Version: USER-PRIVACY-v1.0-2026-07-10 · Effective/updated: July 10, 2026 · Status: Pre-publication counsel review
Lift Like App Inc operates the Lift Like website, checkout, app and services. The service is not directed to anyone under 19 or below the higher local contract age, and there is no guardian route. If we learn we collected an under-19 user's information, we restrict the account and delete information not needed for safety or law.
Information and sources
We collect account, profile, birth date/age-gate, creator selection, onboarding, subscription, entitlement, support, message, report, block, preference, workout, set, meal, nutrition, progress, body, image, audio, prompt, output and other information you provide. We collect device, app, browser, IP, cookie, identifier, session, usage, content-view/follow/save/activity, diagnostic, crash, push, security, attribution and approximate-location information. Sources include Stripe, Supabase, Apple/Google authentication and platforms, creators, referrals, vendors, public sources, complainants and other users.
Stripe directly collects payment credentials. Lift Like receives customer, Checkout Session, subscription, invoice, amount, currency, tax, coupon, refund, dispute and payment-method status information and may receive billing name/address, brand, last four digits and expiry. We do not claim to store full card numbers or bank credentials.
Optional HealthKit permissions allow the app to read authorized steps and active calories and write completed Lift Like workouts. Current code stores app-facing activity summaries and sync state. We do not use HealthKit-derived information for advertising, data brokerage, insurance scoring or creator rankings.
Uses and disclosures
We use information for age gating, account/authentication, onboarding, entitlement, content delivery, personalization, recommendations, payments, renewals, refunds, support, safety, moderation, fraud, analytics, experiments, communications, security and legal compliance. Viewer activity may be visible to creators only through authorized aggregate or interaction features.
Requested photo/audio recognition, transcription and generation can use Google Gemini, Groq and OpenAI through a server proxy. We separate requested delivery; safety/fraud/support; personalization; evaluation; model training; and pricing/enforcement decisions. Current provider retention/training settings and human-review/appeal rules require confirmation before publication. We do not treat broad model training as ordinary improvement where separate consent or licence is required.
We disclose information as necessary to Supabase, Stripe, Vercel, Apple, Google, PostHog where configured, AI/transcription providers, email/push/crash/support/moderation vendors, creators and users through authorized features, contractors and advisers, transaction counterparties, and authorities or affected parties for law, safety, rights and fraud. Providers may process in Canada, the United States and other operating locations, with required contractual and transfer safeguards.
Necessary cookies support sessions and onboarding. Product analytics and experiments operate where configured. Any ATT-triggering tracking, targeted advertising, sale/share, data brokerage, sensitive profiling or email-pixel practice must be disclosed with required controls before activation. You may unsubscribe from marketing while receiving service and legal notices.
Retention, deletion and security
We retain accounts while active and for a reasonable closure period; subscription, tax, refund and dispute records for legal/accounting periods; user content and logs while needed for features; moderation, fraud and security evidence while reasonably needed; and backups until ordinary overwrite. Legal holds override deletion. Exact production periods, backup windows and vendor/AI retention are required before publication.
In-app account deletion must remove or de-identify the account and associated information not legally required, including shared user-generated content where applicable. It is separate from subscription cancellation and refund, and retained transactions, disputes, fraud, security, backups and legal records are not immediately erased. We use risk-appropriate administrative, technical and organizational safeguards, but no system is perfectly secure.
Rights and choices
Depending on location, you may request access, correction, deletion, portability, disclosure information, consent withdrawal, objection/restriction, opt-outs and qualifying automated-decision review or appeal. Exceptions may apply. Device settings control HealthKit, notifications, camera, microphone, photos and ATT. Contact damon@liftlike.app; we verify requests proportionately. Canadians may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial regulator; other regulators may be available locally.
Each policy version is archived with identifier, date and preferably hash. Material changes receive notice and reacknowledgement or consent where required; history is never overwritten.
Lift Like App Inc · 375 University Avenue, Suite 3278, Toronto, Ontario M5G 2J5, Canada · damon@liftlike.app · 416-276-3357 (virtual mailing address; not a walk-in office)
