Legal
Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how PAMPA ITER SL ("Aura", "we", "us") collects, uses, shares and protects your personal data when you use the Aura mobile app and related services (the "Service"). It is provided under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
The data controller for the personal data described here is:
- Entity: PAMPA ITER SL
- Tax ID (CIF): B26690461
- Registered office: Calle Agustín de la Fuente 16, 13610 Campo de Criptana, Ciudad Real (Spain)
- Email: info@pampaiter.com
Full company identification is also in our Legal Notice. We have not appointed a Data Protection Officer as we are not legally required to; the email above handles all data-protection requests.
2. Data we collect
- Account & identity — your name, email address, profile photo and the account identifier provided when you sign in with Google or Apple.
- Fitness & training data — body weight and its evolution, training goals, the workouts you log (exercises, sets, reps, loads, times), personal records, performance metrics, session feedback such as perceived effort, any injuries or limitations you record, and any photos (e.g. a whiteboard/WOD) you choose to scan.
- Subscription data — plan tier, trial status and purchase events. Payments are processed by Apple or Google; we never receive or store your card details.
- AI inputs — when you generate or import a workout or plan, your goal, profile and the content you submit are sent to our AI provider to produce the result (see section 5).
- Technical & usage data — device and app information, app language, usage analytics, and crash/error diagnostics.
Health-related data. Depending on the context, some of the data above — body weight and its evolution, physical goals, performance, injuries or photos — may constitute data concerning health (a "special category" under Article 9 GDPR). Where a processing operation involves health data within the meaning of Article 9, we will first obtain your explicit consent, which you give in the app and can withdraw at any time (see sections 4 and 9). We process such data only to provide the Service.
We do not knowingly collect precise location or contacts.
3. How we use your data
- Provide the Service: authenticate you, store your training history, generate your personalized plans and workouts.
- Operate subscriptions and entitlements (Plus / Pro) and keep your access in sync with the app store.
- Secure and improve the Service, diagnose crashes, and prevent fraud and abuse.
- Respond to your requests and comply with legal obligations.
We do not sell your personal data and we do not use it for third-party advertising.
4. Legal bases (GDPR Art. 6 & 9)
- Performance of a contract (Art. 6(1)(b)) — to provide the app, store your data and run your subscription.
- Explicit consent (Art. 9(2)(a) and 6(1)(a)) — obtained in advance for any processing that involves health data, and for the AI processing of such data. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain and improve the Service and prevent abuse, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — to keep billing and tax records.
5. AI processing
Plan generation and workout import use a third-party large-language-model provider (Google's Gemini API). Only the inputs needed for the feature you use are sent to produce your plan or read an imported workout. According to Google, these inputs are not used to train its models; Google may temporarily retain a request only as needed to provide and secure the service, for a limited period, after which it is deleted. AI output is advisory only: we do not take decisions producing legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR).
6. Who we share data with
We share data only with providers that help us run Aura. They act as processors under Article 28 GDPR, or as independent controllers where the applicable rules and their own terms so determine (for example, Apple and Google for certain sign-in and store operations):
- Sign-in: Apple and Google (authentication).
- Subscriptions & payments: RevenueCat (subscription management) and the Apple App Store / Google Play (payment processing).
- AI: Google (Gemini API) — plan generation and workout import.
- Analytics & diagnostics: Google Firebase (analytics / crash reporting) and Sentry (error diagnostics).
- Hosting & database: Railway (app hosting) and Neon (PostgreSQL database).
We may also disclose data where required by law, or to protect our rights, our users or the public.
7. International transfers
Some of these providers process data outside the EEA, including in the United States. Google LLC adheres to the EU–US Data Privacy Framework where applicable; other transfers rely on the European Commission's Standard Contractual Clauses together with any additional safeguards required. You can request more detail at the contact above.
8. How long we keep it
- Account & training data — while your account is active. When you delete your account it is locked immediately and permanently erased after a 30-day grace period (logging back in within that window restores it).
- Billing / tax records — for the period required by Spanish commercial and tax law (up to 6 years), then deleted or anonymized.
- Crash / error diagnostics — approximately up to 90 days.
- Usage analytics — in aggregated/pseudonymized form, approximately up to 14 months.
- Backups — held on a rolling basis (approximately up to 90 days) and then overwritten.
The periods above are approximate and may vary slightly with each provider's defaults.
9. Your rights
You have the right to access, rectify, erase, restrict and port your data, to object to certain processing, to withdraw consent at any time (without affecting prior processing), and not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (we do not carry out such decisions — see section 5). You can exercise these by emailing info@pampaiter.com or by using the in-app account deletion. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local supervisory authority.
10. Cookies & similar technologies
Our website does not use non-essential cookies. Inside the app, our analytics and diagnostics providers (Google Firebase Analytics / Crashlytics and the Google SDKs) may use device identifiers and similar technologies to count usage and detect crashes. These are used only as described in this policy and never for third-party advertising. If we later introduce cookies or trackers that require it, we will ask for your consent and publish a dedicated cookie policy.
11. Security
We apply appropriate technical and organisational measures (Art. 32 GDPR), including encryption in transit, access controls, and regular backups designed to restore availability after an incident. No method of transmission or storage is 100% secure, but we work to protect your data and, where a personal-data breach legally requires it, to notify the AEPD (within 72 hours) and affected users.
12. Subscriptions
Paid subscriptions are billed by Apple or Google, not by us. Deleting your Aura account does not cancel an active subscription — cancel it in your App Store or Google Play account to stop being billed.
13. Children
Aura is intended exclusively for users aged 16 and over. We do not knowingly collect data from children below that age, and if we learn that we have collected a minor's data without the required authorisation, we will delete it.
14. Changes to this policy
We may update this policy. We will post the new version here and update the date above; material changes will be communicated in the app where appropriate.
15. Contact
PAMPA ITER SL — info@pampaiter.com. See our Legal Notice for full company identification.