#Who this policy covers
This policy applies to personal information handled by LeanLens when you visit its public website, request an analysis, create or use an account, save or share results, use progress or training features, purchase Pro, join a waitlist, or contact support.
Controller identity: LeanLens is the trading name of an independent service provider established in Portugal. Use support@leanlens.ai for privacy, legal, support, and complaint communications.
#Information we process
- Photos and media you provide — analysis photos, saved progress photos, photos included in a user-created share, and, if separately available to you, training media or voice notes. Files can include metadata supplied by your device or browser.
- Body-analysis information — optional height, weight, age, gender and activity inputs; generated body-fat ranges, confidence, muscle, symmetry, physique and strategy outputs; private AI-generated Future Physique illustrations and their normalized Today source frame; analysis status, history, progress, comparisons, and peer-benchmark attributes. These inputs and inferences are sensitive and may constitute data concerning health where they reveal health or physiological status.
- Account information — email address, account and anonymous identifiers, authentication records, profile details, preferences, and links between guest activity and an account when applicable.
- Subscription information — product and storefront identifiers, entitlement state, purchase and renewal context, and receipt metadata. LeanLens does not implement direct web purchases; a launched mobile storefront handles payment details.
- Support and research information — your message, optional contact email, feedback category, page and locale, account or guest identifier, browser/app context, and a hashed network identifier. When the categorized support form is enabled, its accepted messages are stored in LeanLens's application records and are not sent through the generic feedback webhook. Other feedback categories may use that webhook when it is configured. Waitlist entries can include an email address and request context.
- Device, usage and diagnostic information — page views, product events, browser, device and runtime context, performance, errors, masked interaction context, network metadata, and security or abuse-prevention signals. Google Analytics events are restricted to low-cardinality product context and exclude raw analysis identifiers, body-fat values, FFMI, and muscle-score values.
- Optional feature information — if training or voice features are offered and used, this can include goals, equipment, workouts, sets, session feedback, audio, transcripts, summaries, and related AI outputs.
#Why we process information
LeanLens currently processes information to:
- provide, queue, recover, and display requested analyses;
- create and privately display requested Pro Future Physique illustrations;
- create accounts, authenticate users, and preserve settings and saved progress;
- provide comparisons, trends, user-directed sharing, and aggregated peer benchmarks where those features are available;
- verify Pro entitlements, restore purchases, and respond to billing issues;
- answer support, privacy, safety, and feedback requests;
- measure use, diagnose failures, secure the service, prevent abuse, and improve reliability; and
- comply with legal obligations and establish or defend legal claims.
Lawful bases: LeanLens relies on performance of the Terms for core account and requested-service functions; consent where the product asks for a choice, such as optional public-web analytics and the app’s AI-analysis flow; legitimate interests for proportionate native-app product analytics, security, abuse prevention, and necessary diagnostics; and legal obligations or legal claims where applicable. The public web analyzer starts processing only after you choose to analyze and accept the Terms, but it does not collect a separate explicit health-data consent.
#How AI analysis works
When you request an analysis, LeanLens sends the selected photos, relevant profile inputs, instructions, and analysis context to one of the third-party AI providers listed on the Subprocessors page. The provider returns generated content that LeanLens validates and presents as an estimate. The result can be wrong and can vary with lighting, pose, framing, clothing, image quality, model behavior, and changes between photos. It is not a medical measurement or medical advice.
A device-level AI preference exists for the app analyzer. It is a user-interface gate, not account-level consent evidence independently enforced by the analysis service. The public web scanner does not read or store that app preference. When you choose to analyze on the web, LeanLens records the current Terms and Privacy versions and the web click-through, but it does not record separate health-data, age, depicted-adult, or photo-authority confirmations. App analyses record the app attestation that accompanies that flow. Withdrawing an app preference blocks later app scans on that device until you accept again; it does not undo processing that already occurred.
The analysis is automated evaluation or profiling: the system uses the submitted photos and profile inputs to infer body-composition and fitness attributes. LeanLens presents advisory estimates and does not use them to make decisions that produce legal or similarly significant effects. Do not use LeanLens for employment, insurance, credit, healthcare, law enforcement, eligibility, or another high-impact decision.
Future Physique is an optional Pro feature that sends a normalized copy of the saved front photo and bounded transformation instructions to a third-party AI provider listed on the Subprocessors page to create illustrative images for 4, 8, and 12 weeks. The normalized Today frame and generated frames stay private to the account and are delivered through short-lived signed URLs. They are AI illustrations, not forecasts or measurements, and there is no guarantee that they preserve appearance, likeness, pose, background, or realistic future results.
Model training and provider retention: LeanLens does not use uploaded photos to train its own general-purpose model. It sends selected photos to the AI provider used for the requested analysis. Provider-side retention and model-improvement practices depend on the provider service and terms in use, so LeanLens does not promise zero provider retention or training without provider-specific confirmation.
#How information is shared
- Service providers — providers help deliver AI analysis, accounts, storage, hosting, job delivery, subscriptions, analytics, and diagnostics. See the Subprocessors page for current and conditional providers.
- Mobile storefronts — a storefront processes its store account, payment, purchase, refund, and subscription information under its own privacy terms.
- People you choose — if you create an unlisted or public share, the copied result and any included photo remain available to people with access to that share until it is revoked or otherwise removed.
- Another person aged 16+ depicted in an upload — LeanLens receives that person's photo and related information from the uploader rather than directly from the depicted person. The uploader must first provide this policy and obtain the permission described below. The depicted person can exercise privacy rights through the same contact route without creating an account. If you upload a photo of another person aged 16 or older, you are responsible for giving that person this Policy before upload and obtaining their specific, informed authorization for the upload, AI analysis, provider disclosure, retention, and any share you create. The depicted person keeps their privacy rights and may contact LeanLens directly without creating an account.
- Legal and safety recipients — information may be disclosed when reasonably necessary to comply with law, protect users or the service, investigate abuse, or establish and defend legal claims.
- Business changes — information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and appropriate notice.
LeanLens does not sell personal information and does not disclose analysis photos or body-analysis data for third-party targeted advertising. A future change to that commitment would require a new policy, a valid legal basis, and any consent or opt-out required by applicable law.
#Retention and deletion
- Analysis source photos and jobs — source photos use private storage and are kept only for processing, recovery, or an expressly selected result window. Operational job records are normally scheduled for deletion within 30 days.
- Guest analyses — successful or degraded guest analyses can be saved and associated with an anonymous browser identifier. The identifier cookie can last up to 365 days. Guest result history is scheduled for no more than 30 days.
- Saved progress — signed-in analysis history and progress can remain until deleted. The current product can save progress photos by default for signed-in users. A requested Future Physique set stores a normalized Today frame and three generated illustrations until the related snapshot or account is deleted. These four assets are private, use short-lived signed URLs for current Pro access, are excluded from public shares and public comparisons, and are included only in an authenticated account export. You can turn off future progress-photo saving in Privacy & data settings; changing the setting does not delete photos already saved.
- Shares — copied share data and included photos remain available until the share is revoked or removed, subject to any residual operational copies.
- Support, subscription, analytics, security, and backup records — retained only for the published operational, provider, or statutory period, including the schedule summarized below.
- Device-local data — the app or browser can retain preferences, anonymous identity, and recovery media. Clearing an account does not necessarily clear every browser or device cache.
Retention schedule: Upload sessions normally expire after 30 minutes. Failed or expired analysis-job records and their events are scheduled for deletion after 48 hours; successful or degraded job payloads and cancelled jobs are scheduled for scrubbing or deletion after 30 days. Guest history is scheduled for deletion after 30 days. Revoked shares are normally eligible for deletion after 30 days. Signed-in history, progress photos, normalized Future Physique source frames, and generated Future Physique images can remain until the relevant snapshot or account is deleted. Support, subscription, security, legal, provider, and backup records are kept only for as long as needed for their stated purpose, applicable legal duties, disputes, or the provider’s documented deletion cycle.
Account deletion can begin a staged cleanup and does not cancel a mobile subscription. The product distinguishes completed cleanup from a request that is still pending. Some analysis source files or detached processing records may remain until their separate cleanup finishes. Contact support@leanlens.ai if you need confirmation or cannot use the in-app control. LeanLens shows completion only after the cleanup reaches a verified terminal state.
#Cookies, local storage and analytics
LeanLens uses cookies or similar local storage for authentication, security, preferences, anonymous identity, analysis recovery, and subscription or product state. On configured production web hosts, Google Analytics stays off until you choose Allow analytics. You can reopen Privacy choices to change that browser-stored choice. In the production iOS and Android apps, Firebase Analytics processes a pseudonymous app-instance identifier and low-cardinality product interactions. LeanLens disables advertising-identifier collection, personalized-ad signals, automatic native screen reporting, and tracking. Sentry may collect scrubbed error diagnostics when configured; session replay is disabled.
Consent and withdrawal: the public-web Google Analytics preference fails closed when no valid choice is stored. Native-app analytics does not use that browser choice and is limited as described above. Session replay remains disabled and any other non-essential access to information on a device stays off until the applicable consent requirement is satisfied. Necessary cookies and local storage support authentication, security, language, legal choices, recovery, and subscriptions. On production web hosts, Google Analytics stays off until an affirmative browser choice, which you can change from the cookie controls. In the production iOS and Android apps, Firebase Analytics processes pseudonymous app-instance identifiers and low-cardinality product interactions for usage analytics. LeanLens disables advertising-identifier collection, personalized-ad signals, automatic native screen reporting, and tracking. Session replay is disabled.
#Security and international transfers
LeanLens uses access controls, scoped application checks, transport encryption, and provider security features intended to protect data. No online service can guarantee absolute security. Please contact us if you believe your account or information has been compromised.
Providers may process information outside your country. Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.
#Your privacy rights and choices
Depending on where you live and the applicable legal basis, you may have rights to access, correct, erase, restrict, or receive a portable copy of personal information; object to certain processing; withdraw consent without affecting earlier lawful processing; and complain to a data-protection authority. Legal exceptions may apply.
LeanLens must respond to a valid rights request without undue delay and ordinarily within one month. That period can be extended by two further months when necessary due to complexity or volume, with notice during the first month. Requests are ordinarily free. You may complain to the authority in the EU country of your habitual residence, place of work, or the alleged infringement. For Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados.
- Review or update available profile and privacy preferences in the app.
- Delete individual saved items where that control is offered, or request broader deletion. A self-service data-export control is not currently available; contact LeanLens to request a portable copy where that right applies.
- Delete an account from Profile > Privacy & data, or email support@leanlens.ai from the account address if you cannot sign in.
- Email support@leanlens.ai to make a privacy request. LeanLens may need to verify your identity and clarify the scope before acting.
#Service and photos for ages 16+
You must be at least 16 years old to create an account, request an analysis, purchase Pro, or otherwise use LeanLens. You may upload only a photo of yourself or another identifiable person aged 16 or older who has received the Privacy Policy and given express, specific, and informed authorization for LeanLens to process the photo and related body-analysis data for the requested feature, including disclosure to the identified service providers. Never upload a photo of anyone under 16 or anyone who has not given that authorization. You are responsible for verifying the depicted person’s age and authorization, and your own authority to upload. This responsibility does not limit the depicted person’s rights or LeanLens’s own obligations and liability under applicable law.
For a photo of another person aged 16 or older, LeanLens receives personal information from the uploader rather than from the person depicted. If you upload a photo of another person aged 16 or older, you are responsible for giving that person this Policy before upload and obtaining their specific, informed authorization for the upload, AI analysis, provider disclosure, retention, and any share you create. The depicted person keeps their privacy rights and may contact LeanLens directly without creating an account.
#Changes to this policy
LeanLens may update this policy as the product, providers, or legal requirements change. The date at the top identifies the current version. LeanLens will communicate material changes through an appropriate in-product or direct notice where required. Effective July 21, 2026 for acceptances recorded against the July 20, 2026 Terms version and July 21, 2026 Privacy version.