Privacy

Privacy Policy

This policy describes FormLevel's current private-beta data practices in plain language, including what happens to uploaded exercise videos, planner answers, and measurements.

Effective and last updated August 14, 2026

Quick notice at collection

FormLevel uses an uploaded exercise video to run pose detection and create a report. If you describe an exercise after rejecting the automatic matches, FormLevel uses that text to search its exercise catalog. It uses your planner answers and measurements to generate a workout or meal plan. If you use guided training, it also processes workout progress, check-in choices, per-exercise load feedback, and any optional note you enter. If a signed-in user separately opts in to recognition improvement, FormLevel privately retains that video, extracted movement data, the model prediction and suggestions, and the user's confirmation for authorized human review and possible future classifier evaluation or improvement. This choice is optional, is off by default, can be revoked in Settings, and does not affect the requested analysis. The contribution is not public or visible to other users. Access is limited to FormLevel's private service systems and people specifically authorized for this review purpose. If you contact support, FormLevel processes your account email, message, and any screenshot you choose to attach. The service receives technical data needed to deliver and protect the beta. FormLevel does not currently sell personal information or use it for targeted advertising. By default, FormLevel also sends Vercel a fixed set of coarse product-milestone event names to measure aggregate completion and drop-off. FormLevel adds no account, user, session, job, video, or plan identifier and no custom properties to those events. They do not include measurements, planner answers, exercise names, uploaded files, generated plans, or analysis results. Vercel still receives ordinary network, page, device, referrer, and request metadata needed to provide Web Analytics. The dashboard available to FormLevel reports aggregate counts rather than an individual visitor timeline. FormLevel does not load Vercel Analytics or Speed Insights when the browser reports Global Privacy Control or Do Not Track.

1. Information FormLevel processes

  • Exercise video data: the selected recording, filename, file type, file size, duration, frame rate, resolution, pose landmarks, movement measurements, generated preview frames, skeleton overlays, rep timing, and analysis results. A video may include your face, body, voice, clothing, and surroundings.
  • Optional recognition-improvement contribution: if you are signed in and separately check the optional sharing box, FormLevel keeps a private copy of that recording, extracted pose data, the classifier version and original prediction, the suggestions shown, and the confirmation choice, if any. The box is off by default and is not required to receive an analysis. This private contribution has no public URL and is not available to other product users.
  • Exercise-recognition audit data: whether or not you opt in to improvement sharing, FormLevel records the temporary job owner, classifier and label-registry versions, video-quality result, original prediction scores and ranks, the order of suggestions shown, your confirmation or unresolved choice, and the separate consent decision. This server-side record keeps retries consistent and preserves what the model predicted separately from what you selected. Declining sharing means FormLevel does not copy the recording or pose data into the training-candidate bucket.
  • Exercise-matching text: the exercise name or short movement description you enter after rejecting automatic matches, together with the published catalog used to return possible exercises.
  • Planner selections: age range, fitness goal, experience, training schedule, equipment, exact height and weight, optional estimated body-fat percentage, activity level, diet preferences, food restrictions, budget, cooking time, unit preference, workout completion, difficulty, skipped movements, per-exercise "too heavy" or "too light" responses, optional check-in notes, and similar answers.
  • Access and security data: the beta session token when the private gate is enabled, an anonymous job-continuity token in public mode, access attempts, request timestamps, IP address or network information, rate-limit events, and error or security logs.
  • Account and profile data: your Supabase user ID, email, username, display name, optional avatar, onboarding status, measurement system, experience level, optional saved height and weight, an optional self-reported body-fat estimate, account timestamps, and authentication-session data managed by Supabase.
  • Saved workout and progress data: guided workout name and day, completion time, duration, completed exercises, sets, reps, weight or duration, form score when available, check-in notes, XP, level, badges, streaks, totals, and completed onboarding quests.
  • Support data: your account ID, email, display name, request category and message, optional screenshot, submitting page, app version, browser type, ticket number, delivery status, and submission timestamps.
  • Usage and device data: browser and device information, page views, performance measurements, referrer information, and ordinary network and request metadata processed by Vercel Analytics and Speed Insights. FormLevel also sends Vercel a fixed, allowlisted set of coarse event names: intro viewed and tools reached; Form Check opened, analysis started, confirmation reached, and report viewed; and, for each planner, opened, started, halfway, ready, generation started, and plan generated. Each milestone event contains only its event name. FormLevel adds no custom properties and no account, user, session, job, video, or plan identifier. The events do not include measurements, planner answers, exercise names, uploaded files or video content, generated plans, or analysis results. Vercel's dashboard shows FormLevel aggregate milestone counts and drop-off; it does not provide FormLevel an individual visitor journey from these events. FormLevel excludes authentication, contact, onboarding, profile, progress, and settings routes from this telemetry and removes query strings and page fragments from analytics URLs. Separately, the backend counts a small allowlisted set of operational exercise-recognition events, such as suggestions shown, search or candidate choice, analyzer availability, and optional training-consent decisions. Those backend logs are not the Vercel funnel events. They exclude account and job identifiers, exercise names and IDs, model scores, video data, private URLs, tokens, and health payloads; candidate rank is their only property.
  • Browser-stored data: unit, appearance, accessibility, planner defaults, generated plans, temporary guided-workout state, and guest check-ins. Depending on the feature, this data is stored in local storage or session storage on that browser. The beta access credential and the separate public-mode job-continuity credential are instead kept in host-only, HttpOnly cookies that JavaScript cannot read. The public-mode credential identifies a temporary job owner and does not unlock the private beta gate. When you sign in, Supabase stores the account session in browser storage so it can be restored after a refresh.

FormLevel currently has no payment flow. Signed-in profiles, optional saved measurements, and completed workout progress are stored in Supabase; guest plans and guest progress are not added to an account automatically. Saved measurements prefill a new diet planner but do not replace answers in an existing planner session. Passwords are handled by Supabase Auth and are not stored in FormLevel's public database tables or sent to the FormLevel API. FormLevel does not ask for your legal name, mailing address, or payment-card details.

2. How information is used

  • provide exercise recognition, pose processing, rep analysis, overlays, reports, and planning features;
  • generate concise coaching, workout, and meal-plan text;
  • calculate estimated starting dumbbell ranges and adjust later workout days from your check-in;
  • deliver licensed exercise demonstrations;
  • receive, investigate, reply to, and prevent abuse of contact and support requests;
  • operate, maintain, debug, secure, and improve the beta;
  • measure aggregate feature completion and drop-off to improve usability, not to personalize guidance, profile a visitor, or make decisions about a user;
  • queue separately consented exercise recordings for future authorized human label review;
  • enforce access and usage limits and prevent abuse; and
  • comply with law and protect users, the service, and others.

FormLevel does not automatically treat a user selection as a trusted training label, and it does not automatically train or retrain a model from uploaded videos. A separately consented contribution is kept only as a private review candidate. It becomes eligible for a future exercise-recognition training set only after an authorized human reviewer approves or corrects the label. FormLevel does not use these videos to train a general-purpose AI model. If those practices change, this policy and the collection notice must be updated before the new use begins.

Human review is not exposed through a public or ordinary-user interface. A review may occur only after FormLevel enables reviewer identity, authorization, and audit controls for specifically authorized people. Until then, contributions remain private pending candidates and are accessible only to the private service systems and limited service operators who need access for storage, security, deletion, or legal obligations.

3. AI processing

Workout and meal-plan selections and measurements are sent to OpenAI to generate a structured plan. When you provide a body-fat estimate, FormLevel also sends meal planning an approximate lean-body-mass value derived from that estimate and your weight. If you choose "I'm not sure," FormLevel does not calculate or send that derived value. When you choose "Improve plan," the current plan, planner selections, completed-day number, workout check-in, per-exercise load feedback, and optional note are sent to OpenAI so later days can be adjusted. Initial dumbbell ranges are calculated by FormLevel from limited selections and exercise metadata; they are not produced from a strength test.

If automatic exercise suggestions do not match, the exercise name or movement description you enter is sent to OpenAI with FormLevel's published exercise catalog so the service can return possible catalog matches. For form coaching, OpenAI receives derived evidence such as rep count, pose-based angles, depth status, tempo, quality checks, and detected issues. FormLevel does not intentionally send the raw uploaded video to OpenAI.

AI output may be inaccurate. See the Fitness Disclaimerfor important limitations.

4. Service providers and disclosure

FormLevel uses providers that process information to perform specific services:

  • Vercel hosts the website, forwards same-origin API requests and their payloads to Railway, and provides aggregate analytics and performance measurement. Vercel receives ordinary network, page, device, referrer, and request metadata needed to provide those services;
  • Railway hosts the backend, video-processing worker, logs, and temporary media storage;
  • OpenAI generates structured coaching and planner responses;
  • Supabase authenticates product accounts and stores profiles, workout history, progress, contact and support requests, private screenshots and avatars, the exercise catalog, licensed media, exercise-recognition audit records, and separately consented private exercise-training candidates; and
  • Resend delivers support notifications, confirmations, and replies by email.

Providers may receive technical data, including IP addresses and request metadata, as part of hosting and security. FormLevel may also disclose information when required by law, to investigate misuse or security incidents, to protect rights and safety, or as part of a business transfer with appropriate safeguards.

Separately consented recognition contributions are not shared with other users or made public. FormLevel service operators and provider administrators with privileged credentials may technically access them only when authorized and necessary to operate, secure, review, delete, or meet legal obligations for the service. This policy does not claim that developers or administrators can never access private data.

FormLevel does not currently sell personal information, share it for cross-context behavioral advertising, or provide uploaded videos to data brokers.

5. Retention and deletion

  • In the hosted production configuration, the source video is scheduled for deletion after analysis finishes. A failed or rejected job also triggers deletion of its source and generated artifacts.
  • Generated preview frames, pose images, overlay videos, and in-memory job reports are currently configured for a 24-hour retention window. Cleanup runs on service startup and during later upload activity, so deletion may occur after the exact 24-hour mark.
  • Recognition audit rows without active improvement consent or a retained training asset follow the same configured 24-hour live job-expiry window and are removed in bounded background cleanup batches. Encrypted database recovery copies may retain an older version under the documented recovery target of 14 daily and 8 weekly recovery points if those backups are enabled; the provider configuration still requires deployment verification. Before a restored copy becomes accessible, FormLevel reapplies the live expiry cleanup so expired recognition rows are not reintroduced to the active service.
  • If Supabase temporarily cannot accept a completed or failed recognition-job update, FormLevel writes a minimal terminal-status retry record to the private server volume. It can remain beyond the ordinary 24-hour window until the background worker successfully replays it or an operator removes a persistently invalid entry. It contains job-status metadata, not the uploaded video or extracted pose data.
  • A source video follows the ordinary short retention path unless a signed-in user separately opts in to recognition improvement. The private contributed copy and its review metadata are then retained until consent is revoked, the account is deleted, or FormLevel removes the candidate under its data-retention practices. Revocation immediately removes the candidate from training eligibility and schedules its active private video and pose-data objects for deletion; a temporary provider failure may delay completion and will be retried. The ordinary short-lived recognition audit record, including the model suggestions and confirmation, can remain until the 24-hour live expiry described above, and encrypted recovery copies age out under the disclosed provider recovery schedule. Revocation does not delete ordinary reports, workout history, or progress.
  • Signed-in profile, workout-history, and progress records remain until the account or applicable records are deleted. An account-deletion request has a 14-day cancellation period. The account remains active during that period, and the signed-in owner can cancel the request from Settings. After the deadline, FormLevel removes the Supabase Auth user, account-linked FormLevel rows, and the avatar object when available. Account deletion also revokes recognition-improvement consent and removes active private video and pose-data contribution objects. Processing or retries may finish after the exact deadline. Browser-stored guest plans and temporary progress remain until you reset the relevant feature or clear site data. Beta and anonymous job-continuity sessions become invalid when they expire. Their HttpOnly cookies are removed when they expire or when site data is cleared; the beta cookie is also removed when you disconnect beta access. Private-browser site data is normally discarded after all private windows close. The account session remains until you sign out, clear site data, revoke it, or it expires.
  • Support tickets and private screenshots are kept while reasonably needed to respond, investigate product issues, prevent abuse, and meet legal obligations. A screenshot link included in the support email expires, but the private stored screenshot is not deleted merely because that link expires.
  • Vercel analytics data follows the current Vercel plan and provider settings rather than a shorter FormLevel event-deletion promise. Under FormLevel's current Pro reporting window, the analytics dashboard can include up to 12 months of reporting data. Vercel and other hosting, AI, and security providers may retain operational or security logs for longer under their own settings and legal obligations.

6. Security

FormLevel uses access sessions, request limits, private server-side API keys, origin restrictions, security headers, upload validation, protected media routes, Row Level Security, ownership-checked database functions, dependency scanning, and restricted storage paths. Retained recognition contributions are kept in a non-public bucket with no ordinary-user read route; access is limited to private service systems and specifically authorized reviewers under the controls described above. No internet service can guarantee absolute security. The shared beta PIN controls access to the beta, while individual Supabase accounts protect personal profile and progress records. Do not upload a recording you would be uncomfortable transmitting to a hosted service.

7. Your choices and privacy rights

You can choose not to upload a video or generate a plan, continue as a guest, clear local browser data, close the beta session, sign out, edit your profile, omit a support screenshot, reset a generated plan, leave optional check-in fields blank, leave recognition-improvement sharing unchecked, revoke that consent and delete retained contribution copies from Settings, schedule permanent account deletion, or cancel that request during its 14-day grace period. You may also request access, correction, or deletion where applicable law provides those rights. FormLevel may need an account email, ticket number, approximate request time, or job identifier to locate relevant data, and some temporary data may already have been deleted.

Aggregate Vercel analytics are on by default on eligible pages. If your browser reports Global Privacy Control or Do Not Track, FormLevel treats either signal as a request not to load Vercel Analytics or Speed Insights. You can also use browser controls or content-blocking tools to block analytics requests. These choices do not affect FormLevel's core features.

Submit a privacy request by the following method: hello@formlevel.app. FormLevel may need to verify that a request concerns your information before acting on it. You will not be discriminated against for exercising a privacy right granted by applicable law.

8. Children and teens

FormLevel is not directed to children under 13 and does not knowingly collect their personal information. Do not use the service or submit information if you are under 13. Users between 13 and the age of legal majority should use FormLevel only with permission and supervision from a parent or legal guardian.

9. International processing

FormLevel and its providers may process information in the United States and other countries. Those places may have different privacy laws from where you live. Appropriate protections will be used where required by applicable law.

10. Policy changes and contact

This policy will be updated when FormLevel's data practices materially change. The revised policy will show a new effective date, and an in-product notice will be provided when practical. Questions or requests can be sent by the following method: hello@formlevel.app.