Privacy Policy
This Privacy Policy explains how Levla (“Levla,” “we,” “us,” or “our”) collects, uses, shares, and protects your information when you use the Levla iOS app and the “Levla Pro” subscription.
The short version
- What Levla does: it estimates your body-fat percentage from photos you take, builds a personalized daily plan (calorie, protein, step, and training targets), and tracks your progress over time.
- Your photos are stored in a private, per-user space and are only accessible to you. To produce a body-fat estimate, your scan photos and basic details (sex, age, height, weight) are sent to OpenAI through our secure backend. The text you type (such as meal and workout descriptions) and your profile details are sent to OpenAI and Google to build and adjust your plan. Under these providers’ API policies, what we send is not used to train their AI models. We ask for your permission in the app before any of this is sent.
- Apple Health is used only with your permission: we read your steps and weight to keep your plan accurate, and write your body-fat % and weight back. Health data is never sold and never used for advertising.
- No advertising and no cross-app tracking. Levla contains no third-party analytics, advertising, or tracking SDKs, and shows no App Tracking Transparency prompt because we do not track you.
- Subscriptions are billed by Apple. We never see or store your card number.
- You stay in control: you can access, correct, export, or delete your data at any time. Email us at nyrendito@gmail.com.
1. Who we are
Levla is an iOS fitness app that estimates body-fat percentage from user photos, generates a personalized daily plan, and tracks body-composition progress over time. The app is offered on a subscription basis (“Levla Pro”) with a free trial.
For the purposes of the EU/UK General Data Protection Regulation (GDPR), the data controller is:
- Entity: Viggo Nyrensten (individual developer)
- Privacy contact: nyrendito@gmail.com
2. What data we collect
We collect only the data needed to run Levla’s features. We group it as follows.
Account & identity
- You sign in with Sign in with Apple. During onboarding the app may use a temporary anonymous session before you sign in.
- We collect an email address only if you use Sign in with Apple and choose to share your email (you may also choose Apple’s private relay address).
- We assign and store a user ID to identify your account. Authentication and our database are provided by Supabase (a hosted Postgres platform).
Profile information you provide
- Display name, date of birth / age, gender, height, weight, and body measurements.
- Your fitness goal, target body-fat %, the “obstacles” you select, and your “coach voice” preference.
Body-scan photos
- Photos you capture or upload for a body scan. These are stored in a private, per-user storage bucket on Supabase, protected by row-level security and served only through short-lived signed URLs.
Data derived by Levla
- AI body-fat estimates, your body-fat trend over time, daily “move” check-ins, and streak/adherence information.
Apple Health (HealthKit) data — with your permission
- If you grant permission, Levla reads your steps and weight from Apple Health to auto-complete your daily moves and keep your numbers accurate.
- Levla also writes your body-fat % and weight back to Apple Health.
- HealthKit data is accessed on-device with your permission. It is never used for advertising and is never sold. We do not upload your entire Apple Health store to our servers, and we do not store health information in iCloud.
Subscription & purchase data
- Your purchases are processed by Apple via App Store In-App Purchase. We use RevenueCat to manage subscription entitlements and validate receipts.
- RevenueCat receives a pseudonymous app user ID (your Supabase user ID) together with purchase/receipt metadata.
- We do not receive or store your payment-card numbers — Apple handles payment.
On-device storage
- A minimal cached copy of your profile and goal is stored on your device for performance and is cleared when you sign out.
3. How and why we use your data
- Provide the core app functionality — estimate your body-fat percentage from your scan photos, generate your personalized daily plan (calorie, protein, step, and training targets), and track your body-composition progress.
- Authentication & account management — create and secure your account and keep you signed in.
- Personalization — tailor your plan and coaching using your profile, goals, selected obstacles, and coach-voice preference.
- Health features — read steps and weight from Apple Health to keep your plan accurate, and write body-fat % and weight back, only with your permission.
- Subscription management — start your free trial, manage your “Levla Pro” entitlement, and validate receipts.
- Security & operation — protect your account and our service against abuse, debug issues, and keep the service running reliably.
AI processing
Before any of the processing below happens, Levla shows an in-app disclosure and asks for your permission. You can withdraw that permission at any time in the app (Profile → Data & AI processing).
Body-scan photos → OpenAI. To estimate your body fat, your scan photos (front and side, accessed through short-lived signed URLs), together with basic biometrics (sex, age, height, weight), are sent to OpenAI (models gpt-4.1-mini / gpt-4o-mini) through our secure backend, which runs as a Supabase Edge Function. OpenAI returns the estimate to us. We are telling you plainly: your scan photos are processed by OpenAI to generate your body-fat estimate. Under OpenAI’s API data-usage policy, data submitted through the API is not used to train their models.
Text you enter → OpenAI and Google. The text you type — such as meal and workout descriptions — together with your profile details (sex, age, height, weight, goal) is sent to OpenAI (model gpt-4o-mini) and to Google’s Gemini API (model gemini-2.5-flash) through the same secure backend to estimate calories, parse workouts, and build and adjust your daily plan and moves. Under these providers’ API data-usage policies, data submitted through the API is not used to train their models.
4. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Consent — for processing your body-scan photos (including sending them to OpenAI for analysis) and for accessing your Apple Health data. You may withdraw consent at any time (see Your privacy rights).
- Performance of a contract — to provide the Levla app and your “Levla Pro” subscription, including authentication, generating your plan, and managing your subscription.
- Legitimate interests — to keep the service secure, prevent abuse, debug, and operate Levla reliably. We balance these interests against your rights and freedoms.
5. Who we share data with (sub-processors)
We do not sell your personal data. We share data only with the service providers below, each acting as a processor or sub-processor for the purposes described. Each is contractually bound to protect your data to a standard at least equivalent to the protections in this policy, to use it only for the purposes we specify, and not to use it for their own purposes (including, for the AI providers, not to train their models on it).
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database, and private photo storage (our backend). | Account & identity, profile information, scan photos, derived data. |
| OpenAI | AI analysis of your scan photos to produce your body-fat estimate, plus parsing meal/workout text and generating parts of your daily plan. Not used to train OpenAI’s models. | Your scan photos (via short-lived signed URLs) and basic biometrics (sex, age, height, weight), plus your profile and the text you enter. |
| Google (Gemini API) | AI generation of parts of your daily plan and moves. Not used to train Google’s models. No photos are sent to Google. | Profile/biometrics, your goal, and the plan inputs you enter (text). No photos. |
| RevenueCat | Managing subscription entitlements and validating receipts. | Pseudonymous app user ID (your Supabase user ID) and purchase/receipt metadata. |
| Apple | Processing your in-app purchase and subscription billing. | Purchase and payment information (handled by Apple; we do not receive card numbers). |
We may also disclose information where required by law, to enforce our terms, or to protect the rights, safety, and security of our users and Levla.
6. International data transfers
Our authentication, database, and photo storage are hosted by Supabase in the European Union (Frankfurt, eu-central-1).
Some processing may take place outside your country. In particular, AI analysis by Google (Gemini API) and OpenAI may be carried out in the United States. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to protect your data. We do not claim any specific certification on behalf of our providers.
7. Data retention
- We keep your account, profile, photos, and derived data for as long as your account is active, so the app can show your history and progress.
- Scan photos sent to OpenAI for analysis are processed to return an estimate and are subject to OpenAI’s API data-use terms; under OpenAI’s API policy they are not used to train their models. The text and profile data sent to OpenAI and Google for plan generation are subject to those providers’ API retention practices and are likewise not used to train their models.
- When you request deletion of your account (see below), we delete your profile, scans/photos, and derived data, except where we are required to retain limited records to comply with legal obligations (for example, tax or transaction records held by Apple).
- The cached profile/goal on your device is cleared when you sign out.
8. Security
- Row-level security ensures your data — including your private photo bucket — is accessible only to your account.
- Photos are served only via short-lived signed URLs, not public links.
- Data is encrypted in transit using industry-standard TLS.
- AI processing happens through a secure backend (a Supabase Edge Function), so credentials are never exposed in the app.
No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organizational measures.
9. Your privacy rights
Depending on where you live (including under the GDPR and the California Consumer Privacy Act / CPRA), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (see Account & data deletion).
- Export / portability — receive a copy of your data in a portable format.
- Withdraw consent — for AI processing of your photos and data, or for Apple Health access, at any time. You can turn off AI processing in the app at Profile → Data & AI processing, and revoke Health permissions in the iOS Settings app. Withdrawing consent does not affect processing already carried out.
- Object to or restrict certain processing, including processing based on our legitimate interests.
To exercise any of these rights, email us at nyrendito@gmail.com. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority. We do not sell your personal data or use it for cross-context behavioral advertising.
10. Account & data deletion
Once your account is deleted, this action cannot be undone. We may retain a limited amount of information where required to meet legal obligations (for example, transaction records held by Apple). To cancel a subscription itself, manage it in your Apple ID subscription settings.
11. Children
Levla is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact nyrendito@gmail.com and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, provide additional notice in the app. Your continued use of Levla after an update means you accept the revised policy.
13. Contact
If you have any questions about this Privacy Policy or how we handle your data, contact us:
- Email: nyrendito@gmail.com
- Entity: Viggo Nyrensten (individual developer)
This Privacy Policy is governed by the laws of Spain, without regard to its conflict-of-laws rules.