Privacy Policy
Last updated: 18 July 2026
1. Who we are
The controller of your personal data is Loyalty LT, MB, legal entity code 307165534, registered address Chemijos g. 27C-62, LT-51332 Kaunas, Lithuania, email info@loyalty.lt. We process data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the laws of the Republic of Lithuania. Exception – health data provided during remote healthcare consultations: its controller is the licensed healthcare institution providing the consultation, and we process such data only on its behalf as a processor.
2. What data we process and why
We process the following categories of data, with these purposes and legal bases:
- Account data – name, email, sign-in identifiers via Google, Apple or Facebook; to create and administer your account (performance of a contract).
- Profile data – age, sex, height, weight, training goals, equipment and nutrition preferences; for personalised plans and calculations (contract; and for health-related data – your explicit consent).
- Activity data from Apple HealthKit and Android Health Connect – steps, active calories and other metrics you allow; for your activity overview (explicit consent). If you connect third-party wearable accounts (Withings, Fitbit, Garmin), we receive selected data from them with your permission. This data is never used for advertising and never sold.
- Body-composition data – parameters you provide and scan photos. Photos are processed on your device; only the computed results are transmitted and stored on our servers (explicit consent).
- Workout and usage data – completed workouts, progress, choices; to provide and improve the service (contract).
- AI features – to generate plans and recommendations, your profile and goal data are sent to our AI providers (Google – Gemini, and Anthropic – Claude). The data is used only to generate the response and is not used to train AI models.
- Consultation data – bookings, times, video technical data. Video consultations are not recorded unless you explicitly agree.
- Payment data – subscription status from the Apple App Store / Google Play (via RevenueCat). We do not receive or store card details.
- Technical and error data – device model, OS and app version, error logs (via Sentry); for stability and security (legitimate interest).
- Notifications – device token for push notifications and email for service messages. Marketing messages are sent only with your consent.
3. Who we share data with
For remote health consultations, we transfer the necessary data to the licensed institution providing the consultation as controller. We may disclose data to public authorities where required by law. Some providers process data outside the European Economic Area (USA) – in such cases the safeguards of GDPR Chapter V apply (the EU–US Data Privacy Framework or standard contractual clauses). We use the following processors and providers:
- Server hosting – Hostinger.
- Object storage – Cloudflare R2.
- Content delivery network and DNS – Cloudflare.
- Video infrastructure – LiveKit.
- Subscription management – RevenueCat.
- Error monitoring – Sentry (EU).
- AI services – Google and Anthropic.
- Email delivery – Brevo and our own mail server.
- Payment and distribution – Apple, Google. Sign-in is provided by Google, Apple and Meta under their own privacy policies.
4. How long we keep data
Account and profile data are kept while you have an account and deleted no later than 30 days after account deletion, except data we must retain by law (e.g. accounting records – 10 years). Body-composition results and activity data are kept until you delete them or while you have an account. Error logs – up to 90 days. Marketing consents – until withdrawn.
5. Your rights
Submit requests by email to info@loyalty.lt or in the app settings – we will respond within 30 days. If you believe your rights have been infringed, you may lodge a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, Vilnius, www.vdai.lrv.lt), though we are always happy to resolve the matter directly. You have the right to:
- access your data and obtain a copy;
- have inaccurate data corrected;
- have data erased (the “right to be forgotten”);
- restrict processing;
- receive your data in a portable format;
- object to processing based on legitimate interest;
- withdraw consent at any time (this does not affect the lawfulness of processing before withdrawal).
6. Security
We apply technical and organisational security measures: encrypted data transfer (TLS), access control, access logs, backups and regular security reviews.
7. Children’s data
The app is intended for persons aged 16 and over. We do not knowingly collect data from younger children; if we learn that such data has been provided, we will delete it.
8. Changes to this policy
We will inform you of material changes to this policy in the app or by email before they take effect. The current version is always published in the app and on avitra.app.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at hello@avitra.app