Privacy Policy for LIFFT
Last updated: September 2026
1. Overview
LIFFT is designed to be a minimalist, distraction-free training app.
It is built local-first: by default, your workouts, templates, and settings live on your device.
Some features go beyond your device, and only when you choose to use them:
- Connecting with a coach or partner. When you pair with a coach, or share a live workout or a workout link, a small amount of data passes through our backend server (Supabase) to make the connection. See Sections 5.2 and 5.3.
- Exporting to Google Sheets. If you connect Google, your workouts are written to a spreadsheet in your own Google Drive. See Section 5.1.
- iCloud Backup. If you turn it on, a copy of your data is stored in your personal iCloud account. See Section 6.
- Android Backup. On Android, if you turn backup on or choose Back Up Now, LIFFT stores LIFFT backup files in its hidden application-data folder in your own Google Drive. See Sections 5.1 and 6.
- In-App Purchases. On Apple devices, purchases are processed directly through Apple’s StoreKit and App Store systems. On Android, purchases are processed by Google Play, and RevenueCat helps LIFFT manage access to purchased features. See Section 3.
We do not run advertising or behavioral analytics, and we do not use attribution software or track you across apps or websites. On Android, RevenueCat provides purchase and subscription reporting only for billing and access to paid features. Where data does leave your device, we explain below what is sent, where it goes, how long it is kept, and how to delete it.
2. Information We Collect
Data that stays on your device by default
Unless you use one of the connected features below, this stays only on your device:
- Health and fitness data: logged workouts, including exercises, sets, reps, weights, notes, dates, and durations
- Templates and folders you create
- App settings, themes, fonts, and units
- Your local profile (name, username, optional email, optional photo)
Data you provide that may be shared when you use connected features
- Your name / first name — written into your Google Sheet and, when you pair with a coach, passed through our backend so your coach can identify you.
- Coach profile details (if you set up a coach profile): name, optional email address, optional phone number, Instagram, website, bio, certifications, and a profile photo. When you invite a client, these fields—including email and phone when present—are sent through Supabase and shown to the client you invite. LIFFT does not use phone numbers for automated SMS delivery or phone-number-based pairing. The invited client may choose to open Messages, Phone, or Mail from the profile card.
- Workout and fitness data — written to your Google Sheet if connected; included in optional backup if enabled; and uploaded to our backend when you share a workout or history or use a live paired session.
- Backup data — depending on the features you use, an optional backup may include workouts, templates and folders, a local profile and profile photo, saved friends’ names, usernames, status information and avatars, custom exercises and favorites, app settings and customizations, coach or client and Google Sheets metadata, and functional identifiers. Apple backups include a device name and identifier. Android backups include a random installation identifier.
Data collected automatically
- On Apple devices, LIFFT registers with Apple for remote notifications used by CloudKit synchronization. The app receives the device token locally but does not send it to LIFFT’s servers.
- On Android, RevenueCat creates an anonymous App User ID and processes Google Play purchase history so LIFFT can determine which purchases and subscriptions are active. RevenueCat also provides purchase and subscription reporting. LIFFT does not send RevenueCat your profile email or phone number.
- When you use backend sharing, coach connections, or LIFFT LIVE, LIFFT and Supabase use random installation- or coach-scoped identifiers to route and secure those features. These are functional identifiers, not advertising identifiers.
- If you enable iCloud Backup, your device identifier and device name are stored inside your own private iCloud backup records.
We do not collect location data or advertising identifiers, including Apple’s IDFA or the Android advertising ID. We do not use data for advertising or cross-app tracking.
3. In-App Purchases
LIFFT uses Apple’s secure In-App Purchase system.
We do not receive or store your payment information — all transactions are handled by Apple.
For details on how Apple processes purchase data, visit: https://www.apple.com/legal/privacy/
LIFFT offers optional paid features through Apple’s In-App Purchase system, including subscriptions (LIFFT+, billed monthly or annually, and a separate LIFFT Custom subscription) and one-time color-pack purchases. Subscriptions may include a free trial. On Apple devices, StoreKit supplies verified transaction and entitlement information needed to determine which paid features are active. LIFFT does not receive your complete payment or billing details.
On Android, purchases are processed by Google Play. LIFFT uses RevenueCat as a billing service provider to manage access to purchased features. RevenueCat processes an anonymous App User ID and Google Play purchase history, including product, transaction, subscription, and entitlement status. Google Play processes your payment method; neither LIFFT nor RevenueCat receives your complete card or bank-account details.
RevenueCat is used for Android purchases. The current Apple app verifies its purchases directly through StoreKit.
Manage or cancel a subscription through your Apple App Store or Google Play subscription settings. Refund requests are handled by the store that processed the purchase under that store’s policies.
Google Privacy Policy:
https://policies.google.com/privacy
RevenueCat Privacy Policy:
4. Sharing Features
LIFFT allows you to export images of workouts or templates.
When you share this content, it is handled entirely by your device and your chosen destination (Photos, Messages, etc.).
Shareable links. When you create a link to a workout, template, folder, or workout history, the underlying data is uploaded to our backend server (Supabase) so the link can be opened by whoever you send it to. Anyone who has the link can view that content until the link expires. These links and their data are automatically deleted from our servers after 24 hours (see Section 5.2). Image and screenshot shares, by contrast, are handled entirely by your device and the app you send them to — we do not see, store, or transmit those images.
5. Third-Party Services
LIFFT does not use third-party advertising, behavioral analytics, attribution, or tracking software, and does not track you across other apps or websites. RevenueCat provides Android purchase entitlement management and subscription reporting, not behavioral or cross-app tracking. The third-party services we use are:
- Apple — direct StoreKit and App Store purchase processing, and optional iCloud/CloudKit backup and synchronization on Apple devices.
- Google — Google Play purchase processing, optional Google Sheets export and sharing, and optional storage in Google Drive’s hidden application-data folder on Android.
- RevenueCat — Android purchase-history processing, subscription reporting, and entitlement management.
- Supabase — our backend provider for temporary coach–client handoffs, share links, and LIFFT LIVE sessions described in Sections 5.2 and 5.3.
We do not sell your data to anyone.
5.1 Google Account Integration (Optional)
LIFFT may allow you to connect your Google account to export workout data to Google Sheets and, on Android, to use optional Backup & Restore.
If you choose to connect your Google account:
- The App will request permission to create and manage Google Sheets files in your Google Drive
- Workout-related data (such as exercises, sets, and logs) may be written to a spreadsheet in your Google Drive
- On Android, if you use Backup & Restore, the App may create and manage LIFFT backup files in its hidden application-data folder in your Google Drive
For Google Sheets, LIFFT requests https://www.googleapis.com/auth/drive.file. This permission allows LIFFT to create and manage the specific Drive files used with LIFFT; LIFFT uses it for the Google Sheet it creates and cannot browse unrelated files in your Drive.
On Android, LIFFT requests https://www.googleapis.com/auth/drive.appdata only when you use Backup & Restore. This permission allows LIFFT to see, create, update, and delete only LIFFT’s own files in Google Drive’s hidden application-data folder. Those files do not appear in your normal Drive file list and cannot be accessed by other Drive apps.
LIFFT’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This applies to everything LIFFT receives through the two scopes it requests—https://www.googleapis.com/auth/drive.file and https://www.googleapis.com/auth/drive.appdata. We use that information only to provide and improve the Google Sheets export and Backup & Restore features you turned on. We do not transfer it to others except as needed to provide those features, and we never use it for advertising, never sell it, and never allow humans to read it except with your explicit permission, for security or legal reasons, or on data that has been aggregated and anonymised. The policy is at https://developers.google.com/terms/api-services-user-data-policy.
LIFFT does not request your Google account email, profile, contacts, or other identity information. Google sign-in tokens are stored only in secure storage on your device—Keychain on Apple devices and Android OS keystore-backed secure storage on Android—and are never sent to LIFFT’s backend servers.
How your sheet can be shared. When you use sharing or coaching features, LIFFT may:
- If you choose Share Link and confirm the warning, LIFFT applies a public, view-only permission (“anyone with the link can view”). Creating a Sheet alone does not make it public. Once you approve sharing, anyone who has the link can read that Sheet without signing in.
- Grant your coach edit access by email. You are shown a consent screen naming the coach’s email; if you approve, LIFFT shares the Sheet with that address as an editor, and Google sends a notification email containing an app-composed message with the client’s display name.
- You can remove a coach's access (Remove Coach), delete the sheet, or manage permissions directly in Google Drive.
All data transferred to Google is initiated by your action and stored within your Google account.
Your use of Google services is subject to Google’s Privacy Policy:
https://policies.google.com/privacy
5.2 Coach–Client Connections (Our Backend)
LIFFT lets a coach invite a client through a private link. To pass the connection between two devices, a small record is created on our backend server (provided by Supabase). Depending on who you are, this record can contain:
- The client's first name (typed by the coach when inviting).
- The coach's profile card, if the coach created one: name, email, phone number, Instagram, website, bio, certifications, and a profile photo.
- A coach identifier used to match the coach and client.
- The client's Google Sheet link, written back so the coach can find the client's sheet.
When present, the coach profile’s optional email address and optional phone number are transmitted through Supabase to the invited client as part of the currently shipping handoff.
How long we keep it. These records are temporary couriers. They are automatically deleted from our servers within 24 hours, and also as soon as the receiving device has saved the information locally — whichever comes first. After that, the connection lives only on the coach's and client's own devices. Anyone who obtains a coach invitation link can view the coach's contact card until the link expires.
Deletion. A coach can remove a client, and a client can remove a coach, at any time in the app, which clears the local copy on that device and stops sheet access. Because the backend records expire automatically, there is no long-term server copy to request deletion of. We do not use this information for advertising, and we do not sell it.
5.3 Live Workout Pairing (Optional, Real-Time)
If you start a live paired session ("LIFFT LIVE") and share the link, your in-progress workout — workout name, exercises, sets, reps, weights, completion, notes, and your display name — is uploaded to our backend server (Supabase) and updated continuously so your partner can follow along. Pairing is shared editing: the person you pair with can view and modify the sets, reps, weights, and notes in that session, so only pair with people you trust. Active sessions are deleted from our servers after 24 hours of inactivity, and completed sessions within 1 hour of ending.
6. Optional Backup and Sync
If enabled, your data will be stored in your personal iCloud account managed by Apple.
LIFFT does not receive a copy of the backup on its own servers. The LIFFT app accesses it through CloudKit on your authenticated Apple device to provide backup and restore.
iCloud Backup is off by default. When enabled, the data stored in your private CloudKit database can include your LIFFT app data, including workout history; templates and folders; your local profile; saved friends, including names, usernames, status information, avatars, and live-state information; custom exercises, usage, and favorites; app settings and customizations; coach-side client and shared-link information; Google Sheets metadata; tags; cached identifiers for unlocked items; and your device name and identifier.
Turning off iCloud Backup or deleting LIFFT does not remove existing CloudKit records. LIFFT can delete individual manual snapshots from its backup-history screen. To remove all LIFFT CloudKit data, use iOS Settings → your name → iCloud → Manage Account Storage.
Android backup is off by default. If you enable it or choose Back Up Now, LIFFT stores a current backup and manual snapshots as JSON files in LIFFT’s hidden application-data folder in your Google Drive.
Those files can include workout and fitness history; templates and folders; your local profile, including an optional email address and photo; saved friends’ names, usernames, status information, and photos; custom exercises, favorites, and usage; app customization; coach roster and folder-link data, including any client profile already stored in the roster; Google Sheets metadata; preferences and tags; a random installation identifier; and a non-authoritative cache of some unlocked items. They do not include your complete payment-card or bank-account details.
The backup files travel directly between LIFFT on your device and your Google account and are not sent to LIFFT’s backend. Turning off backup, choosing Delete All Data, disconnecting Google, or deleting LIFFT from your device does not ask Google to delete existing backup files. To delete them, use Google Drive Settings → Manage Apps → LIFFT → Options → Delete hidden app data.
7. Device Permissions
LIFFT requests device permissions only when needed for the related feature. You can review or change them in your device settings:
- Notifications — to alert you when a rest timer finishes. On Apple devices, optional iCloud Backup also uses Apple’s silent background notifications to keep backup data synchronized.
- Camera — to scan a gym membership barcode or capture a photo or video for a workout Story.
- Photos — to choose a profile photo, display a recent photo or video in the Story picker, and save workout images or Story media.
- Microphone — to record sound when you choose to record a Story video with audio.
Camera frames, selected photos, and Story recordings are handled on your device. LIFFT does not upload Story media to its backend. Media leaves your device only when you save it or choose a destination through the device’s sharing controls.
8. Data Security
Because LIFFT stores data locally, the security of your information depends on the security of your device.
We recommend enabling a passcode, keeping your device’s operating system updated, and using its built-in privacy protections.
9. Your Rights
Where your data lives determines how to remove it:
- On your device: Delete individual items or use the available deletion controls. In the current Apple app, Delete All Data clears workout history, templates, pinned templates, user-created exercises, and favorites; it does not clear every other local profile, setting, or connection. On Android, Delete All Data clears LIFFT’s on-device app data. Neither platform’s Delete All Data action removes the cloud or provider records below.
- In your Google Sheet: Use Delete Sheet in LIFFT, or delete the file or change its permissions in Google Drive. Disconnecting Google stops LIFFT’s future access but does not ask Google to delete the Sheet.
- In Apple iCloud or CloudKit backup: Delete individual manual snapshots through LIFFT’s backup-history screen. Use iOS Settings → your name → iCloud → Manage Account Storage to remove all LIFFT CloudKit data.
- In Android backup: Delete LIFFT’s hidden app data through Google Drive Settings → Manage Apps → LIFFT → Options → Delete hidden app data. Delete All Data in LIFFT and Disconnect Google do not ask Google to delete these backup files.
- In Google Play and RevenueCat: Delete All Data does not erase purchase or subscription records maintained by those providers under their policies.
- A coach's access to your sheet: Use Remove Coach, or manage sharing in Google Drive.
- On our backend (Supabase): Connection, share, and live-session records are automatically deleted within 24 hours (live sessions within 1 hour of completion).
- In iCloud Backup: See Section 6; deleting the app does not remove it.
If you have a request about your data that these controls don't cover, contact us at contactus@lifft.app and we will help.
If you choose to use third-party integrations such as Google, you may manage or delete your data directly through those services.
10. Children’s Privacy
LIFFT is intended for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us at contactus@lifft.app and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy if our features change in ways that affect privacy.
If so, we will revise the date at the top of this page.
12. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
contactus@lifft.app