Privacy Policy
Effective August 17, 2026
The short version
LeanScore analyzes a physique photo to estimate a body-fat range and a condition score. Your photo is sent one time to our AI provider to produce that estimate and is not kept on our servers afterward. Your results stay on your device. We don’t sell your data, run ads, or track you across other apps. You can delete everything at any time in Settings.
What we collect
- The physique photo you capture or choose, at the moment you request a scan. Your face may appear in it incidentally; see Faces and biometric data below.
- The basics you enter in onboarding: sex, age, height, weight, target look and date. These calibrate your estimate.
- Anonymous product-interaction analytics (which screens are used), with no advertising identifiers.
What we send to our AI provider
When you tap to scan, and only after you have agreed on the consent screen, we transmit your physique photo together with the sex, age, height, weight and goal you entered to Anthropic, PBC(“Anthropic Claude”), our third-party AI vision provider, via our own server. This is done solely to check whether the photo is usable and to generate your body-fat range and condition score. Nothing else is sent, and we share this data with no other third party.
It is not retained on our servers, is never sold, and is not used to train AI models. Anthropic, PBC deletes API inputs and outputs from its systems in accordance with its published commercial retention policy, within 30 days, except where content is flagged by its automated trust-and-safety systems or retention is required by law. We confirm that Anthropic, PBC provides the same or equal protection of your data as described in this privacy policy.
You must agree on the in-app consent screen before any of this data leaves your device. You can withdraw that consent at any time in Settings, under “Withdraw AI analysis consent”. Withdrawing stops all further analysis and deletes the photos and scan results stored on your device.
Faces and biometric data
LeanScore does not use face data. The app performs no facial recognition and no facial identification. It does not detect or map facial landmarks, and it does not create, derive, store or share a faceprint, a scan of face geometry, a biometric template, or any other biometric identifier. It contains no face-detection or face-recognition code, it calls no ARKit, Vision, TrueDepth, Core ML or LocalAuthentication API, and it does not use Face ID or any biometric authentication.
A physique photo is a photo of your body, so your face may appear in it incidentally. Your estimate is derived from the visible physique, your torso, your limbs, and the distribution of fat and muscle, and a photo showing only a face or head is rejected as unusable because there is no physique in it to assess. The instructions we send with every scan direct Anthropic, PBC not to identify or name the person in the photo, and not to describe anything beyond fat, muscle and conditioning. Those same instructions screen the photo for usability before anything is estimated, and one of the conditions they screen for is a subject who does not appear to be an adult, because LeanScore is for adults. That is a judgment about the whole image, not a measurement of your face: it produces no age and no biometric artifact, only a flag that marks the photo unusable. Nothing from a blocked scan is saved. No photo is written to your device and no scan record is created.
Your photo follows the path described above and no other. It is transmitted to Anthropic, PBC through our own server once per scan (a scan that fails and that you retry sends it again), processed to produce your body-fat range and condition score, and is not stored or written to any log on our servers. Under Anthropic’s commercial terms, Anthropic does not train its models on API inputs or outputs, and under its published commercial retention policy it deletes API inputs and outputs within 30 days, except where content is flagged by its automated trust-and-safety systems or retention is required by law. The only working copy is the one on your device, and it stays there until you remove it: Settings → Delete all photos & data permanently removes every photo and result from your device, and Settings → Withdraw AI analysis consent stops all further analysis and deletes the photos and scan results stored on your device. Because we keep no copy on a server, deleting on your device deletes it everywhere on our side.
Where your data lives
Your scans, photos, and results are stored locally on your device. We do not maintain an account for you and do not store your photos or results on our servers. Anonymous analytics are processed by our analytics provider (PostHog) and are not linked to your identity. Purchases and subscription status are processed by RevenueCat; the payment itself is handled by Apple. Neither receives your photos or your results.
Your choices
You control the camera and photo-library permissions in iOS Settings. You can decline AI analysis when first asked and still use the app to log your own measured readings, and you can withdraw consent later via Settings → Withdraw AI analysis consent. You can delete all photos and data at any time via Settings → Delete all photos & data, which permanently removes them from your device. Because we don’t hold your data on a server, deletion on-device is deletion everywhere.
Children
LeanScore is for adults. You must confirm you are 18 or older to use it. We do not knowingly collect data from anyone under 18.
Contact
Questions about privacy? Reach us through the contact form.