Alpha · September 15, 2026
Your data
Your account
LVL is operated by Roshan Amurthur. We store your signed-in account ID, chosen display name, time zone, clans, and invitations. Native sessions use your iPhone Keychain and expire after 30 days; the server stores a token hash. Sign out revokes that session.
Wearables
WHOOP grants read-only access to sleep, recovery, cycles, workouts, and basic profile. The profile confirms your account; its name and email are not retained. Offline access lets LVL refresh your connection. We never receive your WHOOP password.
Oura connects with read-only daily and workout access. LVL imports Readiness, Sleep and Activity scores, overnight sleep summaries, average overnight heart rate and HRV, active time and workout timing. Your Oura password stays with Oura.
Fitbit and Pixel Watch connect through a separate Google Health consent screen. Google sign-in alone grants no health access. You choose read-only sleep, activity and health-metric permissions. LVL requests wearable sleep-session summaries, daily resting heart rate and HRV, and daily active-minute totals. We exclude manual logs and retain the requested summaries at their original granularity. Google Health data is used only for your fitness dashboard and the private practice scores you choose to share. LVL follows Google Health’s Limited Use requirements.
Apple Health connects through the iPhone app. You choose access to sleep, resting heart rate, HRV, exercise time, and recorded workouts. LVL imports daily summaries and source identifiers, not your full Health database. Health data is read-only. No readable records may mean missing data or declined access.
Imports cover approximately six weeks: timestamps, source identifiers, sleep duration and timing, resting heart rate, HRV, and activity. WHOOP also supplies its recovery, sleep-performance and cycle-strain scores, workout heart rate, and energy. Each sync replaces its imported snapshot. For stable baselines, minimized daily observations span up to 84 days and derived scores up to 180 days. Older entries are removed when scores refresh; inactive accounts keep their last stored data until they return or request deletion. Imported records, derived scores, provider credentials, and tokens are encrypted before storage.
What your clan sees
Members see your name and connection status. Joining a practice season separately authorizes sharing your season score, rank, source, valid-day count, and result revisions with current members. Raw health values stay private. Stop sharing to remove your standings and receipt. Leaving a clan removes its score-sharing consent and makes your meals in that clan private.
Anyone with an invitation can see the clan name and available spaces. They must sign in and join to see members. Organizers can replace invitations and remove members.
Meals
Photos and meal labels start private. You choose a clan before sharing. Current members can see and cheer shared meals. Changing the audience clears cheers. We resize photos to JPEG in the app, strip embedded photo metadata on the server, and encrypt both photos and meal details. Photos have authenticated access; there are no public image links. Delete a meal to delete its photo and details from active storage.
Meal logging is manual in this version. Images are not sent to an AI service, and meals do not affect wearable scores. Breakfast, lunch, and dinner reminders are optional local iPhone notifications.
Contacts
Matching is off by default. If you enable it, people who select your account email in their contacts can find your LVL display name. You select which email contacts to check. Those addresses are sent over an encrypted connection, converted to keyed hashes for matching, and not saved as an address book. We store a keyed hash of your sign-in email and a daily request count. Only people who opt in appear. Turn matching off in Find friends to stop appearing.
Storage and deletion
Google sign-in is managed by Firebase Authentication. Google and Firebase process your account identity to sign you in. LVL uses your verified email and name to create your profile and a private session. Wearable records, meal photos and selected contacts are not sent to Firebase Authentication. A ChatGPT account is not required.
LVL runs on Cloudflare through OpenAI Sites. These providers process data to operate the app. We do not sell health or meal data, use it for advertising, or send it to an AI model. If you ask an assistant to inspect displayed records, that is a separate disclosure you control.
Disconnecting a wearable deletes its imported records and derived scores, including shared receipts, from LVL’s active database. Disconnecting WHOOP, Oura or Google Health also requests token revocation. If the provider is unreachable, LVL deletes its local connection and asks you to remove access in the provider’s connected-app settings. Revoking access in a provider’s app alone does not delete existing LVL imports. For Apple Health, you can change read permissions in Health settings. Account records and meals remain until deleted. Provider backups may outlast active deletion.
For an export or complete account deletion, contact roshan.amurthur@gmail.com.