Lifted · Privacy Policy

Privacy Policy

Effective 7 September 2026

Lifted is a recovery and training app, published by Create Business Solutions, LLC (“we”). It reads your heart rate to score how recovered you are each morning and plans strength and endurance sessions from your own logged training. This policy explains what the app collects, where it goes, and how you control it. It is written to be read, not skimmed.

The short version

What the app collects

Health and fitness data

Location

During an outdoor session you start (run, walk, ride), the app records your GPS route to compute distance, pace and elevation and to show the route on a map afterwards. Location is only recorded while a session you started is running, including with the screen locked. It is never collected in the background otherwise.

Profile and setup

Sex, age, units, the equipment you have, your training goal, the days you can train, and any injuries or limits you type in. These are used to configure your plan and, if you connect one, are shown to your AI assistant. The app never interprets your injury notes itself.

Account

If you sign in with Apple, we receive an identifier and, if you allow it, your name and email (or Apple's relay address). If you sign in by email code, we store your email address. No passwords are ever stored.

Device and diagnostics

The identifier and name of the heart rate strap you pair, so the app reconnects to the same one. If crash reporting is enabled in a future version, crash reports contain the app state at the time of the crash and the device model and OS version, never health data.

What the app does not collect

No advertising identifiers, no tracking across other apps or websites, no contacts, no photos, no microphone, no analytics SDKs that profile you. We do not use the data for advertising or for training AI models.

Where your data lives

On your phone, in a local database. This is the source of truth and it works offline.

In your account, if you sign in. Data is stored with our hosting provider, Supabase, in a data centre in the eastern United States, encrypted in transit and at rest. Access is enforced per user by database row-level security: you can read and write only your own rows. Members of a household you have explicitly joined can read (never write) your readings, sessions and lift log. Nobody else, including us in normal operation, reads your data.

Sharing with your own AI assistant

You can connect Lifted to an AI assistant you already use (Claude or ChatGPT) so it can discuss your training with you. This happens only when you set it up and sign in to Lifted from inside that assistant (OAuth); nothing is shared until you tap Allow. The assistant can then read your recovery readings, sessions, lift log, program and setup answers, answer questions you left open, leave short notes in the app, and propose a program for you to accept or reject. It cannot change your training, edit your lift log or delete anything.

What the assistant reads is sent to that provider (Anthropic or OpenAI) under their terms, not ours. Lifted itself never sends your data to any AI provider, and the connector stores nothing of its own: it reads from your account on each request and keeps no copy. Revoke access at any time by removing the connector in the assistant, or by signing out of Lifted; existing tokens stop working within the hour.

Your controls

Retention

We keep your data for as long as you have an account. Deleting your account removes it at once from the live database; encrypted backups held by our hosting provider roll off within 30 days. If you never sign in, we hold nothing.

Children

Lifted is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Changes

If this policy changes in a way that matters, the app will tell you before the change takes effect. The current version is always at this address.

Contact

Questions or requests about your data: nicknowlin@createbusinesssolutions.com.