Privacy Policy
Last updated: September 6, 2026
1. Information We Process
For guests, workout data, routines, settings, and records stay on the device. Information you provide or choose to connect—such as a display name, optional body weight, Apple or Google account details, synced records, purchase status, or body weight you accept from Apple Health or Health Connect—is processed when you use the corresponding feature. If you use Community, public Community posts can include your username, post text, publication time, edited status, and the completed-workout card fields you choose to publish. Separately, Free-tier use may automatically generate advertising data for Google Mobile Ads, and, when Sentry is configured with a DSN, app use may automatically generate crash diagnostics, as described below.
2. Local Storage and Cloud Sync
Signing in starts an initial backup to or restore from Supabase so account data can be synchronized. Signed-in users can start a manual sync, and verified Pro users receive periodic automatic sync. Guests can keep their workout information local by not signing in.
3. Apple Health and Health Connect
Health integration is optional on both platforms. It stays off until you turn it on in the app's Settings, and each permission is requested separately through the platform's own permission screen. On iOS, GoLightWeight uses Apple HealthKit. If you allow it, the app reads your body weight from Apple Health to prefill your profile weight and keep bodyweight-exercise volume accurate, saves each finished workout to Apple Health as a workout, removes only its own entries when you discard a workout, and, while a workout runs on your Apple Watch, reads your heart rate and active energy so the saved entry is accurate. If you turn on showing workouts from other apps, the app also reads workouts other apps recorded so they appear in your log for that day; they are shown read-only and are never counted in your statistics. If you turn on workout location, the app captures your location once at the start of a workout and attaches it to that Apple Health entry; it never tracks your movement. On Android, GoLightWeight uses Health Connect with the same scope. If you allow it, the app reads your body weight, saves each finished workout as a strength-training exercise session, removes only its own sessions when you discard a workout, and, if you turn on showing workouts from other apps, reads exercise sessions recorded by other apps for read-only display that is never counted in your statistics. Health data read on either platform stays on your device, except that a body weight you accept into your profile is stored as your profile weight and, if you sign in, syncs like any other profile data. The app requests no background access to health data. We never sell health data or use it for advertising, and you can revoke any of these permissions at any time in the Health app on iOS or in Health Connect settings on Android.
4. Authentication and Profile Data
Apple or Google authentication may provide a user ID, email address, identity provider, and account metadata such as a name. On the first Apple sign-in, a name supplied by Apple may become the display name stored locally in the app.
5. Advertising
Free users may receive banner, app-open, and rewarded ads through Google Mobile Ads. Ad requests are currently non-personalized, but Google and its advertising partners may process an IP address or coarse location, device and app identifiers, ad impressions and interactions, performance information, and diagnostics to deliver ads, apply frequency limits, provide aggregated reporting, maintain security, and prevent fraud. We do not sell workout data. We do not use or transmit workout or HealthKit data for advertising purposes. The same applies to Health Connect data.
6. Crash Reporting
When Sentry is configured with a DSN, app use may automatically send crash, error, device, and operating-system diagnostics to help us find and fix reliability problems. Sentry is configured not to receive default personally identifying information, and these diagnostics do not include workout data.
7. Purchases and Subscriptions
Payment details are processed by the store you installed from — Apple for App Store purchases and subscriptions, Google for Google Play purchases and subscriptions. RevenueCat receives an app-specific user ID and purchase and entitlement status so the app can verify Pro access; it does not receive payment-card details.
8. Service Providers and Sharing
Apple and Google support authentication and platform services. Supabase provides authentication, hosting, storage, and sync infrastructure. Sentry supports crash reporting, RevenueCat supports purchase and entitlement management, and Google and its advertising partners support advertising. For synchronous OpenAI moderation, we send only submitted post text and custom exercise names; we do not send account IDs, email addresses, workout numbers, or other workout metadata for that purpose. These providers may process information only for their relevant services and must protect it consistently with applicable law and their agreements. We may also disclose information when required by law or to protect rights, safety, and service security.
9. Data Retention and Deletion
A successful in-app account-deletion result means the app's request to our controlled Supabase deletion function succeeded; that function is designed to delete the account and server-side data under our control. Local cleanup is then attempted on a best-effort basis and may not finish. Uninstalling the app ensures its local app data is removed from the device. Public Community posts are retained until deleted under the service lifecycle; approved revisions and minimum audit, report, hide, block, and deletion records may be retained for safety, security, legal obligations, and service operation. OpenAI's moderation endpoint has no application-state retention listed in its API data-controls table, but provider retention and legal obligations can change; see OpenAI's current terms and controls. Providers may retain security, fraud-prevention, transaction, or legally required records for their necessary retention periods. If you have already uninstalled the app, you can request deletion by email at privacy@golightweight.app. Deleting an account does not cancel a subscription; subscriptions are billed by the store you installed from and must be cancelled there.
10. Your Choices and Permissions
You can avoid cloud processing by staying a guest, and delete your account from Settings in the app or by request if you no longer have it installed. You can revoke Health access at any time — in the Health app or iOS Settings on iOS, or in Health Connect settings on Android — and you can turn off workout saving, workouts from other apps, and workout location in the app's Settings. Subscriptions are managed separately in the store you installed from — your App Store account on iOS, or Google Play on Android. Where available, you can use privacy choices offered by Google or your device, including your platform's advertising and privacy controls, to limit advertising data processing. For privacy questions or requests, email privacy@golightweight.app.
11. Security
We use reasonable administrative, technical, and organizational safeguards, including Supabase row-level security (RLS) for controlled cloud records. No storage, transmission, or security measure is absolutely secure, so we cannot guarantee absolute security.
12. International Processing
Our providers may process information in the United States and other countries, where privacy laws may differ from those where you live. Where required, processing is supported by applicable contractual or legal safeguards.
13. Children
GoLightWeight is not directed to children under 13 or under a higher minimum age required by local law. If you believe we knowingly hold a child's information, contact privacy@golightweight.app so the information can be reviewed and deleted as appropriate.
14. Changes and Contact
We may update this Privacy Policy as the service or legal requirements change and will revise the date shown above. This policy is effective as of September 6, 2026. Contact privacy@golightweight.app with privacy-related questions.