Skip to content

Privacy

Privacy Policy

Last updated: May 29, 2026

At Lifted, your privacy is a feature, not an afterthought. We do not sell your personal data, and we do not use your health or workout data to target you with ads. This policy explains, in plain language, what we collect, why, who we share it with, and the choices and rights you have.

1. Who we are

Lifted (the “app”) is operated by Diego San Diego (“we”, “us”), the data controller for the information described here. For any privacy question or request, contact us at support@liftedliving.app.

2. Information we collect

Account & profile. When you create an account we collect your email address, username, first and last name, and (if you choose to add it) your phone number. We also store a password — handled in hashed form by our authentication provider — or, if you use Google or Apple sign-in, an OAuth identifier. Your profile may also include a bio, location, fitness goals, and a profile photo you upload.

Workout & wellness content. The splits, exercises, sets, reps, weights, RPE, personal records, and notes you log, plus wellness entries such as hydration, supplements, sleep, and custom categories. This is stored on your device first and synced to our cloud so you can use it across devices.

Health & fitness data (Apple Health / Google Health Connect). Only with your explicit permission, the app reads steps, sleep, and dietary calories/protein from Apple Health or Health Connect, and can write your completed workouts back to them. Daily summaries derived from this (e.g. step count, sleep hours, calories, protein) are saved alongside your wellness data and synced to our cloud. We never use health data for advertising, and we never sell it. You can revoke this access at any time in your device settings.

Usage & diagnostic data. To fix bugs and improve the app we collect app-interaction events, crash reports, and basic device/app information through Google Firebase (Analytics and Crashlytics). This is linked to a pseudonymous identifier — not your name — and may include app-content labels such as exercise or split names.

Advertising identifier. If you use the free, ad-supported version, Google AdMob may use your device advertising identifier (see “Ads & tracking” below).

Notifications, purchases & support. A device push token (for notifications); in-app purchase receipts, which are validated with Apple/Google to manage your premium status; and, if you submit feedback, the content and contact email you provide to our feedback tool (UserJot).

3. How we use your information

  • Provide the app, your account, and cloud sync across devices.
  • Diagnose crashes, analyze usage, and improve features.
  • Send notifications you’ve enabled.
  • Show ads in the free version and process premium purchases.
  • Respond to support requests and protect against abuse/fraud.

Where required by law (e.g. in the EEA/UK), we rely on these legal bases: performing our contract with you (providing the app), your consent (health-data access, ad tracking, and analytics where applicable), our legitimate interests (security and product improvement), and legal obligations.

4. Who we share it with

We do not sell your personal data. We share data only with the service providers that operate the app on our behalf:

  • Supabase — backend hosting, database, authentication, and file storage (United States).
  • Resend — sending transactional emails (confirmation, password reset).
  • Google Firebase — analytics, crash reporting, and push notifications.
  • Google AdMob — advertising in the free version.
  • Apple & Google — sign-in, in-app purchases, and Health/Health Connect integrations.
  • UserJot — handling feedback you submit.

We may also disclose data if required by law or to protect our rights and users’ safety.

5. Ads & tracking

The free version shows ads through Google AdMob. On iOS you’ll be asked for App Tracking Transparency permission; if you decline (or where consent isn’t given), ads are non-personalized. Upgrading to premium removes ads. We never share your workout or health data with advertisers.

6. Where your data lives & how we protect it

Data on your device is kept in the app’s private storage and protected by your device’s operating-system encryption (such as iOS Data Protection). Data sent to our servers travels over encrypted TLS connections and is stored by Supabase in the United States, encrypted at rest. Authentication tokens are stored in your device’s secure keychain.

7. International transfers

Our servers are located in the United States. If you access Lifted from outside the U.S. (including the EEA or UK), your information will be transferred to and processed in the U.S. under appropriate safeguards.

8. How long we keep it

We keep your information for as long as your account is active. When you delete your account we remove your account, profile, and workout and wellness data from our servers (see below). Limited backups or logs may persist for a short period before being overwritten.

9. Deleting your account

You can delete your account from inside the app at any time: Settings → Account → Delete Account. This permanently removes your account, profile, and associated workout and wellness data from our servers. The action cannot be undone.

Prefer to email us? Send a request to support@liftedliving.app and we will process the deletion within 30 days.

10. Your rights & choices

You can access and correct your profile in the app, export your data (Profile → Export Data), and delete your account as described above. Depending on where you live, you may also have the right to request a copy of your data, restrict or object to certain processing, and withdraw consent. To exercise any of these, email support@liftedliving.app.

EEA/UK: you have the right to lodge a complaint with your local data protection supervisory authority.

California (CCPA/CPRA): you have the right to know, access, correct, and delete your personal information, and we will not discriminate against you for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising beyond the device advertising-identifier use described above.

11. Children’s privacy

Lifted is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect their data. If you believe a child has created an account, contact us at support@liftedliving.app and we will remove it.

12. Changes

We will update this policy when we make material changes to how we handle data. The “Last updated” date at the top reflects the most recent revision.

13. Contact

Questions about this policy? Reach us at support@liftedliving.app.