Privacy Policy
Last updated: 12 May 2026 Controller: Lidbit Ltd., a company registered in England and Wales. Contact: [email protected]
The short version
overlay.fit is built so that we can’t see your stuff even if we wanted to.
- Your videos, .FIT / .GPX / .TCX files and Strava activity data never leave your phone. We have no backend that stores them.
- The app renders every video on-device using your phone’s hardware video encoder.
- If you connect Strava, the app talks to Strava directly from your phone using your own access token. We are never in the middle of that connection.
- We do not run analytics SDKs, tracking pixels or behavioural ads. The free tier shows rewarded ads through Google AdMob; those ads are governed by Google’s policies and you can opt out of personalised ads in-app.
- We do not train any AI models on your data.
The rest of this policy is the long-form version, written in plain English, that satisfies UK GDPR / EU GDPR transparency requirements.
1. Who we are
The “data controller” for overlay.fit is Lidbit Ltd., a company incorporated in England and Wales. You can reach us at [email protected] for any privacy question, including requests to exercise your data-protection rights.
2. The data we process
Because overlay.fit runs on-device, almost all of the data the app touches is processed by your phone, not by us. We’ve split the data into two buckets below.
2.1 Data processed only on your device (we never receive it)
- Video clips you import from your camera roll.
- Workout files (.FIT, .GPX, .TCX) you import from your watch, head unit or another fitness app.
- Strava activity data the app fetches from your connected Strava account (activity list, GPS track, sensor streams, lap data).
- Rendered videos the app creates by combining the above. These are written straight back to your photo library and never uploaded to us.
- Editor preferences (which template you used last, widget positions, recently used activities). Stored in the app’s sandbox on your device.
We do not have servers that hold any of this. There is no Lidbit account system, and the app does not sign you in to anything we operate.
2.2 Data third parties process so the app can work
- Apple App Store / Google Play. Handle subscription purchases and renewals. The app receives an entitlement state (“subscribed” or “not subscribed”) from these platforms. We never see your payment details, card number, billing address or full transaction history. Apple’s and Google’s own privacy policies govern that data.
- Strava. Optional. If you tap “Connect Strava” the app starts an OAuth flow inside an in-app browser. Strava issues an access token that is stored only on your device. From then on, the app talks to Strava’s API directly from your phone. Strava’s privacy policy applies to the data it holds about your Strava account.
- Google AdMob. Serves the rewarded ads that gate renders on the free tier. AdMob uses your device’s advertising identifier and may collect ad-interaction data. In the UK and EEA we use Google’s User Messaging Platform to request your consent before personalised ads are served; you can change your choice at any time in Settings → Privacy → Ad preferences.
- Apple / Google crash reporting. Anonymous crash and performance reports may be sent to Apple or Google if you’ve opted in to share diagnostics with them at the OS level. We do not run our own crash reporting SDK.
3. Why we process this data, and our lawful basis
Under UK GDPR every processing activity needs a lawful basis. Ours are:
| Activity | Purpose | Lawful basis |
|---|---|---|
| Reading your video, workout file or Strava data on-device | Performing the rendering you asked for | Contract - performing the service you bought |
| Storing your editor preferences on-device | Remembering your last template / widget layout | Legitimate interests - making the app usable |
| Subscription entitlement check via Apple / Google | Unlocking Pro features you paid for | Contract |
| Rewarded ads on the free tier | Funding the free tier | Consent (UK / EEA) / legitimate interests (rest of world) |
Because we don’t have a backend, we never become the controller of your video or workout data. Strava remains the controller of your Strava data; Apple / Google remain the controllers of your billing data.
4. How long we keep things
We don’t keep your videos or workout data at all - they live on your phone and you delete them when you delete the app or wipe the device.
Your Strava access token sits in the app’s secure storage on your phone until you disconnect Strava from inside the app, or revoke our access at strava.com/settings/apps.
Subscription entitlement state is held by Apple / Google for as long as you have an active subscription, per their retention policies.
5. International transfers
Because the app processes your video and workout data on your device, no international transfer of that data occurs through us.
When you use Strava or AdMob from inside the app, those services may transfer data internationally according to their own policies. Apple and Google likewise process subscription data on their global infrastructure.
6. Children
overlay.fit is not directed at children under 13. You must be at least the minimum age required to enter into a binding contract in your country to subscribe. We do not knowingly collect any data from children.
7. Your rights
Under UK GDPR / EU GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate personal data.
- Erase (“right to be forgotten”) personal data we hold about you.
- Restrict or object to certain processing.
- Data portability for data you provided to us.
- Withdraw consent at any time where consent is the lawful basis.
- Lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk).
For most users these rights produce a very short answer: we don’t hold any of your data, so there is nothing to access, rectify, erase or port. To exercise any of the rights above, or to confirm that we hold nothing about you, email [email protected] and we will respond within one month.
For data held by Strava, exercise your rights at strava.com. For data held by Apple or Google in connection with your subscription, exercise them with Apple or Google directly.
8. Cookies and tracking
The overlay.fit mobile app does not use cookies or web beacons. We do not place a third-party analytics SDK or marketing pixel in the app.
This website (overlay.fit) is a static marketing page. It does not set cookies, does not load third-party analytics and does not embed fingerprinting scripts.
9. Security
Your data stays on your phone, secured by your phone’s own platform security model (iOS Data Protection / Android keystore). Your Strava access token is stored in the platform secure storage (Keychain on iOS, EncryptedSharedPreferences on Android).
10. Changes to this policy
If we change this policy materially, we will surface the change in-app before the change takes effect and update the “Last updated” date at the top of this page.
11. Contact
Privacy questions, data-rights requests or anything you’d like us to clarify: [email protected].
Postal address available on request.