Legal
Privacy Policy
← Back to homePRIVACY POLICY
Last updated: July 3, 2026
This Privacy Policy explains how Havasi Holding LLC ("LiftLogic," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the LiftLogic mobile application for iOS, watchOS, and any LiftLogic widgets (collectively, the "App"), the liftlogic.fit website (the "Site"), and any related services we provide (together, the "Services").
If you do not agree with this Privacy Policy, please do not use the Services. By creating an account or using the Services, you confirm that you have read and understood this Policy.
Table of contents
- Who we are
- Summary of key points
- Categories of personal information we collect
- Sensitive personal information
- Sources of personal information
- How we use your information
- Who we share information with
- International data transfers
- How long we keep information
- How we keep information safe
- Information from minors
- Your privacy rights
- Cookies and tracking
- Do Not Track and Global Privacy Control
- Health & fitness data (Apple HealthKit)
- Wearable integrations
- AI features
- Trainer and client data flow
- Third-party links and services
- Updates to this Policy
- State-specific and regional disclosures
- Contact us
1. Who we are
The Services are operated by Havasi Holding LLC, a Utah limited liability company. Our registered office is:
Havasi Holding LLC
7533 S Center View St, Ste N
West Jordan, UT 84084
United States
Privacy questions: [email protected]
Legal questions / data subject requests: [email protected]
Product support: [email protected]
Havasi Holding LLC is the controller of personal information collected through the Services for the purposes of the EU and UK General Data Protection Regulation ("GDPR" / "UK GDPR"), the California Consumer Privacy Act as amended ("CCPA/CPRA"), and similar comprehensive privacy laws in other US states.
2. Summary of key points
This summary highlights the most important things in this Policy. Each point links to the full section.
- What we collect. Account details (name, email), workout and fitness data you log or sync, optional health metrics from Apple HealthKit and connected wearables, subscription and billing information processed by Apple or Stripe, basic device and diagnostic information, and messages you send to our AI assistant. See section 3.
- What we do not do. We do not sell your personal information. We do not use your health or fitness data for advertising. We do not use your data to train AI models. We do not show third-party ads in the App or integrate any advertising network that displays ads. The App does ask for your permission through Apple's App Tracking Transparency prompt; if you allow it, the device advertising identifier (IDFA) is used only to measure how well our own advertising performs (for example, whether an ad we ran led to an install). If you decline, the identifier is never accessed. See section 3.8.
- Where data lives. Primary storage is on Google Cloud (Firebase) in the United States. Some processors, such as OpenAI, operate globally; transfers from the EEA or UK rely on Standard Contractual Clauses.
- Your controls. You can export all your data from inside the App (Settings, then Privacy, then Request data export), delete your account permanently (Settings, then Account, then Delete account), disconnect wearables at any time, and revoke Apple HealthKit access from the iOS Settings app. See section 12.
- Children. The Services are intended for users aged 13 and older. Users under 18 require a parent or guardian to accept the Terms on their behalf. See section 11.
- Contact. Email [email protected] for any privacy request.
3. Categories of personal information we collect
We collect the categories of personal information listed below. Not every category applies to every user — for example, we only collect glucose data if you connect a Dexcom continuous glucose monitor.
3.1 Account and profile
- Email address.
- Display name (and, if you sign in with Apple or Google, your given/family name if you choose to share it).
- Password hash (we never see your raw password; Firebase Authentication handles this).
- Authentication provider identifier (Sign in with Apple, Google, or email address).
- Optional profile fields you provide: date of birth, height, weight, sex, fitness goals, equipment available, bio, profile photo.
3.2 Workout and fitness data
- Workouts you create, schedule, or complete: exercises, sets, reps, weights, RPE, rest times, notes, dates.
- Custom routines, programs, and templates you save.
- Custom exercises you author (name, muscles, equipment, video/image you upload).
- Personal records, streaks, body-weight log, body-measurement log.
- Photos you upload: progress photos, equipment photos (used for our AI equipment recognizer), food photos (used for AI nutrition analysis), workout-screen screenshots you choose to share.
- Nutrition entries you log in the food diary (foods, calories, and macros), and daily journal entries — including subjective wellbeing scores (mood, energy, stress, sleep quality, soreness) and any free-text notes you write.
3.3 Health metrics (from Apple HealthKit, when you grant permission)
See section 15 for the full HealthKit disclosure, including the exact data types we request and how to revoke access.
3.4 Wearable data (from third-party platforms you connect)
See section 16 for the per-vendor list and what is exchanged.
3.5 Subscription and billing
- iOS in-app purchases: handled entirely by Apple. We receive a RevenueCat-mediated record of your subscription status (active, trial, expired, refunded) and the product purchased. We do not receive your payment card.
- Web subscriptions: handled by Stripe. We receive a Stripe customer ID, the subscription product/period, and limited metadata (e.g., last 4 digits of the card and card brand) sufficient to display your billing status. We do not see or store full payment card numbers.
3.6 Communications
- Emails you send to support, plus our reply thread.
- Messages, prompts, and image attachments you send to our AI assistant ("Kai"), our equipment-recognition feature, or our food-photo nutrition feature.
- Voice input, if you use voice workout logging or dictation: speech recognition runs on your device (your audio is not sent to our servers), and only the resulting text is processed — the same way as if you had typed it.
- Direct messages between you and a connected trainer or client (if you use the trainer/client features).
- Marketing-preference choices, including whether you have opted out of promotional email.
3.7 Device, log, and diagnostic information
- iOS / watchOS version, device model, app version, locale, time zone.
- Crash reports and performance telemetry (via Sentry — see section 7).
- Push-notification token (Apple Push Notification service / Firebase Cloud Messaging) so we can send notifications you have enabled.
- Approximate IP address (captured transiently by Firebase services for security and abuse prevention; not used for advertising).
- App Attest / App Check attestation tokens that verify requests are coming from a genuine, unmodified copy of the LiftLogic App.
3.8 Product analytics and advertising measurement
We use two analytics services to understand how the App is used and to improve it:
- Firebase Analytics (Google LLC) — high-level usage events (e.g., which screens are visited, which features are used, retention by cohort), linked to a pseudonymous installation identifier.
- PostHog (PostHog, Inc.) — product analytics events (screen views with curated names, feature usage, and application lifecycle events), hosted on PostHog's US Cloud. PostHog events are associated with your LiftLogic account identifier so we can understand usage across sessions; they are not shared with advertisers and are not used to track you across other apps or websites.
App Tracking Transparency and the advertising identifier (IDFA). The App presents Apple's App Tracking Transparency prompt. If you tap "Allow," Google's analytics and on-device conversion-measurement components may use the device advertising identifier (IDFA) to measure the performance of our own advertising campaigns — for example, attributing an App install to an ad we ran. If you tap "Ask App Not to Track" (or never grant permission), the IDFA is not accessed and no cross-app tracking takes place. Either way, we do not show third-party ads in the App, we do not sell your data to advertisers, and your health and fitness data is never used for advertising (see section 4). You can change your choice at any time in iOS Settings, then Privacy & Security, then Tracking.
4. Sensitive personal information
Some of the categories above are treated as "sensitive personal information," "special categories of personal data," or "consumer health data" under applicable laws (including GDPR Art. 9, CCPA/CPRA, the Washington My Health My Data Act, the Connecticut Data Privacy Act, and similar laws). Specifically:
- Health, fitness, and biometric data — heart rate, HRV, resting heart rate, sleep, body weight, body composition, activity / step / workout records, and (if you connect a CGM) blood-glucose readings.
- Precise location — only in three optional, permission-gated cases: (a) if you intentionally sync a workout route from a connected wearable that includes GPS data; (b) if you enable gym-arrival reminders, in which case your device monitors a geofence around the gym location you selected and location processing happens on your device — we store the gym coordinates you chose, not a log of your movements; and (c) if you use the outdoor-training feature, in which case your approximate location is sent to Apple's WeatherKit service to fetch local weather conditions and is not stored by us. We do not otherwise collect location from your phone, and we never use location for advertising or build a history of the places you visit.
- Account credentials — handled by Firebase Authentication; we never see your plaintext password.
We use sensitive personal information only for the purposes you have asked us to (operating the App, generating your personalized recommendations, syncing to your Apple Health profile, etc.) plus the limited backend purposes listed in section 6. We do not use sensitive personal information for advertising, profiling beyond what is necessary to deliver the Service, training third-party machine-learning models, or any purpose unrelated to your use of LiftLogic.
We do not collect government identifiers (such as Social Security numbers, passport numbers, or driver's license numbers) for any purpose.
5. Sources of personal information
We collect personal information from three sources:
- Directly from you — when you create an account, complete your profile, log workouts, send a message to Kai, upload a photo, contact support, subscribe to a paid plan, or update any setting.
- Automatically from your device — your iOS/watchOS device provides version, model, push-notification token, crash logs, and (transiently) IP address to our backend so the Services can operate.
- From third parties you authorize — Apple HealthKit, and any wearable platform you explicitly connect (WHOOP, Oura Ring, Google Health, Garmin, Polar, COROS, Suunto, Withings, Strava, Wahoo, Dexcom). We only access data from these sources after you complete the connection flow and grant permission inside that vendor's authorization screen, and only the data types listed in section 16.
6. How we use your information
We use personal information for the following purposes:
- To provide the Services — let you log and view workouts, sync to Apple Health, generate recommendations, send notifications, surface streaks and personal records, and present your training history across iOS, watchOS, and widgets.
- To authenticate you and protect your account — Firebase Authentication, Apple Sign In, Google Sign In, multi-factor flows, and Apple App Attest / Firebase App Check to block fraudulent or modified clients.
- To process payments and manage your subscription — through Apple In-App Purchase + RevenueCat (iOS) or Stripe (web), so you can purchase, manage, renew, and cancel a paid plan.
- To support trainer and client features — if you connect to a trainer or client, to share the workouts and progress data you both agree to share (see section 18).
- To send transactional and (with your consent) marketing email — using Loops.so as our email service provider. Transactional emails include receipts, security alerts, and account-deletion confirmations and cannot be unsubscribed from. Marketing emails (product updates, tips) include an unsubscribe link in every message.
- To debug and improve the App — using crash reports (Sentry), product analytics (Firebase Analytics and PostHog), and your support messages.
- To measure our own advertising — only if you allow tracking in the App Tracking Transparency prompt, to attribute App installs to advertising campaigns we ran (see section 3.8).
- To deliver AI features — to send the limited prompts and images you choose to share with our AI assistant ("Kai"), equipment recognizer, food-photo nutrition feature, workout-log parser, or AI program builder to OpenAI, our AI inference provider (see section 17).
- To comply with legal obligations and enforce our Terms — including responding to subpoenas, defending claims, preventing fraud and abuse, and enforcing acceptable use.
Our legal bases under GDPR / UK GDPR are: performance of a contract (operating the Services you signed up for), your consent (HealthKit access, wearable connections, marketing email, optional analytics), our legitimate interests (security, fraud prevention, improving the product), compliance with legal obligations, and, for sensitive data, your explicit consent.
7. Who we share information with
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not have advertising partners.
We share personal information with the following categories of recipients, all of whom act either as our service providers / processors (bound by written agreement) or as independent controllers for narrowly defined purposes:
7.1 Infrastructure and security
- Google LLC (Firebase / Google Cloud) — authentication, user and workout data storage (Firestore), file storage (Cloud Storage), push notifications (Firebase Cloud Messaging), product analytics (Firebase Analytics), client attestation (Firebase App Check), and serverless functions. Data hosted in the United States.
- Apple Inc. — Sign in with Apple, Apple Push Notification service, App Attest, App Store hosting and In-App Purchase. Apple is also the platform provider for HealthKit data, which never leaves your device unencrypted by us (see section 15).
- Cloudflare, Inc. — DNS, CDN, and edge security for liftlogic.fit. Cloudflare may process IP addresses to deliver and protect the Site.
- Google Secret Manager — to store our server-side API keys and the encryption key used to wrap your Apple refresh token; never used to store user data itself.
7.2 Payments and subscriptions
- Apple Inc. — processes all In-App Purchases on iOS; payment cards never reach us.
- RevenueCat, Inc. — mirrors and validates your iOS subscription state so the Service knows whether you have an active plan. RevenueCat receives an anonymized App user ID, the product purchased, and entitlement status.
- Stripe, Inc. — processes web subscription payments and, for trainers, pay-outs via Stripe Connect. Stripe receives the information necessary to charge your card and comply with anti-money-laundering rules.
7.3 Communications
- Loops.so — sends transactional and marketing email on our behalf. Loops receives your email address, name, subscription state, and the trigger that caused the email.
7.4 Analytics and diagnostics
- Functional Software, Inc. d/b/a Sentry — receives crash and
performance events. We configure the SDK with
sendDefaultPii=false, so events are tagged with your Firebase user ID for triage but contain no email address or other directly identifying personal data. - PostHog, Inc. — receives product analytics events (screen views, feature usage, lifecycle events) associated with your LiftLogic account identifier, hosted on PostHog's US Cloud. Used solely to understand and improve the product; never shared with advertisers. See section 3.8.
7.5 AI features
- OpenAI, L.L.C. — receives the messages, prompts, and image attachments you send to Kai, our equipment recognizer, our food-photo nutrition feature, our workout-log parser, and our AI program builder, plus the context needed to answer (for Kai this includes your profile basics, recent workout history, and personal records). OpenAI processes the request and returns a response. Under our API agreement with OpenAI, your inputs and outputs are not used to train OpenAI or third-party models. On devices that support it, some short requests are answered by an on-device model instead and never leave your phone. See section 17.
7.6 Wearable platforms (only if you connect them)
When you connect a third-party wearable, our backend exchanges data with that vendor's API using OAuth credentials you have authorized. The full vendor list is in section 16.
7.7 Other recipients
- Google LLC (YouTube) — exercise demonstration videos are played through an embedded YouTube player. When you play a video, YouTube receives your IP address and standard playback telemetry under Google's own privacy policy. No workout or health data is shared with YouTube.
- Trainers or clients you have connected to, limited to the data you both agree to share (see section 18).
- Legal, regulatory, or governmental authorities where required by law, court order, or a binding request, or where necessary to protect our rights, your safety, or the safety of others.
- Acquirers in a corporate transaction — if we are involved in a merger, acquisition, financing, restructuring, or sale of assets, personal information may be transferred to the acquiring party subject to the same protections described in this Policy.
8. International data transfers
Our primary infrastructure is located in the United States. If you use the Services from outside the United States, your personal information will be transferred to and processed in the United States and in other jurisdictions where our service providers operate.
For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses ("SCCs"), the UK Addendum to the SCCs, and equivalent safeguards offered by our processors (including Google Cloud's, Stripe's, RevenueCat's, OpenAI's, PostHog's, and Sentry's published Data Processing Addenda). You can request a copy of the relevant SCCs by emailing [email protected].
9. How long we keep information
We keep personal information only as long as we need it for the purposes described in this Policy or as required by law. The table below summarizes our standard retention windows.
| Category | Retention |
|---|---|
| Account profile, workouts, custom exercises, uploaded media | For the life of your account. Deleted (with a server-side cascade across our databases) within 30 days of you initiating account deletion. |
| Encrypted Firestore + Cloud Storage backups | Up to 30 days after deletion (rolling backup window), then purged. |
| Firebase Analytics events | Up to 14 months, per Firebase's default retention policy. |
| PostHog product analytics events | Per PostHog Cloud's standard retention. You can request deletion of the events associated with your account identifier at any time via [email protected]. |
| Crash and performance events (Sentry) | 90 days, per Sentry's default project retention. |
| Email logs (Loops.so) | For the life of your subscription plus the period needed to demonstrate compliance with anti-spam law (typically up to 24 months). |
| OAuth refresh tokens (Apple, wearable vendors) | Encrypted at rest with AES-256-GCM; deleted on account deletion or when you disconnect the integration. |
| Server logs (Cloud Functions, web requests) | Up to 30 days for security and debugging. |
| Stripe / Apple billing records | Retained by Apple or Stripe according to their own retention rules and as required by tax and anti-money-laundering law (typically 7 years). |
10. How we keep information safe
We use technical and organizational measures designed to protect your information. These include:
- Encryption in transit (TLS 1.2+) for all client-server traffic.
- Encryption at rest for Firestore, Cloud Storage, and our application databases (Google-managed keys).
- Application-layer AES-256-GCM encryption for your Apple Sign-In refresh token; the encryption key lives in Google Secret Manager and is only accessible to our Cloud Functions runtime.
- Firebase Security Rules enforced server-side on every read and write so a user can only see their own data (and, for trainers/clients, the data their connection explicitly authorizes).
- Firebase App Check + Apple App Attest to verify requests come from a genuine LiftLogic App on an unmodified device.
- Secrets (Stripe, OpenAI, RevenueCat, wearable OAuth credentials, etc.) held in Google Secret Manager — never embedded in the iOS bundle, never returned to clients.
- Principle of least privilege for our team's access to backend systems, with audit logging and multi-factor authentication required on all administrative accounts.
No security measure is perfect. If we become aware of a breach that affects your personal information, we will notify you and any required regulator as required by applicable law (e.g., GDPR Art. 33–34, US state breach-notification statutes).
11. Information from minors
The Services are intended for users aged 13 and older. If you are under 18, you may only use the Services with the involvement and consent of a parent or legal guardian, who must accept the Terms of Service on your behalf. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and you believe a child under 13 has provided us with personal information, please contact [email protected]. We will delete that information promptly upon verification.
12. Your privacy rights
Depending on where you live, you may have some or all of the following rights with respect to your personal information. We honor these rights for all users, regardless of jurisdiction, except where law requires us to retain information.
- Right of access / portability. You can request a full copy of your personal information directly from inside the App: Settings → Privacy → Request data export. We will generate a downloadable ZIP archive containing your profile, workouts, and other user-scoped data in a structured, machine-readable format (JSON).
- Right to deletion. You can permanently delete your account from inside the App: Settings → Account → Delete account. This triggers a server-side cascade that removes your data from our Firestore database, Cloud Storage, RevenueCat, Stripe customer record, and any connected wearable OAuth grants; it also revokes your Apple Sign-In token with Apple as required by Apple App Store Review Guideline 5.1.1(v).
- Right to correction. You can update most of your information (name, email, profile, height, weight, workout history) from Settings inside the App. For corrections you can't make yourself, email [email protected].
- Right to object / restrict processing. You may object to or ask us to restrict certain processing — for example, marketing email (use the unsubscribe link), AI features (don't message Kai or upload equipment photos), or wearable syncing (disconnect the vendor in Settings).
- Right to withdraw consent. Where we rely on your consent (HealthKit, wearable connections, optional analytics, marketing email), you can withdraw it at any time without affecting the lawfulness of prior processing.
- Right to opt out of marketing. Every marketing email includes an unsubscribe link. You can also toggle marketing email off globally by emailing [email protected]. Transactional email (receipts, security alerts, account-deletion confirmations) cannot be turned off while you maintain an account.
- Right to non-discrimination. We will not deny, charge different prices for, or provide a different quality of service because you exercised your privacy rights.
- Right to complain to a supervisory authority. If you are in the EEA, UK, or Switzerland, you may lodge a complaint with your local data-protection authority. We would appreciate the chance to address your concerns first — please email [email protected].
To submit a request that you can't fulfill from inside the App, email [email protected] from the address associated with your account. We will verify your identity before fulfilling a request, and we will respond within the timelines required by applicable law (typically 45 days under US state laws, one month under GDPR / UK GDPR).
You may use an authorized agent to submit a request on your behalf where allowed by law. We may ask the agent to provide proof of authorization and may verify your identity directly.
13. Cookies and tracking
The iOS App does not use web cookies, and it does not include any advertising SDK that displays third-party ads. The App does show Apple's App Tracking Transparency prompt: if you allow tracking, the device advertising identifier (IDFA) is used only to measure the performance of our own advertising campaigns, as described in section 3.8. If you decline, the identifier is never accessed and no cross-app tracking takes place.
The liftlogic.fit website uses a limited set of cookies and similar technologies. For details — including the cookie names, providers, and how to control them — please see our Cookie Notice.
14. Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" (DNT) or "Global Privacy Control" (GPC) signal. We do not sell or share personal information for cross-context behavioral advertising, so a "do not sell or share" signal has no operative effect — there is nothing to opt out of. We treat GPC as a valid opt-out signal under the CCPA / CPRA where applicable and honor it as such.
15. Health & fitness data (Apple HealthKit)
If you grant LiftLogic permission to read or write Apple Health data, the following applies. HealthKit access is always optional — the App's core features work without it.
15.1 What we read
We request read access to the data types below, grouped by purpose. You can grant or deny each group individually on the HealthKit permission sheet, and you can change your selections at any time in iOS Settings → Privacy & Security → Health → LiftLogic.
- Workouts (including workout routes) — to show your training history and avoid double-logging sessions you have already recorded with another app.
- Sleep analysis — to recommend rest days when you have slept poorly.
- Heart rate, heart-rate variability (HRV), resting heart rate — for recovery and effort scoring.
- Body mass — to track weight trends over time.
- Active energy, basal energy, step count, exercise minutes — to round out your daily activity picture.
- Oxygen saturation, flights climbed, cycling power, swimming stroke count — surfaced inside workout details when your tracker provides them.
15.2 What we write
- Workouts that you complete in the App, so they appear in the Apple Health app and any other app you have connected to HealthKit.
- Body mass entries you log in the App.
15.3 How HealthKit data is handled
- HealthKit data is read directly from your device. Some of it (e.g., workouts you complete in the App) is mirrored to our backend so the watch, widget, and other devices on your account stay in sync. Only the data necessary for the feature you are using is uploaded.
- We never use HealthKit data for advertising or marketing.
- We never sell HealthKit data.
- We never use HealthKit data to train machine-learning models, ours or anyone else's.
- We do not share HealthKit data with any data broker or marketing platform.
- If you revoke our HealthKit access from iOS Settings, we stop reading immediately. To delete HealthKit-derived data already stored on our backend, use the in-App data export and account-deletion controls described in section 12.
16. Wearable integrations
Connecting a wearable is always optional. You initiate the connection from Settings → Connections → Wearables. The first time you connect a vendor, you complete that vendor's OAuth authorization screen, which lists the exact scopes we request. You can disconnect at any time from the same settings screen, which revokes our access token with the vendor and stops further syncing.
We currently integrate with the following platforms:
| Vendor | What we receive |
|---|---|
| WHOOP | Recovery, sleep, strain, and workouts from your WHOOP band. |
| Oura Ring | Readiness, sleep stages, HRV, and workouts. |
| Google Health | Sleep, HRV, weight, and workouts from any Google-Health-connected device — including Pixel Watch and Fitbit (Fitbit access is read via Google Health rather than the Fitbit Web API, which is being retired). |
| Garmin | Sleep, recovery, Body Battery, and workouts. |
| Polar | Nightly Recharge, sleep, training load, and exercises. |
| COROS | Activities, sleep, and training load. |
| Suunto | Workouts and 24/7 activity. |
| Withings | Weight, body composition, sleep, and heart rate. |
| Strava | Runs, rides, and other activities. |
| Wahoo | Workouts, rides, and runs. |
| Dexcom | Continuous-glucose-monitor readings (only if you connect a Dexcom CGM). |
We do not push any of your LiftLogic data back to most of these vendors; the data flow is read-only from the vendor into LiftLogic. Each vendor is an independent controller for the data you generate on their platform — their own privacy policy governs what they collect from their device. We do not control how those vendors process or retain your data on their side.
We store the wearable's OAuth refresh token encrypted at rest. When you delete your account or disconnect a vendor, we attempt to call that vendor's revoke / disconnect endpoint and, on success, remove the token from our database. If the revoke call fails, we queue it for automatic retry and you remain in control by also revoking access inside the vendor's own app or developer portal.
17. AI features
LiftLogic includes optional AI-powered features. Each one sends limited data to OpenAI, L.L.C., our inference provider, so OpenAI's models can generate a response that we relay back to you.
- Kai, our in-app assistant. We send your message, your recent training context (e.g., current program, last few workouts, personal records, profile basics like name and goals), and relevant prior turns of the conversation.
- Equipment recognizer. When you take a photo of gym equipment, we send the image to OpenAI's vision model so the App can identify what is in the photo and add it to your equipment list.
- Food-photo nutrition analysis. When you photograph a meal or food label, we send the image to OpenAI's vision model to estimate the food and its macros; nutrition facts may also be looked up against the Open Food Facts public database. Results are saved to your food diary only if you confirm them.
- Workout-log parser. When you type, dictate, or paste a freeform workout summary, we send the text to OpenAI to extract a structured list of exercises, sets, reps, and weights for review and saving.
- AI program builder. When you ask for a generated training program, we send your goals, experience level, and available equipment to OpenAI to draft the program.
Important properties of these features:
- Under our OpenAI API agreement, your inputs and the model's outputs are not used to train OpenAI or third-party models.
- OpenAI may retain prompts for a short period (currently up to 30 days) for abuse-detection purposes before deletion. Refer to OpenAI's own privacy and data-usage policies for full detail.
- We do not send your HealthKit-only data (e.g., HRV readings) to OpenAI unless you have asked Kai a question that requires that context.
- On devices that support it, some short requests (for example quick Kai questions or workout-log entries) are answered by an on-device model instead — those requests never leave your phone and are not sent to OpenAI.
- All of these features are optional. You can choose not to use them; the rest of the App is fully functional without them.
- AI suggestions are not medical, training, or nutritional advice from a licensed professional. Always use your judgment and consult a qualified professional where appropriate.
AI assistant connections (MCP). You can optionally connect your LiftLogic training data to a third-party AI assistant of your choice (for example Claude, ChatGPT, Cursor, or Gemini) through our Model Context Protocol ("MCP") server at mcp.liftlogic.fit. This connection only exists if you create it, and it works as follows:
- Authentication. When you connect, you sign in through WorkOS, Inc., our authentication service provider, which processes your email address and sign-in codes on our behalf solely to verify that you are the owner of the LiftLogic account being connected.
- What the assistant can access: your own training data only — profile basics, workout history, exercise progress, personal records, nutrition entries, journal entries (including your subjective wellbeing scores such as mood, energy, stress, and soreness, and any free-text notes you have written), muscle-utilization stats, and recovery data. Access is read-only: an assistant can never create, change, or delete anything in your account.
- Your direction, their policies. Data retrieved by an assistant is disclosed at your direction to the provider of that assistant (e.g., Anthropic, OpenAI, Google). Once delivered, its handling — including any storage in your conversation history — is governed by that provider's own privacy policy and your agreement with them, not by this Policy.
- Disconnecting. You can revoke a connection at any time from the assistant's own settings. Revoked or expired connections stop all further access. Access is also rate-limited to protect the service.
18. Trainer and client data flow
LiftLogic supports a connection between a personal trainer and a client. The connection is two-sided: it only becomes active after both parties accept it.
- What the trainer sees: the workouts and programs the client has agreed to share, the client's completion history for those programs, basic profile information (name, profile photo), and any direct messages the trainer and client exchange in the App.
- What the client sees: the workouts and programs the trainer assigns, the trainer's name and profile, and the direct-message thread with the trainer.
- What is never shared: raw HealthKit samples (heart-rate stream, HRV readings, sleep stages), wearable-vendor connection state, billing details, password, or any other personal data outside the workout / program / messaging scope.
- How to disconnect: either party can end the trainer-client connection at any time from Settings. On disconnection, prior shared data remains in the receiving party's archive of records they already received, but no new data flows.
Trainers using LiftLogic to bill their own clients act as merchants of record for those transactions and have their own obligations under privacy and consumer-protection laws.
19. Third-party links and services
The App and Site may contain links to third-party websites and services (App Store pages, vendor authorization flows, social-media posts, etc.). Those third parties are governed by their own privacy policies. We are not responsible for the practices of any third party we do not control.
20. Updates to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. If we make material changes, we will notify you by email (to the address on your account) or by an in-App notice at least 30 days before the change takes effect, except where a shorter notice is required by law.
Your continued use of the Services after the effective date of an update means you accept the revised Policy.
21. State-specific and regional disclosures
21.1 California (CCPA / CPRA)
In the 12 months preceding the "Last updated" date above, we collected the following CCPA-defined categories of personal information from California residents:
| CCPA category | Examples in our Service | Sold or shared for cross-context behavioral ads? |
|---|---|---|
| Identifiers | Email, Firebase user ID, push-notification token, IP address | No |
| Customer records | Name, billing status | No |
| Commercial information | Subscription product, purchase history | No |
| Internet / electronic activity | In-App event logs, crash reports, support messages | No |
| Inferences | Workout recommendations, recovery scores | No |
| Sensitive personal information | Health and fitness data, biometric metrics, account credentials | No |
We do not sell personal information and have not done so in the 12 months preceding this Policy. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of consumers under 16.
California residents have the rights described in section 12, including the right to request the categories and specific pieces of personal information we have collected, the right to delete, the right to correct, and the right to limit our use of sensitive personal information to that necessary to provide the Services (which is already our practice).
Shine the Light (California Civil Code § 1798.83). We do not disclose personal information to third parties for those third parties' own direct-marketing purposes.
21.2 Other US states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have rights similar to those described in section 12 under their respective state privacy laws. Washington and Nevada residents have additional rights regarding consumer health data under the My Health My Data Act and equivalents. Submit any state-law request to [email protected].
21.3 European Economic Area, United Kingdom, Switzerland
If you are in the EEA, UK, or Switzerland, our legal bases for processing are described in section 6, and your rights (including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent) are described in section 12. You also have the right to lodge a complaint with your local supervisory authority. Where required, we transfer data to the United States under the Standard Contractual Clauses or equivalent safeguards (section 8).
22. Contact us
For any privacy question, data-subject request, or complaint:
Email [email protected] or [email protected].
Mail: Havasi Holding LLC, 7533 S Center View St, Ste N, West Jordan, UT 84084, United States.