Legal document

Data Retention and Destruction Policy

Effective: 20 August 2026 Version: 1.0

1. Purpose and scope

This policy sets out the retention periods, destruction methods and periodic destruction cycle applied by Adem Coşar to personal data processed through the Gainzor mobile app and gainzor.com.

It implements the storage-limitation principle under GDPR Art. 5(1)(e) and the requirements of Turkish Law No. 6698 Art. 7 together with the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. It should be read with the Privacy Policy.

2. Principles

  • Purpose limitation. Data is kept only for as long as the purpose it was collected for requires.
  • Data minimisation. We do not collect data we do not need; if we have, we destroy it.
  • Destruction at the end of the period. When the purpose falls away and no legal obligation to retain remains, data is deleted, destroyed or anonymised.
  • Irreversibility. Destruction is carried out so that the data cannot be recovered or reused.
  • Recording. Destruction operations are logged, and those logs are kept for at least three years.

3. Storage environments

EnvironmentContents
Local database on the user's deviceWorkout records, plans, routines, measurements, achievements, AI Coach chats, app preferences
Cloud database (EU — Frankfurt)Account, profile, synced training and measurement data, social content, subscription status, notification tokens
Cloud file storageProfile photos, post images and videos, custom exercise media
System and application logsConnection logs, error and crash records, server operational logs
BackupsPeriodic backup copies of the cloud database
EmailSupport correspondence and data subject requests

4. Why we keep data

  • Performing the membership agreement and delivering the service,
  • Letting you reach your data when you change device,
  • Statutory retention obligations,
  • Establishing, exercising and defending legal claims within limitation periods,
  • Keeping the system secure and preventing abuse,
  • For consent-based processing, for as long as consent stands.

5. Why we destroy it

  • The purpose requiring processing has ceased,
  • The user has closed their account,
  • Consent has been withdrawn, where processing relied on consent,
  • A deletion or destruction request has been accepted,
  • The legal provision the processing relied on has changed or been repealed,
  • The retention period has expired with no other basis for keeping the data,
  • A supervisory authority has decided otherwise after a rejected request.

6. Retention table

DataRetention periodDestroyed within
Account and profile dataWhile the account is open30 days of account closure
Training data (plans, routines, sessions, sets, records, achievements)While the account is open30 days of account closure
Health data (measurements, weigh-ins)While consent stands30 days of withdrawal
Social content (posts, comments, likes, follows)Until the content or account is deletedImmediately on request; 30 days from backups
Uploaded photos and videosUntil the post or account is deletedImmediately on request; 30 days from backups
AI Coach chat history and user memoryUntil deleted by the user or the account closesImmediately on request
AI usage counters90 daysAutomatically at the end of the period
Push notification tokensUntil permission is withdrawn, the app is uninstalled or the token expiresThe first periodic destruction after expiry
Error and crash reports90 daysAutomatically at the end of the period
System and connection logsThe period required by applicable lawThe first periodic destruction after expiry
Subscription status records10 years from the end of the subscription (tax law and limitation periods)The first periodic destruction after expiry
Support and data subject correspondence3 years from resolutionThe first periodic destruction after expiry
Consent recordsFor the limitation period after withdrawalThe first periodic destruction after expiry
Destruction logsAt least 3 yearsThe first periodic destruction after expiry
Copies in backupsUp to 30 daysOn completion of the backup cycle

Where more than one retention basis applies, the longest period governs. If litigation or a request from a competent authority is pending, the relevant data is preserved until the matter concludes and the hold is recorded.

7. Destruction methods

7.1 Deletion

Data is rendered inaccessible and unusable for the relevant users. Rows are permanently removed from the cloud database (hard delete) and related records go with them through the foreign-key chain. Objects in file storage are permanently removed.

7.2 Destruction

Data is rendered inaccessible and irretrievable by anyone. Where a record exists in physical form, the medium is shredded or otherwise securely destroyed.

7.3 Anonymisation

Data is altered so that it can no longer be associated with an identified or identifiable person, even when combined with other data. Statistical and product analysis uses aggregate data whose link to identity has been permanently severed.

7.4 Backups

Data inside a backup cannot be deleted instantly. Deleted data is therefore made inaccessible in backups and disappears permanently within 30 days as the backup cycle completes. If a backup has to be restored, records deleted in the meantime are deleted again after restoration.

8. Periodic destruction

Data whose retention period has expired is handled in a periodic destruction cycle run every six months (June and December), within the maximum six-month interval permitted.

Each cycle:

  • Identifies records whose retention period has expired,
  • Checks whether any basis for longer retention exists,
  • Applies the appropriate destruction method,
  • Records the date, scope and method of the operation.

9. Deletion on request

You can request deletion using the account deletion feature in the app or by writing to info@gainzor.com.

  • Requests are resolved within 30 days.
  • Where a request is granted, recipients the data was shared with are notified of the deletion.
  • If a legal basis for continued retention exists — for example an ongoing dispute or a tax-law obligation — the request may be refused with reasons. In that case the data is made inaccessible and processed only for the purpose that requires its retention.

10. Technical and organisational measures

  • TLS encryption for data in transit,
  • Row-level security policies and a least-privilege model in the database,
  • One-way hashing of passwords,
  • Secrets held server-side and never embedded in the app package,
  • Signed, time-limited access links for privately visible media,
  • Access rights scoped to role and reviewed periodically,
  • Vulnerability scans and dependency audits,
  • An internal process for notifying the supervisory authority and affected users of a data breach within the statutory deadline.

Last updated: 20 August 2026 · Version 1.0