Privacy
Privacy Policy
This policy describes FormLevel's current private-beta data practices in plain language, including what happens to uploaded exercise videos, planner answers, and measurements.
Effective and last updated July 19, 2026
Quick notice at collection
FormLevel uses an uploaded exercise video to run pose detection and create a report. It uses your planner answers and measurements to generate a workout or meal plan. If you use guided training, it also processes workout progress, check-in choices, per-exercise load feedback, and any optional note you enter. If you contact support, FormLevel processes your account email, message, and any screenshot you choose to attach. The service receives technical data needed to deliver and protect the beta. FormLevel does not currently sell personal information or use it for targeted advertising.
1. Information FormLevel processes
- Exercise video data: the selected recording, filename, file type, file size, duration, frame rate, resolution, pose landmarks, movement measurements, generated preview frames, skeleton overlays, rep timing, and analysis results. A video may include your face, body, voice, clothing, and surroundings.
- Planner selections: age range, fitness goal, experience, training schedule, equipment, exact height and weight, estimated body-fat percentage, activity level, diet preferences, food restrictions, budget, cooking time, unit preference, workout completion, difficulty, skipped movements, per-exercise "too heavy" or "too light" responses, optional check-in notes, and similar answers.
- Access and security data: the beta session token when the private gate is enabled, an anonymous job-continuity token in public mode, access attempts, request timestamps, IP address or network information, rate-limit events, and error or security logs.
- Account and profile data: your Supabase user ID, email, username, display name, optional avatar, onboarding status, measurement system, experience level, account timestamps, and authentication-session data managed by Supabase.
- Saved workout and progress data: guided workout name and day, completion time, duration, completed exercises, sets, reps, weight or duration, form score when available, check-in notes, XP, level, badges, streaks, totals, and completed onboarding quests.
- Support data: your account ID, email, display name, request category and message, optional screenshot, submitting page, app version, browser type, ticket number, delivery status, and submission timestamps.
- Usage and device data: browser and device information, page views, performance measurements, and interactions collected through Vercel Analytics and Speed Insights.
- Browser-stored data: unit, appearance, accessibility, planner defaults, generated plans, temporary guided-workout state, and guest check-ins. Depending on the feature, this data is stored in local storage or session storage on that browser. The beta access credential and the separate public-mode job-continuity credential are instead kept in host-only, HttpOnly cookies that JavaScript cannot read. The public-mode credential identifies a temporary job owner and does not unlock the private beta gate. When you sign in, Supabase stores the account session in browser storage so it can be restored after a refresh.
FormLevel currently has no payment flow. Signed-in profiles and completed workout progress are stored in Supabase; guest plans and guest progress are not added to an account automatically. Passwords are handled by Supabase Auth and are not stored in FormLevel's public database tables or sent to the FormLevel API. FormLevel does not ask for your legal name, mailing address, or payment-card details.
2. How information is used
- provide exercise recognition, pose processing, rep analysis, overlays, reports, and planning features;
- generate concise coaching, workout, and meal-plan text;
- calculate estimated starting dumbbell ranges and adjust later workout days from your check-in;
- deliver licensed exercise demonstrations;
- receive, investigate, reply to, and prevent abuse of contact and support requests;
- operate, maintain, debug, secure, and improve the beta;
- enforce access and usage limits and prevent abuse; and
- comply with law and protect users, the service, and others.
FormLevel does not currently use uploaded videos to train its own general-purpose AI model. If that practice changes, this policy and the collection notice must be updated before the new use begins.
3. AI processing
Workout and meal-plan selections and measurements are sent to OpenAI to generate a structured plan. FormLevel also sends meal planning an approximate lean-body-mass value derived from the weight and body-fat estimate you enter. When you choose "Improve plan," the current plan, planner selections, completed-day number, workout check-in, per-exercise load feedback, and optional note are sent to OpenAI so later days can be adjusted. Initial dumbbell ranges are calculated by FormLevel from limited selections and exercise metadata; they are not produced from a strength test.
For form coaching, OpenAI receives derived evidence such as rep count, pose-based angles, depth status, tempo, quality checks, and detected issues. FormLevel does not intentionally send the raw uploaded video to OpenAI.
AI output may be inaccurate. See the Fitness Disclaimerfor important limitations.
5. Retention and deletion
- In the hosted production configuration, the source video is scheduled for deletion after analysis finishes. A failed or rejected job also triggers deletion of its source and generated artifacts.
- Generated preview frames, pose images, overlay videos, and in-memory job reports are currently configured for a 24-hour retention window. Cleanup runs on service startup and during later upload activity, so deletion may occur after the exact 24-hour mark.
- Signed-in profile, workout-history, and progress records remain until the account or applicable records are deleted. An account-deletion request has a 14-day cancellation period. The account remains active during that period, and the signed-in owner can cancel the request from Settings. After the deadline, FormLevel removes the Supabase Auth user, account-linked FormLevel rows, and the avatar object when available. Processing or retries may finish after the exact deadline. Browser-stored guest plans and temporary progress remain until you reset the relevant feature or clear site data. Beta and anonymous job-continuity sessions become invalid when they expire. Their HttpOnly cookies are removed when they expire or when site data is cleared; the beta cookie is also removed when you disconnect beta access. Private-browser site data is normally discarded after all private windows close. The account session remains until you sign out, clear site data, revoke it, or it expires.
- Support tickets and private screenshots are kept while reasonably needed to respond, investigate product issues, prevent abuse, and meet legal obligations. A screenshot link included in the support email expires, but the private stored screenshot is not deleted merely because that link expires.
- Hosting, analytics, AI, and security providers may retain operational logs under their own settings and legal obligations.
6. Security
FormLevel uses access sessions, request limits, private server-side API keys, origin restrictions, security headers, upload validation, protected media routes, Row Level Security, ownership-checked database functions, dependency scanning, and restricted storage paths. No internet service can guarantee absolute security. The shared beta PIN controls access to the beta, while individual Supabase accounts protect personal profile and progress records. Do not upload a recording you would be uncomfortable transmitting to a hosted service.
7. Your choices and privacy rights
You can choose not to upload a video or generate a plan, continue as a guest, clear local browser data, close the beta session, sign out, edit your profile, omit a support screenshot, reset a generated plan, leave optional check-in fields blank, schedule permanent account deletion from Settings, or cancel that request during its 14-day grace period. You may also request access, correction, or deletion where applicable law provides those rights. FormLevel may need an account email, ticket number, approximate request time, or job identifier to locate relevant data, and some temporary data may already have been deleted.
Submit a privacy request by the following method: hello@formlevel.app. FormLevel may need to verify that a request concerns your information before acting on it. You will not be discriminated against for exercising a privacy right granted by applicable law.
8. Children and teens
FormLevel is not directed to children under 13 and does not knowingly collect their personal information. Do not use the service or submit information if you are under 13. Users between 13 and the age of legal majority should use FormLevel only with permission and supervision from a parent or legal guardian.
9. International processing
FormLevel and its providers may process information in the United States and other countries. Those places may have different privacy laws from where you live. Appropriate protections will be used where required by applicable law.
10. Policy changes and contact
This policy will be updated when FormLevel's data practices materially change. The revised policy will show a new effective date, and an in-product notice will be provided when practical. Questions or requests can be sent by the following method: hello@formlevel.app.