Privacy Policy — Lehko

Last updated: August 16, 2026

This Privacy Policy explains what data Lehko collects, why, and what rights you have over it. Lehko (“Lehko”, “we”, “us”, “our”) is operated by a sole proprietor registered in Ukraine, and is the data controller for the purposes of this policy. Our full registration details are available on request — write to [email protected] and we will send them.

We apply EU/GDPR-level data protection standards to all Lehko users, regardless of where you live — not just where local law requires it.

1. Scope

This policy applies to the Lehko mobile app (iOS and Android) and covers all personal data we process when you use it.

2. Data We Collect and Why

DataWhy we collect it
Account and authentication data (e.g., email, sign-in identifiers)To create and secure your account, and to let you access your data across devices.
Body metrics from onboarding (height, weight, age, sex, goals)To calculate your calorie and macronutrient targets and personalize the App.
Meal photosTo identify food and estimate nutrition via AI analysis (see Section 4).
Nutrition logs (meals, quantities, timestamps)To provide your food diary, progress tracking, and history.
Subscription and purchase data (via Apple/Google and Adapty)To manage your entitlements, billing status, and provide customer support for purchases.
Apple Health data (only if you connect it)To sync relevant health metrics (e.g., weight, activity) you authorize, into your Lehko profile.
Technical diagnostics (crash stack traces, app/device version, operating system, installation identifiers, and limited app logs around a failure)To identify and fix crashes and stability problems. We do not attach meal photos, screenshots, health data, or your Lehko account identifier to crash reports.

We don’t collect data beyond what’s needed for these purposes, and we don’t have any social, community, or advertising features that would require additional tracking.

Under GDPR, we rely on the following legal bases:

  • Contract — processing your account data, meal logs, and body metrics is necessary to provide the App’s core functionality, which you’ve agreed to by using the Service.
  • Consent — connecting Apple Health, and any optional data sharing, is based on your explicit, revocable consent, given at the point you enable the feature.
  • Legitimate interest — we use limited technical data (e.g., crash logs, if enabled) to keep the App secure and functioning, balanced against your privacy interests.

You can withdraw consent at any time (Section 7) without affecting the lawfulness of processing carried out before withdrawal.

4. How Meal Photos Are Processed

When you take a photo of a meal, the image is sent to Google’s Gemini AI API for analysis. Google’s model identifies the food in the photo and returns an estimated calorie and macronutrient breakdown. This processing happens server-side, as part of every scan — we don’t fabricate or simulate results.

Google processes these photos under its own API terms and data-handling commitments; we don’t control Google’s infrastructure. We retain meal photos as described in Section 6, and you can delete them at any time from your food diary.

5. Third-Party Processors and Sub-Processors

We share data with the following third parties, each acting as a processor or sub-processor for the purposes described:

  • Google (Gemini API) — receives meal photos for food identification and nutrition estimation.
  • Open Food Facts — receives barcode identifiers you scan, to look up product nutrition data. Open Food Facts is a public, open database; barcode lookups don’t include your personal account data.
  • Adapty — receives subscription and purchase-related data to manage entitlements and billing status.
  • Apple / Google (App Store, Google Play) — process payments and manage your subscription as the platform billing provider.
  • Apple Health — if you connect it, shares the specific health data types you authorize, directly between your device and Lehko, under Apple’s HealthKit permissions model.
  • Google Firebase Crashlytics — receives limited technical diagnostics when the App crashes or records a non-fatal stability error. Crashlytics retains crash stack traces and associated installation identifiers for 90 days before beginning deletion from live and backup systems.

We enter into data processing agreements with our processors where required by GDPR, and we only share the minimum data necessary for each service to function.

6. Data Retention

We keep your data for as long as your account is active, so the App can function and your history remains available to you. If you delete your account, we delete your personal data — including meal photos, logs, and body metrics — immediately, except where we’re required to retain limited records (e.g., transaction records) for legal or accounting purposes.

7. Your Rights

Regardless of where you live, you have the following rights over your data, consistent with GDPR:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Deletion — ask us to delete your account and personal data (you can also do this directly in the App).
  • Export — request your data in a portable format.
  • Withdraw consent — for any processing based on consent (e.g., Apple Health), withdraw it at any time.
  • Object or restrict — object to or ask us to restrict certain processing based on legitimate interest.

To exercise any of these rights, contact us at [email protected]. We’ll respond within the timeframe required by applicable law (generally within one month under GDPR). If you’re in the EU, you also have the right to lodge a complaint with your local data protection authority.

8. Children’s Privacy

Lehko is not intended for anyone under 16. We don’t knowingly collect data from children under 16. If we become aware that we’ve collected data from someone under this age, we’ll delete it promptly. If you believe a child has provided us data, contact us at [email protected].

9. International Data Transfers

Because Lehko uses providers like Google and Adapty, your data may be processed in countries outside your own, including outside the EU/EEA. Where this happens, we rely on appropriate safeguards required by GDPR, such as Standard Contractual Clauses or the processor’s own adequacy certifications, to ensure your data receives an equivalent level of protection.

10. Security Measures

We use industry-standard measures to protect your data, including encryption in transit, access controls on our backend systems, and limiting data access to what’s needed to operate the App. No system is perfectly secure, but we take reasonable steps to protect your information against unauthorized access, loss, or misuse.

11. Cookies and Analytics

Lehko does not use cookies, as it is a mobile app rather than a website. We do not run Firebase Analytics or other product-tracking tooling. Firebase Crashlytics automatically receives the limited technical diagnostics described in Sections 2 and 5 so we can detect and fix stability problems.

12. Changes to This Policy

We may update this Privacy Policy as the App evolves or as required by law. We’ll update the “Last updated” date above, and for material changes, we’ll notify you in the App or by email before they take effect.

13. Contact

For any privacy question or to exercise your data rights, contact us at [email protected].