Your information

Privacy Policy

This policy explains how the LiftKin website and iOS app handle information. The website waitlist and the app are described separately below.

Effective date: July 13, 2026

1. Who we are

LiftKin is a fitness planning and workout-logging app available in the United States. Bolt is LiftKin’s AI workout coach. In this policy, “LiftKin,” “we,” and “us” refer to the operator of LiftKin. Questions or requests can be sent to liftkin@gmail.com.

2. Website waitlist

The waitlist on liftkin.app is separate from the iOS app. When you submit the form, your email address is received and stored through Netlify Forms, the form service used to host and process the website form.

Netlify processes form submissions under its own privacy and security practices. Please do not submit sensitive health or workout information through the waitlist form.

3. Information handled by the iOS app

Workout and app data stored locally

Workout history and most application data are stored locally on your device. LiftKin currently has no user account system. Deleting the app may remove locally stored data, subject to how iOS backups and device restoration work.

Optional online Bolt coaching

Before LiftKin sends information to a third-party AI service, the app asks for your permission and identifies OpenAI as the AI provider. If you agree, LiftKin may automatically send the context needed to generate your first plan or provide proactive coaching during a workout. It also sends context when you choose to ask Bolt a question or request a plan change.

Depending on the feature, the information sent may include your goals, experience, schedule, equipment, training preferences, optional limitations and exercises to avoid, relevant planned or completed workout information, recent set information, and the question or coaching prompt. The information travels through LiftKin’s Google Cloud backend to OpenAI solely to generate the requested plan or coaching response.

OpenAI requests are sent with store: false. LiftKin’s application code is designed not to retain or body-log Bolt questions, responses, plan requests, or workout context on its backend. Infrastructure providers may still process limited technical data under their own terms and security practices.

Online Bolt coaching is optional. If you decline, LiftKin uses on-device planning and keeps workout logging available. You can grant or revoke permission at any time under Settings → Bolt & OpenAI. After revocation, LiftKin blocks online plan generation, questions, and proactive coaching unless you grant permission again. Plans and messages already saved locally remain on your device until you delete them.

App authentication and abuse prevention

LiftKin uses Apple App Attest and a Google Cloud backend to help verify genuine app requests and prevent abuse. Firestore stores App Attest records, short-lived challenges, assertion counters, and quota windows. These operational records are not used for advertising or cross-app tracking.

Subscriptions

RevenueCat processes anonymous subscription status and purchase history so LiftKin can determine whether paid features are available and support purchase restoration. Apple also processes App Store purchases under Apple’s own policies. LiftKin does not receive your full payment-card details.

Exercise-help images

Exercise-help images are bundled with the app and do not require LiftKin to send an image request tied to your workout.

4. Support communications

If you contact support, we receive the information you choose to include, such as your email address and message. We use it to respond, troubleshoot, protect the service, and maintain a reasonable support record. Please do not email health details, workout notes, Bolt prompts, receipts, API keys, passwords, or other sensitive information.

5. Retention

Local app data remains on your device until you delete it or the app, subject to iOS backups. Waitlist information is handled as described above. Support messages are kept only as long as reasonably needed to resolve the request, maintain business records, prevent abuse, or meet legal obligations. Authentication, quota, and security records are retained only as long as reasonably needed for those operational purposes.

6. Sharing and service providers

We disclose information only as needed to operate LiftKin, comply with law, protect rights and safety, or complete a business transaction. Providers described in this policy include Netlify, Google Cloud/Firestore, OpenAI, RevenueCat, and Apple. We do not sell personal data, use advertising, or perform cross-app tracking.

7. Security

We use administrative and technical safeguards intended to protect information, including App Attest-based request verification and limiting the data our application code retains. No system or transmission method can be guaranteed completely secure.

8. Your choices

9. Children

LiftKin is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can review and address the request.

10. United States availability

LiftKin’s initial launch territory is the United States. Information may be processed in the United States and in other locations where our service providers operate.

11. Changes to this policy

We may update this policy as LiftKin changes. We will post the revised version here and update the effective date. Material changes may also be communicated through the app or another appropriate channel.

Contact

For privacy questions, deletion requests, or waitlist unsubscribe requests, email liftkin@gmail.com.