Back to GymProTrust & Security

Security at GymPro

A clear overview of the safeguards verified in the current GymPro architecture and the responsible route for reporting concerns.

Last updated:

Security approach

GymPro uses technical and organizational safeguards appropriate to its current stage and continues to improve its security practices as the product develops. This page describes controls verified in the current application code; it does not represent an independent certification or a guarantee that incidents cannot occur.

Authentication and account access

GymPro uses Firebase Authentication for account sign-in, email verification and account-security workflows. Protected application routes validate authenticated state and the owner’s current access entitlement before loading gym operations. Users are responsible for safeguarding their credentials and devices.

Tenant-separated gym workspaces

Application records are scoped to a gym workspace. The current product enforces a single active owned-gym relationship for an owner. Firestore security rules restrict browser access, while trusted server commands independently verify authenticated identity, role, entitlement and requested gym instead of relying only on browser state.

Trusted operations and validation

Sensitive membership, financial, attendance and onboarding actions use validated server-side Cloud Function paths where required. Request schemas reject malformed input, and selected mutation workflows use transactions and operation records to reduce duplicate effects during retries.

Data and file access controls

Cloud Firestore rules limit client access to authorized records. Cloud Storage rules and tenant-aware file paths control supported gym and member images. Upload code validates supported image types and size before storage. Public access is not used as a substitute for authorization.

Secrets and environment configuration

Environment-specific configuration separates public Firebase client identifiers from server-side secrets. Sensitive server configuration is bound to trusted function execution rather than placed in browser code. Development emulator routing includes environment safeguards to prevent accidental production use.

Operational records and recovery

GymPro maintains selected operational, adjustment, device, diagnostic and idempotency records needed to investigate changes and safely retry supported actions. Recovery tooling and documented procedures exist for tenant-scoped operations. No public daily-backup, recovery-time or data-residency guarantee is made because the production infrastructure schedule must be separately verified.

Account and data requests

Account or data-deletion assistance is handled through a verified request process. GymPro may confirm identity, account ownership and gym authority before acting, and may retain records where needed for security, recovery, disputes or legal obligations. Requests can be sent to founder@gympro.in.

Report a security issue

Send suspected security issues to founder@gympro.in with the subject “GymPro Security Report.” Include a concise description, affected route or workflow, reproduction steps and impact. Do not access another person’s data, disrupt the service, or include passwords, access tokens or unnecessary personal information.

GymPro does not currently advertise a public bug-bounty program or a guaranteed response time.