Privacy Policy

Last updated: 23 July 2026 · Luke Robinson Personal Training (“LRPT”)

1. Who we are

LRPT is provided by [LEGAL ENTITY NAME] (“we”, “us”), registered in England & Wales at [REGISTERED ADDRESS]. We are the data controller for the personal data described in this policy. Privacy questions: [PRIVACY CONTACT EMAIL]. We are registered with the UK Information Commissioner's Office (ICO).

2. What we collect

Account details — name, email address, date of birth, sex, height, and your login credentials (passwords are hashed; we never see them).

Health and fitness information — this is the heart of the service, and it is “special category” data under UK GDPR: your PAR-Q health-screening answers; body weight and measurements; progress photos you choose to upload; workout logs; nutrition logs including meal photos and barcode scans; weekly check-ins (weight, adherence, energy, sleep, notes); journal entries; and — only if you connect them — data from Apple Health or WHOOP (heart-rate variability, resting heart rate, steps, sleep, activity). You can disconnect these at any time in the app.

Messages — your conversations with your coach, your messages to the AI coach (“Luke”), and anything you post in the community (posts, comments, likes).

Payments — handled entirely by our payment providers (Stripe and/or the checkout used at purchase). We never receive or store your card details; we hold only your subscription status.

Technical data — device type, app version, and basic logs needed to run and secure the service.

3. Health data and your explicit consent

We only process your health information with your explicit consent, which you give during onboarding (UK GDPR Article 9(2)(a)). We record what you agreed to and when. You can withdraw consent at any time by deleting your account in the app (Me → Delete account) or emailing us — withdrawal stops all processing but doesn't affect what was lawfully done before.

4. How we use your data

We use your data to: run your coaching (build your plan, set your nutrition targets, review your check-ins); compute your in-app scores and trends; power the AI coach's answers with your own context; run the community; take payment; and keep the service secure. Legal bases: performance of our contract with you, your explicit consent (health data), and legitimate interests (security, service improvement). We do not sell your data or use it for third-party advertising.

5. The AI coach

“Luke” chat and AI nutrition features are powered by Anthropic's Claude models. When you use them, your message and relevant coaching context (recent scores, workouts, goals) are sent to Anthropic to generate the reply. Under the API terms we use, Anthropic does not use this data to train its models. AI replies are generated automatically and may be imperfect — they are fitness guidance, not medical advice, and your human coach oversees your programme.

6. Who processes your data for us

We use a small set of service providers, each under a data-processing agreement:

Some providers process data outside the UK (including the US). Where they do, transfers are protected by recognised safeguards — UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the ICO's International Data Transfer Agreement / standard contractual clauses.

7. How long we keep it

For as long as your account is active. If you delete your account, your profile, health data, logs, messages and photos are deleted immediately from the live database; residual copies leave encrypted backups within 30 days. We may keep minimal billing records where tax law requires it (up to 6 years) and anonymised, aggregated statistics that no longer identify you.

8. Your rights

You can ask us to: access a copy of your data; correct it; delete it; restrict or object to processing; or export it in a portable format. Contact [PRIVACY CONTACT EMAIL] and we'll respond within one month. You can also complain to the ICO at ico.org.uk — but we'd appreciate the chance to sort it first.

9. Security

Data is encrypted in transit (TLS) and at rest. Access is enforced row-by-row in the database: clients can only ever read their own records, and your coach only their clients'. Administrative keys are held server-side only and never shipped in the app. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify you and the ICO as the law requires.

10. Age

The service is for adults. You must be 18 or over to create an account.

11. Changes

If we make material changes to this policy we'll tell you in the app or by email before they take effect, and where the change affects your health-data consent we'll ask for it again.