How Levely collects, uses, and protects your data on Android and iOS.
How Levely collects, uses, and protects your data on Android and iOS.
This Privacy Policy describes how Levely collects, uses, shares, and protects personal information when you use the Levely mobile application on Android and iOS.
Levely is a fitness gamification app: it turns real-world activity (steps, flights climbed, and sleep) into XP, levels, unlocks, challenges, and social competition. Levely is not a medical device and does not provide medical diagnosis, treatment, or health recommendations.
By creating an account or using the App, you agree to this policy. If you do not agree, do not use the App.
We collect only what we need to:
We do not sell your personal data. We do not use your health or fitness data for advertising. We do not use it for medical analysis.
When you create or use an account, we process:
We also support email verification and password recovery (including one-time codes sent to your email). Those flows process your email and related auth challenge data.
You may change your username or password in Settings (subject to App rules such as cooldown or content filters).
With your explicit permission, Levely reads limited fitness data from the platform health store:
| Platform | Source | Types we request |
|---|---|---|
| Android | Health Connect | Step count, floors climbed, sleep duration |
| iOS | Apple Health (HealthKit) | Step count, flights climbed, sleep analysis |
How we use it
What we do not do
You can revoke health permissions at any time in system settings (Health Connect on Android; Apple Health / Settings on iOS). Revoking access stops new progression from that data but does not by itself delete your account.
Levely includes social features. We process:
Usernames are user-created text. We apply filters and moderation tools (including reporting) to reduce abuse and keep the community fair.
If you allow notifications, we process:
You can change push preferences in Settings and disable notifications in system settings. Disabling notifications does not delete your account.
To operate and improve the App we may process:
We do not use your health samples as advertising identifiers.
If you email us (for example for deletion, export, or support), we process the content of that correspondence and the email address you use to contact us.
As of this policy date, Levely does not:
We use personal data to:
Legal bases (EEA/UK/Switzerland, where applicable): performance of a contract (providing the App you signed up for); legitimate interests (security, fraud prevention, product reliability, basic analytics of crashes); consent (platform health permissions and push permission where required); and legal obligation where applicable.
We do not sell, rent, or trade personal information to advertisers.
We share data with providers who help us run Levely, under instructions consistent with this policy:
| Provider | Role |
|---|---|
| Supabase | Authentication, database, backend APIs / related hosting |
| Firebase (Google) | Push delivery (FCM/APNs integration) and Crashlytics crash reporting |
| Apple | App distribution (App Store / TestFlight), Apple Health permission framework, APNs infrastructure |
| App distribution (Google Play), Health Connect permission framework, and related Google Play / OS services on Android |
These providers process data as needed to provide their services (for example storing account records, delivering a push, or receiving a crash report).
Some information is intentionally visible to other Levely players as part of the product:
Do not choose a username you are unwilling to show other players.
We may disclose information if reasonably necessary to:
If Levely is involved in a merger, acquisition, or asset transfer, personal data may be transferred as part of that transaction, subject to appropriate protections and notice where required.
We retain personal data while your account is active and as needed to provide the App.
After account deletion, we remove account-linked data from our primary production database as described below. Limited residual copies may temporarily remain in encrypted backups or security logs for a short period until those systems rotate, or longer if we must retain information for legal, dispute, or security reasons.
Crash diagnostic records held by Firebase are retained according to Firebase/Crashlytics retention practices and our operational needs to debug reliability issues.
You can delete your Levely account and associated data at any time.
Profile → Settings → Privacy & Data → Delete account
You must confirm by entering your password (twice). After confirmation, deletion starts: your account identity (including email/username), profile, daily metrics, achievements/progression state, challenge/friends associations, and other data tied to your user id are removed from our primary Supabase database according to our deletion process. You are signed out and cannot sign in again with the same credentials.
If you cannot use the App, email levelyapp@protonmail.com from (or clearly identifying) the account email and request deletion. We will verify ownership and complete the same deletion process.
Depending on where you live (including the EEA/UK and similar jurisdictions), you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability.
Export / correction requests: email levelyapp@protonmail.com. Export requests are handled manually and may take a reasonable time.
You may also have the right to lodge a complaint with your local data protection authority.
Levely is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child has created an account, contact us and we will take appropriate steps to delete it.
The App includes user-generated usernames and social competition features; parents/guardians should decide whether the App is appropriate.
We use industry-standard safeguards appropriate to our size and the data we handle, including:
No method of transmission or storage is 100% secure. Please use a strong unique password and keep your devices updated.
We may process and store information on servers located outside your country (including infrastructure operated by Supabase and Google/Firebase). Where required, we rely on appropriate transfer mechanisms provided by our processors and applicable law.
This policy is intended to align with:
High-level categories typically include account info (email), user id, health & fitness aggregates used for gameplay, identifiers such as push tokens, diagnostics (Crashlytics), and social/gameplay data. We do not use this data for third-party advertising. Exact store form answers may use Apple/Google category names; if store UI wording differs, this policy controls the plain-language meaning.
The App may open system apps or links (for example Apple Health, Health Connect settings, privacy policy pages, or store listing pages). Those services are governed by their own terms and privacy policies.
We may update this Privacy Policy from time to time. We will change the Last updated date on this page and, when changes are material, take additional steps as appropriate (for example in-app notice or store release notes). Continued use of the App after an update means you accept the revised policy.
For privacy questions, data export requests, or deletion requests:
Last updated: August 27, 2026