GCO Life Logo
GCO Life

Privacy Policy

Last updated: September 14, 2026

In short: We only collect data that is necessary for the app to work. We do not sell personal data to third parties. Your health data belongs to you and is NOT passed on to advertising third parties. For advertising tracking via Meta (only after your ATT consent), hashed account data is transmitted for identification purposes — details in section 7.

1. Controller

GCO Life
Zürcherstrasse 242
8500 Frauenfeld
Switzerland
Email: support@gcolife.com

There is no legal obligation to appoint a data protection officer (solo developer, fewer than 250 employees, no extensive profiling within the meaning of Art. 10 revDSG (Swiss Federal Act on Data Protection)). For privacy matters you can contact us directly at the address above.

2. What data we collect

GCO Life collects the following data in order to provide the app's functions:

Account data:

Profile and fitness data:

Usage data:

Apple Health (HealthKit):

Push notifications (Firebase Cloud Messaging):

3. How we use your data

Your data is used exclusively for:

AI processing: For the coach features, pseudonymized context data is sent to Anthropic (Claude, USA) and in part to OpenAI (USA). So that the coach can address you personally and advise you appropriately, this includes your first name, age, gender as well as your training, nutrition, sleep and check-in data. Your email address, your last name and your account identifier are NOT transmitted. See section 5 for details.

4. Data storage

Your data is stored in Google Firebase (location: Europe, Belgium). Transmission is encrypted (TLS/SSL). Access to your data is protected by Firebase Authentication, Firestore Security Rules and encryption at rest.

5. AI providers (Anthropic & OpenAI)

GCO Life uses AI models from two providers to deliver the coach features:

Which categories of data are transmitted:

What is NOT transmitted: email, real name, date of birth, exact address, raw Apple HealthKit data.

Place of processing: USA (Anthropic, Inc. and OpenAI, L.L.C.). Basis for the transfer to the USA: the European Commission's Standard Contractual Clauses (SCCs) together with supplementary safeguards and, where the recipient is certified, the EU-U.S. Data Privacy Framework (Swiss-U.S. Data Privacy Framework for Switzerland). Both providers are certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR and Art. 31(2)(a) revDSG respectively) — the AI processing is a core part of the app's functionality.

No training data for AI models: Both Anthropic and OpenAI have contractually assured us that your data is not used to train their models (API use, no consumer plan).

6. Disclosure to third parties

We do not pass your personal data on to third parties, with the following exceptions:

We do not sell personal data and will not do so in the future either.

7. Advertising tracking and third parties (Meta)

GCO Life uses the Meta SDK (Facebook SDK) from Meta Platforms Ireland Limited to measure the effectiveness of our advertising campaigns and to further develop our app. We are transparent about what happens in the process.

After installing iOS version 1.9.9 (build 67) or later, automatic and manual advertising events, advertising ID collection and account matching are enabled only with your explicit App Tracking Transparency consent. Declining or withdrawing consent disables these client-side advertising operations. If the app is closed, the server learns of a withdrawal when the app next contacts it. First-party app analytics is separate.

Older installed versions may continue to send automatic and manual app events and signals about completed workouts, logged meals and check-ins to Meta.

Which data is transmitted to Meta after consent:

Meta Advanced Matching (hashed account data): To improve advertising attribution, GCO Life transmits the following account data to Meta in cryptographically hashed form (SHA-256). Meta never receives the plain-text data — only the hash value, which serves to identify your account within their advertising network:

  • Email address (hashed)
  • First and last name (hashed)
  • Date of birth (hashed)
  • Gender (hashed)
  • Country (hashed)
  • Pseudonymous Firebase user ID

This transmission takes place only after your consent via the iOS ATT prompt or the Android advertising settings. If you decline, no Advanced Matching data is sent.

What Meta does NOT receive from iOS version 1.9.9 (build 67):

What Meta uses this data for:

Legal basis:

Data transfer to the USA: Meta also processes data in the USA. Basis for the transfer: the European Commission's Standard Contractual Clauses (SCCs) together with supplementary safeguards and, where the recipient is certified, the EU-U.S. Data Privacy Framework (Swiss-U.S. Data Privacy Framework for Switzerland). Meta is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework.

Retention period: Meta stores app event data for 25 months by default for advertising reporting purposes. Aggregated data may be stored for longer.

Your choices:

Meta privacy policy: https://www.facebook.com/privacy/policy

8. Apple HealthKit

GCO Life can be connected to Apple Health (HealthKit). Special rules apply to HealthKit data:

9. Retention periods

We store your data only for as long as is necessary to provide the app's functions or to comply with statutory retention obligations. Specifically:

Data categoryRetention period
Account data (email, name)until the account is deleted
Training, nutrition, cardio, recovery datauntil the account is deleted
Sleep, stress, check-in datauntil the account is deleted
Coach memory (personality, preferences)until the account is deleted
Crash logs (Crashlytics)90 days
Meta tracking eventsper Meta policy, max. 24-25 months
Backup snapshots (Firebase)max. 30 days after account deletion
FCM token (push)until uninstallation or account deletion
Deletion record (technical account identifier/UID, status, time)indefinitely; without name, email address or content
Pseudonymised check value of the sign-in identity (trial abuse prevention)180 days from the start of the trial, also after account deletion; deleted automatically within 24 hours of expiry

10. Your rights

You have the right to:

Write to us at support@gcolife.com to exercise one of these rights.

11. California and other US states

12. Right to lodge a complaint

If you believe that the processing of your data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority:

13. Data deletion

You can delete your account at any time directly in the app (Profile → Delete account) or by emailing support@gcolife.com. When you delete in the app we remove your profile, your training, nutrition, check-in and health data, your coach history, uploaded documents and your sign-in account – usually immediately, and within 30 days at the latest; deletion requests by email are likewise processed within 30 days. Backup snapshots are overwritten automatically no later than 30 days after deletion.

Exceptions to deletion:

Right to object: You may object at any time, on grounds relating to your particular situation, to processing based on our overriding or legitimate interest – in particular the trial abuse prevention – (Art. 21 GDPR; Art. 30 para. 2 lit. b Swiss FADP). To do so, contact support@gcolife.com.

14. Children

GCO Life is not directed at persons under the age of 16. Minimum age: 16. Anyone younger may not use GCO Life, not even with a parent's consent. We do not knowingly collect data from children under the age of 16.

15. Changes

We may update this privacy policy from time to time. The current version is always available on this page. In the event of material changes, we will inform you in the app.

16. Contact

If you have any questions about data protection, contact us at:
support@gcolife.com