← GoLightWeight

Privacy Policy

Last updated: August 3, 2026

1. Information We Process

For guests, workout data, routines, settings, and records stay on the device. Information you provide or choose to connect—such as a display name, optional body weight, Apple or Google account details, synced records, purchase status, or HealthKit body weight—is processed when you use the corresponding feature. If you use Community, public Community posts can include your username, post text, publication time, edited status, and the completed-workout card fields you choose to publish. Separately, Free-tier use may automatically generate advertising data for Google Mobile Ads, and, when Sentry is configured with a DSN, app use may automatically generate crash diagnostics, as described below.

2. Local Storage and Cloud Sync

Signing in starts an initial backup to or restore from Supabase so account data can be synchronized. Signed-in users can start a manual sync, and verified Pro users receive periodic automatic sync. Guests can keep their workout information local by not signing in.

3. Apple HealthKit

HealthKit exists only in the iOS app; the Android app has no health-data integration and reads no health data. On iOS, HealthKit access is optional. If authorized, GoLightWeight reads body weight from Apple Health on a read-only basis to support bodyweight calculations and does not write to Apple Health. HealthKit information is never used for advertising.

4. Authentication and Profile Data

Apple or Google authentication may provide a user ID, email address, identity provider, and account metadata such as a name. On the first Apple sign-in, a name supplied by Apple may become the display name stored locally in the app.

5. Advertising

Free users may receive banner, app-open, and rewarded ads through Google Mobile Ads. Ad requests are currently non-personalized, but Google and its advertising partners may process an IP address or coarse location, device and app identifiers, ad impressions and interactions, performance information, and diagnostics to deliver ads, apply frequency limits, provide aggregated reporting, maintain security, and prevent fraud. We do not sell workout data. We do not use or transmit workout or HealthKit data for advertising purposes.

6. Crash Reporting

When Sentry is configured with a DSN, app use may automatically send crash, error, device, and operating-system diagnostics to help us find and fix reliability problems. Sentry is configured not to receive default personally identifying information, and these diagnostics do not include workout data.

7. Purchases and Subscriptions

Payment details are processed by the store you installed from — Apple for App Store purchases and subscriptions, Google for Google Play purchases and subscriptions. RevenueCat receives an app-specific user ID and purchase and entitlement status so the app can verify Pro access; it does not receive payment-card details.

8. Service Providers and Sharing

Apple and Google support authentication and platform services. Supabase provides authentication, hosting, storage, and sync infrastructure. Sentry supports crash reporting, RevenueCat supports purchase and entitlement management, and Google and its advertising partners support advertising. For synchronous OpenAI moderation, we send only submitted post text and custom exercise names; we do not send account IDs, email addresses, workout numbers, or other workout metadata for that purpose. These providers may process information only for their relevant services and must protect it consistently with applicable law and their agreements. We may also disclose information when required by law or to protect rights, safety, and service security.

9. Data Retention and Deletion

A successful in-app account-deletion result means the app's request to our controlled Supabase deletion function succeeded; that function is designed to delete the account and server-side data under our control. Local cleanup is then attempted on a best-effort basis and may not finish. Uninstalling the app ensures its local app data is removed from the device. Public Community posts are retained until deleted under the service lifecycle; approved revisions and minimum audit, report, hide, block, and deletion records may be retained for safety, security, legal obligations, and service operation. OpenAI's moderation endpoint has no application-state retention listed in its API data-controls table, but provider retention and legal obligations can change; see OpenAI's current terms and controls. Providers may retain security, fraud-prevention, transaction, or legally required records for their necessary retention periods. If you have already uninstalled the app, you can request deletion by email at privacy@golightweight.app. Deleting an account does not cancel a subscription; subscriptions are billed by the store you installed from and must be cancelled there.

10. Your Choices and Permissions

You can avoid cloud processing by staying a guest, and delete your account from Settings in the app or by request if you no longer have it installed. On iOS you can revoke Health access in iOS Settings; the Android app does not use Health data. Subscriptions are managed separately in the store you installed from — your App Store account on iOS, or Google Play on Android. Where available, you can use privacy choices offered by Google or your device, including your platform's advertising and privacy controls, to limit advertising data processing. For privacy questions or requests, email privacy@golightweight.app.

11. Security

We use reasonable administrative, technical, and organizational safeguards, including Supabase row-level security (RLS) for controlled cloud records. No storage, transmission, or security measure is absolutely secure, so we cannot guarantee absolute security.

12. International Processing

Our providers may process information in the United States and other countries, where privacy laws may differ from those where you live. Where required, processing is supported by applicable contractual or legal safeguards.

13. Children

GoLightWeight is not directed to children under 13 or under a higher minimum age required by local law. If you believe we knowingly hold a child's information, contact privacy@golightweight.app so the information can be reviewed and deleted as appropriate.

14. Changes and Contact

We may update this Privacy Policy as the service or legal requirements change and will revise the date shown above. This policy is effective as of August 3, 2026. Contact privacy@golightweight.app with privacy-related questions.