Lightweight Privacy Policy

Last updated: 1 September 2026

Lightweight Fitness Ltd ("Lightweight", "we", "us") operates the Lightweight gym-tracking app. We are the controller of the personal data described in this policy. This policy explains what we collect, why, and the control you have over it. It applies to the Lightweight mobile app, the getlightweight.com and lightweight.club websites, the backend, and the optional ChatGPT plugin.

Information we collect

How we use it

We use this information to operate the app: to log and display your training, power records and achievements, show gym discovery and passport features, and — where you have connected WHOOP, Oura, or Fitbit Air — to display bounded recovery/readiness context alongside your training and let accepted friends compare rolling average sleep duration. When you grant Fitbit Air workout write access, we also send newly completed Lightweight workouts to Google Health. If you connect ChatGPT, we use your selected permissions to provide a limited training summary and create routine drafts for your review. Branch responses and uploaded photos are used only to review gym information. Organization responses are used to review the responder's claimed authority and photo rights and whether the chain wants a later conversation about page management or Lightweight Pass. We use the required work email and any optional phone only to perform that manual verification or reply about the submitted response. We do not treat those details as authority by themselves or as consent for marketing or an unrelated campaign. An official-website photo claim remains pending until manual authority and rights review; only after verification may we collect eligible photos the organization owns or can license from the recorded official origins and display them in the Lightweight app or on lightweight.club. No permission claim automatically publishes an image, no interest choice grants management access or enrols a gym in Lightweight Pass, and no response changes public facts or galleries automatically. A wrong-gym or wrong-chain report is used only to stop further invitations to that address for the corresponding reported gym or chain-source scope; it does not become gym information. Optional usage events help us measure logger readiness and diagnose save, sync, Passport, and gym-correction reliability. We combine them with aggregate counts derived from successful app records. Crash diagnostics help us identify and fix production crashes. We do not use product autocapture, route tracking, session replay, advertising identifiers, device fingerprints, location, health data, workout content, or social content for analytics. We do not use your data for advertising and we do not sell it.

We use Contact us messages to understand bugs and requests, add work to the product plan, and record when a message has been handled. The current operator tool does not send replies. A future support reply will use email rather than an in-app chat; an optional reply address is not treated as verified unless it matches the confirmed account email.

We use automated safety checks and assisted report review to keep user-generated content safe. A reviewer receives only one claimed report and its bounded target evidence at a time. It may hide a clearly abusive workout comment or remove a clearly misplaced contributed gym photo from that gym, but those actions preserve the source record and an audited restore path. Unclear, high-risk, identity, account-level, and permanent-deletion decisions go to a person. The automated reviewer cannot ban an account, permanently delete source content, browse other account data, or follow links or instructions embedded in a report.

An individually reviewed initial gym-business email asks the relevant corporate team about accurate gym information or a possible organization relationship. This is direct marketing. For the initial UK corporate-contact pilot, we rely on our legitimate interests in developing accurate gym listings and relevant business relationships, after recording the source, role relevance, jurisdiction and a balancing review. We do not use that basis where applicable electronic marketing law requires consent that we do not have. The email states where we found the address and why we contacted it. You have an absolute right to object to direct marketing at any time; every message provides a prominent Please don’t contact me again link and accepts an objection by reply.

How WHOOP, Oura, and Fitbit Air data are handled

Connecting WHOOP, Oura, or Fitbit Air through Google Health uses OAuth 2.0. Provider access and refresh tokens are stored only on our backend (Supabase) and are never exposed to the app or to another user. Raw synced health history is visible only to you. While connected, a bounded wearable summary may appear with a workout according to that workout’s visibility, including on a public workout. Accepted friends may also see your 30-day average sleep duration, provider label, any available provider sleep score, and contributing-night count on their friends leaderboard. These summaries never grant access to unrelated history or HRV. Fitbit Air contributes no provider sleep score to this feature. You can revoke any connection at any time in Settings → Data & integrations, which asks the provider to revoke our access and deletes the stored tokens. You can also revoke access directly from your WHOOP, Oura, or Google account settings.

Fitbit Air workout export starts only for workouts completed while a write-enabled connection exists; we do not backfill older history. Each exported Google Health strength-training session contains a deterministic workout identifier, start and finish time, duration, and our existing active-calorie estimate when available. It does not contain your workout title or notes, gym or location, exercises, sets, reps, weights, heart-rate samples, photos or videos, friends, achievements, or status. Editing updates the same session and deleting the Lightweight workout asks Google Health to delete it. Export is retried on our backend and never delays saving the workout in Lightweight. Disconnecting stops future exports and removes queued export work, but workouts already sent remain in your Google Health account for you to manage there.

Lightweight’s use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including its Limited Use requirements. We do not sell Google Health data or use it for advertising, credit, research, or medical decision-making.

A friends-leaderboard participant can use the native operating-system share sheet to export either of two Sleep leaderboard images containing at most eight authorized rows selected from the participant and their accepted, unblocked friends. One image shows each included person’s 30-day average sleep duration and contributing-night count; the other shows each included person’s Oura or WHOOP sleep score and contributing-night count, while a Fitbit Air row has no score. Both images include each included person’s display identity and tier, and the participant can send or save them outside Lightweight. They do not include raw individual-night data, HRV, or a public Lightweight link. Disconnecting WHOOP, Oura, or Fitbit Air prevents your sleep summary from appearing in future leaderboard rows and newly generated images, but it cannot retract an image another participant has already shared or saved.

How the ChatGPT connection is handled

Connecting ChatGPT uses OAuth 2.1 and requires your explicit consent. You separately choose whether the plugin may read a limited training summary and create expiring routine drafts. That summary may include workout titles and times, exercise identifiers, set metrics, and routine structure. It excludes notes, photos and videos, precise location, social data, WHOOP or Oura health data, payment data, and account credentials. ChatGPT cannot save a routine, start a workout, edit workout history, or delete data. A draft enters your routine library only after you approve it in Lightweight. You can revoke the connection in Settings → ChatGPT; unfinished drafts are then revoked and the OAuth grant is invalidated.

Where your data lives and who processes it

Lightweight is built on service providers who process data on our behalf: Supabase (authentication, database, and storage), Cloudflare (website delivery, request security, and the access-controlled private moderation page), WHOOP, Oura, and Google Health (only if you connect the corresponding integration, as the source of the recovery data above and destination for the bounded workouts you ask us to export), OpenAI (automated content safety checks, assisted review of user reports, and, only when you choose it, the ChatGPT plugin), and, for optional features, app-store billing via RevenueCat and maps, on-demand travel estimates, and selected-place walking-route comparisons via Mapbox, plus explicit address and coordinate lookup via Geoapify. When crash diagnostics are active, Sentry processes the scrubbed reports in its European Union data region. We share the minimum necessary with each and do not share your data with anyone else except where required by law.

For content safety, OpenAI may receive the exact comment, review, image, sampled video frames or transcript needed for the check. For assisted report review, it receives one report's reason, detail, and bounded target evidence; account emails, credentials, storage paths, and unrelated account history are excluded. OpenAI API inputs and outputs are not used to train its models by default. Requests that use the Responses API disable application storage, while OpenAI may retain limited abuse-monitoring data for up to 30 days unless a shorter approved control applies. A private Codex review task, when used, follows the operator account's OpenAI data controls and task-retention settings; we activate that path only with model improvement disabled. Lightweight records only the bounded decision and fixed audit reason, not the model's private reasoning.

Google Workspace processes gym-outreach mail sent or received through our human reply inbox. Before any separate delivery provider is activated, we will contract it as a processor, name it in this policy, and limit it to message delivery, suppression, bounce and complaint handling. We do not permit open tracking, and delivery tools must not rewrite the private invitation or opt-out links. For optional assisted reply triage, a person may select one inbound outreach reply for the OpenAI API. Before transmission, Lightweight uses automated pattern matching to redact common email-address, phone-number and HTTP(S)-link strings from both email subjects and the reply text. This is not guaranteed to remove every identifier or sensitive detail, so a person must minimize the selected content and complete a disclosure/DLP review before transmission. We send only the organization name, pattern-redacted subjects, language and pattern-redacted reply. The request uses the Responses API with storage disabled. OpenAI does not use API inputs or outputs to train its models by default, but may retain abuse-monitoring data for up to 30 days unless a shorter approved retention control applies. OpenAI returns a structured classification, summary and, only for a non-sensitive reply, an optional draft for a person to review. It never decides or delays an opt-out, bounce, complaint, legal objection, authority finding, photo right, contract or commercial term; sensitive cases cannot receive a draft, it cannot send mail or change contact state, and it is not given access to the whole mailbox.

International transfers

Some processors may handle data outside the United Kingdom. Where the destination is not covered by a UK adequacy regulation, we use an approved transfer safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organizational measures. You may contact us for information about the safeguard relevant to your data.

Retention and deletion

We keep data for a completed account for as long as that account exists. If you authenticate but do not finish onboarding, we keep the provisional identity and setup data so you can resume. Our server runs when Auth creates, updates, or deletes a session and copies that session's latest created, updated, or refreshed time into a private activity timestamp before sign-out removes the row; the current app may also send a resume or Sign out touch. This remains durable for older app versions or when that extra touch cannot reach us. An eligible provisional account is deleted automatically after 30 days without that activity, another onboarding change, or import activity. When this policy begins, every existing unfinished account receives a new full 30-day window. Lightweight does not authorize avatar, workout media, or body-photo uploads before onboarding is complete. If our safety checks nevertheless find an active paid entitlement, stored media, an unexpected dependent record, or an account write in progress, we preserve the provisional account for review or a later daily run rather than risk interrupting activity or orphaning access or files. Disconnecting WHOOP, Oura, or Fitbit Air removes the corresponding stored tokens and synced provider summaries; for Fitbit Air it also removes queued exports, while workouts already sent remain in Google Health under your control. ChatGPT routine drafts expire after seven days unless approved sooner; disconnecting ChatGPT revokes unfinished drafts and its grant.

Deleting your account (Settings → Account → Delete account) starts a durable deletion request. When the server accepts it, the app signs you out and prevents new avatar, workout-media, or body-photo uploads. The app also removes that account's locally saved My Locations document from the device. We remove your sign-in identity, associated account data, and every file under your exact avatar, workout-media, and body-photo folders. If a storage or authentication step is interrupted, a private deletion job retries in the background; it is removed only after those folders have been found empty in two separated checks. Cleanup uses the storage service's deletion API rather than deleting its metadata directly. Limited records may remain only where required for security, legal, or abuse-prevention reasons. Account deletion revokes our Google Health access and stops future Fitbit Air export, but workouts already sent remain in your Google Health account for you to manage there.

Raw optional usage events are deleted automatically after 90 days. Turning Share app usage data off stops collection, clears unsent events from your device, and deletes your account's raw usage events. Anonymous crash reports are retained by Sentry for 30 days. Outside TestFlight, turning Share anonymous crash reports off stops later reports. TestFlight keeps crash reporting active while you use that beta distribution. Because the reports contain no account identity, an earlier report cannot reliably be matched back to you for individual deletion. Branch evidence, organization responses, permission records and their review outcomes are retained as needed to audit gym information, authority and the permissions we rely on. The responder's required name, work email and role plus any optional phone or Other role detail stay with that private response only as long as needed for authority review, reply follow-up and the related permission audit; they are not retained as an unrelated marketing list. Incomplete photo uploads are eligible for cleanup after one hour; unsubmitted photos after 24 hours or when the invitation expires, is revoked, or has been submitted. Photos bound to a submission remain private while the evidence is reviewed. The private invitation address is used to deliver the request, administer any selected follow-up, and honour delivery or contact suppressions. Its owner may ask us to correct or delete the address, response, permission claim, or photos by contacting us. An exact wrong-gym or wrong-chain suppression is retained as needed to honour that request unless the address owner asks us to correct it.

User reports, their bounded review evidence, and moderation outcomes are kept while needed to resolve the report, enforce a reversible content hide, handle a dispute, and protect the service. Removing a reversible hide restores the latest safe classifier state rather than deleting the audit record. Account deletion removes the associated source content and account data, subject to the limited security, legal, and abuse-prevention records described above. The hosted operator session itself expires after no more than one hour and its server-side navigation state is then deleted.

Contact us messages are kept while needed to investigate, plan, or close the request. Account deletion removes the associated Contact us rows; the private operator session does not retain message text after the session ends.

A rejected, unsent outreach contact candidate is deleted within 90 days after review. For a contacted address, we retain its source and lawful-basis review, the messages and replies, and delivery, bounce or complaint history for up to 24 months after the last verification or contact, unless an active organization relationship, permission audit, dispute or legal duty requires longer. We then delete or anonymize the material that is no longer needed. We retain the minimum address and suppression evidence for as long as Lightweight might otherwise contact that address, so an objection, complaint or hard bounce is not forgotten. One-click opt-out requests are applied automatically and do not wait for an LLM or human review.

Your rights

You can access, correct, export, or delete your data from within the app, or by contacting us. Usage analytics is off by default everywhere. Crash reporting is automatically active in TestFlight beta builds and off by default in other distributions. Outside TestFlight, you can change both controls independently under Settings → Privacy. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honour those requests.

Object to gym outreach

You have an absolute right to object at any time to our use of your personal data for direct marketing. Use the Please don’t contact me again link in any outreach email, reply with your objection, or email hello@getlightweight.com. We will stop the outreach and place the address on the appropriate suppression list. You do not have to give a reason, and objecting does not affect any gym listing or your ability to use Lightweight.

You may also complain to the UK Information Commissioner’s Office, or to the data-protection authority where you live or work. You may contact us first, but you are not required to do so.

Children

Lightweight is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

Changes

We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, communicated in the app.

Contact

Questions or requests: hello@getlightweight.com.