Last Updated: April 2026
Last Person Standing ("LPS," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information when you use the LPS application ("App"). By using the App, you agree to the practices described in this policy.
The LPS Challenge service is operated by Little Scarletto Apps Inc., a corporation incorporated under the laws of Ontario, Canada, which is the data controller for personal data processed under this Privacy Policy (referred to in this document as "we," "us," or "our").
1.1. Account Information: When you register, we collect your name, email address, and birth year to create and manage your account. Your birth year is used solely to calculate your personalized maximum heart rate (220 − age) for Zone 2+ heart rate zone detection.
1.2. Health and Fitness Data: When you connect a third-party health platform, we collect the following data solely for the purpose of calculating your Zone 2+ heart rate minutes:
We do not collect GPS location, sleep data, weight, nutrition, menstrual health, or any other health data beyond what is listed above.
1.3. Integration Credentials: When you connect Fitbit or Garmin, we store OAuth access tokens and refresh tokens in our database to enable ongoing activity sync on your behalf. These tokens are never shared with other users or third parties.
We use the data we collect exclusively to:
We do not use your health data for advertising, profiling, or any purpose beyond operating the fitness challenge.
3.1. Fitbit: If you connect your Fitbit account, we receive activity and heart rate data via the Fitbit Web API under the permissions you explicitly grant during the OAuth authorization flow. We request only the activity and heartrate scopes. Your Fitbit credentials are never stored; only OAuth tokens are retained.
3.2. Garmin: If you connect your Garmin account, we receive activity data via the Garmin Health API. We request only the HEALTH_ACTIVITY_DETAIL scope. Your Garmin credentials are never stored; only OAuth tokens are retained.
3.3. Apple Health (HealthKit): On iOS, the LPS app may request read access to your HealthKit workout and heart rate data. This data is read directly on your device and transmitted only to our servers. We do not share HealthKit data with third parties or use it for advertising.
3.4. Google Health Connect: On Android, the LPS app may request read access to your Health Connect exercise session and heart rate records. This data is read directly on your device and transmitted only to our servers. We do not share Health Connect data with third parties or use it for advertising.
Your data is stored in a PostgreSQL database hosted on Railway (a US-based cloud provider). We use HTTPS for all data in transit and apply industry-standard security practices including session-based authentication, hashed tokens, and scoped database access. No health data is stored in browser local storage or transmitted to third-party analytics services.
We retain your account and activity data for as long as your account is active. If you delete your account or disconnect an integration, the associated activity data and OAuth tokens are permanently deleted from our database within 30 days.
We do not sell, rent, or share your personal or health data with third parties for commercial purposes. We may disclose data only in the following limited circumstances:
You may at any time:
The App is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with their data, please contact us at privacy@lpschallenge.com and we will delete it promptly.
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
For privacy-related questions, data deletion requests, or concerns, contact us at: