Privacy, in plain language.
This policy explains how LeanLedger handles information in its Android app, website, cloud API, and connected fitness features. LeanLedger is a fitness and general-wellness service, not a medical device.
Information you choose to provide
Core tracking works locally on your Android device. If you create an account or enable connected features, LeanLedger may process:
- Account information: name, email address, a securely hashed password when you choose password sign-in, membership status, session tokens, and short-lived password-recovery records. If you choose Google or Facebook sign-in, LeanLedger also stores the provider name, the provider's stable account identifier, the email and display name returned with your permission, and whether the provider verified the email.
- Fitness and wellness information: workouts, exercise performance, body measurements, weight, body-fat percentage, height, meals, calories, macros, goals, streaks, recovery inputs, and workout-distance summaries.
- Health Connect information: only the categories you authorize, which may include weight, body fat, height, exercise, distance, nutrition, steps, resting heart rate, sleep, and total calories burned. You can revoke these permissions in Android or Health Connect.
- Content you submit: meal descriptions and barcodes, meal photos, and an adult user's own photo when requesting a Future Self image.
- Optional community information: a first name, team label, division, and challenge score when you choose to join a challenge and make your name public.
- Safety records: the version and time of a workout acknowledgement you accept.
How information is used
LeanLedger uses information to create and verify accounts, link a sign-in provider when you request it, provide and synchronize your dashboard, calculate fitness trends, plan workouts and meals, import or export Health Connect records, estimate meal nutrition, generate requested Future Self images, operate challenges, manage memberships, recover accounts, prevent abuse, and provide support.
Google and Facebook sign-in
Social sign-in is optional. Authentication happens on Google or Facebook, and LeanLedger never receives your password for those services. Google or Facebook returns a short-lived authorization result to LeanLedger, which LeanLedger validates before creating a session. LeanLedger uses the provider's stable account identifier—not an email address—as the long-term identity key. Google sign-in requires Google to report a verified email. Facebook confirms control of the Facebook account, but LeanLedger does not treat a matching Facebook email alone as authority to take over an existing LeanLedger account.
Background step access
If your device supports it, LeanLedger separately asks for the Health Connect Read health data in background permission (android.permission.health.READ_HEALTH_DATA_IN_BACKGROUND). This optional permission is used only when Health Connect synchronization is enabled. It lets Android periodically provide LeanLedger with an aggregated total of your steps for the current day while LeanLedger is not on screen, so your dashboard can remain current without keeping the app, GPS, or a continuous sensor listener running.
Android schedules this battery-aware work approximately once per hour and may delay it during Doze or low-battery conditions. LeanLedger stores the resulting daily step total and last-sync time in its private app storage. If you have enabled optional account synchronization, that summary may be included in your synchronized LeanLedger account state the next time synchronization occurs. LeanLedger does not use background Health Connect access for advertising, location tracking, diagnosis, medication decisions, or emergency monitoring.
Photos, AI, and barcode services
Meal and Future Self photos are sent over HTTPS to LeanLedger and processed by a configured AI service provider only when you request those features. Original photos are processed transiently and are not stored by LeanLedger. Generated Future Self images are private account data and up to 12 recent results may be retained. Meal descriptions may be sent to the same provider for a nutrition estimate. A scanned food barcode may be sent to Open Food Facts to retrieve public product information. AI results are estimates and should be reviewed before use.
Sharing
LeanLedger does not sell personal information and does not use it for advertising. Information is disclosed only to service providers that help operate requested features, such as hosting and AI-processing providers; to Google or Facebook when you choose their sign-in service; to Open Food Facts for a barcode lookup; when you deliberately publish limited challenge information; or when required by law. Service providers are permitted to process information only to provide their contracted service.
Social sharing is always initiated and confirmed by you. If you enable scheduled sharing, LeanLedger stores the selected card period, recurrence, date, and time only in private Android app storage. Android uses that information to display a local reminder. Tapping it opens LeanLedger's Share screen; LeanLedger does not publish in the background, choose a destination, or send a post without your confirmation. Disabling the schedule cancels the pending reminder.
Security and storage
Data sent to LeanLedger is encrypted in transit using HTTPS. Passwords are stored as one-way hashes and account data is protected by access-controlled sessions. Social sign-in uses single-use, short-lived state records, browser binding, and PKCE for Google. Password-reset links are single-use, expire after 30 minutes, and are stored by LeanLedger only as one-way token hashes. A successful reset signs the account out on every device. Device data is stored in Android app storage or browser storage. No online service can guarantee absolute security.
Retention and deletion
Local Health Connect summaries, including the current daily step total and last-sync time, remain in private Android app storage until they are replaced, cleared through the app, or removed by uninstalling LeanLedger or clearing its storage. Account and synchronized fitness data is kept while your account remains active. Expired or used password-recovery and social sign-in state records are routinely removed, and any remaining records are deleted with the account. Rate-limit, administrative-audit, and security records may be retained for the time reasonably necessary to operate and protect the service. When you delete your account, the active account record, linked provider identifiers, session tokens, synchronized state, challenge entry, generated images, and associated usage records are deleted. Residual copies in routine disaster-recovery backups may remain for up to 30 days before expiring and are not used for ordinary operations.
You can permanently delete your account at any time on the LeanLedger account deletion page.
Your choices
You may use local Android tracking without an account, choose email/password instead of social sign-in, and manage LeanLedger's access from your Google or Facebook account settings. You may choose which fitness categories synchronize, pause Health Connect synchronization inside LeanLedger, or separately revoke background access or any individual Health Connect permission in Android or Health Connect settings. Revoking background access stops automatic background step updates while leaving any other permissions you keep available for foreground synchronization. You may also leave optional challenges, export synchronized data from the web dashboard, or delete your account. Depending on where you live, you may have rights to access, correct, or object to certain processing.
Children
LeanLedger is intended for adults aged 18 and over. We do not knowingly collect information from children.
Contact
Questions or privacy requests can be sent to alucas@leanledger.fit.