Privacy Policy

Last updated: 27 August 2026

1. Who we are

The controller of your personal data is Loyalty LT, MB, legal entity code 307165534, registered address Chemijos g. 27C-62, LT-51332 Kaunas, Lithuania, email info@loyalty.lt. We process data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the laws of the Republic of Lithuania. Exception – health data provided during remote healthcare consultations: its controller is the licensed healthcare institution providing the consultation, and we process such data only on its behalf as a processor.

2. What data we process and why

We process the following categories of data, with these purposes and legal bases:

  • Account data – name, email, sign-in identifiers via Google, Apple or Facebook; to create and administer your account (performance of a contract).
  • Profile data – age, sex, height, weight, training goals, equipment and nutrition preferences; for personalised plans and calculations (contract; and for health-related data – your explicit consent).
  • Activity data from Apple HealthKit and Android Health Connect – steps, active calories and other metrics you allow; for your activity overview (explicit consent). If you connect third-party wearable accounts (Withings, Fitbit, Garmin), we receive selected data from them with your permission. This data is never used for advertising and never sold.
  • Body-composition data – parameters you provide and scan photos. Photos are processed on your device; only the computed results are transmitted and stored on our servers (explicit consent).
  • Workout and usage data – completed workouts, progress, choices; to provide and improve the service (contract).
  • AI features – to generate plans and recommendations, your profile and goal data are sent to our AI providers (Google – Gemini, and Anthropic – Claude). The data is used only to generate the response and is not used to train AI models.
  • Consultation data – bookings, times, video technical data. Video consultations are not recorded unless you explicitly agree.
  • Payment data – subscription status from the Apple App Store / Google Play (via RevenueCat). We do not receive or store card details.
  • Usage statistics – which app or website screens you open, which features you use, where an error occurs, device type and app version. Collected only with your separate consent and only in anonymised form: events carry a random account identifier, but never your name, email, health metrics (weight, calories, heart rate), photos or any text you entered. Never used for advertising. You can withdraw consent at any time: in the app under Profile → Consents, on the website via the cookie banner or by clearing site data.
  • Technical and error data – device model, OS and app version, error logs (via Sentry); for stability and security (legitimate interest).
  • Notifications – device token for push notifications and email for service messages. Marketing messages are sent only with your consent.

3. Who we share data with

For remote health consultations, we transfer the necessary data to the licensed institution providing the consultation as controller. We may disclose data to public authorities where required by law. Some providers process data outside the European Economic Area (USA) – in such cases the safeguards of GDPR Chapter V apply (the EU–US Data Privacy Framework or standard contractual clauses). We use the following processors and providers:

  • Server hosting – Hostinger.
  • Object storage – Cloudflare R2.
  • Content delivery network and DNS – Cloudflare.
  • Video infrastructure – LiveKit.
  • Subscription management – RevenueCat.
  • Error monitoring – Sentry (EU).
  • Usage statistics – PostHog (EU servers, Germany).
  • AI services – Google and Anthropic.
  • Email delivery – Brevo and our own mail server.
  • Payment and distribution – Apple, Google. Sign-in is provided by Google, Apple and Meta under their own privacy policies.

4. How long we keep data

Account and profile data are kept while you have an account and deleted no later than 30 days after account deletion, except data we must retain by law (e.g. accounting records – 10 years). Body-composition results and activity data are kept until you delete them or while you have an account. Error logs – up to 90 days. Marketing consents – until withdrawn. Anonymised usage-statistics events – up to 12 months.

5. Your rights

Submit requests by email to info@loyalty.lt or in the app settings – we will respond within 30 days. If you believe your rights have been infringed, you may lodge a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, Vilnius, www.vdai.lrv.lt), though we are always happy to resolve the matter directly. You have the right to:

  • access your data and obtain a copy;
  • have inaccurate data corrected;
  • have data erased (the “right to be forgotten”);
  • restrict processing;
  • receive your data in a portable format;
  • object to processing based on legitimate interest;
  • withdraw consent at any time (this does not affect the lawfulness of processing before withdrawal).

6. Security

We apply technical and organisational security measures: encrypted data transfer (TLS), access control, access logs, backups and regular security reviews.

7. Children’s data

The app is intended for persons aged 16 and over. We do not knowingly collect data from younger children; if we learn that such data has been provided, we will delete it.

8. Cookies

On the website we use only strictly necessary cookies (language choice, session functionality) and – only with your consent – analytics cookies set by PostHog. Analytics cookies are not set until you press “Accept” in the cookie banner; if you decline or withdraw consent they are not used. Strictly necessary cookies do not require consent because the site would not work without them. You can also delete or block cookies in your browser settings.

9. Policy changes

We will inform you of material changes to this policy in the app or by email before they take effect. The current version is always published in the app and on avitra.app.

8. Contact Us

If you have any questions about this Privacy Policy, please contact us at hello@avitra.app