Privacy Policy

Last updated: August 21, 2026

This Privacy Policy explains how CorvoGym SaaS (“CorvoGym,” “we,” “us”) collects, uses, and discloses information when you use our gym management software. CorvoGym is operated by Kehal Louei Imad Eddin and Rais Haytem, based in Skikda, Algeria.

1. Who This Policy Covers

CorvoGym is a business-to-business (B2B) software-as-a-service application used by gym owners and their staff to manage their own gyms, including information about their gym’s members. This Policy covers both: (a) account and usage information about the gym owners and staff who directly use CorvoGym (“Customers”), and (b) information about gym members that Customers enter into CorvoGym on their own behalf, as described further in Section 8 below.

2. Information We Collect

We collect and process the following categories of information through the application:

Account data

  • Name and email address of registered users
  • Password credentials, stored using our authentication provider’s secure hashing mechanisms — CorvoGym does not store or have access to plaintext passwords
  • Authentication and session-related identifiers

Gym data

  • Gym name, currency, timezone, phone, address, email, website, and logo URL

Staff data

  • Role, invitation email, invitation status and expiration, and account relationship to the gym

Member data (entered by Customers)

  • Full name, email, phone, date of birth, gender, membership status, and join date
  • Subscription, invoice, and payment records related to gym membership
  • Attendance and booking history
  • Lead/CRM records, workout programs, nutrition plans, and any free-text notes staff add

Corvo AI data

  • Conversation messages sent to and received from Corvo AI
  • Records of tools the AI used to answer a request, which may include the underlying data those tools retrieved
  • Drafts of actions proposed by Corvo AI that a staff member has not yet confirmed or has rejected

3. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the CorvoGym application
  • Authenticate users and maintain account security
  • Process subscription billing and payments
  • Send transactional emails (password resets, staff invitations, membership and billing reminders)
  • Power Corvo AI features, when requested by an authorized user
  • Respond to support and privacy requests

4. Third-Party Services We Use

CorvoGym relies on the following third-party service providers to operate. We do not sell personal information to any third party.

  • Resend— used to deliver transactional emails, including password resets, staff invitations, membership expiry reminders, and overdue invoice notifications. These emails include the recipient’s name and email address and relevant message content.
  • Lemon Squeezy— used to process subscription checkout and billing. Payment is handled entirely through Lemon Squeezy’s own hosted checkout page. CorvoGym does not process or store card numbers, CVV codes, or any other raw payment credentials.
  • Groq — the AI provider currently used to power Corvo AI by default. Depending on what you ask Corvo AI, information retrieved to answer your request — which may include member information, financial figures, attendance records, lead information, workout/nutrition content, or free-text notes — may be sent to Groq as part of processing that request.
  • Anthropic— an alternative AI provider supported by CorvoGym’s architecture. Anthropic does not receive data during normal operation unless CorvoGym is specifically configured to use it instead of Groq.
  • Vercel — used to host and deploy the CorvoGym application.
  • Our PostgreSQL database infrastructure — used to store the data described in Section 2. We are not identifying a specific named database provider in this Policy.

Information submitted to or retrieved for Corvo AI may be processed by the third-party AI provider currently configured for the service. We do not claim that any AI provider retains zero data, and we do not claim that customer data is used to train AI models, unless and until we can specifically confirm this.

5. Corvo AI

Corvo AI is an assistive software feature. It does not replace qualified medical, nutritional, fitness, financial, or other professional advice. Information it generates — including workout programs, nutrition plans, and any other content — should be reviewed by a qualified human before being relied upon, and certain actions require explicit staff confirmation before taking effect within the application.

6. Data Retention

We retain information for as long as necessary to provide the service, and as may additionally be required for security, accounting and billing, legal obligations, or dispute resolution. Retention periods can vary depending on the type of data involved. We do not currently promise a specific deletion timeframe for all data categories; specifically:

  • Lemon Squeezy webhook processing records are automatically removed after approximately 90 days.
  • Corvo AI conversations, member records, and gym/account records are retained as part of the ongoing service and are not currently subject to an automatic deletion schedule. If you would like specific data removed, please contact us using the information in Section 10.

7. Your Privacy Rights

CorvoGym does not currently provide a fully self-service account-deletion or data-export tool within the application. If you would like to request access to, correction of, or deletion of your information, please contact us using the details in Section 10, and we will address your request. We do not guarantee a specific response time unless separately agreed.

8. Customer Responsibility for Member Data

CorvoGym is a B2B tool: gym owners and their staff (“Customers”) enter and manage information about their own gym members. Customers are responsible for having the necessary rights and permissions to collect and process that information, and for the accuracy and legality of the data they enter into CorvoGym. Customers should not upload information they are not authorized to process.

9. Security

We take reasonable technical measures to protect information within the application, including tenant-isolated data access, secure password handling through our authentication provider, and verified webhook processing for payment events. No system can guarantee absolute security.

10. Contact Us

For privacy questions or requests, contact us at immadkl69@gmail.com or raishaytem3@gmail.com.

CorvoGym SaaS — Skikda, Algeria.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above when we do.