PrivacyTermsSupport

Lean Privacy Policy

Privacy Policy

Lean uses workout logs, recovery data, and health permissions to personalize strength training, recaps, and coaching proposals in the app. This policy also covers the email you submit on this website to join the waitlist.

Last updated October 4, 2026

Data Lean may use

Lean stores account and profile details such as your email, display name, goals, training preferences, and optional profile photo. Lean also stores the workouts, sets, RPE, notes, and pain or form flags you log. Signed-in accounts can sync workout history and body-measurement entries to Lean’s backend, Convex.

Progress check-in photos stay local in the current app. Lean does not upload them for cloud backup or send them for AI analysis. Profile photos and images you choose to attach to Coach use separate upload or request paths.

When external Coach AI is enabled, Lean sends your request and relevant training context through Lean’s server to our cloud AI partner. This can include workout summaries, goals, pain or form notes, available recovery context (such as Apple Health sleep and heart-rate data), your logged weight trend, recent conversation, proposal decisions, imported workout summaries, and attachments you choose to include. Coach can receive the count and timing of progress photos without their image content.

If you grant Apple Health access, the current build may read weight, body measurements, height, date of birth, biological sex, workouts, active energy, heart-rate data, sleep, resting heart rate, and heart-rate variability to personalize plans and recaps. On iOS 26, Lean may add a workout record for an eligible completed strength workout after saving it locally, when the rollout is enabled and you allow workout writing. That record does not include sets, reps, RPE, notes, heart-rate zones, or estimated calories. It contains no richer workout details. Lean can also write eligible weight, body-fat, lean-body-mass, and waist measurements that you record in Lean to Apple Health, after saving them locally and obtaining write permission for each measurement type. Measurement export can be paused. Imported Apple Health values and photo-based body-fat estimates are excluded from these writes. Lean does not connect to, import from, or send data directly to WHOOP. WHOOP may independently read the eligible workout record from Apple Health if you configure that access outside Lean.

Waitlist

When you join the waitlist on this website, Lean stores the email address you submit, along with a short non-identifying source tag and the referring page (referrer), in our backend (Convex). This information is used only to email you when early access opens. It is not used for advertising and is not sold. To be removed from the waitlist, email hello@liftwithlean.com.

How data is used

Your data is used to personalize your training, summarize completed workouts, and surface coaching proposals. Lean does not sell personal health or workout data.

App diagnostics

Lean sends crash, hang, and error reports to Convex to diagnose problems and improve app reliability. Reports can include the app and operating-system version, time, error messages, and stack traces. Lean filters these reports to remove common identifiers and secrets before sending and storing them. Reports sent while signed in can be linked to your account; reports can also be sent before sign-in. App diagnostics are separate from optional website analytics.

Optional website analytics

If you choose Allow analytics on this website, Google Analytics 4 records sanitized page views for the public landing page, landing route, and privacy page (/, /landing, and /privacy), plus whether a valid waitlist submission was attempted or a new signup succeeded and whether it came from the first or final signup section. PostHog records a limited, pseudonymous product funnel: coarse onboarding goal and routine categories, plan creation, paywall and purchase steps, workout start or completion, and Coach proposal lifecycle and scope categories. These events do not include workout contents, exercise values, workout or proposal identifiers, counts, health data, notes, or other free text.

Lean does not send your email, current browser URL, query, hash, referrer, or Lean account or app user ID to these analytics services. Google Analytics receives a fixed eligible-page location and title instead. If enabled, Google Analytics uses its own pseudonymous client and session identifiers to distinguish visits. It may also process a device category and approximate location derived from network information. Advertising personalization, Google Signals, automatic page views, session recording, and autocapture are disabled.

Analytics is off until you opt in. If enabled, Google may set _gacookies to distinguish visits. You can select Privacy choices on the landing or privacy page to withdraw consent; Lean then stops future browser-based Google Analytics and PostHog collection and removes accessible Google Analytics cookies. Lean does not send Stripe customer, checkout, subscription, or invoice identifiers to PostHog from billing webhooks. Lean’s GA4 setup uses a two-month event-data retention period. These records are used to improve the signup experience, not for advertising.

Data retention

Lean keeps your logged data and account while your account is active. When you delete your account, the associated data is removed. Limited operational logs may persist briefly.

Deletion and control

You can delete your account and its data in the app at Settings → Account (tap your name) → Delete account or by emailing hello@liftwithlean.com. You can revoke Apple Health and other permissions at any time in system settings. Coaching changes are proposals and require your approval before they affect training.

The in-app export at Settings → Your data → Export data on this iPhone creates a copy of workout history, progress entries and photos, and milestones currently stored on that iPhone. It is not a complete cloud-account export. To request a copy of other personal data associated with your account, email hello@liftwithlean.com.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data. To exercise any of these, email hello@liftwithlean.com. Lean’s processors (Convex, our cloud AI partner, Superwall, Stripe, PostHog, Google Analytics) are US-based, so your data may be processed in the United States.

Third-party processors

Lean uses Convex for backend storage and sync, our cloud AI partner to power coaching proposals and chat, Superwall to manage subscriptions and the paywall, Stripe to process web billing, PostHog for consented coarse product-funnel analytics, and Google Analytics for consented, limited, manually captured eligible-page views and waitlist analytics. Autocapture, session recording, automatic page views, Google Signals, and advertising personalization are not used. These providers support the functions described above.

Security

Your data is stored with reputable infrastructure providers under access controls and is encrypted in transit. No method of storage or transmission is perfectly secure, but Lean works to protect your information.

Children

Lean is not directed to children under 13, or under the minimum age required in your country. Do not use Lean if you are under that age.

Changes

Lean may update this policy from time to time. The last updated date above reflects the current version, and continued use after that date means you accept the updated policy.

Contact

For privacy or support questions, contact hello@liftwithlean.com.