Consumer Health Data Privacy Notice
SetLift LLC
Effective September 23, 2026 · Last updated September 23, 2026
This notice supplements our Privacy Policy and is provided under Washington's My Health My Data Act, Nevada's SB 370, and the consumer health data provisions of the Connecticut Data Privacy Act. It describes how SetLift handles information about your body and your physical activity. If you are a resident of one of those states, the rights described here are yours by law. We extend the same practices to all users regardless of where you live.
1. What we treat as consumer health data
These laws define "consumer health data" broadly, as information linked to you that identifies your past, present, or future physical or mental health status. In SetLift, that means:
- Body measurements over time: bodyweight, body fat, goal weight, steps, sleep, exercise minutes, water intake, resting heart rate, heart rate variability, height, waist and any other body metrics you record. These may also be read from Apple Health if you switch that on; see section 3.
- Active injuries you tell us about so programming can work around them
- Progress photos: photographs of your body
- Date of birth, gender, and activity level
- Training goals and nutritional focus
- Nutrition: the foods you log with their calories and nutrients, your daily totals, and nutrition targets set by you or your coach
- Logged workouts: exercises, loads, sets, reps, duration, and timestamps, which together describe your physical capability and activity
- Coach notes and messages to the extent they discuss your health, injuries, or physical condition
2. Why we collect it
We collect consumer health data for one reason: to operate the app you asked us to operate. Specifically, to store and display your training history, to calculate personal records and progress, to generate or adjust programming around your goals and injuries, and to let a coach you have connected with do their job.
We do not collect it for advertising, marketing, profiling, resale, or research.
3. How we collect it
Almost all of it comes from you, directly, through the app. We do not buy health data from data brokers, we do not infer it from third-party sources, and we do not receive it from other companies.
Apple Health is the one exception, and it is off unless you turn it on. If you turn it on in Settings → Apple Health:
- We read your bodyweight, body fat percentage, step count, sleep duration, exercise minutes, water intake, resting heart rate, heart rate variability, height and waist measurement from Apple Health, so a reading from a connected scale or watch does not have to be typed in twice. Apple Health only fills in what you have not recorded yourself: a value you entered is never overwritten. Height fills in your profile only if you have not entered one. Waist is stored with your other body measurements. Apple asks your permission for each category separately, and you can share some and refuse others. This half also requires that you have body data collection switched on.
- We read workouts recorded by other apps or an Apple Watch: the kind of activity, when it started and ended, its distance, and the calories the device measured. Each one is added to your history as an activity, stored the same way as a run you type in. This is what lets a run your watch recorded be attached to a group challenge score. Nothing SetLift itself wrote to Apple Health is read back, and a run you already logged by hand is left alone. If one of those workouts covers a SetLift session you logged at the same time, we do not add a second entry for it: the calories your watch measured are shown on that session instead of the estimate we would otherwise calculate.
- What comes in is treated like anything you typed. A reading Apple Health supplies is stored on your Health tab exactly as the same number entered by hand would be, and that means a coach you have connected with can see it: your weight, body fat, steps, sleep, exercise minutes, water, resting heart rate, heart rate variability, height and waist. Apple Health does not create a separate, more private class of data inside SetLift. Disconnecting from a coach stops it.
- We read nothing else. Not menstrual or reproductive data, not clinical records, and not the second-by-second heart rate or the route of a workout. We only read categories that SetLift has a place to show you.
- We write your finished SetLift workouts, and the activities you log by hand, to Apple Health: the kind of activity, when it started and ended, and an estimated energy burn, so they appear in Fitness and count toward your Activity rings. The energy figure is an estimate calculated from your bodyweight and the length of the session; SetLift does not measure heart rate. If an activity you log is one your watch already recorded, we do not write a second copy of it.
- We write a bodyweight you type into SetLift to Apple Health as well, so your Health record stays current. A weight that came from Apple Health is never written back. Nothing else goes out: your other body measurements, progress photos and notes stay in SetLift.
- We remove only what SetLift itself added, and on two occasions. When your watch turns out to have recorded a workout you also logged in SetLift, we delete SetLift's copy from Apple Health so that hour is recorded once, and keep your watch's, which measured your heart rate. And if you delete a workout in SetLift, we ask whether to remove the copy SetLift saved to Apple Health too. It is removed only if you say yes. Apple does not permit an app to delete anything it did not write, so nothing from your watch or any other app can be removed by SetLift.
Data written to Apple Health lives on your device under your control. You can revoke SetLift's access, or delete what it has written, from the Health app at any time, and turning the setting off in SetLift stops both directions immediately, without removing anything already written.
We never use data obtained from Apple Health for advertising or marketing, we never sell it or disclose it to data brokers, and we do not store it in iCloud.
4. Who we share it with
We share consumer health data only with the processors needed to run the service, and with people and services you deliberately share it with:
| Recipient | What they receive | Why |
|---|---|---|
| Supabase (AWS, Ohio USA) | Stores all of it: metrics, injuries, photos, workout logs, messages | Database and file storage. Contractually bound to process only on our instructions. |
| Google (Gemini API) | The prompt you type when generating a workout, the workout image if you use photo import, and, to generate a workout or program, the names of the exercises you logged in the last 90 days with how many sessions each appeared in, without their weights, reps or dates. If a coach you are connected with asks for a coaching brief about you, a summary of your training that SetLift calculates: session counts and how they compare with your program, volume and training load, the balance of your pushing and pulling work, estimated one-rep maxes, the weights, reps and effort ratings of sets where your effort changed, and the dates of missed and upcoming sessions. Neither ever includes your name, measurements, health numbers, nutrition, injuries, photos or messages. If you type health information into a prompt, it goes to Google. | AI workout generation, and coaching briefs for your coach. We use the paid tier, under which Google does not train models on prompts or responses. |
| Coaches you connect with | Your training data, your nutrition log, and any injuries, metrics, or photos you share within the coaching relationship. Metrics here includes anything Apple Health filled in for you, which is stored and shown just like a number you typed. None of your measurements, daily health numbers, photos or injury notes while Collect Body Data is off. | So they can coach you. Coaches are independent, not SetLift staff. |
| Other users | Only what you deliberately post, send or share as a link, and, if you join a Progression challenge scored with a handicap, the weigh-in you join with and the weigh-ins behind your score (none while Collect Body Data is off) | Groups, messages, shares and challenges you initiate. |
| Strava, only if you connect it | Each workout you post: its name and type, when it started and how long it lasted, and a description of your sets with their weights and reps, your total volume and your heaviest set. Never your measurements, health numbers, nutrition, injuries, photos or messages. | To post your workouts to your own Strava feed, at your direction. Strava handles them under its own privacy policy, and who sees them there follows your Strava settings. |
| Open Food Facts and USDA FoodData Central | The barcode number or search words for a food you look up, sent from our server. Nothing that identifies you, so what you eat is never linked to you there. | To find the nutrition numbers of a food you log. |
| Expo and Apple (notifications), Resend (email) | The text of a notification, which for a message is the sender's name and up to its first 140 characters. If your coach has turned on email alerts, up to the first 200 characters of a message you send them, in that email. | To deliver notifications and message alerts. |
SetLift has never sold consumer health data and has no plans to. Under the My Health My Data Act, selling would require your separate, signed, written authorization, a document distinct from consent. We do not ask for one, because we do not sell.
5. Consent, and how to withdraw it
We collect and share your consumer health data on the basis of your consent, which you give when you choose to enter it. Each category is optional in the sense that you decide whether to provide it: you can use SetLift to log workouts without recording injuries, body metrics, or progress photos.
You can withdraw consent at any time. To do so:
- Turn off Collect Body Data in Settings → Privacy & Data: SetLift stops collecting body measurements, progress photos and injury notes, and stops showing them to a coach or a challenge group
- Delete specific data in the app: remove progress photos, clear body metrics, remove recorded injuries, or delete individual workouts, or use Settings → Privacy & Data → Delete My Body Data to delete all of your body data at once, including the weigh-ins copied into challenges you joined and the parts of coaching briefs built from your body data
- Disconnect from a coach to stop sharing new data with them
- Disconnect Strava in Settings → Integrations to stop workouts going to Strava; workouts already posted stay on Strava until you delete them there
- Delete your account: in Settings → Account → Delete Account, which removes all of it
- Email privacy@setlift.app with the subject line "Withdraw consent" and tell us what you want stopped
Withdrawing consent does not affect processing that already happened, and some features stop working without the underlying data.
6. Your rights
You have the right to:
- Know whether we collect, share, or sell your consumer health data, and to see a list of who we have shared it with
- Access a copy of your consumer health data
- Withdraw consent to its collection and sharing, as described above
- Delete it. When you exercise this right we delete it from our active systems and instruct our processors to do the same. We will tell you if any of it must be retained for a legal reason, and why.
- Appeal if we decline a request. Reply to our response and a different reviewer will consider it. If we deny your appeal you may contact the Washington Attorney General at atg.wa.gov/file-complaint or your own state's Attorney General.
Exercise any of these by emailing privacy@setlift.app. We will verify your identity by confirming control of the account's email address, and respond within 45 days. We will not charge you, and we will not degrade your experience for asking.
7. How we protect it
Consumer health data is encrypted in transit with TLS and at rest by Supabase and AWS. Progress photos, voice messages, and coach verification documents are held in private storage that requires authentication.
There is no end-to-end encryption. SetLift's operator and Supabase are technically able to read progress photos, messages, and coach notes. We do not do so routinely, but we will not claim a protection we have not built.
Your profile photo is stored in a public bucket and can be viewed by anyone with the URL. Progress photos are not, so choose your profile photo accordingly.
8. Employees and contractors who can access it
SetLift is currently run by two people. Access to production data is limited to them and to Supabase, which stores it under a contract that restricts it to processing data on our instructions. The other recipients in Section 4 receive only what that section describes and have no access to the rest. If we add staff or contractors with production access, we will update this notice.
9. How long we keep it
For as long as your account exists, or until you delete the specific data. Deleting your account performs a genuine deletion of your authentication record and associated data. Backups may hold copies for a limited period before ageing out.
10. Changes
We will update this notice when our practices change, revise the date above, and notify you in the app or by email before material changes take effect.
11. Contact
- Email: privacy@setlift.app