Trust & Privacy
How we handle your progress photos and data.
This page is maintained by the ProgressLens AI team to answer common security and privacy questions about the app. It describes the controls and practices in place today and is updated as the product evolves. It is not a third-party certification or independent audit.
Account access
Accounts are protected by email-and-password sign-in, with optional Google and Apple sign-in on supported platforms. Each account only sees its own check-ins, photos, weight history and insights — database access rules enforce per-user isolation on every read and write.
Privacy controls you choose
Before a photo leaves your device you can apply on-device face blur, chest cover and underwear cover. These cover layers are baked into the uploaded image so the stored copy already reflects the privacy settings you picked at capture time.
Photo storage & access
Progress photos live in a private storage bucket. They are not publicly browsable — the app generates short-lived signed URLs only for the signed-in owner when they open their own session. No other user, and no public visitor, can read your photos.
What we store
An account row (email, display name, optional age/sex/height/weight goals you provide during onboarding), your check-in sessions (date, weight, notes, photos), AI insights generated for those sessions, badges, and — for paid users — a subscription record from the payment provider. Health data you enter stays linked to your account and is not sold.
Third-party services we rely on
Authentication, database and file storage run on our backend platform (Supabase / Lovable Cloud). Web payments are processed by Stripe; mobile subscriptions are processed by Apple and Google via RevenueCat. AI insights are generated through the Lovable AI Gateway. These providers process the minimum data needed to deliver their part of the service.
Your rights over your data
You can edit your profile, weight history and check-ins from inside the app at any time. You can also delete an individual session — which removes its photos from storage — or delete your entire account from the Profile screen. Account deletion removes your profile, sessions, photos, weight history, insights and badges from our systems.
Data retention
Data is retained for as long as your account is active. When you delete a session or your account, the associated rows and files are removed. Backups taken before a deletion may persist for a limited window in our backend provider's standard backup retention and are not used to restore deleted data.
Security & privacy contact
Questions about how your data is handled, requests to access or delete your data, or reports of a suspected security issue can be sent to support@progresslensai.com. Please include enough detail to reproduce a security issue and allow us reasonable time to investigate before public disclosure.
Shared responsibility. ProgressLens AI is responsible for the application code, account isolation rules, and the privacy controls described above. Our backend, payment and AI providers are responsible for the security of the infrastructure they operate. You are responsible for keeping your sign-in credentials private and for choosing the privacy settings (face / chest / underwear cover) that suit you before capturing each photo.
This page is editable project content, not a certification. It does not, on its own, constitute legal advice or a regulatory compliance statement.
