My Dayapp

Privacy Policy — My Day App

v5 — 2026-08-30

Effective: 2026-08-30

Version: 5

Last updated: 2026-08-30

Applies to: the apps of the My Day App brand — My Day Works, My Day Fitness, My Day Beauty and My Day GYM (together, "the apps")

1. In one page

If you read only one section, read this one:


2. Who is responsible for your data

My Day App is the brand under which we publish the apps. It is not a company. The company behind it — and the controller of the personal data processed in the apps — is:

Legal nameTwo Moons Media Ltda
Trading nameBrave Labs
CNPJ46.326.126/0001-51
AddressAv. Nove de Julho, CEP 01406-200, São Paulo, SP, Brasil
Contact e-mailcontact@bravelabs.co
Data Protection Officer (DPO)Guilherme Valentecdo@mydaysuite.com

In this document, "we" means Two Moons Media Ltda. The complete mapping is this, and there is nothing beyond it:

LayerName
Responsible legal entity (controller)Two Moons Media Ltda, CNPJ 46.326.126/0001-51
Company trading nameBrave Labs
Brand of the appsMy Day App
Apps published under the brandMy Day Works, My Day Fitness, My Day Beauty, My Day GYM

"Controller" is the term used by Brazil's General Data Protection Law (Law 13,709/2018, "LGPD") for whoever decides why and how personal data is processed.

One important exception: in My Day GYM, when you are a personal trainer's trainee, that professional also makes decisions about your data. The My Day GYM section explains exactly who answers for what.


3. Which apps this policy covers

This policy is common to all apps of the My Day App brand:

AppWhat it doesPrivacy particularity
My Day WorksAggregator: brings the whole day's routine togetherNone beyond the common rules
My Day FitnessFood and trainingProcesses food and exercise data; may read Apple Health / Health Connect
My Day BeautySkin and hair careProduct photography is frequent; may involve skin progress photos
My Day GYMSelf-directed training, personal trainers and traineesCollects the PAR-Q questionnaire, a verified mobile number and date of birth. Data may be shared between people when the trainee accepts the link. See section 12

Where an app has processing of its own, that is marked in the text. Where there is no marking, the rule applies to all.

Apps and features not yet launched. This policy already describes the processing of all the brand's apps, including those not yet available in the stores, and of features still under construction. Where an app or a feature does not yet exist, the processing described here only begins when it is published — the advance description exists so that you know, before installing, what will happen.


4. What data we process, why, and on what legal basis

The LGPD requires every processing operation to have a legal basis — the legal ground that authorises it. Below, each category of data with its own.

4.1 Account and identification data

You sign in to your account in one of these ways: Sign in with Apple, Google sign-in or a single-use code sent to your e-mail. What we keep depends on which you choose.

DataOriginWhat forLegal basis (LGPD)
User identifier at the login provider (Apple's or Google's sub)Apple or Google, at loginRecognising you across sessions and devicesArt. 7, V — performance of contract
E-mail (it can be an anonymous Apple relay address, if you choose to hide yours)You type it, or it comes from Apple/Google on first authorisationSigning in, account-related contact and supportArt. 7, V — performance of contract
Single-use access code and the date it was sentGenerated by our serverProving the mailbox is yoursArt. 7, V — performance of contract
First and last nameYou type them, or they come from Apple/Google on first authorisationPersonalising the interface and identifying you to your personal trainer, in My Day GYMArt. 7, V — performance of contract
Session tokenGenerated by our serverKeeping you signed in without asking for login every timeArt. 7, V — performance of contract
IP address of whoever requested the access codeYour connectionLimiting attempts and detecting abuse of code sendingArt. 7, IX — legitimate interest in security

We keep only the hash of the session token and the hash of the access code, never the value itself: a copy of our database does not work as a credential to enter your account.

In My Day GYM, sign-up asks for more, because the product is about physical exercise and training safety depends on it:

DataWhat forLegal basis (LGPD)
Date of birthConfirming you are over 18 — below that, sign-up is refused — and adjusting training guidance to ageArt. 7, V — performance of contract; Art. 7, IX for age verification
GenderParameter for training and body composition referencesArt. 11, I — consent (see 4.3)
Mobile numberVerifying the number is yours, by a code sent by SMS, and allowing your personal trainer to reach youArt. 7, V — performance of contract
Professional registration (CREF), if you apply to act as a personal trainerReviewing your qualification before releasing the trainer roleArt. 7, V — performance of contract
Instagram or TikTok profile, if you provide itDisplaying it on your trainer profileArt. 7, IX — legitimate interest, and it is optional

We do not ask for CPF, ID, home address or payment data. Payment happens entirely inside the App Store or Google Play — see section 4.7.

4.2 Your routine and the content you create

This is the heart of the product: the meals, the workouts, the care products, the schedules, the notes, the "done" and "skipped" marks, the goals.

4.3 Health data — a sensitive category

Health data is sensitive personal data under the LGPD (art. 5, II), and processing it requires your specific and highlighted consent (art. 11, I). We ask for that consent on a dedicated screen, before the first use of each feature that depends on it — not inside a general acceptance and not as a pre-ticked box. Feature and consent screen arrive together: without the consent, the feature is not unlocked and the corresponding data is not processed. Refusing does not stop you using the rest of the app; it only stops the feature that depends on that data.

This category includes:

DataHow it reaches usWhere it stays
PAR-Q questionnaire — seven yes/no answers about heart problems, chest pain during activity and at rest, dizziness or fainting, bone or joint problems, use of blood pressure or heart medication (without asking which), and any other impedimentYou answer in My Day GYM, before training and before accepting the link with a personal trainerOn our server, on a server in Brazil. See the detail below
Water, caffeine, steps, active and basal energy, body weight, body fat percentage, lean mass, BMI, sleep analysis and workoutsFrom Apple Health (HealthKit) or Health Connect on Android, only if you authorise each typeStays on the device. We do not send it to our server
Waist circumference you logYou type it in the appOn the device; we write it to Apple Health only if you ask
Body measurements, weight and composition you log manuallyYou type themOn the device and, as part of the routine, on our server
Logged food (meals, foods, quantities, macros)You type, photograph or dictateOn the device and, as part of the routine, on our server
Body progress and before/after photosYou photographOnly on your device. See 4.4
Free-text description of a skin or hair condition, dietary restriction or health goal you writeYou type itOn the device and, when you use an AI feature, transiting through the providers in section 6
Date of birth and gender, when used as training or body composition parametersYou type them at My Day GYM sign-upOn our server

The PAR-Q, in detail — because it is the most sensitive data that leaves your device.

4.4 Photographs of you

There are three kinds of photo in the product, and they receive different treatment. The distinction matters:

(a) Body progress photos, before-and-after photos, and the profile avatar They are stored on your device, in the app's private area. We do not upload those photos to our server. If your Apple (iCloud) or Google account backup is on on the device, they go into that backup — which belongs to you, is governed by Apple's or Google's terms, and which we cannot access.

(b) Product photos — the case worth explaining When you photograph a product's packaging (a shampoo bottle, a jar of cream, a food label), the image is sent to our artificial intelligence providers for one purpose only: finding out which product it is. What the AI extracts is text — name, brand, size, composition, barcode.

Then, if that product does not yet exist in our catalogue, the system generates a new illustration, from scratch, in the catalogue's visual style (white background, e-commerce-style shot). It is that generated illustration that gets stored — never your photo.

The difference, put plainly: we do not keep your photo. We recognise the product and start using our own illustration of it. And the illustration depicts a product that exists publicly on the market — not you, not your home, not your bathroom.

(c) Meal photos Same logic as above: the photo of the plate goes to the AI to be interpreted into foods and quantities, and what gets recorded is the resulting text (the food, the quantity, the macros), not the photograph.

In (b) and (c), the image transits through the providers listed in section 6 during processing. We do not archive it.

The catalogue of personal care products and foods is common to all users. When you add a product that does not yet exist, it becomes part of that catalogue and can be seen by other users.

What goes into the catalogue is information about the product: name, brand, size, barcode, composition, purpose, pH, directions for use, contraindications, warnings and the generated illustration. Nothing about you goes in — not your name, not your e-mail, not your routine, not when or how you use that product.

Internally, we keep alongside the product record the internal identifier of whoever added it, for curation and duplicate correction. That identifier is an opaque string: it is not your name, it is not your e-mail, and no screen in the app displays it to other users. We treat that identifier as internal curation data and work to keep it from circulating beyond that purpose.

4.6 Technical and security logs

To keep the service running and detect abuse, our servers and our network edge automatically record data such as IP address, request time, route accessed and response code. We also record the IP address associated with each request for an access code by e-mail or SMS, to limit attempts.

4.7 Subscription and billing

We do not process your payment and we do not receive your card details. Billing for any paid feature is done entirely by the App Store (Apple) or Google Play (Google), under their terms and privacy policy.

What reaches us is only what is needed to know whether you are entitled to the product: a transaction identifier or validated purchase receipt, the subscribed product, the status (active, in grace period, expired) and the renewal date. Name, card number, billing address and CPF do not pass through us.

4.8 Usage telemetry

We collect signals about how the app is used — which screens are opened, which features are triggered, where failures occur, how long an operation takes. It serves one purpose only: improving the product.

We use Google Analytics for Firebase for this, in My Day Works and My Day Beauty. It assigns the app installed on your device its own randomly generated identifier (the App Instance ID), which allows counting sessions and understanding flows. That identifier is not your name, is not your e-mail and is not the device's advertising identifier — and it resets if you uninstall the app or erase its data.

Let us be precise about what that identifier is: it is pseudonymised data, not anonymous data. It does not say who you are, but, being a persistent identifier, it remains personal data under the LGPD (art. 12) — and that is how we treat it, with this policy's protections.

What never goes into telemetry: the text you write, the names of your items, your photos, your health numbers, your measurements, your PAR-Q answers. Telemetry carries fixed event names and closed categories, never content you created.

Telemetry does not feed advertising. We do not use it to choose ads, to build a profile of you or for campaign attribution. See 4.9.

4.9 Advertising

The apps may show advertising. When that happens, the following will apply — a product decision, not a vague promise:

If we ever decide to change any of these rules, that will be a material change to this policy, announced as set out in section 14 — and, where the law requires consent, it will be asked for first.

4.10 Artificial intelligence features

Several features use third-party artificial intelligence models: identifying a product by photo or barcode, interpreting a written or photographed meal, drafting a routine proposal from free text, assessing the impact of a change to the training week, generating a new product's illustration.

For that, the relevant content — the text you wrote, the photo of the product or plate, your routine's items — is sent to the corresponding provider through our own intermediary layer, an edge service that sits between the app and the provider. That layer exists for a concrete reason: the providers' access keys never live inside the app installed on your device. The providers are listed by name in section 6 and in Annex B, and most of them are located outside Brazil, which constitutes an international transfer (see section 7).

Four limits we commit to:

  1. We do not archive the images sent to the AI. They transit for processing, and what persists is the structured result (the extracted text, the generated illustration).
  2. Health data from Apple Health, from Health Connect and the PAR-Q are never sent to an artificial intelligence provider.
  3. We do not use your content to train models of our own, and we seek from each provider a contractual commitment not to train models on the submitted content. The state of that commitment varies by provider and can be checked at any time via cdo@mydaysuite.com.
  4. AI gets things wrong. What it returns is a suggestion, not a prescription. See the health disclaimer in the Terms of Use and section 11 of this policy.

5. Where each piece of data lives

This is probably the most useful table in this document.

DataOn the deviceIn your Apple/Google account backupOn our serverWith a third party
Login identifier, e-mail, nameApple / Google (origin)
Session token✅ (Keychain)✅ (hash only)
Access code sent by e-mail✅ (hash only)E-mail delivery service
Access code sent by SMS✅ (hash only)Comtele (delivery)
Mobile numberComtele (only to send the SMS)
Date of birth and gender (My Day GYM)
PAR-Q answers (My Day GYM)
Consent and acceptance records
Routine, meals, workouts, schedulesAI providers, when you use an AI feature
Apple Health / Health Connect dataper Apple/Google
Typed measurements and weight
Body progress and before/after photos
Profile avatar
Product photo you taketransientTransits through the AI providers
Meal photo you taketransientTransits through the AI providers
Generated product illustrationGenerated by an AI provider
Product record in the catalogue (name, brand, composition)✅ (shared)
Subscription statusApple / Google (origin)
Usage telemetry and installation identifierGoogle (Firebase)
Access logs (IP, time)Cloudflare (network edge)
Encrypted backup of our databaseCloudflare R2 (encrypted before leaving)

Legend: ✅ stays; ❌ does not stay; "transient" = exists only during processing.


6. Who we share with

We do not sell personal data. We do not share personal data with data brokers. We do not share data with advertisers for targeting.

We share with processors (in the LGPD's language, "operadores") — suppliers that process data on our behalf, under contract and under our instruction — to the extent needed for the service to work:

Processor / Third partyRoleWhat it receivesWhere it is
HostingerHosting of the account, routine, catalogue and My Day GYM serverAll the data in section 5 marked "on our server"Brazil (São Paulo data centre)
Comtele Soluções em TecnologiaSending the SMS with your mobile verification codeYour mobile number and the code's text. It receives no name, e-mail or any other data of yoursBrazil
Resend, Inc.Sending the e-mail with the access code, when that is the configured channelYour e-mail address and the code's text. When delivery is done by our own e-mail server, hosted on the infrastructure above, no third party receives your addressUSA
AppleAuthentication (Sign in with Apple), distribution, billing, HealthKitLogin credential; billing data (directly with you)USA and global
GoogleAuthentication (Google sign-in), distribution and billing on Google Play, Health Connect on AndroidLogin credential; billing data (directly with you)USA and global
Cloudflare, Inc.Network edge, the intermediary layer that makes the AI and SMS calls, internal panel access control, and storage of backupsApplication traffic, IP, content in transit; backups already encrypted before leaving our serverUSA and global
Google (Gemini)Language and vision modelText and images you submit to an AI featureUSA and global
OpenAI, L.L.C.Generation of the catalogue illustrationThe product's reference photo and the request's textUSA
DeepSeekLanguage model (routine and food structuring)Text you submit to an AI featureChina
Alibaba Cloud (Qwen and Wan)Label reading by computer vision (OCR) and image generationThe label or plate photo you take, and the request's textSingapore (group headquartered in China)
Jina AI GmbHSearch and reading of public pages to ground the product recordThe search term derived from the product. Receives no data of yoursGermany / USA
Open Beauty Facts / Open Food FactsPublic, open product and food databasesThe barcode or name of the product looked up. Receives no data of yoursFrance / European Union
Google LLC (Google Analytics for Firebase)App usage telemetryUsage events and the installation identifier described in 4.8USA and global

We also share:

The list above is kept up to date, and Annex B carries each processor's detail. Processor changes are announced as set out in section 14.


7. International data transfers

Start with the good news: our main server is in Brazil. Your account, your routine, the catalogue and — in My Day GYM — the PAR-Q answers, date of birth, gender and mobile number are kept on a server located in São Paulo, Brazil. For that data there is no international transfer. The verification SMS is also sent by a Brazilian company.

Even so, some of our suppliers are outside Brazil, as the table in section 6 shows. That means data of yours is transferred internationally in the following situations, and only in them:

WhenWhat leaves BrazilWhere to
You use an artificial intelligence featureThe text or image you submittedUSA, European Union, Singapore and China
You sign in with Apple or GoogleThe provider's credentialUSA and global
You receive the access code by e-mail, when the configured channel is the external serviceYour e-mail addressUSA
Any request to our serverIP and content in transit, through the network edgeUSA and global
The daily backup is sent off the machineThe whole database, already encrypted before leaving — the recipient cannot read itUSA and global
Usage telemetry is sentUsage events and the installation identifierUSA and global

We draw attention specifically to the artificial intelligence providers, because that is where the free text of your food routine and the label photo you capture go. Under the LGPD there is no list of prohibited countries: the United States, the European Union, Singapore and China are subject to the same regime, because none of them has, today, an adequacy decision from the ANPD (Brazil's data protection authority).

We ground these transfers, under art. 33 of the LGPD, on at least one of these instruments, for each processor:

You can use the apps without triggering any artificial intelligence feature. In that case, your content is not sent to those providers. And, as said above, the PAR-Q and the data read from Apple Health or Health Connect are never sent to them, under any circumstances.


8. How long we keep it

DataPeriod
Account and routineFor as long as your account exists
Account and routine after the subscription endsKept in use for 5 (five) years, so you can come back and find your history where you left it. After that, erased. It is operational retention: the account stays alive and recoverable by you. Do not confuse it with the period in this section's last paragraph, which has the same duration and the opposite nature
Account and routine after a deletion requestErased within 30 days, save what the law obliges us to keep
Login sessions30 days of validity; once expired, they are erased
Access code by e-mail or SMS, and the requester's IP10 minutes of validity; erased right after
Unaccepted personal trainer invitation14 days; after that, it expires
PAR-Q answersNot erased or overwritten while the account exists. Validity for training is 12 months, but the earlier record remains, because it is what allows reconstructing on what information a training clearance was given
Consent and acceptance recordsWhile the account exists, and for the period in the next item. It is the proof that consent was given — erasing it would harm you, not us
Access logs (IP, time)6 months, under art. 15 of the Marco Civil da Internet
Tax and transaction dataFor the period in the applicable tax legislation
Product record in the shared catalogueRemains, even after your account is deleted — it is information about a market product, not about you, and the link to your identifier is removed
Progress photos, measurements and avatarStay on your device and are erased when you erase them or uninstall the app. If they are in your Apple or Google account backup, removal follows their rules

The backups, said honestly. We make a daily backup of our database. Data erased from the live database survives in those copies for up to 7 days on the machine itself and for up to 30 days in the daily copies sent off it; we also keep one monthly copy for 12 months. All of them leave the machine encrypted. When a deletion is executed, it is reapplied over any copy that is ever restored. No system that makes backups can promise instant erasure across all copies, and we prefer stating the real period to hiding that it exists.

What "save what the law obliges us to keep" means in practice. On completing your account's deletion, we definitively and irreversibly erase your access data, your profile, your routine and your media from our everyday operational system. On the basis of article 16, II, of the LGPD (Law No. 13,709/2018) and article 27 of the Código de Defesa do Consumidor (Law No. 8,078/1990), we keep, for the limitation period of 5 (five) years from the date of the deletion request, a strictly necessary copy of your basic registration, the record of consent and acceptance of the legal documents, the PAR-Q answers, the workout prescription and execution history, and the body measurement progress records — always to the smallest extent needed to reconstruct the safety decisions and prescriptions that may be put in question. That copy is kept in an isolated, encrypted repository (cold storage), with no operational access by our team or by third parties for commercial, marketing or product-intelligence purposes — it is consulted exclusively where needed for defence in judicial, administrative or arbitral proceedings, or to comply with a court order. It is not operational retention: you do not recover the account or the usage history from that data. The period coincides with the table's second row above, and the coincidence is one of duration only — there, your account stays alive and you return to it; here, there is no account any more, there is a sealed archive that exists for defence. Once the 5-year period has run, the records are definitively destroyed.


9. Security

Measures we take:

No system is impenetrable. If a security incident occurs that may cause you relevant risk or harm, we will notify you and the ANPD, within the period and in the manner required by art. 48 of the LGPD.


10. Minors

The apps are intended for people aged 18 or over and are not directed at children or adolescents. We do not knowingly collect data from under-18s.

In My Day GYM, the date of birth is mandatory at sign-up and sign-up by anyone under 18 is refused by the system, not merely discouraged.

If we learn that an account belongs to a minor, it will be closed and the associated data erased. If you are the legal guardian of a minor who created an account, write to cdo@mydaysuite.com and we will handle the request as a priority.


11. Automated decisions

The apps use artificial intelligence to suggest: proposing a routine, estimating a meal's macros, pointing out the impact of moving a workout to another day, suggesting a product. Those outputs are proposals: you accept, edit or discard. Nothing is applied without your confirmation.

There is one automated assessment that produces a concrete effect, and it deserves to be stated clearly: in My Day GYM, the PAR-Q answers determine whether the app considers you cleared to start training and whether you can activate the link with a personal trainer. It is a fixed rule, not a statistical model: if any of the seven answers is "yes", the app presents a follow-up and directs you to seek a medical assessment before training. The purpose is your physical safety, and the criterion is fully described in 4.3.

None of those outputs is an automated decision producing legal effects on you in the sense of art. 20 of the LGPD. Even so, and regardless of that, you have the right to request a review of any automated result and to ask for information about the criteria used, by writing to cdo@mydaysuite.com.

And what the Terms of Use repeat in large letters holds: the apps are not a medical device and do not replace a health professional.


12. My Day GYM: personal trainers and trainees

In My Day GYM, another person only sees your data when you accept a link invitation from a personal trainer and authorise the corresponding sharing.

12.1 Who answers for what

Before being able to invite trainees, the trainer provides their professional registration (CREF) and the application goes through human review on our side. That review checks the qualification as declared by them: it is not automatic validation with the professional council, and it is not an endorsement of the technical quality of their work.

12.2 What the personal trainer sees of the trainee

The link is born of an invitation from the trainer and only exists with the trainee's explicit acceptance. At the moment of acceptance, the trainee reads the text of what they are authorising — text that is frozen and stored with the consent record — and makes an explicit choice, with no pre-ticked option: to share or not share their body measurements with that trainer.

When the link is activated, the trainer starts to see:

The trainer does not see the trainee's PAR-Q answers — they see only whether the trainee is cleared to train. The trainee's body progress photos are not shared with the trainer: they do not leave the trainee's device, and there is no path for them to reach the trainer through the platform.

How to change the choice. Today, to change the sharing of measurements after acceptance, or to revoke it, write to cdo@mydaysuite.com — we respond within the period in section 13. The direct in-app control is under construction; until it exists, this is the channel, and it works.

12.3 When the relationship ends

How the link ends today. You have one active link at a time: when the trainee accepts another professional's invitation, the previous link is closed automatically, at that same instant. Outside that case, trainee or trainer end the link by writing to cdo@mydaysuite.com — we respond within the period in section 13, and neither of the two needs to justify the request. The in-app closure button is under construction; until it exists, this is the channel, and it works for both sides.

What happens to the data the instant the link closes:

12.4 If you are the personal trainer

By linking trainees, you declare that you have your own legal basis to process their data, that you respect the applicable professional secrecy, and that you will not use the platform to collect data beyond what your activity needs. We supply the tool; the professional relationship is yours.


13. Your rights

The LGPD (art. 18) guarantees you:

RightWhat it means
Confirmation and accessKnowing whether we process data of yours and obtaining a copy
CorrectionCorrecting incomplete, inaccurate or outdated data
Anonymisation, blocking or erasureOf data that is unnecessary, excessive or processed in breach of the law
PortabilityReceiving your data in a structured, machine-readable format
ErasureErasing data processed on the basis of your consent
Information about sharingKnowing who we share with — section 6 and Annex B already answer, and you can ask for detail
Information about refusalKnowing what happens if you do not consent
Withdrawal of consentWithdrawing, at any time and free of charge, a consent you gave
ObjectionObjecting to processing based on legitimate interest — including usage telemetry (4.8)
Review of automated decisionsSee section 11

How to exercise them: write to cdo@mydaysuite.com. We may ask for additional information to confirm it is you — not to make it harder, but because handing your data to someone else would be worse.

Response times we commit to, counted from confirmation of your identity:

RequestTime
Confirmation that we process data of yours, in simplified formImmediate, under art. 19, § 3 of the LGPD
Full copy of your data, or portability in machine-readable format15 days, under art. 19, II of the LGPD
Correction, objection, withdrawal of consent15 days
Deletion of the account and data30 days, save what the law obliges us to keep — see section 8

On portability and export. Automated export, from inside the app, is under construction. Until it exists, portability is fulfilled manually, through the channel above, within the 15-day period — the right does not depend on the feature, and the channel works.

Account deletion. You can request the deletion of your account and of everything in our keeping by writing to cdo@mydaysuite.com or through the page https://mydaysuite.com/account-deletion, which describes the request step by step. The request requires no justification. We execute it within 30 days, notify you when it completes, and the deletion is final — what remains retained is only what section 8 describes. In-app deletion is under construction; until it exists, the channel above is the official one and the only one you need.

Complaints: you can complain to the ANPD (Autoridade Nacional de Proteção de Dados)https://www.gov.br/anpd.


14. How we announce changes

This policy can change when the product changes, when we switch suppliers or when the law requires.


15. Contact

SubjectWhere to write
Privacy, data subject rights, DPOcdo@mydaysuite.com
Support and general questionscs@mydaysuite.com
Postal correspondenceAv. Nove de Julho, CEP 01406-200, São Paulo, SP, Brasil

Annex B — Our processors in detail

This is the complete list of the third parties that receive personal data from us, with what each receives and where it is. It is part of this policy: a processor not listed here does not receive data of yours.

ProcessorRoleData categories it receivesLocation
HostingerHosting of the account, routine, catalogue and My Day GYM serverAccount, identification, routine, measurements, PAR-Q, consents, catalogue, technical logsBrazil (São Paulo data centre)
Comtele Soluções em TecnologiaSending the mobile verification SMSMobile number and the code's textBrazil
Resend, Inc.Sending the access code e-mail, when it is the configured channelE-mail address and the code's textUSA
Cloudflare, Inc.Network edge and DNS; intermediary layer for the AI and SMS calls; internal panel access control; storage of encrypted backupsTraffic, IP, content in transit; backups encrypted at originUSA and global
Apple Inc.Sign in with Apple, distribution, billing, HealthKitLogin credential, billing data (directly with you)USA and global
Google LLCGoogle sign-in, distribution and billing on Google Play, Health ConnectLogin credential, billing data (directly with you)USA and global
Google LLC (Google Analytics for Firebase)Usage telemetryUsage events and installation identifierUSA and global
Google LLC (Gemini)Language and vision modelText and images submitted to an AI featureUSA and global
OpenAI, L.L.C.Generation of the catalogue illustrationThe product's reference photo and the request's textUSA
DeepSeekLanguage model for routine and food structuringText submitted to an AI featureChina
Alibaba Cloud (Qwen, Wan)Label OCR and image generationThe label or plate photo, and the request's textSingapore — group headquartered in China
Jina AI GmbHSearch and reading of public pages about the productSearch term derived from the product — no data of yoursGermany / USA
Open Beauty Facts / Open Food FactsPublic, open product and food databasesProduct barcode or name — no data of yoursFrance / European Union

None of the processors above receives: your body progress photos, your avatar, the data read from Apple Health or Health Connect, or your PAR-Q answers.

The state of each artificial intelligence provider's contractual commitment not to train models on submitted content can be checked at any time via cdo@mydaysuite.com. Subscribers who want to be notified of new processors before they enter operation can request that at the same address.


This document is published in Portuguese and in English. Both versions are originals; in case of divergence between them, for users in Brazil the Portuguese version prevails.