Gokin — Privacy Policy
Last updated: September 23, 2026
Gokin is a workout app published by Shapeweaver Solutions Inc. ("we"), of 404-6860 Royal Oak Avenue, Burnaby, British Columbia V5J 0G9, Canada. This policy says what the app collects, where it goes, what never leaves your phone, how long it is kept, and how to get it deleted.
The short version
- Signing in is required, so every user has an account. It holds your email address and your training history.
- Your workouts — the exercises, the loads, the sets — are stored under your account and nowhere else. They are never sent to an analytics or crash-reporting service.
- We record a fixed list of product events (a workout finished, a swap, a forge) and crash reports. Those carry counts, durations and fixed labels, never your exercises, your loads, or anything you typed.
- Gokin never reads your location, and our reporting services are set not to work one out from your network address.
- Nothing in Gokin records your screen, and the app shows no advertising. There is no advertising or attribution software in it, and we do not sell your data.
- You can get a free copy of your data, or delete your account and everything filed under it, at any time.
What we collect, and why
1. Your account
You sign in with your email address: we send a link to it, and tapping that link opens the app. Some accounts — staff and test accounts we set up ourselves — sign in with a password instead. We store:
- Your email address, because it is how you sign in and how we can reach you about the account.
- An account identifier — a random string created with the account. It is what every other record is filed under, and it is the only identity the reporting services below ever receive.
There is no in-app signup, no password reset and no profile: no name, no photo, no age and no body metrics are asked for or stored.
2. Your training data
Everything the app records about your training is stored under your account, so it survives a lost phone and follows you to a second device:
- A finished workout: when you did it, the Training Node and Focuses you chose, the duration you committed to, the elapsed time, the sets completed, the swaps made, the XP and Metals it paid, the number of personal records and load changes, your top sets, and the exercises you performed with their loads and reps.
- A forge: when it happened, the Node, the bars it spent and what it produced.
- A saved workout: its optional name, Node, duration, Focuses and exercises.
- Whether your Gokin Subscription is active on the account, and whether the account is a staff account.
Every row is filed under your account identifier, and the database is configured so that an account can read only its own rows.
3. Purchases
The Gokin Subscription is an auto-renewing subscription, billed monthly or yearly through the App Store or Google Play. The payment is handled entirely by the platform — we never see your card details. We use RevenueCat to keep track of whether a purchase entitles your account to the subscription: the app tells RevenueCat your account identifier, RevenueCat holds the purchase and subscription record against it, and it notifies our backend when the subscription starts or ends, so your account follows the store.
4. Product events
We use PostHog to see how the app is used. The app reports a fixed, closed list of events, and nothing else:
app_opened, signed_in, workout_generated, workout_started, set_logged, swap_sheet_opened, exercise_swapped, workout_completed, workout_abandoned, streak_broken, alloy_forged, node_level_crossed, saved_workout_created, saved_workout_loaded, paywall_viewed, subscription_activated.
Each one carries only numbers, true/false values and fixed labels — a duration in minutes, a count of sets, which Training Node, which purchase screen was raised. A finished workout reports its length, its sets, its XP and how many bars it found; it does not report which exercises you did or what you lifted.
PostHog's own software adds context to each report, such as the app version and the kind of device. The app tells PostHog not to work out a location from the network address a report arrives from, and PostHog is set to discard that address (see 6).
Your reports are filed under your account identifier once you are signed in. Before you sign in they are filed under a random identifier the PostHog software generates on the device; signing in joins that identifier to your account, and signing out starts a fresh one.
5. Crash and performance reports
We use Sentry to find out when the app breaks. A report carries what failed and where in the code, the device model and OS version, a short trail of the app's own activity leading up to the failure, and — for a sample of sessions — timings of how long parts of the app took. Sentry is configured not to attach IP addresses, cookies or request headers, and not to store the network address a report arrives from; your account identifier is the only identity it is given.
6. Location
Gokin never asks for location permission and never reads your phone's location. Neither reporting service keeps the network address a report arrives from, so no approximate location is worked out from it either.
7. Notifications
The rest timer, its alarm and the workout's ongoing notification are scheduled by your own phone. Gokin registers no push token and sends no notifications from a server, so nothing about them leaves the device.
8. Reporting runs in the published app
The product events and crash reports described above are sent by the app versions we publish. They are silent in development builds and in any build assembled without the reporting keys. There is no in-app switch to turn them off.
Why we are allowed to use it
- Your account, your training data and your purchases are used to provide the app you signed up for: without them there is no sign-in, no history, no sync and no subscription.
- Product events and crash reports are used in our legitimate interest in keeping the app working and understanding which parts of it people use. They carry no training detail and no contact details, and you can have them deleted (see "Deleting your account").
By creating an account you agree to this use. You can withdraw that agreement at any time by deleting your account.
What never leaves your phone
- No exercise name, load or set detail appears in a product event or a crash report. Your training detail goes to your account and nowhere else.
- Your email address is never sent to PostHog, Sentry or RevenueCat.
- Nothing records your screen — no session replay, no screenshots. Product analytics captures no taps or screens on its own; the event list above is the whole of it.
- Device-only settings and state: your appearance and unit choices, your exercise library edits and hides, the working loads the app remembers per exercise, and a workout in progress. None of it is uploaded.
- The profile card goes where you send it. It is drawn only when you ask to share it, and it is handed to your phone's own share sheet — we never see where it goes.
Signing in with a different account on the same device first clears the previous account's data from that device, so one person's workouts are never shown to another.
Who else processes it
Each of these acts as our processor, on our instructions, for the purpose named:
| Service | What it receives | Why |
|---|---|---|
| Supabase | Your email, account identifier and all training data | Running the account and sync |
| PostHog | The events listed above, the account identifier, app and device context | Understanding product use |
| Sentry | Crash and performance reports, the account identifier | Finding and fixing failures |
| RevenueCat | The account identifier and your purchase and subscription state | Knowing whether your subscription is active |
| Apple / Google | The purchase itself | Taking the payment |
None of them is an advertising network or a data broker, none receives your data for its own purposes, and Gokin does not track you across other companies' apps or websites.
Where it is held
- Account and training data: Supabase, United States (Ohio).
- Product events: PostHog Cloud, United States.
- Crash and performance reports: Sentry, United States.
- Purchase and subscription state: RevenueCat, United States.
Everything the app sends travels over an encrypted connection.
We are based in Canada and every service above stores data in the United States, so your data is held outside Canada. While it is there it is protected by our agreements with each service, and it is also subject to United States law, which means courts, law enforcement and national security authorities there may be able to obtain it. If you live in the European Union or the United Kingdom, the transfer is covered by the safeguards data protection law requires, such as the European Commission's Standard Contractual Clauses.
How long we keep it
| What | How long |
|---|---|
| Your account and training data | Until you delete the account. Deleting it removes the data from our live database at once, and from our backups within 30 days. |
| Product events | 12 months, after which PostHog deletes them. |
| Crash and performance reports | Up to 90 days, after which Sentry deletes them. |
| Your subscription record at RevenueCat | Until you ask us to delete it (see "Deleting your account"). |
| Data stored on your phone | Until you delete the account in the app, or delete the app. |
Apple and Google keep their own records of your purchases, under their own privacy policies.
Your choices and rights
Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to complain to a data protection authority. Write to privacy@gokin.app from the address your account signs in with and we will answer within 30 days.
A copy of your data is free. Ask for it at the same address, and we will send your account details, your workout history, your forges and your saved workouts as CSV files, which open in any spreadsheet app.
In Canada, you can complain to the Office of the Privacy Commissioner of Canada or, in British Columbia, to the Office of the Information and Privacy Commissioner for British Columbia. In the European Union or the United Kingdom, you can complain to your local data protection authority. We would rather hear from you first, at privacy@gokin.app.
Signing out clears the session from the device.
Deleting your account
You can delete your Gokin account, and everything filed under it, at any time, in either of two ways:
- In the app: open Settings, choose Delete account and confirm. The account is deleted there and then, and the app clears its data from that phone.
- Without the app: email privacy@gokin.app from the address your account signs in with and ask us to delete it. We will delete it and confirm by reply within 30 days.
What is deleted: your account, your email address, and everything filed under them — your workout records, your forges and your saved workouts. They leave our live database at once and our backups within 30 days.
What is kept, and for how long: product events and crash reports already sent carry your account identifier and no other identity, and they expire on the schedule above — 12 months and 90 days. RevenueCat keeps its record of your subscription until we ask it to delete it. To have any of these deleted sooner, say so in your email, or write to us after deleting in the app, and we will have them deleted. Apple and Google keep their own record of your payments.
Deleting your account does not cancel your Gokin Subscription. Apple or Google bills it, so cancel it in your App Store or Google Play subscription settings, or it will keep renewing.
Children
Gokin is not intended for anyone under 16, and we do not knowingly collect data from anyone under
- If you believe someone under 16 has an account, write to privacy@gokin.app and we will delete it.
Changes to this policy
If what the app collects changes, this page changes with it and the date at the top is updated.
Contact
Shapeweaver Solutions Inc., 404-6860 Royal Oak Avenue, Burnaby, British Columbia V5J 0G9, Canada. Privacy questions and requests: privacy@gokin.app. The person responsible for privacy at Shapeweaver Solutions Inc. answers that address.