Privacy Policy
How Lyfto handles your data.
Last updated: 2026-09-25 (rev 5)
This policy describes how the Lyfto mobile app ("Lyfto", "we", "us") collects, uses, and protects your information. By using Lyfto you agree to the practices below. If you do not agree, do not use the app.
1. Who we are
Lyfto is a workout-tracking app for iOS and Android. Lyfto is published by Aksel Cornelius Bjorland, who is the data controller responsible for your information. Contact: supportlyfto@gmail.com.
2. What we collect
Only the data you explicitly enter or grant permission for. We do not collect location, contacts, or browsing history.
| Type | Purpose | Stored where |
|---|---|---|
| Email + password | Account authentication | Supabase (EU, Ireland). Password is hashed; we cannot read it. |
| Apple Sign-In credentials (user identifier; optionally email and name) | Alternative account authentication (iOS only) | Supabase (EU, Ireland). If you choose Apple's email-relay option, we only ever see the relay address, never your real email. |
| Google Sign-In credentials (name and email) | Alternative account authentication (iOS and Android) | Supabase (EU, Ireland). Google provides your name and email address; we use them only to create and sign in to your account. |
| Workout sessions (sets, reps, weights, exercises, notes) | Show your training history; compute personal records | On-device + Supabase (EU) |
| Personal records, body weight, body measurements | Track progress over time | On-device + Supabase (EU) |
| Sex and birthdate | Used to calculate your Strength Score. Optional, but if not set the app calculates your score as if you were male, so we ask you to set it accurately. | On-device + Supabase (EU). Synced as part of your coach preferences. |
| Heart-rate samples (Apple Health, iOS only) | Show live BPM during workouts; compute session averages | On-device only, read from Apple Health on demand. Saved as a number on the workout record. Not available on Android. |
| Coach chat history and coach memory notes | Provide an AI coach that knows your training context and remembers things you have told it | On-device + Supabase (EU) for memory notes. Each message is sent to Google Gemini for processing (see section 4). |
| Progress photos | Track visual changes over time across reinstalls and devices | On-device + Supabase Storage (EU, Ireland). Stored in a private bucket scoped to your account, only you can read or write your own progress photos. |
| Public profile (display name, handle, bio, avatar) | Identify you to other users in the social features | Supabase (EU). Visible to others according to your profile visibility setting (private, group-only, or public). |
| Posts you choose to share (a workout summary, a caption, and an optional photo) | Share your training to a group, your followers, or publicly, only when you tap "Del økten" | Supabase (EU). The optional post photo is uploaded to a private Storage bucket and shown only to the audience of that post. Your avatar photo, if you set one, is stored in a public bucket. A post is visible to others according to the per-post privacy setting you pick (just me, group, followers, or public). |
| Comments and likes you make | Interact with other people's posts | Supabase (EU). Visible to people who can see the post. |
| Follow graph + group membership + weekly league placement | Build your feed, group leaderboards, and weekly tonnage leagues | Supabase (EU). Who you follow, who follows you, which groups you belong to, and which weekly league you are placed in if your profile is public. |
| People search and direct messages | Let you find other users and message them directly | Supabase (EU). Direct messages are visible to the sender and recipient. A search index of public and discoverable profiles is used to power search. |
| Blocks, content reports, and coach-answer reports | Let you block users, report posts, comments, profiles, and AI coach answers; auto-hide content that enough people report | Supabase (EU). Your block list is visible only to you. A coach-answer report stores the reported answer text, a reason, and an optional note; it is readable only by us, never by other users, not even you. |
| Referral codes and gift links | Let you invite friends and send or redeem Pro gift links | Supabase (EU). Records who invited whom and who redeemed a gift link. |
| First-party product analytics (for example: onboarding steps completed, workouts started or finished, sets logged including their weight and reps, app version, platform) | Understand how people use Lyfto so we can fix problems and improve the app | Supabase (EU). Not shared with any third-party analytics or advertising company. See section 4. |
| Push notification token and push content | Deliver rest-timer alerts, workout reminders, and social notifications (likes, comments, follows, direct messages) | Supabase (EU), delivered via Expo's push service and, on Android, Firebase Cloud Messaging. |
| App update client identifier | Deliver over-the-air app updates to the correct app version | Expo EAS Update. Not linked to your Lyfto account. |
| Crash reports + diagnostic data | Find and fix bugs | Sentry. Includes device model, OS version, stack trace. No personal content. |
Social features and visibility. Lyfto has optional social features (a profile, groups, posts, comments, likes, following, people search, and direct messages). When you create your account, we ask "Who can see your training?" with nothing preselected: you choose Public or Private before any profile is created. If you choose Private, other users cannot see your workouts, personal records, or training history, and you are not placed in a weekly league or shown in people search results as publicly discoverable. If you choose Public, any signed-in user can see your workout history, personal records, and strength score, and you may be placed in a weekly league with other users. You can change this choice at any time in your profile settings. Publishing an individual post (tapping "Del økten") is a separate, further choice: you pick the audience for that post (just you, a group, your followers, or public), regardless of your profile visibility. Other users can see, like, comment on, and report content you share, and report your profile, posts, comments, direct messages you send them, or an AI coach answer. We provide blocking and reporting tools, and content that enough people report is automatically hidden.
3. Permissions we ask for
You can revoke any of these in your device settings at any time.
- Apple Health (iOS only): read heart-rate data during workouts; write completed workouts back to Health so they appear in your Activity history. Not available on Android.
- Camera + Photo Library: only if you choose to add a photo: a private progress photo (visible only to you) or a photo on a post / your avatar (visible to others, as described above). Photos are uploaded to Supabase Storage so they survive reinstalls.
- Notifications: rest-timer alerts, optional daily workout reminders, and (on iOS and Android) social notifications such as likes, comments, follows, and direct messages.
4. Third parties
Lyfto uses the following services. Each receives only the data shown.
| Service | What it sees | Purpose |
|---|---|---|
| Supabase | Email, hashed password, workouts, personal records, body measurements, progress photos, analytics events, push tokens, and, if you use the social features, your profile, posts, post photos, comments, likes, follows, group membership, direct messages, blocks and reports | Cloud database + Storage + authentication so your data syncs across devices and the social features work. Servers in EU (Ireland). Private progress photos and post photos live in a private Storage bucket scoped to your user ID or to the post's audience; profile and post avatars live in a public Storage bucket so they render for anyone who can see the profile or post. |
| Google Gemini | Coach messages, a context block summarising your recent workouts and goals (no email or password), and avatar or post photos when they are automatically checked for safety before being shown to others | AI processing for the in-app coach, and automated image moderation for photos you upload to your profile or a post. Requests pass through our Supabase Edge Function so the API key stays on our servers. Google keeps coach questions and moderated images for a limited period of time for abuse monitoring, under Google's own terms. |
| Sentry | Crash stack traces + device + OS info | Detect and fix bugs. No workout content or chat content is sent. |
| Apple HealthKit (iOS only) | Heart-rate (read), workout sessions (write) | Stays on your device. Apple does not receive Lyfto-generated data. Not available on Android. |
| Apple Sign-In (iOS only) | Apple-issued user identifier; optional email and name (only on first sign-in) | Used solely to create and authenticate your Lyfto account. We never receive your Apple ID password. Not available on Android. |
| Google Sign-In | Name and email address | Used solely to create and authenticate your Lyfto account. We never receive your Google account password. |
| Firebase Cloud Messaging (Android only) | A device push token | Delivers push notifications on Android, via Expo's push service. Not available on iOS, which uses Apple Push Notification service instead. |
We do not sell, rent, or trade your data. We do not use your data for advertising or third-party analytics. We do use first-party analytics, described in section 2, to understand app usage and fix problems; this data is not shared outside the services listed above.
5. Data retention
Your data is kept for as long as your account exists. When you delete your account inside the app (Social tab → your profile picture → Settings → Delete account), the following happens immediately:
- All workouts, personal records, body measurements, progress photos, coach memory notes, strength goals, templates, custom programs, custom exercises, and favorites are deleted from Supabase.
- Your social data, profile, posts, post photos, comments, likes, follows, group memberships, direct messages (both sides of every conversation), blocks, push tokens, league placement, referral records, and gift links, is deleted from Supabase.
- Groups you own are handed to their longest-standing remaining member, unless you were the only member, in which case the group is deleted with your account.
- Your authentication record is deleted from Supabase.
- Any data still on your device (coach history, photos, settings) is removed when you uninstall the app.
Some data is kept after your account is deleted, because it belongs to other people's records or to legitimate safety and accounting needs:
- Comments you left on other people's posts stay visible, shown as "deleted user" instead of your name.
- Analytics events (section 2) are kept with your user identifier removed, so a workout count or a feature-usage trend is not lost, but the row can no longer be linked back to you.
- Image-moderation records keep the storage path of a checked photo, but the photo itself is deleted.
- Reports other users filed about you, your posts, or your comments, and group bans that name you, are kept for safety and moderation purposes.
- Google Gemini keeps coach questions and moderated images for a limited period of time for abuse monitoring, under Google's own terms.
- Sentry crash logs are retained for up to 90 days for debugging and then auto-purged.
- Database backups roll off according to our hosting provider's backup retention schedule.
Deletion of your account and the data listed above as deleted is permanent and not recoverable.
6. Your rights (GDPR)
If you live in the European Economic Area, the UK, or Switzerland, you have these rights under GDPR:
- Access: export all your data via Profile → Export Data (JSON file).
- Rectification: edit any workout, set, or measurement directly in the app.
- Erasure: delete your account from Profile → Delete Account, or email us.
- Portability: the export is a standard JSON file you can take with you.
- Object / restrict processing: email us.
- Lodge a complaint: contact your local data protection authority.
7. Children and age of consent
Lyfto is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, contact us and we will delete it.
If you live in the European Economic Area, the age at which you can consent to this kind of data processing on your own varies by country, from 13 to 16. If you are under your country's age of digital consent, you need a parent's or legal guardian's consent before creating a Lyfto account.
8. Security
We use industry-standard security: TLS for all network traffic, hashed passwords, JWT-based authentication, and server-side API keys. No system is perfectly secure, so we cannot guarantee absolute protection, but we follow current best practices and act fast on any vulnerability we learn about.
9. Changes to this policy
If we change this policy in a way that affects your rights, we will notify you in the app before the change takes effect. The "Last updated" date at the top always reflects the current version.
10. Contact
Questions, requests, or complaints: supportlyfto@gmail.com.