Privacy Policy for LIFFT

Last updated: July 2026

1. Overview

LIFFT is designed to be a minimalist, distraction-free training app.

It is built local-first: by default, your workouts, templates, and settings live on your device.

Some features go beyond your device, and only when you choose to use them:

• Connecting with a coach or partner. When you pair with a coach, or share a live workout or a workout link, a small amount of data passes through our backend server (Supabase) to make the connection. See Sections 5.2 and 5.3.

• Exporting to Google Sheets. If you connect Google, your workouts are written to a spreadsheet in your own Google Drive. See Section 5.1.

• iCloud Backup. If you turn it on, a copy of your data is stored in your personal iCloud account. See Section 6.

• In-App Purchases. Payments are handled entirely by Apple. See Section 3.

We do not run advertising or third-party analytics, and we do not track you across apps or websites. Where data does leave your device, we explain below exactly what is sent, where it goes, how long it is kept, and how to delete it.

2. Information We Collect

Data that stays on your device by default

Unless you use one of the connected features below, this stays only on your device:

• Logged workouts (exercises, sets, reps, weights, notes, dates)

• Templates and folders you create

• App settings, themes, fonts, and units

• Your local profile (name, username, optional email, optional photo)

Data you provide that may be shared when you use connected features

• Your name / first name — written into your Google Sheet and, when you pair with a coach, passed through our backend so your coach can identify you.

• Coach profile details (if you set up a coach profile): name, email, phone number, Instagram, website, bio, certifications, and a profile photo. These are shared with the clients you invite and pass through our backend to reach them.

• Workout data — written to your Google Sheet (if connected), and uploaded to our backend when you share a workout, share your history, or run a live paired session.

Data collected automatically

• A device push token is registered with Apple when the app launches so iCloud Backup can sync across your devices. This token stays within Apple and is never sent to LIFFT's servers.

• If you enable iCloud Backup, your device identifier and device name are stored inside your own private iCloud backup records.

We do not collect: location data, advertising identifiers (IDFA), or any data for advertising or cross-app tracking. We run no third-party analytics or tracking software.

3. In-App Purchases

LIFFT uses Apple’s secure In-App Purchase system.

We do not receive or store your payment information — all transactions are handled by Apple.

For details on how Apple processes purchase data, visit: https://www.apple.com/legal/privacy/

LIFFT offers optional paid features through Apple's In-App Purchase system, including subscriptions (LIFFT+, billed monthly or annually, and a separate LIFFT Custom subscription) and one-time color-pack purchases. Subscriptions may include a free trial. We only receive, from Apple, whether a purchase or subscription is active so we can unlock the corresponding features — never your payment or billing details.

4. Sharing Features

LIFFT allows you to export images of workouts or templates.

When you share this content, it is handled entirely by your device and your chosen destination (Photos, Messages, etc.).

Shareable links. When you create a link to a workout, template, folder, or workout history, the underlying data is uploaded to our backend server (Supabase) so the link can be opened by whoever you send it to. Anyone who has the link can view that content until the link expires. These links and their data are automatically deleted from our servers after 24 hours (see Section 5.2). Image and screenshot shares, by contrast, are handled entirely by your device and the app you send them to — we do not see, store, or transmit those images.

5. Third-Party Services

LIFFT does not use third-party advertising, analytics, or tracking software, and does not track you across other apps or websites. The third-party services we do use are:

• Apple — In-App Purchases (payments) and iCloud/CloudKit (optional backup and sync).

• Google — optional Google Drive and Google Sheets export (Section 5.1).

• Supabase — our backend server provider, which hosts the temporary data used for coach pairing, link sharing, and live workout pairing (Section 5.3).

We do not sell your data to anyone.

5.1 Google Account Integration (Optional)

LIFFT may allow you to connect your Google account to export workout data to Google Sheets.

If you choose to connect your Google account:

• The App will request permission to create and manage Google Sheets files in your Google Drive

• Workout-related data (such as exercises, sets, and logs) may be written to a spreadsheet in your Google Drive

LIFFT requests a single, narrow Google permission (drive.file). It can create and manage only the spreadsheet files it creates — it cannot see the rest of your Drive — and it does not request your Google email, profile, or identity. Your sign-in tokens are stored only in your device's secure Keychain and are never sent to LIFFT's servers.

How your sheet can be shared. When you use sharing or coaching features, LIFFT may:

• Apply a public, view-only link permission ("anyone with the link can view") so your sheet can be opened from a shared link. Anyone who has the link can read that sheet.

• Grant your coach edit access by email. When you connect with a coach you are shown a consent screen naming your coach's email; if you approve, LIFFT shares the sheet with that address as an editor (they can view and change your workout data), and Google sends them a notification email. This is the only way coach editing is granted — it is never silent.

• You can remove a coach's access (Remove Coach), delete the sheet, or manage permissions directly in Google Drive.

All data transferred to Google is initiated by your action and stored within your Google account.

Your use of Google services is subject to Google’s Privacy Policy:

https://policies.google.com/privacy

5.2 Coach–Client Connections (Our Backend)

LIFFT lets a coach invite a client through a private link. To pass the connection between two devices, a small record is created on our backend server (provided by Supabase). Depending on who you are, this record can contain:

• The client's first name (typed by the coach when inviting).

• The coach's profile card, if the coach created one: name, email, phone number, Instagram, website, bio, certifications, and a profile photo.

• A coach identifier used to match the coach and client.

• The client's Google Sheet link, written back so the coach can find the client's sheet.

How long we keep it. These records are temporary couriers. They are automatically deleted from our servers within 24 hours, and also as soon as the receiving device has saved the information locally — whichever comes first. After that, the connection lives only on the coach's and client's own devices. Anyone who obtains a coach invitation link can view the coach's contact card until the link expires.

Deletion. A coach can remove a client, and a client can remove a coach, at any time in the app, which clears the local copy on that device and stops sheet access. Because the backend records expire automatically, there is no long-term server copy to request deletion of. We do not use this information for advertising, and we do not sell it.

5.3 Live Workout Pairing (Optional, Real-Time)

If you start a live paired session ("LIFFT LIVE") and share the link, your in-progress workout — workout name, exercises, sets, reps, weights, completion, notes, and your display name — is uploaded to our backend server (Supabase) and updated continuously so your partner can follow along. Pairing is shared editing: the person you pair with can view and modify the sets, reps, weights, and notes in that session, so only pair with people you trust. Active sessions are deleted from our servers after 24 hours of inactivity, and completed sessions within 1 hour of ending.

6. iCloud Sync

If enabled, your data will be stored in your personal iCloud account managed by Apple.

We will still not have access to your information.

iCloud Backup is off by default. When on, the data that syncs to your private iCloud database includes your full workout history, your profile, your coach, client roster (including those clients' names and Google Sheet links), your Google Sheets settings, your customizations and purchases, and your device's name and identifier. LIFFT cannot read this data. Turning off iCloud Backup does not delete the copy already in iCloud, and deleting the app does not remove it — to delete it, use the in-app backup management screen or iOS Settings → your name → iCloud → Manage Account Storage.

7. Device Permissions

LIFFT asks for these device permissions only when you use the related feature, and you can change them anytime in iOS Settings:

• Notifications — to alert you when a rest timer finishes. If you turn on iCloud Backup, the app also uses Apple's silent background notifications to keep your backup in sync; these are not visible alerts.

• Camera — to scan a gym membership barcode, or to take a photo when you share a workout to Instagram Stories.

• Photos — to save a workout image to your photo library, and to choose a profile photo.

Camera frames and photo selections are handled on your device for these purposes; we do not collect them.

8. Data Security

Because LIFFT stores data locally, the security of your information depends on the security of your device.

We recommend enabling a passcode, keeping iOS updated, and using Apple’s built-in privacy protections.

When using third-party services such as Google, data security is also subject to the protections and policies of those services.

9. Your Rights

Where your data lives determines how to remove it:

• On your device: Delete individual items, use "Delete All Data" in Settings, or delete the app. Deleting the app does not remove the items below.

• In your Google Sheet: Use Delete Sheet or Disconnect Google, or delete the file in Google Drive.

• A coach's access to your sheet: Use Remove Coach, or manage sharing in Google Drive.

• On our backend (Supabase): Connection, share, and live-session records are automatically deleted within 24 hours (live sessions within 1 hour of completion).

• In iCloud Backup: See Section 6; deleting the app does not remove it.

If you have a request about your data that these controls don't cover, contact us at contactus@lifft.app and we will help.

If you choose to use third-party integrations such as Google, you may manage or delete your data directly through those services.

10. Children’s Privacy

LIFFT is intended for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us at contactus@lifft.app and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy if our features change in ways that affect privacy.

If so, we will revise the date at the top of this page.

12. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at:

contactus@lifft.app