by you or generated by your own use of the App — we do not buy data or obtain it from data brokers.

3.1 Account data

Your email address and the display name you enter during onboarding. If you sign in with Apple or Google, we receive the email address and name released by that provider instead of a password. Passwords, where used, are stored only as salted hashes by our authentication provider and are never visible to us.

3.2 Training data

The content you create in the App: exercises and custom categories, workout plans, logged sessions with their sets, weights, repetitions, dates and notes, recorded workout durations, and body weight entries with their dates and notes.

3.3 App settings

Preferences that need to follow you between devices: unit (kg or lbs), theme, rest timer lengths and behaviour, set prefill preferences, weight goal, notification preference, category order, and the date your free trial started.

3.4 Purchase data

If you buy a subscription or the lifetime licence, our billing provider records the purchase, its status and its renewal or expiry date, linked to your account identifier and email address. Card and payment details are handled entirely by Apple or Google and never reach us — we never see your card number.

3.5 Diagnostic data

When the App crashes or hits an unexpected error, a report is generated containing the error itself, a stack trace, the app version, and technical details of the device and operating system. These reports may include your IP address, which our diagnostics provider processes as part of delivering the report.

3.6 Data stored only on your device

The App is offline-first: your training data, settings and any unfinished session drafts are written to a local database on your device first, and synchronised afterwards. Data held only on your device is under your control and is removed when you uninstall the App.

3.7 Camera and photo library

The App declares camera and photo library permissions for an equipment-scanning feature that is currently disabled. While it is disabled, no image is captured, uploaded or processed, and the App does not access your photos. If we re-enable the feature, we will update this policy before it ships and explain exactly what happens to the images.

4. Why we process it, and on what legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and authenticate your accountAccount dataPerformance of a contract, Art. 6(1)(b)
Store your training data and sync it across your devicesTraining data, settingsPerformance of a contract, Art. 6(1)(b)
Run the free trial and check whether you have an active planAccount data, purchase data, trial start datePerformance of a contract, Art. 6(1)(b)
Process purchases, renewals and restoresPurchase dataPerformance of a contract, Art. 6(1)(b)
Keep the App stable and fix crashesDiagnostic dataLegitimate interests, Art. 6(1)(f)
Answer your support messagesYour email and what you write to usLegitimate interests, Art. 6(1)(f)
Meet accounting, tax and legal obligationsTransaction recordsLegal obligation, Art. 6(1)(c)

Where we rely on legitimate interests, our interest is in providing a working, stable product and in answering the people who write to us. We have considered your interests and rights and consider this processing to be within your reasonable expectations. You may object at any time — see section 8.

Health data. Body weight and training logs are recorded because you type them in, and we use them only to display them back to you. We do not use them to infer anything about your health, we do not derive health metrics from them, and we do not share them with anyone for any health-related purpose.

5. Who your data is shared with

We do not sell or trade your data. We use the following providers, who process data on our instructions as processors (or, for the app stores, as independent controllers of the payment relationship):

ProviderWhat it doesWhat it receives
SupabaseDatabase and authenticationAccount data, training data, settings
RevenueCatSubscription managementAccount identifier, email, purchase status
Apple / GoogleApp distribution, sign-in, paymentsPurchase and billing data, sign-in identity
SentryCrash and error reportingDiagnostic data, IP address
Expo (EAS)App builds and over-the-air updatesTechnical request data when checking for updates
GitHubHosts the public exercise library images the App downloadsYour IP address, when those images are fetched

We may also disclose data where we are legally required to — for example to comply with a court order — or to establish, exercise or defend legal claims. If ENYX is ever sold or merged, your data may transfer to the acquirer, and we will tell you before that happens and before any change to this policy takes effect.

6. Where your data is stored and transfers outside the EU

Your account and training data are stored in the European Union. Some of the providers listed above are established outside the European Economic Area, principally in the United States. Where data is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or another transfer mechanism permitted under Chapter V of the GDPR. You can ask us for details of the safeguards that apply.

7. How long we keep it

  • Account and training data: for as long as your account exists. If you delete your account, this data is deleted from our systems without undue delay, and in any case within 30 days, except where we must keep something longer by law.
  • Purchase and transaction records: for as long as required by accounting and tax law, which in Slovakia is generally up to ten years.
  • Diagnostic data: retained by our diagnostics provider on a rolling window of up to 90 days and then deleted.
  • Support correspondence: up to three years after the matter is closed, so we can handle follow-ups and any dispute.
  • Data on your device: until you delete it in the App or uninstall the App.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy of it;
  • have inaccurate data corrected;
  • have your data erased — you can do this yourself in Settings, or ask us;
  • restrict processing in certain circumstances;
  • data portability — the App has a one-tap export that gives you your training data in a machine-readable file, and you can also ask us for it;
  • object to processing based on our legitimate interests, including the diagnostic reporting described above;
  • withdraw any consent you have given, without affecting processing already carried out.

To exercise any of these, write to app.enyx@gmail.com. We will respond within one month. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests, as the GDPR allows.

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority, in particular the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk), or with the authority in your country of residence.

9. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. Personal records, estimated one-rep maxima and similar figures shown in the App are simple arithmetic on the numbers you entered, displayed only to you.

10. Security

Data is encrypted in transit using TLS and encrypted at rest by our hosting provider. Access to production data is limited to those who need it, database access is restricted per user by row-level security rules, and we require multi-factor authentication on the administrative accounts that can reach it. No system is perfectly secure; if a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the supervisory authority as the GDPR requires.

11. Children

ENYX is not directed at children. You must be at least 16 years old to create an account, or the minimum age of digital consent in your country if that is lower and a holder of parental responsibility consents. We do not knowingly collect data from children below that age. If you believe a child has given us data, contact us and we will delete it.

12. Notifications and device features

Rest timer alerts are scheduled locally on your device. The App does not register for push notifications and we do not operate a push notification service, so no notification tokens are collected and we cannot send you messages remotely. You can turn the alerts off in Settings.

13. This website

The Site sets no cookies, embeds no third-party scripts, runs no analytics and does not fingerprint visitors. Our hosting provider processes standard server request data, including IP addresses, for the purpose of delivering the Site and protecting it from abuse.

14. Changes to this policy

We may update this policy as the App changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will make it clear in the App before the change takes effect. Continuing to use ENYX after that point means the updated policy applies to you.

15. Contact

Questions, requests, or complaints about this policy go to app.enyx@gmail.com. See also our Terms of Service.