Lift

Privacy Policy

Last updated: 12 July 2026

This Privacy Policy describes how Lift ("we", "our", or "us") collects, uses, and shares your personal data when you use our mobile application and related services (the "Service"). It also explains your rights regarding that data and how to exercise them.

By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.

Definitions

Account. A registered profile created via Sign in with Apple or Google Sign-In.

Personal Data. Any information relating to an identified or identifiable individual, including names, identifiers, IP addresses, and health metrics.

Service Provider. A third-party company that processes data on our behalf (for example, a cloud platform, push-notification provider, or analytics tool).

Usage Data. Information collected automatically, such as device type, app version, and crash diagnostics.

Data We Collect

Account & profile data

When you create an account and complete onboarding, we collect:

Signup location (IP-derived)

On the very first profile save, we record the IP address used to register, together with the country, region, city, and timezone derived from it via a third-party IP geolocation service. This signup location is captured once and is not refreshed when your IP changes (different network, VPN, travel). It is used for fraud-prevention, regional feature availability, and aggregated analytics. We do not use it to track your day-to-day movements.

Workout, fitness, and body data

While using the Service, we store workout sessions, exercise sets and reps, weights, durations, RPE, custom programs, favorites, body measurements, progress photos you upload, and similar fitness records.

Health data (Apple Health)

If you grant the relevant permissions, we read from Apple Health: heart-rate samples recorded during your workouts (from your Apple Watch or a paired heart-rate monitor), steps, active energy (calories), workouts, and body weight — used to show your progress inside the app. Heart-rate samples are summarised into average / minimum / peak BPM and a downsampled time series stored alongside the corresponding workout session. With your permission we also write to Apple Health: workouts you complete in Lift and body-weight entries you log, so your Apple Health record stays in sync. Each permission is optional and the app works without them.

Purchases & subscriptions

If you purchase a Premium subscription, the payment is processed entirely by Apple through your App Store account — we never see your card details. We receive and store your subscription status (product identifier, active/expired state, expiration date) so we can unlock Premium features on your account. Purchase receipts are validated by RevenueCat (see Sharing & Third Parties) acting as our processor.

Device and usage data

Like most apps, we automatically collect device model, operating-system version, app version, language, and crash / diagnostic data. We use a third-party crash reporter for stability monitoring.

Push notification tokens

If you enable notifications, we store your Firebase Cloud Messaging (FCM) device token so we can send you workout reminders and post-workout follow-ups.

How We Use Your Data

Sharing & Third Parties

We do not sell your personal data. We share data only with the following categories of recipients, and only to the extent necessary:

Health Data & Apple HealthKit

The Service integrates with Apple HealthKit. Data we read from HealthKit (heart rate, steps, active energy, workouts, body weight) is used solely to provide features inside the app — live and historical heart-rate views, progress charts, and keeping your logs in sync. Data we write to HealthKit (completed workouts and body-weight entries) is written only with your explicit permission. We never use HealthKit data for advertising, marketing, or to share with data brokers, and we never disclose HealthKit data to third parties for their own purposes. You can revoke HealthKit access at any time in Settings → Privacy & Security → Health → Lift.

Data Retention

We retain your data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain certain records for legal, accounting, or fraud-prevention purposes. Aggregated, non-identifying analytics may be retained indefinitely.

Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the right to:

You can delete your account and all associated data directly in the app at any time: Profile → Delete Account. For any other request, contact us at the address in the Contact section. We respond within 30 days.

Security

We use industry-standard safeguards: TLS for data in transit, encryption at rest where supported by our cloud providers, and authenticated access to backend APIs (every request must carry a valid Firebase ID token; cross-user access is rejected at the middleware layer). No system is perfectly secure, but we work to keep your data safe and to respond quickly to any incident.

International Transfers

Our service providers may process data in countries outside your jurisdiction, including the United States and the European Union. Where applicable, we rely on Standard Contractual Clauses or equivalent safeguards approved by the European Commission for cross-border transfers.

Children’s Privacy

The Service is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect data from such children. If you believe a child has provided us with personal data, please contact us so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via in-app notice or email. Continued use of the Service after a change means you accept the updated policy.

Contact Us

For questions about this policy or to exercise your privacy rights, contact:

apps@meliharik.dev