LiftStyle Train anywhere.
Back to home

Privacy Policy

Last updated: August 4, 2026.

The key choices

LiftStyle does not require an account to get started. Your calendar, plans, and progress stay saved on the device; how the plan is calculated differs between the web and native apps.

  • On the web, the planner runs in the browser and its payload is not sent to the LiftStyle API.
  • In the Android and iOS apps, calculation uses LiftStyle servers. In versions that show the dedicated privacy control, authorization is separate and revocable; in earlier versions, data is submitted when you start a planner feature.
  • The native request may include the planner calendar, activities, exercises, level, the selected gender profile (man/woman), and priorities. It does not automatically add an email address or account ID, but any custom names are free-form text and are transmitted.
  • Local use without an account is the default. Account and cloud sync are optional and are enabled only when you choose and authorize them separately. Remote statistics and the automated newsletter remain disabled.
Read the full text

Controller and contacts

Data controller: Francesco Abbadini.

Privacy and support contacts: hello@liftstyle.app.

Data processed

  • data saved in the app: workout profile, places, equipment, calendar, plans, preferences, and progress;
  • in native apps, data needed by the online planner: dates and activity types, custom place or sport names, target exercise count, including when derived on-device from the selected duration, existing exercises, level, the selected gender profile (man/woman), and planner priorities;
  • if you choose an account: email address, password handled by Supabase as a protected sign-in credential, user and session identifiers, confirmation or recovery tokens and, if you use Google, name and profile-picture URL received from the provider;
  • if you authorize cloud syncing: training profile, places and equipment, calendar, plans, completed exercises, preferences, goals, sports, muscle focus, exclusions, language, timer preferences, planner data, and technical synchronization metadata, including the date and version of the authorization recorded on this device;
  • IP address, approximate location inferred from the IP address, timestamp, user agent, API path, outcome, duration, and request identifiers processed by the infrastructure for operation, diagnostics, and security.

The payload used only to calculate the plan does not automatically add an email address, account identifier, date of birth, or advertising data. If you choose an account, your email address, password handled by Supabase as a protected sign-in credential, identifiers and, with Google, name and profile-picture URL are linked to the account. The password is not included in synchronized training data. Training data is linked to the account only if you authorize syncing. Custom names are free-text fields: do not enter people’s names, email addresses, diagnoses, injuries, or other unnecessary personal or health data. LiftStyle does not ask for medical records, diagnoses, or certificates.

Account and cloud sync are optional. Consent for the online planner and enabling synchronization are separate choices: enabling one does not enable the other. Remote statistics and the automated newsletter are not active. The public frontend does not use Google Analytics, Meta Pixel, or advertising tracking.

Native versions and planner submissions

When you ask to generate, regenerate, substitute, or analyze a plan in the native app, the app sends the data described in this notice to the LiftStyle API. In versions that include the dedicated privacy control, before the first submission the transmitted categories are displayed, authorization is recorded separately, and it can be withdrawn in settings. If the control is not shown, data is submitted when you confirm the planner feature: to avoid new submissions, do not start these features and continue using plans already saved.

Purposes and legal bases

  • local features: saving and displaying the calendar, plans, preferences, and progress on the device;
  • native planner: creating, updating, or analyzing the requested plan through the online service;
  • optional account and cloud: create and manage the account, authenticate access, sync the selected data, and complete a requested deletion;
  • security and abuse prevention: protecting the service, users, and infrastructure;
  • support and legal requests: responding to the request and complying with applicable obligations.

When you ask to generate, update, or analyze a plan in the native app, the ordinary personal data listed above is processed because it is necessary to perform the requested online feature, under Article 6(1)(b) GDPR. In versions that include the dedicated privacy control, if your choices may reveal health data, explicit consent under Article 9(2)(a) is also requested before submission. If the control is not shown, avoid new requests to the remote planner and update the app to the latest available version before using it. If you choose an account, the ordinary data needed is processed to create and manage the account. Only if you authorize syncing is the other data processed to provide the requested synchronization; for possible health inferences, we ask for a separate, explicit choice. Technical metadata strictly necessary for security may be processed on the basis of the legitimate interest in protecting users and the service, Article 6(1)(f), subject to a balancing assessment.

When you voluntarily create or use an account, confirm your address, recover access, sync, or request deletion, the necessary data is processed to fulfill your request under Article 6(1)(b) GDPR; the separate choice covers possible health inferences.

The planner payload is not used for advertising, commercial profiling, diagnosis, or decisions with legal effects.

Where calculation takes place

On the web, the planner runs in the browser: its payload is not sent to the LiftStyle API. Hosting may still process the ordinary technical metadata needed to deliver and protect the page.

In the Android and iOS apps, the planner sends the request to the LiftStyle API over HTTPS. The calendar, plans, and progress stay saved on the device, but plan calculation is not entirely local.

Providers, recipients, and transfers

Vercel provides hosting, distribution, API execution, and security. In the native apps, it therefore processes the payload to perform the calculation, together with the IP address, approximate location inferred from the IP address, and technical request metadata such as API path, outcome, and duration. The planner function is configured in Vercel's fra1 region in Frankfurt, Germany.

Vercel Inc. is based in the United States and uses subprocessors outside the European Economic Area as well. Vercel is certified under the EU-U.S. Data Privacy Framework and states that it uses standard contractual clauses or other mechanisms provided by law for international transfers where necessary.

Supabase handles creation, sign-in, confirmation, recovery, synchronization, and deletion of optional accounts. The LiftStyle project is configured in Supabase’s eu-west-3 region in Paris. If you choose Google, Google also sends Supabase the name and profile-picture URL associated with your account; Supabase stores them as account metadata, and LiftStyle does not use them to personalize workouts. For email sign-in, Supabase handles the password as a protected sign-in credential and does not include it in synchronized training data. If you choose Apple, Apple handles authentication under its own privacy notice. Supabase and its subprocessors may also process data outside the European Economic Area under the transfer safeguards set out in the applicable data processing agreement.

Zoho Mail handles messages sent to hello@liftstyle.app and processes the email address, content, and any attachments so that we can respond. The mailbox uses Zoho's European infrastructure; support and subprocessors may involve transfers under the safeguards described by Zoho.

Cookies and technical logs

For local storage, sessions, and technical cookies used in account flows, see the Cookie Policy. We do not use marketing cookies or advertising tracking.

Retention

Local data stays until you delete it or reset the app.

The native request is processed to return the result, and LiftStyle does not intentionally store the request or result in an application database. Vercel's technical runtime logs are retained for one hour and do not intentionally contain the request body. Support messages remain in the mailbox for the time needed to respond, handle any complaints, and protect rights, then are deleted according to Zoho's technical windows and applicable obligations.

Synced data remains in Supabase until the account is deleted, subject to technical retention periods for sessions, authentication logs, backups, security, and applicable obligations.

Choices and rights

You can use LiftStyle without an account. You may decline or withdraw authorization for the online planner under Settings > Privacy and security. You can pause synchronization under Settings > Account and sync while keeping your account and local data: new transfers from this device stop, but the copy already synchronized remains in the cloud and other devices continue according to their own setting. To withdraw cloud processing and delete the account and synchronized data, use Delete cloud account in the app or the deletion page. These choices do not enable statistics or newsletters.

You may request access, rectification, erasure, restriction, objection, and portability within the applicable limits by writing to hello@liftstyle.app. Because the planner does not require an account, we may ask you for the minimum technical information needed to locate a request in the logs. For the account, you can use password recovery, in-app deletion, and the deletion page. You can also lodge a complaint with the Italian Data Protection Authority or the competent authority in your country.

Minors

LiftStyle is not intended for minors and does not collect dates of birth. If you believe data from a minor has been received, contact hello@liftstyle.app immediately.

Updates

This page is updated when data, purposes, providers, or applicable rules change. Material changes are brought to your attention and may require a new confirmation.