Privacy Policy

LightWeight Inc. (the "Company") is a fitness technology company based in the Republic of Korea. This Privacy Policy explains what personal information we collect through the LightWeight Platform, which comprises our mobile and tablet applications, websites, and Digital Exercise Equipment (the "Equipment"); how we use and share it; and the choices and rights you have. Two companion documents cover special categories in more detail: the Biometric Data Policy & Consent and the Consumer Health Data Privacy Policy.

1.Information We Collect

We collect personal information with your knowledge, telling you and obtaining consent where the law requires, in the following situations: when you enter it during sign-up or service use; when you sign in through an external account (such as Google or Apple) or verify your mobile phone number; when you create a Temporary Member account at a kiosk; when you contact customer support; at offline events and seminars; from Partner Centers and other partner organizations that obtained your consent to share it with us; automatically as you use the Service; and, with your separate consent, when you register for Facial Recognition Login.

The categories we collect are:

  1. Account and profile information (all members)
    • Account details: login ID (username), name, photo, member number, password, email, nickname, date of birth, mobile phone number, and device information
    • Body and workout information: gender, height, weight, exercise experience, self-tracked records (such as body measurements and other entries you log yourself), workout records ("Workout Data," as defined in the Terms of Service, including sensor measurements and values derived from them, movement trajectory and speed, and exercise evaluation scores), workout plans, AI analysis results, session reports, and Equipment usage records
    • External login information (identifiers for linked accounts such as Google or Apple)
  2. Temporary Member information (accounts created at a kiosk)
    • Name, mobile phone number, gender, height, weight, birth year, exercise experience, and Temporary Member account identifiers (including the member number used to log in to the Equipment)
  3. Automatically collected information (all users)
    • IP address and service usage records (log data, cookies, usage times, feature satisfaction ratings, and the like)
  4. Trainer information (trainer members only)
    • Work records and career information
  5. Facial recognition data (only members, including Temporary Members, who use Facial Recognition Login, with separate consent)
    • Facial recognition data (face images and the face templates derived from them)
    • On the Facial Recognition Login screen, the Equipment's camera operates and automatically captures an image when a face is detected close to the screen. Captured images are processed solely to match registered members; images of unregistered faces are not stored and are deleted immediately.
  6. Customer support information (users who contact support)
    • The content of your inquiry, support history, information you submit during the inquiry, and the outcome

2.How We Use Your Information

  1. Providing the Service: identifying and managing your account, connecting and logging you in to the Equipment, planning and running workouts, automatically recording and analyzing your training, AI-based workout analysis and plan generation and revision, linking you with Partner Centers, and issuing session reports
  2. Developing and improving the Service: demographic analysis, exercise volume and characteristics analysis, analysis of body condition and performance, and improving the quality of AI analysis and generation (including prompt improvement and satisfaction analysis)
  3. Support and dispute handling: receiving and handling inquiries and complaints, responding to failures, resolving disputes, and meeting legal obligations
  4. Preventing misuse and keeping the Service secure: preventing fraudulent use and account theft, and strengthening security
  5. Optional features: providing Facial Recognition Login; and, for members who have given the relevant consents, event and benefit announcements, personalized offers and promotional messages based on usage analysis, marketing messages sent by your linked Partner Center through our system, and delivering advertisements for third-party products and services that the Company has been engaged to promote

Some processing does not rest on consent: information generated automatically as you use the Service (such as IP addresses and usage records) and customer support information are processed because they are necessary to perform our contract with you and to keep the Service secure, and information we must keep under applicable law is processed to comply with those laws.

3.How We Share Your Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as follows.

  1. With the Partner Center you link. When you link your account to a Partner Center, that center's managers, trainers, and staff receive the information described in the Consent to Share Personal Information with Partner Centers, under the advance consent given at sign-up plus a separate consent naming that specific center, and only while the link remains active.
  2. With service providers who process data on our behalf, described in Section 4.
  3. Where required by law: for investigations or other requests made by authorities through lawful procedures.
  4. In de-identified form: statistics, academic research, or market research data processed so that it can no longer identify you may be provided to research institutions and similar bodies.
  5. In a business transfer: if personal information is transferred through a merger, acquisition, or transfer of business, we notify you before the transfer.

4.Service Providers

We use service providers to perform parts of our data processing under contracts that limit their processing to the purposes we specify and require safeguards, restrictions on subcontracting, our supervision, and liability for damages. The full, current list of providers and their work is published on the Third-Party Service Providers page and updated whenever a provider changes. Equipment installation, maintenance, technical support and servicing, remote inspection and control, applying and lifting Equipment use restrictions, and support for the Partner Centers it serves may be entrusted to the distribution and installation partner that sold and supplied the Equipment, in which case that partner processes the member information, Workout Data, and equipment-status information of those Partner Centers and their linked members, to the extent needed for that work.

5.Where Your Data Is Stored: Transfers to the Republic of Korea

The Company is based in the Republic of Korea, and the personal information we collect, including from users in the United States, is transmitted to and stored on servers located in the Republic of Korea, operated by the Company and its cloud infrastructure provider. Facial recognition data is stored on the servers of our facial recognition service provider, ITCEN PNS Co., Ltd., also in the Republic of Korea (see the Third-Party Service Providers page). Korean law, including the Personal Information Protection Act, applies to our handling of that data, in addition to any United States laws that apply to you, and we protect it with the safeguards described in Section 8 regardless of where you are located.

6.Transfers to AI and Analytics Providers in the United States

To provide AI-based features and analyze service usage, we also transfer limited data to providers in the United States:

  1. OpenAI OpCo, LLC (United States)
    • When: at the moments automated analysis runs during a workout (such as the end of a rest period between sets) and when you use AI features (such as workout plan recommendations), via network transmission (API)
    • Contact: privacy@openai.com
    • Data: the minimum needed from your Workout Data (including sensor measurements and derived values), workout plans, exercise experience, and body-related information such as gender, height, weight, and birth year, with directly identifying information (such as name and contact details) removed
    • Their use and retention: processed solely to generate AI analysis results and workout plans, and deleted within 30 days of processing
  2. Anthropic, PBC (United States; processing may pass through facilities outside the United States)
    • When: at the same moments as item 1, via network transmission (API)
    • Contact: privacy@anthropic.com
    • Data: the same minimized data as item 1, with directly identifying information removed
    • Their use and retention: processed solely to generate AI analysis results and workout plans, and deleted within 30 days of processing
  3. Google LLC (United States)
    • When: continuously during app and service use, through analytics tools (Firebase and similar)
    • Contact: https://policies.google.com/privacy
    • Data: device information, app usage records, error and performance records, and advertising identifiers
    • Their use and retention: processed to provide usage analytics and error diagnostics, and deleted or anonymized after at most 14 months

For the AI transfers (items 1 and 2), our contracts require that the recipients not use your information to train their AI models. You may object to these transfers by contacting the privacy officer in Section 12 in writing, by phone, or by email; you can keep using the Service, but AI-based analysis and planning features will be limited. To block the analytics collection in item 3, see Section 7.

7.Cookies, Analytics, and Advertising Identifiers

  • Our web services (such as the administrator portal) use essential cookies for staying logged in, security, and remembering settings such as language. You can block or delete cookies in your browser, but some features, such as staying logged in, may then be limited.
  • Our mobile and tablet apps automatically generate device information, app usage records, and error records during use, and use Google's Firebase (Analytics, Crashlytics, and similar) to analyze usage patterns and errors and improve quality. This information may be processed on Google's servers in the United States (Section 6).
  • Advertising identifiers (such as the Android advertising ID) may be collected only for usage analysis and misuse prevention; we do not use them for targeted advertising. You can block or reset identifier-based collection in your device settings:
    • Android: Settings > Google > Ads > Delete or reset advertising ID
    • iOS: Settings > Privacy & Security > Tracking > turn off "Allow Apps to Request to Track"
  • Changing these settings may limit some features.

8.How We Protect Your Information

We maintain administrative, technical, and physical safeguards for personal information, including:

  1. An internal data protection program with regular (quarterly) internal audits
  2. Limiting personal information handling to designated, trained staff
  3. Granting, changing, and revoking system access on a least-privilege basis, with records kept
  4. Access controls against unauthorized outside access, including intrusion prevention and detection
  5. Encryption of authentication data and other information requiring it, and encrypted channels for transmission
  6. Retention and regular review of access logs for the systems that process personal information, for the legally required period
  7. Security software against malicious programs, updated and checked regularly
  8. Physical access controls for places and materials where personal information is kept
  9. Supervision of service providers, with additional measures for processing that crosses borders
  10. Incident response: if personal information is breached, we notify affected users and report to the competent authorities without delay, as applicable law requires, and take the steps needed to minimize harm

9.Retention and Deletion

We delete personal information without delay once its purpose is fulfilled, such as when you close your account or withdraw the relevant consent, unless a law requires us to keep it, in which case we keep only the required items for the required period, in a segregated store.

  • Temporary Member accounts: if not converted to full membership within one year of creation, the account's personal information is deleted without delay, except for items we must retain under applicable law, which are kept in a segregated store for the required period only. Any registered face template is destroyed, not stored separately (see the Biometric Data Policy & Consent).
  • Dormant accounts: if you have no service activity for one continuous year, your account becomes dormant and its personal information is stored separately from active data. We notify you at least 30 days before the conversion, and you can resume use by logging in again. If a dormant account sees no activity for three more years, we may delete its personal information after notifying you at least 30 days in advance.
  • Deletion methods: printed materials are shredded or incinerated; electronic files are deleted using methods that prevent recovery.

10.Your Rights and Choices

You may, at any time, request to: access your personal information; correct errors; delete it; restrict its processing; or withdraw a consent you have given. You can make requests through customer support in the app, by phone (+82 31-212-3175), or in writing, by fax, or by email to the privacy officer in Section 12, and we will act without delay. A legal representative or an authorized agent may act for you with proof of authority.

We may decline all or part of an access, correction, or deletion request only where the law prohibits or limits it, or where fulfilling it would harm another person's life or body or unjustly infringe another person's property or interests. If we decline, we will explain why, and you may appeal by replying to our response; we will review your appeal and answer in writing.

If a member dies, a person with lawful authority, such as an heir, may request deletion of the member's account and personal information with supporting documents.

For Workout Data, body measurements, and other consumer health data, the Consumer Health Data Privacy Policy describes the additional rights available to you under Nevada law and similar laws, such as confirmation of collection, a list of recipients, and deletion timelines. Depending on your state of residence, you may have further rights under state privacy laws; we honor those that apply. You may also lodge a complaint with your state Attorney General or, in the Republic of Korea, the Personal Information Protection Commission.

11.Children's Privacy

The Service is not directed to children. You must be at least 14 years old to use the Service, and we do not knowingly collect personal information from anyone under 14, including children under 13 as defined by the Children's Online Privacy Protection Act (COPPA). If we learn that we have collected personal information from a child under 14, we delete it without delay.

12.Privacy Officer and Contact

The Company has designated a privacy officer responsible for protecting personal information and handling related complaints:

  1. Name: Seung-hyun Lee
    • Title: Chief Executive Officer
    • Phone: +82 31-212-3175
    • Email: contact@lightweight.run

13.Changes to This Policy

This Privacy Policy applies from its effective date. For material changes affecting your rights (such as changes to what we collect, how we use it, or with whom we share it), we announce the change on the Notices page at least 30 days before it takes effect, together with a comparison of the old and new versions; other changes are announced at least 7 days in advance. Previous versions remain available through the version selector on this page.

Effective Date and Contact Information

Posted: August 27, 2026

Effective: August 27, 2026

LightWeight Inc.

Website: www.lightweight.run

Email: contact@lightweight.run

Phone: +82 31-212-3175 (weekdays 10:00–18:00 KST)