This Privacy Policy explains how TMDigital Studio Ltd ("we", "us", "our") collects, uses, and protects personal data when you use InSync — our coaching management platform for personal trainers. We operate in compliance with UK GDPR and the Data Protection Act 2018.
1. Who We Are
TMDigital Studio Ltd is the data controller for your account data as a personal trainer using InSync. When you use InSync to manage your own clients, you act as the data controller for your clients' personal data, and we act as your data processor. Our Data Processing Agreement (available at /legal/data-processing-agreement) governs that relationship.
2. What Data We Collect
We collect the following categories of data depending on how you use the platform:
- Account information: Your name, email address, and password when you register.
- Profile information: Business name, branding preferences, and any profile details you choose to add.
- Client records: Information you enter about your clients — names, contact details, goals, health notes, and any data you record on their behalf.
- Workout and programme data: Exercise records, workout logs, programme templates, and training history entered through the portal.
- Nutrition data: Nutrition logs and goals recorded for clients through the platform.
- Health and fitness data (mobile app): Workout logs, meal logs, macros, and in-app photos (taken or uploaded inside the iOS app) entered by your clients. Steps, heart rate, and other activity metrics your clients choose to record.
- AI-processed content: Meal photos imported via the AI meal-scan feature and messages sent through AI chat are processed by OpenAI on our behalf. See Section 5 for details.
- Push notification tokens: Device tokens used to deliver push notifications via Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM).
- Transactional email content: Content of password-reset emails, verification emails, and other system notifications processed by Resend on our behalf.
- Payment information: If and when PT subscription billing is enabled, payment details will be processed by Stripe. We do not store raw card numbers — Stripe handles all payment data under their own PCI-DSS compliance.
- Usage analytics: Information about how features within the app are used (screen views, feature interactions) to help us improve the product. Processed via Firebase Analytics.
- Crash and performance diagnostics: Crash reports and basic performance data collected automatically when issues occur. Processed via Firebase Crashlytics.
3. Why We Process Your Data
We process personal data for the following purposes:
- To provide the InSync platform: Running your account, storing your client data, and delivering the features of the coaching portal and mobile app. Lawful basis: performance of a contract.
- To improve the service: Understanding how the platform is used so we can fix bugs and build better features. Lawful basis: legitimate interests.
- To communicate with you: Sending important account updates, billing notices, and — where you have opted in — product news. Lawful basis: contract performance and legitimate interests.
- To meet legal obligations: Maintaining records required by law and responding to lawful requests from authorities. Lawful basis: legal obligation.
4. How Long We Keep Your Data
We retain your account data for as long as your account is active. If you close your account, your data is scheduled for deletion within 30 days. Client records you have entered are retained for the same period. You can view the full data retention schedule on the Privacy & Data page in your account settings.
5. Who We Share Your Data With
We do not sell your data or your clients' data to anyone. We use the following third-party processors to deliver the service:
- Firebase / Google Cloud (Google LLC, US/EU): Authentication, database (Firestore), file storage, push notifications (FCM), usage analytics (Firebase Analytics), and crash diagnostics (Firebase Crashlytics). Data is stored in Google's infrastructure. Google processes this data on our behalf under a Data Processing Agreement.
- OpenAI (OpenAI Inc., US): AI features including meal photo import and AI chat. Data sent includes photos and prompt text. Standard Contractual Clauses (SCCs) apply for transfers outside the UK/EU.
- Resend (Resend Inc., US): Transactional email delivery (password resets, verification emails, notifications). SCCs apply for transfers outside the UK/EU.
- Stripe (Stripe Inc., US/EU/UK): Payment processing for PT subscriptions (when billing is enabled). Stripe is PCI-DSS compliant and processes payment data under its own Data Processing Agreement. SCCs apply where relevant.
- Apple (Apple Inc., US): Push notifications delivered via Apple Push Notification Service (APNs). Device tokens are passed to APNs solely to deliver notifications.
We may also disclose data if required by law, court order, or to protect the rights or safety of our users.
6. International Data Transfers
Some of our processors are based outside the UK and EU — for example, OpenAI and Resend are headquartered in the United States. Where personal data is transferred outside the UK or EU, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards approved by the relevant supervisory authority to protect that data. You can request further information about these transfer mechanisms by contacting us at the address in Section 11.
7. Children's Privacy
InSync is intended for adults aged 18 and over. Personal trainers using the platform are professionals, and their clients are expected to be adults. Minors should only use the platform under parental supervision and at the direction of a personal trainer. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
8. Your Rights Under UK GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access: Request a copy of the data we hold about you.
- Right to erasure: Ask us to delete your data ("right to be forgotten").
- Right to portability: Receive your data in a structured, machine-readable format.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to object: Object to processing based on legitimate interests.
- Right to restrict processing: Ask us to pause processing while a dispute is resolved.
To exercise any of these rights, contact us at support@insynctrainer.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).
9. Security
We take data security seriously. All data is stored using Firebase/Google Cloud infrastructure with access controls, encryption at rest, and encryption in transit. Access to your account data is restricted to authenticated users only.
10. Changes to This Policy
We may update this policy from time to time. When we make material changes we will update the "last updated" date at the top of this page and, where appropriate, notify you by email.
© 2026 TMDigital Studio Ltd. All rights reserved.