Legal

Privacy Policy

Effective date: 22 May 2026 · Last updated: 10 September 2026 (account sync and provider cleanup)

01 Overview

Local First

LiftLab is a local-first workout tracking app. No account is required, and your workout logs, body metrics, training history, and personal settings stay on your device unless you choose an account-backed service such as Premium cloud backup. XLSX, PDF, and CSV training reports are generated on your device and leave it only when you choose a share or save destination.

02 Who We Are

LiftLab is an independently developed Android and iOS application. For privacy enquiries, contact us at [email protected].

03 Data Stored on Your Device

The following information is stored locally in the app's private storage. It is transmitted to us only if you use a feature described under Data Sent Off Your Device:

Category Examples
Workout logs Exercises, sets, reps, weights, RPE ratings, and session dates
Training setup Training plans and progression settings
Body metrics Weigh-ins, optional notes, circumference measurements, and an optional sex setting used for relative-strength and tape-based body-fat calculations and body-map figures
App preferences Weight unit, language, theme, and timer-alert choices
Update prompts Google Play update prompt cooldown timestamp

When you generate a Premium XLSX, PDF, or CSV training report in the current app, LiftLab first checks that Premium is active. That check contains no report selections, workout or body-metric content, photos, or generated file. LiftLab then creates the report on your device without uploading its content or a cloud snapshot. A temporary copy is created only when you open the system share sheet; LiftLab attempts to remove older temporary reports, and your operating system clears temporary app files according to its normal storage rules. A report leaves the device only when you choose a share or save destination.

If you enable rest-timer notifications on Android 13 or later, LiftLab requests the system notification permission. This permission is used only to show a local alert when a rest timer ends. The optional timer sound uses your device's notification sound and can be enabled separately. Timer alerts do not send notification content, workout data, or any other information off your device.

So that a rest-timer alert arrives on time while LiftLab is in the background, the app also uses the Android alarms and reminders permission (SCHEDULE_EXACT_ALARM) to schedule the alert with the system clock. On Android 14 and later you are asked to grant this access when you turn timer notifications on; if you decline, alerts still arrive but may be delayed. The scheduled alarm holds only the timer's end time and the alert text, stays on your device, and is cancelled when the timer is stopped.

This data is not accessible by other apps. It is cleared when you uninstall the app or clear app data from your device settings.

04 Data Sent Off Your Device

LiftLab sends data off your device only for the purposes described below:

Anonymous install identifier
The first time the app uses an online feature, it creates a random identifier and stores it on your device. This identifier lets LiftLab securely recognize that installation. It is not linked to a person unless that installation is later connected to a LiftLab account. It resets if you reinstall the app.

Play Integrity verification
We use Google Play Integrity to confirm that the app is genuine and unmodified. Google uses device and app information to create a temporary verification result, which LiftLab checks but does not retain. Google's handling of this data is governed by the Google Privacy Policy.

iOS request verification. Where enabled, diagnostic submissions and installation-data deletion use Apple App Attest. Apple processes app and device information to confirm that a request comes from a genuine copy of LiftLab. We retain the verification key and its identifier, the installation identifier, app identity and build, verification environment, request counter and verification times. We also process the request IP address and short-lived, one-use verification challenges to prevent abuse. The private key remains on the device. This verification does not send your workouts, body metrics or photos to Apple and is specific to the action you requested. We do not retain Apple's original verification response or receipt. See the Apple Privacy Policy.

Optional LiftLab account
You can use the core app without an account. If you choose to sign in with Google or Apple, we receive and store the provider name, the provider's unique account identifier, and the email address and display name supplied by that provider. We also store account creation and last-sign-in times and the identifiers needed to manage LiftLab access and keep you signed in. We do not receive or store your Google or Apple password, and we do not retain the provider's temporary sign-in credential after sign-in. For Sign in with Apple, we retain a protected authorization credential solely to revoke the Apple authorization when you delete your account. If an older account has no usable credential, we ask you to sign in with Apple again before deletion begins.

Account e-mail
When a LiftLab account is first created, we send one transactional welcome e-mail to the address supplied by your sign-in provider, confirming that the account exists. It is not marketing, there is no mailing list, and we send no follow-up campaigns, so there is nothing to unsubscribe from. To deliver it, your email address and the message content are passed to our email delivery provider, which acts as our processor and does not use them for its own purposes. If your provider supplies no usable address, the account is created normally and no message is sent. An Apple private relay address can receive this message when relay delivery is configured.

Subscription verification
When you buy or restore LiftLab Premium, Google Play or the Apple App Store handles the payment. LiftLab sends its account identifier to RevenueCat to associate the store purchase with your signed-in LiftLab account. This identifier does not contain your email address or display name. RevenueCat processes store receipt or purchase-token information, product and transaction identifiers, subscription and renewal state, and expiration dates to verify purchases and deliver subscription updates. LiftLab stores the resulting access and verification records, including store, product, state, expiry and verification times; records created by older app versions may also contain a protected purchase token or original transaction identifier. We use this information to verify the purchase, prevent one purchase being linked to multiple LiftLab accounts, grant Premium features, and apply cloud-retention rules. We do not receive or store your payment-card number, bank-account details, or store-account password.

To prevent duplicate purchase attempts after an interruption or reinstall, LiftLab stores an account-linked attempt identifier, product, store, creation and registration times, and recovery status. A definite app-reported no-charge outcome or an administrator-recorded provider confirmation can resolve the matching attempt. For a support resolution, we keep a restricted provider case reference and the resolving administrator identifier; this record is not an automated guarantee from the payment provider. Purchase-attempt records remain while the account exists and are deleted with it. An unresolved attempt is not automatically cleared merely because time passes or Premium is inactive.

Premium cloud synchronization
If you are signed in with Premium, LiftLab synchronizes your exercise and program library, workout and set history, weigh-ins, body measurements and the existing cloud preference whitelist across your signed-in devices. Local changes wait until you are back online. To keep those changes consistent and prevent duplicates, we also store identifiers that connect related records and installations, version and deletion information, and an account reset identifier. Sync runs when the app becomes active, after local changes, when you use the account sync action, and periodically while active. The data is sent securely and is accessible only through your account; it is not end-to-end encrypted. It is not used for advertising or shared with other users. Synced records and deletion information follow the same cloud-retention deadline as recovery snapshots, and are removed by account erase or deletion. Administrator account data exports include synchronized records but exclude sign-in secrets and duplicate-prevention information.

Premium cloud snapshots
If you are signed in with Premium, LiftLab initially uploads, and refreshes when the daily interval is due, one replaceable recovery snapshot for each connected installation. A snapshot can contain your full exercise and program library, complete workout and set history, weigh-ins, body measurements, and whitelisted preferences such as units, theme, training-max formula, dashboard layout, and plate inventory. Premium status, advertising consent, operating-system permission choices, and security credentials are excluded. We also store the snapshot's device identifier and name, platform, app build, size, integrity-check value, and creation/update times. Each snapshot is limited to 25 MiB.

The snapshot is sent securely and stored in a protected format. It is not end-to-end encrypted: LiftLab can read it when needed to validate or restore the backup.

Premium progress photos
Progress photos are an optional Premium feature. A body check-in can hold up to four photos — front, left side, right side and back — for one calendar day. A photo is added only when you deliberately capture one with the camera or choose one from your photo library for a specific pose; LiftLab never scans, indexes, or uploads your photo library. Before a photo leaves the device it is downscaled to at most 1440 pixels on its longest edge and re-encoded as a JPEG of at most 1 MB, so the original full-resolution file is never uploaded and the camera metadata attached to it (including any GPS coordinates the original may carry) is not carried into the stored image.

The photo is sent securely and stored privately against your LiftLab account, on infrastructure located in the European Union. Alongside the image we store the check-in date, the pose, the image dimensions, its size, an integrity-check value, and creation/update times. Photos are private to your account: they are never shown to other users, never used for advertising, and never used to train any model. Access requires your signed-in app. A copy is also kept on your own device so the timeline works offline. Progress photos are deliberately excluded from the local backup file.

You can request deletion of an individual photo at any time, including without an active subscription. LiftLab removes the local photo and schedules its removal from private storage; an offline or failed request is retried. Any leftover private copies are also removed.

Training reports from older app versions
Current app versions generate XLSX, PDF, and CSV reports on your device as described above. An older compatible app version may instead create a report from the account's latest cloud snapshot. For that older process, we temporarily store the request, its status, selected format and sections, times, and generated file for download. We do not create such a report unless you explicitly request one.

Bug reports and suggestions, user-initiated only
If you choose to submit a bug report or suggestion through the in-app form, the following information is sent:

  • Your report or suggestion title and description
  • Contact information you provide, if any
  • App version and build number
  • Device model and Android version
  • Device locale, such as en-GB

Bug reports and suggestions are submitted only when you explicitly tap "Send". This manual flow does not send background telemetry. Diagnostic submission uses a verified installation session on Android and, where enabled and supported, Apple App Attest on iOS. If verification is unavailable, you can contact support by email. Signing in does not bypass these checks. Android reports from an installation linked to an account are associated with that account for deletion. iOS App Attest reports are tied to the device key and are deleted through the installation-data deletion action; signing in alone does not link that separate diagnostic identity to an account.

Crash reports, automatic
If the app crashes, a crash report may be sent automatically on Android when a verified reporting session is available. This report contains:

  • Exception type and message
  • Technical crash call details, limited to 8,000 characters
  • App version and build number
  • Device model and Android version
  • Device locale

Crash reports do not include your workout data or any content you have entered. If the installation is signed in when a crash report is submitted, we associate that report with the LiftLab account for account-deletion purposes. Automatic crash reporting can be turned off at any time under Settings > Legal & privacy > Crash reporting. When it is off, no crash reports are sent.

Google Play in-app updates
Separately, LiftLab uses Google Play's in-app update feature to check whether Google Play has an update available for your installed copy of the app. Google Play may process device metadata, the app version, and installed module or asset-pack information to determine update availability and expected download size. Google's handling of this data is governed by the Google Privacy Policy and Google Play terms.

Program library downloads
When you choose to download a workout program from LiftLab's online program library, LiftLab records an aggregate download count for that program and the time it was most recently downloaded. We do not store a per-install program-download history, and the downloaded workout plan is stored locally on your device.

Advertising in ads-enabled Android and iOS builds
LiftLab may use Google AdMob to show a banner ad in Settings and native ad cards in the Program Library. Google may process advertising or device identifiers, device and app information, approximate location, and ad interaction data to deliver ads, measure performance, and protect against abuse. We do not send your workout logs, training plans, exercise history, or other fitness data to AdMob. Google's handling of advertising data is governed by the Google Privacy Policy.

Where required by law — including the EEA, the United Kingdom, and certain US states such as Texas — the app uses Google's User Messaging Platform to present a consent or privacy-choices message before ads are personalised or, where applicable, before any ad is requested. If you consent, ads may be personalised using advertising identifiers available on Android or iOS; if you do not, ad delivery is limited to non-personalised ads and basic functions such as frequency capping and fraud prevention. Where this applies to your region, you can review or change these choices at any time under Settings > Legal & privacy > Ad privacy.

Before starting advertising consent or requesting ads, LiftLab requires users to select an age group: under 13, 13–17, or 18 and older. We store only this selection and a policy version on the device, not a date of birth. These preferences are not uploaded to LiftLab or included in local backups or cloud snapshots. Google's advertising service receives the corresponding restricted-treatment choice, not your birthday or training data. Users aged 13–17 receive conservative under-age treatment in every region: personalised advertising and remarketing are disabled. Users who do not select an age group, or select under 13, receive no ads. You can change the selection under Settings > Legal & privacy > Age group. Changing a previously eligible group requires completely closing and reopening the app before continuing; the app then refreshes consent for the new group. Age groups do not advance automatically.

Eligible users aged 13–17 can still earn the 90-day chart window through an available restricted rewarded ad. When no eligible ad is available, the free 30-day chart remains available. Selecting under 13 displays the minimum-age message and returns to age selection. Cancelling the selector does not open the app. The same entry requirement applies to free and Premium users.

For users aged 18 and older on iOS, LiftLab also uses Apple's App Tracking Transparency permission before allowing cross-app tracking or access to the advertising identifier. Declining this permission does not prevent you from using LiftLab and does not require you to enable tracking to see ads; it limits tracking and ad personalisation.

05 Data We Do Not Collect

  • Google or Apple passwords, LiftLab passwords, or provider access tokens retained after sign-in (the protected Apple refresh credential used for authorization revocation is described above)
  • Payment-card numbers, bank-account details, or other store payment credentials
  • Precise GPS location; AdMob may infer or process approximate location as described above
  • Microphone data
  • Camera or photo-library content, except a progress photo you deliberately capture or choose for a body check-in as described above; LiftLab never reads your photo library in the background and never uploads a photo you did not add to a check-in
  • Contacts or calendar data
  • Workout logs, body metrics, or training history when you use LiftLab without cloud backup; generating a current in-app report does not send this data to us, and the finished report leaves the device only through a share or save destination you select

06 Third-Party Services

LiftLab uses the following third-party services:

  • Google Play Integrity API is used to verify app authenticity and is governed by the Google Privacy Policy.
  • Google Play in-app updates is used to show Google Play's update prompt when a newer Play Store version is available and is governed by the Google Privacy Policy.
  • Google Sign-In and Sign in with Apple are optional account providers. They authenticate you and supply the account fields described above, subject to the Google Privacy Policy or Apple Privacy Policy.
  • Google Play Billing and the Apple App Store process Premium purchases and send purchase/subscription status for verification, subject to the provider's privacy policy and store terms.
  • Google AdMob may be used in ads-enabled Android and iOS builds to show a Settings banner and Program Library native ad cards, and is governed by the Google Privacy Policy.
  • Email delivery provider — the account-created welcome message is sent through a third-party transactional email provider acting as our processor. It receives your email address and the message content for delivery only, and does not use them for its own purposes.
  • Cloud storage provider — Premium cloud snapshots and progress photos are held by a third-party cloud infrastructure provider acting as our processor, on infrastructure located in the European Union. It processes this data only on our instructions and does not use it for its own purposes.

RevenueCat provides purchase verification, restore and subscription-status processing for Premium, using the account and purchase information described above. See the RevenueCat Privacy Policy.

We do not use analytics services, and we do not share workout logs, body metrics, progress photos, cloud snapshots, or training reports with advertising services.

07 Data Retention

  • Anonymous app data: install identifiers and crash, bug-report, and suggestion data may be retained for up to 12 months. Aggregate program download counts remain with the catalog program until that catalog record is deleted and are not linked to an install or account.
  • App Attest replay protection: the public key, counter and associated security installation record have no automatic expiry, so an old proof cannot become valid again after inactivity. They contain no diagnostic report text. One-use challenges expire after two minutes and are removed by scheduled cleanup after a further hour, preserving the short abuse-control window. Deleting diagnostic reports does not reset this security state.
  • RevenueCat account cleanup: account deletion or administrator anonymization queues removal of the RevenueCat customer when RevenueCat is configured. The existing account identifier is held encrypted in a separate cleanup request until RevenueCat accepts deletion; failed requests are retried. This does not cancel store billing.
  • Apple authorization revocation: the protected refresh credential is retained while the Apple identity is linked. On account deletion or administrator anonymization, a durable revocation request retains that credential separately until Apple confirms revocation; failed requests are retried and the credential is cleared on success.
  • Deletion confirmation: a non-reversible confirmation value and the requesting install identifier are retained for up to 30 days so the app can confirm completion after a lost response. They do not restore the deleted profile or training data.
  • Account data: your profile, linked sign-in identity, and Premium record remain while the LiftLab account exists. Sign-in access normally lasts 20 minutes and can be renewed for up to 30 days; revoked sign-ins are removed within seven days.
  • Cloud snapshots: snapshots are retained while Premium access is active. If Premium ends, uploads stop, but existing snapshots remain available for restore until the paid-through date plus two calendar months. They are then deleted by scheduled cleanup.
  • Progress photos: a photo is kept until you delete it, until you delete your LiftLab account, or until the cloud-retention window ends. If Premium ends, uploads stop and the stored photos follow the same deadline as cloud snapshots — available until the paid-through date plus two calendar months, then deleted by scheduled cleanup whether or not the account created a cloud snapshot.
  • On-device training reports: we do not receive or retain them. The current app creates a temporary report for sharing and attempts to remove older temporary reports; a file still being used by a share destination may remain until a later cleanup or until your operating system clears temporary app files. Copies you save or send are controlled by you and the destination you choose.
  • Training reports from older app versions: a generated report file is available for up to 24 hours after completion and is then removed. Its remaining status information is removed within seven additional days.
  • Store notifications: we keep only the provider and a non-reversible notification identifier for up to 90 days to reject duplicate notifications; the notification content itself is not stored in that record.
  • Short sign-in exchanges: temporary sign-in verification information expires after 10 minutes and a one-time LiftLab sign-in code after 5 minutes; expired records are then removed.

We do not retain Play Integrity verification results. Google Play in-app update data is handled by Google and is not stored by LiftLab.

08 Your Rights

You can use LiftLab without an account and keep your training data only on your device. Cloud backup and progress photos are optional Premium actions, and you can stop future snapshot and photo uploads by signing out or allowing Premium to lapse. Any progress photo can be deleted individually at any time, whether or not your subscription is active, and account deletion includes removal of stored photos and their metadata. Local training reports are generated only when you request one, and you decide whether and where to share or save the result.

If you created a LiftLab account, choose Settings > LiftLab Account > Delete account. This permanently deletes the profile, linked sign-in identities, active sign-ins, Premium and purchase-attempt records, synchronized account records and deletion information, cloud snapshots, progress photos and their private copies, reports from older app versions, and diagnostic reports associated with the account. Provider revocation and the short-lived deletion-confirmation record follow the retention rules above. It does not delete reports you previously saved or shared to another destination. Your workout data stays on each device until you clear app data or uninstall LiftLab. Deleting the LiftLab account does not cancel a Google Play or Apple App Store subscription; cancel it separately in the store that billed you to prevent renewal.

If you no longer have the app, request account deletion at liftlab.smallcatfactory.com/account-deletion.html. The page explains how to submit and verify a request without reinstalling LiftLab.

Settings > Legal & privacy > Delete my server data requests deletion of crash, bug and suggestion reports linked to your verified installation. Android uses its installation signature; iOS uses its App Attest device key where enabled and supported. If verification is unavailable or the device key has been lost, use the email route below. Account-associated reports are included when you delete your LiftLab account; iOS reports under the separate App Attest identity require the installation-data action or a verified support request.

Alternatively, you can email us at [email protected] with your install identifier, visible and copyable in the app under Settings > Legal & privacy > Install ID, and we will delete it promptly.

09 Children

LiftLab requires a self-declared age of at least 13 before normal app access. This is an age-category declaration, not identity or document verification. LiftLab is not directed at children under the age of 13. We do not knowingly collect data from users under 13. If you believe a child under 13 has submitted data to us, contact us and we will delete it.

10 Changes to This Policy

We may update this policy when the app's data practices change. The effective date at the top of this page will reflect the most recent revision. Continued use of the app after a policy update constitutes acceptance of the revised policy.

11 Contact

For any privacy-related questions or requests, email us at [email protected].