Version: 2026-07-24 · Last updated: 2026-07-24
This version string matches
POLICY_VERSIONin the app. When we change this policy materially we bump the version and re-request your consent in-app.Before you publish: fill the two remaining placeholders — your legal name and a contact/postal address — then host this page at its public URL (
https://leonisfitness.com/privacy, the URL you enter in App Store Connect, Google Play, the Google API / OAuth consent screen, and the Meta app dashboard), and have privacy counsel review the health-data, legal-basis, retention, transfers, advertising and automated-decision sections for your markets.Advertising is disclosed here (Section 6A) but the policy alone does not make ads compliant. To actually serve personalized ads you must also: integrate a Google-certified CMP (e.g. Google UMP) for EEA/UK consent; show the iOS App Tracking Transparency prompt; publish
app-ads.txtat your domain root; and declare the ad data collection in the Google Play Data Safety form and Apple App Privacy labels ("Data used to track you"). Do not enable ads before this page (and the version bump) are live, and do not describe ads as active before they are. This document is not legal advice.
Leonis ("Leonis", "we", "us", "our") is an AI fitness, nutrition and recovery coaching app. This policy explains what personal data we process, why, the legal bases we rely on, who we share it with, how long we keep it, how we handle data received from third-party platforms (including Google, Apple and Meta), and the rights you have. We are committed to processing your data lawfully, fairly and transparently, and to collecting only what we need to coach you.
We are based in the State of Qatar and operate the Service for a global audience. In addition to Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, "PDPPL") where it applies, we honor the EU/UK GDPR and the California CCPA/CPRA for users in those regions, as described below.
Data controller: [Your legal name], an individual (sole proprietor) trading as Leonis, based in the State of Qatar (contact address: [postal address]). Privacy contact: privacy@leonisfitness.com. General & security contact: support@leonisfitness.com. EU/UK representative (if we have no EU/UK establishment, per GDPR/UK GDPR Art. 27): not appointed — contact privacy@leonisfitness.com.
This policy applies to everyone who downloads, uses, or contacts Leonis — through the mobile app (iOS and Android), the website at leonisfitness.com, and our backend API. It covers our processing as a controller (we decide why and how your data is used). Where we act only as a processor for a platform (for example, data we receive from Google, Apple or Meta APIs), we also honor that platform's rules, described in Sections 6–9.
a. Data you provide directly
Auth); and, depending on how you sign in, an identifier and basic profile from Sign in with Apple, Google Sign-In, or (where offered) another provider. Optionally a display name, username, avatar, bio, country and preferred language.
training location and equipment, dietary preferences and restrictions, allergies, cooking equipment, budget, and any optional health context you choose to share so we can build a safe plan — e.g. injuries, health conditions, medications and supplements, menstrual-cycle information, pregnancy/postpartum status, and bloodwork you upload.
activities, body weight and measurements, water and hydration, check-ins, mood, and photos you choose to upload (meals, progress, bloodwork, form checks).
post to the community or share with a Care Circle contact.
b. Data from your device — only with your explicit, in-app permission
heart-rate variability, respiratory rate, blood oxygen, skin temperature, steps, active/resting energy, VO₂max and body weight. We read these only after you grant access in the OS permission prompt, only to power your recovery score and adapt coaching, and never in the background beyond what you enable.
sleep, strain, heart rate, cycles and workout data from providers you link. We store the access/refresh tokens server-side; you can disconnect at any time.
progress photo, only when you use those features.
to map your route and measure distance, pace and elevation. Background location is used only during an in-progress recording you started, so the route stays accurate when your screen locks. You can stop or disable it at any time.
enable.
c. Special-category / sensitive data. Health, fitness, biometric and (if you provide it) menstrual-cycle and reproductive-health data are special-category personal data under GDPR Art. 9 (and "sensitive personal information" under US state laws). They receive heightened protection: we process them only with your explicit consent (Section 4), solely to deliver the coaching features you asked for, and never for advertising.
d. Data we generate or collect automatically
request logs, device/app version and platform, timezone, coarse diagnostics and crash/error reports, and a private usage/token ledger for cost accounting.
e. Advertising data. Leonis is free to use and supported by advertising. When ads are enabled, our ad partners' SDKs (Section 6A) collect your device's advertising identifier (Google Advertising ID on Android, Identifier for Advertisers / IDFA on iOS), other device and app identifiers, IP address, coarse/approximate location, device characteristics, and data about the ads you're shown and interact with — to show, measure and cap the frequency of ads and, where you consent, to personalize them (Section 6A). We never use your health, fitness, biometric, menstrual or other special-category or coaching data (Sections 2b–2c) for advertising, and we never share it with ad partners.
recovery plans, and compute progress, adherence, recovery and weekly insights.
guidance to build your plan.
keep the app free, using only the non-sensitive advertising data in Section 2e / Section 6A.
We use your coaching and health data solely to provide the coaching service to you — we do not sell it and never use it for advertising. Separately, we work with ad partners who use the limited, non-sensitive advertising data in Section 6A to show you ads; for personalized ads this "sharing"/"selling" is subject to your consent and opt-out rights (Sections 6A, 12, 18).
| Purpose | Legal basis |
|---|---|
| Provide the app, account, plans and features you request | Contract (Art. 6(1)(b)) |
| Process health / special-category data to coach you | Explicit consent (Art. 9(2)(a)); withdrawable any time |
| Security, abuse-prevention, backups, debugging, product improvement | Legitimate interests (Art. 6(1)(f)) — balanced against your rights |
| Optional "help improve Leonis" learnings; device Health/wearable reads; location recording; marketing email (if any) | Consent (Art. 6(1)(a)) |
| Personalized (interest-based) ads via our ad partners' SDKs (ad identifiers etc.) | Consent (Art. 6(1)(a)), collected via a certified consent tool; withdrawable any time |
| Non-personalized / contextual ads and ad measurement/fraud-prevention | Legitimate interests (Art. 6(1)(f)) where permitted, else consent |
| Meeting legal/regulatory obligations | Legal obligation (Art. 6(1)(c)) |
Recording consent. When you accept our Terms and this Policy (and health-data processing), we store when you consented and which version you accepted (consentAt + policyVersion) so consent is demonstrable (Art. 7). You can withdraw consent at any time (Section 12). Withdrawal doesn't affect processing done beforehand, but may mean we can no longer provide some features.
provide the app's coaching features to you, on-device and on our secured backend.
share it with third parties for their own purposes or use it to train AI models.
do not store Health data we don't need.
(or Android → Health Connect). Revoking stops new reads; previously-synced metrics are deleted when you delete your account (Section 13).
Leonis uses Google API Services. Our use of them is governed by the Google API Services User Data Policy, including the Limited Use requirements:
Leonis's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google API Services in these ways:
basic profile and email address you approve on Google's consent screen, and use them only to create and authenticate your Leonis account. We request the narrowest scopes needed, don't use this data for advertising, don't sell it, and don't transfer it to others except to provide or improve this feature, for security, or to comply with law — consistent with Limited Use. You can review or revoke access at Google Account → Security → Third-party access.
exercise, we search YouTube for a relevant public video using an application API key and embed it in the in-app player. We access only public video metadata (title, description, video ID); we do not access your YouTube account, your YouTube user data, your watch history, or your Google identity for this feature, and we do not store personal data from YouTube. Because this feature embeds and plays YouTube content:
about that playback under their own policies; that processing is controlled by Google, not Leonis.
illustrative images for exercises and dishes using Google's Gemini image model, accessed through our AI gateway (OpenRouter). The prompts are our own generic content descriptions — we do not send your personal or health data, photos, or identity to the image model.
Leonis is free and supported by advertising. We work with third-party ad networks to display ads in the app. Each acts as an independent controller for the data its SDK collects, under its own privacy policy:
use our services](https://policies.google.com/technologies/partner-sites) · Google Privacy Policy · AdMob & personalization.
published in our app-ads.txt at https://leonisfitness.com/app-ads.txt, and is available from us on request.
What our ad partners collect. To show and measure ads, these partners' SDKs collect your device's advertising identifier (Google Advertising ID on Android, IDFA on iOS), other device/app identifiers, IP address, coarse/approximate location, device characteristics, and data about the ads you're shown and click.
Personalized ads. Where you consent, ad partners use this data to show you personalized (interest-based) ads and to measure and cap them. Without consent (or where personalization is unavailable), you'll see non-personalized / contextual ads instead.
Your controls.
through a Google-certified Consent Management Platform built on the IAB Transparency & Consent Framework (TCF v2.2). You can review or change your choices any time in Account & privacy → Ad & privacy settings.
Not to Track", we do not use the IDFA or cross-app tracking to personalize ads.
personalization in your device settings (iOS → Settings → Privacy & Security → Tracking / Apple Advertising; Android → Settings → Privacy → Ads).
We never advertise on your health. We do not share your health, fitness, biometric, menstrual, precise-location, message or other special-category or coaching data with ad partners, and we never use it to target ads. Advertising is supported only by the non-sensitive data described above.
Children. We do not serve personalized ads to users under 16 (or the applicable age of digital consent); any ads shown to them are non-personalized, and we configure our ad partners accordingly (e.g. AdMob "child-directed treatment" / "below age of consent" flags).
You can create or link your account and connect services through third-party platforms. Each is optional and, where you use it, subject to that platform's own terms and privacy policy in addition to ours:
name and email; Apple's Hide My Email private relay may forward a relay address instead of your real one. See the Apple Privacy Policy.
Meta and you choose to use it, we receive only the basic profile data you approve and handle it in line with the Meta Platform Terms and Meta Developer Policies; Meta's own processing is described in the Meta Privacy Policy. We do not currently import your Meta contacts, posts or friends, and we don't use such data for advertising.
strain and activity data you authorize, under WHOOP's terms, and use it only to coach you. Disconnect any time in the app.
To generate coaching responses, plans and insights, relevant context (e.g. your goals, profile summary and the message you send) is processed by our AI providers — Anthropic (directly and/or via the OpenRouter gateway) and, for image generation, Google Gemini via OpenRouter — under their data-processing terms. We send only what's needed to produce the output, and we do not send your email address, authentication tokens, raw Apple Health/Health Connect samples, or precise location to the AI providers, and we do not authorize them to use your content to train their models. Nutrition and product facts may be looked up via USDA FoodData Central and Open Food Facts. See Section 15 on automated decision-making.
When you record an outdoor activity, the app draws your route on a map using the device's map provider (Apple Maps on iOS, Google Maps on Android, via expo-maps) and your GPS location. Route coordinates you save are stored with your account so you can review the activity, and are deleted when you delete your account. Map tiles are served by the map provider under their own terms.
We share data only with vetted processors who act on our documented instructions under data-processing agreements (GDPR Art. 28):
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file/photo storage | Account, profile, plans, logs, photos, tokens |
| Fly.io | Hosting our backend API | All data, in transit and processing |
| Anthropic | AI model inference (coaching) | Coaching context (no email/tokens/raw Health/precise location) |
| OpenRouter | AI gateway routing to Anthropic + Google Gemini | Same as above; image prompts (no personal data) |
| Google (YouTube Data API; Gemini image model; Google Sign-In) | Exercise-video search; image generation; optional login | Public video queries; generic image prompts; login profile/email you approve |
| Apple (Sign in with Apple; App Store; Maps) | Optional login; app distribution; maps on iOS | Login identifier/email you approve; route rendering |
| Meta (if you use Meta sign-in/sharing) | Optional login/sharing | Basic profile you approve |
| USDA FoodData Central · Open Food Facts | Nutrition & product lookups | Food/barcode queries (not tied to your identity) |
| WHOOP (and wearables you connect) | Read the recovery/activity data you authorize | OAuth tokens; the metrics you authorize |
| Expo / EAS | App delivery, over-the-air updates, push notifications | Push tokens, app version, diagnostics |
| Resend | Transactional & (if enabled) opt-in email | Email address, message content |
Advertising partners (independent controllers, not our processors — Section 6A):
| Partner | Purpose | Data involved |
|---|---|---|
| Google AdMob · AppLovin (MAX) · Meta Audience Network (+ networks MAX mediates) | Show, measure, frequency-cap and (with consent) personalize ads | Advertising ID / IDFA, device & app identifiers, IP, coarse location, ad-interaction data — never health, sensitive or coaching data |
We do not otherwise disclose your data except: to comply with law or valid legal process; to protect our rights, our users or the public; or in a merger/acquisition (with notice, and this policy continues to apply). Other than the limited, non-sensitive advertising data we share with the ad partners above (which, for personalized ads, may count as a "sale"/"share" under US law — see Sections 6A and 18 for your opt-out), we do not sell your data, and we never share your health, sensitive or coaching data for advertising.
South Korea (Seoul region, ap-northeast-2).
AppLovin, Meta, e.g. AI inference and platform/ad services) may process data in the United States or other countries.
Where personal data leaves the EEA/UK, we rely on a valid GDPR Chapter V transfer mechanism:
December 2021), so transfers to our Korea-hosted database are permitted without additional safeguards, on essentially the same footing as transfers within the EEA.
States), we rely on the EU Standard Contractual Clauses (and the UK Addendum), plus supplementary measures where needed, or on the provider's Data Privacy Framework certification where applicable.
Depending on where you live (e.g. EEA/UK under GDPR/UK GDPR, California under CCPA/CPRA, and other US states), you have rights to:
Export my data** (a full JSON export), or by contacting us.
same JSON export).
→ Delete my account**, which permanently removes your profile, plans, logs, photos, synced metrics, connected-service tokens and login. You can also email us.
turn off "help improve Leonis"; disconnect a wearable; delete your account).
"share"/"sell" (as US laws define those terms) limited advertising identifiers with our ad partners (Sections 6A, 18). You can opt out any time via Account & privacy → Ad & privacy settings, the iOS App Tracking Transparency prompt, or your device ad settings, and we honor Global Privacy Control signals. We do not sell or share your health, sensitive or coaching data at all, and never use sensitive data beyond providing the service.
subject to solely-automated decisions** with legal or similarly significant effects (Section 15).
supervisory authority (in the EEA/UK, your local Data Protection Authority; in California, the CPPA) — though we'd appreciate the chance to help first.
We respond to verified requests within the timeframes the law requires (generally one month under GDPR; 45 days under CCPA). We don't charge for these rights except where the law allows. You may use an authorized agent where the law permits.
We keep your data while your account is active. When you delete your account we delete or irreversibly anonymize your personal data within 30 days, except where we must retain limited records to meet legal obligations, resolve disputes or enforce agreements. Backups are purged on a rolling 30-day cycle. Aggregated or de-identified data that can no longer be linked to you may be retained.
We protect your data with encryption in transit (HTTPS/TLS), encryption at rest for our database and file storage, per-user row-level security so each user can only access their own data, server-side secret handling, scoped access tokens, and least-privilege access for our team. No system is perfectly secure; if a personal- data breach occurs we will notify the relevant supervisory authority and affected users as required (GDPR Art. 33–34, generally within 72 hours of becoming aware).
Leonis uses deterministic algorithms plus AI to generate suggestions (plans, targets, recovery guidance, exercise/meal swaps). These are recommendations to support your choices, not decisions that produce legal or similarly significant effects on you, and you remain in control of what you do. AI output can be imperfect — always apply judgment, and consult a qualified professional for medical, health or dietary decisions. If you believe an automated output affected you unfairly, contact us for human review.
Leonis is not directed to children under 16 (and never under 13), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it. Where a lower age of digital consent applies in your country, that age governs, subject to the 13-year floor. We do not serve personalized ads to anyone under the applicable age of consent (Section 6A).
With advertising enabled, the mobile app uses advertising identifiers (Google Advertising ID / IDFA) and third-party ad-network SDKs (Section 6A). On iOS we request permission via App Tracking Transparency before any cross-app tracking; if you decline, we do not use the IDFA to personalize ads. In the EEA/UK/Switzerland we gather ad consent through a certified consent tool (Section 6A). You can manage ad personalization in Account & privacy → Ad & privacy settings and in your device settings. Our website uses only strictly-necessary cookies unless you consent otherwise; where we serve web ads or embed third-party content (e.g. YouTube), those providers may set cookies under their own policies (Section 6).
In the past 12 months we have collected the categories described in Section 2 (identifiers; account and profile data; health/biometric and other sensitive information you provide or authorize; commercial/usage data; photos; geolocation you record; internet/advertising activity; and inferences we compute to coach you), for the purposes in Section 3, from the sources in Section 2.
Sale / sharing. For personalized advertising we "share"/"sell" (as the CCPA/CPRA define those terms) a limited set of identifiers — your advertising ID, device identifiers, IP address and ad-interaction data — with our advertising partners (Section 6A) so they can show you interest-based ads and measure them. We do not sell or share your health, biometric or other sensitive personal information, your coaching content, your messages, or your precise location, and we do not use sensitive personal information for these purposes.
Your rights include the right to know, access, delete and correct; to opt out of the sale/sharing of your personal information; and to limit the use of sensitive personal information. Exercise the opt-out through the "Do Not Sell or Share My Personal Information" control in Account & privacy → Ad & privacy settings (or by declining the iOS tracking prompt / your device ad settings); we also honor Global Privacy Control signals. Sensitive data is already limited to providing the service. California residents also have the rights in Section 12, and the right to be free from discrimination for exercising them.
We'll update this page and the Version / Last updated date for changes. For material changes we bump POLICY_VERSION and ask you to re-accept in-app before you continue using affected features.
Questions, requests, or complaints: privacy@leonisfitness.com (or the postal address above). In the EEA/UK you may also lodge a complaint with your local supervisory authority; in California, with the California Privacy Protection Agency.
This document is a good-faith description of how the Leonis app is built and operated. It is not legal advice; have qualified counsel review it for your entity and markets before you launch.