LiftAxis

Datenschutzerklärung

Zuletzt aktualisiert: 2026-08-12

LiftAxis ist eine local-first Fitness-App. Der Kern funktioniert ohne Account und speichert Trainingsdaten zunächst auf deinem Gerät. Pseudonyme Produktdiagnostik ist standardmäßig ausgeschaltet und wird erst gesendet, wenn du sie in den Einstellungen aktivierst; Cloud-Sync, AI Coach und Apple Health sind ebenfalls optionale Funktionen, deren Verarbeitung unten genau beschrieben ist. Es gibt keine Werbung und kein app-/webseitenübergreifendes Tracking. Diese Erklärung gilt für die App und die Website liftaxis.app.

Verantwortlicher

Verantwortlich für die Datenverarbeitung ist der Anbieter von LiftAxis. Die vollständigen Kontaktdaten findest du im Impressum. Bei Datenschutzfragen erreichst du uns unter liftaxisapp@gmail.com.

Die App: local-first

Workouts, Sätze, Körperwerte, Fortschrittsfotos, Routinen, Ziele, Profil und Einstellungen werden zuerst auf deinem Gerät gespeichert (SQLite / Dateisystem / lokaler Speicher). Fortschrittsfotos und Apple-Health-Rohdaten werden nicht in die LiftAxis-Cloud hochgeladen. Notizen an Workouts, Sätzen und Übungen gehören dagegen zu den Trainingsdaten und werden mitsynchronisiert, sobald du Cloud-Sync aktivierst. Backups exportierst du selbst und entscheidest, wo sie liegen. Nur wenn du optionale Online-Funktionen nutzt, werden die unten genannten, begrenzten Daten verarbeitet.

Website-Warteliste

Wenn du dich auf liftaxis.app in die Warteliste einträgst, verarbeiten wir datensparsam nur die folgenden Daten:

  • E-Mail-Adresse – um dich über den Launch zu informieren.
  • Beta-Wunsch (optional) – ob du für TestFlight/Beta berücksichtigt werden möchtest.
  • Spracheinstellung & Zustimmungsnachweis – Sprache deines Browsers sowie der Text und die Version deiner Einwilligung (DSGVO-Nachweis).

Wir speichern keine IP-Adresse und keinen User-Agent. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO). Wir nutzen ein Double-Opt-in: nach der Anmeldung senden wir genau eine Bestätigungs-E-Mail; ohne Klick auf den Bestätigungslink erhältst du keine weiteren E-Mails. Du kannst sie jederzeit per E-Mail an liftaxisapp@gmail.com widerrufen; wir löschen deinen Eintrag dann. Die Daten werden bei unserem Dienstleister Supabase gespeichert. Es gibt keinen versteckten Newsletter und kein Marketing-Tracking.

Newsletter (App)

Im Sign-in-Screen der App gibt es eine Checkbox für den Produkt- und Launch-Newsletter. Sie ist standardmäßig deaktiviert – du entscheidest aktiv (Opt-in). Bei Aktivierung verarbeiten wir datensparsam nur:

  • E-Mail-Adresse – um dir Produkt- und Launch-Updates zu schicken.
  • Spracheinstellung – für die Sprache der E-Mails.
  • Zustimmungsnachweis – Version und Text deiner Einwilligung (aktuell „app-newsletter-2026-07-v1"), Quelle „app" und Zeitstempel.

Die Daten werden in der Supabase-Tabelle newsletter_signups (EU-Region Frankfurt) gespeichert. Zweck ist ausschließlich der Versand von Produkt- und Launch-Updates (Marketing); Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO). Wir nutzen ein Double-Opt-in: nach der Anmeldung senden wir genau eine Bestätigungs-E-Mail; ohne Klick auf den Bestätigungslink erhältst du keine weiteren E-Mails. Wir speichern keine IP-Adresse und keinen User-Agent. Du kannst jederzeit widerrufen – über den Abmelde-Link in jeder E-Mail oder per Nachricht an liftaxisapp@gmail.com. Löschst du dein Konto, wird dein Newsletter-Eintrag automatisch mitgelöscht.

Produktdiagnostik und optionale Online-Funktionen

  • Pseudonyme Produktdiagnostik (Supabase): Standardmäßig aus. Es wird nichts erfasst oder gesendet, solange du sie nicht in den Einstellungen einschaltest; schaltest du sie wieder aus, wird auch alles noch nicht Gesendete verworfen. Ist sie aktiv, sendet die App begrenzte Nutzungsereignisse mit App-Version, Plattform, Sprache, zufälliger Installations-ID und Sitzungs-ID. Keine Namen, E-Mails, Fotos, Notizen oder Workout-Inhalte. Zweck: App-Funktion und Produktverbesserung; kein Werbetracking und kein Verkauf. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Account: Für AI Coach, Community oder Cloud-Sync kannst du dich per E-Mail anmelden; Cloud-Sync setzt zusätzlich LiftAxis Pro voraus. Supabase verarbeitet die E-Mail zur Authentifizierung und zur Zuordnung deiner optionalen Cloud-Daten. (Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO — Vertragserfüllung)
  • Cloud-Sync (Supabase): Optional und Teil von LiftAxis Pro. Ohne Pro wird nichts synchronisiert. Bist du angemeldet und hast Pro, wird ein Snapshot unterstützter Trainingsdaten hochgeladen — automatisch nach einem abgeschlossenen Training und beim Öffnen der App, höchstens alle 15 Minuten, sowie jederzeit über den Knopf „Jetzt synchronisieren". Den automatischen Teil kannst du unter Konto & Sync abschalten; der Knopf bleibt davon unberührt. Übertragen werden Workouts, Sätze, Übungen, Vorlagen, Gewohnheiten, Ziele, Körperwerte und die Notizen, die du zu Workouts, Sätzen und Übungen erfasst hast. Fortschrittsfotos, Apple-Health-Daten sowie Übungsfavoriten/-verlauf werden nicht per Cloud synchronisiert. (Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO — Vertragserfüllung)
  • Freunde, Gruppen, Leaderboard und geteilte Vorlagen (Supabase): Optional. Mit der Anmeldung wird ein Profil aus deiner Konto-ID angelegt; der Anzeigename bleibt dabei leer, bis du ihn in der App unter Einstellungen › Konto & Cloud-Sync selbst einträgst — wir leiten ihn nie aus deiner E-Mail-Adresse ab. Freundschaften speichern ausschließlich Konto-IDs und den Status — die E-Mail-Adresse, über die du jemanden suchst, wird serverseitig zu einer ID aufgelöst und nicht gespeichert. Gruppen speichern Gruppenname und Einladungscode. Es wird nichts geteilt, bevor du die einmalige Frage nach dem Teilen mit Ja beantwortet hast; lehnst du ab, bleibt alles auf diesem Gerät und du wirst nicht erneut gefragt. Nach deiner Zustimmung wird die Leaderboard-Zeile nach jedem gespeicherten Training automatisch übertragen und enthält Wochen-Aggregate: Anzahl Sessions, Gesamtvolumen, Anzahl persönlicher Rekorde, Streak, Arbeitssätze pro Muskelgruppe und — nur wenn du dein Körpergewicht selbst eingetragen hast — einen auf das Körpergewicht normierten DOTS-Wert. Dieselbe automatische Übertragung sendet außerdem deine Bestleistung je Übung für bis zu 60 Übungen (Übungs-Kennung, geschätztes Ein-Wiederholungs-Maximum, bestes Gewicht und dessen Wiederholungen); daraus entstehen die gemeinsamen Übungen im Profil deiner Freunde. Ein Tippen auf „Boards aktualisieren“ überträgt zusätzlich je Anker-Übung eine Zeile für die 90-Tage-Konsistenz-Boards: Wiederholungen, Sätze, Sessions und eine Kraftschätzung für diese Übung. Schaltest du das Teilen aus, endet all das und das bereits Übertragene wird gelöscht. Geteilte Vorlagen enthalten den Vorlagennamen sowie je Übung deren Kennung und Zielvorgaben (Sätze, Wiederholungen, Gewicht, RPE); der Übungsname wird nicht mitgesendet, bei den mitgelieferten Übungen lässt die Kennung aber auf die Übung schließen — selbst angelegte Übungen tragen eine zufällige Kennung. Eine von dir veröffentlichte Vorlage ist für alle angemeldeten Nutzer sichtbar — zusammen mit deinem Anzeigenamen und der Zahl der Übernahmen; ist sie eine Abwandlung der Vorlage einer anderen Person, wird deren Anzeigename als Ursprung mitgeführt. Challenges speichern Titel, Beschreibung, Metrik, Format, einen optionalen Zielwert, eine optionale Übung, eine Wiederholungseinstellung und den Zeitraum sowie dein Team-Kürzel, falls du eines wählst; der Fortschritt bleibt ein einzelner Zahlenwert. Meldungen speichern den angegebenen Grund als Freitext; der LiftAxis-Betreiber liest ihn zur Entscheidung und löscht ihn spätestens 90 Tage nach Abschluss des Falls. Fotos überträgt keine dieser Funktionen. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Aktivitäts-Feed (Supabase): Optional. Veröffentlichst du ein Workout im Feed, werden Name und Datum des Workouts, Dauer, Gesamtvolumen, Anzahl der Sätze, Anzahl persönlicher Rekorde, ein Session-Score, die beanspruchten Muskelgruppen und die Übungen mit ihren Zielvorgaben übertragen — dazu ein von dir geschriebener Begleittext von bis zu 280 Zeichen. Kommentare und Reaktionen zu Beiträgen werden ebenfalls gespeichert. Du entscheidest pro Beitrag, ob er für niemanden, für deine Freunde oder für eine Gruppe sichtbar ist; voreingestellt ist niemand. Beiträge sind ausschließlich für bestätigte Freunde bzw. Mitglieder der gewählten Gruppe sichtbar, niemals öffentlich. Beiträge, Kommentare und Anzeigenamen durchlaufen einen automatischen Inhaltsfilter, der auch serverseitig erzwungen wird. Fotos und Standortdaten überträgt der Feed nicht. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Blockier- und Stummschaltlisten (Supabase): Blockierst oder schaltest du jemanden stumm, speichern wir die Konto-ID der betroffenen Person und den Zeitpunkt, damit die Entscheidung auch serverseitig durchgesetzt wird. Beide Listen kannst du in der App unter Einstellungen › Datenschutz einsehen und jeden Eintrag dort wieder aufheben. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • In-App-Feedback (Supabase): Nur wenn du im Feedback-Formular etwas absendest. Übertragen werden deine Freitext-Nachricht, die gewählte Kategorie (Fehler, Verbesserung, Wunsch, Design, Sonstiges), die Angabe, ob wir dich zurückkontaktieren dürfen, und — nur wenn du das erlaubst — die E-Mail-Adresse deines Kontos. Zusätzlich kannst du technische Diagnosedaten mitschicken (App-Version, Build-Nummer, Plattform, Betriebssystem-Version und Ausführungsumgebung); dieser Schalter ist voreingestellt an und lässt sich vor dem Absenden ausschalten. Kannst du gerade nicht senden, bleibt die Meldung so lange auf deinem Gerät, bis sie übertragen werden konnte. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Kauf- und Abodaten (Apple / Supabase): Kaufst du LiftAxis Pro, wickelt Apple den Kauf ab. Apple meldet uns anschließend Änderungen am Abo-Status; wir speichern dazu Apples ursprüngliche Transaktions-ID, die Produkt-ID, die Umgebung (Produktion oder Sandbox), den Status (aktiv, abgelaufen, Kulanzzeitraum, Zahlungswiederholung, widerrufen, erstattet), Ablauf- und Widerrufszeitpunkt, ob sich das Abo automatisch verlängert, sowie Art, Untertyp, Kennung und Zeitstempel der letzten Apple-Meldung. Verknüpft ist der Datensatz mit deiner Konto-ID; löschst du dein Konto, wird nur die Verknüpfung entfernt und der Datensatz enthält danach ausschließlich Apples eigene Transaktionskennung. Zahlungsdaten erhalten wir nie. (Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO — Vertragserfüllung)
  • Community Strength Map (Supabase): Optional, standardmäßig aus, einzuschalten unter Einstellungen › Datenschutz. Ist der Schalter an, wird pro Anker-Übung ein Bestwert übertragen, zusammen mit Körpergewicht, Geschlecht und Erfahrungslevel. Nie dein Alter, nie ein Workout, nie eine Notiz. Ein aus Apple Health importiertes Körpergewicht qualifiziert nie — nur ein Gewicht, das du selbst eingetragen hast. Die Zeile einer einzelnen Person ist für niemanden lesbar; sichtbar ist ausschließlich das Aggregat, und Vergleichswerte werden erst ab einer Mindestzahl beitragender Personen gebildet. Du kannst deine Beiträge jederzeit im selben Bildschirm wieder entfernen; die Vergleichsringe funktionieren auch mit ausgeschaltetem Schalter. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Push-Benachrichtigungen (Expo / Apple): Optional. Erlaubst du Mitteilungen und bist angemeldet, wird ein gerätebezogener Push-Token zusammen mit der Sprache des Geräts gespeichert, um dich über Freundschaftsanfragen, Kommentare und Reaktionen zu informieren. Der Token identifiziert das Gerät, nicht dich persönlich; er wird beim Abmelden entfernt. Für die Zustellung übergeben wir Token und Mitteilungstext an den Push-Dienst von Expo, der sie an Apple (APNs) weiterreicht; der Titel enthält dabei den Anzeigenamen der Person, die die Mitteilung ausgelöst hat. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • AI Coach (Supabase / DeepSeek): Nur auf deine Anfrage. Verarbeitet werden minimierte Trainings-Aggregate wie Übungsnamen/-kategorien, Sätze, Wiederholungen, Gewicht, RPE und grobe Recovery-Werte. Stellst du eine Frage im Freitext, wird dieser Text zur Antwortgenerierung mitgesendet — gib dort bitte keine sensiblen personenbezogenen Daten ein. Keine Fotos, Apple-Health-Daten, Namen oder E-Mails werden an das Modell gesendet. Bei der Notes-Import-Bereinigung kann nur nach ausdrücklicher Auswahl der eingefügte Text für diese Anfrage gesendet werden. Lässt du eine eigene Übung per AI einordnen, werden ihr Name und die von dir eingetippte Notiz für diese eine Anfrage mitgesendet. Vor der ersten AI-Anfrage fragt die App in einem eigenen Einwilligungs-Hinweis, der DeepSeek namentlich nennt und die übermittelten Felder auflistet; ohne diese Zustimmung verlässt keine AI-Anfrage das Gerät, und du kannst sie in der App unter Datenschutz jederzeit widerrufen. Die Weiterleitung läuft über unseren eigenen Server, der an DeepSeek ausschließlich den oben beschriebenen Anfragetext übergibt — niemals deine Konto-Kennung, dein Zugangs-Token, deinen Namen oder deine E-Mail-Adresse. DeepSeek erhält damit kein Merkmal, das eine Anfrage mit deinem LiftAxis-Konto verknüpft. DeepSeek verarbeitet die Anfragen außerhalb der EU/des EWR (China); es handelt sich um einen Drittlandtransfer. Für dieses Land liegt kein Angemessenheitsbeschluss der EU-Kommission vor; die Übermittlung stützt sich auf deine ausdrückliche Einwilligung nach Art. 49 Abs. 1 lit. a DSGVO, die du mit dem Opt-in für den AI Coach erteilst. Du kannst den AI Coach jederzeit ungenutzt lassen — alle übrigen Funktionen der App arbeiten ohne ihn. Erfolgreiche Antworttexte und Request-Metadaten können für idempotente Wiederholungen bis zu 30 Tage serverseitig gespeichert werden. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Apple Health: Optional und pro Datentyp freigegeben. LiftAxis kann Körpergewicht, Schritte und aktive Energie lesen sowie — wenn du die Recovery-Auswertung aktivierst — Schlafanalyse, Ruhepuls und Herzfrequenzvariabilität (HRV), und kann abgeschlossene Krafttrainings zurückschreiben. Diese Health-Daten werden ausschließlich auf dem Gerät verarbeitet und weder an Supabase noch an den AI-Anbieter hochgeladen; auch aus Health importierte Körpergewichte bleiben vom Cloud-Sync ausgenommen. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)
  • Absturzdiagnose (Sentry): Standardmäßig aus. Erst wenn du sie in den Einstellungen einschaltest, wird der Absturzberichts-Dienst überhaupt gestartet; ist der Schalter aus, entsteht kein Bericht. (Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO — Einwilligung)

Cloud-Sync, AI Coach und Apple Health lassen sich nicht ohne deine jeweilige Aktion bzw. Einwilligung nutzen.

Eingesetzte Dienstleister: Supabase (EU/Frankfurt — Konto, optionaler Cloud-Sync, Weiterleitung der KI-Anfragen), DeepSeek (KI-Antworten — Verarbeitung in China, außerhalb der EU/des EWR), Resend (transaktionale Anmelde-E-Mails), Cloudflare (Hosting/CDN dieser Website), Expo (Zustelldienst für Push-Benachrichtigungen), Apple (Abwicklung der Käufe im App Store und Zustellung der Push-Benachrichtigungen über APNs), Sentry (EU-gehostete, anonymisierte Absturzdiagnose, nur nach Opt-in) und GitHub (Microsoft, USA — Aufbewahrung der wöchentlichen Sicherungskopie unserer Cloud-Datenbank für 35 Tage; die Kopie wird vor dem Hochladen verschlüsselt, GitHub erhält nur die verschlüsselte Datei und nie den Schlüssel; Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO — berechtigtes Interesse an der Wiederherstellbarkeit des Dienstes; die Übermittlung in die USA stützt sich auf das EU-US Data Privacy Framework, unter dem GitHub zertifiziert ist).

Aufbewahrung

  • Produktdiagnostik: Ereignisse werden 180 Tage nach ihrem Zeitstempel automatisch gelöscht (täglicher Auftrag in der Datenbank).
  • AI-Coach-Anfragen: Antworttext und Request-Metadaten bis zu 30 Tage, danach automatische Löschung.
  • Warteliste und Newsletter: bis zu deinem Widerruf — danach löschen wir den Eintrag.
  • Feed-Beiträge, Begleittexte, Kommentare und Reaktionen: bis du sie oder dein Konto löschst.
  • Leaderboard-Aggregate und Beiträge zur Community Strength Map: bis du sie zurückziehst oder dein Konto löschst.
  • Mitteilungen im Benachrichtigungs-Bereich: gelesene 90 Tage, alle spätestens 180 Tage.
  • Meldungen: spätestens 90 Tage nach Abschluss des Falls; noch offene Meldungen spätestens nach 365 Tagen.
  • In-App-Feedback: bis dein Anliegen erledigt ist, längstens bis zu deinem Löschverlangen.
  • Absturzdiagnose (Sentry): Berichte entstehen nur, solange die Einwilligung aktiv ist; schaltest du sie aus, werden keine weiteren erzeugt.
  • Konto und Cloud-Daten: Nach deiner Löschanfrage innerhalb von 30 Tagen; als gelöscht markierte Sync-Einträge werden 30 Tage nach der Markierung endgültig entfernt.
  • Kauf- und Abodaten: Bei der Kontolöschung wird die Verknüpfung zu deiner Konto-ID entfernt; der verbleibende Datensatz enthält dann nur noch Apples eigene Transaktionskennung.

Deine Rechte

Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch sowie das Recht, dich bei einer Aufsichtsbehörde zu beschweren. Wende dich dafür an liftaxisapp@gmail.com.

Löschung

Lokale Daten kannst du in den Einstellungen löschen. Cloud-Daten kannst du unter „Account & Sync" entfernen; dort kannst du auch die Kontolöschung beantragen. Das Konto und zugehörige Cloud-Daten werden innerhalb von 30 Tagen gelöscht.

Kein medizinischer Rat

LiftAxis ist ein Trainings-Logging-Werkzeug. Recovery- und Readiness-Werte sind Schätzungen aus deinen Trainingsdaten – keine medizinische Beratung, Diagnose oder Behandlung.

Änderungen

Wir können diese Erklärung aktualisieren und passen dann das Datum oben an.

LiftAxis is a local-first fitness app. The core works without an account and stores training data on your device first. Pseudonymous product diagnostics are off by default and are only sent once you turn them on in Settings; Cloud Sync, AI Coach and Apple Health are likewise optional features described precisely below. LiftAxis has no advertising and no cross-app or cross-site tracking. This policy covers both the app and the liftaxis.app website.

Controller

The provider of LiftAxis is responsible for data processing. Full contact details are in the Impressum. For privacy questions, contact liftaxisapp@gmail.com.

The app: local-first

Workouts, sets, body stats, progress photos, routines, goals, profile and settings are stored on your device first. Progress photos and raw Apple Health data are never uploaded to LiftAxis Cloud. Notes on workouts, sets and exercises, by contrast, are part of your training data and are synced once you enable Cloud Sync. You export backups yourself and choose where they live. Only the limited data listed below is processed when online features are used.

Website waitlist

When you join the waitlist on liftaxis.app we process only the minimum data:

  • Email address — to notify you about the launch.
  • Beta preference (optional) — whether you want to be considered for TestFlight/beta.
  • Locale & consent record — your browser language plus the text and version of your consent (DSGVO record).

We store no IP address and no user agent. The legal basis is your consent (Art. 6(1)(a) GDPR). We use double opt-in: after signing up we send exactly one confirmation email, and without clicking the confirmation link you receive no further email. You can withdraw any time by emailing liftaxisapp@gmail.com; we then delete your entry. Data is stored with our processor Supabase. There is no hidden newsletter and no marketing tracking.

Newsletter (app)

The app's sign-in screen has a checkbox for the product and launch newsletter. It is off by default — you opt in actively. If enabled, we process only the minimum data:

  • Email address — to send you product and launch updates.
  • Locale — to send emails in the right language.
  • Consent record — the version and text of your consent (currently "app-newsletter-2026-07-v1"), the source ("app"), and a timestamp.

Data is stored in the Supabase table newsletter_signups (EU region, Frankfurt). The sole purpose is sending product and launch updates (marketing); the legal basis is your consent (Art. 6(1)(a) GDPR). We use double opt-in: after signing up we send exactly one confirmation email, and without clicking the confirmation link you receive no further email. We store no IP address and no user agent. You can withdraw at any time via the unsubscribe link in every email or by emailing liftaxisapp@gmail.com. If you delete your account, your newsletter entry is deleted automatically.

Product diagnostics and optional online features

  • Pseudonymous product diagnostics (Supabase): Off by default. Nothing is collected or sent unless you turn it on in Settings, and turning it off again discards anything not yet sent. While it is on, the app sends limited usage events with app version, platform, locale, a random installation ID, and a session ID. No names, emails, photos, notes, or workout content. Purpose: app functionality and product improvement; never advertising or sale. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Account: You may sign in by email for AI Coach, Community or Cloud Sync; Cloud Sync additionally requires LiftAxis Pro. Supabase processes the email for authentication and to associate optional cloud data with your account. (Legal basis: Art. 6(1)(b) GDPR — performance of a contract)
  • Cloud Sync (Supabase): Optional and part of LiftAxis Pro. Without Pro nothing is synced. Once you are signed in and have Pro, a snapshot of supported data is uploaded — automatically after a finished workout and when you open the app, at most every 15 minutes, and at any time via the "Sync now" button. You can switch the automatic part off under Account & Sync; the button is unaffected. What travels: workouts, sets, exercises, templates, habits, goals, body stats and the notes you wrote on workouts, sets and exercises. Progress photos, Apple Health data, exercise favorites, and picker recency are not cloud-synced. (Legal basis: Art. 6(1)(b) GDPR — performance of a contract)
  • Friends, groups, leaderboard and shared templates (Supabase): Optional. Signing in creates a profile from your account ID; the display name stays empty until you enter one yourself in the app under Settings › Account & Cloud Sync — we never derive it from your email address. Friendships store only account IDs and a status — the email address you search with is resolved to an ID server-side and is not stored. Groups store a group name and an invite code. Nothing is shared until you answer the one-time sharing question with yes; if you decline, everything stays on this device and you are not asked again. Once you have agreed, the leaderboard row is uploaded automatically after every saved workout and contains weekly aggregates: session count, total volume, number of personal records, streak, working sets per muscle group, and — only if you entered your body weight by hand — a bodyweight-normalised DOTS score. That same automatic upload also sends your best lift per exercise for up to 60 exercises (the exercise identifier, an estimated one-rep max, the best weight and its reps); this is what lets a friend's profile show the exercises you have in common. Tapping “Update boards” additionally uploads one row per anchor exercise for the 90-day consistency boards: reps, sets, sessions and a strength estimate for that lift. Turning the sharing switch off stops all of it and deletes what is already on the boards. Shared templates contain the template name plus, per exercise, its identifier and targets (sets, reps, weight, RPE); the exercise name is not sent, though for the built-in catalogue the identifier still reveals which exercise it is — exercises you created yourself carry a random identifier. A template you publish is visible to every signed-in user, together with your display name and how often it was adopted; if it is a fork of somebody else’s template, that person’s display name travels with it as the original author. Challenges store a title, description, metric, format, an optional target value, an optional exercise, a repeat setting and a time range, plus your team label if you pick one; progress is a single number. Reports store the reason you typed as free text; the LiftAxis operator reads it to decide the case and deletes it at the latest 90 days after the case is closed. None of these features transmit photos. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Activity feed (Supabase): Optional. When you post a workout to the feed, we transmit the workout name and date, duration, total volume, set count, number of personal records, a session score, the muscle groups worked, and the exercises with their targets — plus a caption of up to 280 characters that you write. Comments and reactions on posts are stored as well. You choose per post whether it is visible to nobody, to your friends, or to one group; the default is nobody. Posts are visible only to confirmed friends or members of the group you choose, never publicly. Posts, comments and display names pass through an automatic content filter that is also enforced server-side. The feed transmits no photos and no location data. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Block and mute lists (Supabase): When you block or mute someone, we store that person's account id and the time, so the decision is enforced server-side as well. Both lists are visible in the app under Settings › Privacy, and every entry can be undone there. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • In-app feedback (Supabase): Only when you submit the feedback form. We transmit your free-text message, the category you picked (bug, improvement, feature, design, other), whether we may contact you back, and — only if you allow that — your account's email address. You can additionally attach technical diagnostics (app version, build number, platform, OS version and execution environment); that switch is on by default and can be turned off before sending. If you cannot send right now, the report stays on your device until it can be transmitted. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Purchase and subscription data (Apple / Supabase): If you buy LiftAxis Pro, Apple handles the purchase. Apple then reports subscription state changes to us, and we store Apple's original transaction id, the product id, the environment (production or sandbox), the status (active, expired, grace period, billing retry, revoked, refunded), expiry and revocation timestamps, whether the subscription auto-renews, and the type, subtype, id and timestamp of Apple's last notification. The record is linked to your account id; if you delete your account only that link is removed, and the remaining record holds nothing but Apple's own transaction id. We never receive payment details. (Legal basis: Art. 6(1)(b) GDPR — performance of a contract)
  • Community Strength Map (Supabase): Optional, off by default, switched on under Settings › Privacy. While it is on, one best value per anchor lift is uploaded together with body weight, sex and experience level. Never your age, never a workout, never a note. A body weight imported from Apple Health never qualifies — only a weight you entered yourself. No one can read an individual person's row; only the aggregate is ever visible, and comparison values are formed only above a minimum number of contributors. You can remove your contributions again at any time on the same screen; the comparison rings keep working with the switch off. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Push notifications (Expo / Apple): Optional. If you allow notifications and are signed in, a device-specific push token is stored together with the device's language so we can tell you about friend requests, comments and reactions. The token identifies the device, not you personally, and is removed when you sign out. To deliver a notification we hand the token and the message text to Expo's push service, which passes them on to Apple (APNs); the title contains the display name of the person who triggered the notification. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • AI Coach (Supabase / DeepSeek): User-initiated only. It processes minimised training aggregates such as exercise names/categories, sets, reps, weight, RPE, and coarse recovery. If you type a free-text question, that text is sent along to generate the answer — please do not enter sensitive personal data there. Photos, Apple Health data, names, and emails are not sent to the model. Notes Import cleanup sends pasted text only when you explicitly opt in for that request. If you ask AI to classify a custom exercise, the name and the note you typed for it are sent for that one request. Before the first AI request the app shows a separate consent notice that names DeepSeek and lists the fields it will send; without that agreement no AI request leaves the device, and you can withdraw it at any time under Privacy in the app. The relay runs through our own server, which passes DeepSeek nothing but the request text described above — never your account identifier, access token, name or email address. DeepSeek therefore receives no identifier that links a request to your LiftAxis account. DeepSeek processes requests outside the EU/EEA (China); this is a third-country transfer. There is no EU adequacy decision for that country; the transfer relies on your explicit consent under Art. 49(1)(a) GDPR, given with the AI Coach opt-in. You can simply leave the AI Coach unused — every other feature of the app works without it. Successful response text and request metadata may be retained server-side for up to 30 days for idempotent retries. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Apple Health: Optional and permission-based per data type. LiftAxis may read body weight, steps and active energy, plus — if you enable the recovery estimate — sleep analysis, resting heart rate and heart-rate variability (HRV), and may write completed strength workouts back. Health data is processed on-device only and is never uploaded to Supabase or the AI provider; body weights imported from Health are also excluded from Cloud Sync. (Legal basis: Art. 6(1)(a) GDPR — consent)
  • Crash diagnostics (Sentry): Off by default. The crash-reporting service is only started once you turn it on in Settings; with the switch off, no report is created at all. (Legal basis: Art. 6(1)(a) GDPR — consent)

Cloud Sync, AI Coach, and Apple Health require your corresponding action or permission.

Service providers: Supabase (EU/Frankfurt — account, optional cloud sync, AI request relay), DeepSeek (AI answers — processed in China, outside the EU/EEA), Resend (transactional sign-in emails), Cloudflare (hosting/CDN for this site), Expo (push notification delivery service), Apple (App Store purchase handling and push delivery via APNs), Sentry (EU-hosted, anonymised crash diagnostics, opt-in only), and GitHub (Microsoft, USA — keeps the weekly backup copy of our cloud database for 35 days; the copy is encrypted before upload, so GitHub only ever receives the encrypted file and never the key; legal basis: Art. 6(1)(f) GDPR — legitimate interest in being able to restore the service; the transfer to the US relies on the EU-U.S. Data Privacy Framework, under which GitHub is certified).

Retention

  • Product diagnostics: events are deleted automatically 180 days after their timestamp (a daily database job).
  • AI Coach requests: response text and request metadata for up to 30 days, then deleted automatically.
  • Waitlist and newsletter: until you withdraw — we then delete the entry.
  • Feed posts, captions, comments and reactions: until you delete them or your account.
  • Leaderboard aggregates and Community Strength Map contributions: until you withdraw them or delete your account.
  • In-app notifications: read ones for 90 days, all of them for at most 180 days.
  • Reports: at the latest 90 days after the case is closed; reports still open at most 365 days.
  • In-app feedback: until your request is resolved, at the latest until you ask us to delete it.
  • Crash diagnostics (Sentry): reports are only created while consent is active; turning it off means no further reports are produced.
  • Account and cloud data: within 30 days of your deletion request; sync items flagged as deleted are removed permanently 30 days after being flagged.
  • Purchase and subscription data: account deletion removes the link to your account id; the remaining record then holds nothing but Apple's own transaction id.

Your rights

You have the right to access, rectification, erasure, restriction, portability and objection, and to lodge a complaint with a supervisory authority. Contact liftaxisapp@gmail.com.

Deletion

You can delete local data in Settings. Cloud data can be removed under Account & Sync, where you can also request account deletion. The account and associated cloud data are deleted within 30 days.

No medical advice

LiftAxis is a training-logging tool. Recovery and readiness values are estimates from your training data — not medical advice, diagnosis or treatment.

Changes

We may update this policy and will adjust the date above when we do.