SuperLyfe is an athletic coaching platform that connects athletes, coaches and sports consultancies. This Privacy Policy describes how we process your personal data in compliance with the Brazilian General Data Protection Law (LGPD — Law 13.709/18).
1. Who we are
SuperLyfe is operated by Elety Servicos Ltda, CNPJ 49.888.405/0001-05, headquartered in Brazil. For privacy matters, contact us at suporte@superlyfe.com.br.
2. Data we collect
We collect the following data, as necessary to provide the contracted services:
- Identification: full name, email, phone, CPF (or equivalent document for foreigners), date of birth, residential address.
- Health (sensitive data — LGPD art. 11): responses to the health intake questionnaire (conditions, smoking, medication use, physical activity), Par-Q questionnaire (cardiovascular readiness for physical activity), height, weight.
- Payment: credit card data processed and stored in tokenized form exclusively by the payment provider Asaas — SuperLyfe does not store full card numbers, CVV or expiry. We store only the last digits and brand for display. For card-storage and subscription-renewal authorizations, we record as evidence: the exact text displayed and accepted, its version, the date and time of acceptance, IP address and browser identifier.
- Wearables: when you authorize an available connection, we receive activities and health metrics such as heart rate, VO₂max, HRV, sleep and training sessions, subject to the permissions you grant and the data your device provides. Garmin connects directly to SuperLyfe, as described in the "Garmin data" section. Other wearable providers, and Garmin accounts connected through Terra API Inc. (for example, when the direct connection is not yet available to you, or for connections created before it was), go through Terra (see section 4). We also retain the source, account and authorizations associated with the data.
- Platform usage: login records, interactions with the coach tool (chat, WhatsApp Business messages), training feedback, race registrations.
- Technical: IP address, device identifier, operating system, app version.
3. Purposes and legal bases
- Contract performance (LGPD art. 7, V): create and maintain your account, process payments, deliver the training plan built by your coach, enable communication with your sports consultancy.
- Consent (LGPD art. 7, I and 11, II, "a"): processing of sensitive health data (health intake, Par-Q, wearable metrics) so your coach can prescribe appropriate and safe training.
- Legal obligation (LGPD art. 7, II): issuing invoices, retaining tax and accounting records.
- Legitimate interest (LGPD art. 7, IX): fraud prevention, platform security, aggregated usage metrics.
- Consent records (LGPD art. 8, §2 and art. 7, VI): keeping evidence of card-storage and subscription-renewal authorizations for accountability to the data subject and the regular exercise of rights in judicial and administrative proceedings and billing disputes.
Direct connection consents
When direct connection is available, you will review separate, versioned notices for each purpose:
- Data synchronization: receive and store authorized activities, history and health data to display your records and support your coach in following your progress.
- Workout transfer: transfer prescriptions, intensity parameters and scheduled dates to each device account you select as a destination. You must not upload data that you are restricted from transferring to Garmin.
- AI analysis (optional): use authorized data from that account as inputs to inference that supports workout analysis, summaries and recommendations, processed through Amazon Bedrock. Declining this purpose keeps authorized synchronization and views that do not use AI available.
You may withdraw each purpose separately. Authorization is tied to the provider, account and notice version: consent for Garmin does not authorize Strava data or another account. An analysis combining sources must respect the consent for every contributing source. Reconnecting a device does not restore withdrawn consent.
We record the accepted notice version and content, purpose, account, date and decision as evidence of your choice. Withdrawing AI use stops new use of that data for this purpose; this differs from deleting data already stored or requesting an export.
Garmin data
This section describes how the SuperLyfe application in the Garmin Connect Developer Program handles your data, from the moment you connect your Garmin account until you disconnect it or delete your SuperLyfe account. Garmin and SuperLyfe exchange this data directly, with no intermediary.
- You connect your Garmin account. In the SuperLyfe app, you choose to connect Garmin and review the purposes described in "Direct connection consents" above. You are then taken to Garmin's own sign-in and consent screen, where you decide what Garmin shares with SuperLyfe: activity data (Activity API), health data (Health API) and receiving workouts in Garmin Connect (Training API). You can change these permissions in Garmin Connect at any time.
- Garmin sends your data to SuperLyfe. Garmin sends new data over an encrypted connection (HTTPS) to SuperLyfe's server at api.superlyfe.com.br. We receive: activities (such as distance, duration, pace, laps, heart rate, elevation and GPS track), activity details, activity files (FIT) and activities you edit manually in Garmin Connect; daily summaries (such as steps, resting heart rate and stress); sleep summaries; and the device model. Your data from before the connection needs a separate permission on Garmin's consent screen. If you grant it, when you first connect we also request up to the last 30 days of your activities, daily summaries and sleep summaries, and no other data. If Garmin does not offer this permission, we receive only data from after you connect. We receive only what you allowed on Garmin's consent screen. We use it to show you your own records, match completed activities to the training plan your coach prescribed, and calculate training and recovery metrics.
- Where it is stored and how it is protected. We store Garmin data on Amazon Web Services (AWS) in the US East (N. Virginia) region, us-east-1, in infrastructure operated by Elety Servicos Ltda. The database and file storage are encrypted at rest, file storage only accepts encrypted connections, and the access credentials Garmin issues for your account are stored encrypted. Access is controlled by role.
- Who can see it. You; the sports consultancy you chose and its coaches; and SuperLyfe platform administrators, only to operate and support the service. We do not sell Garmin data and do not share it with advertisers.
- What we send to Garmin. When your coach schedules a workout in your training plan, and you have allowed workout transfer and selected your Garmin account as a destination, SuperLyfe sends that workout (steps, targets, notes and date) to your Garmin Connect calendar through the Garmin Training API. When your coach changes or removes it, we update or remove it there too. Beyond the requests needed to run the connection (confirming your account, requesting history and ending the registration when you disconnect), we send no other data to Garmin.
- Optional AI feedback. Only if you allow it, as a separate choice you can decline or withdraw at any time without affecting the connection, SuperLyfe uses your Garmin data as input to Amazon Bedrock, an AWS service running in AWS regions in the United States, to generate workout feedback and recovery insights for you and your coach. Garmin data is used only to generate these responses and is never used to train AI models. Without this permission, your Garmin data is not sent for AI processing.
- Retention and deletion. When you disconnect Garmin in the SuperLyfe app, we stop accepting new data from Garmin immediately. Shortly after, we end the registration with Garmin and delete the access credentials for your account, retrying if Garmin does not respond. If you remove SuperLyfe in Garmin Connect, Garmin sends us a deregistration notification; we confirm it with Garmin and then do the same. If you change permissions in Garmin Connect, Garmin notifies us and we apply the new permissions. Data already received stays in your history until you request its deletion or delete your account. When you delete your account or request deletion, we end the Garmin registration and delete the Garmin data we hold, including activity files, together with the data derived from it that our deletion process covers, such as the summaries and metrics we calculate from it. AI feedback generated from your Garmin data is deleted where our deletion process can link it to that data. Notifications already delivered to your devices cannot be recalled. The only exception is the legal retention described in the "Retention" section.
- Your controls. You can change what Garmin shares in Garmin Connect; allow or withdraw data synchronization, workout transfer and AI feedback separately in SuperLyfe's connection settings; disconnect Garmin in the app; and request access to, export of or deletion of your data by writing to suporte@superlyfe.com.br. Garmin handles the data it holds under the Garmin Connect Privacy Policy.
Any change to this section is submitted to the Garmin Connect Developer Program for written approval before it takes effect.
4. Sharing with third parties
We share data only with partners strictly necessary to deliver the service:
- Firebase (Google LLC) — authentication (Firebase Auth) and realtime database. Data stored on Google servers.
- Asaas (Asaas Gestão Financeira Ltda.) — payment processing via card, Pix and bank slip. SuperLyfe acts as the parent account holder with automatic split to partner sports consultancies.
- Garmin — for direct connections, we receive authorized Garmin account data and send workouts when you select that destination and authorize the transfer. Garmin processes data under its Garmin Connect Privacy Policy.
- Terra (Terra API Inc.) — connects other wearable providers, and Garmin accounts connected through Terra (for example, when the direct connection is not yet available to you, or for connections created before it was). Terra is not part of the direct Garmin connection described in the "Garmin data" section and does not receive data from it. Each account authorization remains specific.
- Amazon Web Services (Amazon Bedrock) — processes authorized data as inference inputs for AI analysis and recommendations. Optional direct connection consent determines which data from that account may contribute to this processing.
- WhatsApp Business (Meta Platforms, Inc.) — messages between athlete and coach, when enabled by your sports consultancy.
- Your sports consultancy — name, email, phone, health intake, Par-Q, goals, training feedback and wearable metrics are shared with the sports consultancy you chose and its coaches.
We do not sell personal data to third parties for advertising purposes.
5. International transfer
Some of our partners and processors (Firebase, Terra, Garmin and Amazon Web Services) are headquartered outside Brazil. These transfers occur based on standard contractual clauses and safeguards provided in LGPD art. 33.
6. Retention
We keep your data for as long as your account is active. After account deletion, we retain tax records for the legal period (5 years), security audit logs for 12 months, and evidence of card-storage and subscription-renewal consents for the period necessary for defense in judicial and administrative proceedings and billing disputes — even if the authorization was revoked before deletion. All other data is anonymized or deleted.
Disconnecting a wearable stops new data from that connection but does not delete history already stored. You may request access, export or deletion of retained data through the privacy contact below. Requests cover data from the identified sources and accounts, including data that contributed to analyses, subject to applicable retention requirements.
7. Your rights (LGPD art. 18)
At any time, you may:
- Confirm the existence of processing and access your data;
- Correct incomplete, inaccurate or outdated data;
- Anonymize, block or delete unnecessary data or data processed in non-compliance;
- Port your data to another provider;
- Request deletion of data processed under your consent;
- Be informed about with whom we share your data;
- Withdraw consent at any time.
To exercise any right, email suporte@superlyfe.com.br — we respond within 15 days.
8. Security
We use encryption in transit (TLS 1.2+) and at rest, role-based access control (athlete, coach, sports consultancy, administrator), and authentication via Firebase Auth (magic link or social providers). Card data is tokenized by Asaas and never traverses our servers.
10. Changes
We may update this Policy. The current version is always available at plataforma.superlyfe.com.br/privacy. Material changes will be communicated by email and will require new acceptance on your next login.