Lifto

Privacy Policy

Last updated: 17 August 2026

Lifto (“the app”) is a workout-tracking and effective-volume-analysis app. This policy explains what data the app handles and where it goes. The short version: your workout data lives on your device, and stays there unless you choose to sign in. Signing in with Apple, Google, or an email one-time passcode is entirely optional; if you do sign in, your workouts also back up and sync through our own developer-operated server, and we can then see that data there along with your account identifier and, for most accounts, your email address. The app also sends only anonymous, content-free usage and crash analytics through our own privacy relay, plus, only if you use an optional AI feature, the text you deliberately submit, which is processed by OpenAI and not stored by us. All of this is described below.

Who we are (data controller)

The data controller for any personal data processed through Lifto is Geometry Lab L.L.C-FZ, Licence No. 2651608.01, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Geometry is our trading style. See geometryapps.com.

EU representative (Art 27 GDPR): Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. UK representative (Art 27 UK GDPR): Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom. Exercise your rights at app.prighter.com/portal/geometry — or email [email protected].

What data Lifto handles

Where your workout data is stored

Accounts (optional)

Lifto works fully without ever creating an account. If you choose to sign in with Sign in with Apple, Sign in with Google, or an email one-time passcode (OTP) (there is no separate Lifto password), we create an account identified by an internal account ID and, for most accounts, store your email address. We use this only to identify your account and keep your synced workout data attached to it.

Deleting your account and synced data: from Profile → Back up & sync → Delete Account, you can permanently delete your account. This removes your account, linked sign-in methods, profile display name, photo, muscle-map preferences, and every synced template, completed workout, program, gym profile, custom exercise, and workout photo from our server. Data that remains on your device is not affected and stays exactly as it was. Signing out (without deleting) simply stops syncing. Your data stays on our server and your device keeps working locally either way.

What Lifto does NOT do

Health data sync (optional, explicit consent)

If you are signed in, you can additionally choose to include the average heart rate and active calories saved with your workouts in your account backup and cross-device sync. This is health data (special-category data under GDPR Article 9), and we process it only with your explicit consent — GDPR Art 9(2)(a) is the lawful basis. It is off by default and is never folded into signing in, Apple Health, Health Connect, Wear OS sensor permission, or any other setting:

Usage analytics (anonymous, no personal content)

To understand which features are used and improve the app, Lifto records anonymous in-app activity — for example which screen you open, when you start or finish a workout (counts and coarse numbers like set count, effective-set count, total volume, and duration), and how you interact with the paywall. Analytics are content-free: they never include your workout content (weights, reps, exercises, notes), heart rate, calories, name, email, account identifier, or Apple ID, whether or not you are signed in. Analytics events are entirely separate from your account and synced data.

How it is processed — a two-layer privacy design:

Your choice (consent):

AI template builder (optional)

Lifto can turn a short written description of your training (e.g. “upper/lower 4 days, I squat 5×5”) into workout templates. Only when you use this feature, the text you type is sent over an encrypted connection to our own server (a Cloudflare Worker at getlifto.app), which forwards it to OpenAI (API) to generate the templates.

Sharing a template (optional)

If you choose to share one of your templates via a link, the template you share — its name, exercise names, and any notes you added — is stored on our server (a Cloudflare Worker with Cloudflare KV) so that anyone you give the link to can open it. This happens only when you explicitly tap Share; nothing is uploaded otherwise.

App-health diagnostics (crash & performance) — always on

Lifto also reports anonymous app-health diagnostics from Apple MetricKit on iOS and Android platform diagnostics such as ApplicationExitInfo and Play Vitals. These contain no personal data and no workout content and exist solely to find and fix crashes and slowdowns. Because they are content-free and carry no persistent identifier, they are sent on a legitimate-interest basis to keep the app stable and are not affected by the usage-analytics opt-out.

Sub-processors

Apple Health

Health access is optional. Lifto requests permission to read heart rate and active energy and to write completed workouts to Apple Health. You can grant, limit, or revoke this at any time in Settings → Privacy & Security → Health → Lifto. The per-session summary (average heart rate, active calories) is saved with that workout on your device only and is not transmitted to our servers — unless you separately and explicitly turn on Health Data Sync (see “Health data sync” above), which you can revoke at any time.

Android Health Connect and Wear OS health sensors

Android health access is optional. On the phone, Lifto requests only Health Connect’s exercise-write permission. After you save a workout, Lifto can write one strength-training session containing its title and start/end time. Lifto does not read your Health Connect history, and a Health Connect error never prevents the local workout from being saved.

On a paired Wear OS watch, after you start a workout and grant the requested permissions, Lifto uses Android Health Services to read heart-rate samples and active calories for that workout. It shows the live values, calculates the session average and keeps collecting while the display sleeps through a foreground health service with an ongoing notification. Collection stops when the workout service ends. Lifto does not use these permissions for passive monitoring, advertising, diagnosis or location.

Wear-derived average heart rate and active calories stay with the workout on your devices unless a signed-in user separately enables Health Data Sync. With that explicit consent they are encrypted in transit and included in the account-scoped workout backup described above. Lifto does not sell health data or share it for advertising.

Medical and training disclaimer

Lifto is a fitness tracker, not a medical device. It does not diagnose, treat, cure, or prevent any medical condition. Its volume figures are estimates based on published research and are not medical advice. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment, and a qualified training professional before making material changes to how you exercise.

Subscriptions

Lifto Pro is an auto-renewable subscription processed by the store where you subscribe: Apple’s App Store or Google Play. RevenueCat manages paywall and entitlement state for both stores. Lifto never sees or stores your payment information. Manage or cancel in your App Store or Google Play subscription settings.

Your control & rights

International transfers

Analytics are hosted in the EU (PostHog EU). Where data is processed outside the EEA/UK, it relies on appropriate safeguards (EU Standard Contractual Clauses / UK IDTA / Swiss FADP addendum) via our processors. The controller is established in the UAE; the Art 27 representatives above act as the EU/UK points of contact.

Children

Lifto is not directed at children and does not knowingly collect data from children.

Contact

Questions about this policy: [email protected]