Privacy Policy

Last updated: July 22, 2026

Want to delete your account?

You can delete it in the Lafe app or request deletion on the web, even if you no longer have the app installed.

Delete or request deletion of your account

1. Who we are

LOTUS APP LIMITED, trading as Lafe, is the controller of the personal data described in this policy. We are registered in England and Wales under company number 16061353. Our registered office is 58 Canrobert Street, London, United Kingdom, E2 6PX. You can contact our privacy team at luv@lotushealth.app.

2. Scope

This policy applies to the Lafe mobile and watch apps, lafeapp.com, our support channels, and related services. A connected service has its own privacy policy for data it handles independently. This policy does not replace the privacy settings or notices provided by Apple, Google, Garmin, WHOOP, Strava, Wahoo, Oura, Polar, Samsung, or another service you choose to connect.

3. Personal data we collect

  • Account and profile data: name, email address, authentication provider, profile photo, age or date of birth, sex, height, weight, timezone, preferences, and account identifiers.
  • Health and fitness data: workouts, routes and location, heart rate, HRV, sleep, recovery, readiness, training load, body measurements, mobility or injury information, nutrition data, and other sensor or wearable data you choose to provide. Some of this is special category health data.
  • Coaching and content data: goals, plans, check-ins, ratings, messages, voice or audio inputs, AI memories, notes, photos, feedback, and content you post or share.
  • Connected-service data: data and authorisation tokens received from, or sent to, services you connect, such as Apple Health, Health Connect, Garmin, WHOOP, Strava, Wahoo, Oura, Polar, or Samsung Health.
  • Subscription data: subscription status, product, renewal and transaction references supplied by Apple, Google, or RevenueCat. We do not receive your full payment-card details.
  • Device, diagnostics, and usage data: IP address, device and app information, push token, pages and features used, interaction events, performance logs, crash reports, and—where enabled and permitted—session recordings. These recordings can reflect app screens, so we treat them as potentially sensitive.
  • Support and legal data: correspondence, requests, complaint records, and information needed to verify and respond to you.

We collect data from you, your device, services you connect, app stores and service providers, and other Lafe users when they interact with you. You do not have to connect a wearable or provide optional information, but some features will not work without the data they need.

4. How and why we use personal data

PurposeUK GDPR lawful basis
Create your account; provide coaching, workouts, synchronisation, social features, support, and subscriptionsPerformance of our contract with you
Use health data to personalise coaching, recovery, training, injury-aware guidance, and related featuresExplicit consent for special category data, alongside contract where applicable
Secure, troubleshoot, monitor, and improve Lafe; prevent fraud or misuseOur legitimate interests in a safe, reliable service; legal obligation where applicable
Process purchases, keep accounting records, and enforce our termsContract and legal obligation; legitimate interests for claims and enforcement
Measure website or product usage and test improvementsConsent where required for device storage or sensitive data; otherwise legitimate interests
Send marketing communicationsConsent, or legitimate interests where electronic-marketing law permits

Where we rely on legitimate interests, those interests are operating and improving Lafe, protecting users and our systems, and understanding whether the service works. We balance them against your rights and reasonable expectations. You can withdraw consent at any time. Withdrawal does not affect earlier lawful processing, but it may disable features that require the relevant data.

5. AI processing and coaching

Lafe uses AI to generate and adapt workouts, answer coaching questions, analyse activities or food photos, interpret voice inputs, and extract coaching-relevant memories. Depending on the feature and model configuration, relevant prompts and data may be processed by providers such as Google (Gemini), OpenAI, and ElevenLabs. We minimise direct account identifiers in AI requests where the feature permits, but the content itself may contain personal or health information.

We do not permit public foundation models to be trained on your personal health data for their providers' own purposes. AI output may be incomplete or wrong and is not medical advice. Lafe's recommendations do not make decisions that have legal or similarly significant effects on you; you decide whether to follow them.

You can delete individual or all AI memories and conversation history in the app. Deleting your account also deletes account-linked memories and conversations from our active systems, subject to the limited exceptions below.

6. When we share personal data

We do not sell personal data. We share it only as needed with:

  • Infrastructure and storage providers, including AWS.
  • Identity, messaging, and platform providers, including Firebase, Apple, and Google.
  • AI and voice providers, including Google, OpenAI, and ElevenLabs, for the features described above.
  • Analytics and diagnostics providers, including PostHog and Sentry.
  • Subscription providers, including RevenueCat, Apple App Store, and Google Play.
  • Connected fitness services at your direction, to import data or send workouts and related information.
  • Professional advisers, authorities, or a buyer of our business where reasonably necessary, legally required, or subject to appropriate safeguards.

Providers acting for us may use personal data only to deliver their contracted service. Some connected platforms and app stores act independently under their own terms and privacy policies.

7. Social features and visibility

If you enable or use social features, other Lafe users may see information you choose to share, such as your display name, profile photo, activities, route map, selected activity metrics, goals, training summaries, photos, captions, likes, comments, and selected performance or recovery summaries.

Other users are not given access to your underlying wearable records, detailed sleep data, HRV records, resting heart rate records, or private coaching messages unless a feature clearly tells you otherwise. You can turn off feed visibility in Settings > Social. This hides content from the feed but does not itself delete it.

8. International transfers

Some providers process data outside the United Kingdom. Where UK law requires a transfer safeguard, we use an adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, and assess the transfer as required. Contact us if you want more information about the safeguard used for a particular transfer.

9. Retention and account deletion

We keep account, coaching, and health data while your account is active and it is needed to provide Lafe, unless you delete it sooner. We keep diagnostics, security, support, transaction, consent, and legal records only for as long as needed for their purpose, our legal obligations, dispute resolution, fraud prevention, or the establishment and defence of legal claims. We periodically review and delete or anonymise data that is no longer needed.

When you delete your account, deletion begins immediately for the active account and associated data. We aim to complete deletion from active systems within 30 days after any necessary identity verification or connected-service cleanup. Limited data may be retained where the law requires or permits it, and isolated backup copies may remain until they are overwritten in the ordinary backup cycle. We do not restore deleted account data from backups for ordinary business use.

Deleting the app does not delete your account. Use the in-app path Settings > Account Details > Delete account, or use our web account-deletion page. Deleting your Lafe account does not automatically cancel an Apple or Google subscription; cancel it separately in the relevant app store.

10. Your data-protection rights

Depending on where you live and the circumstances, you may have rights to be informed; access your data; correct inaccurate data; erase data; restrict or object to processing; receive portable data; withdraw consent; and challenge qualifying solely automated decisions. These rights are not absolute and lawful exceptions may apply.

Email luv@lotushealth.app to exercise a right or make a data-protection complaint. We may ask for proportionate information to verify your identity. We normally respond without charge within one month. We will acknowledge a data-protection complaint within 30 days, investigate it, and explain the outcome.

You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or to your local data-protection authority. We would appreciate the chance to address your concern first, but you do not have to contact us before the regulator.

11. Website cookies and analytics

Our website stores a necessary preference so it can remember your cookie choice. If you select “Accept All,” PostHog may use cookies or local storage to measure page views, referrals, and interactions and to help us improve the website. We do not enable optional website analytics before consent. Selecting “Necessary Only” keeps optional analytics off.

You can change your choice by clearing Lafe site data in your browser and revisiting the site. Browser controls can also block or delete cookies, although strictly necessary storage may be needed for requested features.

12. Security

We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, credential protection, and monitoring. No system is completely secure, so we cannot guarantee absolute security. Please contact us promptly if you believe your account has been compromised.

13. Children

Lafe is not intended for anyone under 16, and we do not knowingly allow them to create an account. If you believe a child under 16 has provided personal data, contact us so we can investigate and delete it where appropriate.

14. Changes and contact

We may update this policy when Lafe, our providers, or the law changes. We will update the date above and give additional notice in the app or by email when a change materially affects how we use personal data.

LOTUS APP LIMITED
58 Canrobert Street
London E2 6PX
United Kingdom
luv@lotushealth.app