Privacy Policy
1.Our core principle: local-first
LockIn is designed so your personal fitness data never has to leave your device. The following are stored only in the app's private storage on your phone and are never transmitted to us or any third party under normal use:
- Body metrics (height, weight, age, biological sex used for a calorie estimate)
- Food and allergy information, meal logs, and macro totals
- Workouts, sets, reps, personal records, streaks, and badges
- Wake-up times, commitments, and any location you attach to a commitment
- Health & fitness data you choose to connect (see §4)
This data is excluded from Android cloud backup and device-to-device transfer. Uninstalling the app, or clearing its data in Android Settings, permanently removes it.
2.Optional account (Sign in with Google)
Signing in is optional. The app is fully usable signed-out and offline. If you sign in with Google, we receive and store, solely to operate your account: your Google account email address and display name, and a Firebase user ID (a random identifier). We do not receive or store your Google password. Signing out clears the stored sign-in state on the device.
2a.Signing up to be a tester (this website)
If you submit your email address through the tester signup form on this website, we store that address and the date you submitted it, so we can add you to the Google Play closed test and send you the invite. That is the only reason it is kept.
- It is not used for marketing, not added to any newsletter, and not shared or sold to anyone.
- To stop the form being abused, we count recent submissions per network address for one hour. The network address is stored hashed, never in the clear, in a throwaway counter that holds no email address and is not linked back to your signup.
- Ask us to remove your address at any time, before or after the test, by emailing support@fitnesslockedin.com. There is nothing to keep once the test ends, and signups are deleted then.
This is separate from the app. Signing up here creates no account and puts nothing on your phone.
2b.Sending feedback (this website)
If you report a bug or send a note through the feedback form, we store what you typed, along with anything you optionally added: your email address, your phone model, and the app version. Every field except the message itself is optional, and a report with no address is still accepted.
- The report is filed as a ticket in the project's private issue tracker, hosted by GitHub, so it sits next to the code it is about. That tracker is not public. Your email address is on the ticket so we can reply to you, and is used for nothing else.
- The form sends only what you type into it. It has no access to the app and cannot read your workouts, food logs, or health data. Please do not paste anything into it that you would not want stored in a ticket.
- Submissions are counted per network address for one hour to stop the form being abused, using the same hashed, throwaway counter described above.
- Ask us to delete a report you sent at any time by emailing support@fitnesslockedin.com.
3.Optional cloud features
These are off unless you turn them on:
- Cloud backup. Part of LockIn Plus. Your data is encrypted on your phone with a passphrase you choose, and only the sealed file is uploaded, to Google Cloud Storage linked to your account. We cannot read it: the passphrase never leaves your device, which also means if you forget it the backup cannot be recovered by anyone, including us. You can delete the cloud copy at any time (see §7). Restoring never requires an active subscription, so a lapsed subscription can never lock you out of your own data.
- Community food database. LockIn can download a shared database of product information only (barcode number, product name, nutrition facts) so scanning a barcode recalls its macros. This contains product data, not user data. Contributions are not linked to your identity.
4.Health & fitness data (Health Connect)
With your explicit permission, LockIn can read the following data types from Android Health Connect to estimate readiness and training load:
- Steps
- Sleep
- Exercise sessions
- Resting heart rate
- Heart-rate variability (RMSSD)
- Heart rate. Used only to find the highest rate you have reached in the last 90 days, so your training zones come from a beat your heart has actually hit rather than a formula based on your age. LockIn asks Health Connect for that single maximum figure. It does not read or store your individual heart-rate readings.
- Weight. Used for the weight trend chart and to recognise progress toward a goal weight.
- Active calories burned
- Total calories burned
Two further permissions change when and how far back LockIn can read, rather than adding new data types:
- Access to past data. Without this, Health Connect limits LockIn to data recorded after you granted permission. Your trends cover 90 days and your workout history can go back years, so this is what lets those screens show your real history instead of starting from empty.
- Access while the app is closed. The coach checks your recovery signals in the background so it can reach you at a useful time of day. Without this, LockIn can only read your data while you have the app open. You can decline it and everything else still works.
With your permission LockIn may also write one data type back to Health Connect: a workout you completed in the app is saved as an exercise session. It writes nothing else.
You grant each permission individually and can revoke any of them at any time in Health Connect settings. This data is used on your device only. It is not sent to us, not shared or sold, and never used for advertising.
4a.The Wear OS watch app
If you install LockIn on a Wear OS watch, the watch app reads your heart rate and your step and calorie totals from the watch's own sensors while a workout is running, so it can show your live heart-rate zone and buzz your wrist if your heart rate stays unusually high or low. Readings are shown while the session is active and are not kept as a history on the watch.
The watch and the phone exchange data directly over your paired Bluetooth connection, using Android's Wear Data Layer. That exchange does not pass through our servers. The watch sends the phone what you did (your completed sets and the finished session) and the phone sends the watch what to show today. Your resting and maximum heart rate are deliberately stripped before anything is cached on the watch.
5.On-device AI
Meal photo recognition and barcode scanning run on your device (Google's on-device models and ML Kit). Photos you take for meal logging are processed in memory and are not uploaded or stored by us. The AI coach's guidance is generated on-device from your local data.
6.What we do NOT do
- No advertising, and no advertising identifiers.
- No third-party analytics, tracking, or crash-reporting SDKs.
- We do not sell or share your personal information.
- Health and fitness data is never used for advertising and never leaves the device except through a cloud feature you explicitly enable (§3).
7.Your choices and data deletion
- Local data: clear it any time via Android Settings → Apps → LockIn → Storage → Clear data, or by uninstalling.
- Health permissions: manage or revoke in Health Connect.
- Account & cloud backup: delete your account from within the app under You → Account, or request deletion by email. Full details, including exactly what is removed and what is not, are on the delete your account page.
8.Data security
Local data is kept in app-private (sandboxed) storage. Network connections use encrypted HTTPS. Access to any optional cloud data is restricted to your authenticated account.
9.Children
LockIn is not directed to children under 13 (or under the minimum age of digital consent in your region). We do not knowingly collect personal information from children.
10.Changes and contact
We may update this policy; material changes will be reflected by a new effective date. Questions or data requests: support@fitnesslockedin.com.
LockIn is operated by Constantia Technologies LLC, a Georgia limited liability company, which is the data controller for the limited information described in this policy.
Email is read and answered by the person who wrote the app, and is the fastest way to reach us. For anything that needs a postal address, including formal privacy or data requests:
Constantia Technologies LLC
1870 The Exchange SE, Ste 220, PMB 533704
Atlanta, GA 30339-2171
United States