LiftNote Support and legal information

Privacy Policy

Last updated:

LiftNote is a workout tracking app. This policy explains the account, workout, and technical information processed when you use the app, its optional AI import, and these public pages.

1. Data controller and contact

LiftNote is operated by Ömer Furkan Bilge, an individual in Türkiye, who is the data controller. For support, privacy, or Turkish personal data protection (KVKK) requests, email support@liftnoteapp.com. Our public website is liftnoteapp.com.

2. How information is collected and used

Information is collected electronically through account forms, your workout entries, import requests, guardian permission forms, and operation of the app and website. If you contact support, we receive your email address and the information you choose to send. These flows support account access, workout records and progress, optional text import, age restrictions, support, and service reliability.

3. Account and authentication

We process your email address, email verification state, date of birth and resulting age/access state, and account and sign-in timestamps. First and last names are optional profile fields. Passwords are processed during registration, sign-in, and reset; the database stores password hashes rather than readable passwords.

Access and refresh tokens keep you signed in. The server stores hashed refresh tokens and their expiry/revocation state, and can retain a device description supplied at sign-in. Email verification and password reset use hashed codes or tokens with expiry, use, and attempt state.

4. Workout information and sharing

We store the programs, training days, custom exercises, exercise alternatives, planned and performed sets, repetitions, weights, RPE (perceived effort), rest targets, and notes you enter. Workout sessions include start/completion times and exercise history. Progress summaries and personal bests are calculated from that history.

If you publish a program for sharing, we store a program snapshot, sharing codes, and import records. Other users with the code can import a copy. Only share content you intend recipients to receive, including any notes in the program.

5. Optional AI workout import

When you request an import, the workout text you paste is sent through LiftNote to OpenAI to turn it into a structured program preview. This feature parses text; it is not an AI coach. Avoid pasting contact details, medical records, or other unnecessary personal information.

LiftNote does not persist the raw pasted text in its database or device storage through this import flow. Text and preview data are held temporarily in memory. A program is stored when you review and save the preview; exercise data is also stored if you explicitly create a custom exercise. Saved program fields can contain information from your source text.

Requests to OpenAI set store:false, disabling storage of the response for later retrieval through the API. This setting does not mean that OpenAI retains no data for any purpose; separate provider controls, including abuse monitoring, can apply.

6. Children and guardian permission

People under 13 are not eligible to create or maintain a usable LiftNote account. Users aged 13–17 can use normal workout tracking, but AI import requires parent or legal guardian permission. Adults do not require this permission. Date of birth is used to determine these restrictions.

For minor AI access, we store the guardian email, request/approval/revocation status and times, language, and permission policy version. Approval and management codes are stored as hashes. Guardians approve or withdraw permission through the emailed management process. Withdrawal stops the minor's AI import access without deleting their workout account or existing consent record. Account deletion removes associated guardian and consent records from the application database.

7. Service providers and processing locations

The cloud deployment is documented in a European region, outside Türkiye, and these external services can involve international processing. This policy does not promise Türkiye-only storage or a particular provider-wide storage location.

8. Diagnostics and public website

The backend records operational information such as request paths, status, duration, diagnostic identifiers, and internal user identifiers where available. Hosting services also process connection/request information needed to serve traffic. Optional Seq integration can collect backend logs when configured.

The mobile app includes configurable Sentry crash/error reporting. When enabled, events can contain app/device context, errors, request metadata, diagnostic identifiers, and the signed-in internal user ID. Default personal-information sending is disabled, and a filter removes sensitive fields such as credentials, request bodies, and workout notes. This is a protective measure, not a guarantee that every event is anonymous.

The current app has no advertising, attribution, or separate product analytics integration. These public pages contain no analytics, tracking scripts, external fonts, or third-party JavaScript, and do not set cookies or use local storage to display their content.

9. Information on your device

Expo SecureStore holds session credentials. AsyncStorage stores preferences, language/translation data, active workout drafts and skipped-exercise state, progress selections, import-guide preferences, and rest-timer state. Some preferences apply to the device rather than an account.

Rest timers can schedule local notifications with your device's permission. Active workout status and timers can appear in iOS Live Activities or supported Android notifications, including on the lock screen. You can manage these features in the app and device settings. They do not require sending workout text to an AI provider.

10. Retention and deletion

Saved records are retained to provide your account and workout history. Removing an individual program, completed workout, or custom exercise can mark it as deleted while retaining its database record; account deletion removes these account-owned records as well. Revoking guardian permission changes the permission state; it does not erase the record. Expiry limits the use of authentication and permission codes and tokens, but does not itself delete their database records.

Deleting your account permanently removes your account, authentication/reset records, guardian consent records, workout programs and history, and your custom exercises from the active application database. Associated program shares and codes stop working. Copies already imported by other users remain in their accounts.

The app signs you out, clears cached user data and saved session credentials, and attempts to remove local workout drafts, account-specific progress selections, and active timer/notification state. Device-wide preferences, such as language and activity settings, may remain. See Delete Account for the steps.

In-app deletion does not itself erase infrastructure backups, previously generated operational logs, provider records, or support correspondence. We do not promise a fixed retention period for those systems here. Contact us about the scope of your deletion or privacy request.

11. Privacy rights and requests

You can contact support@liftnoteapp.com about your personal information, corrections, or deletion. Explain your request and the account concerned; do not send your password or verification codes.

Under KVKK Article 11, within its applicable conditions, you may ask whether and how your data is processed, its purposes and recipients in Türkiye or abroad; request correction or erasure/destruction and notification of those actions to recipients; object to an adverse result based solely on automated analysis; and seek compensation for damage caused by unlawful processing. These rights are distinct from the in-app account deletion feature.

12. Security and changes

LiftNote uses authenticated account operations, password/code/token hashing, and filtering of sensitive diagnostic fields. No software or security measure can guarantee absolute protection. This page's last-updated date identifies the current text; contact us if you have questions about changes or processing.