Lightweight Privacy Policy

Last updated: 22 September 2026

Lightweight Fitness Ltd ("Lightweight", "we", "us") operates the Lightweight gym-tracking app. We are the controller of the personal data described in this policy. This policy explains what we collect, why, and the control you have over it. It applies to the Lightweight mobile app, the getlightweight.com and lightweight.club websites, the backend, and optional AI-assistant connections.

Information we collect

How we use it

We use this information to operate the app: to log and display your training, power records and achievements, show gym discovery and passport features, and — where you have connected WHOOP, Oura, or Fitbit Air — to display bounded recovery/readiness context alongside your training and let accepted friends compare rolling average sleep duration. When you grant Fitbit Air workout write access, we also send newly completed Lightweight workouts to Google Health. If you connect an AI assistant, we use your selected permissions to analyze your complete history of completed workouts and saved routines and, when you separately grant routine-write permission, to create a saved routine. Updating an existing routine also requires training-history permission. ChatGPT saves only after you confirm the specific change. With Claude, review the exact change before permitting it; approval behavior follows your Claude tool settings. Branch responses and uploaded photos are used only to review gym information. Organization responses are used to review the responder's claimed authority and photo rights and whether the chain wants a later conversation about page management or Lightweight Pass. We use the required work email and any optional phone only to perform that manual verification or reply about the submitted response. We do not treat those details as authority by themselves or as consent for marketing or an unrelated campaign. An official-website photo claim remains pending until manual authority and rights review; only after verification may we collect eligible photos the organization owns or can license from the recorded official origins and display them in the Lightweight app or on lightweight.club. No permission claim automatically publishes an image, no interest choice grants management access or enrols a gym in Lightweight Pass, and no response changes public facts or galleries automatically. A wrong-gym or wrong-chain report is used only to stop further invitations to that address for the corresponding reported gym or chain-source scope; it does not become gym information. Optional product analytics help us measure logger readiness, diagnose save, sync, Passport, and gym-correction reliability, understand which features are useful, and see where subscription journeys succeed or fail. We combine them with aggregate counts derived from successful app records. Crash diagnostics help us identify and fix production crashes. We do not use product autocapture, route tracking, session replay, advertising identifiers, device fingerprints, location, health data, workout content, or social content for product analytics. Campaign measurement is used only to attribute and optimize advertising for Lightweight. We do not sell your data.

Campaign measurement is a separate choice used to measure whether a campaign led to an install or one of the bounded milestones above and to optimize Lightweight's campaigns. Product analytics and campaign measurement are off by default and can be changed independently. Neither choice enables crash reports.

We use Contact us messages to understand bugs and requests, add work to the product plan, and record when a message has been handled. The current operator tool does not send replies. A future support reply will use email rather than an in-app chat; an optional reply address is not treated as verified unless it matches the confirmed account email.

We use automated safety checks and assisted report review to keep user-generated content safe. A reviewer receives only one claimed report and its bounded target evidence at a time. It may hide a clearly abusive workout comment or remove a clearly misplaced contributed gym photo from that gym, but those actions preserve the source record and an audited restore path. Unclear, high-risk, identity, account-level, and permanent-deletion decisions go to a person. The automated reviewer cannot ban an account, permanently delete source content, browse other account data, or follow links or instructions embedded in a report.

An individually reviewed initial gym-business email asks the relevant corporate team about accurate gym information or a possible organization relationship. This is direct marketing. For the initial UK corporate-contact pilot, we rely on our legitimate interests in developing accurate gym listings and relevant business relationships, after recording the source, role relevance, jurisdiction and a balancing review. We do not use that basis where applicable electronic marketing law requires consent that we do not have. The email states where we found the address and why we contacted it. You have an absolute right to object to direct marketing at any time; every message provides a prominent Please don’t contact me again link and accepts an objection by reply.

How WHOOP, Oura, and Fitbit Air data are handled

Connecting WHOOP, Oura, or Fitbit Air through Google Health uses OAuth 2.0. Provider access and refresh tokens are stored only on our backend (Supabase) and are never exposed to the app or to another user. Raw synced health history is visible only to you. While connected, a bounded wearable summary may appear with a workout according to that workout’s visibility, including on a public workout. Accepted friends may also see your 30-day average sleep duration, provider label, any available provider sleep score, and contributing-night count on their friends leaderboard. These summaries never grant access to unrelated history or HRV. Fitbit Air contributes no provider sleep score to this feature. You can revoke any connection at any time in Settings → Data & integrations, which asks the provider to revoke our access and deletes the stored tokens. You can also revoke access directly from your WHOOP, Oura, or Google account settings.

Fitbit Air workout export starts only for workouts completed while a write-enabled connection exists; we do not backfill older history. Each exported Google Health strength-training session contains a deterministic workout identifier, start and finish time, duration, and our existing active-calorie estimate when available. It does not contain your workout title or notes, gym or location, exercises, sets, reps, weights, heart-rate samples, photos or videos, friends, achievements, or status. Editing updates the same session and deleting the Lightweight workout asks Google Health to delete it. Export is retried on our backend and never delays saving the workout in Lightweight. Disconnecting stops future exports and removes queued export work, but workouts already sent remain in your Google Health account for you to manage there.

Lightweight’s use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including its Limited Use requirements. We do not sell Google Health data or use it for advertising, credit, research, or medical decision-making.

A friends-leaderboard participant can use the native operating-system share sheet to export either of two Sleep leaderboard images containing at most eight authorized rows selected from the participant and their accepted, unblocked friends. One image shows each included person’s 30-day average sleep duration and contributing-night count; the other shows each included person’s Oura or WHOOP sleep score and contributing-night count, while a Fitbit Air row has no score. Both images include each included person’s display identity and tier, and the participant can send or save them outside Lightweight. They do not include raw individual-night data, HRV, or a public Lightweight link. Disconnecting WHOOP, Oura, or Fitbit Air prevents your sleep summary from appearing in future leaderboard rows and newly generated images, but it cannot retract an image another participant has already shared or saved.

How AI-assistant connections are handled

Connecting ChatGPT or Claude uses OAuth 2.1 and requires your explicit consent. Through Lightweight’s authorization-server UserInfo endpoint, the connected service receives an opaque Lightweight account subject identifier, your verified account email, and its verification status for OAuth identity and workspace-domain controls. It never receives your Apple or Google password or provider tokens. You separately choose whether the connection may analyze your complete training history and saved routines, and whether it may create saved routines through a separately granted routine-write permission. Updating an existing routine requires both training-history and routine-write permissions. ChatGPT saves only after you confirm the specific change. With Claude, review the exact change before permitting it; approval behavior follows your Claude tool settings. Training history includes completed workouts and exercise-free gym check-ins. That analysis may include workout, routine, and folder names; session and routine-update times; exercise identifiers and names; set metrics; associated canonical gym names or user-entered one-off place labels; technical identifiers needed to select the exact workout, gym, routine, or folder; aggregate training measures; and routine structure. A one-off label is returned exactly as you entered it. The analysis excludes separate gym street-address and coordinate fields, other location fields, notes, photos and videos, social data, separate wearable-health data, payment data, and account credentials. A connected assistant cannot delete routines or folders, start workouts, or edit workout history. With routine-write permission, a routine may be created and placed in an existing private routine folder or in a named private routine folder that the connection creates or reuses. Updating an existing routine also requires training-history permission. You can revoke each connection in Settings → Data & integrations → AI connections; the OAuth grant is then invalidated immediately.

The OAuth access token contains only the minimum technical claims needed to validate the connection, including an opaque session identifier; it excludes provider, name, avatar, phone, custom, and authentication-method metadata.

Where your data lives and who processes it

Lightweight is built on service providers who process data on our behalf: Supabase (authentication, database, and storage), Cloudflare (website delivery, request security, and the access-controlled private moderation page), WHOOP, Oura, and Google Health (only if you connect the corresponding integration, as the source of the recovery data above and destination for the bounded workouts you ask us to export), OpenAI (automated content safety checks, assisted review of user reports, and, only when you choose it, the ChatGPT connection), Anthropic (only when you choose the Claude connection), and, for optional features, app-store billing via RevenueCat and maps, on-demand travel estimates, and selected-place walking-route comparisons via Mapbox, plus explicit address and coordinate lookup via Geoapify. When crash diagnostics are active, Sentry processes the scrubbed reports in its European Union data region. When you enable Product analytics, Amplitude processes the bounded product-analytics events in its United States data region. When you enable Campaign measurement, Adjust and Meta process the bounded campaign-measurement signals. We share the minimum necessary with each and do not share your data with anyone else except where required by law.

When you choose an external AI connection, OpenAI for ChatGPT or Anthropic for Claude processes the tool inputs and outputs under the terms and data controls for your account with that service. Lightweight sends only data permitted by the categories you approve and does not send your Apple or Google password or provider tokens.

For content safety, OpenAI may receive the exact comment, review, image, sampled video frames or transcript needed for the check. For assisted report review, it receives one report's reason, detail, and bounded target evidence; account emails, credentials, storage paths, and unrelated account history are excluded. OpenAI API inputs and outputs are not used to train its models by default. Requests that use the Responses API disable application storage, while OpenAI may retain limited abuse-monitoring data for up to 30 days unless a shorter approved control applies. A private Codex review task, when used, follows the operator account's OpenAI data controls and task-retention settings; we activate that path only with model improvement disabled. Lightweight records only the bounded decision and fixed audit reason, not the model's private reasoning.

Google Workspace processes gym-outreach mail sent or received through our human reply inbox. Before any separate delivery provider is activated, we will contract it as a processor, name it in this policy, and limit it to message delivery, suppression, bounce and complaint handling. We do not permit open tracking, and delivery tools must not rewrite the private invitation or opt-out links. For optional assisted reply triage, a person may select one inbound outreach reply for the OpenAI API. Before transmission, Lightweight uses automated pattern matching to redact common email-address, phone-number and HTTP(S)-link strings from both email subjects and the reply text. This is not guaranteed to remove every identifier or sensitive detail, so a person must minimize the selected content and complete a disclosure/DLP review before transmission. We send only the organization name, pattern-redacted subjects, language and pattern-redacted reply. The request uses the Responses API with storage disabled. OpenAI does not use API inputs or outputs to train its models by default, but may retain abuse-monitoring data for up to 30 days unless a shorter approved retention control applies. OpenAI returns a structured classification, summary and, only for a non-sensitive reply, an optional draft for a person to review. It never decides or delays an opt-out, bounce, complaint, legal objection, authority finding, photo right, contract or commercial term; sensitive cases cannot receive a draft, it cannot send mail or change contact state, and it is not given access to the whole mailbox.

International transfers

Some processors may handle data outside the United Kingdom. Where the destination is not covered by a UK adequacy regulation, we use an approved transfer safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organizational measures. You may contact us for information about the safeguard relevant to your data.

Retention and deletion

We keep data for a completed account for as long as that account exists. If you authenticate but do not finish onboarding, we keep the provisional identity and setup data so you can resume. Our server runs when Auth creates, updates, or deletes a session and copies that session's latest created, updated, or refreshed time into a private activity timestamp before sign-out removes the row; the current app may also send a resume or Sign out touch. This remains durable for older app versions or when that extra touch cannot reach us. An eligible provisional account is deleted automatically after 30 days without that activity, another onboarding change, or import activity. When this policy begins, every existing unfinished account receives a new full 30-day window. Lightweight does not authorize avatar, workout media, or body-photo uploads before onboarding is complete. If our safety checks nevertheless find an active paid entitlement, stored media, an unexpected dependent record, or an account write in progress, we preserve the provisional account for review or a later daily run rather than risk interrupting activity or orphaning access or files. Disconnecting WHOOP, Oura, or Fitbit Air removes the corresponding stored tokens and synced provider summaries; for Fitbit Air it also removes queued exports, while workouts already sent remain in Google Health under your control. Disconnecting an AI assistant immediately invalidates that connection's grant. Saved routines that were created or updated before disconnection remain in your library as ordinary training data.

Deleting your account (Settings → Account → Delete account) starts a durable deletion request. When the server accepts it, the app signs you out and prevents new avatar, workout-media, body-photo, or private custom-exercise photo uploads. The app also removes that account's locally saved My Locations document from the device. We remove your sign-in identity, associated account data, and every file under your exact avatar, workout-media, body-photo, and private custom-exercise photo folders. If a storage or authentication step is interrupted, a private deletion job retries in the background; it is removed only after those folders have been found empty in two separated checks. Cleanup uses the storage service's deletion API rather than deleting its metadata directly. Limited records may remain only where required for security, legal, or abuse-prevention reasons. Account deletion revokes our Google Health access and stops future Fitbit Air export, but workouts already sent remain in your Google Health account for you to manage there.

Older database recovery archives remain in a restricted private repository. They are not covered by the retention rule for the encrypted Cloudflare recovery storage we are preparing. We have not completed the first recovery copy in that storage. Once the deletion process above completes, your data is removed from the live service, but an older recovery archive may still contain data that existed when it was created. Before using an archive to restore the service, we would need to compare it with newer authoritative deletion records where they remain available and keep affected restored data unavailable if we cannot reconcile it safely. The archives do not contain a separate ledger proving every deletion made after each copy was created.

Raw first-party product-analytics events are deleted automatically after 90 days. Turning Product analytics off stops both product-analytics streams, clears unsent first-party and Amplitude events from your device, deletes your account's raw first-party events, and queues deletion of the Amplitude history associated only with your random provider-specific identifier. Completed Amplitude delivery details are removed after 90 days. To avoid sending the same trial or purchase milestone again, we retain only your account, the event type, and a one-way fingerprint of the store transaction or subscription chain while your account exists, never the raw store identifier or milestone time. Deleting your account removes this marker and also queues that Amplitude deletion. Anonymous crash reports are retained by Sentry for 30 days. Outside TestFlight, turning Crash reports off stops later reports. TestFlight keeps crash reporting active while you use that beta distribution. Because the reports contain no account identity, an earlier report cannot reliably be matched back to you for individual deletion. Branch evidence, organization responses, permission records and their review outcomes are retained as needed to audit gym information, authority and the permissions we rely on. The responder's required name, work email and role plus any optional phone or Other role detail stay with that private response only as long as needed for authority review, reply follow-up and the related permission audit; they are not retained as an unrelated marketing list. Incomplete photo uploads are eligible for cleanup after one hour; unsubmitted photos after 24 hours or when the invitation expires, is revoked, or has been submitted. Photos bound to a submission remain private while the evidence is reviewed. The private invitation address is used to deliver the request, administer any selected follow-up, and honour delivery or contact suppressions. Its owner may ask us to correct or delete the address, response, permission claim, or photos by contacting us. An exact wrong-gym or wrong-chain suppression is retained as needed to honour that request unless the address owner asks us to correct it.

Campaign conversion payloads and store transaction identifiers held by Lightweight are removed after 90 days. We retain only the minimal event identity needed to prevent the same conversion from being sent again while the account exists; account deletion removes that ledger. Turning Campaign measurement off stops future sharing with Adjust and Meta and drops unsent campaign events. After the server accepts an irreversible account deletion, Lightweight records and retries Adjust's permanent erasure request if that app installation ever activated Adjust, even if the current control is off. Adjust may transmit a previously queued, consented signal before processing that request; Lightweight sends no new campaign-measurement signal after the deletion is accepted. The completed request deletes the installation's historical Adjust data and stops future Adjust data from that installation. Meta receives no Lightweight account identifier through this route; its handling of device-level app-event data follows its own retention and privacy controls.

User reports, their bounded review evidence, and moderation outcomes are kept while needed to resolve the report, enforce a reversible content hide, handle a dispute, and protect the service. Removing a reversible hide restores the latest safe classifier state rather than deleting the audit record. Account deletion removes the associated source content and account data, subject to the limited security, legal, and abuse-prevention records described above. The hosted operator session itself expires after no more than one hour and its server-side navigation state is then deleted.

Contact us messages are kept while needed to investigate, plan, or close the request. Account deletion removes the associated Contact us rows; the private operator session does not retain message text after the session ends.

A rejected, unsent outreach contact candidate is deleted within 90 days after review. For a contacted address, we retain its source and lawful-basis review, the messages and replies, and delivery, bounce or complaint history for up to 24 months after the last verification or contact, unless an active organization relationship, permission audit, dispute or legal duty requires longer. We then delete or anonymize the material that is no longer needed. We retain the minimum address and suppression evidence for as long as Lightweight might otherwise contact that address, so an objection, complaint or hard bounce is not forgotten. One-click opt-out requests are applied automatically and do not wait for an LLM or human review.

Your rights

You can access, correct, export, or delete your data from within the app, or by contacting us. Product analytics and campaign measurement are off by default everywhere. After onboarding and any first-run feature tour, Lightweight may offer Product analytics once in a centred prompt; Not now keeps it off. An automatic Campaign measurement choice can appear only in a later app session. Android uses a short Lightweight choice; Not now keeps Adjust and Meta off. On iOS, Apple's own tracking alert is the direct choice. If Apple permission is not granted, both SDKs and the advertising identifier remain off on that iPhone. An account choice made on another platform does not bypass Apple's device permission. Neither choice enables crash reports. Crash reporting is automatically active in TestFlight beta builds and off by default in other distributions. You can always change Product analytics and Campaign measurement independently under Settings → Privacy → Data sharing. Outside TestFlight, you can also change Crash reports there. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honour those requests.

Object to gym outreach

You have an absolute right to object at any time to our use of your personal data for direct marketing. Use the Please don’t contact me again link in any outreach email, reply with your objection, or email [email protected]. We will stop the outreach and place the address on the appropriate suppression list. You do not have to give a reason, and objecting does not affect any gym listing or your ability to use Lightweight.

You may also complain to the UK Information Commissioner’s Office, or to the data-protection authority where you live or work. You may contact us first, but you are not required to do so.

Children

Lightweight is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

Changes

We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, communicated in the app.

Contact

Questions or requests: [email protected].