Privacy Policy
Last updated: 10 May 2026
This Privacy Policy describes how Lift ("we", "our", or "us") collects, uses, and shares your personal data when you use our mobile application and related services (the "Service"). It also explains your rights regarding that data and how to exercise them.
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Definitions
Account. A registered profile created via Apple Sign-In, Google Sign-In, or email and password.
Personal Data. Any information relating to an identified or identifiable individual, including names, identifiers, IP addresses, and health metrics.
Service Provider. A third-party company that processes data on our behalf (for example, a cloud platform, push-notification provider, or analytics tool).
Usage Data. Information collected automatically, such as device type, app version, and crash diagnostics.
Data We Collect
Account & profile data
When you create an account and complete onboarding, we collect:
- Name, email address, sign-in provider identifier (Apple, Google).
- Profile attributes you enter: gender, birth year, height, weight, fitness goals, experience level, available equipment, preferred workout days.
- An IANA timezone identifier (e.g. Europe/Istanbul) used to schedule reminders at your local 9 AM.
Signup location (IP-derived)
On the very first profile save, we record the IP address used to register, together with the country, region, city, and timezone derived from it via a third-party IP geolocation service. This signup location is captured once and is not refreshed when your IP changes (different network, VPN, travel). It is used for fraud-prevention, regional feature availability, and aggregated analytics. We do not use it to track your day-to-day movements.
Workout, fitness, and body data
While using the Service, we store workout sessions, exercise sets and reps, weights, durations, RPE, custom programs, favorites, body measurements, progress photos you upload, and similar fitness records.
Health data (heart rate)
If you grant the relevant permission, we read heart-rate samples written to Apple Health by your Apple Watch (or a paired Bluetooth heart-rate monitor) during workouts you record in the Service. We summarise these into average / minimum / peak BPM and a downsampled time series, which we store alongside the corresponding workout session.
Subscription & purchase data
If you start a subscription, our subscription provider (RevenueCat) records your purchase events, the in-app product purchased, the platform store transaction identifier, the entitlement status (active / expired / refunded), the trial status, and a pseudonymous user identifier we associate with your account. We do not receive or store your payment card or bank details — those remain with the platform store (Apple).
Device and usage data
Like most apps, we automatically collect device model, operating-system version, app version, language, and crash / diagnostic data. We use a third-party crash reporter for stability monitoring.
Push notification tokens
If you enable notifications, we store your Firebase Cloud Messaging (FCM) device token so we can send you workout reminders and post-workout follow-ups.
How We Use Your Data
- Provide the Service: personalising your workout plan, generating recommended programs, displaying workout history and progress charts.
- Notifications: sending the morning workout reminder and post-workout follow-ups using your stored timezone.
- Health insights: showing live heart rate during workouts and historical heart-rate summaries on the workout-detail screen.
- Subscription management: verifying your entitlement, granting access to paid features, processing renewals and refunds, and supporting subscription restore.
- Service improvement: diagnosing crashes, measuring feature usage in aggregate, and prioritising fixes.
- Security & fraud prevention: using signup geo and account metadata to detect abuse.
- Legal compliance: meeting our obligations under applicable laws and regulations.
Sharing & Third Parties
We do not sell your personal data. We share data only with the following categories of recipients, and only to the extent necessary:
- Cloud infrastructure: Google Firebase (Authentication, Cloud Firestore, Realtime Database, Cloud Storage, Cloud Messaging) and Railway for backend hosting.
- Authentication providers: Apple and Google when you sign in via those providers.
- Subscription management: RevenueCat receives a pseudonymous user identifier (your Firebase user id) and the in-app purchase events generated by Apple StoreKit, so we can grant or revoke entitlements correctly across devices and over time.
- Product analytics: PostHog receives a pseudonymous distinct identifier and event-level usage data (which screens you view, which features you tap, paywall outcomes). We do not send personally identifying fields such as your name, email, or precise location to PostHog.
- Analytics & crash reporting: Firebase Analytics and Firebase Crashlytics. Identifiers used are app-scoped and not joined with third-party advertising profiles.
- IP geolocation: a third-party lookup service receives your IP address once during signup to return country/city information.
- Legal: we may disclose data when required by law, court order, or to protect the rights, property, or safety of users or the public.
Health Data & Apple HealthKit
The Service integrates with Apple HealthKit. Data we read from HealthKit (such as heart-rate samples) is used solely to provide features inside the app and to compute the heart-rate summary stored with the corresponding workout. We never use HealthKit data for advertising, marketing, or to share with data brokers, and we never disclose HealthKit data to third parties for their own purposes. You can revoke HealthKit access at any time in Settings → Privacy & Security → Health → Lift.
Subscriptions & Payments
Subscription billing is handled entirely by Apple through the App Store. We never see your card number, billing address, or any other payment instrument. After a purchase, the platform store sends a signed transaction to our subscription provider (RevenueCat), which then notifies our backend so we can flag your account as premium and grant access to paid features. If a renewal fails, you cancel, or your purchase is refunded, the same flow runs in reverse and your premium access is removed. You can manage or cancel your subscription at any time from Settings → [Your Apple ID] → Subscriptions on your device.
Data Retention
We retain your data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain certain records for legal, accounting, or fraud-prevention purposes. Aggregated, non-identifying analytics may be retained indefinitely.
Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data.
- Export a portable copy of your data.
- Object to or restrict certain processing.
- Withdraw consent (where processing is based on consent).
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at the address in the Contact section. We respond within 30 days.
Security
We use industry-standard safeguards: TLS for data in transit, encryption at rest where supported by our cloud providers, and authenticated access to backend APIs (every request must carry a valid Firebase ID token; cross-user access is rejected at the middleware layer). No system is perfectly secure, but we work to keep your data safe and to respond quickly to any incident.
International Transfers
Our service providers may process data in countries outside your jurisdiction, including the United States and the European Union. Where applicable, we rely on Standard Contractual Clauses or equivalent safeguards approved by the European Commission for cross-border transfers.
Children’s Privacy
The Service is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect data from such children. If you believe a child has provided us with personal data, please contact us so we can delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via in-app notice or email. Continued use of the Service after a change means you accept the updated policy.
Contact Us
For questions about this policy or to exercise your privacy rights, contact:
Lift app — apps@meliharik.dev