LiftFlow is a strength-training companion with a LiftFlow API backend. This policy describes what data we collect and your choices.
| Data | Purpose | Stored where |
|---|---|---|
| Telegram profile (ID, name, username, language) | Account | Server |
| Workout data | Core functionality | Server + local cache |
| JWT / refresh tokens | Authentication | Device + server hashes |
| FCM token (optional) | Push reminders | Server |
| Health Connect / Apple Health (optional) | Health summary | On device |
| Crash reports (Sentry, optional) | Stability | Sentry |
| Webhook URL (optional) | Workout events | Server |
We do not sell personal data or use workout data for advertising.
Contract (service), consent (Health, push, webhooks), legitimate interest (security).
Telegram, Google Firebase (FCM), Sentry (if enabled), your hosting provider.
Until account deletion or logout; local cache until app uninstall.
Access, correction, export (CSV in app), deletion — contact support.
HTTPS, short-lived JWT, rotating refresh tokens.
Not directed at children under 13 (16 in the EU).
privacy@liftflow.app — replace with your support email before store submission.