Leonis — Privacy Policy

Version: 2026-08-26 · Last updated: 2026-09-11

Leonis ("Leonis", "we", "us", "our") is an AI fitness, nutrition and recovery coaching app. This policy explains what personal data we process, why, the legal bases we rely on, who we share it with, how long we keep it, how we handle data received from third-party platforms (including Google, Apple and Meta), and the rights you have. We are committed to processing your data lawfully, fairly and transparently, and to collecting only what we need to coach you.

We are based in the State of Qatar and operate the Service for a global audience. In addition to Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, "PDPPL") where it applies, we honor the EU/UK GDPR and the California CCPA/CPRA for users in those regions, as described below.

Data controller: Leonis Fitness LLC, a limited liability company registered in the State of Qatar, trading as Leonis (registered address: Area 56, PO Box 3350, Doha, Qatar). Privacy contact: privacy@leonisfitness.com. General & security contact: support@leonisfitness.com. EU/UK representative (if we have no EU/UK establishment, per GDPR/UK GDPR Art. 27): not appointed — contact privacy@leonisfitness.com.


1. Who and what this policy covers

This policy applies to everyone who downloads, uses, or contacts Leonis — through the mobile app (iOS and Android), the website at leonisfitness.com, and our backend API. It covers our processing as a controller (we decide why and how your data is used). Where we act only as a processor for a platform (for example, data we receive from Google, Apple or Meta APIs), we also honor that platform's rules, described in Sections 6–9.

2. The personal data we process

a. Data you provide directly

Auth); and, depending on how you sign in, an identifier and basic profile from Sign in with Apple, Google Sign-In, or (where offered) another provider. Optionally a display name, username, avatar, bio, country and preferred language.

training location and equipment, dietary preferences and restrictions, allergies, cooking equipment, budget, and any optional health context you choose to share so we can build a safe plan — e.g. injuries, health conditions, medications and supplements, menstrual-cycle information, pregnancy/postpartum status, and bloodwork you upload.

activities, body weight and measurements, water and hydration, check-ins, mood, and photos you choose to upload (meals, progress, bloodwork, form checks).

post to the community or share with a Care Circle contact.

b. Data from your device — only with your explicit, in-app permission

heart-rate variability, respiratory rate, blood oxygen, skin temperature, steps, active/resting energy, VO₂max and body weight. We read these only after you grant access in the OS permission prompt, only to power your recovery score and adapt coaching, and never in the background beyond what you enable.

sleep, strain, heart rate, cycles and workout data from providers you link. We store the access/refresh tokens server-side; you can disconnect at any time.

progress photo, only when you use those features.

run, ride or walk, to map your route and measure distance, pace and elevation. Background location is used only during an in-progress recording you started, so the route stays accurate when your screen locks. You can stop or disable it at any time.

allow it, we take one location reading and turn it into a country and a city / area — because your meal plan is built from the products and brands actually sold near you and priced in your own currency. We never receive your coordinates: the reading is converted into a place name by your phone's own geocoding service (Apple on iOS, Google on Android — the same service your Maps app uses, under their privacy policies) and then discarded on the device, so no latitude or longitude of yours is ever sent to Leonis, stored by us or shared by us for this purpose. We keep only the country, the city/area, and a short record of how we established it. If you decline, nothing is read and you can simply type your country instead — declining costs you nothing but a little typing. You can turn location off at any time in your device settings.

you have already allowed location, and only at the moment you photograph a meal. This exists so a plate bought at a restaurant can use that restaurant's own published nutrition figures instead of an estimate from the picture. Your coordinates never leave your phone. Your device turns your position into a coarse geohash tile (an area, not a point) plus the eight tiles around it, and asks us which venues fall inside them. Our answer is identical for everyone who names the same tiles and carries no reference to you, which is what makes it impossible for us to work out where you are from it. Your phone then does the distance ranking itself, and the only thing sent back to us is the opaque identifier of the one venue you were shown, stored against that scan so the next scan of the same dish in the same place can reuse what you confirmed. We never receive a latitude or longitude for this purpose, and we never store one. This screen never asks for the permission: if you have not already granted location, nothing is read and the scan works exactly as it does today.

against are public map data from OpenStreetMap, © OpenStreetMap contributors, used under the Open Database Licence (ODbL). It is not data about you or collected from you, and it describes places rather than people.

lookup of the country associated with your IP address (via ipapi.co) and compare it with the country your device reported. This is only to notice when the two disagree — for example when you are travelling, on a company network, or using a VPN or private relay — so that we can use your device's answer rather than your network's, and tell you we could not confirm it. We do not use this to block or restrict your account, and we do not claim to detect VPN use: we cannot see that, and saying otherwise would be a guess. We store only the resulting two-letter country code and the result of the comparison — never your IP address and never any coordinates. Your device's answer always beats your network's, and what you tell us yourself beats both.

enable.

c. Special-category / sensitive data. Health, fitness, biometric and (if you provide it) menstrual-cycle and reproductive-health data are special-category personal data under GDPR Art. 9 (and "sensitive personal information" under US state laws). They receive heightened protection: we process them only with your explicit consent (Section 4), solely to deliver the coaching features you asked for, and never for advertising.

d. Data we generate or collect automatically

request logs, device/app version and platform, timezone, coarse diagnostics and crash/error reports, and a private usage/token ledger for cost accounting.

e. Advertising data. Advertising is enabled in Leonis, on the free plan only. Members on a paid plan (Pro, Coach+ or Elite) are shown no ads at all, and no advertising identifier is read for them. Advertising is what funds the free plan.

On the free plan, our ad partners' SDKs (Section 6A) collect your device's advertising identifier (Google Advertising ID on Android, Identifier for Advertisers / IDFA on iOS), other device and app identifiers, IP address, coarse/approximate location, device characteristics, and data about the ads you're shown and interact with — to show, measure and cap the frequency of ads and, where you consent, to personalize them (Section 6A). We never use your health, fitness, biometric, menstrual or other special-category or coaching data (Sections 2b–2c) for advertising, and we never share it with ad partners.

3. How and why we use your data (purposes)

recovery plans, and compute progress, adherence, recovery and weekly insights.

guidance to build your plan.

where you consent, personalized ads, to keep that plan free — using only the non-sensitive advertising data in Section 2e / Section 6A. Paid plans carry no ads.

We use your coaching and health data solely to provide the coaching service to you — we do not sell it and never use it for advertising. Separately, on the free plan we work with ad partners who use the limited, non-sensitive advertising data in Section 6A to show you ads; for personalized ads that "sharing"/"selling" is subject to your consent and opt-out rights (Sections 6A, 12, 18). This applies to the free plan only — no advertising data leaves the app for a member on a paid plan.

4. Legal bases (GDPR Art. 6 & 9)

PurposeLegal basis
Provide the app, account, plans and features you requestContract (Art. 6(1)(b))
Process health / special-category data to coach youExplicit consent (Art. 9(2)(a)); withdrawable any time
Security, abuse-prevention, backups, debugging, product improvementLegitimate interests (Art. 6(1)(f)) — balanced against your rights
Optional "help improve Leonis" learnings; device Health/wearable reads; location recording; marketing email (if any)Consent (Art. 6(1)(a))
Personalized (interest-based) ads via our ad partners' SDKs (ad identifiers etc.)Consent (Art. 6(1)(a)), collected via a certified consent tool; withdrawable any time
Non-personalized / contextual ads and ad measurement/fraud-preventionLegitimate interests (Art. 6(1)(f)) where permitted, else consent
Meeting legal/regulatory obligationsLegal obligation (Art. 6(1)(c))

Recording consent. When you accept our Terms and this Policy (and health-data processing), we store when you consented and which version you accepted (consentAt + policyVersion) so consent is demonstrable (Art. 7). You can withdraw consent at any time (Section 12). Withdrawal doesn't affect processing done beforehand, but may mean we can no longer provide some features.

5. Apple Health & Android Health Connect — specific commitments

provide the app's coaching features to you, on-device and on our secured backend.

share it with third parties for their own purposes or use it to train AI models.

do not store Health data we don't need.

(or Android → Health Connect). Revoking stops new reads; previously-synced metrics are deleted when you delete your account (Section 13).

6. Google API Services, YouTube & Gemini (images) — Limited Use

Leonis uses Google API Services. Our use of them is governed by the Google API Services User Data Policy, including the Limited Use requirements:

Leonis's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google API Services in these ways:

basic profile and email address you approve on Google's consent screen, and use them only to create and authenticate your Leonis account. We request the narrowest scopes needed, don't use this data for advertising, don't sell it, and don't transfer it to others except to provide or improve this feature, for security, or to comply with law — consistent with Limited Use. You can review or revoke access at Google Account → Security → Third-party access.

exercise, we search YouTube for a relevant public video using an application API key and embed it in the in-app player. We access only public video metadata (title, description, video ID); we do not access your YouTube account, your YouTube user data, your watch history, or your Google identity for this feature, and we do not store personal data from YouTube. Because this feature embeds and plays YouTube content:

about that playback under their own policies; that processing is controlled by Google, not Leonis.

illustrative images for exercises and dishes using Google's Gemini image model, accessed through our AI gateway (OpenRouter). The prompts are our own generic content descriptions — we do not send your personal or health data, photos, or identity to the image model.

6A. Advertising (Google AdMob)

Advertising is enabled in Leonis, on the free plan only. Google AdMob's SDK ships in the app, ads are served to free-plan members, and — on iOS, only if you allow it at the App Tracking Transparency prompt — the advertising identifier is read. Members on a paid plan see no ads and have no advertising identifier read.

We work with a third-party ad network to display ads. It acts as an independent controller for the data its SDK collects, under its own privacy policy:

use our services](https://policies.google.com/technologies/partner-sites) · Google Privacy Policy · AdMob & personalization.

mediation layer. The authorized list is published in our app-ads.txt at https://leonisfitness.com/app-ads.txt, and is available from us on request. If we ever add another network, it will be named here and in that file in the same release that ships its SDK.

What our ad partner collects. To show and measure ads, AdMob's SDK collects your device's advertising identifier (Google Advertising ID on Android, IDFA on iOS), other device/app identifiers, IP address, coarse/approximate location, device characteristics, and data about the ads you're shown and click.

They never receive your health, fitness, biometric, menstrual-cycle, precise-location, message or coaching data. That is a hard boundary in how the app is built, not only a promise here: no such data is ever passed to an ad SDK.

Personalized ads. Where you consent, ad partners use this data to show you personalized (interest-based) ads and to measure and cap them. Without consent (or where personalization is unavailable), you'll see non-personalized / contextual ads instead.

Your controls.

through a Google-certified Consent Management Platform built on the IAB Transparency & Consent Framework (TCF v2.2). You can review or change your choices any time in Account & privacy → Ad & privacy settings.

Not to Track", we do not use the IDFA or cross-app tracking to personalize ads.

personalization in your device settings (iOS → Settings → Privacy & Security → Tracking / Apple Advertising; Android → Settings → Privacy → Ads).

We never advertise on your health. We do not share your health, fitness, biometric, menstrual, precise-location, message or other special-category or coaching data with ad partners, and we never use it to target ads. Advertising is supported only by the non-sensitive data described above.

Children. We do not serve personalized ads to users under 16 (or the applicable age of digital consent); any ads shown to them are non-personalized, and we configure our ad partners accordingly (e.g. AdMob "child-directed treatment" / "below age of consent" flags).

7. Sign-in and connected platforms (Apple · Google · Meta · wearables)

You can create or link your account and connect services through third-party platforms. Each is optional and, where you use it, subject to that platform's own terms and privacy policy in addition to ours:

name and email; Apple's Hide My Email private relay may forward a relay address instead of your real one. See the Apple Privacy Policy.

Meta and you choose to use it, we receive only the basic profile data you approve and handle it in line with the Meta Platform Terms and Meta Developer Policies; Meta's own processing is described in the Meta Privacy Policy. We do not currently import your Meta contacts, posts or friends, and we don't use such data for advertising.

strain and activity data you authorize, under WHOOP's terms, and use it only to coach you. Disconnect any time in the app.

8. AI processing

To generate coaching responses, plans and insights, relevant context (e.g. your goals, profile summary and the message you send) is processed by our AI providers — Anthropic (directly and/or via the OpenRouter gateway) and, for image generation, Google Gemini via OpenRouter — under their data-processing terms. We send only what's needed to produce the output, and we do not send your email address, authentication tokens, raw Apple Health/Health Connect samples, or precise location to the AI providers, and we do not authorize them to use your content to train their models. Nutrition and product facts may be looked up via USDA FoodData Central and Open Food Facts. See Section 15 on automated decision-making.

9. Maps & location

When you record an outdoor activity, the app draws your route on a map using the device's map provider (Apple Maps on iOS, Google Maps on Android, via expo-maps) and your GPS location. Route coordinates you save are stored with your account so you can review the activity, and are deleted when you delete your account. Map tiles are served by the map provider under their own terms.

Setting up your food plan is different, and deliberately so. The one reading we take at onboarding is turned into a place name by your device's geocoding service — Apple's on iOS, Google's on Android, the same one your Maps app uses, and the same one already involved when you record a route — and the coordinates are then discarded on the device. That lookup is between your phone and Apple or Google under their own privacy policies; Leonis never receives the coordinates. What reaches us is a country and a city/area — the coarsest information that still lets us source your meals locally. We store no latitude or longitude for this purpose, which is why precise location does not appear anywhere in your data export as a stored value.

Correcting it. If your country is wrong, or you declined and want to supply it, you can enter it by hand during onboarding. Getting it wrong has a visible cost — the wrong shops, the wrong brands, the wrong currency — so we would rather you correct us than have us guess. If we cannot establish a country at all, we leave it blank and say so on the affected screens instead of assuming one.

10. Who we share data with (sub-processors)

We share data only with vetted processors who act on our documented instructions under data-processing agreements (GDPR Art. 28):

Sub-processorPurposeData involved
SupabaseDatabase, authentication, file/photo storageAccount, profile, plans, logs, photos, tokens
Fly.ioHosting our backend APIAll data, in transit and processing
AnthropicAI model inference (coaching)Coaching context (no email/tokens/raw Health/precise location)
OpenRouterAI gateway routing to Anthropic + Google GeminiSame as above; image prompts (no personal data)
Google (YouTube Data API; Gemini image model; Google Sign-In)Exercise-video search; image generation; optional loginPublic video queries; generic image prompts; login profile/email you approve
ipapi.coOne country-level IP lookup at onboarding, to check it against the country your device reported (Section 2)Your IP address, sent from your device at that moment only. We receive back a two-letter country code and store only that; we never send them your name, account or any health data
Apple (Sign in with Apple; App Store; Maps)Optional login; app distribution; maps on iOSLogin identifier/email you approve; route rendering
Meta (if you use Meta sign-in/sharing)Optional login/sharingBasic profile you approve
USDA FoodData Central · Open Food FactsNutrition & product lookupsFood/barcode queries (not tied to your identity)
WHOOP (and wearables you connect)Read the recovery/activity data you authorizeOAuth tokens; the metrics you authorize
Expo / EASApp delivery, over-the-air updates, push notificationsPush tokens, app version, diagnostics
ResendTransactional & (if enabled) opt-in emailEmail address, message content

Advertising partners (independent controllers, not our processors — Section 6A):

PartnerPurposeData involved
Google AdMobShow, measure, frequency-cap and (with consent) personalize adsAdvertising ID / IDFA, device & app identifiers, IP, coarse location, ad-interaction data — never health, sensitive or coaching data

We do not otherwise disclose your data except: to comply with law or valid legal process; to protect our rights, our users or the public; or in a merger/acquisition (with notice, and this policy continues to apply). Other than the limited, non-sensitive advertising data we share with the ad partners above (which, for personalized ads, may count as a "sale"/"share" under US law — see Sections 6A and 18 for your opt-out), we do not sell your data, and we never share your health, sensitive or coaching data for advertising.

11. Where your data is processed & international transfers

South Korea (Seoul region, ap-northeast-2).

e.g. AI inference and platform services) may process data in the United States or other countries.

Where personal data leaves the EEA/UK, we rely on a valid GDPR Chapter V transfer mechanism:

December 2021), so transfers to our Korea-hosted database are permitted without additional safeguards, on essentially the same footing as transfers within the EEA.

States), we rely on the EU Standard Contractual Clauses (and the UK Addendum), plus supplementary measures where needed, or on the provider's Data Privacy Framework certification where applicable.

12. Your rights

Depending on where you live (e.g. EEA/UK under GDPR/UK GDPR, California under CCPA/CPRA, and other US states), you have rights to:

Export my data** (a full JSON export), or by contacting us.

same JSON export).

→ Delete my account**, which permanently removes your profile, plans, logs, photos, synced metrics, connected-service tokens and login. You can also email us.

turn off "help improve Leonis"; disconnect a wearable; delete your account).

"share"/"sell" (as US laws define those terms) limited advertising identifiers with our ad partners (Sections 6A, 18). You can opt out any time via Account & privacy → Ad & privacy settings, the iOS App Tracking Transparency prompt, or your device ad settings, and we honor Global Privacy Control signals. We do not sell or share your health, sensitive or coaching data at all, and never use sensitive data beyond providing the service.

subject to solely-automated decisions** with legal or similarly significant effects (Section 15).

supervisory authority (in the EEA/UK, your local Data Protection Authority; in California, the CPPA) — though we'd appreciate the chance to help first.

We respond to verified requests within the timeframes the law requires (generally one month under GDPR; 45 days under CCPA). We don't charge for these rights except where the law allows. You may use an authorized agent where the law permits.

13. Retention

We keep your data while your account is active. When you delete your account we delete or irreversibly anonymize your personal data within 30 days, except where we must retain limited records to meet legal obligations, resolve disputes or enforce agreements. Backups are purged on a rolling 30-day cycle. Aggregated or de-identified data that can no longer be linked to you may be retained.

14. Security

We protect your data with encryption in transit (HTTPS/TLS), encryption at rest for our database and file storage, per-user row-level security so each user can only access their own data, server-side secret handling, scoped access tokens, and least-privilege access for our team. No system is perfectly secure; if a personal- data breach occurs we will notify the relevant supervisory authority and affected users as required (GDPR Art. 33–34, generally within 72 hours of becoming aware).

15. Automated decision-making & AI

Leonis uses deterministic algorithms plus AI to generate suggestions (plans, targets, recovery guidance, exercise/meal swaps). These are recommendations to support your choices, not decisions that produce legal or similarly significant effects on you, and you remain in control of what you do. AI output can be imperfect — always apply judgment, and consult a qualified professional for medical, health or dietary decisions. If you believe an automated output affected you unfairly, contact us for human review.

16. Children

Leonis is not directed to children under 16 (and never under 13), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it. Where a lower age of digital consent applies in your country, that age governs, subject to the 13-year floor. We do not serve personalized ads to anyone under the applicable age of consent (Section 6A).

17. Cookies, advertising identifiers & tracking

With advertising enabled, the mobile app uses advertising identifiers (Google Advertising ID / IDFA) and third-party ad-network SDKs (Section 6A). On iOS we request permission via App Tracking Transparency before any cross-app tracking; if you decline, we do not use the IDFA to personalize ads. In the EEA/UK/Switzerland we gather ad consent through a certified consent tool (Section 6A). You can manage ad personalization in Account & privacy → Ad & privacy settings and in your device settings. Our website uses only strictly-necessary cookies unless you consent otherwise; where we serve web ads or embed third-party content (e.g. YouTube), those providers may set cookies under their own policies (Section 6).

18. California & US state privacy notices

In the past 12 months we have collected the categories described in Section 2 (identifiers; account and profile data; health/biometric and other sensitive information you provide or authorize; commercial/usage data; photos; geolocation you record; and inferences we compute to coach you), for the purposes in Section 3, from the sources in Section 2. On the free plan we also collect advertising activity (Section 6A); on a paid plan we do not.

Sale / sharing. On the free plan, showing personalized ads involves "sharing"/"selling" as the CCPA/CPRA define those terms, because an advertising identifier reaches our ad partners. You can opt out at any time — see the "Do Not Sell or Share" control below and in Account & privacy → Ad & privacy settings. We never sell or share your health, fitness or coaching data, on any plan. On a paid plan there is no advertising identifier to share and no ad partner receiving one.

If we introduce advertising, we would "share"/"sell" (as the CCPA/CPRA define those terms) a limited set of identifiers — advertising ID, device identifiers, IP address and ad-interaction data — with advertising partners (Section 6A) so they can show you interest-based ads and measure them, and we would update this notice before doing so. We would never sell or share your health, biometric or other sensitive personal information, your coaching content, your messages, or your precise location, and we do not use sensitive personal information for these purposes.

Your rights include the right to know, access, delete and correct; to opt out of the sale/sharing of your personal information; and to limit the use of sensitive personal information. Exercise the opt-out through the "Do Not Sell or Share My Personal Information" control in Account & privacy → Ad & privacy settings (or by declining the iOS tracking prompt / your device ad settings); we also honor Global Privacy Control signals. Sensitive data is already limited to providing the service. California residents also have the rights in Section 12, and the right to be free from discrimination for exercising them.

19. Changes to this policy

We'll update this page and the Version / Last updated date for changes. For material changes we bump POLICY_VERSION and ask you to re-accept in-app before you continue using affected features.

20. Contact & complaints

Questions, requests, or complaints: privacy@leonisfitness.com (or the postal address above). In the EEA/UK you may also lodge a complaint with your local supervisory authority; in California, with the California Privacy Protection Agency.