Let's Get Hot

Privacy Policy

Short version: we collect what we need to plan your meals and workouts, we don’t sell it, we don’t track you, and the AI that builds your plans never learns your name.

Last updated August 4, 2026

What we collect

Almost all of it comes from you, during onboarding or in Preferences. We don’t buy data about you, and we don’t run analytics or advertising trackers.

Your account

  • Email address
  • Password (stored only as a bcrypt hash — we never see or keep the original)
  • If you sign in with Google, Apple, or Facebook: the verified email address and name they give us, and nothing else

About you

  • First and last name (last name optional)
  • Profile photo, if you upload one
  • Date of birth, biological sex, height, current weight, and target weight
  • Your goal, activity level, and chosen pace

Food and training preferences

  • Allergies, dietary restrictions, and eating style
  • Foods you love, foods you avoid, and preferred cuisines
  • Fitness level, equipment access, movement styles, and session length
  • Injuries and areas you asked us to protect

What the app creates for you

  • Weekly meal plans, recipes, and grocery lists
  • Weekly training plans and which sessions you completed
  • Saved and favorited recipes, along with your ratings and notes
  • Weigh-ins and daily step counts you log

Billing

  • Your Stripe customer ID, subscription status, plan, and renewal date
  • Card numbers never touch our servers — Stripe collects and stores them directly

Technical

  • Push notification subscriptions, if you turn notifications on
  • A private calendar-feed token, if you subscribe to your plan in a calendar app
  • Token and image counts per AI generation, so we can measure what the service costs to run

About your health information

Your birth date, sex, weight, allergies, and injuries are sensitive, and we treat them that way. We collect them for one reason: the math and the safety checks don’t work without them. Your age, sex, height, and weight produce your calorie target. Your allergies and injuries become hard rules that every recipe and every workout is checked against in code before you ever see it.

We are not a medical provider, and Let's Get Hot is not a medical record. We don’t share this information with insurers, employers, advertisers, or data brokers — ever.

How AI uses your information

Your plans are generated by OpenAI. Before anything is sent, we build a deliberately anonymous summary in a single place in our code: your nutritional targets, restrictions, allergies, injuries, preferences, and equipment. Your name, email address, and account ID are excluded by design and never leave our servers as part of a generation request.

OpenAI processes these requests through its business API, which does not use submitted data to train its models. Dish photos are generated from a recipe name and description only, and are cached and reused across all users — the images are not personal to you.

Who else touches your data

These are our service providers. We don’t sell your personal information, and we don’t share it for advertising or cross-context behavioural targeting.

  • OpenAI

    Generates your meal plans, workouts, and dish photos

    Your calorie target, goal, budget, dietary restrictions, allergies, food likes and dislikes, injuries, fitness level, and equipment. Never your name, email, or any account identifier.

  • MongoDB Atlas

    Stores the database

    Everything listed above, encrypted in transit and at rest.

  • Vercel

    Hosts and serves the application

    Standard server request logs, including IP address.

  • Stripe

    Processes subscription payments

    Your email address and payment details, which you enter on Stripe’s own checkout page.

  • Google (YouTube)

    Serves optional exercise tutorial videos

    Nothing until you tap a video. When you do, YouTube receives the request in privacy-enhanced mode.

  • Your browser vendor

    Delivers push notifications

    Apple, Google, or Mozilla relay the notification to your device if you enabled notifications.

Things you choose to share

Two features publish information on purpose, and both are entirely up to you:

  • Recipe links. Creating a link publishes that one recipe — its name, ingredients, and steps — to an unlisted web address anyone with the link can open. Nothing about you appears on the page, it isn’t indexed by search engines, and you can switch the link off at any time from the recipe.
  • Calendar subscriptions. The private feed URL exposes only meal or session names and dates. Treat it like a password: anyone you give it to can read it.

Your choices and rights

You can view and change everything about yourself in Profile and Preferences. Beyond that:

  • Download your data. Profile → Your data exports everything we hold about you as a JSON file.
  • Delete your account. Profile → Your data → Delete account removes your account and every record tied to it immediately. It cannot be undone.
  • Turn off notifications any time on the Notifications page.

Depending on where you live, you may also have the right to correct your data, object to processing, or lodge a complaint with a data protection authority. To make any request, email support@letsgethot.app.

How long we keep it

We keep your information for as long as your account exists, because your plans and history are the product. When you delete your account, we delete your profile, plans, grocery lists, workouts, saved recipes, weigh-ins, step logs, push subscriptions, profile photo, and recipe links right away.

Two things intentionally survive: cached dish photos, which are shared across all users and contain nothing personal; and records Stripe must retain for financial and tax compliance, which are governed by Stripe’s own policy.

Security

Passwords are hashed with bcrypt and never stored in readable form. Traffic runs over HTTPS, and the database is encrypted in transit and at rest. Access to private data is always scoped to your signed-in session on the server — never to an ID the browser can change. No system is perfectly secure, but we keep the amount of data we hold deliberately small.

Children

Let's Get Hot is not intended for anyone under 13, and onboarding won’t accept a date of birth younger than that. If you believe a child has created an account, email us and we will remove it.

Changes to this policy

If we change how we handle your information in a meaningful way, we’ll update the date at the top of this page and tell you in the app before the change takes effect.

Questions? Email support@letsgethot.app. See also Cookies & device storage and our Terms of Service.