Privacy Policy
What Liftor holds, and why.
Everything the app and this site collect, where it goes, who else sees it, how long it stays and how you delete it. Written from the code, not from intentions.
01About this policy, and changes to it
This policy explains how Liftor Software and Technology (OPC) Private Limited (CIN U58201DL2026OPC465080) (“Liftor”, “we”, “us”) collects, uses, shares, keeps and deletes personal data when you use the Liftor app for iPhone and Android (the “App”) and the website at www.liftor.app (the “Site”). It forms part of our Terms of Use.
The version published at https://www.liftor.app/privacy when you create an account, or when you continue to use the App after a change, is the version that applies to you. The App links to this address and does not carry its own copy. Each version has an effective date and a version number at the top of this page.
We change this policy when the App changes what it collects or who it shares with, when the law changes, or to make it clearer. When we do, we publish the new version here with a new version number and effective date. For a change that materially affects how your personal data is used, or that needs your consent under the law that applies to you, we will tell you in the App or by email before it takes effect and, where consent is required, ask for it. Continuing to use the App after the effective date means you accept a change that does not require consent. If you do not accept it, you can delete your account from Settings before the change applies.
What changed in version 2.1 (2 October 2026). The minimum age is 13; version 2.0 said 18 (section 15). Every request and complaint goes to support@liftor.app. Section 18 says exactly what the voice demonstration’s cookie and rate-limit counter are and how long they last, and adds Cloudflare, the Android list and the calculators. How the App handles your data is unchanged.
02Who is responsible, and how to reach us
The controller of your personal data (the “Data Fiduciary” under India’s Digital Personal Data Protection Act 2023, the “controller” under the EU and UK GDPR, and the “business” under California law) is Liftor Software and Technology (OPC) Private Limited (CIN U58201DL2026OPC465080), a one-person company incorporated in India on 31 March 2026 and registered with the Registrar of Companies, Delhi, at Plot No. G-2, Kh. No. 1280, Village Asola Fatehpur Beri, Sanjay Colony, Bhati Mines, South West Delhi, Delhi 110074, India.
- Privacy questions and requests: support@liftor.app
- Grievance Officer (India: Digital Personal Data Protection Act 2023 and the Information Technology Act 2000): Lakshay Bhati, Director, support@liftor.app, Plot No. G-2, Kh. No. 1280, Village Asola Fatehpur Beri, Sanjay Colony, Bhati Mines, South West Delhi, Delhi 110074, India
- Data Protection Officer: none has been appointed; the Grievance Officer above handles every privacy request
- Representative in the European Union (Article 27 GDPR): none has been appointed; write to the Grievance Officer above
- Representative in the United Kingdom (Article 27 UK GDPR): none has been appointed; write to the Grievance Officer above
Requests made from inside the App (export and delete, in Settings) do not need a separate email. For anything else, write to support@liftor.app; section 13 explains what you can ask for and how quickly we answer.
03The short version
- We collect what a coach needs to write your plan: who you are, your body measurements and goals, injuries, allergies and dietary rules, your check-ins, what you lift and eat, and, only if you allow it, health data from Apple Health or Health Connect.
- The coach is an AI. To write plans, meals, chat replies and notes, we send the relevant parts of your data, sometimes including your first name, to AI providers: DeepSeek, Google (Gemini) and OpenAI, through our server; and Rork Toolkit, directly from the App, only when those fail. Photographs of food go to Google; voice recordings go to OpenAI for transcription.
- We do not sell your personal data, we do not share it for advertising, and there is no advertising, analytics or tracking SDK in the App or on the Site. Product-usage events and crash reports go to our own database only.
- Health data is never used for advertising or marketing, never sold, and never shared except with the processors that run the feature you asked for.
- Friends see what you let them see. Social features share stats, workouts and plans with people you have accepted as friends, under privacy settings you control. Nothing is public unless you choose the Public setting.
- You can export a report and delete your account from Settings. Deletion signs you out at once and removes your data on the schedule in section 12.
- This Site sets one cookie, and only if you try the voice demonstration. It holds a count and an expiry that is particular to your browser, and your browser keeps it for up to 28 days. The Site has no analytics and no tracking.
04What we collect, feature by feature
The App collects personal data only when a feature needs it. This section lists each feature, what it collects, and where the data goes. “Our database” means the Supabase project the App runs on (section 9). “Your phone” means data the App keeps on your device and does not send to us.
Account and sign-in
You can create an account with an email address and password, with Sign in with Apple, or with Google. Passwords are stored only as a one-way hash by our authentication provider, Supabase, and are never readable by us. Apple gives us an identifier for your Apple ID and, if you choose to share them, your name and either your email address or an Apple relay address. Google gives us your Google account email and name. Signing in, changing your email or resetting a password may use a one-time code sent to your email. We record the name you enter, the time you signed up, when you last opened the App and the App version you used, and the user ID our database assigns you, which is the key every other record is filed under.
Profile and onboarding
To write your plan the App asks for your date of birth, sex, height, weight and target weight, goal, training experience, training days, session length, preferred training time, training environment and equipment, activity level and daily step goal, sports you play, injuries and injury locations, exercises to avoid, dietary preferences and rules, allergens and intolerances, cooking situation and food budget, meals per day and fasting window, sleep and wake times, caffeine and alcohol frequency, typical stress and sleep quality, supplements you take, your motivations, what you want the coach to sound like, and any free-text description of your situation you type or dictate. You can add a profile photo, which is stored in a publicly readable storage bucket, so anyone who has its address can load it. Your phone’s time zone is recorded so that plans and notifications land on the right day. All of this is stored in our database against your user ID, and the parts a plan needs are sent to the AI providers when a plan is generated (section 8). The App also generates a written “voice document” about you from your onboarding answers, including your first name and the free text you wrote, and stores it.
Daily check-ins and readiness
Each check-in can record your body weight, sleep hours and quality, how you woke, energy, mood, stress, soreness by muscle, appearance, digestion, hunger, water, salt, supplements, caffeine and alcohol, steps, motivation, resting heart rate and heart-rate variability (typed by you or pre-filled from your phone’s health data if you accept the suggestion), injuries, busy periods, travel, sport you are playing, yesterday’s workout quality, and free-text notes and requests. The App derives trends and a daily readiness score from these and from health data. Check-ins are stored in our database, archived into a history table, and the recent ones are summarised into the prompts that rewrite the day’s plan.
Workouts, strength and progress
When you train, the App records each exercise, set, weight, reps, duration, rest, notes, substitutions, additions, session start and end times, personal records, an estimated one-rep max and a Strength Score derived from your logged lifts and bodyweight. Custom exercises you create (with an optional image), workouts you save as templates and exercise history are stored too. This history is stored in our database and summarised into AI prompts for plans, chat, blends and recaps.
Nutrition and food logging
The App records the meals you tick off, extra foods you log, custom foods and saved foods, recipes you generate and save, shopping lists, water intake, corrections you make to the App’s food estimates, and your calorie and macronutrient targets. Food can be logged four ways, and each sends something different:
- Photograph. The image is uploaded from your phone to a private folder in our file storage that only you can read, then our server sends it to Google (Gemini) together with any note you typed and your last five corrections to earlier estimates, to identify the food and estimate its nutrition. The photo stays in your folder (section 12); the estimate is stored as a food entry.
- Voice. The recording, from the App or from the iPhone lock-screen widget, is sent to our server, which sends it to OpenAI for transcription and the transcript to DeepSeek to turn into foods and numbers. The recording is not kept on our server, and the transcript is not stored; only the resulting food entry is. Voice logging is limited to ten meals per day.
- Barcode. The barcode number is sent from your phone to Open Food Facts, a public food database, and, if the product is not found there and the feature is configured, to Nutritionix. No account data goes with it.
- Text. A typed description is sent to our server and on to DeepSeek like any other prompt.
Health data from your phone
If, and only if, you grant permission, the App reads from Apple Health (HealthKit) on iPhone or Health Connect on Android. On iPhone the App asks to read sleep, heart-rate variability, resting heart rate, heart rate, workouts, body weight, steps, active energy and resting energy. On Android it asks to read steps, sleep, heart rate, resting heart rate, active calories burned and heart-rate variability. The App never writes to either.
What is read stays on your phone first: the App keeps a 30-day baseline and an overnight snapshot on the device, and a background task on iPhone refreshes the snapshot without any network activity. The values reach our database in two ways: steps are synced to a daily steps table, and the other values are offered to you as a pre-filled check-in, which is stored only if you accept it. Readiness explanations built from these values (for example, how your HRV or sleep compares with your baseline) are sent to the AI providers as part of the day’s plan and readiness tip. Section 7 explains how this data is protected and how to withdraw permission.
Plans, phases, events and AI outputs
Everything the coach writes for you is stored in our database: base plans and daily plans, meal plans, recipes, phase plans and event plans (with the events, dates and outfits you enter), blended plans, insights, morning notes, nightly summaries, debriefs, season and year recaps, and the reasoning it shows you. These are derived from your data and are personal data too; they are deleted with your account.
Trainer chat, home chat and insights
Messages you send to the trainer chat or the home chat, and the replies, are sent to the AI providers together with the context the chat needs: your first name, goal, level, equipment, injuries, supplements, diet, age and bodyweight, recent check-ins, today’s plan and, during a workout, your live session stats. Chat history is kept on your phone, not in our database. The App also runs an “insights” engine that reads your check-ins, sessions, strength, social activity and chat transcripts (the transcripts are sent to the AI providers for this) and stores short derived insights about you in our database, which later notes and reminders draw on.
Notifications
If you allow notifications, the App registers a push token with Expo’s push service and stores it in our database with your user ID, platform, operating-system version and device model, so that our server can reach your phone. Many notifications are scheduled on the device itself from your own data (check-in and water reminders, the nightly recap, streak and milestone notes, phase reminders). Others come from our server: plan-ready notices, morning notes, friend activity, blend and live-session updates, streak-risk nudges to friends, phase reminders, and occasional announcements from us. Some notification text is generated by the AI providers from your recent data. Section 17 lists the switches for each kind.
Social: friends, blend, live sessions, leaderboard and sharing
If you use the social features, we store your six-character friend code (also shown as a QR code), friend requests and friendships, blocks, your privacy settings, messages to friends, the workouts, personal records, recipes and meals you share with a caption, reactions, blended plans, live sessions you host or join, leaderboard entries (total volume, sessions, consistency and streak), skipped-day records, and exercises you submit to the community library with your display name and profile photo. Section 10 says exactly who can see what. Blended plans are generated by DeepSeek from every member’s profile, today’s check-in and recent sessions.
Spotify
If you connect Spotify, you sign in with Spotify and it gives the App an access token and a refresh token, which are kept in your phone’s secure keychain and never stored on our server (on Android our server exchanges and refreshes them for you and returns them without keeping them). The App asks Spotify for permission to control playback on your devices, read your playback state and what is playing, read your private playlists, and read your email address; the App does not read or store your Spotify email, and we will remove that permission. The App sends Spotify the playback commands you trigger and looks up tracks by their identifiers; it does not send Spotify anything about your training. Spotify’s own privacy policy governs your Spotify account.
Subscriptions and trials
We record whether you have an active subscription, which store it came from, whether it will renew and when it expires, the entitlement it grants, and your RevenueCat identifiers. The full event RevenueCat sends us about a purchase is stored on your profile record. We do not receive or store payment card details; Apple, Google and RevenueCat handle payment, and RevenueCat knows you only by a random identifier (your user ID), never by your email or name. If you start the in-App three-day trial, we record that you have had it. If you cancel, the App may ask why; your answer and any comment are stored in our database. When you delete your account, a one-way hash of your email address and your RevenueCat identifier are kept, with a flag saying whether you used a trial, so that the same person cannot take a second free trial with a new account.
Errors, usage events and technical data
There is no analytics SDK, no crash-reporting SDK, no advertising SDK and no attribution SDK in the App. Instead, when the App hits an error it writes a report to our own database with your user ID, the error message and stack trace (with email addresses, tokens and keys removed first), the App version, platform and update identifiers. The App also records a small set of product events in our database, such as the App being opened, a check-in logged, a meal logged or skipped, a workout completed, cut short or skipped, a plan viewed or regenerated, and step-tracking connection events, so that the coach and our own reports can see how the plan is being followed. These never leave our systems. Our hosting providers (section 9) see your IP address in the ordinary course of serving requests, and our server records the time zone your phone reports.
The lock-screen widget and Live Activities (iPhone)
The iPhone voice-logging widget records a meal from the lock screen and uploads it directly to our server the same way the App does, using a copy of your sign-in session that the App shares with the widget through a container on your phone. After the upload it shows the transcript and the estimated nutrition on the lock screen until dismissed. Live Activities show your current exercise, set count and rest timer on the lock screen and Dynamic Island. These displays are rendered by your phone and are not sent to us separately.
Exports and reports
The App can build PDF reports on your phone (a data export covering the last 30 days, a weekly plan, a shopping list, a strength report). They are generated on the device and handed to the share sheet you choose; we do not receive a copy. When the weekly-plan or shopping-list PDF is built, the page it renders loads a typeface from Google Fonts, so Google receives an ordinary font request from your phone at that moment; none of the plan’s contents are included in it.
The Site
What the website collects is small enough to describe in one section: section 18.
05Where the data comes from
- You, when you sign up, onboard, check in, log, chat, share or write to us.
- Your phone, when you grant a permission: Apple Health or Health Connect, the camera and photo library, the microphone, and notifications. The App does not request location, contacts or calendar access; a location library is included in the App’s build, but no code in the App uses it, and no location permission is declared.
- Your friends, when they share workouts, records, recipes or plans with you, message you, or add you to a live session or blend.
- Apple, Google and RevenueCat, about your sign-in and your subscription.
- The AI providers and the food and exercise databases, in the form of the outputs they return about you.
06Why we use it, and the legal basis
We use personal data for the purposes below. For people in the EU, the UK and other places whose law requires a legal basis for each purpose, the basis is given after it. For people in India, the Digital Personal Data Protection Act 2023 requires notice and consent for most processing, or a legitimate use the Act permits; the purposes below are the purposes you consent to when you create an account, and section 13 explains how to withdraw consent.
- To provide the Service you asked for: creating and securing your account, writing and rewriting your plans, tracking your training and food, running the social features you use, sending the notifications you enabled, and answering support requests. *Basis: performance of our contract with you (the Terms).*
- To process health data and other sensitive data (health metrics, body measurements, injuries, allergies, dietary and religious food rules, mood and stress) for those same purposes. *Basis: your explicit consent, given when you grant a phone permission or enter the data. You can withdraw it at any time (section 7).*
- To improve and secure the Service: fixing errors from the reports the App sends, understanding how plans are followed from the usage events above, preventing abuse (for example repeat free trials), enforcing rate limits, and keeping the AI on topic. *Basis: our legitimate interest in running a safe, working service, balanced against your interests; we use the least data that does the job and no third-party analytics.*
- To bill you: checking with RevenueCat and the stores whether you are entitled to the paid features. *Basis: performance of the contract.*
- To send you service messages: emails when your plan is built, when your subscription starts or stops renewing, and about changes to these documents; notifications about your plan and your friends. *Basis: performance of the contract and our legitimate interest in keeping you informed.*
- To send you re-engagement and announcement messages: an email if you have not checked in for four days, an email about unlocking the full Service if you built a plan without subscribing, and occasional announcements from us by push notification or email. *Basis: our legitimate interest in keeping the Service useful to you, and your consent where the law requires it. Section 17 explains how to stop them.*
- To tell you when Liftor is on Google Play: the address you leave on the Site’s Android list is used for one email, the day the Google Play listing is live, with a discount code (section 18). *Basis: your consent, given when you send the address. You can withdraw it at any time by writing to support@liftor.app.*
- To comply with law: keeping records the law requires, responding to lawful requests, and enforcing our Terms. *Basis: legal obligation and legitimate interest.*
We do not use your personal data to build profiles for advertising, we do not sell it, we do not share it with data brokers, and we do not make decisions with legal or similarly significant effects about you by automated means. The plan the coach writes is automated, and it affects what the App suggests, but you decide what to do with it, and you can change or discard any of it.
07Health data: special handling
Health data means anything about your body, health or physical state: the metrics read from Apple Health or Health Connect, the weight, heart-rate and HRV values you type, sleep, injuries, allergies, mood, stress and soreness, and what the App derives from them, such as readiness. Under the GDPR it is a special category of data; under California law it is sensitive personal information; under India’s law it is personal data processed only with your consent. We treat all of it the same way:
- We read it only with your explicit consent. Phone health data is read only after you grant the permission in the system dialog, which lists each data type. You choose the types; the App works without any of them.
- It is used only to run the features you asked for: readiness, step and activity tracking, adjusting calorie targets and recovery guidance, and the plans, notes and blends that depend on them. Health values from your phone reach the AI providers only as part of those features, in the form of check-in values you accepted and readiness explanations.
- It is never used for advertising or marketing, never sold, and never disclosed to data brokers, insurers, employers or advertisers, in keeping with Apple’s HealthKit rules and Google’s Health Connect policy.
- We never write to Apple Health or Health Connect.
- You can withdraw permission at any time in the iPhone Health app (Sharing → Apps) or in Health Connect settings on Android. The App stops reading at once. Values already stored in a check-in stay until you delete the check-in or your account; write to us if you want them removed sooner.
- The Android Health Connect permission sheet links to this policy, as Google requires.
A note on the iPhone permission text. The message the App shows when it asks for Health access describes reading your step count. The permission dialog itself lists every type the App can read (the nine types in section 4), and that dialog is the authoritative list. We are updating the message to name all of them.
08AI processing: what goes to which provider
The coach is built on third-party AI models. We do not train models ourselves. Each request sends a model a prompt made from the parts of your data the feature needs and stores the answer in our database as part of your plan or history. Our AI relay stores no prompts and no responses; it forwards what the App sends, logs your user ID, the provider, the model and the length of the reply, and enforces a per-user rate limit. Our other server functions that call these providers likewise log identifiers and sizes rather than the content of what you said, with two exceptions: a diagnostic setting, off by default, can write the first 200 characters of a voice-log transcript to our server logs; and the step that designs your training year keeps the model’s full reply about you in our database next to the parsed plan, and writes that reply to our server logs for debugging. Those replies describe your plan and the model’s reading of you; they are deleted with your account. This is what leaves our systems, by provider:
| Provider | Reached | What it receives | Used for |
|---|---|---|---|
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.), model deepseek-v4-flash | From our server | Prompts built from your profile: first name in some features, date of birth or age, sex, height, weight and target weight, goal, level, equipment, injuries and injury locations, allergens and dietary rules, supplements, sports, motivations and the free text you wrote, the written voice document and the stored insights about you, events you enter (date, importance, what you plan to wear, the look you want), your previous plan; recent check-ins including sleep, stress, energy, soreness, heart rate and HRV; recent workouts with sets and weights; meals; your requests and chat messages; transcripts of your voice logs; and, for blends, the same for each friend in the blend. Never your email address or password. The daily-plan prompt identifies you only by the first six characters of your user ID. | Base and daily plans, meal plans and recipes, phase and event plans, blended plans, trainer and home chat, exercise information when the catalogue has none, morning and nightly notes, insights, debriefs and recaps, Strength Score facts, voice-log parsing, the onboarding voice document |
| Google (Google LLC), model Gemini 2.5 Flash | From our server | The photographs you take of food, with your note and your last five corrections; the same kinds of prompt as DeepSeek when used as a fallback (including the morning-note prompt: your motivations, the free text about why now and your future self, your sleep and training times, and the voice document); and specifically the workout part of your daily plan and the personalised paywall text (name, goal, sex, age, motivations). | Food-photo nutrition estimates; fallback for plans, chat and morning notes; some workout generation; paywall personalisation |
| OpenAI (OpenAI, L.L.C.), model gpt-4o-transcribe (or whisper-1) | From our server | Your voice recordings of meals and onboarding dictation, from the App (with the language you chose), the lock-screen widget and the Site demonstration. Nothing else about you. OpenAI chat models are also reachable through our relay for text prompts, if a feature is configured to use them. | Speech-to-text; text generation only where configured |
| Rork Toolkit (toolkit.rork.com) | Directly from your phone, only when our server-side providers fail or time out | The same prompt that was about to go to DeepSeek or Gemini, over HTTPS, without any account credential. | Emergency fallback for text generation so a plan or reply still arrives |
Exercise look-ups send only the exercise name or search term to DeepSeek and to the exercise database, never anything about you.
The providers’ own terms, not ours, govern what they do with what they receive, including whether they keep it, for how long, and whether they use it to improve their models. We have not audited them and cannot control them. Their policies are published by DeepSeek (deepseek.com), Google (ai.google.dev and policies.google.com), OpenAI (openai.com) and Rork (rork.com). If you would rather your data did not reach an AI provider, the App cannot generate plans, meals, chat or voice logs for you; you can still use it to track workouts, water and steps by hand.
Everything these providers write is machine-generated and can be wrong; the Terms explain why it is not medical, dietary or professional advice.
09Who else receives data
We share personal data only with the companies that run part of the Service for us, each for the purpose named, and with the parties the law or your safety requires. Nobody is paid for your data and nobody buys it.
| Provider | Role | What it receives |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage and server functions for the App; hosted in Singapore (Amazon Web Services region ap-southeast-1) | Everything in section 4 that is stored in “our database”, your login credentials (password as a hash), food photographs, profile photos, custom-exercise images, and the logs of our server functions; and, for the Site, the email addresses left on the Android list |
| Vercel, Inc. | Hosting for the Site, and its request logs | Your IP address and request headers when you visit the Site and, in transit, what you send it: the recording if you use the voice demonstration, the address if you use the Android list |
| Cloudflare, Inc. | DNS and network edge (proxy) for liftor.app, in front of the Site’s host | Your IP address and request headers on every visit and, in transit, the same content Vercel handles: a recording or an Android-list address if you use them |
| Upstash, Inc. (Redis) | Rate-limit counters for the Site’s voice demonstration | A shortened hash of your network address, a count and a timestamp, for up to 14 days after your last try |
| Expo (650 Industries, Inc.) | Push-notification delivery, and delivery of App updates | Your push token and the text of each notification; when the App checks for an update, your device’s platform, App version and update channel |
| Resend, Inc. | Sending email | Your email address, your first name where the email uses it, and the content of the email |
| RevenueCat, Inc. | Subscription status across Apple and Google | A random identifier for your account, your store purchase receipts and subscription events; never your card details, email or name |
| Apple Inc. and Google LLC | App distribution, payment, Sign in with Apple and Google, Apple Health and Health Connect, the Health Connect permission sheet, and Google Fonts when a PDF is built | What you give them directly under their own terms; we receive from them only sign-in identifiers, purchase status and, with permission, health data |
| Spotify AB | Music control if you connect Spotify | Your Spotify sign-in and the playback commands the App sends; our server sees your Spotify tokens only in transit |
| Open Food Facts (non-profit) and Nutritionix, Inc. (if configured) | Barcode lookups | The barcode you scanned, sent directly from your phone; Open Food Facts also sees an App identifier and our support address in the request |
| ExerciseDB (via RapidAPI, Inc.) and Ascend API | Exercise catalogue, images and demonstrations | Exercise names, identifiers and search filters, sent through our server; no account data |
| DeepSeek, Google, OpenAI, Rork | AI generation and transcription | As set out in section 8 |
We may also disclose personal data:
- to comply with law, a court order, or a lawful request from a public authority, after checking that the request is valid and, where the law allows, telling you;
- to protect someone’s safety or our rights, for example to investigate abuse of the Service or a threat to a user;
- to a successor if we sell or transfer the business or the App, in which case this policy continues to apply and we tell you before your data is handled under a different one;
- at your direction, for example when you share a report with your doctor or a friend.
11Where your data is processed
We are in India. Our database is hosted by Supabase in Singapore (Amazon Web Services region ap-southeast-1). The providers in sections 8 and 9 process data in the United States and in other countries where they operate; DeepSeek processes data in the People’s Republic of China. Your data therefore crosses borders, and some destinations do not have laws the EU, the UK or India consider equivalent to their own.
If you are in the EU, the EEA, the UK or Switzerland, we rely on the following for those transfers: the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) in our agreements with providers that offer them, adequacy decisions where they exist (for example for providers certified under the EU–US Data Privacy Framework), and, for the AI providers where no such mechanism is available, your explicit consent to the transfer, which you give when you use an AI feature and can withdraw by not using it. You can ask us for a copy of the safeguards by writing to support@liftor.app.
If you are in India, the Digital Personal Data Protection Act 2023 permits transfer of personal data outside India except to countries the Central Government restricts by notification. We transfer only to the providers named here and only for the purposes named.
12How long we keep it
We keep personal data for as long as you have an account, and then as follows:
| Data | Kept until |
|---|---|
| Your account and everything filed under it (profile, check-ins, workouts, food entries, plans, insights, health values, social data, notifications, error reports, usage events, subscription status) | You delete your account. Deletion disables the account immediately and the records are permanently removed by our purge process 30 days later (section 14). A copy may persist in our database provider’s routine backups for up to seven days after that, and then it is gone. |
| Food photographs | Until you delete your account |
| Voice recordings and transcripts | Not kept. The recording is discarded once transcribed and the transcript once parsed; only the resulting food entry (or your dictated text) is stored |
| Push tokens | Deleted the moment you delete your account, replaced whenever your phone issues a new one, and removed when the push service reports the device gone |
| The deletion tombstone: a one-way hash of your email, your RevenueCat identifier, whether you had a trial, and the deletion and purge dates | Indefinitely, to prevent repeat free trials and abuse. It contains no readable identifier |
| Cancellation reasons | Deleted with your account |
| Emails sent to you | Delivery logs are held by Resend for 30 days, the data-retention period of our Resend plan |
| Subscription records at RevenueCat and the stores | Under their own retention policies; we do not delete the RevenueCat customer record when you delete your account, because Apple and Google may still need it to settle a refund or a dispute |
| Server logs (function logs at Supabase, request logs at Vercel and Cloudflare) | Under those providers’ default retention, which each of them publishes |
| Data on your phone | Until you delete your account (the App wipes its local data), delete the App, or clear its data. Chat history lives only here |
| Site voice-demonstration cookie (lf_taste) | Your browser keeps it for 14 days from each successful try, so up to 28 days in all. You can delete it in your browser at any time |
| Site voice-demonstration counter: a shortened hash of your network address, with a count and a timestamp (at Upstash) | 14 days after your last try |
| Email address left on the Site’s Android list (at Supabase) | Until the one launch email has been sent, and then deleted. Sooner if you ask: write to support@liftor.app |
| Correspondence with you | For as long as it takes to handle the matter, and then for up to three years as a record of it |
We may keep data longer where the law requires it, to resolve a dispute, or to enforce our Terms, and we may keep aggregated, de-identified statistics that do not identify anyone.
13Your rights, and how to use them
Wherever you live, you can:
- See what we hold about you. The App shows almost all of it, and the export in Settings produces a report of the last 30 days; ask us for a complete copy in a portable format.
- Correct it. Your profile, settings and history can be edited in the App; write to us for anything you cannot change yourself.
- Delete it, in the App (Settings → Delete Account) or by writing to us.
- Withdraw consent at any time: revoke a phone permission in system settings, turn off a notification category, disconnect Spotify, or stop using an AI feature. Withdrawing consent does not affect processing that already happened.
- Object to, or restrict, processing based on our legitimate interests, including re-engagement messages, and we will stop unless we have a compelling reason not to.
- Complain. We would rather hear from you first, but you can complain to a supervisory authority at any time (below).
If you are in India
Under the Digital Personal Data Protection Act 2023 you have the right to access information about your personal data and its processing, to correction and erasure, to grievance redressal, and to nominate a person to exercise your rights if you die or are incapacitated (write to us to record a nominee). Send requests and grievances to the Grievance Officer named in section 2; we respond within the time the Act and its rules prescribe. If you are not satisfied, you may approach the Data Protection Board of India.
If you are in the EU, the EEA, the UK or Switzerland
You have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to solely automated decisions with legal or similarly significant effects, and the right to withdraw consent. We answer within one month, extendable by two months for complex requests, and we will tell you if we extend. You may complain to the data-protection authority of the country where you live or work, to the UK Information Commissioner’s Office, or to the Swiss Federal Data Protection and Information Commissioner.
If you are in California or another US state with a privacy law
You have the right to know what personal information we collect, use and disclose and for what purposes (this policy, and section 19 in the categories the law uses), to access it, to correct it, to delete it, to limit the use of sensitive personal information, and not to be discriminated against for exercising a right. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months, so there is nothing to opt out of; because we do not track you across sites or apps, a Global Privacy Control signal changes nothing about how we treat you. We use sensitive personal information (health data, precise body data, account credentials) only to provide the Service you requested, which is a permitted purpose. You may use an authorised agent to make a request; we will ask for proof of their authority. We answer within 45 days, extendable once by 45 days.
Making a request
Use the App where it can do the job. Otherwise email support@liftor.app from the email on your account, or tell us which account you mean; we verify that a request comes from the account holder before acting on it, and we may ask you to confirm through the App. Requests are free, unless they are manifestly unfounded or excessive, in which case the law lets us charge a reasonable fee or decline, and we will explain why.
14Deleting your account
In the App, go to Settings → Delete Account, and confirm twice. This is what happens, in order:
- Our server writes the deletion tombstone described in section 12, marks your profile as deleted with a purge date 30 days ahead, permanently bans your sign-in so the account cannot be used again, and deletes your push tokens so no notification can reach you.
- The App wipes its local data from your phone and signs you out.
- After those thirty days our purge process permanently deletes your account from our authentication system, and every record filed under your user ID in our database is removed with it by database rules. We run the purge ourselves rather than on a timer, so the day can vary by a little, and we remove the files you uploaded (food photographs, profile photo, custom-exercise images) from file storage when we run it.
There is no way to undo this from the App. The 30 days exist so that a deletion made by mistake, or by someone who got into your account, can be reversed by writing to us before the purge date with proof that the account is yours; after that, the data is gone. Deleting your account does not cancel a store subscription (see the Terms, section 08) and does not delete data a friend already received from you, or your customer record at RevenueCat, Apple or Google.
If you cannot use the App, email support@liftor.app from the address on your account and we will run the same deletion for you. The App’s help text also mentions an older request-based deletion that took a few business days; that flow has been replaced by the in-App deletion above.
15Children
You must be at least 13 years old to create an account or use the App. We do not knowingly collect personal data from anyone under 13. If you are under 18, you should have a parent or guardian’s permission to use Liftor, and we encourage you to read this policy with them. The App asks for your date of birth during onboarding and uses it to work out your age. If we learn that we have collected personal data from a child under 13, we will close the account and delete the data. If you believe a person under 13 has an account, write to support@liftor.app and we will close it and delete its data.
16Security
We protect personal data with measures that fit a small, focused service:
- Encryption in transit. Every connection from the App and the Site to our servers and to every provider uses HTTPS; the App’s transport-security settings require TLS 1.2 or higher.
- Encryption at rest for our database and file storage, as provided by Supabase on its platform.
- Row-level access rules in the database, so that a signed-in user can read and write only their own records and the records friends have shared with them; food photographs are readable only by their owner.
- Keys held server-side. The credentials for the AI providers, transcription, email, Spotify, RevenueCat and the exercise database live only on our server; the App carries none of them.
- Authentication by Supabase, with passwords stored as one-way hashes, and email one-time codes, Sign in with Apple and Google as alternatives.
- Minimal logging. Our server functions log identifiers, sizes and notification text, not the content of your prompts, photographs or recordings, and the Site’s own code never writes a raw network address to a log (our hosts, section 9, see it in the ordinary course of serving you).
- Access limited to the people who need it to run the Service, under confidentiality obligations.
The App keeps your sign-in session and a local copy of your data in its own storage area on your phone, protected by your phone’s lock, so that your plan works offline; Spotify tokens are kept in the phone’s secure keychain. Anyone who can unlock your phone can open the App. No system is perfectly secure. If we learn of a breach that affects your personal data, we will tell the authorities the law requires, and tell you, without undue delay. You can help by keeping your phone locked, using a strong unique password, and telling us at once if you think your account has been used by someone else.
17Notifications and email
Push notifications
You control notifications at three levels:
- Your phone’s notification permission. Turning it off stops every notification, from the device and from our server.
- Notification settings in the App. A master switch for the coach’s notes, with separate switches for late-night notes, missed meals, workout windows, missed supplements, breathing prompts, the weekly insight, the good-night note and streak notes; quiet hours; and a daily ceiling of one to three. Check-in reminders and milestone notes have their own switches in Settings and Program settings.
- Privacy settings. “Share streak” and “friend streak alerts” govern streak-risk nudges; “share skipped days” governs skipped-workout nudges; friend, blend and live-session notifications follow from the friendships and sessions you accept.
Plan-ready and phase-reminder notifications, and occasional announcements from us (which may link to our social media), are sent to every device with a push token and have no switch of their own inside the App; turn off the phone permission, or write to us and we will remove your token from announcements.
We email the address on your account for: a one-time code when you sign in or verify; confirmation that your plan is built; a welcome when your subscription starts and a note when it stops renewing; a check-in prompt if you have not checked in for four days; a reminder about unlocking the full Service if you built a plan without subscribing; changes to these documents; replies to your requests; and occasional announcements. The emails come from Resend on our behalf. To stop the check-in prompt, the unlock reminder and announcements, write to support@liftor.app or reply to the email and we will stop them; you cannot opt out of one-time codes, the plan-built confirmation, subscription notices or legal notices while you have an account, because the Service depends on them.
18This website
The Site is a set of pages about Liftor. Vercel hosts it, with Cloudflare handling DNS and the network edge in front of it. It sets no cookie of its own when you read it, loads no fonts, scripts or images from any third party, and runs no analytics or tracking. The Site’s content-security policy forbids the page from contacting any host but our own. What Vercel and Cloudflare see is what any web host and network provider sees: your IP address, the page you requested and your browser’s standard headers, in their request logs, and, in transit, whatever you send us. Cloudflare may set a short-lived security cookie of its own; we set none.
Three parts of the Site do more:
- The Android list at /android, and on the Android tab of /download. If you type an email address there and send it, your browser sends it to our server, which stores it in our database (the same Supabase project the App uses, in Singapore) together with which link on the Site you arrived from and the time. It is used for one email — to tell you the Google Play listing is live and to carry the discount code — and for nothing else. We do not sell it or pass it to anyone for their own use; only the providers that run the list for us handle it (Vercel, Cloudflare, Supabase, and our email provider when the launch email goes out, section 9). It is deleted once that email has been sent. To be removed before then, write to support@liftor.app with the address to remove. Nothing is written to your browser: no cookie, no storage. To stop double taps, the server keeps in its own memory, and nowhere else, a shortened hash of your network address and the time of your last try; it goes when that server instance restarts. The Site logs no address.
- The voice demonstration on the home page. If you tap the button and speak, your browser sends the recording to our server, which forwards it to the same server function the App uses; that function sends the audio to OpenAI for transcription and the transcript to DeepSeek for the nutrition estimate (section 8), and returns the result. The recording is processed to read the meal, and neither the Site nor our function stores the recording, the transcript or the result; the Site’s server logs the size of the recording, how long the call took and its cost, and nothing you said. To limit use and spending, the Site does two things. After a successful try it sets one cookie, lf_taste, which holds a count of successful tries, the moment your window ends (to the millisecond, so the value is particular to your browser) and a signature. Your browser keeps it for 14 days from each successful try, so up to 28 days in all, sends it back to the Site and to no one else, and hides it from scripts on the page. And on each try it keeps a shortened hash of your network address, with a count and a timestamp, in Redis at Upstash for 14 days after your last try; a hash of an address is not anonymous, so we treat it as personal data. We do not store or log the raw address ourselves, but Vercel and Cloudflare, as the hosts, see it in the ordinary course. Your microphone is used only after you tap, and only while you speak, for about twenty seconds at most.
- The calculators (the Strength Score tool and the calorie and one-rep-max calculators) run entirely in your browser. What you type is used to compute the result on your device. It is not sent to us and not stored.
The home page remembers what you did on it (a meal you logged in the demonstration, a mood you picked) in your browser tab’s memory only, so later sections can refer back to it. Nothing is written to storage or sent anywhere, and closing the tab forgets it.
19California notice at collection
For California residents, this is the same information as above, in the categories the California Consumer Privacy Act uses. We collected each category in the preceding 12 months from the sources in section 5, for the purposes in section 6, and disclosed it for a business purpose to the service providers in section 9. We do not sell or share any category.
| Category | Examples in Liftor | Collected |
|---|---|---|
| Identifiers | Name, email address, user ID, Apple or Google sign-in identifier, push token, friend code, IP address | Yes |
| Personal information under Cal. Civ. Code §1798.80(e) | Name, email; no payment card data (held by Apple/Google) | Yes |
| Protected classifications | Age and date of birth, sex; religious dietary rules if you enter them | Yes |
| Commercial information | Subscription status, trial use, purchase events from RevenueCat, cancellation reasons | Yes |
| Biometric information | None | No |
| Internet or network activity | Site request logs at our hosts; product-usage events and error reports in our own database | Yes |
| Geolocation data | None; no location permission is requested. Your time zone is recorded | No |
| Audio, electronic, visual information | Voice recordings of meals and dictation (transcribed, then discarded), food photographs, profile photo, custom-exercise images | Yes |
| Professional or employment information | None | No |
| Education information | None | No |
| Inferences | Readiness score, Strength Score, trends, insights, and the plans and notes the coach writes | Yes |
| Sensitive personal information | Health data (steps, sleep, heart rate, HRV, weight, injuries, mood, stress), account log-in credentials, precise body measurements | Yes, used only to provide the Service |
Retention for each category is in section 12. California’s “Shine the Light” law: we do not disclose personal information to third parties for their direct marketing.
20Contact
- Controller / Data Fiduciary: Liftor Software and Technology (OPC) Private Limited (CIN U58201DL2026OPC465080), Plot No. G-2, Kh. No. 1280, Village Asola Fatehpur Beri, Sanjay Colony, Bhati Mines, South West Delhi, Delhi 110074, India
- Privacy requests: support@liftor.app
- Grievance Officer (India): Lakshay Bhati, Director, support@liftor.app, Plot No. G-2, Kh. No. 1280, Village Asola Fatehpur Beri, Sanjay Colony, Bhati Mines, South West Delhi, Delhi 110074, India
- EU representative: none appointed
- UK representative: none appointed
The feature-by-feature table behind this policy, with the code each row was read from, is kept with the App’s documentation and is available on request.

10What other users can see
By default, only people you have accepted as friends can see anything about you, and only what your settings allow. In detail:
Anything you share with a friend is theirs to keep; deleting your account removes your records from our database, but does not recall a workout or record a friend has already received. Share cards and reports you export from the App are files on your phone; where they go is up to you.