Privacy Policy — My Day App
Effective: 2026-08-30
Version: 5
Last updated: 2026-08-30
Applies to: the apps of the My Day App brand — My Day Works, My Day Fitness, My Day Beauty and My Day GYM (together, "the apps")
1. In one page
If you read only one section, read this one:
- Your personal photos never go to our servers. Body progress photos, before-and-after photos, avatars and the images the app generates for you stay on your device. If your Apple or Google account backup is on, they go into that backup — which is yours, not ours.
- Our server is in Brazil. Your account, your routine, the catalogue and — in My Day GYM — the physical readiness questionnaire are kept on a server located in Brazilian territory. See section 7.
- What stays on our server is the minimum for three things: keeping your account and subscription working, keeping your routine working and, in My Day GYM, recording what training safety requires. The routine needs to be stored to be shown again, and processed to be improved.
- Product photos are not kept. When you photograph a package, the image is read by artificial intelligence only to identify which product it is. If the product does not yet exist in our catalogue, the system generates its own illustration, in the catalogue's visual style. What gets stored is that illustration of a product that exists publicly on the market — not your photo.
- Your health data from Apple Health / Health Connect stays on the device. We read what you authorise to build your statistics. We do not send those numbers to our server.
- There is one exception, and it matters: in My Day GYM, the seven answers of the physical activity readiness questionnaire (PAR-Q) are recorded on our server, because that is what makes it possible to say with confidence whether you can train. It is health data, it is treated as such, and section 4.3 explains exactly what happens to it.
- There is no advertising tracking. We do not use an advertising identifier, we do not build an ad profile of you, we do not share data with data brokers and we sell no data at all. When there is advertising in the apps, it will be chosen by the app, not by you: someone opening My Day Beauty sees a skincare ad because the app is about skin — not because we watched your behaviour.
- You are in charge of your data. You can access, correct, export and erase it. The Your rights section says how, and through which channel.
2. Who is responsible for your data
My Day App is the brand under which we publish the apps. It is not a company. The company behind it — and the controller of the personal data processed in the apps — is:
| Legal name | Two Moons Media Ltda |
| Trading name | Brave Labs |
| CNPJ | 46.326.126/0001-51 |
| Address | Av. Nove de Julho, CEP 01406-200, São Paulo, SP, Brasil |
| Contact e-mail | contact@bravelabs.co |
| Data Protection Officer (DPO) | Guilherme Valente — cdo@mydaysuite.com |
In this document, "we" means Two Moons Media Ltda. The complete mapping is this, and there is nothing beyond it:
| Layer | Name |
|---|---|
| Responsible legal entity (controller) | Two Moons Media Ltda, CNPJ 46.326.126/0001-51 |
| Company trading name | Brave Labs |
| Brand of the apps | My Day App |
| Apps published under the brand | My Day Works, My Day Fitness, My Day Beauty, My Day GYM |
"Controller" is the term used by Brazil's General Data Protection Law (Law 13,709/2018, "LGPD") for whoever decides why and how personal data is processed.
One important exception: in My Day GYM, when you are a personal trainer's trainee, that professional also makes decisions about your data. The My Day GYM section explains exactly who answers for what.
3. Which apps this policy covers
This policy is common to all apps of the My Day App brand:
| App | What it does | Privacy particularity |
|---|---|---|
| My Day Works | Aggregator: brings the whole day's routine together | None beyond the common rules |
| My Day Fitness | Food and training | Processes food and exercise data; may read Apple Health / Health Connect |
| My Day Beauty | Skin and hair care | Product photography is frequent; may involve skin progress photos |
| My Day GYM | Self-directed training, personal trainers and trainees | Collects the PAR-Q questionnaire, a verified mobile number and date of birth. Data may be shared between people when the trainee accepts the link. See section 12 |
Where an app has processing of its own, that is marked in the text. Where there is no marking, the rule applies to all.
Apps and features not yet launched. This policy already describes the processing of all the brand's apps, including those not yet available in the stores, and of features still under construction. Where an app or a feature does not yet exist, the processing described here only begins when it is published — the advance description exists so that you know, before installing, what will happen.
4. What data we process, why, and on what legal basis
The LGPD requires every processing operation to have a legal basis — the legal ground that authorises it. Below, each category of data with its own.
4.1 Account and identification data
You sign in to your account in one of these ways: Sign in with Apple, Google sign-in or a single-use code sent to your e-mail. What we keep depends on which you choose.
| Data | Origin | What for | Legal basis (LGPD) |
|---|---|---|---|
User identifier at the login provider (Apple's or Google's sub) | Apple or Google, at login | Recognising you across sessions and devices | Art. 7, V — performance of contract |
| E-mail (it can be an anonymous Apple relay address, if you choose to hide yours) | You type it, or it comes from Apple/Google on first authorisation | Signing in, account-related contact and support | Art. 7, V — performance of contract |
| Single-use access code and the date it was sent | Generated by our server | Proving the mailbox is yours | Art. 7, V — performance of contract |
| First and last name | You type them, or they come from Apple/Google on first authorisation | Personalising the interface and identifying you to your personal trainer, in My Day GYM | Art. 7, V — performance of contract |
| Session token | Generated by our server | Keeping you signed in without asking for login every time | Art. 7, V — performance of contract |
| IP address of whoever requested the access code | Your connection | Limiting attempts and detecting abuse of code sending | Art. 7, IX — legitimate interest in security |
We keep only the hash of the session token and the hash of the access code, never the value itself: a copy of our database does not work as a credential to enter your account.
In My Day GYM, sign-up asks for more, because the product is about physical exercise and training safety depends on it:
| Data | What for | Legal basis (LGPD) |
|---|---|---|
| Date of birth | Confirming you are over 18 — below that, sign-up is refused — and adjusting training guidance to age | Art. 7, V — performance of contract; Art. 7, IX for age verification |
| Gender | Parameter for training and body composition references | Art. 11, I — consent (see 4.3) |
| Mobile number | Verifying the number is yours, by a code sent by SMS, and allowing your personal trainer to reach you | Art. 7, V — performance of contract |
| Professional registration (CREF), if you apply to act as a personal trainer | Reviewing your qualification before releasing the trainer role | Art. 7, V — performance of contract |
| Instagram or TikTok profile, if you provide it | Displaying it on your trainer profile | Art. 7, IX — legitimate interest, and it is optional |
We do not ask for CPF, ID, home address or payment data. Payment happens entirely inside the App Store or Google Play — see section 4.7.
4.2 Your routine and the content you create
This is the heart of the product: the meals, the workouts, the care products, the schedules, the notes, the "done" and "skipped" marks, the goals.
- What for: so the app can show your routine back to you, day after day, and improve it — when you ask for a reorganisation, an assessment or a new proposal, that content is what the artificial intelligence works on.
- Legal basis: Art. 7, V (performance of contract). For AI processing of content that reveals a health condition, see 4.3 — in that case the basis is consent.
- Where it lives: on your device, always. On our server, to the extent needed for the routine to survive a device change and for the AI features to work.
4.3 Health data — a sensitive category
Health data is sensitive personal data under the LGPD (art. 5, II), and processing it requires your specific and highlighted consent (art. 11, I). We ask for that consent on a dedicated screen, before the first use of each feature that depends on it — not inside a general acceptance and not as a pre-ticked box. Feature and consent screen arrive together: without the consent, the feature is not unlocked and the corresponding data is not processed. Refusing does not stop you using the rest of the app; it only stops the feature that depends on that data.
This category includes:
| Data | How it reaches us | Where it stays |
|---|---|---|
| PAR-Q questionnaire — seven yes/no answers about heart problems, chest pain during activity and at rest, dizziness or fainting, bone or joint problems, use of blood pressure or heart medication (without asking which), and any other impediment | You answer in My Day GYM, before training and before accepting the link with a personal trainer | On our server, on a server in Brazil. See the detail below |
| Water, caffeine, steps, active and basal energy, body weight, body fat percentage, lean mass, BMI, sleep analysis and workouts | From Apple Health (HealthKit) or Health Connect on Android, only if you authorise each type | Stays on the device. We do not send it to our server |
| Waist circumference you log | You type it in the app | On the device; we write it to Apple Health only if you ask |
| Body measurements, weight and composition you log manually | You type them | On the device and, as part of the routine, on our server |
| Logged food (meals, foods, quantities, macros) | You type, photograph or dictate | On the device and, as part of the routine, on our server |
| Body progress and before/after photos | You photograph | Only on your device. See 4.4 |
| Free-text description of a skin or hair condition, dietary restriction or health goal you write | You type it | On the device and, when you use an AI feature, transiting through the providers in section 6 |
| Date of birth and gender, when used as training or body composition parameters | You type them at My Day GYM sign-up | On our server |
The PAR-Q, in detail — because it is the most sensitive data that leaves your device.
- It is seven yes/no questions, in the version we identify internally as
parq-1. None of them asks for a diagnosis, a report, a doctor's name or a medication's name — the question about blood pressure or heart medication is answered only with yes or no, without identifying which medication. - Answers are recorded on our server by addition, never by replacement: a submitted answer is not edited or erased by a later one. This exists so that the decision to unlock or not unlock a workout can be reconstructed later — including against us.
- Validity is 12 months. After that, the app asks for the questionnaire again.
- If any answer is "yes", the app does not block you silently: it presents a follow-up and directs you to seek a medical assessment before training. See section 11.
- Who can see it. Your personal trainer does not see the answers; they see only whether you are cleared to train. Our team can only reveal the answers through a recorded action, which requires a written reason and is logged in an audit trail — it is not a routine lookup.
- Legal basis for everything in this section: Art. 11, I of the LGPD — the holder's specific and highlighted consent, for specific purposes. You can withdraw that consent at any time (see Your rights); withdrawal does not affect what was lawfully processed before it, and it switches off the features that depend on that data.
- A limit we commit to: data read from Apple Health or Health Connect is not transmitted to our server, does not feed advertising, and is not sold or shared for third parties' commercial purposes. It serves only to build your statistics inside the app. The same limit applies to the PAR-Q: it never feeds advertising, is never sold and is never sent to an artificial intelligence provider.
- System-level revocation: you can cut the app's access to Apple Health or Health Connect at any time through the operating system itself (on iOS, Settings → Privacy & Security → Health), without going through us.
4.4 Photographs of you
There are three kinds of photo in the product, and they receive different treatment. The distinction matters:
(a) Body progress photos, before-and-after photos, and the profile avatar They are stored on your device, in the app's private area. We do not upload those photos to our server. If your Apple (iCloud) or Google account backup is on on the device, they go into that backup — which belongs to you, is governed by Apple's or Google's terms, and which we cannot access.
(b) Product photos — the case worth explaining When you photograph a product's packaging (a shampoo bottle, a jar of cream, a food label), the image is sent to our artificial intelligence providers for one purpose only: finding out which product it is. What the AI extracts is text — name, brand, size, composition, barcode.
Then, if that product does not yet exist in our catalogue, the system generates a new illustration, from scratch, in the catalogue's visual style (white background, e-commerce-style shot). It is that generated illustration that gets stored — never your photo.
The difference, put plainly: we do not keep your photo. We recognise the product and start using our own illustration of it. And the illustration depicts a product that exists publicly on the market — not you, not your home, not your bathroom.
(c) Meal photos Same logic as above: the photo of the plate goes to the AI to be interpreted into foods and quantities, and what gets recorded is the resulting text (the food, the quantity, the macros), not the photograph.
In (b) and (c), the image transits through the providers listed in section 6 during processing. We do not archive it.
- Legal basis: Art. 7, V (performance of contract) for product photos; Art. 11, I (consent) when the photo can reveal a health condition — which includes body progress photos and, depending on the case, meal photos.
4.5 The shared product catalogue
The catalogue of personal care products and foods is common to all users. When you add a product that does not yet exist, it becomes part of that catalogue and can be seen by other users.
What goes into the catalogue is information about the product: name, brand, size, barcode, composition, purpose, pH, directions for use, contraindications, warnings and the generated illustration. Nothing about you goes in — not your name, not your e-mail, not your routine, not when or how you use that product.
Internally, we keep alongside the product record the internal identifier of whoever added it, for curation and duplicate correction. That identifier is an opaque string: it is not your name, it is not your e-mail, and no screen in the app displays it to other users. We treat that identifier as internal curation data and work to keep it from circulating beyond that purpose.
- Legal basis: Art. 7, IX — legitimate interest in maintaining a quality shared catalogue, which is what lets the next user avoid redoing the same entry. The published data is about a market product, not about a person.
4.6 Technical and security logs
To keep the service running and detect abuse, our servers and our network edge automatically record data such as IP address, request time, route accessed and response code. We also record the IP address associated with each request for an access code by e-mail or SMS, to limit attempts.
- Legal basis: Art. 7, IX (legitimate interest in information security) and Art. 7, II (compliance with a legal obligation — the Marco Civil da Internet, Law 12,965/2014, art. 15, which requires application access logs to be kept for six months).
4.7 Subscription and billing
We do not process your payment and we do not receive your card details. Billing for any paid feature is done entirely by the App Store (Apple) or Google Play (Google), under their terms and privacy policy.
What reaches us is only what is needed to know whether you are entitled to the product: a transaction identifier or validated purchase receipt, the subscribed product, the status (active, in grace period, expired) and the renewal date. Name, card number, billing address and CPF do not pass through us.
- Legal basis: Art. 7, V — performance of contract.
4.8 Usage telemetry
We collect signals about how the app is used — which screens are opened, which features are triggered, where failures occur, how long an operation takes. It serves one purpose only: improving the product.
We use Google Analytics for Firebase for this, in My Day Works and My Day Beauty. It assigns the app installed on your device its own randomly generated identifier (the App Instance ID), which allows counting sessions and understanding flows. That identifier is not your name, is not your e-mail and is not the device's advertising identifier — and it resets if you uninstall the app or erase its data.
Let us be precise about what that identifier is: it is pseudonymised data, not anonymous data. It does not say who you are, but, being a persistent identifier, it remains personal data under the LGPD (art. 12) — and that is how we treat it, with this policy's protections.
What never goes into telemetry: the text you write, the names of your items, your photos, your health numbers, your measurements, your PAR-Q answers. Telemetry carries fixed event names and closed categories, never content you created.
Telemetry does not feed advertising. We do not use it to choose ads, to build a profile of you or for campaign attribution. See 4.9.
- Legal basis: Art. 7, IX — legitimate interest in improving the product. In jurisdictions that require prior consent for a persistent identifier, we will ask for it before enabling collection.
- How to object: because this processing rests on legitimate interest, you can object to it at any time (LGPD, art. 18, § 2). Write to cdo@mydaysuite.com and we will switch collection off for your installation, at no cost and with no loss of any functionality. Where the app offers the direct control, it lives in Settings → Privacy.
4.9 Advertising
The apps may show advertising. When that happens, the following will apply — a product decision, not a vague promise:
- Targeting comes from the app, not from you. Each app is thematic by nature: someone in My Day Beauty is interested in skincare; someone in My Day Fitness is interested in training and food. That alone is enough to choose the ad. This is what is called contextual advertising.
- We do not use an advertising identifier. We do not request the IDFA on iOS or the Advertising ID on Android, and we do not associate them with anything.
- We do not build an advertising profile of you. We do not derive interests from your behaviour in the app, your history, your routine or your health data to choose an ad.
- Usage telemetry is not used for advertising. The identifier described in 4.8 serves to understand the product, not to target you.
- We do not share data with data brokers and we do not sell personal data.
- Health data never feeds advertising. No exception — and that includes the PAR-Q.
- We do not track you across third-party apps or sites — what Apple calls tracking and gates behind App Tracking Transparency. Since we do not do it, we do not ask for that authorisation.
If we ever decide to change any of these rules, that will be a material change to this policy, announced as set out in section 14 — and, where the law requires consent, it will be asked for first.
- Legal basis: Art. 7, IX — legitimate interest in sustaining the service with advertising that does not depend on profiling.
4.10 Artificial intelligence features
Several features use third-party artificial intelligence models: identifying a product by photo or barcode, interpreting a written or photographed meal, drafting a routine proposal from free text, assessing the impact of a change to the training week, generating a new product's illustration.
For that, the relevant content — the text you wrote, the photo of the product or plate, your routine's items — is sent to the corresponding provider through our own intermediary layer, an edge service that sits between the app and the provider. That layer exists for a concrete reason: the providers' access keys never live inside the app installed on your device. The providers are listed by name in section 6 and in Annex B, and most of them are located outside Brazil, which constitutes an international transfer (see section 7).
Four limits we commit to:
- We do not archive the images sent to the AI. They transit for processing, and what persists is the structured result (the extracted text, the generated illustration).
- Health data from Apple Health, from Health Connect and the PAR-Q are never sent to an artificial intelligence provider.
- We do not use your content to train models of our own, and we seek from each provider a contractual commitment not to train models on the submitted content. The state of that commitment varies by provider and can be checked at any time via cdo@mydaysuite.com.
- AI gets things wrong. What it returns is a suggestion, not a prescription. See the health disclaimer in the Terms of Use and section 11 of this policy.
5. Where each piece of data lives
This is probably the most useful table in this document.
| Data | On the device | In your Apple/Google account backup | On our server | With a third party |
|---|---|---|---|---|
| Login identifier, e-mail, name | ✅ | — | ✅ | Apple / Google (origin) |
| Session token | ✅ (Keychain) | — | ✅ (hash only) | — |
| Access code sent by e-mail | — | — | ✅ (hash only) | E-mail delivery service |
| Access code sent by SMS | — | — | ✅ (hash only) | Comtele (delivery) |
| Mobile number | ✅ | — | ✅ | Comtele (only to send the SMS) |
| Date of birth and gender (My Day GYM) | ✅ | — | ✅ | ❌ |
| PAR-Q answers (My Day GYM) | ✅ | — | ✅ | ❌ |
| Consent and acceptance records | — | — | ✅ | ❌ |
| Routine, meals, workouts, schedules | ✅ | ✅ | ✅ | AI providers, when you use an AI feature |
| Apple Health / Health Connect data | ✅ | per Apple/Google | ❌ | ❌ |
| Typed measurements and weight | ✅ | ✅ | ✅ | ❌ |
| Body progress and before/after photos | ✅ | ✅ | ❌ | ❌ |
| Profile avatar | ✅ | ✅ | ❌ | ❌ |
| Product photo you take | transient | — | ❌ | Transits through the AI providers |
| Meal photo you take | transient | — | ❌ | Transits through the AI providers |
| Generated product illustration | ✅ | ✅ | ✅ | Generated by an AI provider |
| Product record in the catalogue (name, brand, composition) | ✅ | ✅ | ✅ (shared) | ❌ |
| Subscription status | ✅ | — | ✅ | Apple / Google (origin) |
| Usage telemetry and installation identifier | — | — | — | Google (Firebase) |
| Access logs (IP, time) | — | — | ✅ | Cloudflare (network edge) |
| Encrypted backup of our database | — | — | ✅ | Cloudflare R2 (encrypted before leaving) |
Legend: ✅ stays; ❌ does not stay; "transient" = exists only during processing.
6. Who we share with
We do not sell personal data. We do not share personal data with data brokers. We do not share data with advertisers for targeting.
We share with processors (in the LGPD's language, "operadores") — suppliers that process data on our behalf, under contract and under our instruction — to the extent needed for the service to work:
| Processor / Third party | Role | What it receives | Where it is |
|---|---|---|---|
| Hostinger | Hosting of the account, routine, catalogue and My Day GYM server | All the data in section 5 marked "on our server" | Brazil (São Paulo data centre) |
| Comtele Soluções em Tecnologia | Sending the SMS with your mobile verification code | Your mobile number and the code's text. It receives no name, e-mail or any other data of yours | Brazil |
| Resend, Inc. | Sending the e-mail with the access code, when that is the configured channel | Your e-mail address and the code's text. When delivery is done by our own e-mail server, hosted on the infrastructure above, no third party receives your address | USA |
| Apple | Authentication (Sign in with Apple), distribution, billing, HealthKit | Login credential; billing data (directly with you) | USA and global |
| Authentication (Google sign-in), distribution and billing on Google Play, Health Connect on Android | Login credential; billing data (directly with you) | USA and global | |
| Cloudflare, Inc. | Network edge, the intermediary layer that makes the AI and SMS calls, internal panel access control, and storage of backups | Application traffic, IP, content in transit; backups already encrypted before leaving our server | USA and global |
| Google (Gemini) | Language and vision model | Text and images you submit to an AI feature | USA and global |
| OpenAI, L.L.C. | Generation of the catalogue illustration | The product's reference photo and the request's text | USA |
| DeepSeek | Language model (routine and food structuring) | Text you submit to an AI feature | China |
| Alibaba Cloud (Qwen and Wan) | Label reading by computer vision (OCR) and image generation | The label or plate photo you take, and the request's text | Singapore (group headquartered in China) |
| Jina AI GmbH | Search and reading of public pages to ground the product record | The search term derived from the product. Receives no data of yours | Germany / USA |
| Open Beauty Facts / Open Food Facts | Public, open product and food databases | The barcode or name of the product looked up. Receives no data of yours | France / European Union |
| Google LLC (Google Analytics for Firebase) | App usage telemetry | Usage events and the installation identifier described in 4.8 | USA and global |
We also share:
- With your personal trainer, in My Day GYM, under section 12.
- With authorities, where there is a court order, a demand from a competent authority or a legal obligation. In that case, we notify you whenever the law allows.
- In an eventual corporate reorganisation, merger or acquisition, data may be transferred to the successor, which remains bound by this policy. We will notify you before that produces effects on you.
The list above is kept up to date, and Annex B carries each processor's detail. Processor changes are announced as set out in section 14.
7. International data transfers
Start with the good news: our main server is in Brazil. Your account, your routine, the catalogue and — in My Day GYM — the PAR-Q answers, date of birth, gender and mobile number are kept on a server located in São Paulo, Brazil. For that data there is no international transfer. The verification SMS is also sent by a Brazilian company.
Even so, some of our suppliers are outside Brazil, as the table in section 6 shows. That means data of yours is transferred internationally in the following situations, and only in them:
| When | What leaves Brazil | Where to |
|---|---|---|
| You use an artificial intelligence feature | The text or image you submitted | USA, European Union, Singapore and China |
| You sign in with Apple or Google | The provider's credential | USA and global |
| You receive the access code by e-mail, when the configured channel is the external service | Your e-mail address | USA |
| Any request to our server | IP and content in transit, through the network edge | USA and global |
| The daily backup is sent off the machine | The whole database, already encrypted before leaving — the recipient cannot read it | USA and global |
| Usage telemetry is sent | Usage events and the installation identifier | USA and global |
We draw attention specifically to the artificial intelligence providers, because that is where the free text of your food routine and the label photo you capture go. Under the LGPD there is no list of prohibited countries: the United States, the European Union, Singapore and China are subject to the same regime, because none of them has, today, an adequacy decision from the ANPD (Brazil's data protection authority).
We ground these transfers, under art. 33 of the LGPD, on at least one of these instruments, for each processor:
- contractual clauses carrying the safeguards required by the ANPD in Resolution CD/ANPD No. 19/2024, where executed with the processor; and
- your specific and highlighted consent, informed of the transfer — it is always collected when the data is sensitive, and it is the basis that sustains the transfer where no contractual clause is in force with that processor. That is why the authorisation for the features involving that sending is requested separately and mentions the transfer.
You can use the apps without triggering any artificial intelligence feature. In that case, your content is not sent to those providers. And, as said above, the PAR-Q and the data read from Apple Health or Health Connect are never sent to them, under any circumstances.
8. How long we keep it
| Data | Period |
|---|---|
| Account and routine | For as long as your account exists |
| Account and routine after the subscription ends | Kept in use for 5 (five) years, so you can come back and find your history where you left it. After that, erased. It is operational retention: the account stays alive and recoverable by you. Do not confuse it with the period in this section's last paragraph, which has the same duration and the opposite nature |
| Account and routine after a deletion request | Erased within 30 days, save what the law obliges us to keep |
| Login sessions | 30 days of validity; once expired, they are erased |
| Access code by e-mail or SMS, and the requester's IP | 10 minutes of validity; erased right after |
| Unaccepted personal trainer invitation | 14 days; after that, it expires |
| PAR-Q answers | Not erased or overwritten while the account exists. Validity for training is 12 months, but the earlier record remains, because it is what allows reconstructing on what information a training clearance was given |
| Consent and acceptance records | While the account exists, and for the period in the next item. It is the proof that consent was given — erasing it would harm you, not us |
| Access logs (IP, time) | 6 months, under art. 15 of the Marco Civil da Internet |
| Tax and transaction data | For the period in the applicable tax legislation |
| Product record in the shared catalogue | Remains, even after your account is deleted — it is information about a market product, not about you, and the link to your identifier is removed |
| Progress photos, measurements and avatar | Stay on your device and are erased when you erase them or uninstall the app. If they are in your Apple or Google account backup, removal follows their rules |
The backups, said honestly. We make a daily backup of our database. Data erased from the live database survives in those copies for up to 7 days on the machine itself and for up to 30 days in the daily copies sent off it; we also keep one monthly copy for 12 months. All of them leave the machine encrypted. When a deletion is executed, it is reapplied over any copy that is ever restored. No system that makes backups can promise instant erasure across all copies, and we prefer stating the real period to hiding that it exists.
What "save what the law obliges us to keep" means in practice. On completing your account's deletion, we definitively and irreversibly erase your access data, your profile, your routine and your media from our everyday operational system. On the basis of article 16, II, of the LGPD (Law No. 13,709/2018) and article 27 of the Código de Defesa do Consumidor (Law No. 8,078/1990), we keep, for the limitation period of 5 (five) years from the date of the deletion request, a strictly necessary copy of your basic registration, the record of consent and acceptance of the legal documents, the PAR-Q answers, the workout prescription and execution history, and the body measurement progress records — always to the smallest extent needed to reconstruct the safety decisions and prescriptions that may be put in question. That copy is kept in an isolated, encrypted repository (cold storage), with no operational access by our team or by third parties for commercial, marketing or product-intelligence purposes — it is consulted exclusively where needed for defence in judicial, administrative or arbitral proceedings, or to comply with a court order. It is not operational retention: you do not recover the account or the usage history from that data. The period coincides with the table's second row above, and the coincidence is one of duration only — there, your account stays alive and you return to it; here, there is no account any more, there is a sealed archive that exists for defence. Once the 5-year period has run, the records are definitively destroyed.
9. Security
Measures we take:
- Everything in transit is encrypted (HTTPS/TLS) between the app, our servers and our suppliers.
- The session token lives in the iOS Keychain (or the equivalent protected storage on Android), not in ordinary storage.
- On the server, we keep only the hash of the session token and the hash of the access codes — never the value. A copy of the database does not allow entry into your account.
- Access codes have short validity, single use and an attempt cap, per address and per connection.
- Protection against credential replay in Sign in with Apple, through a single-use challenge.
- The server only accepts traffic coming from our network edge — the machine's address does not answer whoever tries to bypass it.
- Catalogue images are served through signed, expiring URLs, not permanent public addresses. The service refuses to start without the signing key configured.
- The internal curation panel requires corporate authentication and is accessible only to authorised personnel. Revealing a PAR-Q's answers requires a written reason and generates an audit record.
- Backups are encrypted before leaving the machine, with a key that does not live on the server.
- The most sensitive photos are simply not on our server — the best protection against a data leak is not holding the data.
No system is impenetrable. If a security incident occurs that may cause you relevant risk or harm, we will notify you and the ANPD, within the period and in the manner required by art. 48 of the LGPD.
10. Minors
The apps are intended for people aged 18 or over and are not directed at children or adolescents. We do not knowingly collect data from under-18s.
In My Day GYM, the date of birth is mandatory at sign-up and sign-up by anyone under 18 is refused by the system, not merely discouraged.
If we learn that an account belongs to a minor, it will be closed and the associated data erased. If you are the legal guardian of a minor who created an account, write to cdo@mydaysuite.com and we will handle the request as a priority.
11. Automated decisions
The apps use artificial intelligence to suggest: proposing a routine, estimating a meal's macros, pointing out the impact of moving a workout to another day, suggesting a product. Those outputs are proposals: you accept, edit or discard. Nothing is applied without your confirmation.
There is one automated assessment that produces a concrete effect, and it deserves to be stated clearly: in My Day GYM, the PAR-Q answers determine whether the app considers you cleared to start training and whether you can activate the link with a personal trainer. It is a fixed rule, not a statistical model: if any of the seven answers is "yes", the app presents a follow-up and directs you to seek a medical assessment before training. The purpose is your physical safety, and the criterion is fully described in 4.3.
None of those outputs is an automated decision producing legal effects on you in the sense of art. 20 of the LGPD. Even so, and regardless of that, you have the right to request a review of any automated result and to ask for information about the criteria used, by writing to cdo@mydaysuite.com.
And what the Terms of Use repeat in large letters holds: the apps are not a medical device and do not replace a health professional.
12. My Day GYM: personal trainers and trainees
In My Day GYM, another person only sees your data when you accept a link invitation from a personal trainer and authorise the corresponding sharing.
12.1 Who answers for what
- Two Moons Media Ltda is the controller of the platform: of the account, authentication, infrastructure, security, the PAR-Q questionnaire and the technical link between trainer and trainee.
- The trainer is the controller of the data they collect and process in the exercise of their own professional activity — the assessment they make, the prescription they build, the notes they write about the trainee. They answer for those decisions to the trainee and before the law, including for their profession's duty of secrecy.
- In practice, each answers for what they decide. We do not interfere with the prescription's technical content; the trainer does not control the infrastructure.
Before being able to invite trainees, the trainer provides their professional registration (CREF) and the application goes through human review on our side. That review checks the qualification as declared by them: it is not automatic validation with the professional council, and it is not an endorsement of the technical quality of their work.
12.2 What the personal trainer sees of the trainee
The link is born of an invitation from the trainer and only exists with the trainee's explicit acceptance. At the moment of acceptance, the trainee reads the text of what they are authorising — text that is frozen and stored with the consent record — and makes an explicit choice, with no pre-ticked option: to share or not share their body measurements with that trainer.
When the link is activated, the trainer starts to see:
- the trainee's name and account contact;
- the training routine they themselves prescribe and its execution (what was done, what was skipped, loads, repetitions);
- if — and only if — the trainee authorised it at acceptance: the trainee's body measurements.
The trainer does not see the trainee's PAR-Q answers — they see only whether the trainee is cleared to train. The trainee's body progress photos are not shared with the trainer: they do not leave the trainee's device, and there is no path for them to reach the trainer through the platform.
How to change the choice. Today, to change the sharing of measurements after acceptance, or to revoke it, write to cdo@mydaysuite.com — we respond within the period in section 13. The direct in-app control is under construction; until it exists, this is the channel, and it works.
12.3 When the relationship ends
How the link ends today. You have one active link at a time: when the trainee accepts another professional's invitation, the previous link is closed automatically, at that same instant. Outside that case, trainee or trainer end the link by writing to cdo@mydaysuite.com — we respond within the period in section 13, and neither of the two needs to justify the request. The in-app closure button is under construction; until it exists, this is the channel, and it works for both sides.
What happens to the data the instant the link closes:
- The trainer's access to the trainee's data ceases. The trainer's permission derives from an open link; once closed, the app stops delivering to them the trainee's name, contact, workout execution and measurements. It is not a hidden screen — it is access denied.
- Nothing of the trainee's is erased, and that is deliberate. The routine, the history, the measurements and the photos stay in the trainee's account, exactly as they were. Ending a link is not erasing data; it is cutting off an access.
- The record that the link existed is kept, with the date it began, the date it ended and the reason. It is not erased along with the access, because it is what allows answering later who was technically responsible for a prescription on a given date — a question that matters to the trainee as much as to us.
- The trainer keeps, in their own account and under their own responsibility, the plans they prescribed and the records their professional legislation obliges them to keep. In that part they are the controller (12.1), and their profession's duty of secrecy continues after the relationship ends.
- If the trainee wants to erase what is under the trainer, the request is made directly to them. What is in our keeping, the trainee asks us, via Your rights. If the trainer does not respond, write to cdo@mydaysuite.com: we do not decide for the professional, but we pass the request on and tell the trainee what was done.
12.4 If you are the personal trainer
By linking trainees, you declare that you have your own legal basis to process their data, that you respect the applicable professional secrecy, and that you will not use the platform to collect data beyond what your activity needs. We supply the tool; the professional relationship is yours.
13. Your rights
The LGPD (art. 18) guarantees you:
| Right | What it means |
|---|---|
| Confirmation and access | Knowing whether we process data of yours and obtaining a copy |
| Correction | Correcting incomplete, inaccurate or outdated data |
| Anonymisation, blocking or erasure | Of data that is unnecessary, excessive or processed in breach of the law |
| Portability | Receiving your data in a structured, machine-readable format |
| Erasure | Erasing data processed on the basis of your consent |
| Information about sharing | Knowing who we share with — section 6 and Annex B already answer, and you can ask for detail |
| Information about refusal | Knowing what happens if you do not consent |
| Withdrawal of consent | Withdrawing, at any time and free of charge, a consent you gave |
| Objection | Objecting to processing based on legitimate interest — including usage telemetry (4.8) |
| Review of automated decisions | See section 11 |
How to exercise them: write to cdo@mydaysuite.com. We may ask for additional information to confirm it is you — not to make it harder, but because handing your data to someone else would be worse.
Response times we commit to, counted from confirmation of your identity:
| Request | Time |
|---|---|
| Confirmation that we process data of yours, in simplified form | Immediate, under art. 19, § 3 of the LGPD |
| Full copy of your data, or portability in machine-readable format | 15 days, under art. 19, II of the LGPD |
| Correction, objection, withdrawal of consent | 15 days |
| Deletion of the account and data | 30 days, save what the law obliges us to keep — see section 8 |
On portability and export. Automated export, from inside the app, is under construction. Until it exists, portability is fulfilled manually, through the channel above, within the 15-day period — the right does not depend on the feature, and the channel works.
Account deletion. You can request the deletion of your account and of everything in our keeping by writing to cdo@mydaysuite.com or through the page https://mydaysuite.com/account-deletion, which describes the request step by step. The request requires no justification. We execute it within 30 days, notify you when it completes, and the deletion is final — what remains retained is only what section 8 describes. In-app deletion is under construction; until it exists, the channel above is the official one and the only one you need.
Complaints: you can complain to the ANPD (Autoridade Nacional de Proteção de Dados) — https://www.gov.br/anpd.
14. How we announce changes
This policy can change when the product changes, when we switch suppliers or when the law requires.
- Material changes — a new data category, a new purpose, a new recipient, a change of legal basis — are announced by e-mail, to your account's address, at least 15 days in advance.
- Editorial changes take effect on publication.
- The effective date at the top is always that of the version in force. Previous versions are available on request at cdo@mydaysuite.com.
- When a change requires new consent — for sensitive data in particular — we will ask again. Continuing to use the app does not substitute consent for sensitive data.
15. Contact
| Subject | Where to write |
|---|---|
| Privacy, data subject rights, DPO | cdo@mydaysuite.com |
| Support and general questions | cs@mydaysuite.com |
| Postal correspondence | Av. Nove de Julho, CEP 01406-200, São Paulo, SP, Brasil |
Annex B — Our processors in detail
This is the complete list of the third parties that receive personal data from us, with what each receives and where it is. It is part of this policy: a processor not listed here does not receive data of yours.
| Processor | Role | Data categories it receives | Location |
|---|---|---|---|
| Hostinger | Hosting of the account, routine, catalogue and My Day GYM server | Account, identification, routine, measurements, PAR-Q, consents, catalogue, technical logs | Brazil (São Paulo data centre) |
| Comtele Soluções em Tecnologia | Sending the mobile verification SMS | Mobile number and the code's text | Brazil |
| Resend, Inc. | Sending the access code e-mail, when it is the configured channel | E-mail address and the code's text | USA |
| Cloudflare, Inc. | Network edge and DNS; intermediary layer for the AI and SMS calls; internal panel access control; storage of encrypted backups | Traffic, IP, content in transit; backups encrypted at origin | USA and global |
| Apple Inc. | Sign in with Apple, distribution, billing, HealthKit | Login credential, billing data (directly with you) | USA and global |
| Google LLC | Google sign-in, distribution and billing on Google Play, Health Connect | Login credential, billing data (directly with you) | USA and global |
| Google LLC (Google Analytics for Firebase) | Usage telemetry | Usage events and installation identifier | USA and global |
| Google LLC (Gemini) | Language and vision model | Text and images submitted to an AI feature | USA and global |
| OpenAI, L.L.C. | Generation of the catalogue illustration | The product's reference photo and the request's text | USA |
| DeepSeek | Language model for routine and food structuring | Text submitted to an AI feature | China |
| Alibaba Cloud (Qwen, Wan) | Label OCR and image generation | The label or plate photo, and the request's text | Singapore — group headquartered in China |
| Jina AI GmbH | Search and reading of public pages about the product | Search term derived from the product — no data of yours | Germany / USA |
| Open Beauty Facts / Open Food Facts | Public, open product and food databases | Product barcode or name — no data of yours | France / European Union |
None of the processors above receives: your body progress photos, your avatar, the data read from Apple Health or Health Connect, or your PAR-Q answers.
The state of each artificial intelligence provider's contractual commitment not to train models on submitted content can be checked at any time via cdo@mydaysuite.com. Subscribers who want to be notified of new processors before they enter operation can request that at the same address.
This document is published in Portuguese and in English. Both versions are originals; in case of divergence between them, for users in Brazil the Portuguese version prevails.