LivuFit.Nederlands
← Back to LivuFit

Privacy notice

How LivuFit uses data and what you can manage. Updated 20 September 2026.

This notice applies to LivuFit, which is currently available by invitation. On 20 September 2026 we updated the explanation of optional usage statistics: sharing is off by default and your choice applies to your account. We update this notice when providers, features or retention periods change. Questions? Email info@livufit.nl.

Who is responsible?

LivuFit is a trading name of DevOps with a Smile.

Dutch Chamber of Commerce number: 93875428. Business address: Dr. Ir. Vondelingpark 35, 6716 EL Ede, Netherlands.

Contact: info@livufit.nl or +31 6 16422630 (WhatsApp).

Data used by LivuFit

Your email and account details are used for sign-in. Your profile may include goals, target weight, sex, age, height, weight, experience, equipment and available time. Injuries (body region and side), recovery, pregnancy or breastfeeding information is also processed if you enter it. From sex, experience, weight and age the app estimates a starting weight for an exercise you have not done before; that estimate is calculated on your device and not stored separately.

Your logbook includes the workouts, food, water, measurements, check-ins and preferences you record. These support your plan, nutrition calculations, calendar, insights and rewards.

You can separately consent to pseudonymous usage statistics to help improve the app. This is off by default; details are below.

On your device and in the cloud

Your device keeps a local copy for app use. Supabase provides sign-in and personal-logbook synchronisation; the database is located in Frankfurt (EU). Netlify serves the website and web-app files and handles product searches. Account emails (such as your invitation and password reset) are sent through Resend and contain no health data; replies and questions to info@livufit.nl arrive in a Microsoft 365 mailbox. Measurement reminders are designed for a separate Supabase function which receives no weight values or full logbooks. Providers may process technical data such as IP addresses and browser information when you connect.

Online product search sends your query or barcode to a server function and Open Food Facts. Camera access reads barcodes on your device; the current scanner does not upload camera images. Optional notifications use a device registration and, for web push, a push service.

Health data and legal basis

We ask for separate explicit consent to store and use health data, including weight, target weight, injuries and training limitations, pregnancy and recovery, and related personal suggestions and summaries. The legal basis is consent (GDPR Articles 6(1)(a) and 9(2)(a)). Consent is not preselected; its version and time are recorded in the database. A backup file does not count as new consent.

Without this consent you can browse recipes and save favourites. Account data and these requested functions are processed to provide the service. You choose notifications separately. Technical security processing must be limited to what is needed for safe operation.

Withdraw consent in Settings → Privacy & data. After confirmation, we remove your profile, logbook, measurements and planning from the active database, retaining only recipe favourites. This deletes data; it is not a temporary module pause. You can download your data first.

Pseudonymous usage statistics

Usage statistics are off by default. You can voluntarily consent in Settings → App & data → Share usage statistics. Your choice applies to your entire account on web, Android and iOS. Consent for your personal logbook is separate. All features work without usage statistics.

With your consent, we count features you use and actions such as completing a workout or opening a recipe. Events include the platform, app version and time rounded to the hour. We do not include names, email addresses, exact health values, recipe names or free text.

Events use a SHA-256 hash of your account ID with a secret key held in the database. This recognises repeat use. The data is pseudonymous, not fully anonymous: within our protected database it can be looked up through your account, for example for your data export. We use no advertising ID or location. The admin portal and Grafana receive only aggregate product counts, not individual logbooks.

You can withdraw consent at any time using the same switch. New usage measurements then stop for your account; pending events on this device are discarded. Previous counts remain for at most 400 days and are removed by the daily cleanup job. Your consent choice and history are included in your data export and erased when your account is deleted. Technical errors are processed separately as described below.

For account emails sent through Resend, such as your invitation and password reset, LivuFit receives the delivery status through a webhook: sent, delivered, bounced or complained. Your email address is immediately replaced by the same kind of keyed hash; only the status, subject and time are stored. Open and click tracking is off at Resend and stays off. These statuses are also deleted after 400 days.

Technical error logging

When something goes wrong technically in the app, for example a failed sign-in, a database error, a failed sync or a notification that cannot be scheduled, the app sends an error report to Grafana Cloud (Grafana Labs), an error-tracking service set up in the EU region. This applies to the web app, the Android app and the iPhone app. Only errors are sent, never ordinary use.

An error report contains: the technical error description and stack trace, the kind of error, the route in the app without search terms or ids, an HTTP status or error code, the app version, the platform, browser or operating-system information, a random session number and the time. Your account is included only as a SHA-256 hash of your user ID so that errors from the same user can be grouped; that hash is only included when you have enabled usage statistics for your account. Email addresses, tokens, UUIDs and long keys are replaced before sending. Health data and the contents of your logbook are never sent.

The legal basis is our legitimate interest in a working, secure service (Article 6(1)(f) GDPR). Grafana Cloud keeps the reports for 30 days; anything that cannot be sent immediately waits briefly on your device (at most 50 reports) and is then deleted.

Retention and deletion

You can edit and delete logbook entries. Privacy & data lets you download your local logbook and account data, sign out and clear local account data, or permanently delete your account. Account deletion also removes linked active logbook, consent and push records.

Simply signing out or uninstalling does not delete your cloud account. Erase downloaded files and copies on other offline devices yourself. An offline device receives changes made elsewhere only after reconnecting. A notification already sent may still arrive.

Account data is kept while needed to provide your account service. The configured cleanup job runs daily and deletes app-open records older than 30 days and pseudonymous usage statistics and email delivery statuses older than 400 days. Previously stored counts remain after account deletion until this retention period expires. Your usage-statistics choice and its change history are deleted with your account. Supabase keeps daily database backups and technical logs for 7 days. Resend keeps email data and delivery logs for 30 days and backups for 7 days. Deleting from the active database therefore means copies in backups disappear within those periods, not immediately. Contact info@livufit.nl about these copies.

Your rights

Where applicable, you may request access, correction, deletion, restriction or portability and object to processing. You may withdraw consent where processing relies on it. You may also complain to the Dutch Data Protection Authority. Email your request to info@livufit.nl.

Storage and preferences

The app stores your sign-in details, logbook, language and preferences on your device. It also saves files for offline use. The current app has no advertising trackers. Netlify does not publish a fixed retention period for technical access logs; we are requesting it from Netlify and will add it here once known.

Usage statistics are off by default. Your choice under Settings → App & data applies to your entire account across devices.

Optional situation details and training pause

Pregnancy & recovery asks separately for your explicit consent to store and use the details you provide there. These may include pregnancy, recovery, breastfeeding, a due date or the date a pregnancy ended. The purpose is your preferences, relevant information and the profile prompt you choose. Consent is recorded with the date and setup version. Choosing a notification is separate from this consent.

These details are part of your personal account logbook and the local copy on this device, and are included in exports and imports. In the same screen, you can remove these situation details and withdraw consent for this feature. This also removes the corresponding fields from your training profile. The change is applied to your current cloud logbook on the next successful sync. Training is paused so missing information is not treated as medical clearance.

Your own exports and free-text notes are not automatically erased. Remove your own copies and contact info@livufit.nl about deletion and backup retention. Pausing training keeps your logbook; it is not a deletion request. Optional return notifications use neutral text without pregnancy or breastfeeding details on the lock screen.

Providers and international processing

An EU database region determines where primary project data is stored. It does not automatically keep all support, logs, email, CDN or push processing within the EU. Actual project region, processor agreements, subprocessors and transfer safeguards are checked before new participants are admitted. We therefore make no unverified promise that all processing is EU-only.

Pseudonymous usage statistics and email delivery statuses are stored in the same Supabase database in Frankfurt (EU). Grafana can read only aggregate product counts for the admin dashboard. Technical error reports are stored with Grafana Labs (Grafana Cloud, EU region) and deleted there after 30 days. Resend sends the delivery status of account emails through a webhook to a Supabase function, which replaces the email address with a keyed hash before anything is stored.

The website contact form uses Netlify Forms. Do not share medical details, passwords or logbooks there. Messages are used to handle your enquiry and are deleted no later than 6 months after handling, unless there is a follow-up relationship or a concrete need. Deleted mail remains technically present at Microsoft for up to 30 more days. On the website you can also leave your email address to receive one message when LivuFit goes live or new invitations are available. That sign-up (email address and chosen language) also goes through Netlify Forms, is used for that one message only and is deleted no later than 6 months after that message. Want off the list sooner? Email info@livufit.nl.

Official information

Privacy rights — Dutch Data Protection Authority ↗