Liftgeist Privacy Policy

Version 2.2 · Effective August 23, 2026 · Replaces Version 2.1 of August 22, 2026

Liftgeist is a workout, nutrition and bodyweight tracker. This policy explains exactly what it collects, who receives it, how long it is kept, and how to get rid of it. It covers the website at liftgeist.com, the web app at app.liftgeist.com, the web dashboard at web.liftgeist.com, and the Liftgeist apps for iOS, Android and Apple Watch.

The short version. Your training data is yours. We never sell it and never use it for advertising. You can export all of it as a file at any time, free. You can delete your account from inside the app. Guest mode needs no account and never syncs. The longer version below names every company that receives anything, because a summary is not a disclosure.

1. Who we are

Liftgeist is operated by Luka Jorjoliani, an individual trading as Liftgeist ("we", "us"). We are the data controller for the personal data described here.

Contact: [email protected]. We will provide a postal address on request to anyone exercising a data protection right.

We have not appointed a Data Protection Officer, because we do not meet the criteria in Article 37 of the GDPR. We do not currently have an establishment in the EU or the UK, and we have not appointed representatives there under Article 27. If you are in the EEA or the UK and want to raise something, email us and we will deal with it directly.

If Liftgeist is later operated by a company, the controller named above will change and this policy will be updated with the company name and registered address.

2. What we collect

Account data

Hide My Email. Sign in with Apple can give us a private relay address instead of your real one, and we then hold only the relay address: it identifies your account, and it is what Settings shows you. Nothing in the app needs the address behind it. Three consequences worth knowing: Apple only delivers mail to a relay address from senders it has on file, so if you sign in with Apple and hide your address, use the Apple button to sign in again rather than the email link; if you switch the relay off in your Apple ID settings we have no other address to try; and because we match a request to an account by its address, a relay user should delete in the app or write to us from the relay address.

Training, body and nutrition data you enter

Meal photos

A meal photo takes two paths, and both matter:

Both copies are redrawn in your browser before they leave the device, which strips EXIF metadata including any GPS coordinates.

Technical data

Payment data

If you buy a premium plan on the web dashboard, Stripe handles the payment. Card details never reach Liftgeist. We share your email address and account identifier with Stripe to create the checkout, and store the customer and subscription identifiers Stripe returns, plus your plan and renewal date. At the time of writing the paid tier is not yet live.

3. Why we process it, and our legal basis

WhatWhyLegal basis (UK and EU)
Account and sign-in dataTo create your account, sign you in and sync across devicesPerformance of a contract
Training, body and nutrition dataTo provide the tracker itself: logging, charts, PRs, targetsPerformance of a contract, and explicit consent for health data (section 4)
Meal photo and text sent to AITo estimate calories and macros because you asked for an estimateExplicit consent, given by using the feature
Coach and program builder inputsTo generate the program or answer you requestedExplicit consent, given by using the feature
IP address at the AI endpointsTo stop abuse and enforce a daily limitLegitimate interests: keeping a free service available
Analytics on web surfacesTo see which pages and features get usedConsent where required. See section 7 for the current status, stated honestly
Payment dataTo take payment and grant premiumPerformance of a contract, and legal obligation for tax records
Email about the serviceTo send sign-in links and essential service noticesPerformance of a contract

Providing your data is not a statutory requirement. If you provide none of it, guest mode still works; an account and cloud sync do not.

4. Health data

Bodyweight, waist measurements, meals, calories, macros, readiness answers and pain reports are health data. Under the UK and EU GDPR this is special category data (Article 9), and in Washington, Nevada and Connecticut it is consumer health data under those states' health privacy laws.

We rely on your explicit consent to process it, which you give by entering it. You can withdraw that consent at any time by deleting the data or your account, which stops the processing. Withdrawal does not affect processing that already happened.

Washington and Nevada require a separate document covering this data specifically. It is here: Consumer Health Data Privacy Policy.

5. Who receives your data

Everyone. Not categories, names.

CompanyWhat it receivesRole
SupabaseYour email and account record, and your entire synced ledger, held as one row: workouts, sets, bodyweight, meals, meal photo thumbnails, notes, targets and check-insProcessor (acts on our instructions)
CloudflareHosting and the API. Sees request metadata including IP. Briefly stores your IP for the AI rate limit, and caches AI results as described in section 8Processor
AnthropicWhatever you submit to an AI feature: meal text and photos, program notes, uploaded plans, and for the coach a summary of your bodyweight and trend, PRs, recent sessions, nutrition against targets and recent check-in notesProcessor
StripeYour email and account identifier when you start a purchase, and the payment itselfIndependent controller for payment
Microsoft (Clarity)Analytics and session-replay data from our web surfaces. See section 7, which explains what this means, plainlyIndependent controller, by Microsoft's own terms
Google (Analytics)Analytics from liftgeist.com and web.liftgeist.com only. Not from the web appIndependent controller in practice
Google (Fonts)Your IP address and browser, whenever a web page loads our typeface. The installed apps ship the font inside the app and never request itIndependent controller
jsDelivrYour IP address when exercise demonstration images loadIndependent controller
Open Food FactsThe barcode you scan or the food name you search, plus your IP address. Sent directly from your device, including from the installed appsIndependent controller
Apple, GoogleIf you use their sign-in, the sign-in itself: the provider learns that you are signing in to Liftgeist, sees your IP address and browser as any visited page does, and returns the identity we then hold. Apple's button is in the iOS app and on the dashboard, Google's is on every surface. No training, body or nutrition data goes to either. Their own privacy policies govern that stepIndependent controllers

We do not sell your personal data, and we do not share it with advertisers or data brokers.

6. AI features, in detail

Meal estimates, program building, plan imports, target setting and the in-app coach are powered by Anthropic's Claude models. Your input goes over an encrypted connection to our server on Cloudflare, and from there to Anthropic's API using our key. Requests do not carry your name, email or account identifier.

The coach sends more than the others, so it is worth stating outright: using it transmits a summary of your bodyweight and its trend, your personal records, your recent sessions with actual loads, your nutrition against your targets, and your recent readiness notes. That is health data leaving your device. If you would rather it did not, do not use the coach; every other part of the app works without it.

We do not write your meal text, photos, notes or coach messages to our own logs. Anthropic processes them to produce your result under its commercial API terms, which provide that inputs and outputs submitted through the API are not used to train its models.

AI outputs are not used to make any decision with a legal or similarly significant effect about you. They are suggestions you can edit or ignore, and every estimate is presented as editable before it is saved.

7. Cookies, storage and analytics

On your device

Liftgeist stores your ledger and preferences in your browser's local storage, and on iOS and Android mirrors them into the operating system's app storage so they survive. This is how the app works offline. It is not tracking, and it is not shared.

Analytics, stated plainly

We use two analytics tools on our web surfaces. Neither runs inside the installed iOS or Android apps.

SurfaceMicrosoft ClarityGoogle AnalyticsCloudflare
liftgeist.com (marketing)YesYesNo
app.liftgeist.com (web app)YesNoYes (Cloudflare Web Analytics)
web.liftgeist.com (dashboard)YesYesNo
iOS / Android appsNoNoNo

What Clarity actually does. Microsoft Clarity is a session-replay tool. It records how pages are used, including clicks, scrolling, mouse movement and page changes, and sets cookies (_clck, roughly a year; _clsk, roughly a day) that pseudonymously link your visits. Microsoft states that it acts as a data controller for this data, which means Microsoft may use it for its own purposes under the Microsoft Privacy Statement, not only for ours. We do not send Clarity your name, email or account identifier. Session replay reconstructs the page, though, so on the signed-in surfaces a replay can include training and nutrition figures that were on screen. What a replay captures is governed by settings in Microsoft's own console rather than by anything in our code, so we will not promise you more than our code can prove: if you would rather no replay tool ever saw your numbers, use the installed app, which loads none.

Google Analytics sets its own cookies and reports aggregate usage of the marketing site and the dashboard.

Cloudflare Web Analytics runs on the web app and counts page views without cookies.

Current status, stated honestly rather than aspirationally: Liftgeist does not yet present a cookie consent banner, so these tools currently load without asking first. That is being changed. Until it is, if you are in the EEA, the UK or Switzerland and would prefer no analytics at all, use the installed app, which loads none, or block the domains clarity.ms and google-analytics.com in your browser. We will update this section and the date above when the consent banner ships.

8. How long we keep things

DataKept for
Your ledger: workouts, sets, bodyweight, meals, macros, notes, check-insUntil you delete it or delete your account. It does not age out
Meal photo thumbnailsRemoved once more than 60 days old, applied the next time you log a meal
Account and email addressUntil you delete your account
AI results cached on Cloudflare (the estimate, not the photo)Up to 24 hours, keyed by a hash of the request
IP address at the AI endpoints, for the daily limitUp to about 25 hours
Deletion records, so a deleted item cannot reappear on another deviceAn internal id and a timestamp, no content. Meal and freestyle records are pruned after 180 days; deleted-program records are kept
Billing recordsAs long as tax law requires, typically six to seven years
Analytics data held by Microsoft and GoogleAccording to those products' own retention settings and policies. It is pseudonymous and not linked to your account
Automatic snapshots of your synced row, the safety net against accidental data lossAt most the last 24, each replaced as you keep using the app. Account deletion does not clear them today: see section 12
Encrypted database backupsDeleted data may persist in routine backups for a short period before they rotate out. It is never restored to the service

9. Your rights

Wherever you live, you can ask us to do all of the following, and we will not treat you differently for asking:

Email [email protected]. We answer within 30 days, and within 45 days for US state requests, extendable once where the law allows. We may need to confirm you control the account email before acting.

10. International transfers

We are based in the United States and our providers are largely US-based, so data about EEA and UK users is transferred to the United States. Where a provider offers Standard Contractual Clauses or participates in the EU-US Data Privacy Framework, that is the mechanism relied on, and each provider named in section 5 publishes its own data processing terms.

11. Security

All traffic between the app, our servers and our providers uses HTTPS. Cloud data is protected by database-level access rules so an account can only read its own row; we have verified that an unauthenticated request cannot read any user's data. There is no password to steal, because we do not use passwords.

Two limits worth stating: on iOS and Android your sign-in token is held in the operating system's standard app preference storage rather than the secure keychain, and Android's system backup may copy the app's data to your Google account unless you turn that off. We are addressing both.

No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority as the law requires.

12. Deleting your data

In the app: You tab, gear icon, Settings, Delete account. It asks twice, then deletes immediately.

What that removes: your account, your sign-in identity and your entire synced ledger from our database, along with any billing entitlement record.

What it does not remove: the copy already on the device you are using. That stays until you delete the app (iOS and Android) or clear the site data (web). We say this plainly because the alternative would be untrue.

What it does not clear, today: our database writes automatic snapshots of your synced row so that an accidental loss can be undone, and keeps at most the last 24. Access rules make those snapshots unreadable to the app, which means the app cannot delete them either, and account deletion does not currently reach them. They are never restored to the service and are used for nothing else. Email us and we will remove them by hand. This paragraph goes away once deletion clears them on its own.

Without the app: email [email protected] from your account address and we will delete it for you. A public page describing this is at liftgeist.com/delete-account.

Analytics data held by Microsoft or Google is pseudonymous and not linked to your account, so we cannot single it out for deletion; you can clear those cookies in your browser.

13. Children

Liftgeist is not intended for children. You must be at least 16 to create an account. We do not knowingly collect data from anyone younger, and if we learn that we have, we will delete it. If you believe a child has created an account, email us.

14. Apple Health (iOS and Apple Watch)

If you use the Apple Watch companion, Liftgeist asks for Health permission for Workouts only.

Health data stays on your device and in Apple Health. It is never sent to our servers, to the AI provider, to analytics, or to anyone else, and is never used for advertising or marketing. You can revoke access in iOS Settings, Health, Data Access & Devices.

Note that the rest-complete notification and the Live Activity display the exercise name and set count on your lock screen, which is visible without unlocking. You can turn notifications off in system settings.

15. US state privacy rights

California. We are almost certainly below the thresholds that make the CCPA apply to a business, but we honour its rights anyway. We collect the categories described in section 2: identifiers (email), health and nutrition information (sensitive personal information), internet activity, and commerce information if you purchase. We use sensitive personal information only to provide the service you asked for, never to infer characteristics about you. We do not sell personal information and do not share it for cross-context behavioural advertising. Because our analytics tools may be treated as "sharing" under some readings, you can opt out by declining analytics once our consent banner ships, by blocking those domains, or by using the installed app. We honour Global Privacy Control signals where our tooling supports it. To exercise any right, email us; an authorised agent may act for you with written permission.

Washington, Nevada and Connecticut. Your consumer health data rights, and the disclosures those laws require, are in our separate Consumer Health Data Privacy Policy.

Other states. Where your state gives you rights to access, correct, delete, port or opt out, we honour them through the same contact address, and you may appeal a refusal by replying to our decision.

16. Health and fitness disclaimer

Liftgeist is not a medical device. It does not diagnose, treat, cure or prevent any medical condition. Its numbers, including AI calorie and macro estimates and estimated one-rep-maxes, are approximations for tracking trends, not medical or nutritional advice. Talk to a qualified professional before making health decisions, especially if you have a medical condition or an eating disorder.

17. Changes to this policy

We will update this page and the version and date at the top. For changes that materially affect how your data is handled, we will tell you inside the app before they take effect, and where the law requires it we will ask for your consent again. Previous versions are available on request.

18. Contact

Questions, requests, or anything in this policy that looks wrong: [email protected].

This policy is linked from the app, from the App Store and Google Play listings, and from every Liftgeist website.