Privacy Policy
Last updated: August 1, 2026
This policy explains what data Liftrava collects when you use our websites and apps, why we collect it, and the choices you have. The short version: we collect what the product needs to work, we don’t sell your data, and you can export or delete it at any time.
1. Data you give us
- Account details — your name, email address and password (stored as a salted hash, never in plain text). If you sign in with Google we receive your name, email address and Google account identifier; we never see your Google password.
- Training data — the workouts, sets, reps, weights, cardio sessions and plans you log, plus profile settings such as units and training goals.
- Gym data— if you run a gym on Liftrava: the member names, phone numbers, email addresses, plans and payment records you enter. You are responsible for having the right to share your members’ contact details with us; we process them only to provide the gym features (membership tracking and expiry reminders).
2. Data collected automatically
We keep standard technical logs (IP address, device and browser type, timestamps) for security and debugging, and session tokens to keep you signed in. The marketing site and app do not use third-party advertising trackers.
3. How we use data
- to provide the Service — storing and syncing your training log;
- to send service messages: password and account emails, and — for gym members — membership expiry reminders by in-app notification, email or SMS, sent on behalf of your gym;
- to secure the Service and prevent abuse;
- to understand aggregate usage and improve the product.
We do not sell your personal data or share it with advertisers.
4. Who we share it with
Only service providers that make Liftrava work: cloud hosting and database providers, file storage (Amazon S3) for uploads such as exercise media, email delivery for account and reminder emails, SMS delivery (Twilio) for gym reminders, and Google for optional Google sign-in. Each provider processes data only on our instructions. We may also disclose data if the law requires it. If you are a gym member, your gym’s owner can see the membership details they manage for you — not your personal training log.
5. Retention and deletion
We keep your data while your account is active. When you delete your account, your personal data and training log are deleted from our systems; residual copies in encrypted backups expire on a rolling schedule. Gym business records (for example payment entries) may be retained by the gym that created them, without your personal training data.
6. Your rights
You can access, correct, export or delete your data at any time from the app, or by emailing us. Depending on where you live you may have additional statutory rights (for example under the GDPR); we honour access, rectification, erasure, portability and objection requests for everyone, regardless of location.
7. Security
Traffic is encrypted in transit (HTTPS), passwords are hashed, sessions use short-lived rotating tokens, and access to production data is restricted. No system is perfectly secure — if a breach ever affects your data, we will notify you as required by law.
8. Children
Liftrava is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
9. Changes and contact
If we materially change this policy we will notify you in the app or by email before the change takes effect. Questions or requests: support@liftrava.com.