Summary
- Liftr does not sell your personal information.
- Liftr does not use third-party advertising or cross-app tracking.
- Your workout history, routines, profile details, nutrition entries, preferences, and app settings are stored locally on your device. In the current version of Liftr, this data is not synced to iCloud.
- If you choose to join the leaderboard, your display name and selected training stats are shared to a community leaderboard visible to other Liftr users.
- HealthKit access is optional and controlled by Apple Health permissions on your device.
- Apple Watch workout delivery and completion sync happen between your paired Apple devices.
- If you use AI food photo scanning, your photo is sent over HTTPS to Liftr's server and forwarded to Anthropic to estimate the meal's nutrition; the photo itself is not stored by Liftr's server.
Legal Entity, Data Controller, and DPO Contact
Liftr is developed and operated by Handyy Pte. Ltd., a company registered in Singapore, of 13 Lorong 8 Toa Payoh, #06-04 Braddell Tech, Singapore 319261, which acts as the data controller (or equivalent role under your local law) for the personal information described in this policy.
Liftr does not currently have a dedicated Data Protection Officer. For any data-protection question, access/deletion request, or complaint — including requests you would otherwise direct to a DPO under GDPR, UK GDPR, or a similar law — contact: [email protected]. If a DPO is appointed in the future, their contact details will be published here.
Data We Handle
Liftr may handle the following information when you choose to enter it or grant access:
- Workout and routine data: exercises, sets, reps, weights, rest timers, workout notes, personal records, goals, badges, Hyrox-style sessions, and training history.
- Profile and preference data: display name, age, body weight, unit preferences, selected gym, saved settings, and app customization choices.
- Nutrition and food data: food search terms, scanned barcodes, meal entries, calories, macros, and related nutrition values you log in the app.
- Photos and camera input: images you choose for profile, workout, or barcode scanning features.
- Location-related data: approximate or precise location only if you allow Liftr to help search for nearby gyms or places.
- Account or purchase data: if sign-in or subscriptions are enabled, Liftr may process Apple account identifiers, email or display name provided by Apple, and purchase entitlement status.
How We Use Data
Liftr uses data to provide core app features: building routines, running live workouts, calculating progress, syncing selected workout state to Apple Watch, showing nutrition totals, supporting app preferences, and responding to support requests.
We do not use your personal data for third-party advertising, and we do not sell or rent your personal data.
Apple Health and HealthKit
Apple Health integration is optional. If you grant permission, Liftr may read or write workout-related HealthKit data such as workouts, heart rate, active energy, body mass, and activity information needed for training features.
HealthKit data is used only for health and fitness functionality inside Liftr. Liftr does not use HealthKit data for advertising, does not sell HealthKit data, and does not share HealthKit data with data brokers.
You can change Health permissions at any time in the Apple Health app or iOS Settings.
Apple Watch Sync
Liftr uses Apple Watch connectivity to send routines, live workout state, timers, and workout completion details between your paired iPhone and Apple Watch. This device-to-device sync is used to run workouts across the phone and watch surfaces.
Local Storage (No iCloud Sync)
Your workout history, routines, profile, nutrition entries, and preferences are stored locally on your device. In the current version of Liftr, this data is not synced to iCloud — it stays on the device you're using and is not automatically available on your other Apple devices.
Because this data is not synced anywhere, uninstalling Liftr or erasing your device removes it permanently unless you've exported it yourself (for example, via the app's CSV export feature, where available). A future version of Liftr may add optional iCloud sync; if we do, this policy will be updated first and the feature will be clearly presented in the app.
Food Photo Analysis
Liftr's optional AI food photo feature lets you take or choose a photo of a meal and get an estimated nutrition breakdown. When you use this feature, the photo is sent over HTTPS to Liftr's server (hosted on Cloudflare), which forwards it to Anthropic so its Claude model can analyze the photo and produce the estimate. Anthropic processes the photo in the United States — see International Transfers below. The photo is processed by Anthropic solely to produce the nutrition estimate.
Liftr's server does not store the photo — it is held only for the moment needed to relay it to Anthropic and return the result, then discarded. Because the photo is not retained, there is no server-side copy for us to delete on request. The nutrition estimate produced from the photo (dish name, ingredients, calories, and macros) is saved only on your device, the same way as any other food entry you log.
This feature requires your in-app consent the first time you use it, and device-level requests are subject to daily quota limits to prevent abuse. You can decline consent and continue using every other part of Liftr, including manual and barcode food logging.
International Transfers
Liftr's core workout, routine, profile, and nutrition data stays on your device and is not transferred anywhere by us. The one feature that does transfer personal data internationally is the AI food photo feature: when you use it, your photo is transmitted from your device, through Liftr's Cloudflare-hosted server, to Anthropic, which processes it in the United States. If you are located outside the United States (for example, in the EEA, UK, or Singapore), this means your photo is processed in a country whose data-protection laws may differ from your own.
We rely on Anthropic's own safeguards for cross-border processing (including its standard contractual commitments to customers) and on the facts that: the photo is not linked to an account or persistent identifier, is not stored by Liftr's server, and is used by Anthropic solely to generate the nutrition estimate returned to the app. If you do not want your photo processed in the United States, do not use the AI food-scan feature — manual and barcode food logging do not transmit a photo anywhere.
Community Leaderboard
Liftr includes an optional community leaderboard. If you open and participate in the leaderboard, your chosen display name and selected training statistics are published to a shared CloudKit database so they can be ranked alongside and shown to other Liftr users. Do not use a display name you do not want others to see.
Participation is optional, and the information shared is limited to your display name and the stats used for ranking. It does not include your detailed workout history, health data, nutrition entries, location, or contact details. You can avoid sharing to the leaderboard by not using that feature, and you can change your display name in the app.
Device Permissions
Liftr may request access to Apple Health, notifications, camera, photos, and location. Each permission is optional unless a feature depends on it, such as scanning a barcode with the camera or saving workout data to Apple Health.
You can disable permissions at any time in iOS Settings. Some features may stop working when their required permission is disabled.
Third-Party Services
Liftr does not include third-party advertising or analytics. Some features may interact with service providers or public databases when you choose to use them:
- Apple services: App Store, StoreKit, Sign in with Apple, HealthKit, MapKit, notifications, and device frameworks used to operate iOS and Apple Watch features. Liftr does not currently sync app data through iCloud/CloudKit (see Local Storage above).
- Food lookup services: barcode or food search features may query nutrition databases such as Open Food Facts or Singapore Health Promotion Board data sources using the barcode or search term you provide.
- AI food photo analysis: if you use the AI photo feature, your photo is relayed through Liftr's server (Cloudflare) to Anthropic for analysis. See Food Photo Analysis above.
- Purchases: if subscriptions or premium features are enabled, Apple and RevenueCat may process purchase status and entitlement data. Liftr's current free launch does not require a purchase.
Third-party services process information under their own privacy policies and only to the extent needed for the feature you use.
Retention Schedule
The table below states, for each category of data Liftr touches, where it lives and how long it is kept.
| Data category | Where it's stored | Retention period |
|---|---|---|
| Workout/routine data, profile, body metrics, nutrition entries, preferences, badges, HYROX sessions | Locally on your device (SwiftData) | Indefinitely, until you edit/delete it in-app, use in-app Account Deletion, or remove the app |
| HealthKit data written by Liftr | Apple Health, on your device | Until you delete it in the Apple Health app; not controlled by Liftr |
| AI food-scan photo | In transit only, through Liftr's server to Anthropic | Not retained by Liftr's server. Processed by Anthropic only for the duration of generating the response; not used to train Anthropic's models under our agreement with Anthropic's API terms |
| App Attest device record (key id, public key, counter) | Cloudflare KV (server) | Kept while the device is active, to allow the food-scan quota and replay protection to function; not linked to your identity |
| App Attest challenges and daily quota counters (device/IP/global) | Cloudflare KV (server) | Challenges: single-use, expire after 5 minutes. Quota counters: auto-expire after 48 hours |
| Leaderboard display name and stats (if you opt in) | CloudKit public database (only if the leaderboard is enabled — currently disabled for all users) | Until you change your display name, stop participating, or request removal via support |
| Support emails and correspondence | Our email provider | Kept long enough to respond and maintain support records, generally no more than 24 months unless needed longer for legal reasons; deletable on request |
Health data written to Apple Health can be managed through the Apple Health app. If you contact support, we may retain your message and email address long enough to respond and maintain support records. You may request deletion of support correspondence by emailing us (see Your Rights below).
Security
Liftr relies on Apple platform protections, local device storage, and permission prompts to limit access to your data. No method of storage or transmission is perfectly secure, so you should keep your device, Apple ID, and passcode protected.
Children's Privacy
Liftr is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can help remove it where possible.
Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to object to or limit certain processing. Because Liftr is local-first, most app data can be viewed, changed, exported, or deleted directly on your device:
- Access/export: use the app's CSV export feature (where available) or view your data directly in the relevant tab (Workouts, Food, Profile).
- Correction: edit or delete individual entries directly in the app at any time.
- Deletion: use in-app Account Deletion (Profile → Settings → Delete Account) to permanently erase all local app data and sign out of Apple in a single step. Deleting the app does the same.
Data-subject request workflow. For anything the in-app tools above can't do yourself — for example, requesting deletion of support correspondence, asking what data we hold about a specific interaction, or exercising a right under GDPR/UK GDPR/CCPA or a similar law — email [email protected] with a description of your request and enough detail for us to identify the relevant records (e.g. approximate date and nature of a support conversation). We will acknowledge your request within 5 business days and aim to resolve it within 30 days (or notify you if a request is complex enough to need more time, consistent with applicable law). We may ask you to verify your request before acting on it.
For privacy requests related to support emails, account identifiers, or purchase support, contact us at the same address above.
Security Incident Contact
If you believe you have discovered a security vulnerability in Liftr (the app or its backend at joinliftr.app), or you suspect a security incident affecting your data, contact us immediately at [email protected] with as much detail as you can provide (steps to reproduce, affected endpoint, and any relevant logs or screenshots). We will acknowledge reports within 3 business days. If a confirmed incident affects your personal information, we will notify affected users and any relevant regulator without undue delay and consistent with applicable law.
Changes to This Policy
We may update this Privacy Policy when Liftr changes, when legal requirements change, or when new services are added. The effective date above will be updated when the policy changes.
Contact
Questions, privacy requests, and support messages can be sent to [email protected].