Guide7 min read

Is It Safe to Use AI for Personal Trainers?

Yes to build programs, no with a client's named health data: it's special-category data you must anonymise before the prompt.

By Pierre de ONYRI

The short answer fits in one line. AI can help you build a program, but never hand it a client's named health data. A Par-Q screen, an injury, a condition, a medication, body measurements, a pregnancy: these are health data. Under the GDPR, Article 9 makes them a special category, the most protected class there is. A trainer holds a lot of it. Pasting it into a consumer AI hands it to a third party. In the United States, a trainer is usually not covered by the HIPAA health law. There is a clean method: anonymise names and identifiers before you send.

What a client's file lays bare

A personal trainer collects more data than they think. A Par-Q fitness questionnaire. An injury history. Conditions and current medications. Body measurements. Goals, and sometimes a pregnancy. Each of these speaks to a person's health.

The GDPR files this data in a precise box. Article 9 covers 'data concerning health'. It makes them a special category. Processing them is prohibited by default, save narrow exceptions like explicit consent. They sit beside genetic, biometric and sex-life data. It is the most locked drawer in the text.

The definition is broad. Per the ICO, the UK regulator, health data covers any information about a person's physical or mental health. An injury. A disease. A medical exam. Even a note that a client is pregnant counts as health data. No formal diagnosis is needed.

The coverage gap in the United States

Many trainers assume HIPAA protects this data. It rarely does. HIPAA (the U.S. federal health law) applies only to 'covered entities'. These are health plans, clearinghouses and providers that transmit data for standard transactions. Their business associates too.

A personal trainer, a gym or a wellness coach fits none of these boxes as a rule. With no tie to a covered entity, they stay outside HIPAA. The direct result: the health data they collect is not protected the way a clinic's records are.

The FTC (the U.S. federal trade agency) confirms this for wellness tools. A fitness app found on a store, with no tie to a clinic, is usually not subject to HIPAA. That data falls instead under the FTC Act and the Health Breach Notification Rule. A different, and for the individual weaker, protection than clinical records.

You assumeThe reality
“An injury isn't medical”The GDPR files it as health data, a special category (Art. 9)
“HIPAA protects my clients' data”A trainer is usually not a covered entity, so not covered
“No diagnosis means no health data”The ICO also covers what reveals a health status, by inference
“AI can judge a contraindication”AI is confidently wrong; its answer is not medical advice
The risk isn't building a program with an AI — it's the named health data you leave behind in the prompt.

Two traps to know: minors and fake medical advice

Coaching young people raises the bar. A minor's data is children's data. Authorities treat it as needing extra protection. A trainer coaching under-18s therefore handles two sensitive layers at once: health and childhood.

Another trap is reliability. AI can be confidently wrong about an injury or a condition. Its answer is not medical advice. That is a real safety issue for a client. The trainer must keep judgement over anything health-related. Never act on an AI answer about a client's condition.

The fix: anonymise before the prompt

Good news: AI is still useful for your work. It can structure a program, write a plan, suggest progressions. For that, it does not need your client's name. It reasons well on de-identified health inputs. The person is no longer directly identifiable, with no loss to the program.

Two-part diagram: at top, a client profile card with an injury/health row and a measurements row in the clear (amber), beside a small dumbbell, travels toward an AI card that receives the exposed file with an amber alert; at bottom, the same card anonymized shows only cobalt tokens, and the AI receives only tokens with a shield and a checkmark.
After GDPR Article 9 (EUR-Lex), the ICO's guidance on special category data, and the FTC's Mobile Health Apps tool.

The base rule is simple. Never paste a medical screen or a condition tied to a name. Replace each identifier with a token before you send. The AI builds the program on the shape of the case, without seeing the real values. You restore the real data afterwards, locally.

  • Anonymise the client's names and identifiers before every prompt.
  • Do not paste medical screens or conditions tied to a name.
  • Keep a human judgement on anything health-related.
  • Prefer vetted tools covered by a data processing agreement (DPA).
  1. 1Spot the sensitive data: name, injuries, conditions, medications, measurements.
  2. 2Replace it with reversible tokens, in the browser.
  3. 3Send only the anonymized text to the AI.
  4. 4Restore the real values in the reply, locally.

That's what ONYRI Sanitize is for. The engine detects sensitive data — names, injuries, conditions, measurements — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI builds your program on tokens, never on your client's real health file. You get the help, without exposing the class of data the GDPR protects most.

Frequently asked questions

Is it safe to use AI for personal trainers?
Yes to build programs, no with a client's named health data. AI can structure a plan or suggest progressions with no personal data at all. But never paste a Par-Q screen, an injury, a condition or measurements tied to a name into a consumer AI. Under the GDPR, these are special-category data (Article 9). Anonymise names and identifiers before you send.
Does HIPAA protect the health data a trainer collects?
Usually not. HIPAA applies only to 'covered entities': health plans, clearinghouses and providers doing standard electronic transactions, plus their business associates. A personal trainer or gym with no tie to a covered entity stays outside HIPAA. So the health data they collect is not protected the way a clinic's records are. The FTC confirms this for wellness tools.
Can I ask AI for advice on a client's injury?
Be careful. AI can be confidently wrong about an injury, a contraindication or a condition. Its answer is not medical advice, and that is a real safety issue. Always keep a human judgement over anything health-related, and never act on an AI answer about a client's condition.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next