Privacy Policy
Last updated: 17 August 2026
Lifto (“the app”) is a workout-tracking and effective-volume-analysis app. This policy explains what data the app handles and where it goes. The short version: your workout data lives on your device, and stays there unless you choose to sign in. Signing in with Apple, Google, or an email one-time passcode is entirely optional; if you do sign in, your workouts also back up and sync through our own developer-operated server, and we can then see that data there along with your account identifier and, for most accounts, your email address. The app also sends only anonymous, content-free usage and crash analytics through our own privacy relay, plus, only if you use an optional AI feature, the text you deliberately submit, which is processed by OpenAI and not stored by us. All of this is described below.
Who we are (data controller)
The data controller for any personal data processed through Lifto is Geometry Lab L.L.C-FZ, Licence No. 2651608.01, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Geometry is our trading style. See geometryapps.com.
EU representative (Art 27 GDPR): Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. UK representative (Art 27 UK GDPR): Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom. Exercise your rights at app.prighter.com/portal/geometry — or email [email protected].
What data Lifto handles
- Workout data you enter: templates, exercises, sets (weight, reps, RIR), notes, gym profiles, completed-workout history, and any optional photo you deliberately attach to a completed workout.
- Health metrics during a workout (optional): if you grant Apple Health access on iOS or health-sensor access on Wear OS, Lifto reads your heart rate and active energy (calories) during a user-started workout to show live metrics and stores the session’s average heart rate and active calories alongside that completed workout. The Wear OS foreground health service keeps the workout metrics running while the watch display sleeps and stops when the workout ends; Lifto does not passively monitor health data. These two values stay on your device unless you separately and explicitly turn on Health Data Sync — see “Health data sync” below. They are never sent to Lifto’s servers without that explicit consent, whether or not you sign in. With your permission Lifto also writes a completed workout to Apple Health on iOS or a completed strength-session record to Health Connect on Android.
- Settings and preferences: unit choice (kg/lbs), timer settings, and most display options are stored locally on your device. If you sign in, the muscle-map anatomy, priority order, and hidden muscles you choose are backed up to your account for cross-device display consistency.
- Account information (optional): if you sign in with Sign in with Apple, Sign in with Google, or an email one-time passcode, we store an account identifier and, for most accounts, your email address. On iOS and Android, your profile display name, profile photo, and muscle-map display preferences (the anatomy, priority order, and hidden muscles you choose) are also backed up to your account so they can be restored when you sign in. See “Where your workout data is stored” below.
- AI template builder text (optional): if you use the “describe your training” template builder, the description you type is sent to our server and on to OpenAI to generate workout templates — see “AI template builder” below.
- Anonymous usage & crash analytics: content-free feature-usage events and app-health diagnostics, described under “Usage analytics” below.
Where your workout data is stored
- On your device, using SwiftData on iOS and Room on Android. This is where your data lives if you never sign in, and the app remains fully functional this way. Signing in is not required.
- If you sign in with Apple, Google, or an email one-time passcode, your workout data (templates, exercises, sets, notes, gym profiles, programs, custom exercises, completed-workout history, and attached workout photos) are additionally backed up and synced across your devices. Your profile display name, profile photo, and muscle-map display preferences are also backed up to your account and restored when you sign in. This uses our own developer-operated server: the
lifto-syncservice (a Cloudflare Worker with a database and account-scoped media storage) atsync.getlifto.app. Attached photos are used only for account backup/sync and never analytics. This is not Apple’s iCloud or CloudKit. Lifto no longer uses CloudKit or iCloud for any purpose. Average heart rate and active calories are the one exception: they are included in this sync only if you separately turn on Health Data Sync (explicit consent. See “Health data sync” below). Otherwise they stay on your device only, signed in or not. A completed-session record that you allow Lifto to write to Apple Health or Health Connect remains under that platform’s controls and is not read back or uploaded by Lifto. - Because that data is stored on our own server, we can access it there for signed-in accounts, together with your account identifier and, for most accounts, your email address (see “Accounts” below). Your data is scoped to your account and never shared with other accounts.
- If you do not sign in, Lifto stores everything locally only on your device, and we cannot see or access it. Signing in is a convenience for backup and multi-device sync, not a requirement.
Accounts (optional)
Lifto works fully without ever creating an account. If you choose to sign in with Sign in with Apple, Sign in with Google, or an email one-time passcode (OTP) (there is no separate Lifto password), we create an account identified by an internal account ID and, for most accounts, store your email address. We use this only to identify your account and keep your synced workout data attached to it.
Deleting your account and synced data: from Profile → Back up & sync → Delete Account, you can permanently delete your account. This removes your account, linked sign-in methods, profile display name, photo, muscle-map preferences, and every synced template, completed workout, program, gym profile, custom exercise, and workout photo from our server. Data that remains on your device is not affected and stays exactly as it was. Signing out (without deleting) simply stops syncing. Your data stays on our server and your device keeps working locally either way.
What Lifto does NOT do
- No cross-app tracking, no ads. Lifto does not track you across apps or websites, uses no advertising identifier (IDFA), and contains no advertising or attribution SDKs.
- Your workout data never goes to AI. Your workout history, sets, and health metrics are never sent to any AI service. The only AI feature is the optional template builder, which sends solely the description text you choose to type (see below).
- Your workout data is never sold or shared. Your workouts and templates stay on your device, or, for signed-in accounts, on our own server; your heart-rate and calorie metrics stay on your device unless you explicitly turn on Health Data Sync. We never sell or share this data, and it is never shared across accounts.
Health data sync (optional, explicit consent)
If you are signed in, you can additionally choose to include the average heart rate and active calories saved with your workouts in your account backup and cross-device sync. This is health data (special-category data under GDPR Article 9), and we process it only with your explicit consent — GDPR Art 9(2)(a) is the lawful basis. It is off by default and is never folded into signing in, Apple Health, Health Connect, Wear OS sensor permission, or any other setting:
- Turning it on requires an explicit confirmation on a dedicated consent screen that names exactly these two values. Nothing else changes: no other health data is read or synced.
- Turning it off is one tap in Profile → Privacy & Data → Sync Health Data, independent of signing out. When you turn it off, the app stops sending these values and our server deletes the previously synced heart rate and calorie values from your backup. Copies already synced to your own other devices remain on those devices, under your control.
- Your choice is stored with your account, so turning it off on one device turns it off on all of them.
- Deleting your account (see “Accounts”) removes the consent record along with everything else.
Usage analytics (anonymous, no personal content)
To understand which features are used and improve the app, Lifto records anonymous in-app activity — for example which screen you open, when you start or finish a workout (counts and coarse numbers like set count, effective-set count, total volume, and duration), and how you interact with the paywall. Analytics are content-free: they never include your workout content (weights, reps, exercises, notes), heart rate, calories, name, email, account identifier, or Apple ID, whether or not you are signed in. Analytics events are entirely separate from your account and synced data.
How it is processed — a two-layer privacy design:
- No analytics SDK in the app. The app sends events over a plain encrypted connection to our own relay (a Cloudflare Worker at
e.getlifto.app), which forwards them to PostHog (our analytics processor, EU hosting). The app holds no analytics key. - The relay anonymises by region (data minimisation). For users in the EEA, the UK, and Switzerland (and any user whose region can’t be determined), each event is given a fresh random identifier per event, your IP address is stripped, and no profile is built — the events are unlinkable. For the rest of the world, events are tied only to a random, app-generated device identifier (never your identity), still with no IP.
Your choice (consent):
- In Germany and Austria (and where your region is unknown), analytics are off until you opt in — we show a clear one-time prompt and nothing is sent unless you tap Allow.
- Everywhere else (including the US, UK, France, Italy, Spain, and the rest of the EEA), analytics are on by default, with this notice serving as disclosure. You can opt out at any time in Profile → Privacy & Data → Share Usage Analytics (one tap). When you opt out, events stop immediately and any stored device identifier is forgotten.
- It is not used for advertising, involves no cross-app tracking and no IDFA (so there is no App Tracking Transparency prompt), and is never linked with third-party data or sold.
AI template builder (optional)
Lifto can turn a short written description of your training (e.g. “upper/lower 4 days, I squat 5×5”) into workout templates. Only when you use this feature, the text you type is sent over an encrypted connection to our own server (a Cloudflare Worker at getlifto.app), which forwards it to OpenAI (API) to generate the templates.
- Only the description text you type is sent — never your workout history, health data, identifiers, or anything else. The request carries no account or device identifier.
- We do not store your text. Our server forwards it and returns the result; nothing is logged or retained by us.
- OpenAI processes it as an API request: under OpenAI’s API terms it is not used to train models and is retained by OpenAI only briefly (up to 30 days) for abuse monitoring, then deleted.
- The feature is entirely optional — if it is unavailable or you prefer not to use it, the same builder works with on-device parsing instead.
- We ask first. Before the first time anything is sent, the app shows a consent screen naming OpenAI and explaining what is sent, with a “Build on-device instead” option. You can change this choice anytime in Profile → Privacy & Data → Use AI to build templates.
Sharing a template (optional)
If you choose to share one of your templates via a link, the template you share — its name, exercise names, and any notes you added — is stored on our server (a Cloudflare Worker with Cloudflare KV) so that anyone you give the link to can open it. This happens only when you explicitly tap Share; nothing is uploaded otherwise.
- Link-based access. A shared template is reachable by its unguessable link; it is not listed publicly or searchable.
- Retention. Shared templates are automatically deleted 365 days after they are created. We store no identifier linking a share to you.
- No personal or workout data. Only the template content you chose to share is stored — never your workout history, health metrics, or account/device identifiers.
App-health diagnostics (crash & performance) — always on
Lifto also reports anonymous app-health diagnostics from Apple MetricKit on iOS and Android platform diagnostics such as ApplicationExitInfo and Play Vitals. These contain no personal data and no workout content and exist solely to find and fix crashes and slowdowns. Because they are content-free and carry no persistent identifier, they are sent on a legitimate-interest basis to keep the app stable and are not affected by the usage-analytics opt-out.
Sub-processors
- Apple: App Store / StoreKit (subscriptions), Sign in with Apple (authentication), HealthKit (on-device).
- Google: Google Play Billing (subscriptions), Sign in with Google (authentication), Android Health Connect and Wear OS Health Services (user-authorized on-device health integrations), and Android platform diagnostics.
- Cloudflare: operates the analytics relay and the AI template endpoint (transport only; strips IP, does not store event payloads or template text); hosts the optional shared-template store (Cloudflare KV; stores only templates you explicitly share, auto-deleted after 365 days); and, for signed-in accounts, runs the
lifto-syncbackup/sync service (account identifier, email address where applicable, and your synced workout data) atsync.getlifto.app. - OpenAI — processes AI template-builder descriptions (API; not used for model training, short-term abuse-monitoring retention only). Used only when you invoke the AI template builder.
- PostHog (EU hosting) — analytics processor; no onward sharing or advertising use.
- RevenueCat — subscription-management processor under an Art 28 data-processing agreement; receives your purchase history and an app-generated subscriber identifier to validate your subscription and manage entitlements. No onward sharing, no advertising use.
- Resend — email-delivery processor; sends the one-time passcode email when you sign in with an email OTP, so it receives your email address for that purpose only. No onward sharing, no advertising use.
Apple Health
Health access is optional. Lifto requests permission to read heart rate and active energy and to write completed workouts to Apple Health. You can grant, limit, or revoke this at any time in Settings → Privacy & Security → Health → Lifto. The per-session summary (average heart rate, active calories) is saved with that workout on your device only and is not transmitted to our servers — unless you separately and explicitly turn on Health Data Sync (see “Health data sync” above), which you can revoke at any time.
Android Health Connect and Wear OS health sensors
Android health access is optional. On the phone, Lifto requests only Health Connect’s exercise-write permission. After you save a workout, Lifto can write one strength-training session containing its title and start/end time. Lifto does not read your Health Connect history, and a Health Connect error never prevents the local workout from being saved.
On a paired Wear OS watch, after you start a workout and grant the requested permissions, Lifto uses Android Health Services to read heart-rate samples and active calories for that workout. It shows the live values, calculates the session average and keeps collecting while the display sleeps through a foreground health service with an ongoing notification. Collection stops when the workout service ends. Lifto does not use these permissions for passive monitoring, advertising, diagnosis or location.
Wear-derived average heart rate and active calories stay with the workout on your devices unless a signed-in user separately enables Health Data Sync. With that explicit consent they are encrypted in transit and included in the account-scoped workout backup described above. Lifto does not sell health data or share it for advertising.
Medical and training disclaimer
Lifto is a fitness tracker, not a medical device. It does not diagnose, treat, cure, or prevent any medical condition. Its volume figures are estimates based on published research and are not medical advice. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment, and a qualified training professional before making material changes to how you exercise.
Subscriptions
Lifto Pro is an auto-renewable subscription processed by the store where you subscribe: Apple’s App Store or Google Play. RevenueCat manages paywall and entitlement state for both stores. Lifto never sees or stores your payment information. Manage or cancel in your App Store or Google Play subscription settings.
Your control & rights
- Delete individual workouts, or clear all history, from Profile → Data.
- Opt out of usage analytics anytime in Profile → Privacy & Data.
- Delete your account and all synced data anytime from Profile → Back up & sync → Delete Account, or simply sign out to stop syncing without deleting anything.
- Revoke Apple Health access in the iOS Health app, Wear OS sensor access in Android permission settings, or Lifto’s exercise-write access in Health Connect at any time.
- GDPR / UK GDPR rights (access, rectification, erasure, objection, portability): contact us or use the rights portal above. For a signed-in account, Delete Account above is the fastest way to exercise erasure for your synced data; contact us for any other request. Note that the EEA/UK/CH analytics branch is anonymous at source, so there is no linkable analytics record tied to you to export or erase.
- CCPA / CPRA rights (California residents): you have the right to know what personal information we collect, to request its deletion, and to request correction of inaccurate information — email [email protected] or use the rights portal above. We do not sell or share your personal information (including no sale or sharing for cross-context behavioral advertising), and we do not use or disclose sensitive personal information (such as precise health metrics) for any purpose beyond providing the app’s own functionality.
International transfers
Analytics are hosted in the EU (PostHog EU). Where data is processed outside the EEA/UK, it relies on appropriate safeguards (EU Standard Contractual Clauses / UK IDTA / Swiss FADP addendum) via our processors. The controller is established in the UAE; the Art 27 representatives above act as the EU/UK points of contact.
Children
Lifto is not directed at children and does not knowingly collect data from children.
Contact
Questions about this policy: [email protected]