Privacy Policy
Last updated: 6 July 2026
Lifto (“the app”) is a workout-tracking and effective-volume-analysis app. This policy explains what data the app handles and where it goes. The short version: your workout data lives on your device, and stays there unless you choose to sign in. Signing in (with Sign in with Apple or an email one-time passcode) is entirely optional; if you do sign in, your workouts also back up and sync through our own developer-operated server, and we can then see that data there along with your account identifier and, for most accounts, your email address. The app also sends only anonymous, content-free usage and crash analytics through our own privacy relay, plus, only if you use the optional AI template builder, the training description you type, which is processed by OpenAI and not stored. All of this is described below.
Who we are (data controller)
The data controller for any personal data processed through Lifto is Iulia Brezeanu Sole Professional No. 106465 (Dubai Development Authority), Building 16, Ground Floor, Dubai Internet City, Dubai, United Arab Emirates. Trading as Geometry — see geometryapps.com.
EU representative (Art 27 GDPR): Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. UK representative (Art 27 UK GDPR): Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom. Exercise your rights at app.prighter.com/portal/geometry — or email [email protected].
What data Lifto handles
- Workout data you enter: templates, exercises, sets (weight, reps, RIR), notes, gym profiles, and completed-workout history.
- Health metrics during a workout (optional): if you grant Apple Health access, Lifto reads your heart rate and active energy (calories) to show live metrics during a session, and stores the session’s average heart rate and active calories alongside that completed workout. These two values always stay on your device (and in your own Apple Health, if you grant write access) — they are never sent to Lifto’s servers, whether or not you sign in. With your permission Lifto also writes your completed workouts back to Apple Health.
- Settings and preferences: unit choice (kg/lbs), timer settings, and display options, stored locally on your device.
- Account information (optional): if you sign in with Sign in with Apple or an email one-time passcode, we store an account identifier and, for most accounts, your email address, so your workout data can sync and be restored on a new device. See “Where your workout data is stored” below.
- AI template builder text (optional): if you use the “describe your training” template builder, the description you type is sent to our server and on to OpenAI to generate workout templates — see “AI template builder” below.
- Anonymous usage & crash analytics: content-free feature-usage events and app-health diagnostics, described under “Usage analytics” below.
Where your workout data is stored
- On your device, using Apple’s local storage. This is where your data lives if you never sign in, and the app remains fully functional this way. Signing in is not required.
- If you sign in with Sign in with Apple or an email one-time passcode, your workout data (templates, exercises, sets, notes, gym profiles, programs, custom exercises, and completed-workout history) is additionally backed up and synced across your devices through our own developer-operated server: the
lifto-syncservice (a Cloudflare Worker with a database) atsync.getlifto.app. This is not Apple’s iCloud or CloudKit. Lifto no longer uses CloudKit or iCloud for any purpose. Average heart rate and active calories are the one exception: they are never included in this sync, signed in or not — they stay on your device (and in your own Apple Health) only. - Because that data is stored on our own server, we can access it there for signed-in accounts, together with your account identifier and, for most accounts, your email address (see “Accounts” below). Your data is scoped to your account and never shared with other accounts.
- If you do not sign in, Lifto stores everything locally only on your device, and we cannot see or access it. Signing in is a convenience for backup and multi-device sync, not a requirement.
Accounts (optional)
Lifto works fully without ever creating an account. If you choose to sign in with Sign in with Apple or an email one-time passcode (OTP) (there is no separate Lifto password), we create an account identified by an internal account ID, and, for most accounts, store your email address (your real address, or an Apple private-relay address if you used Hide My Email with Sign in with Apple). We use this only to identify your account and keep your synced workout data attached to it.
Deleting your account and synced data: from Profile → Back up & sync → Delete Account, you can permanently delete your account. This removes your account and every synced template, completed workout, program, gym profile, and custom exercise from our server, and revokes our stored Sign in with Apple authorization where applicable. Data that remains on your device is not affected and stays exactly as it was. Signing out (without deleting) simply stops syncing. Your data stays on our server and your device keeps working locally either way.
What Lifto does NOT do
- No cross-app tracking, no ads. Lifto does not track you across apps or websites, uses no advertising identifier (IDFA), and contains no advertising or attribution SDKs.
- Your workout data never goes to AI. Your workout history, sets, and health metrics are never sent to any AI service. The only AI feature is the optional template builder, which sends solely the description text you choose to type (see below).
- Your workout data is never sold or shared. Your workouts and templates stay on your device, or, for signed-in accounts, on our own server; your heart-rate and calorie metrics stay on your device (and your own Apple Health) only, never on our server. We never sell or share this data, and it is never shared across accounts.
Usage analytics (anonymous, no personal content)
To understand which features are used and improve the app, Lifto records anonymous in-app activity — for example which screen you open, when you start or finish a workout (counts and coarse numbers like set count, effective-set count, total volume, and duration), and how you interact with the paywall. Analytics are content-free: they never include your workout content (weights, reps, exercises, notes), heart rate, calories, name, email, account identifier, or Apple ID, whether or not you are signed in. Analytics events are entirely separate from your account and synced data.
How it is processed — a two-layer privacy design:
- No analytics SDK in the app. The app sends events over a plain encrypted connection to our own relay (a Cloudflare Worker at
e.getlifto.app), which forwards them to PostHog (our analytics processor, EU hosting). The app holds no analytics key. - The relay anonymises by region (data minimisation). For users in the EEA, the UK, and Switzerland (and any user whose region can’t be determined), each event is given a fresh random identifier per event, your IP address is stripped, and no profile is built — the events are unlinkable. For the rest of the world, events are tied only to a random, app-generated device identifier (never your identity), still with no IP.
Your choice (consent):
- In Germany and Austria (and where your region is unknown), analytics are off until you opt in — we show a clear one-time prompt and nothing is sent unless you tap Allow.
- Everywhere else (including the US, UK, France, Italy, Spain, and the rest of the EEA), analytics are on by default, with this notice serving as disclosure. You can opt out at any time in Profile → Privacy & Data → Share Usage Analytics (one tap). When you opt out, events stop immediately and any stored device identifier is forgotten.
- It is not used for advertising, involves no cross-app tracking and no IDFA (so there is no App Tracking Transparency prompt), and is never linked with third-party data or sold.
AI template builder (optional)
Lifto can turn a short written description of your training (e.g. “upper/lower 4 days, I squat 5×5”) into workout templates. Only when you use this feature, the text you type is sent over an encrypted connection to our own server (a Cloudflare Worker at getlifto.app), which forwards it to OpenAI (API) to generate the templates.
- Only the description text you type is sent — never your workout history, health data, identifiers, or anything else. The request carries no account or device identifier.
- We do not store your text. Our server forwards it and returns the result; nothing is logged or retained by us.
- OpenAI processes it as an API request: under OpenAI’s API terms it is not used to train models and is retained by OpenAI only briefly (up to 30 days) for abuse monitoring, then deleted.
- The feature is entirely optional — if it is unavailable or you prefer not to use it, the same builder works with on-device parsing instead.
- We ask first. Before the first time anything is sent, the app shows a consent screen naming OpenAI and explaining what is sent, with a “Build on-device instead” option. You can change this choice anytime in Profile → Privacy & Data → Use AI to build templates.
Sharing a template (optional)
If you choose to share one of your templates via a link, the template you share — its name, exercise names, and any notes you added — is stored on our server (a Cloudflare Worker with Cloudflare KV) so that anyone you give the link to can open it. This happens only when you explicitly tap Share; nothing is uploaded otherwise.
- Link-based access. A shared template is reachable by its unguessable link; it is not listed publicly or searchable.
- Retention. Shared templates are automatically deleted 365 days after they are created. We store no identifier linking a share to you.
- No personal or workout data. Only the template content you chose to share is stored — never your workout history, health metrics, or account/device identifiers.
App-health diagnostics (crash & performance) — always on
Lifto also reports anonymous app-health diagnostics gathered by Apple’s MetricKit — aggregate performance figures (launch time, hangs, memory, CPU) and crash counts with code-level (not personal) information. These contain no personal data and no workout content — only counts and your app/OS version — and exist solely to find and fix crashes and slowdowns. Because they are content-free and carry no persistent identifier, they are sent on a legitimate-interest basis to keep the app stable and are not affected by the usage-analytics opt-out.
Sub-processors
- Apple: App Store / StoreKit (subscriptions), Sign in with Apple (authentication), HealthKit (on-device).
- Cloudflare: operates the analytics relay and the AI template endpoint (transport only; strips IP, does not store event payloads or template text); hosts the optional shared-template store (Cloudflare KV; stores only templates you explicitly share, auto-deleted after 365 days); and, for signed-in accounts, runs the
lifto-syncbackup/sync service (account identifier, email address where applicable, and your synced workout data) atsync.getlifto.app. - OpenAI — processes AI template-builder descriptions (API; not used for model training, short-term abuse-monitoring retention only). Used only when you invoke the AI template builder.
- PostHog (EU hosting) — analytics processor under an Art 28 data-processing agreement; no onward sharing, no advertising use, EU/UK/Swiss transfer safeguards.
- RevenueCat — subscription-management processor under an Art 28 data-processing agreement; receives your purchase history and an app-generated subscriber identifier to validate your subscription and manage entitlements. No onward sharing, no advertising use.
- Resend — email-delivery processor; sends the one-time passcode email when you sign in with an email OTP, so it receives your email address for that purpose only. No onward sharing, no advertising use.
Apple Health
Health access is optional. Lifto requests permission to read heart rate and active energy and to write completed workouts to Apple Health. You can grant, limit, or revoke this at any time in Settings → Privacy & Security → Health → Lifto. The per-session summary (average heart rate, active calories) is saved with that workout on your device only — it is not transmitted to our servers, even if you are signed in and syncing.
Subscriptions
Lifto Pro is an auto-renewable subscription processed entirely by Apple’s App Store (StoreKit), with subscription management via RevenueCat (our paywall/entitlement processor). Lifto never sees or stores your payment information. Manage or cancel anytime in your App Store account settings.
Your control & rights
- Delete individual workouts, or clear all history, from Profile → Data.
- Opt out of usage analytics anytime in Profile → Privacy & Data.
- Delete your account and all synced data anytime from Profile → Back up & sync → Delete Account, or simply sign out to stop syncing without deleting anything.
- Revoke Health access in the iOS Health app at any time.
- GDPR / UK GDPR rights (access, rectification, erasure, objection, portability): contact us or use the rights portal above. For a signed-in account, Delete Account above is the fastest way to exercise erasure for your synced data; contact us for any other request. Note that the EEA/UK/CH analytics branch is anonymous at source, so there is no linkable analytics record tied to you to export or erase.
- CCPA / CPRA rights (California residents): you have the right to know what personal information we collect, to request its deletion, and to request correction of inaccurate information — email [email protected] or use the rights portal above. We do not sell or share your personal information (including no sale or sharing for cross-context behavioral advertising), and we do not use or disclose sensitive personal information (such as precise health metrics) for any purpose beyond providing the app’s own functionality.
International transfers
Analytics are hosted in the EU (PostHog EU). Where data is processed outside the EEA/UK, it relies on appropriate safeguards (EU Standard Contractual Clauses / UK IDTA / Swiss FADP addendum) via our processors. The controller is established in the UAE; the Art 27 representatives above act as the EU/UK points of contact.
Children
Lifto is not directed at children and does not knowingly collect data from children.
Contact
Questions about this policy: [email protected]