Your account and data

LiftLab Privacy Policy

How your information is used, stored and deleted.

Last updated: 26 September 2026

Overview

Local First

LiftLab is a local-first workout tracking app. No account is required, and your workout logs, body metrics, training history, and personal settings stay on your device unless you choose an account-backed service such as Premium cloud backup. Body metrics and progress photos also need your separate permission before they are stored with your account. XLSX, PDF, and CSV training reports are generated on your device and leave it only when you choose a share or save destination.

Who We Are

LiftLab is developed and operated by Borna Hilc, an individual based in Croatia, using the developer brand Small Cat Factory. Small Cat Factory is a brand name, not a separate company. For privacy enquiries, contact us at [email protected].

Data Stored on Your Device

The following information is stored locally in the app's private storage. It is transmitted to us only if you use a feature described under Data Sent Off Your Device:

Category Examples
Workout logs Exercises, sets, reps, weights, RPE ratings, and session dates
Training setup Training plans and progression settings
Body metrics Weigh-ins, optional notes, circumference measurements, and an optional sex setting used for relative-strength and tape-based body-fat calculations and body-map figures
App preferences Weight unit, language, theme, and timer-alert choices
Update prompts Google Play update prompt cooldown timestamp

When you generate a Premium XLSX, PDF, or CSV training report in the current app, LiftLab first checks that Premium is active. That check contains no report selections, workout or body-metric content, photos, or generated file. LiftLab then creates the report on your device without uploading its content or a cloud snapshot. A temporary copy is created only when you open the system share sheet; LiftLab attempts to remove older temporary reports, and your operating system clears temporary app files according to its normal storage rules. A report leaves the device only when you choose a share or save destination.

If you enable rest-timer notifications on Android 13 or later, LiftLab requests the system notification permission. This permission is used only to show a local alert when a rest timer ends. The optional timer sound uses your device's notification sound and can be enabled separately. Timer alerts do not send notification content, workout data, or any other information off your device.

So that a rest-timer alert arrives on time while LiftLab is in the background, the app also uses the Android alarms and reminders permission (SCHEDULE_EXACT_ALARM) to schedule the alert with the system clock. On Android 14 and later you are asked to grant this access when you turn timer notifications on; if you decline, alerts still arrive but may be delayed. The scheduled alarm holds only the timer's end time and the alert text, stays on your device, and is cancelled when the timer is stopped.

This data is not accessible by other apps. It is cleared when you uninstall the app or clear app data from your device settings.

Data Sent Off Your Device

LiftLab sends data off your device only for the purposes described below:

Anonymous install identifier
The first time the app uses an online feature, it creates a random identifier and stores it on your device. This identifier lets LiftLab securely recognize that installation. It is not linked to a person unless that installation is later connected to a LiftLab account. It resets if you reinstall the app.

Play Integrity verification
We use Google Play Integrity to confirm that the app is genuine and unmodified. Google uses device and app information to create a temporary verification result, which LiftLab checks but does not retain. Google's handling of this data is governed by the Google Privacy Policy.

iOS request verification. Where enabled, diagnostic submissions and installation-data deletion use Apple App Attest. Apple processes app and device information to confirm that a request comes from a genuine copy of LiftLab. We retain the verification key and its identifier, the installation identifier, app identity and build, verification environment, request counter and verification times. We also process the request IP address and short-lived, one-use verification challenges to prevent abuse. The private key remains on the device. This verification does not send your workouts, body metrics or photos to Apple and is specific to the action you requested. We do not retain Apple's original verification response or receipt. See the Apple Privacy Policy.

Optional LiftLab account
You can use the core app without an account. If you choose to sign in with Google or Apple, we receive and store the provider name, the provider's unique account identifier, and the email address and display name supplied by that provider. We also store account creation and last-sign-in times and the identifiers needed to manage LiftLab access and keep you signed in. We do not receive or store your Google or Apple password, and we do not retain the provider's temporary sign-in credential after sign-in. For Sign in with Apple, we retain a protected authorization credential solely to revoke the Apple authorization when you delete your account. If an older account has no usable credential, we ask you to sign in with Apple again before deletion begins.

Account e-mail
When a LiftLab account is first created, we send a transactional welcome e-mail to the address supplied by your sign-in provider, confirming that the account exists. We also send transactional messages when Premium starts or ends. These messages concern your account and subscription; they are not a marketing mailing list. To deliver it, your email address and the message content are passed to our email delivery provider, which acts as our processor and does not use them for its own purposes. If your provider supplies no usable address, the account is created normally and no message is sent. An Apple private relay address can receive this message when relay delivery is configured.

Subscription verification
When you buy or restore LiftLab Premium, Google Play or the Apple App Store handles the payment. LiftLab sends its account identifier to RevenueCat to associate the store purchase with your signed-in LiftLab account. The identifier itself does not contain your email address or display name, so LiftLab also sends the email address supplied by your sign-in provider to RevenueCat and stores which address was last sent. This is so a purchase or refund enquiry that names an address can be matched to the right subscription; it is not used to contact you, and RevenueCat does not send you email on our behalf. RevenueCat processes store receipt or purchase-token information, product and transaction identifiers, subscription and renewal state, and expiration dates to verify purchases, deliver subscription updates and provide subscription analytics. LiftLab stores the resulting access and verification records, including store, product, state, expiry and verification times; records created by older app versions may also contain a protected purchase token or original transaction identifier. We use this information to verify the purchase, prevent one purchase being linked to multiple LiftLab accounts, grant Premium features, and apply cloud-retention rules. We do not receive or store your payment-card number, bank-account details, or store-account password.

To prevent duplicate purchase attempts after an interruption or reinstall, LiftLab stores an account-linked attempt identifier, product, store, creation and registration times, and recovery status. A definite app-reported no-charge outcome or an administrator-recorded provider confirmation can resolve the matching attempt. For a support resolution, we keep a restricted provider case reference and the resolving administrator identifier; this record is not an automated guarantee from the payment provider. Purchase-attempt records remain while the account exists and are deleted with it. An unresolved attempt is not automatically cleared merely because time passes or Premium is inactive.

Premium cloud synchronization
If you are signed in with Premium, LiftLab synchronizes your exercise and program library, workout and set history and the existing cloud preference whitelist across your signed-in devices, and — only if you allow body data sync, described below — your weigh-ins, body measurements and recorded body-fat estimate. Local changes wait until you are back online. To keep those changes consistent and prevent duplicates, we also store identifiers that connect related records and installations, version and deletion information, and an account reset identifier. Sync runs when the app becomes active, after local changes, when you use the account sync action, and periodically while active. The data is sent securely and is accessible only through your account; it is not end-to-end encrypted. It is not used for advertising or shared with other users. Synced records and deletion information follow the same cloud-retention deadline as recovery snapshots, and are removed by account erase or deletion. Administrator account data exports include synchronized records but exclude sign-in secrets and duplicate-prevention information.

Premium cloud snapshots
If you are signed in with Premium, LiftLab initially uploads, and refreshes when the daily interval is due, one replaceable recovery snapshot for each connected installation. A snapshot can contain your full exercise and program library, complete workout and set history, and whitelisted preferences such as units, theme, training-max formula, dashboard layout, and plate inventory, plus — only if you allow body data sync — your weigh-ins, body measurements and recorded body-fat estimate. Premium status, advertising consent, operating-system permission choices, and security credentials are excluded. We also store the snapshot's device identifier and name, platform, app build, size, integrity-check value, and creation/update times. Each snapshot is limited to 25 MiB.

The snapshot is sent securely and encrypted where it is stored. It is not end-to-end encrypted: LiftLab can read it when needed to validate or restore the backup.

Backup files you save yourself
The backup file LiftLab writes to a location you choose is compressed and carries a check that detects any change to it, but it is not encrypted and is not protected by a password. Anyone who obtains the file can recover the training data it holds. Keep it somewhere you trust, and remember that where you save it is outside LiftLab's control. The file never includes progress photos, weigh-ins or body measurements.

Premium progress photos
Progress photos are an optional Premium feature. A body check-in can hold up to four photos — front, left side, right side and back — for one calendar day. A photo is added only when you deliberately capture one with the camera or choose one from your photo library for a specific pose; LiftLab never scans, indexes, or uploads your photo library. Before a photo leaves the device it is downscaled to at most 1440 pixels on its longest edge and re-encoded as a JPEG of at most 1 MB, so the original full-resolution file is never uploaded and the camera metadata attached to it (including any GPS coordinates the original may carry) is not carried into the stored image.

If you allow body data sync, the photo is sent securely and stored privately against your LiftLab account, on infrastructure located in the European Union. If you do not, it stays on your device only. Alongside the image we store the check-in date, the pose, the image dimensions, its size, an integrity-check value, and creation/update times. Photos are private to your account: they are never shown to other users, never used for advertising, and never used to train any model. Access requires your signed-in app. A copy is also kept on your own device so the timeline works offline. Progress photos are deliberately excluded from the local backup file.

You can request deletion of an individual photo at any time, including without an active subscription. LiftLab removes the local photo and schedules its removal from private storage; an offline or failed request is retried. Any leftover private copies are also removed.

Body data sync — your choice
Weigh-ins, body measurements, your recorded body-fat estimate and progress photos can reveal information about your health. LiftLab stores them with your account only if you allow it, and for one purpose: to back them up and show them on your other signed-in devices. This choice is separate from signing in, buying Premium and accepting the Terms of Use, and our legal basis for storing this data is your explicit consent. The first time you open a body screen while signed in with Premium, LiftLab asks once. Until you choose, this data stays on your device; dismissing the question uploads nothing. We record each choice with the version of the explanation you were shown, when you chose and the installation you chose on, so that we can show what you agreed to.

You can change your choice at any time under Settings > LiftLab Account > Body data sync, or from the status line at the top of any body screen. If you keep this data on your device or stop syncing it, LiftLab first copies to that device any progress photos held only in your account. From that moment the account's copy is locked: nothing more is uploaded, none of it is sent to any of your devices, and it is removed from cloud snapshots straight away. The rest of the account's copy of your weigh-ins, body measurements, body-fat estimate and progress photos is deleted within three days. If you allow body data sync again before then, the kept copy is used again rather than being uploaded a second time. The copies on your devices are not deleted. Withdrawing consent does not affect processing that took place before you withdrew it. Local tracking, on-device reports and your other Premium features keep working without body data sync.

Accounts created before this choice was introduced have not chosen yet. Nothing new is uploaded for them until they choose; body data they already stored remains available to their signed-in devices until then, and choosing to keep it on the device deletes it from the account within three days.

Training reports from older app versions
Current app versions generate XLSX, PDF, and CSV reports on your device as described above. An older compatible app version may instead create a report from the account's latest cloud snapshot. For that older process, we temporarily store the request, its status, selected format and sections, times, and generated file for download. We do not create such a report unless you explicitly request one.

Bug reports and suggestions, user-initiated only
If you choose to submit a bug report or suggestion through the in-app form, the following information is sent:

Bug reports and suggestions are submitted only when you explicitly tap "Send". This manual flow does not send background telemetry. Diagnostic submission uses a verified installation session on Android and, where enabled and supported, Apple App Attest on iOS. If verification is unavailable, you can contact support by email. Signing in does not bypass these checks. Android reports from an installation linked to an account are associated with that account for deletion. iOS App Attest reports are tied to the device key and are deleted through the installation-data deletion action; signing in alone does not link that separate diagnostic identity to an account.

Crash reports, automatic
If the app crashes, a crash report may be sent automatically on Android or iOS when a verified reporting session is available. This report contains:

Crash reports do not attach your workout history or a copy of your training data. Error messages can contain information involved in the failure. Android reports are associated with the account when the reporting installation is linked to it. On iOS, diagnostic reports use a separate device identity and require the installation-data deletion action described below. Automatic crash reporting can be turned off at any time under Settings > Legal & privacy > Crash reporting. When it is off, LiftLab does not send automatic crash reports. This switch does not control diagnostics collected separately by advertising or purchase providers.

Google Play in-app updates
Separately, LiftLab uses Google Play's in-app update feature to check whether Google Play has an update available for your installed copy of the app. Google Play may process device metadata, the app version, and installed module or asset-pack information to determine update availability and expected download size. Google's handling of this data is governed by the Google Privacy Policy and Google Play terms.

Program library downloads
When you choose to download a workout program from LiftLab's online program library, LiftLab records an aggregate download count for that program and the time it was most recently downloaded. We do not store a per-install program-download history, and the downloaded workout plan is stored locally on your device.

Advertising in ads-enabled Android and iOS builds
LiftLab may use Google AdMob to show banner ads on Settings, Profile, Measurements, Bodyweight, DOTS and Strength Standards screens, native ad cards in the Program Library, and optional rewarded ads for longer chart views. Google may process advertising or device identifiers, device and app information, approximate location, and ad interaction data to deliver ads, measure performance, and protect against abuse. We do not send your workout logs, training plans, exercise history, or other fitness data to AdMob. Google's handling of advertising data is governed by the Google Privacy Policy.

Where required by law — including the EEA, the United Kingdom, and certain US states such as Texas — the app uses Google's User Messaging Platform to present a consent or privacy-choices message before ads are personalised or, where applicable, before any ad is requested. If you consent, ads may be personalised using advertising identifiers available on Android or iOS; if you do not, ad delivery is limited to non-personalised ads and basic functions such as frequency capping and fraud prevention. Where this applies to your region, you can review or change these choices at any time under Settings > Legal & privacy > Ad privacy.

Before starting advertising consent or requesting ads, LiftLab requires users to select an age group: under 13, 13–17, or 18 and older. We store only this selection and a policy version on the device, not a date of birth. These preferences are not uploaded to LiftLab or included in local backups or cloud snapshots. Google's advertising service receives the corresponding restricted-treatment choice, not your birthday or training data. Users aged 13–17 receive conservative under-age treatment in every region: personalised advertising and remarketing are disabled. Users who do not select an age group, or select under 13, receive no ads. You can change the selection under Settings > Legal & privacy > Age group. Changing a previously eligible group requires completely closing and reopening the app before continuing; the app then refreshes consent for the new group. Age groups do not advance automatically.

Eligible users aged 13–17 can still earn the 90-day chart window through an available restricted rewarded ad. When no eligible ad is available, the free 30-day chart remains available. Selecting under 13 displays the minimum-age message and returns to age selection. Cancelling the selector does not open the app. The same entry requirement applies to free and Premium users.

For users aged 18 and older on iOS, LiftLab also uses Apple's App Tracking Transparency permission before allowing cross-app tracking or access to the advertising identifier. Declining this permission does not prevent you from using LiftLab and does not require you to enable tracking to see ads; it limits tracking and ad personalisation.

Data We Do Not Collect

Third-Party Services

LiftLab uses the following third-party services:

RevenueCat provides purchase verification, restore, subscription analytics and subscription-status processing for Premium, using the account and purchase information described above, including your email address. See the RevenueCat Privacy Policy.

We do not run a separate LiftLab usage analytics service. RevenueCat processes subscription analytics, and Google AdMob measures ad interactions and performance as described above. We do not share workout logs, body metrics, progress photos, cloud snapshots, or training reports with advertising services.

Where Your Data Is Processed

LiftLab's own servers, which hold your account, synchronized records and cloud snapshots, are located in Finland, in the European Union. Progress-photo files are stored in the European Union by our cloud storage provider.

Some of the providers that act on our behalf are based in, or process data in, the United States: RevenueCat, our email delivery provider and our cloud storage provider. Storing a file in the European Union does not mean that every provider handles data only there. Each of these providers processes data for us under a data processing agreement, and any transfer outside the European Economic Area is protected by the European Commission's standard contractual clauses or, where the provider is certified under it, the EU–U.S. Data Privacy Framework.

Google and Apple handle the data involved in sign-in, app verification, store purchases, app updates and, for Google, advertising under their own privacy policies, and they apply their own safeguards when they transfer it.

To ask which safeguard applies to your data or to obtain a copy of it, email [email protected].

Data Retention

We do not retain Play Integrity verification results. Google Play in-app update data is handled by Google and is not stored by LiftLab.

Your Rights

Where data protection law applies, you can ask to access or correct the personal data we hold about you. You may also ask us to erase data, restrict its use, or provide a portable copy where those rights apply. You may object to processing based on legitimate interests and withdraw consent for processing based on consent; withdrawing consent does not affect processing that was lawful before withdrawal. To make a request, email [email protected]. We may need to verify that the request concerns your data. You also have the right to complain to a data protection supervisory authority, including the Croatian Personal Data Protection Agency.

You can use LiftLab without an account and keep your training data only on your device. Cloud backup and progress photos are optional Premium actions, and you can stop future snapshot and photo uploads by signing out or allowing Premium to lapse. Weigh-ins, body measurements, body-fat estimates and progress photos reach your account only if you allow body data sync, and you can withdraw that permission — which deletes the account's copy within three days — at any time under Settings > LiftLab Account > Body data sync. Any progress photo can be deleted individually at any time, whether or not your subscription is active, and account deletion includes removal of stored photos and their metadata. Local training reports are generated only when you request one, and you decide whether and where to share or save the result.

If you created a LiftLab account, choose Settings > LiftLab Account > Delete account. This permanently deletes the profile, linked sign-in identities, active sign-ins, Premium and purchase-attempt records, synchronized account records and deletion information, cloud snapshots, progress photos and their private copies, reports from older app versions, and diagnostic reports associated with the account. Provider revocation and the short-lived deletion-confirmation record follow the retention rules above. It does not delete reports you previously saved or shared to another destination. Your workout data stays on each device until you clear app data or uninstall LiftLab. Deleting the LiftLab account does not cancel a Google Play or Apple App Store subscription; cancel it separately in the store that billed you to prevent renewal.

If you no longer have the app, request account deletion at liftlab.smallcatfactory.com/account-deletion.html. The page explains how to submit and verify a request without reinstalling LiftLab.

Settings > Legal & privacy > Delete my server data requests deletion of crash, bug and suggestion reports linked to your verified installation. Android uses its installation signature; iOS uses its App Attest device key where enabled and supported. If verification is unavailable or the device key has been lost, use the email route below. Account-associated reports are included when you delete your LiftLab account; iOS reports under the separate App Attest identity require the installation-data action or a verified support request.

Alternatively, you can email us at [email protected] with your install identifier, visible and copyable in the app under Settings > Legal & privacy > Install ID, and we will delete it promptly.

Children

LiftLab requires a self-declared age of at least 13 before normal app access. This is an age-category declaration, not identity or document verification. LiftLab is not directed at children under the age of 13. We do not knowingly collect data from users under 13. If you believe a child under 13 has submitted data to us, contact us and we will delete it.

Changes to This Policy

We may update this policy when the app's data practices change. The effective date at the top of this page will reflect the most recent revision. An update never extends a consent you have given: if a change affects processing that relies on your consent, we will ask you again.

Contact

For any privacy-related questions or requests, email us at [email protected].