Privacy Policy
The short version. JimHell collects what it needs to track your training and nothing else. No ads, no tracking, never sold. Health data from Apple Health is never used for advertising and never shared with third parties. Delete your account in the app and everything goes, immediately.
Who we are
JimHell is a strength-training tracker for iPhone and Apple Watch, with this website at jimhell.webetzy.com. “JimHell”, “we” and “us” mean the developer of the app, who is responsible (the “controller”) for the personal data described here. The way to reach us is the support form.
What we collect
Your account
When you sign in with Apple or Google we receive your email address, your name if you choose to share it, and an account identifier from Apple or Google so we recognise you next time. Sign in with Apple lets you hide your address, in which case we receive a private relay address from Apple instead. We never see your Apple or Google password.
Your workouts
For each session you record: when it started and ended, when each set started and ended and the rest before it, your rest and session-length targets, and an optional title.
If you allow it in Apple Health, your Apple Watch also records, through HealthKit, your heart rate during the workout (a reading every few seconds, plus average, maximum and per-set values) and the active energy (calories) you burned. JimHell stores these with the session so you can see them on all your devices. If you don’t allow it, your workouts are saved without them.
Your profile (optional)
Birth year, resting heart rate, maximum heart rate and a weekly session goal — only if you enter them. They’re used to work out your heart-rate zones and your progress towards your goal.
Cards you share
Only when you choose to share a session: the card image and the score, tier and caption on it. A shared card is public — anyone with its link can see it.
Support messages
What you write in the support form, and your email address if you choose to give it so we can reply.
Technical logs
Our server keeps short-lived logs of the requests it handles — the time, the page or endpoint requested and whether it worked — to keep the service running and secure. They don’t contain your workout or health data.
We don’t collect your location, contacts, photos or advertising identifier, and JimHell contains no advertising or third-party analytics code.
How we use it
Only to provide JimHell: to sign you in, to save your workouts and keep them in sync between your devices, to calculate your stats, zones and scores, to host the cards you share, and to answer you when you write to us.
- No ads. JimHell shows no advertising and none of your data is used for it.
- No tracking. We don’t track you across other companies’ apps or websites, and we don’t build profiles about you.
- Never sold. We don’t sell, rent or trade your data, and we don’t share it with data brokers.
- Health data stays health data. Heart rate and active energy from HealthKit are used only to show you your own training. They are never used for advertising, marketing or data mining, and never shared with third parties.
Legal bases
If you’re in the European Economic Area or the UK: we process your account, workout and profile data because it’s necessary to provide the app you asked for (performance of a contract). Heart rate and active energy are health data, which we process only with your explicit consent — given when you allow JimHell access in Apple Health. You can withdraw it at any time in the Health app or in Settings; that stops new readings, and you can remove what’s already stored by deleting those sessions or your account. Technical logs and protecting the service from abuse rely on our legitimate interest in running a secure service. Support messages are processed to answer your request.
Where it’s stored
Your data is stored with Amazon Web Services (AWS) in the European Union, in AWS’s Ireland region (eu-west-1). It’s encrypted in transit (HTTPS) and at rest. AWS hosts the service for us as a data processor and may not use your data for its own purposes. Apple and Google handle your sign-in under their own privacy policies when you choose to use them.
Who we share it with
Nobody, except: AWS, which hosts the service on our behalf; anyone you send a shared card’s link to; and authorities, if the law requires us to.
How long we keep it
- Until you delete it. Your account and workouts are kept for as long as you have the account.
- Deleting a workout erases its contents from our servers straight away. A blank marker holding only the session’s random ID and the time it was deleted remains, so your other devices know to remove it too; it goes when your account does.
- Deleting your account, which you can do inside the app at any time, removes everything immediately: your account, profile, every workout, your sign-in links, and every card you’ve shared, images included. Encrypted database backups kept to recover from failures roll off automatically within 35 days.
- Support messages are deleted automatically 12 months after you send them.
- Technical logs are deleted after 30 days.
Your rights
You can ask us to access, correct, export or delete your personal data. Depending on where you live — for example under the GDPR, the UK GDPR or California law — you may also have the right to object to or restrict processing, to data portability, and to withdraw consent at any time.
Most of this you can do yourself in the app: edit your profile, delete sessions, or delete your account. For anything else, such as a copy of your data, write to us through the support form; we’ll reply within 30 days. You also have the right to complain to a data protection authority, such as the one where you live or Ireland’s Data Protection Commission.
We don’t sell or “share” personal information as those terms are defined in California law, and we don’t use it for targeted advertising.
Children
JimHell is not directed at children under 13 (or the minimum age for consent in your country), and we don’t knowingly collect their data. If you believe a child has given us personal data, tell us through the support form and we’ll delete it.
Security
Data travels over HTTPS and is encrypted at rest. The app signs in to our server with a signed access token, only the systems that run JimHell can reach the database, and share images sit in private storage that is reachable only through the links you create. No system is perfectly secure; if a breach ever affects your data, we’ll tell you as the law requires.
Changes
If we change this policy we’ll update the date at the top. If a change is significant, we’ll tell you in the app before it takes effect.
Contact
Questions or requests about your privacy: use the contact form on our support page. It goes straight to the person who builds JimHell.