Last updated 15 September 2026
Privacy Policy
For gyms · Owners, admins and trainers · Looking for the member documents?
Welcome to Connec8 Plans. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how M/S Connec8 (“we”, “M/S Connec8”) looks after personal data when you use the Connec8 Plans Staff app for managing your gym’s AI workout and diet plans, and the rights you have under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
If you are gym staff — an owner, admin or trainer with a Connec8 Plans login — we are the Data Fiduciary for your account. If you are a gym member — you filled in an intake form your gym gave you — your gym is the Data Fiduciary and we are a Data Processor acting only on its instructions. Member requests to see, correct or erase data go to your gym first; you may also write to our Grievance Officer (section 12).
1. Data We Collect
We collect the following information to provide our gym plan management services:
- Identity Data: Name, email address, and mobile number of gym owners, administrators, and staff.
- Contact Data: Phone number and email (used for authentication and communication).
- Business Data: Gym name, city, address, operational settings, gym logo, and photographs of gym equipment.
- Member Data: Information about your gym members that you input or that members submit through your intake form, including names, contact details, intake answers, generated plans, and plan delivery status.
- Health and Fitness Data: Members’ age, sex, height, weight, injuries, allergies, dietary preferences, and fitness goals as entered on the intake form. Under the SPDI Rules 2011, injuries, allergies and body measurements are Sensitive Personal Data or Information.
- Staff Data: Staff names, contact details, roles, and permissions you configure.
- Financial Data: Subscription tier, credits bought and spent, and payment references from Razorpay. We never see or store your card number, UPI ID or bank details; those stay with Razorpay.
- Photos and Media: Images selected from your photo library or captured via camera for gym logos and equipment records.
- Device Information: Device type, operating system, app version, and push notification tokens.
- Diagnostics Data: When something fails in the app, an error report goes to our error-monitoring provider, Sentry. It holds the device model, operating system, app version, IP address, the screens used just before, and the request and response involved — which can include member data — with passwords, one-time passwords and session tokens removed. It is used only to find and fix faults.
- Consent Records: When you accept our Terms of Service and this Privacy Policy, we record which version you accepted, the date and time, and the IP address, device and app version it came from, so that we can show your consent was given.
2. How We Use Your Data
- To provide and maintain the Connec8 Plans Staff platform.
- To authenticate your identity and manage staff access roles.
- To process subscription payments and manage your billing and credits.
- To generate AI-powered workout and diet plans for your members.
- To let you review, store, and share plans with members, including optional WhatsApp delivery.
- To send push notifications and operational notifications (for example, when a plan is ready).
- To build workout plans around the equipment your gym actually owns.
3. Data Sharing
Member data you enter is shared with the respective members through the Connec8 Plans Member app and plan links so they can view their plans. We do not sell any data to third parties. We use the following third-party service providers, each for one job, none of which involves advertising:
- Google Cloud (Mumbai, India) — the servers and database this service runs on. Your data stays in the Indian region.
- Google Vertex AI — generates the plan from intake answers. Data sent to Vertex AI is not used to train Google’s public models.
- MongoDB Atlas — the database.
- Fast2SMS — sends one-time passwords by SMS and, where your gym has enabled it, plan links by WhatsApp.
- Expo Push Notification Service — delivers notifications to gym staff devices.
- Razorpay — takes subscription payments from gyms. They are a separate controller of your payment data under their own policy.
- Cloudflare Turnstile — stops automated abuse of the public intake form.
- Sentry — receives error reports from the Connec8 Plans Staff app so we can find and fix faults. A report can include the data involved in the request that failed.
Some of these process data on servers outside India. That is permitted under section 16 of the DPDP Act 2023. We will stop using any processor that becomes restricted by the Central Government.
4. AI-Generated Plans and Data Processing
When you use the AI plan generation feature, your member’s fitness profile data (goals, body metrics, experience level, dietary preferences, and any medical conditions they have disclosed) is transmitted to our AI service provider solely to generate a personalised plan. This data is:
- Processed in real time to generate the plan and not retained by the AI provider beyond the immediate request.
- Not used by the AI provider to train their public models or for any advertising purpose.
- Not sold or shared with any third party other than the AI service provider for the stated purpose.
You are responsible for ensuring that your members have consented to their data being used for AI plan generation before initiating a plan for them. You should not input sensitive medical data beyond the basic fitness and dietary fields supported by the intake form.
5. Data We Do Not Collect
The Connec8 Plans Staff app does not collect your GPS location, does not use any third-party analytics or advertising SDKs, and does not track your activity outside of the app. We do not collect contacts, biometric data, government identifiers, or photographs of members through the staff app — members submit their own details through the intake form.
6. Data Security
We implement appropriate technical and organizational security measures to protect all data against unauthorized access, alteration, disclosure, or destruction. This includes encrypted data transmission (TLS), secure cloud infrastructure, role-based access controls, and gym-scoped data isolation. Access to member data is restricted based on the staff roles you configure.
- Passwords are bcrypt hashes, never reversible text.
- Every gym’s data is scoped to that gym on every read and write. One gym cannot see another’s members or plans.
- A member’s plan link contains random entropy and is not indexed by search engines.
These are our “reasonable security practices and procedures” for the purposes of section 43A of the IT Act 2000 and Rule 8 of the SPDI Rules 2011. If a breach affects you, we will notify you and the Data Protection Board as Rule 7 of the DPDP Rules 2025 requires.
7. Data Retention
- We retain your data for as long as your subscription is active.
- A staff account you delete — the login is destroyed immediately: the password hash is erased, every session ends, and notification tokens are removed. Your name and mobile number are retained against historical records that name you.
- A gym’s business records — its members, their plans and its billing history are retained while the gym holds an account with us and for eight years afterwards, as financial record-keeping laws require.
- Upon account termination, we will delete or anonymize your data within 90 days unless required by law to retain it. You may request a data export before account closure.
- One-time passwords — deleted automatically within 24 hours.
- Intake links — deleted automatically after 30 days.
- Consent records — kept while your account exists and for eight years after it is deleted, so that an acceptance can still be shown if it is ever questioned.
8. Your Rights
Under sections 11 to 14 of the DPDP Act 2023 you have the right to:
- Access and receive a copy of your data and, where you are gym staff, your members’ data stored on our platform.
- Request correction of inaccurate data.
- Request deletion of your account and associated data, except where a law requires us to keep it.
- Export your data in standard formats.
- Withdraw consent at any time, as easily as you gave it.
- Opt out of non-essential push notifications.
- Complain — to our Grievance Officer first, and then to the Data Protection Board of India if we have not resolved it.
Staff: delete your account yourself from Settings in the app or on the web. What that does, and what survives it, is set out on our account deletion page.
Members: ask your gym, since it is the Fiduciary. If your gym does not act, write to our Grievance Officer and we will.
9. Camera and Photo Library Access
The app requests access to your device camera and photo library to capture and upload gym logos and equipment photos. Photos are uploaded to our secure cloud storage. You can deny camera access and instead select images from your photo library.
10. Children’s Privacy
The Connec8 Plans Staff app is intended for use by gym business operators aged 18 and above. We do not knowingly collect data from anyone under the age of 18 through the staff app. A gym must not submit an intake form for anyone under 18 without their parent or guardian’s consent. Tell our Grievance Officer if you believe we hold a child’s data and we will delete it.
11. Changes to this Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. The date at the top of this page indicates when the policy was last revised. Material changes will be communicated through the app or via email, and where the law requires it we will ask for your consent again rather than assume it.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Entity: M/S Connec8
Email: support@gymconnec8.com
Phone: +91 9752769420
Address: House No 22, Panchwati Colony, Airport road, Bairagarh, Huzur, Bhopal Madhya Pradesh - 462030
Grievance Officer — under section 13 of the DPDP Act 2023 and Rule 5(9) of the SPDI Rules 2011:
Name: Harshit Gandhi
Designation: Manager
Email: support@gymconnec8.com
Acknowledged within 48 hours, resolved within 30 days.