This page is maintained by the GymPro Afghanistan team to answer common security and privacy questions about the app. It describes the controls we have enabled today. It is editable project content, not an independent certification or third-party audit.
Last updated: 2026-08-13
Each gym is responsible for what it collects from its members and for having the right to enter that information.
We use the minimum browser storage needed to keep you signed in and remember your language and theme. We do not run third-party advertising trackers on the app.
Gym data is retained for as long as the gym uses the service. Gym owners and managers can edit or remove athlete records, memberships, and other records from inside the app. To request full account deletion or an export of your gym's data, contact us using the security contact below.
If you believe you have found a security issue, please report it to us privately so we can investigate before any details are made public. Do not test attacks against other gyms' data.
The Lovable platform is responsible for the underlying hosting, network, database engine, and platform security controls. We — the GymPro Afghanistan team — are responsible for application code, access rules, and how data is used inside the app. Each gym is responsible for keeping its own user accounts secure, granting the right roles, and only entering information it is allowed to collect.
This page describes current practices and may change as the app evolves. It is not a certification, regulatory compliance statement, or legal contract.