Lightweight
The workout tracking app for serious lifters
Lightweight Privacy Policy
Last updated: 18 August 2026
Lightweight Fitness Ltd ("Lightweight", "we", "us") operates the Lightweight gym-tracking app. We are the controller of the personal data described in this policy. This policy explains what we collect, why, and the control you have over it. It applies to the Lightweight mobile app, the getlightweight.com and lightweight.club websites, the backend, and the optional ChatGPT plugin.
Information we collect
- Account — your email address (and, if you use Google or Apple sign-in, the identifier those providers return) so you can sign in and we can secure your account.
- Training data — the workouts, exercises, sets, routines, and personal records you create, plus the gyms and locations you choose to associate with a workout.
- Gym-operator responses — if a branch receives a private gym-information invitation, we store the invitation email address, the branch confirmation, any branch contact, access, price, hours, equipment, facility, and policy answers submitted, optional gym photos and photo-permission confirmation, optional permission to use photos from the gym's official website in the Lightweight app, and, only when that permission is selected, the responder's name and role at the gym. We also store separate optional choices to be contacted about verified gym-page management, paid referrals, hosting gym competitions, or Lightweight Pass. We also store the response language and consent-copy version. If the recipient reports that the invitation reached the wrong gym, we store that report and the exact gym/email pairing so we do not send another invitation for that gym. The form requires no Lightweight account and otherwise asks for no responder identity, private phone number, or additional contact details. Its evidence record does not store the responder's IP address or user agent.
- Location — used only when you ask (to suggest nearby gyms or confirm a visit). The Android app uses foreground location only. On iOS, if you enable gym arrival reminders, Lightweight registers fixed regions around the saved gyms you select so iOS can notify you when you arrive. It may also use one active-workout region to remind you if you leave while a workout is still running. Lightweight does not store or upload background location samples or a continuous route, and location is not used for advertising or analytics.
- WHOOP health data (optional) — if you connect a WHOOP account, we retrieve your recovery score, heart-rate variability (HRV), resting heart rate, daily strain, sleep duration, and sleep-performance percentage, along with the WHOOP profile identifier needed to link the account. We only request read access, and only for the categories listed here.
- Oura health data (optional) — if you connect an Oura account, we retrieve daily readiness, activity, and sleep scores plus sleep timing, duration, lowest overnight heart rate, and HRV. We request only Oura's daily read scope, not Oura personal-profile data.
- ChatGPT connection data (optional) — if you connect the Lightweight plugin in ChatGPT, we store the connection's client identifier, the permissions you grant, minimal tool-use audit metadata, and any expiring routine draft it creates. We do not store your ChatGPT conversation or prompt.
- Usage analytics (optional) — if you enable Share usage analytics in Settings, we collect a small, fixed set of app-performance and feature-use events: time to reach the editable workout logger, workout save and later sync outcomes, Passport opens, and whether a wrong-gym suggestion was shown and how it was resolved. Events include only a random event or save-operation identifier, event time, platform, app and build version, operating-system major version, and the bounded result or timing needed for that event. The save-operation identifier is not a workout identifier. These events are linked to your account only so we can enforce your choice, prevent duplicates, delete them when you opt out, and produce restricted aggregate unique-user and consent-coverage counts.
- Crash diagnostics (optional) — if you separately enable Share crash diagnostics, production builds send anonymous, scrubbed JavaScript error reports to Sentry. Native crash handling is not enabled. These reports contain the exception type and allowlisted technical stack frames plus app-release context. They do not contain your account identity, breadcrumbs, console output, network requests, screenshots, view hierarchy, session replay, performance traces, or app content.
How we use it
We use this information to operate the app: to log and display your training, power records and achievements, show gym discovery and passport features, and — where you have connected WHOOP or Oura — to display bounded recovery/readiness context alongside your training and let accepted friends compare rolling average sleep duration. If you connect ChatGPT, we use your selected permissions to provide a limited training summary and create routine drafts for your review. Gym-operator responses and uploaded photos are used only to review gym information. Permission to use photos from an official gym website is also reviewed manually and does not automatically copy or publish a photo. When the invitation address separately opts in, we may send the selected future notice about verified page management, paid referrals, gym competitions, or Lightweight Pass. No interest choice enrols a gym. Submitted answers and photos remain private pending evidence and never update public gym facts or galleries automatically. A wrong-gym report is used only to stop further invitations to that address for the reported gym; it does not become gym information. Optional usage events help us measure logger readiness and diagnose save, sync, Passport, and gym-correction reliability. We combine them with aggregate counts derived from successful app records. Optional crash diagnostics help us identify and fix production crashes. We do not use product autocapture, route tracking, session replay, advertising identifiers, device fingerprints, location, health data, workout content, or social content for analytics. We do not use your data for advertising and we do not sell it.
How WHOOP and Oura data are handled
Connecting WHOOP or Oura uses OAuth 2.0. Provider access and refresh tokens are stored only on our backend (Supabase) and are never exposed to the app or to another user. Raw synced health history is visible only to you. While connected, a bounded wearable summary may appear with a workout according to that workout’s visibility, including on a public workout. Accepted friends may also see your 30-day average sleep duration, provider label, average provider sleep score, and contributing-night count on their friends leaderboard. These summaries never grant access to unrelated history or HRV. You can revoke either connection at any time in Settings → Health, which asks the provider to revoke our access and deletes the stored tokens. You can also revoke access directly from your WHOOP or Oura account settings.
How the ChatGPT connection is handled
Connecting ChatGPT uses OAuth 2.1 and requires your explicit consent. You separately choose whether the plugin may read a limited training summary and create expiring routine drafts. That summary may include workout titles and times, exercise identifiers, set metrics, and routine structure. It excludes notes, photos and videos, precise location, social data, WHOOP or Oura health data, payment data, and account credentials. ChatGPT cannot save a routine, start a workout, edit workout history, or delete data. A draft enters your routine library only after you approve it in Lightweight. You can revoke the connection in Settings → ChatGPT; unfinished drafts are then revoked and the OAuth grant is invalidated.
Where your data lives and who processes it
Lightweight is built on service providers who process data on our behalf: Supabase (authentication, database, and storage), Cloudflare (website delivery and request security), WHOOP and Oura (only if you connect them, as the source of the health data above), OpenAI (only when you choose to use the ChatGPT plugin, which receives the permitted tool responses), and, for optional features, app-store billing via RevenueCat and maps via Mapbox. If you enable crash diagnostics, Sentry processes the scrubbed reports in its European Union data region. We share the minimum necessary with each and do not share your data with anyone else except where required by law.
Retention and deletion
We keep your data for as long as your account exists. Disconnecting WHOOP or Oura removes the corresponding stored tokens. ChatGPT routine drafts expire after seven days unless approved sooner; disconnecting ChatGPT revokes unfinished drafts and its grant. Deleting your account (Settings → Account → Delete account) permanently removes your account and associated data from our systems. Raw optional usage events are deleted automatically after 90 days. Turning Share usage analytics off stops collection, clears unsent events from your device, and deletes your account's raw usage events. Anonymous crash reports are retained by Sentry for 30 days. Turning Share crash diagnostics off stops later reports; because the reports contain no account identity, an earlier report cannot reliably be matched back to you for individual deletion. Gym-operator evidence and its review outcome are retained as needed to audit and maintain gym information. Incomplete photo uploads are eligible for cleanup after one hour; unsubmitted photos after 24 hours or when the invitation expires, is revoked, or has been submitted. Photos bound to a submission remain private while the evidence is reviewed. The private invitation address is used only to deliver the request and, for each choice selected, the future page-management, paid-referral, gym-competition, or Lightweight Pass notice. Its owner may ask us to correct or delete the address, response, or photos by contacting us. A wrong-gym suppression is retained as needed to honour that request unless the address owner asks us to correct it.
Your rights
You can access, correct, export, or delete your data from within the app, or by contacting us. Both optional diagnostics choices are off by default and can be changed independently under Settings → Privacy. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honour those requests.
Children
Lightweight is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, communicated in the app.
Contact
Questions or requests: [email protected].
Lightweight Fitness Ltd is registered in England and Wales under company number 17401675. Registered office: 9B Eastcheap, London, England, EC3M 1BN.
Lightweight Terms of Use
Last updated: 3 August 2026
These terms are an agreement between you and Lightweight Fitness Ltd, trading as Lightweight. They apply to your use of the Lightweight mobile app and related services. By using Lightweight, you agree to use it responsibly and in accordance with these terms.
Eligibility
Lightweight is intended for users who are at least 18 years old, or the age of majority where they live.
Training and health
Lightweight is a workout logging app with social features. It is not medical advice, coaching, diagnosis, or a substitute for professional guidance. You are responsible for training safely and choosing exercises, loads, and routines appropriate for you.
Routine drafts generated through the optional ChatGPT plugin are suggestions, may be incomplete or incorrect, and must be reviewed by you before use. They are not medical or professional training advice.
Your content
You are responsible for workouts, profile details, comments, photos, gym information, and other content you add to Lightweight. Do not upload or share content that is unlawful, abusive, harassing, hateful, sexually explicit, exploitative, deceptive, infringing, or otherwise objectionable.
Moderation
Lightweight may remove content, restrict visibility, suspend access, or take other action when content or behavior violates these terms or harms other users. Users can report content and block other users in the app.
Subscriptions
If Lightweight offers paid features, purchases are handled by the relevant app store. Subscription renewal, cancellation, refunds, and billing are managed through your Apple App Store or Google Play account.
Account deletion
You can delete your account in the app from Settings > Account > Delete account. Deletion removes your account and associated personal data from our systems, subject to limited retention where required for security, legal, or abuse-prevention reasons.
Contact
Questions or requests: [email protected].
Lightweight Fitness Ltd is registered in England and Wales under company number 17401675. Registered office: 9B Eastcheap, London, England, EC3M 1BN.
Lightweight Support
Lightweight is operated by Lightweight Fitness Ltd. Email us for help with Lightweight or your account.
Contact
Email [email protected]. Please include the email address on your Lightweight account and a short description of the issue.
Account deletion
In the app, go to Settings > Account > Delete account. If you cannot access the app, email support from the address on your Lightweight account.