Lupora is built on sensitive data — your training, your health signals, your progress photos. This policy explains exactly what we collect, why, who processes it, how long we keep it, and the controls you have.
If you only read one thing: we never sell your data, never show you ads, never share your data with advertisers or data brokers, and never use your Apple Health data for anything except the health and fitness features you asked for.
1. Who we are
Lupora is a personal training app for iPhone that builds workout plans around how recovered your body actually is. This policy covers the Lupora iOS app and the Lupora cloud services that power it.
Lupora LLC, a Virginia limited liability company, is the controller of the personal data described here.
- Privacy questions and requests: privacy@lupora.com
- Everything else: support@lupora.com
- Postal address: Lupora LLC, 8401 Mayland Dr, Ste A, Richmond, VA 23294-4648, United States
2. The short version
| What | Where it goes | How long |
|---|---|---|
| Account (name, email, account ID) | Our servers | Until you delete your account |
| Profile (birthday, goal, experience, height, optional gender and photo) | Our servers, encrypted | Until you delete your account |
| Apple Health signals (sleep, HRV, heart rate, steps, energy, weight, workouts) | Read on your device; only what's needed for a request is sent to our servers, encrypted | Readiness history prunes automatically after 90 days |
| Workouts and plans | Our servers, encrypted | Until you delete them or your account |
| Check-ins (feelings, optional cycle phase, optional note, optional photos) | Our servers, encrypted | Until you delete them or your account |
| Usage analytics (optional, switchable off) | Firebase Analytics | Per Firebase retention settings |
| Crash reports | Firebase Crashlytics | Per Crashlytics retention |
| Feedback you send us | Our servers, then a private GitHub issue | Screenshots 30 days; report metadata 180 days |
| Notification token (only if you enable push) | Our servers and Apple's push service | Until you disable notifications or delete your account |
3. What we collect
We collect only what the app's features need.
Account. When you sign in with Apple, we receive your name and email address — or Apple's private relay address, if you choose to hide your real one — and a unique account identifier. We never see your Apple password.
Profile. What you enter: birthday, training goal, experience level, height, preferred units, and optionally your gender and a profile photo. Gender is used only to tailor starting-weight suggestions and check-in questions, and you can leave it unset.
Health signals from Apple Health. With your permission, Lupora reads: sleep analysis, heart-rate variability, heart rate, resting heart rate, steps, active energy, body weight, height, and completed workouts. These are used to compute your daily readiness and to personalize your plans. If you allow it, Lupora also writes workouts you completed in the app back to Apple Health, and can schedule planned workouts to your Apple Watch.
Workouts. The plans you create or generate and what you complete — exercises, sets, weights, reps, and durations.
Weekly check-ins. How you're feeling (chosen from a fixed list), an optional menstrual-cycle phase, an optional free-text note to your trainer, and optional progress photos.
Trainer conversation. The multiple-choice answers you give when building a plan, plus any optional note you add.
Usage analytics (optional). Anonymous behavior events — which screens you view, which features you use, and counts such as how many exercises a workout had. Analytics never include health values, photos, check-in answers, workout or exercise names, free text, names, or emails. This is enforced structurally in our code, not just by policy: every event is checked against an allowlist of fixed values, booleans, and bounded numbers, and a test fails the build if anything else appears. Analytics are on by default and you can turn them off at any time in Settings → Privacy.
Crash reports. If the app crashes, Firebase Crashlytics sends us the crash, your device model, and OS version so we can fix it.
Feedback you choose to send. If you use the in-app feedback form, we receive your description, a screenshot if you attach one, and a small diagnostic snapshot (app version, device model, OS version, locale). The diagnostic snapshot never includes health data, check-in content, workout content, your identity, or authentication tokens.
Notifications. Lupora can remind you about workouts and check-ins. Today these are local notifications, scheduled and delivered entirely on your device — nothing about them reaches our servers. If you enable notifications that we send from our side (push notifications), Apple issues a device token that we store and use only to deliver those messages through Apple's Push Notification service. A push token identifies a device installation, not you personally, and we never put health data, check-in content, or workout content in a notification's payload. You can turn notifications off at any time in iOS Settings, and deleting your account deletes any stored token.
Device integrity. Before our servers accept a request, the app proves it is a genuine, unmodified copy of Lupora using Apple's App Attest. This produces an attestation, not information about you.
What we don't collect: we do not use advertising identifiers (no IDFA), we do not track you across other apps or websites, we do not collect your precise location, and we do not use tracking cookies.
4. How we use your data, and our legal bases
Your data is used to run Lupora's features for you — nothing else.
| Purpose | Data used | Legal basis (GDPR / LGPD) |
|---|---|---|
| Computing your daily readiness | Health signals | Explicit consent (health data) |
| Building and adjusting training plans | Profile, workouts, check-ins, health signals | Performance of our contract with you; explicit consent for health data |
| Analyzing progress photos you submit | Photos you choose to send | Explicit consent |
| Showing you your own history and progress | Workouts, check-ins, weight | Performance of our contract |
| Keeping the service secure and within quota | Account ID, request counts, attestation | Legitimate interests |
| Fixing crashes and bugs | Crash reports, feedback you send | Legitimate interests |
| Improving the app | Optional analytics | Consent (you can switch it off) |
| Meeting legal obligations | As required | Legal obligation |
You can withdraw consent at any time — revoke Health access in the iOS Health app, switch analytics off in Settings, delete individual check-ins and photos, or delete your account entirely.
5. AI processing
Lupora's coaching intelligence runs on Google's Gemini models hosted on Google Cloud (Vertex AI). To build a plan or analyze a check-in, the relevant inputs — your answers, health signals, check-in details, and any photos you submitted — are processed by these models on our behalf.
- Google acts as our data processor. Under Google Cloud's terms, this data is not used to train Google's models.
- Progress photos are analyzed once, at upload, and are never re-sent to the model afterwards. Later coaching uses only the short structured insights derived from them.
- Photos are screened for safety before analysis; a photo that fails screening is rejected rather than analyzed.
- The model never receives your name, email, or account identifier.
- AI output can be wrong. It is guidance, not medical advice — see the Terms of Service.
6. Apple Health
Health access is entirely optional and controlled by you.
- Lupora reads only the categories you approve, and asks for write access only to save workouts you completed in Lupora.
- Apple Health data stays on your device except where a specific feature needs it — readiness and plan generation send the relevant recent signals to our servers, encrypted.
- We never use Apple Health data for advertising, marketing, or data mining, and we never share it with third parties for those purposes, as Apple's rules require.
- You can review or revoke Lupora's Health access at any time in the iOS Health app under Sharing → Apps.
7. Who we share data with
We do not sell your personal data, and we do not share it for advertising. We use a small number of processors who handle data on our instructions:
| Processor | What they process | Why |
|---|---|---|
| Google Cloud / Firebase (Google LLC) | Account identity, encrypted app data, photos, analytics, crash reports | Hosting, database, authentication, app integrity, analytics, crash reporting |
| Google Vertex AI (Gemini) | Plan inputs, check-in content, photos at upload | Generating plans and check-in insights |
| Apple | Sign in with Apple identity, App Attest | Sign-in and app integrity |
| GitHub (Microsoft) | Only the feedback reports you choose to send | Tracking bugs you report, in a private repository |
We may also disclose data if we are legally required to, or to protect the rights, safety, or property of Lupora, our users, or the public. If we are ever part of a merger or acquisition, your data may transfer to the successor, and we will tell you before it becomes subject to a different privacy policy.
8. Storage and security
- All traffic between the app and our servers uses TLS (HTTPS).
- Sensitive content — health signals, workouts, check-in answers, cycle information, free-text notes, and progress photos — is additionally encrypted at rest with AES-256-GCM by our own application layer, on top of Google Cloud's storage encryption. Photos are stored as individually encrypted records.
- Your name and email remain readable so your account can be identified and supported.
- Every request to our servers requires both a valid sign-in and a passing Apple App Attest check; requests are rate-limited per account.
- Access to production systems is restricted and authenticated.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
9. Retention and deletion
- You can delete your account entirely from inside the app: Settings → Delete Account. This revokes Lupora's Sign in with Apple grant, permanently erases your profile, workouts, check-ins, photos, readiness history, and feedback reports from our servers, deletes your login, and wipes the data on your device.
- Deleting a single check-in also deletes its photos and insights.
- Readiness history is pruned automatically after 90 days.
- Feedback screenshots are deleted after 30 days; feedback report metadata is kept for 180 days. A GitHub issue created from your feedback contains only the sanitized subset described above and follows our repository retention.
- Data you keep in Apple Health belongs to your device and Apple account — deleting your Lupora account does not touch it.
- Backups may persist for a short period after deletion before they age out.
10. Where your data is processed
Lupora's servers run in the United States (Google Cloud, us-central1). If you use Lupora from the European Economic Area, the United Kingdom, Switzerland, or Brazil, your data is transferred to the United States. These transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) in our agreements with Google, together with the technical measures described in section 8.
11. Your rights
Depending on where you live, you have some or all of these rights: to access your data, correct it, delete it, export it in a portable format, restrict or object to processing, withdraw consent, and not be discriminated against for exercising them.
Most of these controls are built into the app: your profile is editable, analytics are switchable, Health access is revocable, individual check-ins and photos are deletable, and account deletion is self-serve. For anything else — including a copy of your data — email privacy@lupora.com and we will respond within 30 days (or sooner where the law requires).
EEA, UK, and Switzerland (GDPR). Legal bases are listed in section 4. You have the right to lodge a complaint with your local supervisory authority.
Brazil (LGPD). You have the rights described above, including confirmation of processing, anonymization, and information about data sharing.
Virginia (VCDPA), California (CCPA/CPRA), and other US states. You may access, correct, delete, and obtain a copy of your personal data, and appeal a denied request by replying to our response. We do not sell personal information and we do not share it for cross-context behavioral advertising — including for consumers under 16. California residents may also designate an authorized agent.
Washington, Nevada, and Connecticut consumer health data. See our separate Consumer Health Data Privacy Notice, which Washington's My Health My Data Act requires us to publish separately.
12. Children
Lupora is for adults. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact privacy@lupora.com and we will delete it.
13. Changes to this policy
When we change this policy in a meaningful way, we will update the date at the top and, for significant changes, tell you in the app before they take effect. Continued use of Lupora after a change means the updated policy applies.
14. Contact
Questions, requests, or concerns about your privacy: privacy@lupora.com.
Lupora LLC · Virginia, USA