Consumer Health Data Privacy Notice

SetLift LLC

Effective September 23, 2026 · Last updated September 23, 2026

This notice supplements our Privacy Policy and is provided under Washington's My Health My Data Act, Nevada's SB 370, and the consumer health data provisions of the Connecticut Data Privacy Act. It describes how SetLift handles information about your body and your physical activity. If you are a resident of one of those states, the rights described here are yours by law. We extend the same practices to all users regardless of where you live.

1. What we treat as consumer health data

These laws define "consumer health data" broadly, as information linked to you that identifies your past, present, or future physical or mental health status. In SetLift, that means:

2. Why we collect it

We collect consumer health data for one reason: to operate the app you asked us to operate. Specifically, to store and display your training history, to calculate personal records and progress, to generate or adjust programming around your goals and injuries, and to let a coach you have connected with do their job.

We do not collect it for advertising, marketing, profiling, resale, or research.

3. How we collect it

Almost all of it comes from you, directly, through the app. We do not buy health data from data brokers, we do not infer it from third-party sources, and we do not receive it from other companies.

Apple Health is the one exception, and it is off unless you turn it on. If you turn it on in Settings → Apple Health:

Data written to Apple Health lives on your device under your control. You can revoke SetLift's access, or delete what it has written, from the Health app at any time, and turning the setting off in SetLift stops both directions immediately, without removing anything already written.

We never use data obtained from Apple Health for advertising or marketing, we never sell it or disclose it to data brokers, and we do not store it in iCloud.

4. Who we share it with

We share consumer health data only with the processors needed to run the service, and with people and services you deliberately share it with:

RecipientWhat they receiveWhy
Supabase (AWS, Ohio USA) Stores all of it: metrics, injuries, photos, workout logs, messages Database and file storage. Contractually bound to process only on our instructions.
Google (Gemini API) The prompt you type when generating a workout, the workout image if you use photo import, and, to generate a workout or program, the names of the exercises you logged in the last 90 days with how many sessions each appeared in, without their weights, reps or dates. If a coach you are connected with asks for a coaching brief about you, a summary of your training that SetLift calculates: session counts and how they compare with your program, volume and training load, the balance of your pushing and pulling work, estimated one-rep maxes, the weights, reps and effort ratings of sets where your effort changed, and the dates of missed and upcoming sessions. Neither ever includes your name, measurements, health numbers, nutrition, injuries, photos or messages. If you type health information into a prompt, it goes to Google. AI workout generation, and coaching briefs for your coach. We use the paid tier, under which Google does not train models on prompts or responses.
Coaches you connect with Your training data, your nutrition log, and any injuries, metrics, or photos you share within the coaching relationship. Metrics here includes anything Apple Health filled in for you, which is stored and shown just like a number you typed. None of your measurements, daily health numbers, photos or injury notes while Collect Body Data is off. So they can coach you. Coaches are independent, not SetLift staff.
Other users Only what you deliberately post, send or share as a link, and, if you join a Progression challenge scored with a handicap, the weigh-in you join with and the weigh-ins behind your score (none while Collect Body Data is off) Groups, messages, shares and challenges you initiate.
Strava, only if you connect it Each workout you post: its name and type, when it started and how long it lasted, and a description of your sets with their weights and reps, your total volume and your heaviest set. Never your measurements, health numbers, nutrition, injuries, photos or messages. To post your workouts to your own Strava feed, at your direction. Strava handles them under its own privacy policy, and who sees them there follows your Strava settings.
Open Food Facts and USDA FoodData Central The barcode number or search words for a food you look up, sent from our server. Nothing that identifies you, so what you eat is never linked to you there. To find the nutrition numbers of a food you log.
Expo and Apple (notifications), Resend (email) The text of a notification, which for a message is the sender's name and up to its first 140 characters. If your coach has turned on email alerts, up to the first 200 characters of a message you send them, in that email. To deliver notifications and message alerts.
We do not sell consumer health data

SetLift has never sold consumer health data and has no plans to. Under the My Health My Data Act, selling would require your separate, signed, written authorization, a document distinct from consent. We do not ask for one, because we do not sell.

5. Consent, and how to withdraw it

We collect and share your consumer health data on the basis of your consent, which you give when you choose to enter it. Each category is optional in the sense that you decide whether to provide it: you can use SetLift to log workouts without recording injuries, body metrics, or progress photos.

You can withdraw consent at any time. To do so:

Withdrawing consent does not affect processing that already happened, and some features stop working without the underlying data.

6. Your rights

You have the right to:

Exercise any of these by emailing privacy@setlift.app. We will verify your identity by confirming control of the account's email address, and respond within 45 days. We will not charge you, and we will not degrade your experience for asking.

7. How we protect it

Consumer health data is encrypted in transit with TLS and at rest by Supabase and AWS. Progress photos, voice messages, and coach verification documents are held in private storage that requires authentication.

Two honest limitations

There is no end-to-end encryption. SetLift's operator and Supabase are technically able to read progress photos, messages, and coach notes. We do not do so routinely, but we will not claim a protection we have not built.

Your profile photo is stored in a public bucket and can be viewed by anyone with the URL. Progress photos are not, so choose your profile photo accordingly.

8. Employees and contractors who can access it

SetLift is currently run by two people. Access to production data is limited to them and to Supabase, which stores it under a contract that restricts it to processing data on our instructions. The other recipients in Section 4 receive only what that section describes and have no access to the rest. If we add staff or contractors with production access, we will update this notice.

9. How long we keep it

For as long as your account exists, or until you delete the specific data. Deleting your account performs a genuine deletion of your authentication record and associated data. Backups may hold copies for a limited period before ageing out.

10. Changes

We will update this notice when our practices change, revise the date above, and notify you in the app or by email before material changes take effect.

11. Contact