Privacy Policy
Last updated: August 8, 2026
This policy explains how fitleo collects, uses and protects your personal data when you use our website and mobile application. We take your privacy seriously and comply with the General Data Protection Regulation (GDPR).
1. Who we are
fitleo is operated personally by Alexandre Henrotte, a natural person residing at 6730 Tintigny, Belgium. No commercial entity is registered at this stage: the service is provided privately during the launch phase. Contact: fitleo.app@gmail.com.
2. Data we collect
We only collect data necessary to run the coach:
- Identity: name, email, optional profile picture, identifier from your login provider (Apple, Google).
- Fitness profile: goal, level, training days, session duration, equipment, locations, weight, height, date of birth, gender.
- Workout activity: sessions completed, exercises, sets, reps, loads, personal records, body measurements.
- Conversations with Leo: messages exchanged with Leo and facts memorised to personalise its responses.
- Technical: timezone, language, Expo push token, subscription identifier, anonymised technical logs.
3. Purposes and legal basis
- Contract performance (art. 6.1.b GDPR): deliver the service, generate your program, personalise coaching.
- Legitimate interest (art. 6.1.f): security, abuse prevention, product improvement.
- Legal obligation (art. 6.1.c): billing, fraud prevention.
- Consent (art. 6.1.a): push notifications, marketing communications (revocable at any time).
4. Sub-processors
We share some data with providers who help us run the service:
- Supabase (database hosting, authentication): EU (Ireland).
- Google / Gemini API (engine powering Leo): transfers covered by Standard Contractual Clauses.
- Mem0 (long-term coach memory): SCCs.
- Vercel (web hosting): SCCs.
- Expo (mobile push notifications).
- RevenueCat (subscription management).
- Loops (transactional email delivery).
- PostHog (product analytics: which screens are used, to improve the app): EU.
- Sentry (crash and error reports): SCCs.
- AppsFlyer (marketing attribution: which campaign led you to install the app): SCCs. On Android this relies on the advertising identifier (
AD_IDpermission).
None of these processors resell your data. We sign a GDPR-compliant data processing agreement with each of them.
5. AI processing
Leo is powered by artificial intelligence. The app asks for your explicit consent on a dedicated screen during onboarding, and nothing is sent to an AI provider before you accept.
What is sent:
- Your messages to Leo, including photos you attach, screenshots of a training plan you import, and photos of machine labels you scan.
- Your fitness profile: first name, age, gender, weight, height, goal, level, availability, equipment, sports practised, and any sensitive areas you reported.
- Your training history: workouts, exercises, sets, reps, loads, personal records and body measurements, when they are relevant to Leo's answer.
- Voice dictation: if you dictate a message, the audio recording is transcribed.
Who receives it: Google, through the Gemini API, generates Leo's answers; Mem0 stores the facts Leo needs to remember about you from one conversation to the next. Both act as processors, on our instructions only, under a GDPR-compliant data processing agreement that binds them to protections equivalent to those described in this policy. Neither uses your data for its own purposes, resells it, nor uses it to target you with advertising.
You can erase everything Leo remembers about you at any time from the app settings, and delete your entire account from the same place.
6. Retention
- Active account: as long as you use fitleo.
- Deleted account: full erasure within 30 days (except legal accounting retention).
- Technical logs: 90 days maximum.
7. Your rights
Under GDPR you have the following rights:
- Access: know what data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: request complete deletion of your account (directly from the app, Account section).
- Portability: receive your data in a structured format.
- Object: refuse certain processing (notably marketing).
- Restriction: freeze processing in certain cases.
- Withdraw consent at any time.
To exercise these rights, write to fitleo.app@gmail.com. We reply within 30 days. You may also lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
8. Security
Your data is encrypted in transit (HTTPS/TLS) and at rest (database encryption). Internal access is limited to staff who need it. No system is perfect: in case of a breach, we will notify you as required by GDPR.
9. Cookies
The fitleo website only uses a functional cookie fl_lang to remember your language preference. No advertising cookies, no third-party trackers. The mobile app does not use cookies.
10. Transfers outside the EU
Some processors (Gemini, Mem0, RevenueCat, Expo, Sentry, AppsFlyer) are based in the United States. Transfers are governed by Standard Contractual Clauses issued by the European Commission, complemented where needed by supplementary technical safeguards.
11. Minors
fitleo is restricted to users aged 9 or older. If you believe a minor under 9 has created an account, contact us and we will delete it.
12. Changes
We may update this policy to reflect legal or product changes. For substantial changes we will notify you by email or in-app at least 30 days in advance.
13. Contact
Questions about your data? fitleo.app@gmail.com
