Privacy Policy
Last updated: 7 September 2026
YNTA is an app for personal trainers and the people they train. It holds health and fitness data, which is sensitive by nature, so this policy sets out plainly what we collect, who else sees it, and how you get rid of it.
1. Who we are
YNTA is operated by Abay Kaldybayev, an individual developer based in Kazakhstan, who is the data controller for the purposes of this policy. Contact: privacy@ynta.app.
This policy covers the YNTA mobile app on iOS and Android, the website at ynta.app, public trainer pages at ynta.app/t/…, and the trainer dashboard.
2. What we collect
Only what the app needs to do its job. Most of it you enter yourself; the rest is listed below so nothing comes as a surprise.
| Category | What exactly |
|---|---|
| Account | Name, surname, email address, phone number, username, profile photo, gender, date of birth |
| Training | Logged workouts, exercises, sets, reps, weights, rest times, personal records, streaks, programs and templates |
| Body and health | Weight history, body measurements, progress photos, health conditions, medical test entries, PAR-Q readiness questionnaires, mood entries, water intake |
| Nutrition | Meal logs, foods and recipes, calorie and macro targets, photos of meals |
| Coaching | Trainer–client relationships, scheduled and live sessions, session feedback, trainer notes about a client |
| Messages | Conversations between trainer and client, voice messages, attached files |
| Money | Payments and session balances recorded in the app by a trainer, subscription status and purchase history |
| Location | The name of your city and country only, asked once during sign-up to suggest the gym you train at. Coordinates are not stored. |
| Device and usage | Push notification token, app events (sign-up, workout started and completed, paywall shown), device model and OS version, advertising identifier |
Contacts are the exception. When a trainer invites a client from their address book, contacts are read on the device only and are never sent to our servers or stored by us.
3. Why we use it
- To run the app: keep your account, show your workouts, sync a live session between a trainer and a client, deliver messages.
- To let a trainer coach you: show your progress to the trainer you are connected to, track how many sessions remain in your package, and remind them when it runs low.
- To generate plans and insights with AI, when you ask for them — see section 5.
- To send notifications you have turned on: session reminders, messages, client alerts.
- To bill subscriptions and restore purchases.
- To understand which channel an install came from, and to make sign-up work better.
- To keep the service secure: rate limits, one-time codes, abuse prevention.
4. Who else sees your data
We do not sell your data and we do not share it for advertising. We do use the following services to operate YNTA, and each of them processes some of what is listed above:
| Service | What it receives |
|---|---|
| Supabase | Hosts the database and the files you upload — photos, videos, voice messages. Effectively all of your data lives here. |
| OpenAI | Photos of meals, entries from medical tests you ask it to interpret, and your training goals, body parameters and workout history when you generate a plan or ask for insights. See section 5. |
| Google Firebase | Push notification tokens and app usage events. Used for delivery of notifications and for analytics. |
| AppsFlyer | Device and advertising identifiers, install and app events. Used to tell which link or referral an install came from, including referral rewards. |
| RevenueCat | Subscription and purchase status. Card details never reach us or them — Apple and Google handle payment. |
| Resend | Your email address, to deliver the one-time sign-in code. |
| Cloudflare | A captcha check on sign-in, when it is enabled. |
| Apple Health and Google Fit | Workout and activity data, only if you turn the sync on, and only in the direction you choose. |
We may also disclose data where the law requires it, or to protect someone's life, health or rights.
5. AI features, and what they send
Several features work by sending your data to OpenAI, an American company, and using its answer. This is worth stating explicitly because some of that data is about your health.
- Photo of a meal → sent to OpenAI to estimate what the dish is and its calories and macros.
- Medical test entries → sent to OpenAI when you ask the app to explain them.
- Goals, level, body parameters and training history → sent to OpenAI when you generate a workout plan or a program, or ask for training and nutrition insights.
- Your questions in the AI coach chat, together with the workout context they refer to.
These features are optional. If you do not use them, nothing goes to OpenAI. The app is fully usable without a single AI feature — you can log workouts, track progress and work with a trainer as normal.
AI output is a suggestion, not medical advice. It can be wrong. Do not use it to diagnose or treat anything, and consult a doctor before acting on it — especially with a health condition, an injury, during pregnancy, or when interpreting test results.
6. What your trainer sees, and what your client sees
A trainer and a client see each other's data only after both sides have confirmed the connection — by scanning a QR code, accepting an invitation, or the client applying through the trainer's public page.
Once connected, your trainer sees: your name and contact details, your workouts and progress, your body measurements and weight, your progress photos, your health conditions, medical test entries and PAR-Q answers, your nutrition log if you keep one, your session schedule and balance, and your messages with them. Your trainer needs this to train you safely; if you would rather they did not have it, do not enter it.
A client sees the trainer's profile, certificates, portfolio, schedule and the programs assigned to them. A trainer never sees another trainer's clients.
Ending the relationship stops the access. Your data stays yours: a client keeps their own account and full workout history when a trainer deletes theirs.
7. What is public
If you are a trainer and you publish a page at ynta.app/t/your-name, then your name, photo, bio, city, certificates, social links, group classes, available booking slots, and the reviews clients left you are visible to anyone on the internet, and to search engines. Portfolio items appear only if you mark them public.
Nothing about a client is ever published. Client data never appears on a public page.
8. Permissions the app asks for
| Permission | What it is for |
|---|---|
| Camera | Scanning your trainer's QR code, taking progress photos, photographing meals |
| Photos | Choosing a profile picture, a progress photo, a meal photo or an attachment. Selection goes through the system picker, so the app sees only the file you pick — not your library. |
| Microphone | Recording voice messages in chat |
| Contacts | Letting a trainer invite an existing client by name. Read on the device only, never uploaded. |
| Calendar | Adding your scheduled workouts to your calendar and keeping them current |
| Location | Asked once at sign-up to suggest your city. Never tracked in the background. |
| Notifications | Session reminders, messages, rest timer, client alerts for trainers |
Every one of these is optional and can be refused or revoked in your device settings. Refusing one disables the feature that needs it and nothing else.
9. Your rights
- See what we hold about you, and get a copy.
- Correct anything that is wrong — most of it you can edit in the app directly.
- Delete your account and your data. See section 10.
- Withdraw consent, for example by turning off Health sync or notifications, or by stopping using the AI features.
- Object to how we use your data, and complain to the authorised body for the protection of personal data in Kazakhstan.
Write to privacy@ynta.app to exercise any of these. We answer within 3 business days.
10. Deleting your data
You can delete your account from inside the app, in Profile → Settings. Deletion is immediate and cannot be undone: your account and everything listed in section 2 goes with it.
If you cannot sign in, email privacy@ynta.app from the address on the account and we will do it for you within 30 days.
Deleting the account does not cancel a paid subscription. Billing belongs to the App Store or Google Play and only you can stop it there.
11. How long we keep it
- While your account exists — we keep your data so the app can show it to you.
- After deletion — removed immediately, and within 30 days from backups.
- One-time sign-in codes — minutes, then discarded.
- Records that accounting or tax law requires us to keep — only those records, and only for as long as the law says.
12. Security
Traffic is encrypted in transit. Access to rows in the database is enforced per user at the database level, so one account cannot read another's data. Sign-in is by a one-time code sent to your email; there is no password for you to reuse or leak.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the authorities as the law requires.
13. Where your data is processed
Our providers operate servers outside Kazakhstan, including in the European Union and the United States. Using YNTA means your data is transferred and processed there.
14. Children
YNTA is not for people under 16. We do not knowingly collect their data. If you believe a child has an account, write to privacy@ynta.app and we will delete it.
15. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects you — a new category of data, or a new recipient of it — we will tell you in the app before it takes effect.
16. Contact
Questions about privacy: privacy@ynta.app. Anything else: support@ynta.app.