生效日期:2026年9月29日
資料使用者:Labyrinth Studio Limited(「本公司」、「我們」)
白話摘要(唔係政策一部分,只係幫你快啲明):
我哋收嘅嘢好少:你個登入帳戶(Google/Apple)、暱稱、性別,同埋你喺遊戲入面嘅進度(打卡、積分、角色裝扮、人氣)。你撳打卡嗰一刻,部機會將 GPS 座標交去伺服器,核對你係咪真係喺嗰間健身室附近(防作弊);嗰組座標會連住嗰次打卡紀錄一齊儲低。我哋唔會喺後台跟住你,亦冇你嘅行蹤軌跡。 相機淨係用嚟掃職員證 QR 加好友,唔會影相。你嘅相簿我哋唔會掃,淨係兩個情況你會自己揀一張相交畀我哋:① 公會會長揀「公會章」,部機即場縮做 64×64 像素,管理員人手批咗先出;② 你自己揀要唔要喺「職員證」放一張相(唔放都得)。職員證相片會喺伺服器縮細、剷走晒相入面嘅附加資料(包括影相位置),再交 Google Cloud Vision 自動檢查:唔啱嘅相會被拒,拿不定嘅留低等我哋人手睇,過咗先會喺你張職員證同 GymL龍虎榜(人氣榜同小遊戲排行榜)你個名隔離出現,所有已登入嘅人都睇到;你隨時可以移除。你打咗卡之後,同一個健身品牌全港分店打咗卡嘅人,都可能喺房入面見到你嘅暱稱、角色、地區同人氣。呢個 app 冇廣告、冇賣你資料、冇第三方追蹤分析。你隨時可以要求刪除帳戶,30 日後帳戶同個人資料會剷走(第 5 條講嘅少數例外除外,例如你喺公開頻道同討論區講過嘅嘢)。有問題,電郵搵我哋。
本政策說明我們如何收集、使用、披露及保障你的個人資料,並構成《個人資料(私隱)條例》(香港法例第 486 章)(「私隱條例」)下的收集個人資料聲明(PICS)。
1. 我們收集的資料
1.1 你直接提供的資料
| 類別 | 內容 | 收集時點 |
|---|
| 帳戶資料 | 電郵地址(Google/Apple 登入) | 註冊時 |
| 個人檔案 | 暱稱、性別、登入帳戶頭像連結(如你的 Google/Apple 帳戶附有) | 註冊時 |
| 同意紀錄 | 你接受本政策及《服務條款》的版本編號及時間 | 註冊時 |
| 遊戲設定 | 虛擬角色配置(身形、服裝)、主場地區 | 遊戲過程中 |
| 用戶內容 | 私人訊息、頻道訊息、討論區帖子及回覆、投票、留言 | 你發布時 |
| 舉報與封鎖 | 你封鎖的用戶名單、你提交的舉報內容(包括對其他用戶職員證相片的舉報) | 你使用相關功能時 |
| 公會章 | 公會會長為公會提交的標誌圖片:由你相簿中自行選取的一張相片,在你的裝置上裁切並縮小為 64×64 像素 PNG(不多於 32 KB)後上傳 | 你提交公會章時 |
| 職員證相片(可選) | 你由相簿中自行選取的一張相片,顯示於你的「職員證」及 GymL龍虎榜(見第 3 條)。你的裝置先讓你裁切該相片並縮小(裁切後約 512 × 583 像素)才上傳;我們的伺服器再將其轉換為最長邊不超過 384 像素的 JPEG,並移除相片內的所有附加資料(包括 EXIF 拍攝位置、拍攝時間及裝置資料)後才儲存。你原本選取的相片及上傳的版本均不會被儲存 | 你設定職員證相片時 |
| 私訊花名 | 你為好友設定、只在你的私訊中顯示的名稱 | 你設定時 |
| 邀請碼及邀請關係 | 系統為你產生的專屬邀請碼;如你輸入朋友的邀請碼,我們會記錄「誰邀請了誰」(你的及對方的用戶編號、所用邀請碼、輸入時間)及被邀請人打卡的日數。只用於核對及發放邀請獎勵;該紀錄只有該對邀請人及被邀請人本人讀取得到,不會向其他用戶顯示 | 你取得邀請碼時;你輸入邀請碼時;被邀請人其後打卡時 |
1.2 自動產生的資料
| 類別 | 內容 |
|---|
| 遊戲進度 | 打卡紀錄(健身室名稱、所屬品牌及地區、時間,及打卡當刻的位置座標 — 見第 1.3 條)、你去過的健身室清單、積分、代幣、碎片、經驗值、等級、每週連續打卡紀錄、活躍日數、已解鎖服裝及扭蛋收藏、小遊戲分數及排行榜紀錄 |
| 社交紀錄 | 好友請求及好友紀錄、對話清單、透過「職員證」QR 加好友時產生的一次性配對碼(內含你的用戶編號及當時所在的健身室)、你在健身室及辦公室空間的在場狀態及所發出的表情動作 |
| 人氣 | 你收到的 🔥 總數及每週數目(即人氣及人氣榜紀錄);你每日送出 🔥 的總數及送給每位用戶的數目(只保留最近一個送出日的紀錄);你收到 🔥 時,你的在場紀錄會更新你的人氣數目(不會記下送出者是誰) |
| 安全紀錄 | 打卡距離核對結果、定位精確度、你的裝置是否回報該定位為模擬(mock)位置、操作速率限制計數、職員證相片的每日更換次數、職員證相片的自動審查結果(被拒絕或需人手審核的相片,其 Google Cloud Vision 評級會連同你的用戶編號保存)、你提交或涉及的舉報及其處理結果 |
| 裝置資料 | 推送通知登記碼(FCM token) |
| 購買紀錄 | 你透過 App Store 購買的項目、Apple 簽發的交易編號、購買時間及交易環境。付款由 Apple 處理,我們不會收到你的付款卡、帳單或 Apple 帳戶資料 |
語言偏好只儲存在你的裝置上,不會上傳至我們的伺服器。
1.3 位置資料 — 特別說明
打卡功能需要存取你裝置的位置。當你按下打卡:
- 應用程式讀取你當時的 GPS 座標及定位精確度,連同你所選的健身室送交我們的伺服器;
- 伺服器計算你與該健身室的距離,超出範圍即拒絕打卡 — 這是防止偽造打卡所必需的核對;
- 核對通過後,該次打卡當刻的座標(四捨五入至小數點後 5 位,約 1 米精度)及定位精確度,會連同該次打卡紀錄一併儲存,以便日後覆核打卡真偽。
我們不會在背景持續讀取你的位置,亦不會儲存打卡以外的任何位置點,因此不存在你的移動軌跡。如你的裝置回報該定位為模擬(mock)位置,我們只會收到「是/否」這項訊號並拒絕該次打卡。打卡座標隨該次打卡紀錄保存,並於帳戶永久刪除時一併刪除(見第 5 及第 6 條)。你可隨時於裝置系統設定關閉位置權限(打卡功能將無法使用,其他功能不受影響)。
1.4 我們不會收集的資料
- 不收集你的真實姓名、住址、身份證明文件
- 不會在背景追蹤你的位置,亦不儲存打卡以外的位置點或移動軌跡(見第 1.3 條)
- 不收集健康或生物特徵數據(本服務的「健身紀錄」只是遊戲打卡次數;職員證相片只作內容安全檢查,不作人臉識別)
- 相機只用於掃描其他用戶「職員證」上的 QR 碼以加為好友:影像只在你的裝置上即時解碼,我們不會拍攝、上傳或儲存任何影像或畫面
- 不會掃描或讀取你的相簿內容:只有在以下兩種情況下,系統相片選擇器才會交出你所選的那一張相片:(a) 你以公會會長身份主動選擇「更換公會章」;(b) 你主動設定「職員證相片」(只可由相簿選取,不會使用相機)。見第 1.1 條及第 3 條。除此以外,本應用程式不設任何相片或檔案上傳功能
- 不使用第三方廣告或追蹤分析工具
- 不收集年齡或出生日期(見第 9 條)
1.5 過往版本的歷史資料
如你由舊版應用程式(GymWorld iOS)遷移而來,你的帳戶或存有舊版功能收集的資料(如個人簡介、健身程度、目標部位、相片集)。新版應用程式不再收集此等資料;現存的歷史資料會按第 5 條的保留政策處理,你亦可電郵要求我們提前刪除。
2. 收集目的
我們只會為以下目的使用你的個人資料:
- 建立及管理你的帳戶,提供本服務的核心功能;
- 促成遊戲內社交功能(加好友、聊天、討論區、排行榜、人氣榜、職員證);
- 發送服務通知及推送訊息(你可隨時於系統設定關閉);
- 維持服務安全:核對打卡位置、防止欺詐、濫用、多重帳戶及偽造打卡,審查用戶上載的相片,處理舉報及執行社群規則;
- 遵守適用法律或監管要求。
提供第 1.1 條所列的帳戶資料屬自願性質,但如不提供,我們將無法為你建立帳戶及提供本服務。職員證相片及私訊花名完全屬自願性質,不提供亦不影響你使用本服務。我們不會將你的個人資料用於直接促銷,如日後擬作此用途,將按私隱條例事先取得你的同意。
3. 其他用戶可見的資料
以下資料會向其他用戶展示,屬本服務社交功能的固有部分:
- 你的暱稱及虛擬角色形象。你 Google/Apple 帳戶附帶的頭像連結(如有)會隨你的公開檔案及打卡紀錄儲存,其他已登入用戶可讀取,惟現行版本的應用程式不會顯示該頭像;
- 你的「職員證」資料卡:暱稱、等級及稱號、主場地區、榮譽徽章、人氣,以及你的職員證相片(如有,見下一點);如對方是你的好友,另會顯示你目前所在或最近打卡的健身室名稱(職員證不會向非好友顯示此項);
- 你的職員證相片(如你已設定):會顯示於你的職員證,以及 GymL龍虎榜(人氣榜及各小遊戲排行榜)你的名字旁邊(房間及聊天仍然顯示虛擬角色);所有已登入用戶打開你的職員證或排行榜時均可看到。相片須先通過自動審查(見第 4 條),需要人手審核的相片在我們批准前只有我們的管理員可以看到。相片以下載連結提供,任何取得該連結的人均可開啟該相片;
- 你打卡後在健身室房間的在場狀態:你的暱稱、虛擬角色、你打卡分店所在的地區(顯示於名牌上)及人氣,會向在同一健身品牌全港任何分店打卡的用戶展示(視乎我們當時的房間設定,範圍亦可能只限同區或同一分店;用戶亦可自行收窄所看到的範圍)。名牌不會顯示你所在的分店。你發出的表情動作、你收到 🔥 時的效果,以及你在全港、同區或本館頻道發出訊息的開首幾個字(以對話氣泡短暫顯示於你的角色上方),同房用戶均會即時看到。辦公室空間的在場狀態亦會向同場用戶展示。為顯示房間名單,你的在場紀錄(包括暱稱、虛擬角色、分店名稱、地區、打卡時間及人氣)可被已登入用戶的應用程式讀取;
- 你的遊戲成績(排行榜分數)及人氣榜紀錄(暱稱、虛擬角色、人氣,以及你的職員證相片(如有)),所有已登入用戶均可看到;
- 你發布的用戶內容:頻道訊息、討論區帖子及回覆。頻道包括全港(同一健身品牌一個頻道)、同區、本館及辦公室頻道;訊息會連同你的暱稱顯示,全港頻道的訊息另顯示你所在的地區,同區頻道的訊息另顯示你所在的分店,而每則房間頻道訊息的紀錄均載有你發送時所在的分店。上述頻道的內容可被任何已登入用戶讀取(應用程式只在房間內顯示)。私人訊息只有對話雙方可以看到;
- 你的公會的公會章(如你是會長並已提交):圖片會先由我們的管理員人手審核,批准後才會顯示於公會頁、成員名單及邀請卡,所有已登入用戶均可見;待審核期間只有我們的管理員可以看到該圖片。
你的電郵及打卡位置座標不會向其他用戶展示。你的性別不會以文字顯示,但你註冊時選擇的性別決定你虛擬角色的男/女身形,其他用戶可從角色外觀看到。你為好友設定的私訊花名只有你自己看到。
4. 資料的披露及轉移
4.1 我們不會出售你的個人資料。我們只會向以下類別的承讓人披露資料:
| 承讓人 | 目的 | 地點 |
|---|
| Google LLC(Firebase:身份驗證、資料庫、檔案儲存、雲端函數、推送通知) | 本服務的後端基礎設施 | Google 數據中心(後端雲端函數位於亞洲東部二區(香港);其他 Google 服務可能位於美國或其他地區) |
| Google LLC(Google Cloud Vision SafeSearch) | 自動檢查職員證相片是否可能含成人、暴力或性感內容。我們只傳送經伺服器縮小並已移除附加資料的相片本身,不附你的暱稱或用戶編號。Google 就此服務處理資料的說明:Cloud Vision Data Usage FAQ | Google 數據中心(可能位於香港以外) |
| Apple Inc. / Google LLC(登入服務) | 帳戶登入驗證 | 美國 |
| 執法機關或監管機構 | 應法律要求或法院命令 | 視乎要求 |
職員證相片的自動審查結果如下:任何一項被評為「頗有可能」(LIKELY)或「極有可能」(VERY_LIKELY)的相片會被拒絕,不會儲存;任何一項被評為「有可能」(POSSIBLE)、評級不明或檢查未能完成的相片,會留待我們的管理員人手審核,批准後才會顯示;其餘相片會直接顯示於你的職員證。
4.2 上述轉移可能涉及將資料傳送至香港以外地區(主要為美國)。我們的後端雲端函數部署於 Google 的亞洲東部二區(香港),惟身份驗證、資料庫、檔案儲存、推送通知及 Cloud Vision 等其他 Google 服務可能在香港以外的 Google 數據中心處理資料。我們透過與服務供應商訂立的資料處理條款,要求其提供不低於私隱條例標準的保障。
5. 資料保留
| 資料 | 保留期 |
|---|
| 帳戶及個人檔案 | 帳戶有效期內;停用後 30 日永久刪除 |
| 打卡紀錄(包括打卡座標)、好友請求及好友紀錄、私人訊息及對話(雙方的副本)、QR 配對碼、速率限制紀錄、每日計數(送出 🔥 及更換相片的次數)、私訊花名、儲存檔案 | 隨帳戶永久刪除一併刪除 |
| 討論區帖子及回覆、健身室/地區/全港/辦公室頻道訊息 | 為維持其他用戶的對話完整性,於帳戶刪除後繼續保留。該等內容仍附有你原帳戶的用戶編號,惟該編號屆時已不對應任何有效帳戶,亦無法用以查閱你的個人檔案(檔案已刪除)。如你希望移除某項已發布的內容,請於刪除帳戶前自行刪除,或電郵要求我們處理 |
| 人氣榜及小遊戲排行榜紀錄 | 帳戶有效期內;於你要求刪除帳戶時即時移除(人氣榜每週榜以最近 27 週為限,更早的每週榜紀錄會保留,但只載有當時的暱稱、虛擬角色及分數) |
| 職員證相片 | 已顯示的相片保存至你更換或移除相片、我們移除該相片,或你提出刪除帳戶為止,屆時隨即刪除;更換相片後,舊相片隨即刪除。被自動審查拒絕的相片不會儲存。需要人手審核的相片於審核完成後處理(批准即顯示,拒絕即刪除)。被舉報而暫時收起的相片會保留至我們審視完畢,其後刪除或恢復顯示 |
| 公會章圖片 | 待審核的圖片於審核完成(批准或拒絕)後刪除;已批准的公會章於公會更換會章或解散時刪除 |
| 邀請碼及邀請關係 | 帳戶有效期內保存,只用於發放邀請獎勵。你要求刪除帳戶時,你的邀請碼、你自己的「被邀請」紀錄及相關核對紀錄即時移除;你邀請的朋友的邀請紀錄屬於該朋友的帳戶,會保留至該朋友刪除帳戶為止,期間只載有你已失效的用戶編號 |
| 購買紀錄(交易編號) | 為防止重複派發、處理退款爭議及會計目的保留,不會因帳戶刪除而自動刪除;紀錄只載有交易編號、項目及你原帳戶的用戶編號,該編號屆時已不對應任何有效帳戶 |
| 舉報紀錄及相關安全紀錄(包括相片審查評級及審批紀錄) | 為安全、防止濫用及法律目的保留,不會因舉報人或被舉報人刪除帳戶而自動刪除;我們會在不再需要時刪除 |
6. 帳戶刪除
你可於應用程式內「背囊 → 設定 → 刪除帳戶」提出刪除要求,亦可電郵至下述地址提出。流程如下:
- 帳戶即時停用,登入功能同時封鎖,其他用戶無法再看見你;你的職員證相片同時刪除(如你其後於復原期內恢復帳戶,相片不會恢復,你可重新設定);
- 30 日復原期內,你可電郵至下述地址要求復原帳戶(由於登入已被封鎖,無法以重新登入的方式取消刪除);
- 30 日屆滿後,系統自動永久刪除你的帳戶、個人檔案、打卡紀錄(包括打卡座標)、好友請求及好友紀錄、私人訊息及對話、QR 配對碼、每日計數、私訊花名及儲存檔案,並註銷你的登入憑證。此操作不可逆轉,所有虛擬物品同時失效。第 5 條所述已與其他用戶共享的內容及安全紀錄除外。
你的人氣榜及小遊戲排行榜紀錄亦會於你要求刪除帳戶時移除(見第 5 條)。其他用戶為你設定的私訊花名屬於該用戶的帳戶,只有該用戶看到。
7. 資料保安
我們採取合理可行的措施保障你的個人資料,包括:傳輸加密(TLS)、伺服器端存取規則(每名用戶只可存取自己的資料)、後端函數的身份驗證及速率限制、以及員工存取限制。惟互聯網傳輸無法保證絕對安全,如發生涉及你個人資料的重大資料外洩事故,我們會按私隱公署的指引通知你及相關監管機構。
8. 你的權利
根據私隱條例,你有權:
- 查閱我們持有的你的個人資料(第 18 條);
- 改正不準確的資料(第 22 條)— 暱稱可直接於應用程式內更改;
- 移除職員證相片 — 可隨時於應用程式內「背囊 → 個人 → 更換 / 移除頭像」移除或更換;
- 刪除帳戶及資料(見第 6 條);
- 拒收推送通知 — 於裝置系統設定關閉。
行使查閱或改正權,請電郵至下述地址。我們會於 40 日內回覆。我們可就查閱要求收取合理費用。
9. 未成年人
本服務並無最低年齡限制,我們亦不會要求用戶提供年齡或出生日期。如你未滿 18 歲,請先徵得家長或監護人同意方使用本服務。家長或監護人可電郵聯絡我們,要求查閱或刪除未成年人的個人資料(見第 8 及第 11 條)。
10. 政策修訂
我們可不時修訂本政策。重大修訂會透過應用程式內通知提前告知。修訂後的政策於公布的生效日期起適用。
11. 聯絡我們及投訴
- 電郵:enquiry@gymlonline.com
- 你亦有權向香港個人資料私隱專員公署(PCPD)投訴:www.pcpd.org.hk / 2827 2827
文件版本:v1.1(2026年9月29日)
Effective date: 29 September 2026
Data user: Labyrinth Studio Limited ("the Company", "we", "us")
Plain-language summary (not part of the Policy):
We collect very little: your sign-in account (Google/Apple), nickname, gender, and your in-game progress (check-ins, points, avatar outfit, popularity). When you tap check-in, your phone sends its GPS coordinates to our server to verify you are really at that gym (anti-cheat), and those check-in coordinates are stored with that check-in record. We do not track you in the background and we hold no movement history. The camera is used only to scan a staff-card QR to add a friend — no photos are taken. We never scan your photo library; there are only two cases where you hand us one photo you picked yourself: ① a clan owner picks a clan crest, which your phone shrinks to 64×64 pixels on the spot and a human admin reviews before it appears; ② you choose to put a photo on your staff card (optional). A staff card photo is shrunk on our server, stripped of all embedded data (including where it was taken), then checked automatically by Google Cloud Vision: unsuitable photos are refused, uncertain ones wait for a human review, and only then does it appear on your staff card and next to your name on the GymL leaderboards (popularity and mini-game boards), where every signed-in user can see it; you can remove it any time. Once you check in, people checked in at any branch of the same gym brand across Hong Kong may see your nickname, avatar, district and popularity in the room. No ads, no selling your data, no third-party tracking. You can request account deletion any time; after 30 days your account and personal data are wiped (with the few exceptions in section 5, such as what you said in public channels and the forum). Questions? Email us.
This Policy explains how we collect, use, disclose and protect your personal data, and constitutes our Personal Information Collection Statement (PICS) under the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) (the "Ordinance").
1. Data We Collect
1.1 Data you provide directly
| Category | Data | When |
|---|
| Account | Email address (Google/Apple sign-in) | At registration |
| Profile | Nickname, gender, the link to your sign-in account's profile picture (if your Google/Apple account has one) | At registration |
| Consent record | The version and timestamp of the Terms and this Policy you accepted | At registration |
| Game settings | Avatar configuration (body, costumes), home district | During play |
| User content | Private messages, channel messages, forum threads and replies, votes, comments | When you post |
| Invite code and invite link | The personal invite code we generate for you; if you enter a friend's invite code, we record who invited whom (both user ids, the code used, the time) and how many days the invited player has checked in. Used only to verify and pay the invite reward; the record can be read only by that inviter and that invited player themselves and is never shown to other users | When you get your code; when you enter a code; when the invited player later checks in |
| Reports & blocks | Users you block, reports you submit (including reports about another user's staff card photo) | When you use those features |
| Clan crest | The crest image a clan owner submits for their clan: one photo you pick yourself from your library, cropped and downscaled on your device to a 64×64 pixel PNG (at most 32 KB) before upload | When you submit a crest |
| Staff card photo (optional) | One photo you pick yourself from your library, shown on your "staff card" and on the GymL leaderboards (see section 3). Your device first lets you crop it and shrinks it (about 512 × 583 pixels after cropping) before upload; our server then converts it to a JPEG of at most 384 pixels on the long side and removes all embedded data (including EXIF location, capture time and device details) before storing it. Neither the photo you originally picked nor the uploaded copy is stored | When you set a staff card photo |
| Private alias | A name you give a friend, shown only in your own private messages | When you set one |
1.2 Data generated automatically
| Category | Data |
|---|
| Game progress | Check-in records (gym name, its brand and district, time and the coordinates at the moment of check-in — see 1.3), the list of gyms you have visited, points, tokens, fragments, XP, level, weekly streak, active days, unlocked costumes and gacha collection, mini-game scores and leaderboard entries |
| Social records | Friend requests and friend records, conversation list, the one-time pairing code generated when you add a friend by "staff card" QR (it carries your user id and the gym you were at), your presence in gym and office spaces and the emotes you send |
| Popularity | The total and weekly number of 🔥 you receive (your popularity and popularity-board entries); how many 🔥 you gave in a day in total and to each user (only the most recent day you gave is kept); when you receive 🔥, your presence record is updated with your popularity count (it does not record who gave it) |
| Safety records | Check-in distance verification result, location accuracy, whether your device reports the fix as a mock location, rate-limit counters, how many times you changed your staff card photo in a day, automated screening results for staff card photos (for a photo that is refused or held for human review, its Google Cloud Vision ratings are kept with your user id), reports you file or that concern you and how they were handled |
| Device | Push-notification token (FCM) |
| Purchase history | The items you buy through the App Store, the Apple-issued transaction identifier, the purchase time and the transaction environment. Payment is handled by Apple; we do not receive your payment card, billing or Apple account details |
Your language preference is stored on your device only and is not uploaded to our servers.
1.3 Location data — special note
Check-ins need access to your device location. When you tap check-in:
- the app reads your current GPS coordinates and location accuracy and sends them, with the gym you selected, to our server;
- the server computes your distance to that gym and refuses the check-in if you are outside the radius — this verification is necessary to prevent spoofed check-ins;
- once verified, the coordinates at the moment of that check-in (rounded to 5 decimal places, roughly 1 m) and the location accuracy are stored on that check-in record, so the check-in can be re-verified later.
We do not read your location in the background and we store no location point other than your check-ins, so no movement history exists. If your device reports the fix as a mock location, we receive only that yes/no signal and refuse the check-in. Check-in coordinates are kept with the check-in record and are deleted when your account is permanently deleted (see sections 5 and 6). You can disable location permission in your device settings at any time (check-ins will stop working; everything else is unaffected).
1.4 What we do not collect
- No real name, home address or identity documents
- No background location tracking, and no location points or movement history beyond your check-ins (see 1.3)
- No health or biometric data (your in-game "workout record" is simply a count of game check-ins; staff card photos are used only for a content-safety check, never for face recognition)
- The camera is used only to scan the QR code on another user's "staff card" to add them as a friend: frames are decoded on your device in real time — we do not take, upload or store any image
- No scanning or reading of your photo library: the system photo picker hands us the single photo you selected in only two cases: (a) you, as a clan owner, actively choose "change crest"; (b) you actively set a "staff card photo" (library only — the camera is never used). See 1.1 and section 3. Beyond that the app has no photo or file upload feature
- No third-party advertising or tracking analytics
- No age or date of birth (see section 9)
1.5 Legacy data from previous versions
If you migrated from the previous app (GymWorld iOS), your account may hold data collected by retired features (e.g. bio, fitness level, target body parts, photo gallery). The current app no longer collects such data; existing legacy data is handled under the retention rules in section 5, and you may email us to request earlier deletion.
2. Purposes of Collection
We use your personal data only to:
- create and manage your account and provide the Service's core features;
- enable in-game social features (adding friends, chat, forums, leaderboards, the popularity board, staff cards);
- send service and push notifications (you can turn these off in system settings);
- keep the Service safe: verify check-in location, prevent fraud, abuse, multi-accounting and spoofed check-ins; screen photos users upload; handle reports; enforce community rules;
- comply with applicable legal or regulatory requirements.
Providing the account data in section 1.1 is voluntary, but without it we cannot create an account or provide the Service. A staff card photo and private aliases are entirely voluntary; leaving them out does not affect your use of the Service. We do not use your personal data for direct marketing; if we ever intend to, we will first obtain your consent as required by the Ordinance.
3. Data Visible to Other Users
The following is shown to other users as an inherent part of the Service's social features:
- your nickname and your in-game avatar. The link to your Google/Apple account's profile picture, if any, is stored with your public profile and your check-in records and can be read by other signed-in users, but the current version of the app does not display that picture;
- your "staff card" player card: nickname, level and title, home district, honour badges, popularity, and your staff card photo if you have one (see the next point); if the viewer is your friend, it also shows the gym you are at now or last checked in at (the staff card never shows this to non-friends);
- your staff card photo (if you set one): shown on your staff card and next to your name on the GymL leaderboards (popularity and mini-game boards) — rooms and chat still show your avatar — to every signed-in user who opens your staff card or a leaderboard. It must first pass the automated screening (see section 4); a photo held for human review is visible only to our admins until approved. The photo is served through a download link, and anyone who has that link can open the photo;
- your presence in a gym room once you check in: your nickname, avatar, the district of the branch you checked in at (shown on your nameplate) and your popularity are shown to users checked in at any branch of the same gym brand across Hong Kong (depending on our room settings at the time, the scope may instead be limited to the same district or the same branch; users can also narrow what they see themselves). Your nameplate does not show your branch. The emotes you send, the effect when you receive 🔥, and the first few characters of a message you send in the Hong Kong-wide, district or branch channel (briefly shown as a speech bubble above your avatar) are seen live by everyone in the room. Your presence in office spaces is also shown to users in the same space. To display the room roster, your presence record (including nickname, avatar, branch name, district, check-in time and popularity) can be read by signed-in users' apps;
- your game results (leaderboard scores) and your popularity board entry (nickname, avatar, popularity and your staff card photo if you have one), visible to every signed-in user;
- User Content you post: channel messages, forum threads and replies. Channels are the Hong Kong-wide channel (one per gym brand), the district channel, the branch channel and office channels; messages show your nickname, Hong Kong-wide messages also show your district, district-channel messages also show your branch, and the record of every gym-room channel message carries the branch you sent it from. These channels can be read by any signed-in user (the app shows them only inside rooms). Private messages are visible only to the two people in the conversation;
- your clan's crest (if you are the owner and submitted one): the image is first reviewed by a human admin, and only once approved is it shown on the clan page, member roster and invite cards to every signed-in user; while pending, only our admins can see it.
Your email and check-in coordinates are never shown to other users. Your gender is not shown as text, but the gender you chose at sign-up sets your avatar's male or female figure, which other users can see. The private aliases you give friends are visible only to you.
4. Disclosure and Transfer of Data
4.1 We do not sell your personal data. We disclose it only to the following classes of transferees:
| Transferee | Purpose | Location |
|---|
| Google LLC (Firebase: authentication, database, file storage, cloud functions, push notifications) | Backend infrastructure of the Service | Google data centres (our backend cloud functions run in asia-east2 (Hong Kong); other Google services may run in the United States or elsewhere) |
| Google LLC (Google Cloud Vision SafeSearch) | Automated check of whether a staff card photo is likely to contain adult, violent or racy content. We send only the photo itself, after our server has shrunk it and removed its embedded data — not your nickname or user id. Google's description of how this service handles data: Cloud Vision Data Usage FAQ | Google data centres (may be outside Hong Kong) |
| Apple Inc. / Google LLC (sign-in services) | Account authentication | United States |
| Law-enforcement or regulatory authorities | Where required by law or court order | As required |
The automated screening of staff card photos works as follows: a photo rated LIKELY or VERY_LIKELY in any of these categories is refused and not stored; a photo rated POSSIBLE in any of them, or with an unclear rating, or whose check could not be completed, is held for human review by our admins and shown only once approved; any other photo appears on your staff card straight away.
4.2 These transfers may involve sending data outside Hong Kong (mainly to the United States). Our backend cloud functions are deployed in Google's asia-east2 (Hong Kong) region, but other Google services — authentication, the database, file storage, push notifications and Cloud Vision — may process data in Google data centres outside Hong Kong. Through data-processing terms with our service providers we require protection no less stringent than the Ordinance's standards.
5. Data Retention
| Data | Retention |
|---|
| Account and profile | Life of the account; permanently deleted 30 days after deactivation |
| Check-in records (including check-in coordinates), friend requests and friend records, private messages and conversations (both sides' copies), QR pairing codes, rate-limit records, daily counters (🔥 given and photo changes), private aliases, stored files | Deleted together with the account |
| Forum threads and replies, gym/district/Hong Kong-wide/office channel messages | Retained after account deletion, to preserve conversation integrity for other users. Such content still carries your former user id, but that id no longer corresponds to any live account and cannot be used to reach your profile (which has been deleted). If you want a specific post removed, delete it before deleting your account, or email us |
| Popularity board and mini-game leaderboard entries | Life of the account; removed at once when you request account deletion (weekly popularity boards are cleared for the most recent 27 weeks; older weekly boards keep their entries, which hold only the nickname, avatar and score of that time) |
| Staff card photo | A displayed photo is kept until you replace or remove it, we remove it, or you request account deletion, and is then deleted; when you replace your photo the old one is deleted. A photo refused by the automated screening is never stored. A photo held for human review is dealt with once reviewed (shown if approved, deleted if rejected). A photo temporarily hidden after reports is kept until we have reviewed it, then deleted or shown again |
| Invite code and invite link | Kept for the life of the account and used only to pay the invite reward. When you request account deletion, your invite code, your own "invited by" record and the related verification records are removed at once; the record of a friend you invited belongs to that friend's account and is kept until they delete theirs, holding only your (by then dead) user id |
| Clan crest images | A pending image is deleted once the review is decided (approved or rejected); an approved crest is deleted when the clan replaces it or is dissolved |
| Purchase history (transaction identifiers) | Kept to prevent duplicate grants, to handle refund disputes and for accounting, and not deleted automatically when an account is deleted; the record holds only the transaction identifier, the item and the user ID of your former account, which by then no longer matches any active account |
| Report records and related safety records (including photo screening ratings and review decisions) | Kept for safety, abuse-prevention and legal purposes; they are not automatically deleted when the reporter's or reported user's account is deleted. We delete them when they are no longer needed |
6. Account Deletion
Request deletion in-app via Backpack (背囊) → Settings → Delete Account, or by email (below):
- your account is deactivated immediately, sign-in is blocked and you are hidden from other users; your staff card photo is deleted at the same time (if you later restore the account within the recovery window, the photo does not come back — you can set a new one);
- during a 30-day recovery window you can email us to restore the account (because sign-in is blocked, simply logging back in cannot cancel the deletion);
- after 30 days, your account, profile, check-in records (including check-in coordinates), friend requests and friend records, private messages and conversations, QR pairing codes, daily counters, private aliases and stored files are permanently deleted and your sign-in credentials revoked. This is irreversible; all Virtual Items lapse with the account. Content already shared with other users, and the safety records described in section 5, are excepted.
Your popularity board and mini-game leaderboard entries are also removed when you request account deletion (see section 5). Private aliases other users have given you belong to their accounts and are visible only to them.
7. Data Security
We take reasonably practicable steps to protect your personal data, including: encryption in transit (TLS), server-side access rules (each user can access only their own data), authentication and rate-limiting on backend functions, and restricted staff access. No internet transmission is completely secure; in the event of a material data breach affecting your personal data we will notify you and the relevant authorities in line with PCPD guidance.
8. Your Rights
Under the Ordinance you may:
- access the personal data we hold about you (s.18);
- correct inaccurate data (s.22) — nicknames can be changed directly in-app;
- remove your staff card photo — remove or replace it any time in-app via Backpack (背囊) → Me (個人) → Change / remove photo (更換 / 移除頭像);
- delete your account and data (section 6);
- opt out of push notifications — via device system settings.
To exercise access or correction rights, email us (below). We respond within 40 days. A reasonable fee may apply to access requests.
9. Minors
There is no minimum age for the Service, and we do not ask users for their age or date of birth. If you are under 18, please obtain a parent's or guardian's consent before using the Service. Parents and guardians may email us to access or delete a minor's personal data (see sections 8 and 11).
10. Changes to This Policy
We may revise this Policy from time to time. Material changes will be notified in-app in advance. The revised Policy applies from its stated effective date.
- Email: enquiry@gymlonline.com
- You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD): www.pcpd.org.hk / +852 2827 2827
Document version: v1.1 (29 September 2026). In case of discrepancy with the Chinese version, the Chinese version prevails.