LiftLock Privacy Policy

LiftLock Privacy Policy

Last updated: 8 August 2026 (version 2)

LiftLock ("the app", "we", "us") is a workout tracker with an optional AI coach and an app-blocking Focus feature. This policy explains what data the app handles, when it leaves your device, who processes it, why we are allowed to process it, how long we keep it, and the rights you have depending on where you live.

The short version. The app works fully offline with no account. Everything you log stays on your iPhone. Data leaves your device only if you create an account to use the AI coach, and only after you have accepted the Terms of Use and this policy in the app. Health-related data (injuries, pain) is processed only with your separate, explicit consent, which you can withdraw at any time in Settings. There are no ads, no third-party analytics, and no trackers. We never sell your data.


1. Who is responsible for your data


2. Two modes, two very different data pictures

2a. Without an account (default)

If you never sign in, LiftLock is 100% on-device. Your workouts, routines, body metrics, exercise catalog, and Focus app selections are stored locally on your iPhone (and, if you enable it, written to Apple Health, which stays on your device and iCloud under Apple's control). Nothing is sent to us. We have no server record of you.

2b. With an account (to use the AI coach)

Signing in (Sign in with Apple, or email + password) unlocks the AI coach. To generate personalized coaching, the following is sent to and stored on our backend (Amazon Web Services, primary region: Europe, Paris eu-west-3):


Processing Legal basis
Creating and operating your account, syncing workouts, generating coaching and programs Performance of a contract (GDPR Art. 6(1)(b))
Injuries, pain and other health-related data Your explicit consent (GDPR Art. 9(2)(a)); you can withdraw it in Settings at any time
Subscription entitlement checks Performance of a contract
Keeping proof of the consents you gave Legal obligation and legitimate interest in demonstrating compliance (Art. 6(1)(c), 6(1)(f))
Abuse prevention, quotas, service security and diagnostics Legitimate interest in running a safe, working service (Art. 6(1)(f))

Withdrawing health-data consent stops the coach from receiving new health-related data and disables the features that depend on it; everything else keeps working. Withdrawal does not affect the lawfulness of processing before the withdrawal.


4. The AI coach: how it works and what it does not do

Sub-processors:

Processor Role Location
Amazon Web Services (AWS) Hosting, database, authentication, AI inference (Bedrock) EU (storage in Paris eu-west-3; inference in the EU regions listed above)
Anthropic (via AWS Bedrock) AI model that generates coaching Within AWS, EU
Apple Sign in with Apple, App Store payments, HealthKit Per Apple's policy

We do not use Google Analytics, Firebase, Meta SDKs, or any advertising or attribution SDK.


5. Consumer Health Data Privacy Policy

This section is our consumer health data privacy policy under the Washington My Health My Data Act and similar laws (e.g. Nevada SB 370). It applies to everyone, wherever you live.

What health data we collect (only with your separate opt-in consent): injuries you declare; chronic pain areas; pain reported during a set (body area and intensity); health-related statements you make to the coach in chat (the coach may note, for example, that a topic requires a doctor); and body measurements you provide (height, body mass). We do not collect biometric identifiers, genetic data, precise location, or reproductive health data, and we do not infer health conditions from unrelated data.

Sources: you. Everything comes from what you type or select in the app.

Why: solely to personalize your coaching (e.g. the coach avoids loading a joint you told it to protect) and, where you report red-flag symptoms, to tell you to see a professional.

Sharing: we do not sell consumer health data and we do not share it with third parties or affiliates for their own purposes. It is processed only by the sub-processors listed in section 4, acting on our instructions, to provide the service. No one else can access it, and we would seek your separate, explicit authorization before any sale or new sharing (none is planned).

Your rights: you can access it (Settings → export), withdraw consent (Settings → consent), and delete it (delete your account, or wipe the coach's memory and chat). Deletion propagates to backups as they expire (35 days; see section 7). To exercise rights by email, or to appeal a refusal, write to aymane6@hotmail.com; we answer within 30 days and explain how to appeal. If you are in Washington and unsatisfied after appeal, you may contact the Washington Attorney General.


6. Payments, Apple Health, Focus


7. Retention: exactly how long we keep things


8. International transfers

Your account data is stored and processed in the European Union. We do not transfer it to servers outside the EU. If you use the app from the USA, Canada, Australia, Brazil, or anywhere else, your data travels to the EU over TLS and is processed there under this policy. Apple processes sign-in and payments under its own worldwide arrangements.


9. Your rights

These rights are free. Exercise them in-app (Settings gives you direct controls: export your data, edit your profile, clear chat history, wipe coach memory, withdraw health-data consent, delete your account) or by email to aymane6@hotmail.com. We answer within 30 days (or the shorter period your law requires), and we never discriminate against you for exercising a right. We may ask you to confirm control of the account email before acting.

European Economic Area, United Kingdom, Switzerland (GDPR/UK GDPR/FADP). Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20; the in-app export gives you a machine-readable copy), objection (Art. 21), and withdrawal of consent at any time (Art. 7(3)). You may lodge a complaint with your supervisory authority; in France, the CNIL (cnil.fr).

California (CCPA/CPRA). Right to know/access, correct, delete, and to limit use of sensitive personal information. We do not sell or share personal information as the CCPA defines those terms, and we have not done so in the preceding 12 months; there is therefore nothing to opt out of. We use sensitive personal information (health data) only to provide the service you asked for. We honor these rights for all Californians regardless of whether the CCPA's thresholds technically apply to us. You may use an authorized agent; we will verify the request.

Washington and Nevada. See section 5 (consumer health data), including the right of appeal.

Canada (PIPEDA and Québec Law 25). Right to access and correct your information, to withdraw consent, to data portability, and to complain to the Office of the Privacy Commissioner of Canada or, in Québec, the Commission d'accès à l'information. The person in charge of the protection of personal information is named in section 1.

Australia (Privacy Act 1988, APPs). Right to access and correct your information (APP 12 and 13) and to complain; if unsatisfied with our answer, you may complain to the OAIC (oaic.gov.au).

Brazil (LGPD). Confirmation of processing, access, correction, anonymization or deletion, portability, information about sharing, and withdrawal of consent (Art. 18). Complaints go to the ANPD.

Everywhere else. We extend the same set of controls (access, export, correction, deletion, consent withdrawal) to every user, wherever you live.


10. Age requirement

LiftLock is for adults. You must be at least 18 years old to create an account, and the app asks you to confirm this. We do not knowingly collect personal data from anyone under 18; if we learn we hold such data, we delete it. If you believe a minor has an account, contact aymane6@hotmail.com.


11. Security

Data in transit uses TLS 1.2+. Data at rest on our backend is encrypted with AWS KMS (customer-managed keys). Access to your rows is scoped to your authenticated identity; one user cannot read another's data. Backend components run with least-privilege permissions, and administrative access is logged. No system is perfectly secure; if a breach affects your data we will notify you and the competent authorities as the law requires (e.g. GDPR Art. 33/34, state breach laws, Québec Law 25).


12. Changes to this policy

We will update this page and the "last updated" date when practices change. For material changes (new data categories, new purposes, new sharing) we will surface a notice in the app and, where the change concerns data processed under your consent, ask for that consent again before it applies to you.


13. Contact

Data controller: Aymane Bamhamed, France. Privacy contact: aymane6@hotmail.com. Support: aymane6@hotmail.com.

This policy is drafted in English; translations may be provided for convenience. Where a translation is required by local law (e.g. French in Québec), the required-language version prevails for consumers in that jurisdiction.