Privacy Policy

Last Updated: January 10, 2026

1. Introduction

Welcome to Levorofit ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fitness and wellness platform (the "Service").

By using Levorofit, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us, including:

  • Account Information: Email address, username, password (hashed and encrypted)
  • Profile Information: Gender, date of birth, country, height, weight, fitness goals, activity level
  • Health and Fitness Data: Weight logs, sleep logs, meal logs, exercise records, calorie intake, fitness goals
  • Google Account Integration: If you choose to connect your Google account, we may access your Google email, name, and profile picture

2.2 Automatically Collected Information

When you use our Service, we automatically collect certain information:

  • Usage Data: Pages visited, features used, time spent on the platform
  • Device Information: Device type, operating system, browser type, IP address
  • Location Data: General location information (city/country level) for gym finder features
  • Cookies and Tracking Technologies: We use cookies to enhance your experience and analyze usage patterns

2.3 Google User Data

If you choose to connect your Google account, we access the following Google user data through Google APIs:

This section complies with Google API Services User Data Policy and Google APIs Terms of Service.

2.3.1 Data Accessed

We access the following types of Google user data:

  • User Profile Information: Your Google account email address, full name, and profile picture (accessed via https://www.googleapis.com/auth/userinfo.profile and https://www.googleapis.com/auth/userinfo.email scopes)
  • Google Calendar Events: We access your Google Calendar to read existing events and create new meal plan events (accessed via https://www.googleapis.com/auth/calendar.events scope)
  • OAuth Tokens: We securely store OAuth 2.0 access tokens and refresh tokens to maintain your Google account connection

Note: We only access Google user data that you explicitly authorize through Google's OAuth consent screen. You can revoke access at any time through your Google Account settings.

2.3.2 Data Usage

We use Google user data solely for the following purposes:

  • Account Authentication: Your Google email and profile information are used to create and authenticate your Levorofit account, eliminating the need for a separate password
  • Profile Personalization: Your Google name and profile picture are used to personalize your Levorofit profile and dashboard experience
  • Meal Plan Calendar Integration: We create calendar events in your Google Calendar for your personalized meal plans (breakfast, lunch, dinner) to help you stay organized and track your nutrition schedule
  • Calendar Event Management: We read your existing calendar events to avoid scheduling conflicts and delete old meal plan events when you generate a new meal plan

We do NOT: Use Google user data for advertising purposes, sell Google user data to third parties, or use Google user data for any purpose other than those explicitly stated above.

2.3.3 Data Sharing

We do NOT share your Google user data with any third parties, except in the following limited circumstances:

  • Service Providers: We use Google Cloud Platform (GCP) for hosting and data storage. Google user data stored on GCP is subject to Google's data processing agreements and security measures. We do not grant third parties access to your Google user data beyond what is necessary to provide our Service.
  • Legal Requirements: We may disclose Google user data if required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users.

Important: We do not sell, rent, or monetize your Google user data. We do not use your Google user data for advertising or marketing purposes. We do not share your Google user data with data brokers or analytics companies.

2.3.4 Data Storage & Protection

We implement the following security measures to protect your Google user data:

  • Encrypted Storage: All Google user data, including OAuth tokens, is stored in encrypted databases on Google Cloud SQL (MySQL) with encryption at rest
  • Secure Transmission: All data transmission between your device and our servers uses HTTPS/TLS encryption (TLS 1.2 or higher)
  • Token Security: OAuth access tokens and refresh tokens are stored securely in our database and are never exposed in URLs, logs, or client-side code
  • Access Controls: Only authorized Levorofit servers can access Google user data. Access is restricted to authenticated requests and logged for security auditing
  • Regular Security Audits: We conduct regular security assessments and vulnerability scans to ensure the security of your data
  • Compliance: We comply with Google API Services User Data Policy, Google APIs Terms of Service, and applicable data protection regulations (GDPR, CCPA, etc.)

Data Location: Your Google user data is stored on Google Cloud SQL servers located in secure data centers. We do not store Google user data on local servers or unsecured storage systems.

2.3.5 Data Retention & Deletion

Our data retention and deletion practices for Google user data:

  • Retention Period: We retain your Google user data (email, name, profile picture, OAuth tokens) for as long as your Levorofit account is active and you maintain your Google account connection. If you disconnect your Google account, we will delete your Google OAuth tokens immediately, but we may retain your email address if you continue to use Levorofit with email/password authentication.
  • Calendar Events: Meal plan events created in your Google Calendar remain in your Google Calendar until you delete them manually or we delete them when you generate a new meal plan. We do not retain copies of calendar events in our database beyond what is necessary to manage event creation and deletion.
  • Account Deletion: When you delete your Levorofit account, we will permanently delete all Google user data from our systems within 30 days, including:
    • Google email, name, and profile picture stored in our database
    • OAuth access tokens and refresh tokens
    • Any cached Google user data
  • Data Deletion Requests: You can request deletion of your Google user data at any time by:
  • Deletion Timeline: Upon receiving a deletion request, we will delete your Google user data from our systems within 30 days. Note that calendar events created in your Google Calendar will remain in your Google Calendar until you delete them manually.

Your Rights: You have the right to access, correct, or delete your Google user data at any time. You can also revoke our access to your Google account through your Google Account settings, which will immediately stop us from accessing new Google user data.

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, maintain, and improve our Service
  • To personalize your fitness and wellness experience
  • To generate personalized meal plans, workout recommendations, and health insights
  • To track your progress toward fitness goals
  • To communicate with you about your account, updates, and promotional offers
  • To process payments and manage subscriptions
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our Terms of Service
  • To conduct research and analytics to improve our Service

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We may share information with third-party service providers who perform services on our behalf, such as:

  • Cloud hosting and data storage providers
  • Payment processors
  • Email service providers
  • Analytics and performance monitoring services

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption of sensitive data in transit and at rest
  • Secure password hashing (bcrypt/argon2)
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Secure database connections and data storage

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

6. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

6.1 Access and Portability

You can access, update, or export your personal information through your account settings or by contacting us.

6.2 Deletion

You can request deletion of your account and associated data by contacting us at privacy@levorofit.com.

6.3 Opt-Out

You can opt out of marketing communications by clicking the unsubscribe link in our emails or adjusting your notification preferences in your account settings.

6.4 Cookie Preferences

You can manage cookie preferences through your browser settings. Note that disabling cookies may affect certain features of our Service.

6.5 GDPR Rights (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the right to:

  • Request access to your personal data
  • Request correction of inaccurate data
  • Request erasure of your data ("right to be forgotten")
  • Object to processing of your data
  • Request restriction of processing
  • Data portability
  • Withdraw consent at any time

7. Data Retention

We retain your personal information for as long as necessary to provide our Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.

8. Children's Privacy

Our Service is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete such information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. We take appropriate safeguards to ensure your information is protected in accordance with this Privacy Policy.

10. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@levorofit.com

Address: Dwarka, New Delhi, India

Phone: +91 94748 32694