← Back to LiftStrong
Privacy Policy
Last updated: 1 April 2026
LiftStrong ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use the LiftStrong mobile application.
1. Information We Collect
Information you provide directly:
- Account information — If you create an account, we collect your display name, email address, and password (stored securely via Supabase Authentication).
- Workout data — Exercises performed, weights, sets, reps, workout duration, and completion dates.
- Body weight — Weight measurements you choose to log.
- Profile information — Optional details such as gym name and profile photo.
- Messages — Text messages sent through the buddy chat feature.
Information collected automatically:
- Device information — Device type, operating system version, and app version for compatibility and debugging purposes.
- Usage data — App feature usage patterns to improve the product (no personally identifiable information).
Information we do NOT collect:
- We do not collect your location data.
- We do not access your contacts, camera, or microphone without explicit permission.
- We do not collect financial or payment information.
- We do not use advertising trackers or sell your data to third parties.
2. How We Use Your Information
- Provide the service — Store and sync your workouts, track progression, calculate statistics, and display your training history.
- Community features — Enable buddy pairing, leaderboards, challenges, chat messaging, and activity feeds.
- Cloud backup — Sync your data across devices when you create an account.
- Health platform integration — Write workout and bodyweight data to Apple Health (iOS) or Health Connect (Android) only when you explicitly enable this in Settings.
- Improve the app — Understand usage patterns to fix bugs and build better features.
3. Data Storage & Security
Your data is stored in two places:
- Locally on your device — All workout data is stored in a local SQLite database on your phone. This works offline and does not require an account.
- Cloud (Supabase) — If you create an account, your data is synced to Supabase, a secure cloud database hosted on AWS infrastructure. Data is encrypted in transit (TLS) and at rest.
We use Row Level Security (RLS) policies to ensure that each user can only access their own data. Your workout data, messages, and profile information are never visible to other users unless you explicitly share them (e.g., via the buddy system or leaderboards).
4. Health Data
LiftStrong can optionally integrate with Apple Health (iOS) and Health Connect (Android). When enabled:
- We write workout sessions (type, duration, estimated calories) and bodyweight measurements to your device's health platform.
- We read your latest bodyweight measurement to suggest it in the app.
- Health data stays on your device and is managed by Apple Health or Health Connect — we do not store health data on our servers.
- You can disable health integration at any time in Settings.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- Supabase — Our cloud database provider, which processes data on our behalf under strict data processing agreements.
- Legal requirements — If required by law, regulation, or legal process.
- Your explicit sharing — Workout summaries you choose to share via the Share button, buddy features, or leaderboards.
6. Your Rights
You have the right to:
- Access your data — Export all your workout data as CSV from Settings.
- Delete your data — Delete your account from Settings. This removes your cloud data from Supabase. Local data on your device can be removed by uninstalling the app.
- Withdraw consent — Disable cloud sync, health integration, or notifications at any time.
- Data portability — Your CSV export includes all workout data in a standard format.
7. Children's Privacy
LiftStrong is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete that information promptly.
8. Data Retention
We retain your data for as long as your account is active. If you delete your account, your cloud data is removed within 30 days. Local data on your device is retained until you uninstall the app.
9. Data Deletion Requests
You can delete your data at any time using one of the following methods:
- In the app — Go to Settings and sign out to remove your cloud data, then uninstall the app to remove local data.
- By email — Send a request to info@liftstrong.app with the subject line "Data Deletion Request". We will delete all your account and associated data within 30 days and confirm by email once complete.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the app and updating the "Last updated" date above.
11. Contact Us
If you have any questions about this Privacy Policy or your data, please contact us at:
Email: info@liftstrong.app