Lyfto
Privacy Policy

How Lyfto handles your data.

Last updated: 2026-06-26 (rev 4)

This policy describes how the Lyfto mobile app ("Lyfto", "we", "us") collects, uses, and protects your information. By using Lyfto you agree to the practices below. If you do not agree, do not use the app.

1. Who we are

Lyfto is a workout-tracking app for iOS. Lyfto is published by Aksel Cornelius Bjorland, who is the data controller responsible for your information. Contact: supportlyfto@gmail.com.

2. What we collect

Only the data you explicitly enter or grant permission for. We do not collect location, contacts, or browsing history.

TypePurposeStored where
Email + password Account authentication Supabase (EU, Ireland). Password is hashed; we cannot read it.
Apple Sign-In credentials (user identifier; optionally email and name) Alternative account authentication on iOS Supabase (EU, Ireland). If you choose Apple's email-relay option, we only ever see the relay address — never your real email.
Workout sessions (sets, reps, weights, exercises, notes) Show your training history; compute personal records On-device + Supabase (EU)
Personal records, body weight, body measurements Track progress over time On-device + Supabase (EU)
Heart-rate samples (Apple Health) Show live BPM during workouts; compute session averages On-device only — read from Apple Health on demand. Saved as a number on the workout record.
Coach chat history Provide an AI coach that knows your training context On-device. Each message is sent to Google Gemini for processing (see §4).
Progress photos Track visual changes over time across reinstalls and devices On-device + Supabase Storage (EU, Ireland). Stored in a private bucket scoped to your account — only you can read or write your own progress photos.
Public profile (display name, handle, bio, avatar) Identify you to other users in the social features Supabase (EU). Visible to others according to your profile visibility setting (private, group-only, or public).
Posts you choose to share (a workout summary, a caption, and an optional photo) Share your training to a group, your followers, or publicly — only when you tap "Del økten" Supabase (EU). The optional post photo is uploaded to a public Storage bucket. A post is visible to others according to the per-post privacy setting you pick (just me, group, followers, or public).
Comments and likes you make Interact with other people's posts Supabase (EU). Visible to people who can see the post.
Follow graph + group membership Build your feed and group leaderboards Supabase (EU). Who you follow / who follows you, and which groups you belong to.
Blocks and content reports Let you block users and report content; auto-hide content that enough people report Supabase (EU). Your block list is visible only to you.
Crash reports + diagnostic data Find and fix bugs Sentry. Includes device model, OS version, stack trace. No personal content.

Social features and visibility. Lyfto has optional social features (a profile, groups, posts, comments, likes, and following). Anything social is opt-in: nothing about your training is shared until you create a profile or tap "Del økten" to publish a specific workout. You choose the audience for your profile and for each post (just you, a group, your followers, or public). Two important points: (1) a photo you attach to a post, and a photo you set as your avatar, are stored in a public Storage bucket and are visible to anyone who can see that post or profile — unlike private progress photos, which only you can see; (2) other users can see, like, comment on, and report content you share. We provide blocking and reporting tools, and content that enough people report is automatically hidden.

3. Permissions we ask for

You can revoke any of these in your device settings at any time.

4. Third parties

Lyfto uses the following services. Each receives only the data shown.

ServiceWhat it seesPurpose
Supabase Email, hashed password, workouts, personal records, body measurements, progress photos, and — if you use the social features — your profile, posts, post photos, comments, likes, follows, group membership, blocks and reports Cloud database + Storage + authentication so your data syncs across devices and the social features work. Servers in EU (Ireland). Private progress photos live in a private Storage bucket scoped to your user ID; post photos and photo avatars live in a public Storage bucket so they render for the people you share them with.
Google Gemini Coach messages + a context block summarising your recent workouts and goals (no email or password) AI processing for the in-app coach. Requests pass through our Supabase Edge Function so the API key stays on our servers.
Sentry Crash stack traces + device + OS info Detect and fix bugs. No workout content or chat content is sent.
Apple HealthKit Heart-rate (read), workout sessions (write) Stays on your device. Apple does not receive Lyfto-generated data.
Apple Sign-In Apple-issued user identifier; optional email and name (only on first sign-in) Used solely to create and authenticate your Lyfto account. We never receive your Apple ID password.

We do not sell, rent, or trade your data. We do not use your data for advertising or third-party analytics.

5. Data retention

Your data is kept for as long as your account exists. When you delete your account inside the app (Profile → Delete account), the following happens immediately:

Deletion is permanent and not recoverable. Sentry crash logs are retained for up to 90 days for debugging and then auto-purged.

6. Your rights (GDPR)

If you live in the European Economic Area, the UK, or Switzerland, you have these rights under GDPR:

7. Children

Lyfto is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, contact us and we will delete it.

8. Security

We use industry-standard security: TLS for all network traffic, hashed passwords, JWT-based authentication, and server-side API keys. No system is perfectly secure, so we cannot guarantee absolute protection — but we follow current best practices and act fast on any vulnerability we learn about.

9. Changes to this policy

If we change this policy in a way that affects your rights, we will notify you in the app before the change takes effect. The "Last updated" date at the top always reflects the current version.

10. Contact

Questions, requests, or complaints: supportlyfto@gmail.com.