Back to home

Privacy Policy

Last updated: August 17, 2026

Overview

LiftLabb ("we", "our", "the app") is operated by Cole Matlock in New South Wales, Australia. This policy explains what we collect, where it is stored, who else touches it, what becomes public, and how to get it back or get rid of it. We do not sell your personal data, and we do not use it for advertising. We don't run any advertising or analytics SDKs — nothing in the app tracks you or reports what you do to an ad network.

What we collect

When you use LiftLabb, we collect information you provide directly:

  • Account information: your email address, display name, username, and the profile photo your sign-in provider gives us (Apple or Google) if you sign in that way
  • Workout data: exercises, sets, reps, weights, RIR and RPE ratings, comments, warm-ups, the programs you build, and the dates and durations of your workouts
  • Health and fitness data from Apple Health, if you connect it: heart rate and active calories recorded during a workout, and body weight and body fat percentage — see the next section
  • Body measurements you record yourself
  • Voice input: when you log sets by voice, your speech is transcribed on your device. If the on-device parse fails, the transcribed text — never the audio — is sent to Anthropic to interpret, along with the names of the exercises in your current workout
  • Community content: programs you choose to publish, including your username, display name, and the program name, category, description, days and exercises
  • Safety data: reports you submit about community content, and the list of creators you have blocked
  • Support messages: when you contact us from inside the app we receive your message along with your email address, username, and account ID
  • Subscription data: plan type, status, billing platform (Apple or Stripe), and the customer identifiers our billing providers assign to you
  • Technical information: your platform (iOS or web), and the server logs our functions generate when your app talks to them

Apple Health and health data

Connecting Apple Health is optional. If you turn it on and grant permission, LiftLabb reads exactly four things:

  • Heart rate — live during a workout, and the average and maximum for the session
  • Active energy (calories) burned during a workout
  • Body weight
  • Body fat percentage

The average and maximum heart rate and the calorie total for each workout are saved with that workout in our database, and body weight and body fat are saved with your measurements, so your history is there on every device you sign in on. LiftLabb also writes your completed workouts back into Apple Health, along with the active energy and heart-rate samples recorded during them.

We never use health data for advertising, marketing or data mining, we never sell it, and we never store it in iCloud. To stop the sync, revoke our access in the Apple Health app — iOS Settings > Health > Data Access & Devices > LiftLabb — which is where iOS keeps the switches for what we may read and write. Values already written into Apple Health stay there for you to manage, and values already saved to your LiftLabb account are removed if you delete your account.

If you export a workout as an image to share, that image can include your heart rate and calories. The image is built on your device and handed to the app you share it with — we never receive it.

How we use your data

  • To run the app: your workout history, programs, progression charts and measurements
  • To sync your data across the devices you sign in on
  • To manage your subscription and process payments
  • To interpret voice input when you log sets by voice
  • To review reports, remove content that breaks our terms, and keep blocked creators out of your feed
  • To answer your support messages
  • To keep the service secure and working — rate limits, abuse prevention, and debugging from server logs

We do not sell your personal data. We do not use it for advertising, and we do not profile you for anyone else.

What becomes public

Nothing in LiftLabb is public until you choose to publish it. Two features publish something:

Publishing a program to the community. Your username, your display name, and the program's name, category, description, days, exercises, sets and reps become visible to every other LiftLabb user. Exercise details from the program (name, category, muscles, equipment) are copied into the library of anyone who adopts it. You can unpublish at any time from the program menu; that removes the listing from the feed, but copies other users already saved into their own libraries stay theirs.

Sharing a workout as a link. This creates a page at app.liftlabb.ca/w/… that anyone with the link can open without signing in. It shows your username, the workout name and date, how long the session took, your total sets and total volume, and each exercise with its best set. The page also carries the rest of what you logged for that workout — every set, with its weight, reps and RIR. It does not include heart rate, calories, body weight or body fat. A share link stops working 90 days after you create it, and you can revoke a link at any time from Settings, which deletes the page from our database — copies cached by browsers or the network can keep loading for a few minutes before the link goes dead.

Everything else — your logged workouts, measurements, Apple Health data, email address and support messages — stays private and never appears in the community feed or on a share page.

Reports and blocking

If you report a program or a creator, we receive your account ID and the email address on your account, what you reported, and anything you typed in the report. The report is stored in our database as the record we act on, and a copy is emailed to our support inbox through Resend, our email provider — that copy also notes the reported item's name and creator as they stood when you reported it. Reporting a shared workout page works differently: the Report link on the page opens your own email app, so that report reaches us as an ordinary email from you — with whatever your email shows about you as the sender — and is not stored in our database. Either way we use a report only to review it, act on it, and contact you if we need more detail. We do not tell the reported creator who reported them.

When you block a creator, we store your account ID together with that creator's account ID and their username at the time you blocked them, so their programs stay hidden from you on every device. Blocks are private, the blocked creator is not notified, and your block list is deleted when you delete your account. If someone else has blocked you, that record belongs to their account and goes when they unblock you or delete their own account.

AI features

Voice logging. Speech is transcribed on your device. If the app cannot parse the transcript itself, it sends the text — never the audio — plus the names of the exercises in your current workout to Anthropic in the United States, which returns the set it understood. We ask for your consent the first time a transcript needs that cloud fallback — not every voice log does — and you can turn voice input off in Settings.

AI connections. If you connect an AI client from Settings > AI Connections, that client can read the data you authorise it to read, which can include your workouts and their heart rate and calorie figures, your programs, and your measurements. You choose which clients to connect, and you can disconnect one at any time, which stops its access.

Who else processes your data

  • Supabase (United States) — the database that holds your account, workouts, programs, measurements and health data
  • Firebase (Google, United States) — sign-in, and the server functions that run behind the app
  • Anthropic (United States) — interprets voice-logging transcripts and powers optional AI connections
  • Resend (United States) — delivers our support and report emails
  • RevenueCat (United States) — manages subscriptions bought through Apple In-App Purchase
  • Stripe (United States) — processes web payments
  • Apple — In-App Purchase, Sign in with Apple, and HealthKit

Each of these has its own privacy policy, and we require them to protect your information to at least the standard set out here. None of them is permitted to use your data for advertising.

Where your data is stored

Your data is held in a Supabase Postgres database hosted in the United States, encrypted in transit and at rest. LiftLabb is operated from Australia, but the services that run it are overseas, mostly in the United States — so by using LiftLabb you consent to your personal information, including your health information, being stored and processed there. Overseas providers may be subject to laws that differ from Australian law. Every table is protected by row-level security so your data is readable only by your own account, apart from the two things you choose to publish: programs you publish to the community, which any signed-in user can read, and workouts you share as a link, which anyone with the link can read.

How long we keep it

  • Your account, workout, health and measurement data: for as long as your account exists
  • Share pages: until you revoke them or delete your account. A link stops working 90 days after it is created
  • Reports: while we may still need them to recognise repeat offenders, and no longer than 12 months
  • Support and report emails: in our inbox and our email provider's logs for up to 24 months
  • Billing records: Apple, Stripe and RevenueCat keep transaction records for as long as tax and financial-record law requires, typically seven years. We cannot delete those for you

Deleting your account

You can delete your account at any time from Settings. That deletes your profile and everything attached to it from our database — workouts, exercise library, programs, measurements, the heart rate, calorie, body weight and body fat values we stored from Apple Health, your saved templates, any programs you published to the community, your share pages and your block list — and then deletes your sign-in account. Any subscription billed through Stripe is cancelled first; a subscription bought through Apple must be cancelled with Apple.

Some things survive: emails you already sent us (support messages and reports) cannot be unsent, copies of a published program that other users had already saved into their own libraries stay in their libraries, and billing providers keep their transaction records.

One housekeeping record is not removed automatically today: access tokens you issued for AI connections. They are keyed to your account identifier and contain no workout or health data; email us and we will delete them on request. The daily counters we use for rate limiting delete themselves after about a month — they are keyed to your account identifier, except for password-reset requests, where the counter key is a one-way hash so we never accumulate the raw email address or network address used.

Access, correction and complaints

You can export your training data — workouts, programs, exercise library, saved templates, measurements and settings — at any time from Settings > Export Data, correct your account details from your profile, and delete your account from Settings. For a complete copy of everything we hold about you (including your profile, reports, blocks and share records), or if you would rather we did any of it for you — access, correction, deletion or a portable copy — email support@liftlabb.ca and we will respond within 30 days. If you think we have mishandled your personal information, tell us first. If our answer does not satisfy you, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and if you are in the European Economic Area or the United Kingdom you can complain to your local data protection authority.

Data breaches

If a data breach happens that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.

Children

You must be at least 13 years old to create a LiftLabb account, and at least 16 in the European Economic Area or the United Kingdom unless a parent or guardian has consented on your behalf. We do not knowingly collect data from anyone below these ages, and if we learn that we have, we delete it and close the account.

Changes to this policy

We may update this policy. We will change the date at the top of this page, and we will tell you in the app if a change is material.

Contact

Questions about this policy, or a privacy request? Email us at support@liftlabb.ca. You can also reach us from Settings > Support inside the app.

This document has not been reviewed by a lawyer.