gyvo · Svensk version
gyvo measures your training with your phone, and everything the app measures stays on the phone until you ask for something else. Nothing is sent automatically, and there is no analytics and no advertising.
Three things can send data onwards, and every one of them is a choice you make yourself. Two of them carry what the app has measured; the third is the account, described further down. The first is cloud sync, a switch under More → Account that is off until you turn it on: the app then keeps a copy of your history in your own account with our cloud service, so that a new phone can fetch it.
The second is Promises. When you make a goal a promise, a friend should be able to get an email when you miss it. The judging happens in the cloud and not on the phone, so that it also happens on an evening when the phone is switched off — and that is why the app sends the promise itself there: the goal, what it measures, whether it is daily or weekly, the check time you chose and your time zone, the period's date and the period's number. The goal's history goes with it — which targets you have had and from which dates. That is needed so that a period is judged against the target that applied when it began, and so that the promise works on a new phone if you switch. Only that, and only for the goals you have made promises of. The rest of your training data does not go along, and if you make no promises nothing is sent.
To know whom the email comes from, the app needs an account — and so does cloud sync, so that the copy is yours and no one else's. You sign in with Google under More, and that is the third thing that sends data: signing in itself stores your email address and the name on your Google account with our cloud service, before you have promised or synced anything. If you do not sign in, the app never connects, and everything else in the app works the same without an account — steps, workouts, goals, history, the camera and Earn your scroll never ask for a sign-in.
Steps come from Health Connect. That total counts every app and device that has written steps there — if you have a watch or another fitness app, their steps may be included. The app cannot always separate the phone's own steps out of that figure, and says so on screen when it knows that something comes from another source.
The app’s interface is in English and Swedish. It starts in Swedish if your phone is set to Swedish and in English otherwise, and then follows your choice under More → Settings. Screen names below are given in English.
The app reads your number of steps per day from Health Connect, and only to show them to you and keep your own history in the app. The permission is requested when you press the button on the Results screen, never when the app starts. Every other permission the Health Connect library could handle is explicitly removed from the app — except weight and height, described next. The app never writes anything to Health Connect, never uses Health Connect data for advertising, never sells it, and never sends it anywhere unless you yourself turn on cloud sync or make a goal a promise, as described above.
Under More you can let the app fetch your weight and height from Health Connect, for example if you weigh yourself on a scale that writes there. The permission is requested when you press the button, never when the app starts, and you can decline without anything else in the app stopping — the fields can always be filled in by hand.
The app reads the latest weighing as a single record, not as a merged total, precisely so that it can show where the number came from: which app wrote it and which date it applies to. That is shown under the field. If you enter a value of your own, yours applies — a reading never silently overwrites it, but is offered beside it until you choose it yourself.
Weight and height are used for BMI and for the app's estimates of distance and calories. They are stored on the phone like any other setting and are never written back to Health Connect. One thing is worth saying plainly rather than glossing over: your settings are not synced, but an estimate is stored together with the numbers it was based on — so if you turn on cloud sync, the height and weight behind a day's estimated distance and calories travel with that day. An estimate that cannot be recalculated is worse, but it does mean those numbers are in the cloud copy. Resting heart rate, sleep and other health values are not read.
When you start a workout, the app reads the phone's position to work out distance, pace and speed. It reads location only while the workout is running. The app has no permission to read your location in the background and therefore cannot do so when you are not recording a workout.
While recording, the app shows a notification so that you can see that the phone is reading your position. The notification is a condition and not a side effect: if it cannot be shown — because you declined the permission or switched off the app's notifications — no workout starts, and a running one is ended. The app never records your position without it showing.
If you forget to stop a workout, the app does it for you. If the phone has not moved for half an hour, the workout is ended at the point where you were last moving, and a workout is ended in any case after six hours. The summary tells you that it was the app and not you that stopped it.
The positions are used to work out the workout's numbers. What is saved in your history is distance, the number of workouts, and for running also pace and an estimated elevation gain worked out from the phone's air-pressure sensor — no map and no route. The raw positions, and the air-pressure readings recorded alongside them, never leave the phone, and they are deleted once the app has both counted the workout and confirmed that to the recording layer. That happens when you next open the workout screen, and the app clears the track again when you start your next workout. If the phone refuses both to delete the file and to empty it — rare, and noted in the app's log — the old track can stay until one of those succeeds. A workout too short to be saved leaves nothing in your history; its raw track is cleared the same way, and not before.
The app has permission to recognise whether you are walking, running, cycling or still, through Android and Google Play services. Recognition runs only if you turn it on yourself, and the result — times and type of movement — is stored on the phone. Entries older than 30 days are discarded, but the clean-up happens when the app reads or writes, not by the clock, so single entries can remain longer. The feature is off until you turn it on under More → Passive movement, and is turned off again in the same place.
The camera is used only when you start camera mode yourself, from the Train tab, and only while it is open. The app estimates your body's position frame by frame, on the phone, to count reps — push-ups, squats, lunges — and to time holds such as plank and wall-sit. No video and no image is recorded, stored or sent anywhere, and the model that does the analysis is packaged inside the app, so camera mode needs no connection. No sound is recorded: the app has no microphone permission and opens the camera without audio.
What a camera session leaves behind is a number: reps per exercise and seconds held, with the session's start and end time and a note of how certain the count was. That goes into your history on the phone like any other measurement — and, only if you have turned on cloud sync, into the copy in your account. The app also remembers what you calibrated with your own body, as settings on the phone: the depth you set in Coach mode, and the position you held for plank and wall-sit. The body points the camera finds exist only in the phone's memory while the camera is open.
Three things use notifications: the one that shows that a workout is being recorded, the one that shows that Earn your scroll is on (see below), and an optional notice about today's goal that you turn on yourself under More. If you have promises, that notice can also tell you when last night's promise could not be judged — the app reads that from your own promises in the cloud. Notifications contain only what you see in them and are sent nowhere. If you decline the permission, the app otherwise works as usual — you just do not see them. The exception is workout recording, which requires its notification: see Location — only during a workout above.
Earn your scroll puts apps you have chosen on hold after a time you have chosen, until your daily goals are reached — and never past midnight. It is off until you turn it on under Promise → Earn your scroll, and it needs two rights that you grant yourself in Android's settings: Usage access, so that the app can see which app is in the foreground, and Display over other apps, so that it can put its own screen over a chosen app. While it is on, a guard runs in the background, and Android requires it to post a notification saying so. Being honest about the difference: workout recording refuses to run when that notification cannot be shown, but the hold does not — so if you have turned off gyvo's notifications, the guard can be watching which app is in front without a badge in your notification shade.
What the app reads is which app is on top right now — on the phone, by the guard, and for nothing else. To let you choose, the app lists the apps on your phone that have an icon. The list of apps you chose, the time and which goals bind are stored on the phone, are never sent anywhere and are not part of cloud sync. The list is read on the phone in two places, and nowhere else: by the guard, each time it decides whether the app in front of you is one you chose, and by the chooser screen, to show you what you picked. The hold never applies when the app does not know how your goals stand, and the home button always works — it is a nudge you chose, not a lock.
The app has permission to use the internet. It uses it for three things, and all three are your own choices: to sign you in with Google, to send your promises and their numbers to the cloud that judges them and sends the emails, and — if you have turned on cloud sync — to keep a copy of your history in your account. Until August 2026 the app had no such permission at all, which made the promise that nothing leaves the phone something Android itself upheld. Now it is instead a promise about how the app is built: whoever neither signs in, promises nor syncs sends nothing, but that is guaranteed by the code and not by the phone.
Sign-in happens with Google, in the phone's ordinary browser — never in a sign-in box the app draws itself. The app never sees your password. What the account receives from Google is that you are signed in, your email address, which is needed to know whose promises are whose, and the name on your Google account, which the friend email uses to say who made the promise — if your Google account has no name, the email address is used instead. The email itself is sent from a fixed gyvo address. Google sign-in also hands over the link to your Google profile picture; the app does not use it, but it sits in the account record until the account is deleted.
The account itself carries no training data. Steps, workouts, distance, pace and history stay on the phone as long as you have neither turned on cloud sync nor made a goal a promise — and both of those choices are yours, not pre-selected.
You sign out under More. Signing out removes the session from the phone.
A promise needs someone to go to. You enter a friend's email address — and optionally a name — under Promise → Active promises, and the address leaves the phone only when you have ticked the box that says what your friend will receive. It is used for the promise emails and for nothing else, and is not passed on.
What the email contains: your name — as Google gives it — as the person who made the promise, the goal, the day's or the week's number — for a daily promise also how the week stands against your weekly goal, when you have one and it could be measured — and a line saying that you chose the address. Nothing else about your training. A friend only gets emails about checks that happened after they were added. Every email has a link where your friend can decline further emails, and that no applies to the address — it stays even if you remove and add the same address again, and even if you delete everything the app has stored — or delete your account. That choice is your friend's, not yours.
The check happens each evening at a time you choose (21:00 unless you change it), in your time zone. If you do not miss, no email goes. If the phone could not measure the period, no email goes either — a number we are not sure of is not passed on to anyone else.
Everything is worked out on the phone: today's steps, history, estimated distance and calories, walking and running minutes, reps and hold times from the camera, and the distance and pace of your workouts. The estimates of distance and calories start from your steps and from height and weight. Until you have entered your own values, the app uses an average body (172 cm, 72 kg) — those numbers are marked as estimates, and BMI is not shown at all until you have entered your real measurements.
On the phone, in the app's own storage. No data is sold, and the app contains no advertising and no analytics.
With our cloud service — Lovable Cloud, which runs on Supabase — is what you yourself have put there: your account with your email address and the name from Google, your promises with the goals behind them and the numbers that belong to them, the friends you chose — and, if you have turned on cloud sync, a copy of your history. None of it is there if you have neither signed in, promised anything nor turned on sync.
Beyond that, two things are shared: Google learns that you sign in to gyvo, since it is Google that performs the sign-in, and the email delivery service our cloud provider uses receives your friend's address and the email's content in order to deliver it. If you do not sign in, nothing is shared at all.
What is stored is:
History is stored on the phone precisely so that it can become longer than the 30 days Health Connect hands out. It is not pruned automatically.
The app is set so that none of this goes to Google's cloud backup, nor to a new phone in a device-to-device transfer.
You can also save an extract of a day's raw step records as a file, under More: the app shows you what the extract contains first, and you choose where the file goes. It is not sent anywhere.
You can withdraw the app's permissions at any time: steps, weight and height in the Health Connect app under Permissions, the rest under Android's app settings. The app then stops measuring what the permission covered and says so on screen instead of continuing to show numbers. The weight and height you have already entered or fetched remain in the app's settings until you change them or delete your data.
You can delete what the app has stored on the phone from inside the app: More → Delete my data. The deletion covers the history, your goals and settings, movement recognition's times, the latest workout's position track and the goal notification — and what is in the cloud: your promises with their periods, the friends you chose, and the cloud copy of your history if you turned on sync. Afterwards the app shows what went through — and distinguishes what the phone confirmed it deleted from what was handed to the phone's own layers, which do not answer whether it worked. The deletion cannot be undone.
The cloud part requires you to be signed in, and the confirmation says so before you press: if you are signed out, the app can neither reach what is there nor see whether it exists, and the receipt then says so instead of claiming it is gone. A friend who declined emails stays unsubscribed even after a deletion — that choice is your friend's and not yours. The key behind the unsubscribe link also stays: a row with your friend's email address in plain text, written when an email was sent or attempted. Without it, the link in an email that has already arrived would stop working, and your friend's way out must not disappear with your data.
Two things the deletion does not touch, because the app does not own them: what is in Health Connect — your steps, and your weight and height if they came from there — which stays until you delete it in the Health Connect app, and the permissions you granted, which you revoke yourself. And one thing it does not reach yet, although it should: Earn your scroll's own storage on the phone — whether it is on, the apps you chose, the time and the last goal statuses the guard saw. Switching the feature off and removing the apps clears your choice; what the guard stored stays until you uninstall. Because what is in Health Connect stays there, it also comes back: as long as the app still has its permissions, it re-reads the days Health Connect hands out the next time you open it, and the weight and height the next time you open More. Anything older than that is gone for good; if you typed your weight and height in yourself, they are gone. If you uninstall gyvo, everything the app stored on the phone disappears.
The account itself — your email address and the name from Google — is not removed by Delete my data. It has a path of its own: More → Account → Delete my account, which removes the sign-in and everything in the cloud that belongs to it — your promises and their periods and goals, the friends you chose, and the cloud copy if you turned sync on — and signs you out. It cannot be undone, and we keep no copy of a deleted account anywhere else. The same two things stay as above, and for the same reason: a friend's no to emails, and the key behind the unsubscribe link. What the app measured on the phone stays too — the account is the sign-in, not the measurements — and Delete my data is the path for that.
If you no longer have the app installed, write to the contact address below and we delete the account for you. gyvo.app/delete-account is a public page that describes both paths, what is deleted and what stays.
When you submit an email on gyvo.app, we save the address, your chosen platform, the time and the version of the consent text in our cloud service. This list is separate from app accounts and contains no training data. The Android download is shown after a successful sign-up; we do not send a download or verification email.
We use the list for one email when Gyvo is available in your phone’s app store, not for other marketing. Submitting again for the same platform keeps your original consent. To leave the list or delete your address, write to support@gyvo.app. The app file is hosted on GitHub, which receives your IP address when you download it.
Gyvo is intended for adults aged 18 and over and is not directed at children. The only information about who you are that the app takes in is what Google hands over with the account — email address, name and the profile-picture link — and only if you choose to sign in, which Promises and cloud sync both need and nothing else does. Information about anyone else is taken in only when you yourself enter a friend's address for a promise.
Questions about this policy or about what gyvo stores go to support@gyvo.app, and so can a request to delete your account if you no longer have the app to do it from. It is read by the person who makes the app.
Last updated 14 September 2026.