Privacy Policy
Covers the GAINSBYBRAINS App, the GAINSBYBRAINS website, memberships and email communications.
Version 1.2.0 · 15 September 2026
Who we are
This is the privacy statement of GAINSBYBRAINS B.V. (“GAINSBYBRAINS”, “we”). We explain why we collect and use your personal data when you use our app, our website, or purchase a membership, what your rights are, and how to contact us.
Contact: gdpr@gainsbybrains.com. Corporate address: GAINSBYBRAINS B.V., Zekeringstraat 17 A, 1014 BM Amsterdam, the Netherlands. Dutch Chamber of Commerce number: 76549348.
What personal data do we collect and use?
The table below lists the personal data we process, why, and the legal basis. The legal bases are explained further below.
| Type | Why | Legal basis |
|---|---|---|
| necessary to communicate with you | Art. 6(1)(b) GDPR | |
| Name (pseudonym allowed) | necessary to properly address you | Art. 6(1)(b) GDPR |
| IP address(es) | security measures | Art. 6(1)(f) GDPR |
| Preferred language ISO code | necessary to properly inform you | Art. 6(1)(b) GDPR |
| Password | to secure your account | Art. 6(1)(b) GDPR |
| Preferred workout days / intensity level | necessary to perform the services | Art. 6(1)(b) GDPR |
| Liked content IDs | perform the services; analyse general content preferences | Art. 6(1)(b) / 6(1)(f) GDPR |
| Fitness plan data (start date, workouts, exercises, recipes, completion state) | necessary to perform the services | Art. 6(1)(b) GDPR |
| Subscription data from the Apple App Store and from our payment/subscription providers (Stripe, RevenueCat) | to check for a valid subscription and manage your membership across app and website | Art. 6(1)(b) GDPR |
| Payment and billing data for website memberships (payment method type, billing details, transaction history) | to process payments, renewals, refunds and chargebacks; to keep statutory financial records | Art. 6(1)(b) / 6(1)(c) GDPR |
| Consent and order records (acceptance of terms, express-start request, marketing consent, timestamps, IP address, terms version) | to prove conclusion of the agreement and consent | Art. 6(1)(c)/(f) GDPR |
| Marketing consent status and email engagement data (subscriptions, opens, clicks, unsubscribes) | to send program guidance, feature updates and offers if you opted in; to personalise them; to honour opt-outs | Art. 6(1)(a) GDPR; opt-out records: Art. 6(1)(c)/(f) GDPR |
| Profile and activity properties used for email personalisation (first name, current program, subscription status, platform, recent activity signals) | to segment and personalise the emails you consented to (e.g. program-specific coaching) | Art. 6(1)(a) GDPR |
| Push notifications | to send news and updates about the app or our services | Art. 6(1)(a) GDPR |
| Website cookie and similar-technology data | functional operation of the website; with consent: analytics | Art. 6(1)(b)/(f) GDPR; consent-based cookies: Art. 6(1)(a) GDPR |
| Anonymized data analysis | statistical analysis of use and stability of the app | Art. 6(1)(f) GDPR |
We do not process any health data or monitor your health via your mobile device, sensory equipment or the app. Should we extend the app in the future to allow health tracking, your informed consent will always be requested first.
Payments (Stripe)
If you purchase a membership via our website, payment is processed by Stripe. Stripe collects and processes your payment details (such as card number and authentication data) directly — we never receive or store your full card details. We receive from Stripe only what we need to manage your membership: payment method type, payment status, billing details and transaction history. When you start a trial, Stripe stores your payment method before any charge is made, so that the first payment can be taken at the end of the trial.
Stripe also processes certain data as an independent controller for its own purposes, such as fraud prevention and compliance with financial regulations. See Stripe’s privacy policy at https://stripe.com/privacy.
We are legally required to retain records of transactions for our financial administration for 7 years (Dutch tax law).
Email marketing (Klaviyo)
If you tick the marketing checkbox (“Send me program guidance, new feature updates and offers by email.”) at signup or checkout, we send you emails with program guidance, new feature updates and offers. We only do this with your consent (Art. 6(1)(a) GDPR), and you can withdraw that consent at any time via the unsubscribe link in every email or via your account settings — withdrawal is as easy as giving consent was.
We use Klaviyo, Inc. as our email service provider (processor). To personalise these emails, the following data is shared with Klaviyo: your email address, first name, language, current program, subscription status, the platform you use, and recent activity signals (for example, whether you have been inactive). Klaviyo also measures on our behalf whether emails are opened and which links are clicked, so we can send fewer and more relevant emails. This constitutes basic segmentation and personalisation; we do not use it for automated decisions with legal or similarly significant effects.
If you unsubscribe, we keep a minimal suppression record (your email address and the fact that you opted out) so that we can guarantee you no longer receive marketing. This record is kept precisely to honour your opt-out and is not used for any other purpose.
Subscription management (RevenueCat)
We use RevenueCat, Inc. to manage subscription entitlements across the App Store, our website and (in the future) other platforms. RevenueCat processes an internal user ID, subscription status and purchase events on our behalf so that one membership unlocks the app and the website alike.
May we process your personal data? (legal bases)
Performance of the agreement.
Most processing is necessary to perform our services: providing the app and website, verifying a valid subscription, processing payments and handling complaints (Art. 6(1)(b) GDPR).
Legal obligation.
In some cases we are obligated by law to process or archive personal data, such as keeping financial records of transactions for 7 years (Art. 6(1)(c) GDPR).
Legitimate interests.
We store IP addresses to secure the app and prevent illegitimate use. We analyse which content is liked in anonymised form to improve the app. We analyse in-app behaviour and stability with Google Analytics for Firebase and Firebase Crashlytics; details on the data Firebase collects: https://support.google.com/firebase/answer/6318039 (Art. 6(1)(f) GDPR). We also keep consent and order records to be able to demonstrate the conclusion of your agreement and your consent choices (Art. 6(1)(c)/(f) GDPR).
Consent.
We ask your consent for push notifications, for marketing emails and for non-functional cookies. You can withdraw consent at any time; from that moment we no longer process your data on that basis, unless another legal basis applies (Art. 6(1)(a) GDPR).
International transfers
Our hosting and primary data storage with Amazon Web Services takes place in the European Union. However, some of our service providers (including Klaviyo, Stripe, Google and RevenueCat) are based in, or may process data in, the United States. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place. Klaviyo, Stripe and Google are certified under the EU–U.S. Data Privacy Framework, with the European Commission’s Standard Contractual Clauses applying as a fallback under their data processing agreements. Transfers to RevenueCat take place on the basis of the Standard Contractual Clauses incorporated in its data processing agreement. You can request a copy of the relevant safeguards via gdpr@gainsbybrains.com.
How do we secure your data?
We take technical measures (physical security of data centres, logical access control, secure connections, password hashing, encryption, IP-address logging) and organisational measures (access limited to authorised persons bound by confidentiality, data processing agreements with all processors, security incident management) to protect your data.
How long do we keep your data?
We do not keep personal data longer than necessary for the purpose for which it was collected. Upon deletion of your account or a removal request, your data is deleted within 14 days, except where we must or may retain specific data longer:
- transaction and invoicing records: 7 years (Dutch fiscal retention obligation);
- consent and order records: for the duration of the agreement plus the applicable limitation period;
- marketing suppression records: retained to permanently honour your opt-out;
- data needed for the establishment, exercise or defence of legal claims: for the duration of the relevant limitation period.
What are your rights?
You can ask us what personal data we process about you, and request correction, deletion, transfer or restriction of processing. You can object to processing based on legitimate interests, and you can withdraw any consent at any time. Restricting processing may affect or prevent the performance of the app or your membership.
If you disagree with how we process your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the supervisory authority of your country of residence.
Requests, questions or complaints: gdpr@gainsbybrains.com.
Changes to this privacy statement
This privacy statement is valid as of 15 September 2026 and replaces the version of 1 September 2026. The most recent version applies at all times. If a revision could significantly affect you, we will do our best to inform you — in the app via an update notice, and for email recipients via email.
v1.2.0 (15 September 2026) — 14-day trial on all plans, confirmation page, consent records. v1.0/1.1 — 1 September 2026, initial unified version.