Security and ownership

Bank-grade isolation, daily backups, and the exit door on the front page.

Every table is walled by row-level security and a test suite proves gym A cannot read gym B. Card details never touch our servers. Daily backups with seven-day point-in-time recovery. And you can export members, attendance, payments and plans as CSV from Settings, any time.

What it does

Your data is yours, in four parts.

01

Row-level isolation, proven

Every row in the database carries the gym it belongs to and the database itself refuses to serve it to anyone else. An automated suite runs those checks on every release.

02

Cards never touch us

Card and bank details go straight to Stripe from the member's phone. Gym OS only ever holds a token.

03

Backups and monitoring

Daily backups, seven-day point-in-time recovery, error tracking, alerting, rate limiting and security headers on every response. Boring in the best way.

04

Export any time

Members, attendance, payments and plans as CSV from Settings. Your Stripe account is yours. There is no lock-in and nothing to ask us for.

How it works

Three steps, and none of them are yours to remember.

  1. 1

    Every request is scoped

    Who you are decides which gym's rows you can see, at the database, not in the app.

  2. 2

    Every release is tested

    The isolation suite has to pass before code ships.

  3. 3

    Every night is backed up

    And any point in the last seven days can be restored.

See it

What happens, step by step.

What sits between your members' data and everyone else.

Layer 1Your login

Owner, manager, coach and member roles, each with only the screens they need.

Layer 2Row-level security

The database refuses to serve one gym's rows to another gym's user.

Layer 3Stripe holds the cards

Payment details never pass through Gym OS servers.

Layer 4Backups and alerts

Daily backups, seven-day recovery, errors and attacks watched around the clock.

What changes for you
Nobody else can see your members

Not another gym, not by accident, and the tests prove it.

A card breach cannot happen here

Because the cards are not here. They are with Stripe.

You can leave with everything

Your CSVs, your Stripe account, your payment history. The door is open on purpose.

Questions

Things gym owners ask about this.

Where is the data stored?

In a managed Postgres database with daily backups, with Stripe holding all payment details.

What happens to my data if I cancel?

You export it from Settings first, then we delete your gym's rows on request.

Get a beta spot

A gym app so good, your members will want to use it.

We are bringing gyms on a few at a time so each one gets set up properly. Leave your details and we will let you know when your spot is ready.