Privacy Policy
SetLift LLC
Effective September 23, 2026 · Last updated September 23, 2026
SetLift has no analytics, no crash reporting, no advertising, and no trackers of any kind. We do not sell your data and we never will. We collect what the app needs to work, which is your workouts, your profile, and anything you choose to post or send, and nothing else. You can delete your account and everything in it from inside the app at any time.
- Who we are
- What we collect
- What we don't do
- How we use your data
- AI features
- Who we share data with
- Where your data lives
- Security, and its limits
- Who else can see your data
- How long we keep it
- Your rights and choices
- U.S. state privacy rights
- International users
- Children and teens
- Changes to this policy
- Contact us
1. Who we are
SetLift ("SetLift", "we", "us") is a workout tracking and coaching application operated by SetLift LLC, a California limited liability company. This policy explains what data the SetLift mobile application and this website collect, why, and what control you have over it.
This policy applies to the SetLift app and setlift.app. It does not apply to third-party services you reach from within SetLift, which have their own policies.
2. What we collect
Account information
When you create an account we collect your email address, a display name, and the date your account was created. If you sign up with email and password, we send a six-digit verification code to confirm the address; the same mechanism is used for password resets. If you sign in with Google, Google confirms your email address to us and we skip our own verification step. If you sign in with Apple, Apple gives us your email address, or a private relay address if you choose Hide My Email, and your name the first time you sign in, if you choose to share it.
You may optionally add a phone number. It is typed by you and we do not verify it. Other users cannot find you by phone number unless you switch that on: phone search is off by default, and you can turn it on or back off in your settings at any time.
Profile and fitness information
During onboarding and in your profile settings, you provide:
- Date of birth: asked when you create an account, to confirm you are old enough to use SetLift (see Children and teens), and used to inform training recommendations such as heart-rate ranges. Optional for accounts created before September 20, 2026
- Gender, activity level, and training goals
- Active injuries, so programming can work around them
- Equipment access and nutritional focus
- Goal weight and body metrics recorded over time
Some of this is information about your body and your health. We treat it accordingly, and we describe your specific rights over it in the Consumer Health Data Privacy Notice.
Apple Health
SetLift can connect to Apple Health. It is off until you turn it on, in Settings → Apple Health, and you can turn it off again at any time.
- What we read: your bodyweight, body fat percentage, step count, sleep duration, exercise minutes, water intake, resting heart rate, heart rate variability, height and waist measurement, so a reading from a connected scale or watch does not have to be entered twice. These are the same measurements SetLift already lets you type in, and Apple Health only fills in what you have not recorded yourself: a value you entered is never overwritten. Height fills in your profile only if you have not entered one, and waist is stored with your other body measurements. We also read workouts recorded by other apps or an Apple Watch: the kind of activity, when it started and ended, its distance, and the calories the device measured. Each one is added to your history as an activity, stored the same way as a run you type in, so it can be attached to a group challenge score. Nothing SetLift itself wrote to Apple Health is read back, and a run you already logged by hand is left alone. If one of those workouts covers a SetLift session you logged at the same time, which is what happens when you wear a watch through a workout, we do not add it as a second entry: we take the calories the watch measured and show them on that session in place of our own estimate. We do not read any category of Health data that SetLift has no place to show you. Apple asks your permission for each category separately, and you can share some and refuse others.
- What we write: your finished SetLift workouts, and activities you log by hand such as a run or a pickup game: the kind of activity, when it started and ended, and an estimated energy burn, so they appear in Fitness and count toward your Activity rings. That estimate is calculated from your bodyweight and how long the session lasted; SetLift does not measure heart rate. If an activity you log is one your watch already recorded, we do not write a second copy of it. If you type a bodyweight into SetLift, we save it to Apple Health as well, so your Health record stays current; a weight that came from Apple Health is never written back. We write nothing else to Apple Health: your other body measurements, photos and notes stay in SetLift.
- What we remove: only ever something SetLift itself added, and on two occasions. When your watch turns out to have recorded a workout you also logged in SetLift, we delete our own copy of it from Apple Health so the same hour is not recorded twice, and keep the watch's, which measured your heart rate. And if you delete a workout in SetLift, we ask whether to remove the copy SetLift saved to Apple Health too; it is removed only if you say yes. Apple does not permit an app to delete anything it did not write, so a recording from your watch or any other app cannot be removed by SetLift.
Where it goes once it is in SetLift: a reading from Apple Health is stored and treated exactly like the same number typed in by hand, which means a coach you have connected with can see it (see section 9). Nothing about it is shared more widely than that.
We never use data obtained from Apple Health for advertising or marketing, we never sell it or disclose it to data brokers, and we do not store it in iCloud. You can revoke SetLift's access, or delete anything it has written, from the Health app at any time.
Strava
You can connect SetLift to your own Strava account in Settings → Integrations, so the workouts you finish appear on your Strava feed. It is off until you connect it, and it only works in one direction: SetLift asks Strava for permission to upload activities and nothing else, and never reads your activities, your feed or your profile from Strava.
- What we send: each workout you finish while Post workouts to Strava is on, or one you choose to post from its own page: its name and type, when it started and how long it lasted, and a description listing your total sets and volume, your heaviest set, and each exercise's working sets with their weights and reps. Nothing else goes to Strava: not your body measurements, health numbers, nutrition, photos, notes or messages.
- What we keep: your Strava athlete ID and name, so the app can show which account is connected; the access keys Strava issues, which only our server can read and your phone never holds; and the ID of each activity we posted, so a workout is never posted twice.
- Once a workout is on Strava, Strava's privacy settings and privacy policy govern it, and who can see it depends on the visibility you have chosen in Strava. Deleting a workout in SetLift does not remove it from Strava; delete it there.
- To stop: turn off Post workouts to Strava to stop new workouts going automatically. Disconnecting in Settings → Integrations, or revoking SetLift in your Strava settings, deletes the access keys and stops all posting.
Photos, video, and audio
- Profile photo: if you upload one, it is stored in a public storage bucket. This means anyone who has or guesses the file's URL can view it, whether or not they use SetLift. Please treat your profile photo as public. See Security.
- Progress photos: these are photos of your body, stored in a private bucket that requires authentication to access. They are not shown to other users unless you deliberately share them.
- Form videos: video you record or select to review or share your lifting technique.
- Exercise videos and images you upload: a video or picture you add to an exercise you created, or that a coach adds to their exercise library, is stored on Cloudflare R2 and served from a web address that does not require signing in. Anyone who has that address can open it, so treat it the way you would your profile photo.
- Voice messages: audio you record to send to a coach or client, stored in a private bucket.
- Coach verification materials: if you apply to be a coach on SetLift, we collect your name, contact email, certifying body and certification number, a description of your experience, a link to a public profile or website, and a selfie, which is stored in a private bucket and deleted as soon as your application has been reviewed. We do not collect or store a government identity document.
Workout data
The core of the app. We store your routines, logged workouts (exercise, sets, reps, weight, duration, and timestamps), calendar events, programs and program enrolments, exercise categories, per-exercise notes, saved blocks, and templates. Personal records are calculated from your logs rather than stored separately. If you import your history from a file exported by another app, such as Strong, Hevy or Fitbod, the file is read on your phone and the workouts in it are saved to your account like ones you logged in SetLift.
Nutrition
If you log what you eat, we store each food you log (its name, brand, serving and nutrition numbers, and the day and meal), your daily totals, and any nutrition targets you or your coach set. When you scan a barcode or search for a food, the barcode number or the words you typed go from our server to Open Food Facts or USDA FoodData Central, the two public food databases SetLift looks foods up in. Your phone reads the barcode itself; no picture is taken or kept. The databases never see your name, your account or your IP address, because the request comes from our server, not from your phone. A product found this way is kept in a shared list of products so the next scan of it is faster; that list holds the product only, never who scanned it. If you correct a product's numbers, the correction is saved to your account alone and is never shown to anyone else.
Social and messaging data
If you use SetLift's social features we store your groups and the posts, comments, and reactions within them; direct messages; notifications; workouts and programs you share; your recent contacts; and coach–client relationships. Coaches can write private notes about their clients, which are visible to the coach and not to the client.
Liability agreement: if you connect with a coach and choose to sign a liability or assumption-of-risk agreement with them, we store your typed full legal name, the exact text of the agreement you signed, and the date and time you signed it.
By default, other users can find you by searching for your email address. They cannot find you by phone number unless you deliberately turn phone search on.
Safety and moderation data
When you report a post, comment or conversation we store the report: who reported it, who it was about, the reason chosen, and a copy of the reported content so we can review it after the fact even if it is later edited or deleted. Group posts and comments are also checked automatically for hate speech and explicit sexual content, and a match is queued for our review in the same way; this check never blocks or alters what you post. We store the list of people you have blocked. Reports are readable by SetLift administrators and by the person who filed the report; we do not tell the person reported who reported them.
Device permissions
SetLift asks for access to your photo library (for form videos and progress photos), your camera (for progress photos, for recording form videos, for scanning a food barcode, and for the verification selfie if you apply to be a verified coach), your microphone (for voice messages, for the sound on form videos you record, and for dictating notes), and speech recognition (to turn a dictated note into text). Each is requested only at the point you use that feature. iOS also asks before SetLift can send you notifications. You can decline or revoke any of these in iOS Settings; the rest of the app continues to work.
Dictation is transcribed on your device. SetLift asks iOS for on-device recognition, so the audio never leaves your phone: it is not sent to Apple, and it is never sent to us. We receive only the text you choose to keep. When iOS asks for this permission it shows its own standard wording about speech data being sent to Apple. That sentence is Apple’s, shown in every app that requests speech recognition, and it describes the server-based transcription that SetLift does not use.
Notifications reach your phone through Expo's push service and Apple's. A message notification shows the sender's name and up to the first 140 characters of the message, so anyone who can see your Lock Screen may see it too; iOS Settings lets you hide previews. You can turn each kind of notification off in Settings → Notifications.
3. What we don't do
This section exists because it is unusually short in our case and we would rather be specific than vague.
- No analytics. SetLift contains no analytics SDK. Not Firebase, Amplitude, Mixpanel, PostHog, Segment, or anything comparable.
- No crash reporting. No Sentry, no Crashlytics. We do not receive automatic reports about your device or your session.
- No advertising and no ad identifiers. We do not serve ads, we do not use the IDFA, and we do not build advertising profiles.
- No behavioural tracking. We do not log what screens you visit or how you move through the app.
- No selling or sharing for advertising. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.
- No use of your health or fitness data for marketing or data mining.
4. How we use your data
We use the data described above only to:
- Operate the app: store and display your workouts, programs, and progress
- Authenticate you and keep your account secure
- Generate workouts and programs when you ask us to (see AI features)
- Write a coaching brief about your training when a coach you are connected with asks for one (see AI features)
- Deliver messages, notifications, and shared content between you and other users you have connected with
- Let coaches you have connected with view the training data they need to coach you
- Look up the foods you scan or search for (see Nutrition)
- Post your finished workouts to Strava, if you connect it (see Strava)
- Process in-app purchases and keep track of whether your account has SetLift Pro
- Send email: verification codes, password resets, account notices, and the alerts a coach chooses to receive by email about their clients and their messages
- Verify coach credentials
- Respond to your support requests
- Comply with law and enforce our Terms of Service
We do not use your data for any purpose beyond these without asking you first.
5. AI features
SetLift uses the Google Gemini API to generate workouts and programs, to import routines, and to write coaching briefs for coaches. When you generate a workout or program or import a routine:
- Your typed prompt is sent to Google
- If you import a routine from a photo, the image of that workout is sent to Google
- When you generate a workout or program, the names of the exercises you have logged in the last 90 days, and how many sessions each one appeared in. This is what lets the generator work out which equipment you actually train with. Names and counts only, never the weights, reps or dates you recorded
We use Gemini's paid API tier. Under Google's terms for paid services, Google does not use prompts or responses submitted through the paid tier to train its models. Google's handling of this data is governed by the Gemini API Additional Terms of Service and the Google Cloud Privacy Notice, which we encourage you to read rather than rely on our summary.
Coaching briefs. A coach you are connected with can ask SetLift for a short brief about your training before a check-in. When they do, SetLift works out a summary of your training and sends that summary to Google: how many sessions you logged and how that compares with your program, your total volume and training load, the balance of your pushing and pulling work, your estimated one-rep maxes and where they are heading, the weights, reps and effort ratings of sets where your effort changed, the dates of scheduled sessions you missed and of your next one, and what the previous brief suggested. It does not send your name, your messages or check-in answers, your body measurements or daily health numbers, your nutrition, or your injury notes. SetLift's own code reads those (your body data only while Collect Body Data is on) and shows your coach what it finds, without sending them to Google. Each brief is saved so the next one can say what changed, and only the coach who asked for it can open it, and only while you are connected.
We do not send your progress photos, voice messages, direct messages, or body measurements to Google. When you generate a workout or program, we send from your workout logs only the exercise names and session counts described above, never the weights, reps or dates you recorded. A coaching brief sends the training summary described above. Neither sends your logs themselves.
Workouts and programs generated by SetLift's AI features are produced automatically and are not reviewed by a medical professional or certified trainer before you see them. See our health and fitness disclaimer.
6. Who we share data with
We share data with a small number of service providers who process it on our behalf, under contract, for the purposes listed. We do not sell data to anyone.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Essentially all app data: account, profile, workouts, messages, photos, audio | AWS us-east-2, Ohio, USA |
| Google (Gemini API) | AI workout and program generation, routine import, coaching briefs | Your typed prompt; for photo import, the workout image; for a coaching brief, the training summary described in section 5 | Google infrastructure |
| Resend | Email delivery | Your email address and the contents of the email sent to you. For a coach who has turned on message alerts, that includes up to the first 200 characters of a client's message | USA |
| Cloudflare R2 | Storage and delivery of exercise videos, animations and images, including ones you upload | Videos and images you upload for exercises; your IP address when your device loads one | Cloudflare global network |
| Expo | Delivers push notifications, through Apple's push service, and app updates | Your device's push token and the text of each notification; when the app checks for an update, your IP address and a random ID for that installation | USA |
| RevenueCat | Manages in-app purchases and subscriptions | Your SetLift account ID and your App Store purchase and subscription records. Payment details stay with Apple and never reach SetLift or RevenueCat | USA |
Food databases. When you scan a barcode or search for a food, our server looks it up in Open Food Facts and USDA FoodData Central. They receive the barcode number or the words you searched for, and nothing that identifies you: not your name, your account or your IP address.
Services you connect or open yourself. Two more companies receive data only when you use a feature that reaches them, and handle it under their own policies rather than on our behalf: Strava, if you connect it (see Strava), and YouTube, when you play an exercise demonstration video, which loads from YouTube and lets it see your IP address and set cookies. What you share to another app, such as Instagram, is covered in section 9.
We may also disclose data if we are legally required to, for example in response to a valid subpoena or court order, or where we believe in good faith that disclosure is necessary to prevent imminent harm. If SetLift is acquired or merges with another company, your data may transfer as part of that transaction; we will tell you before it does and before any new privacy policy applies to it.
7. Where your data lives
SetLift's primary data store is Supabase, running on Amazon Web Services in the us-east-2 region (Ohio, United States). Exercise videos, animations and images, including ones you upload, are stored on Cloudflare R2 and served from Cloudflare's global network. If you use SetLift from outside the United States, your data is transferred to and processed in the United States.
8. Security, and its limits
Your data is encrypted in transit using TLS, and encrypted at rest by Supabase and AWS. Access to production systems is restricted.
We would rather tell you the limits plainly than let you assume protections that are not there:
- There is no end-to-end encryption. SetLift's operator and Supabase are technically capable of reading your progress photos, voice messages, direct messages, and the private notes coaches write about clients. We do not do this as a matter of routine, but the encryption we use does not make it impossible.
- Your profile photo is stored in a public bucket. Anyone who has the file's URL can open it without signing in to SetLift. Do not use a profile photo you would not be comfortable being public.
- Session tokens are stored in the device's app storage (AsyncStorage) rather than the iOS Keychain. This is a deliberate implementation choice. It means your session token has less operating-system-level protection than Keychain storage would provide, which matters most if your unlocked device is accessed by someone else.
- No method of transmission or storage is completely secure. We cannot guarantee absolute security.
9. Who else can see your data
Beyond service providers, other people may see your data in the ordinary course of using SetLift:
- Coaches you connect with can see the training data, messages, and any progress photos or videos you share with them within the coaching relationship, and whether you have signed a liability agreement with them, and its contents. That includes your height and the body measurements and daily health numbers on your Health tab, and it makes no difference whether you typed those in or Apple Health filled them in for you: a weight from your scale, and your steps, sleep, resting heart rate and heart rate variability, are visible to a coach you are connected to exactly as a number you entered would be. Disconnecting from a coach stops it. So does turning off Collect Body Data in Settings → Privacy & Data: while it is off a coach sees none of your body measurements, daily health numbers, progress photos, height or injury notes, though your training, your nutrition log and your messages stay visible to them. A coach can also ask for a coaching brief about you (see section 5).
- Group members can see anything you post, comment, or react to in that group. In a group challenge they see your results. In a Progression challenge the board also carries the scoring curve and date of birth you joined with, which set how your score is calculated, and in one scored with a handicap, the weigh-in you joined with and the weigh-ins behind your score. No other challenge shows your weigh-ins. While Collect Body Data is off you cannot join one scored with a handicap, and the ones you are already in stop showing your weigh-ins.
- People you message can see your messages, including voice messages. If your coach has turned on email alerts for messages, a message you send them is also emailed to them, with up to its first 200 characters.
- Anyone who knows your email address can find your account. Phone-number search is off unless you turn it on; if you do, anyone who knows that number can find you too.
- Anyone with a link you share. When you share a workout, routine or program as a link, SetLift saves a copy of what you shared at that moment, with your display name, at a setlift.app/s/ address, and anyone who has the link can open it without an account. A shared routine or program leaves out your weights and notes; a shared workout shows its numbers, such as your top lift and any records. Editing or deleting the original does not change the copy, and it stays viewable until you delete your account or ask us at privacy@setlift.app to take it down.
- Apps you share to. When you send something from SetLift to another app, such as Messages, Instagram Stories or Strava, that app and its own policies govern it from then on. A recap you share to Instagram Stories is handed to the Instagram app on your phone, with SetLift's app ID so Instagram can show where it came from; SetLift sends Meta nothing else.
- Anyone at all, in the case of your profile photo and exercise videos or images you upload, as described above.
10. How long we keep it
We keep your account data for as long as your account exists. Some specifics worth stating:
- Voice messages are retained indefinitely by design: they are not auto-deleted after a period of time. They are removed when you delete your account or delete the conversation.
- Coach verification materials: your selfie is deleted as soon as your application has been reviewed, whatever the outcome. The details you submitted (name, contact email, certifying body and certification number, experience, and the link you gave us) are kept for as long as you hold coach status. We also keep a permanent record of each verification decision: the date, the outcome, the certification details as submitted, and the reviewer's notes. That record is how we can show what was checked and when, and it is kept even if an application is declined.
- Progress photos and body metrics are retained until you delete them or your account. Settings → Privacy & Data → Delete My Body Data deletes all of them at once, including the weigh-ins copied into challenges you joined, finished ones included, and the parts of coaching briefs built from your body data.
- Coaching briefs a coach asks for about you are kept for as long as both accounts exist. The coach can open them only while you are connected, and the parts built from your body data only while Collect Body Data is on.
- Food you log is kept until you delete it or your account. A correction you saved to a product is kept until you switch back to the database numbers or delete your account.
- Share links stay viewable until you delete your account or ask us to take one down.
- Strava: disconnecting deletes your Strava access keys and connection. The note of which workouts were posted stays with each workout until you delete it or your account. Workouts already on Strava stay there until you delete them in Strava.
- Liability agreements: once you sign a liability agreement with a coach, we keep a permanent record of the exact text you signed, your typed name, and the date, even if you later delete your account or disconnect from that coach. This is so there is a lasting record of what was agreed to, the same way we retain a permanent record of each coach verification decision.
When you delete your account, we perform a real deletion of your authentication record and associated data, not a soft flag that hides it. Backups may retain copies for a limited period before they age out. Content you posted into a shared space, such as a group post someone else has replied to, may persist in that context; contact us if you need it removed.
11. Your rights and choices
Regardless of where you live, you can:
- Access and correct your profile data directly in the app
- Delete your account from inside the app, in Settings → Account → Delete Account. This performs a genuine deletion.
- Control discoverability: turn phone-number search on or off in your settings
- Turn off Collect Body Data in Settings → Privacy & Data to stop SetLift collecting body measurements, progress photos and injury notes, and to stop showing them to a coach or a challenge group
- Revoke device permissions for photos, camera, microphone, speech recognition and notifications in iOS Settings at any time
- Disconnect Strava in Settings → Integrations, or turn Apple Health off in Settings → Apple Health
- Export your data: download your workout history and body measurements as CSV files from Settings → Import & Export, or email us for a full copy
To exercise any right we cannot handle in-app, email privacy@setlift.app. We will respond within 45 days, and will tell you if we need longer.
12. U.S. state privacy rights
California (CCPA/CPRA)
If you are a California resident you have the right to know what personal information we collect and how we use it, to request deletion, to request correction, to request a portable copy, and to not be discriminated against for exercising these rights. You also have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We do not sell or share personal information for advertising, and we do not use sensitive personal information for any purpose other than providing the app, so there is nothing to opt out of. The categories of personal information we collect are described in Section 2; the purposes in Section 4; the recipients in Section 6.
Washington, Nevada, and Connecticut consumer health data
Washington's My Health My Data Act, Nevada's SB 370, and the Connecticut Data Privacy Act give residents specific rights over consumer health data. Because SetLift collects information about your body, injuries, and physical activity, those laws apply to us. Your rights under them, including the right to withdraw consent and to have consumer health data deleted, are described in our separate Consumer Health Data Privacy Notice.
Other states
Residents of states with comprehensive privacy laws, including Colorado, Virginia, Utah, Texas, Oregon, Montana, and others, have rights to access, correct, delete, and obtain a copy of their personal data, and to appeal a denied request. Email privacy@setlift.app to exercise them or to appeal.
13. International users
SetLift is operated from the United States and your data is stored there. If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR including access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Our legal bases for processing are performance of our contract with you (operating the app), your consent (for optional features such as progress photos, phone discoverability, Apple Health and Strava), and our legitimate interests (security and abuse prevention). Contact privacy@setlift.app to exercise these rights.
14. Children and teens
SetLift is not intended for anyone under 16, and our Terms require you to be at least 16 to create an account. When you create an account we ask for your date of birth. If it shows you are under 16, we delete the account you just created, along with anything in it, and we do not keep the date of birth you entered. Your device remembers for one day that the check was not passed, so the question is not simply asked again; that note holds no date of birth and never leaves your device. A date of birth is what you tell us; we do not check it against documents. Accounts created before September 20, 2026 were not asked, and date of birth stays optional for them. We do not knowingly create or keep accounts for users under 16. If we learn that we have collected data from someone under 16, we will delete it promptly; email privacy@setlift.app if you believe this has happened.
If you are between 16 and 18, please review this policy with a parent or guardian.
15. Changes to this policy
We will update this page when our practices change and revise the "last updated" date above. If a change is material, for example if we added analytics, changed what we send to a third party, or began processing data for a new purpose, we will notify you in the app or by email before it takes effect.
16. Contact us
Questions, requests, or concerns about privacy:
- Email: privacy@setlift.app
- Support: support@setlift.app