Privacy Policy
LazyFit is in private beta. We use account, profile, nutrition, training, progress, feedback, and safety metadata only to operate and improve the service. We do not sell personal data.
Where data is processed
Supabase stores LazyFit's authentication and application database in the EU (Paris, France). Vercel hosts the web application and operational logs on provider-operated infrastructure. PostHog analytics, when allowed, uses its EU service. Food and exercise lookups may contact Open Food Facts, USDA FoodData Central, or ExerciseDB with a bounded food, barcode, or canonical exercise query and no LazyFit account identity.
Food AI
When you choose Food AI, LazyFit sends the meal text, reviewed voice transcript, correction, and bounded editable-draft facts needed to build an estimate to DeepSeek's API. We do not send your LazyFit user ID, email address, or raw microphone audio. Common contact and account-like identifiers are removed before transfer.
DeepSeek processes submitted text under its own terms and privacy policy, which describes processing and storage in China without a fixed API deletion period. LazyFit does not claim zero retention, a training opt-out, region-only processing, or a custom data-processing agreement. Because requests contain no LazyFit user identifier or provider record ID, LazyFit cannot selectively export or delete an already completed DeepSeek request. We can stop future processing and escalate a verified request to the provider, but provider-held content remains subject to its rules and legal exceptions. Do not include personal, medical, or account information in a food description.
Anthropic is disabled and is not a Food AI fallback. Vercel hosts LazyFit, but the optional Vercel AI Gateway is not currently in the production Food AI request path. Production text requests go directly from LazyFit's server to the pinned DeepSeek V4 Flash model.
Image analysis is not currently available. Selected images are re-encoded locally to remove embedded metadata, but the current server path asks you to describe the food in text, use search, or enter it manually. Voice entry uses the browser or operating-system speech service; LazyFit receives only the transcript after you submit it. Every AI estimate requires review before logging.
Optional product analytics
LazyFit does not load PostHog until you choose Allow analytics. With consent, PostHog receives typed product events, flow timing, and errors under your Supabase account UUID as its distinct identifier. Events exclude email, names, passwords, raw food text, voice transcripts, measurements, diary text, prompts, and request bodies. Session replay is disabled.
Consent can also create a private authoritative food-demand observation: a bounded normalized food, product, or valid barcode, lookup surface, miss category, and one-way account bucket. LazyFit accepts at most one observation per account, demand tuple, and UTC day and physically deletes observations after 180 days. Rankings use only the rolling previous 180 days. Browser-supplied demand is never authoritative. Historical PostHog demand events are non-authoritative. PostHog demand events are not used for catalog decisions.
Withdrawing consent stops future capture and removes identifiers from that browser, but does not itself erase earlier PostHog events or accepted authoritative demand. Account deletion separately queues PostHog person, event, and recording deletion for the UUID and erases authoritative demand rows for the account's one-way bucket. PostHog deletion is asynchronous and is verified by the operator workflow.
Retention
- Account and app content: while the account is active, then removed by the verified deletion workflow.
- AI request metadata, API-abuse records, and exercise-provider request records created from August 14, 2026: 35 days. These stores contain bounded telemetry, not raw prompts or IP addresses.
- A bounded set of older AI request metadata is under a separately authorized legacy-cleanup hold. It is not covered by the new 35-day automation and contains no raw prompt, response, media, IP address, token, or provider secret. Account deletion still removes linked rows of any age.
- Authoritative food-demand observations are physically deleted after 180 days by the daily database cleanup.
- Active workout browser drafts: owner-scoped for up to 24 hours and cleared on sign-out, account switch, completion, discard, expiry, or malformed data.
- Shared food/exercise catalogs and provider caches: retained until source replacement or quality retirement. They are not keyed to an account and cannot be selectively deleted as user data.
- Vercel, Supabase, DeepSeek, and other provider operational logs: provider/plan-controlled. LazyFit minimizes identifiers and content but cannot promise user-selective log deletion.
- Encrypted database backup artifacts: 35 days. Deleted rows can remain only in inaccessible disaster-recovery copies until the last pre-deletion artifact expires.
- Completed deletion audit: a one-way HMAC request key, timestamps, safe result codes, and row counts for 365 days after backup aging. Email, UUID, prompts, and deleted content are not retained in that completed record.
Export and deletion
Profile provides a JSON export of LazyFit-controlled live account data, authoritative demand linked by the private account bucket, and counts for security metadata. It excludes shared catalogs/caches, provider logs that LazyFit cannot selectively export, and backup artifacts that are not live stores.
An authenticated deletion request requires your exact account email plus DELETE. LazyFit records a durable request, globally revokes refresh sessions, locks new sign-ins, and then runs provider acceptance, transactional application and derived-data deletion, Auth deletion, verification, and backup aging in that order. Access tokens already issued on another device can remain valid until their short expiry. Failures are retried from the durable step ledger; completed live deletion never waits silently on a failed provider step.
The account hold is attempted immediately, processing starts within 24 hours, and live-store/provider deletion is targeted within 30 days. Provider or legal blocks are reported instead of being shown as complete. The separate 35-day backup-aging period starts after verified live deletion.
Download your export before requesting deletion. For a request ID, provider question, correction, or access request, email lazyfitapp@gmail.com.