Privacy policy

Last updated: September 15, 2026
Contact: levelyapp@protonmail.com

This Privacy Policy describes how Levely collects, uses, shares, and protects personal information when you use the Levely mobile application on Android and iOS.

Levely is a fitness gamification app: it turns real-world activity (steps, flights climbed, and sleep) into XP, levels, unlocks, challenges, and social competition. Levely is not a medical device and does not provide medical diagnosis, treatment, or health recommendations.

By creating an account or using the App, you agree to this policy. If you do not agree, do not use the App.

1. Overview

We collect only what we need to:

  • create and secure your account
  • read activity data you authorize (to power XP and gameplay)
  • sync progression and social features
  • send optional push notifications you control
  • fulfill optional Levely Premium subscriptions
  • keep the App reliable and fair (security, abuse prevention, crash diagnostics, referral rewards)

We do not sell your personal data. We do not use your health or fitness data for advertising. We do not use it for medical analysis.

2. Data we collect

2.1 Account and profile data

When you create or use an account, we process:

  • Email address (including a Hide My Email relay address if you choose that option with Apple)
  • Authentication credentials (password is handled by our auth provider; we do not store your plaintext password). You can also sign in with Google or Apple as identity providers.
  • Username (display identity in the App)
  • Profile and cosmetics you choose (picture, background, emblems from our catalog)
  • Account flags needed to run the product (progression totals, preferences, feature eligibility)
  • Optional invite / referral code entered at sign-up (so we can credit the person who invited you)

We also support email verification and password recovery (including one-time codes sent to your email). Those messages are delivered by Resend.

2.2 Health and fitness activity data

With your explicit permission, Levely reads limited fitness data from the platform health store:

PlatformSourceTypes we request
AndroidHealth ConnectStep count, floors climbed, sleep duration
iOSApple Health (HealthKit)Step count, flights climbed, sleep analysis

On-device reads are converted into gameplay. When you are signed in, we sync day-level aggregates and related progression state to our servers so progress works across devices and in multiplayer features. We aim to exclude obviously manual samples where the platform lets us detect them. You can pick preferred data sources in Health & Metrics.

We do not sell health data, use it for ads, or provide medical advice. You can revoke health permissions in system settings at any time.

2.3 Social, competition, and user-generated content

Friends, social challenges, leaderboards and seasons, usernames and profile cards, and in-app notifications related to those features. Usernames are user-created; we apply filters and moderation tools. Conduct rules are in our Community guidelines.

2.4 Push notifications

If you allow notifications: push tokens (FCM / APNs), preference flags, and timezone so reminders can respect your local day. Disable in Settings or the OS.

2.5 Device, diagnostics, and security data

App version, basic server/auth logs, and crash reports via Firebase Crashlytics. Crashlytics is for reliability, not advertising.

2.6 Support communications

If you email us, we process that correspondence and the address you use.

2.7 Purchases and subscriptions

Levely Premium is an optional auto-renewable subscription sold inside the App. Payments go through Apple In-App Purchase on iOS and Google Play Billing on Android. Apple or Google (the store you buy from) is the merchant of record. They handle charging, taxes, receipts, refunds, and cancellation. We do not see or store your card number, bank account, or other payment-instrument details. Renewal and receipt emails come from Apple or Google, not from Levely.

To unlock, restore, and turn Premium off when a subscription ends, we process:

  • Your Levely user id (not your App Store or Google Play email)
  • Whether Premium is currently active on that account
  • Which store billed the subscription (Apple or Google)
  • Product identifier and expiry / renewal timing
  • Purchase / customer identifiers from our subscription processor

RevenueCat verifies store receipts and tells us when a subscription starts, renews, is refunded, or expires. It receives the Levely user id and the store purchase tokens needed for that job. It does not receive your card number.

Deleting your Levely account removes Premium from our servers for that account. It does not cancel billing with Apple or Google. Cancel in the store that charged you: in the App, Settings → Subscription, policies, delete → Manage subscription, or the Apple / Google subscription pages.

2.8 Data we do not collect (current product)

As of this policy date, Levely does not:

  • show third-party advertising networks in the App
  • require contacts, camera, microphone, or precise continuous background location for core play
  • use App Tracking Transparency / advertising ID for cross-app tracking
  • collect card numbers or bank details (those stay with Apple or Google)

3. How we use data

  1. Provide the App: accounts, sync, XP, awards, cosmetics, friends, challenges, leaderboards.
  2. Authenticate and secure accounts.
  3. Power optional notifications you enable.
  4. Maintain fairness and safety (abuse, reports, bans). We may use activity patterns to keep referral rewards fair.
  5. Improve reliability (crash diagnostics).
  6. Fulfill optional Levely Premium (unlock features you paid for, restore purchases, and remove access when a subscription ends).
  7. Comply with law where required.
  8. Communicate about support, security, or material policy changes.

Legal bases (EEA/UK/Switzerland, where applicable): contract, legitimate interests (security, reliability), consent (health and push permissions), and legal obligation.

4. How we share data

We do not sell, rent, or trade personal information to advertisers.

ProviderRole
SupabaseAuthentication, database, backend APIs / related hosting. Google and Apple are used as identity providers for sign-in.
ResendTransactional and auth email (verification codes, password reset, username-reset notices). Recipient address only; canned templates.
RevenueCatSubscription receipt verification and entitlement events (no card numbers)
Firebase (Google)Push delivery and Crashlytics
AppleApp Store / TestFlight, HealthKit, APNs, In-App Purchase, Sign in with Apple (including Hide My Email relay)
GoogleGoogle Play, Health Connect, related Android OS services, Play Billing, Google sign-in
AppsFlyer OneLinkInvite and install links (onelink.to) may see IP and device/browser data so the tap lands on the right store. Not an in-app ads or analytics SDK. We do not use AppsFlyer inside the App.

Other players can see username and profile presentation, accepted friends, challenge participation/scores, and leaderboard standings.

5. Retention

We retain personal data while your account is active. After deletion, account-linked data is removed from our primary production database. Blocked usernames may be kept so they cannot be reused. Crashlytics, Resend, and Apple/Google billing records follow those vendors. Limited residual copies may remain in encrypted backups or logs until those systems rotate, or longer if the law requires it.

6. Account deletion

In the App: Profile → Settings → Subscription, policies, delete → Delete account. Confirm your password twice. Deletion starts; you are signed out. This does not cancel an Apple or Google subscription. Billing continues until you cancel with the store that charged you.

By email: levelyapp@protonmail.com from (or clearly identifying) the account email.

7. Your controls and rights

Revoke Health Connect or Apple Health in system settings. Disable push in Settings or the OS. Change username/password in Settings. Cancel Premium in the store that billed you (Settings → Subscription, policies, delete → Manage subscription). Renewal and receipt emails come from that store, not from Levely. Delete the account as above.

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. Export / correction: email us. You may lodge a complaint with your local data protection authority.

8. Children

Levely is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age.

9. Security

HTTPS/TLS in transit, encryption at rest on our primary backend, authenticated APIs, and abuse / rate-limiting where applicable. No method is 100% secure. Use a strong unique password.

10. International transfers

We may process and store information on servers outside your country (including infrastructure operated by Supabase, Resend, RevenueCat, and Google/Firebase).

11. Store disclosures

This policy is intended to align with Google Play Data safety and Apple App Privacy nutrition labels. We do not use this data for third-party advertising. In-app purchases are processed by Apple and Google; we store entitlement status, not payment-instrument details.

12. Third-party links and OS services

The App may open system apps or links (Apple Health, Health Connect, store listings, our Terms of use, this privacy policy). Those services have their own policies.

13. Changes

We may update this policy. We will change the Last updated date and, when changes are material, take additional steps as appropriate. Continued use after an update means you accept the revised policy.

14. Contact

Operator / data controller: Carl Hardhaug, Norway
Email: levelyapp@protonmail.com
Web: https://levely-app.com

The contract for using the App is in our Terms of use.