Privacy Policy
Last updated: 2026-07-31
Who we are
Liftstuff ("the App") is a personal fitness app that lets you plan workouts, track meals and macros, log activities and check-ins, and review statistics across days. The App is developed and operated by Liftstuff. For privacy questions or requests, contact privacy@liftstuff.com.
How the App works
Your logs (workouts, exercises, sets/reps, meals and macros, goals, streaks and other day entries) are stored locally on your device using IndexedDB so the app works offline. If you sign in with your email, the App can back up and restore your data to our cloud database.
Information we collect
- Account information: email address used for sign‑in via one‑time passcode (OTP).
- App content you create: workout templates, day logs (workouts, meals/macros, activities, check-ins), and related notes or settings. This is your data.
- Authentication and security data: hashed OTP codes (temporary), JSON Web Tokens (JWT) for session management, and backup timestamps.
- Health and fitness data you choose to share from Apple Health or Health Connect. See Health and fitness data below for the full list and how it is used.
We do not collect address books, photos, or precise device identifiers. We do not include advertising SDKs and do not serve ads.
How we use information
- Authenticate you using email OTP and maintain your session with a JWT.
- Store your content on‑device and, if you choose to sign in, back it up to the cloud.
- Provide subscription features and access control for premium functionality.
- Send required transactional emails (your OTP code) when you request it.
Where your data is stored
- On your device: IndexedDB stores your day logs, templates and activity data. On web, the JWT may be kept in a secure cookie or local storage; on mobile (Capacitor), tokens are stored in the device's secure storage.
- In the cloud (optional): When signed in, backups are sent over HTTPS to our infrastructure on Microsoft Azure (Cosmos DB for data storage and Azure Communication Services for sending OTP emails). Azure provides encryption at rest by default.
Health and fitness data (Apple Health and Health Connect)
On mobile, the App can read health and fitness data that other apps and devices — a watch, a ring, a phone's step counter — have already recorded, so you don't have to log it twice. This is entirely optional: nothing is read until you grant permission, and the App never writes anything back to Apple Health or Health Connect.
What we read
We request read‑only access to exactly these five categories, and no others:
- Steps – shown as your daily step count on the day log and in statistics.
- Sleep – shown as last night's sleep (duration, stages and timing where your tracker provides them).
- Exercise sessions / workouts – offered to you for import as activity entries, so a run your watch recorded appears in your log.
- Active calories burned – used to fill in the energy figure of an imported workout.
- Distance – used to fill in the distance of an imported workout.
How it is stored
Daily step and sleep values are cached on your device (IndexedDB) so the App can show history without re‑querying. Workouts are only stored when you accept the import prompt, at which point they become an ordinary activity entry in your log.
If you are signed in, this data is included in the same cloud sync as the rest of your logs — transmitted over HTTPS and stored in our Azure Cosmos DB database, which is encrypted at rest — so your history survives losing or changing your device. If you never sign in, health data never leaves your device.
How it is not used
We use health and fitness data solely to provide the features described above, to you. Specifically, we do not sell it, do not share it with third parties, do not use it for advertising or marketing, do not use it to train machine‑learning models, and do not transfer it to data brokers or use it to determine credit, insurance or employment eligibility. It is not sent to any AI provider.
Revoking access and deletion
You can withdraw permission at any time — on Android in the Health Connect app under App permissions, and on iOS in Settings → Privacy & Security → Health → Liftstuff. Revoking stops all further reads immediately. Entries already imported into your log stay there until you delete them, which you can do individually in the App, by clearing local data, or by deleting your account. To have cloud‑stored health data removed, contact privacy@liftstuff.com.
Third‑party services we use
- Microsoft Azure Cosmos DB – stores user accounts and your optional backups.
- Microsoft Azure Communication Services – sends OTP emails to your address.
- RevenueCat (purchases‑capacitor) – manages in‑app purchases and subscriptions via the Apple App Store and Google Play. We do not receive your full payment details.
Subscriptions and payments
Purchases are processed by the Apple App Store or Google Play. RevenueCat helps manage entitlements. We do not store your card numbers. The stores may provide us with non‑financial information such as subscription status to enable premium features.
Data retention
OTP codes are hashed and expire within minutes. Account records and cloud backups are retained while your account is active. Your workout history is retained until you delete the specific entries or your account. You can delete your local data from the app at any time. If you want your cloud‑stored data deleted, contact privacy@liftstuff.com and we will remove it.
Security
Data is transmitted over HTTPS. Tokens are stored in secure storage on mobile and may be stored in http‑only cookies in the web app. Azure provides encryption at rest. No system is 100% secure, but we take reasonable steps to protect your information.
Children’s privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child provided us information, contact us to request deletion.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your data. Contact privacy@liftstuff.com to make a request. We may ask you to verify your identity.
Changes to this policy
We may update this policy as our app evolves. We will post updates here and revise the date above. Your continued use of the App after changes take effect constitutes acceptance.