Privacy Policy
Last updated: June 7, 2026 · Effective: June 7, 2026
This Privacy Policy explains how Lyfr(“Lyfr,” “we,” “us”) collects, uses, and protects information across our products — FitCore (a fitness coaching platform) and AvatarFlow(an AI avatar & social content tool) — available at getlyfr.com and its subdomains (app, client, avatar, api, af-api). By using our services you agree to this Policy.
1. Information We Collect
- Account & profile: name, email, role, organization, avatar image, and settings.
- Fitness & health data (FitCore): goals, workout/meal plans, sessions, habits, and self-reported vitals (e.g. weight, body measurements). You choose what to enter.
- Content (AvatarFlow): scripts, captions, generated avatar videos, and publishing schedules you create.
- Connected social accounts: when you connect Instagram/Facebook, TikTok, YouTube, or LinkedIn, we receive OAuth tokens and basic profile/account identifiers needed to publish on your behalf. Tokens are encrypted at rest.
- Payment data: processed by Stripe; we do not store full card numbers.
- Usage & device: log data and device/browser info. We use only strictly necessary cookies for authentication and security — no advertising or cross-site tracking cookies.
2. How We Use Information
- Provide and improve the services (generate plans/content, schedule and publish posts, process payments).
- Authenticate you and secure accounts.
- Publish content to social platforms only at your direction or under approval rules you configure.
- Communicate service and support messages. We do not sell your personal information.
3. AI-Generated Content Disclosure
AvatarFlow produces AI-generated avatars, voice, and video. Where a platform requires it, content we publish on your behalf is labeled as AI-generated (e.g. TikTok's AI-content flag, Meta's AI label, YouTube's altered/synthetic-content disclosure). You remain responsible for the content you approve and publish.
4. Third-Party Services
We use trusted processors to operate the service, each under their own privacy terms:
- Supabase (database, auth, storage)
- Stripe (payments)
- Groq and Anthropic (AI text generation)
- HeyGen (AI avatar video, AvatarFlow)
- Meta, TikTok, Google/YouTube, LinkedIn (only when you connect those accounts)
Our use of information received from each platform's APIs adheres to that platform's Developer Policies and Platform Terms, including any limited-use requirements. For each platform we request only publish / content-management and basic-profile scopes — we do not read your private messages, contacts, or follower lists.
5. Google / YouTube API Services
AvatarFlow's use of information received from Google APIs (including the YouTube Data API) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube account data solely to upload and report on videos you create, never for advertising, never sold, and never transferred except as required to provide the feature, comply with law, or with your consent. By using the YouTube features you also agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke our access at any time via your Google security settings.
6. Data Retention & Deletion
Data Deletion Instructions
To delete your account and all associated personal data — including any data obtained from connected platforms (Instagram, Facebook, TikTok, YouTube, LinkedIn): (1) open Settings → Account → Delete Account in the app, or (2) email [email protected]with the subject “Data Deletion Request” from your account email. We verify and complete deletion within 30 days and confirm by email. Disconnecting a social account in the app immediately revokes and deletes the stored access tokens for that platform. To remove Lyfr's access from Facebook/Instagram directly, go to Facebook Settings → Settings & Privacy → Apps and Websites and remove “Lyfr.”
Retention periods. We retain account and content data for the life of your account. After deletion we erase your personal data within 30 days, except: (a) data we must keep for legal, tax, or accounting obligations (up to 7 years); and (b) residual copies in encrypted backups, purged on our rolling cycle (no longer than 90 days). OAuth tokens are deleted immediately when you disconnect a platform or delete your account.
7. Your Rights
EEA/UK (GDPR): access, rectification, erasure, restriction, portability, and objection.
California (CCPA/CPRA): the right to know, delete, correct, and opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising.
Exercise any right at [email protected].
8. Security
We use encryption in transit and at rest (including encrypted OAuth tokens), access controls, and reputable infrastructure. No method is 100% secure, but we work to protect your data.
9. Children
Our services are not directed to children under 13, and we do not knowingly collect their data. Fitness features used by minors should be supervised by a parent, guardian, or coach.
10. International Transfers & Changes
We may process data in the United States and other countries with appropriate safeguards. We may update this Policy; we will post the new date here and, for material changes, notify you in-app or by email.
11. Contact
Lyfr — [email protected]
See also our Terms of Service.