FitLiftPro

Privacy Policy

Effective 26 August 2026 · Last updated 26 August 2026

FitLiftPro records things about your body, your training and where you walk. That is unusually personal information, and this policy sets out exactly what we collect, why, who else sees it, how long we keep it and how you get rid of it.

The short version. We do not sell your data. We do not use your health or fitness information for advertising, and we do not share it with advertisers or data brokers — not now, and not as a future option. FitLiftPro is a private, single-user app: nothing you record is visible to anyone else. Your workouts, measurements, photos and walking routes exist to show you to yourself. You can delete your account and everything in it from inside the app or from this website, and we will actually delete it.

1. Who we are

FitLiftPro ("FitLiftPro", "we", "us") provides the FitLiftPro mobile application for iOS and Android and the website at fitliftpro.com. For the purposes of the UK GDPR and the EU GDPR we are the controller of the personal data described in this policy.

FitLiftPro LTD, a limited company registered in England and Wales.
Flat 3, 23 Thorndike Road, London, England, N1 2LS
Contact: support@fitliftpro.com

Company registration number: 17245472

One company controls your data, wherever you live. Many services in this field route users through different corporate entities depending on their country. We do not. FitLiftPro LTD is the controller for every user, everywhere, and this single policy applies to all of them. We have no parent, subsidiary or group companies, so your information is never shared inside a corporate group.

Representative in the European Union (EU GDPR, Article 27). FitLiftPro is not currently offered to users in the European Economic Area. We are appointing a representative in an EEA member state, and their name and address will be published here before we make the app available in the EEA. Until then you can reach us directly at support@fitliftpro.com, and if you are in the EEA you may also complain to your national supervisory authority.

2. Private by design

FitLiftPro is a private, single-user application. Nothing you record is visible to any other user. There is no feed, no friends list, no followers, no leaderboard, no sharing and no messaging. Your content is never published and never made available to anyone else.

This is not a setting you have to find and switch on, and it is not a default that could be changed later by you or by us. It is how the product is built. There is no audience inside FitLiftPro, because there is nobody else in it.

What follows from that is worth spelling out, because it is unusual:

Because FitLiftPro has no social features, there is no moderation of your content, no scanning of your messages, and no automated review of your photographs. We simply do not look.

3. What we collect

We collect only what the app needs to work. The table below is exhaustive as at the effective date above. We keep the Data Safety information on our Google Play listing consistent with it.

CategoryWhat it includesWhere it comes from
Account details Email address, first name and surname (if you provide them), the sign-in method you used, and an internal account identifier. You, or your Google or Apple account when you sign in with one.
Body measurements
Health data
Body weight, body-fat percentage, and circumference measurements for chest, waist, hips, arms, thighs and neck, along with the date and any notes you write. You, entered manually.
Progress photos
Health data
Photographs of yourself that you choose to take or upload, and the date they belong to. You, via your camera or photo library.
Workouts
Health data
Training sessions, the exercises in them, and each set — weight, repetitions, perceived effort, rest timings and completion. You, entered in the app.
Walks and activity
Health data + location
Walk start and end times, duration, distance, step counts, pace, elevation, and the precise route you walked as a series of location points. Your device's location and motion sensors while a walk is recording.
Health platform data
Health data
Steps, walking and running distance, active energy burned, heart rate, height and weight. Apple Health or Android Health Connect — only if you grant permission, and only the types you allow.
Preferences Units (kg/lbs, km/miles), timer defaults, plate sizes, theme, calendar and display settings, and the step source you chose. You, through the app's settings.
Subscription status Whether you hold an active subscription and which entitlement it grants. We never receive your card details. Apple's App Store or Google Play, through RevenueCat.
Diagnostic logs Technical records of what the app did — errors, timings, which screens and operations ran, device model, operating system version and app version. Deliberately excludes your measurements, weights, reps and location coordinates. The app, and only sent to us if you have turned log sharing on.
Issue reports Anything you write when reporting a problem, plus the email address or phone number you give us to reply to, and your device details. You, when you choose to report an issue.
Technical data IP address and connection information, inherent in using an online service. An IP address indicates your approximate location — typically your country, region or city, not your street. Automatically, when the app or website contacts our servers.
Your privacy choices A record of the permissions and consents you have given or withdrawn, and when. We are required to be able to show that you consented, so we have to keep this. Your choices in the app and in your device settings.

What we do not collect. We do not use advertising identifiers. We do not run advertising or analytics SDKs in the app — no Firebase, no attribution tools, no third-party analytics of any kind. We do not track you across other apps or websites. We do not collect your contacts, your calendar, your microphone, or a list of the other apps on your device. We do not buy personal data about you from anyone, and we do not maintain profiles of you for marketing.

4. What you must give us, and what is optional

Almost everything in the table above is your choice. It is worth separating the two, because a great deal of what this policy describes will simply never apply to you if you do not want it to.

Required to have an account: an email address and a sign-in method. That is all. Your name is optional.

Entirely optional — the app works without each of them: body measurements, progress photographs, walks and location, Apple Health or Health Connect, diagnostic log sharing, and issue reports.

Declining any of these does not degrade the rest of the app, and no paid feature depends on granting any permission. You can hold a subscription and never turn on location, health access, the camera or diagnostics. We mention this because consent only counts as freely given if refusing it costs you nothing.

5. Health and fitness data

Your measurements, photographs, workouts, walks and anything read from Apple Health or Health Connect are health data. Under the UK and EU GDPR this is a "special category" of personal data with stronger protection, and we treat all of it that way regardless of where you live, and regardless of which door it came in through — typed in by you, or read from a health platform, it gets the same protection.

Our commitments

Some of these are not merely promises we have chosen to make. Apple's and Google's developer rules prohibit using health-platform data for advertising, marketing or data mining, and prohibit selling or transferring it to advertising platforms or data brokers, and those prohibitions apply even if a user were to consent. You could not authorise us to do those things, and we would not ask.

Apple Health and Health Connect

If you connect Apple Health or Android Health Connect, the app reads only the data types you approve, and you can withdraw that permission at any time — in iOS Settings under Health, or in the Health Connect app on Android. The app keeps working without it.

Under Google's Health Connect rules, an app must fit one of a defined set of permitted uses. Ours is fitness and wellness: showing you your own activity, so you can review it. We are not a coaching service and we do not use health data to prescribe or recommend anything to you.

What Apple Health and Health Connect themselves do with your data is governed by Apple and Google, under Apple's Health app privacy notice and Google's privacy policy. What we do with the data you allow us to read is governed by this policy.

Where your health data is stored

Data you record in FitLiftPro, including health-platform data you allow us to read, is stored in your account on our own servers, so that your history survives losing or changing your phone. It is not stored in iCloud. Some apps in this field keep health-platform data only on the device; we do not, because FitLiftPro syncs across your devices, and we would rather say so plainly than imply otherwise. See section 12 for where those servers are, and section 17 for how the data is protected.

Consent, and how to withdraw it

In the UK and the EU we rely on your explicit consent under Article 9(2)(a) to process health data. We ask for it separately, at the point you first do the thing that needs it — when you first connect a health platform, when you first record a walk with location, when you first add a progress photograph. Each is asked for on its own, each can be refused on its own, and refusing one does not affect the others.

You can withdraw consent at any time, and there is more than one way:

Withdrawing consent stops the processing that depended on it. It does not make processing that already happened unlawful.

6. Location data

When you record a walk, the app collects precise location — latitude, longitude, altitude and speed — to draw your route and calculate distance, pace and elevation.

Background location

FitLiftPro collects location in the background — that is, while the app is closed or not in use, and while your screen is off. It does this only while a walk is actively recording. You start a walk; we collect location; you stop the walk; we stop. At no other time does the app collect your location.

Without this, a walk would stop being recorded the moment you put your phone in your pocket, which is when most people put their phone. Your device will ask you for this permission separately from ordinary location access, and you can refuse it or withdraw it at any time in your device settings — the app carries on working, and you can still record a walk's time and duration.

We never use your location for advertising, marketing, analytics or personalisation. We never sell location data, and never share it for any purpose that would facilitate a sale. We do not publish your routes or contribute them to any public or community map.

Third parties that receive location

None of these receive your account details, and none are told who you are.

7. Progress photos

Progress photos are stored encrypted on our cloud storage and on your device, and are visible only to you. They are not published, not shared with other users, not used to train any model, and not analysed by us.

They are photographs of a person's body, so we treat them with the same care as health data — and that is more than a matter of taste. Apple's developer rules put data obtained through the camera and photo APIs in the same category as HealthKit data, and forbid using any of it for marketing, advertising or data mining. We go further: we do not look at them at all.

Deleting a photo removes both the stored image and the record pointing at it. Deleting your account removes every photo you have, in both places. See how long we keep it.

8. How we use your information, and our legal basis

What we doWhyLegal basis (UK/EU GDPR)
Record and display your workouts, walks, measurements and photos This is the product Contract — Art. 6(1)(b); explicit consent for health data — Art. 9(2)(a)
Synchronise your data between your devices and our servers So you do not lose your history and can change phone Contract — Art. 6(1)(b); explicit consent for health data — Art. 9(2)(a)
Maintain your account and sign you in To keep your data yours Contract — Art. 6(1)(b)
Protect your sign-in — checking credentials, recording failed attempts, blocking automated attacks So nobody else gets into your account Legitimate interests — Art. 6(1)(f): account security
Manage subscriptions and entitlements To provide paid features Contract — Art. 6(1)(b)
Show map tiles for your route, and look up the weather for a finished walk So a walk means something when you look back at it Contract — Art. 6(1)(b)
Diagnose faults from logs and issue reports To fix the app Consent for sending us logs — Art. 6(1)(a); otherwise legitimate interests — Art. 6(1)(f): a working, reliable app
Keep the service secure and prevent abuse To protect you and us Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c)
Send service messages — account deletion, security notices, and material changes to this policy So you know what is happening to your account. These are not marketing and you cannot unsubscribe from them while you have an account Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Keep a record of the permissions and consents you have given or withdrawn Because we must be able to show that you consented Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f)
Handle a request you make about your rights, and keep a record that we handled it Because we must, and must be able to show we did Legal obligation — Art. 6(1)(c)
Comply with law and respond to lawful requests Because we must Legal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and we will explain that assessment if you ask.

We do not send marketing email. If that ever changes we will ask for your consent first, and you will be able to withdraw it in one click.

9. Who we share information with

We do not sell personal data. We share it only with the providers below. Where they act as our processors, they act on our instructions and may not use your data for their own purposes.

We require every provider that receives your personal data to protect it to the same standard this policy sets out, and to the standard Apple's and Google's developer rules require of us.

ProviderWhat they handleRoleWhereSafeguard
Amazon Web Services Authentication, databases, file storage, email delivery and server functions — effectively all of your data ProcessorUnited States (us-east-1) UK Addendum + EU Standard Contractual Clauses
RevenueCat Subscription status and entitlements. No health data, no location, no photos. ProcessorUnited States UK Addendum + EU Standard Contractual Clauses
Apple / Google Payments and subscriptions; health platform data on your device; app distribution Independent controllersVarious Their own policies and transfer arrangements
Open-Meteo Coordinates sent to retrieve weather for a walk. No account details. Independent controllerEuropean Union Within the EEA
Stadia Maps Map tiles, and the IP address that requests them Independent controllerUnited States Their own transfer arrangements — see below
OpenStreetMap Foundation The underlying map data, and requests served through their infrastructure and content delivery networks Independent controllerUnited Kingdom / various Their own policy
YouTube (Google) Exercise demonstration videos played in the app Independent controllerUnited States and elsewhere Google's own policy and transfer arrangements

We may also disclose information where we are legally required to, or where it is necessary to establish or defend legal claims, to prevent harm, or as part of a merger or acquisition — in which case we would tell you before your data became subject to a different policy.

10. Videos, maps and weather

Three parts of the app reach out to services we do not run. This section says exactly what leaves your device when they do.

Exercise videos (YouTube)

Exercise demonstration videos are hosted by YouTube and played through YouTube's embedded player. YouTube is operated by Google. FitLiftPro is a YouTube API Services client, and this section is part of how we meet YouTube's requirements for one.

When you choose to play a video, your device contacts Google. Google receives your IP address, information about your device and player, and which video you are watching, and may store or read cookies or similar identifiers on your device. That use is governed by Google's Privacy Policy and the YouTube Terms of Service, in addition to this policy. By playing a video you are also using YouTube's service under those terms.

Google may show advertising inside its own player. We do not control it, we do not target it, we receive nothing for it, and we give Google nothing about you to target it with. FitLiftPro shows no advertising of its own anywhere.

We do not connect to your YouTube account. We ask for no YouTube permissions, we do not sign you in, and we cannot see your YouTube history, subscriptions, comments or likes. We hold no data from your YouTube account, because we never receive any. If you want to check or remove access you have granted to any app across Google's services, you can do so at security.google.com/settings/security/permissions.

Maps (OpenStreetMap and Stadia Maps)

When a map is shown, your device downloads map tiles directly from the tile provider. That request necessarily reveals your IP address and the area and zoom level you are looking at — which, for a map of a walk you have just finished, is approximately where you walked. It does not carry your name, email address or account identifier.

Stadia Maps states that end users of applications built with their services never receive cookies from Stadia, and that their server logs are kept for approximately 7 to 14 days. The OpenStreetMap Foundation states that detailed usage information is retained for 180 days, with IP addresses shortened. Those are their practices, not our promises, and they may change them.

Weather (Open-Meteo)

When a walk finishes, the app may look up the weather for it. That sends approximate coordinates and nothing else — no account identifier, no name, no device identifier.

11. Cookies and similar technologies

Cookies and similar technologies — local storage, tokens, software development kits, pixels — are ways of storing or reading small pieces of information on your device. Most services in this field use four kinds: strictly necessary, personalisation, analytics, and advertising.

We use only the first kind. FitLiftPro runs no analytics, no personalisation and no advertising technologies — neither in the app nor on this website. There is nothing here that follows you to another site, and no advertising identifier is used or collected.

What we do use:

You can clear or block storage through your browser or device settings. Blocking what is strictly necessary will stop parts of the site working — most obviously, you will not be able to sign in to request deletion.

12. Where your information is stored

Our servers are hosted by Amazon Web Services in the United States (us-east-1). If you are in the UK, the EEA or anywhere else outside the United States, your personal data is transferred out of your country in order to provide the service. For transfers from the UK we rely on the UK International Data Transfer Addendum, and for transfers from the EEA on the European Commission's Standard Contractual Clauses, together with the technical measures described under security.

What that does and does not mean. Those are contractual protections, and they are real, but they are not magic. While your information is in the United States it is subject to United States law, which in some circumstances permits courts, law enforcement and government agencies there to require access to it. We tell you this because a transfer clause that only lists the paperwork is not really telling you anything.

We would resist any request we believed to be unlawful or overbroad, and we would tell you about it unless we were legally prohibited from doing so.

13. Artificial intelligence, profiling and automated decisions

We do not use your personal data to train, develop, test or improve artificial intelligence or machine-learning models — not ours, and not anyone else's.

We do not send your personal data to any third-party artificial intelligence service. Your health data, your progress photographs and your walking routes in particular are never sent anywhere for analysis of any kind.

We do not make decisions about you with legal or similarly significant effects by automated means, and we do not profile you. The app makes no recommendations: it does not suggest weights, prescribe progressions, plan your training or assess your fitness. Charts, totals, streaks and personal records are arithmetic on data you entered — a sum, a maximum, a line drawn through your own numbers. They are records of what you did, not judgements about you, and not advice. See our Terms of Service on what FitLiftPro is and is not.

14. How long we keep it

The principle is simple: the things you create last as long as you want them to; the things we generate to run the service do not. Your workouts and photographs are yours and stay until you remove them. Our logs and internal records have short, fixed lives.

InformationKept for
Workouts, walks, measurements, photos, custom exercises, preferencesUntil you delete them, or until your account is deleted
Account details (name, email)Until your account is deleted
The internal record of which items changed and when — needed so that deleting something on one device also deletes it on your others6 months, or until your account is deleted, whichever is sooner
Diagnostic logs and issue reports you sent90 days, or until your account is deleted, whichever is sooner
The record of consents and permissions you gave or withdrewUntil your account is deleted, and then for as long as we may need to show that we handled your data lawfully
The record that we handled a rights request you made3 years from the end of the year in which we handled it
The record that an account deletion was requested, that we warned you, and that it was carried out — see below10 years
Copies held on your own deviceRemoved when you sign out or delete your account
Encrypted backups of your workouts, walks and measurements35 days. Our database keeps a rolling 35-day recovery window; after that, no backup contains the deleted information
Backups of your progress photographs and walk routesNone. These files are not versioned or backed up separately, so deleting one removes the only copy immediately
Records we are legally required to retainAs long as the law requires

Deleted information is removed from our live systems immediately. Where a backup exists, it is rotated on the schedule above, and a copy in a backup is never restored to the live service and is not used for any purpose. Your photographs and walk route files have no separate backup at all, so deleting one removes the only copy there is — please be sure before you delete a photograph.

The one record that outlives your account

When an account is deleted, everything in it goes. But we keep one small, separate record of the deletion itself — not of anything in the account — for 10 years, in storage that cannot afterwards be altered or erased by anyone, including us.

What it contains:

What it does not contain: your name; your email address in readable form; any workout, walk, route, measurement, weight or photograph; any location; or any free-text description. It is a list of dates and counts.

The email fingerprint is a keyed hash. It lets us confirm that a notice went to a particular address if that is ever questioned — you tell us the address and we check whether it matches — but it cannot be read, reversed, or used to contact anyone.

Why we keep it, and why we cannot delete it on request. Deleting an account is permanent. If someone later says their data was deleted without their consent, this record is the only way either of us can establish what actually happened: when it was asked for, that we warned them repeatedly, and that nobody cancelled. That protects you as much as it protects us. Article 17(3)(e) of the UK GDPR permits keeping personal data where it is necessary for the establishment, exercise or defence of legal claims, and this is that. It also means the right to erasure does not extend to it — erasing the evidence of a deletion at the request of the person disputing it would remove its only purpose. It is deliberately as small as it can be while still doing that job.

The same record is described in section 20.2b of our Terms of Service.

Deleting individual things

You do not have to delete your whole account to remove something. Any single workout, walk, measurement or progress photograph can be deleted on its own, in the app, and doing so removes it from your account and from your devices.

15. Deleting your account

How to do it

What happens

Deletion does not happen instantly, and that is deliberate. When you request it:

  1. We email you straight away to confirm the request and tell you the date it will complete.
  2. Your account stays fully usable for 30 days. Nothing is removed during that time.
  3. We remind you three times during that period.
  4. Every time you open the app you will see a notice with a countdown and a button to cancel.
  5. After 30 days your account and everything in it are permanently deleted, and we email you to confirm.

Why the delay. It is a security measure, not an obstacle. If someone else ever got into your account, the waiting period plus the notices are what give you the chance to stop them destroying your history. You can cancel at any point during the 30 days from the email, from the notice in the app, or by contacting us. This is a scheduled deletion that you can call off — not a freeze, and not a way of keeping your data longer.

What is deleted

Everything: your workouts, walks and routes, body measurements, progress photographs, custom exercises, preferences, your name and email address, your diagnostic logs and issue reports, the copies held on your device, and your sign-in itself.

What is not deleted

Anything we have to keep for legal reasons is held separately, is not linked back to your deleted account, and cannot be used to restore it or to identify you as a former user.

16. Your rights

If you are in the UK or the EEA you have the right to:

To exercise any of these, email support@fitliftpro.com. We respond within one month. We do not charge, and we will not ask you why. You may appoint someone to make a request on your behalf; we will need to be satisfied that they are authorised and that you are who you say you are.

You have these rights even if you have never had an account — for example if you only ever sent us an issue report with your email address or phone number.

These rights have limits set by law. We may not be able to erase information we are legally required to keep, and we may refuse a request that is manifestly unfounded or excessive. If we refuse a request, we will tell you why, and you can ask us to reconsider. You can also complain to a supervisory authority — see section 22.

17. How we protect your information

No service can promise perfect security, and anyone who tells you otherwise is selling something.

18. If something goes wrong

If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, as the UK GDPR requires, and to any other supervisory authority that must be told.

If the breach is likely to result in a high risk to you, we will tell you directly and without undue delay. We will say what happened, what data was involved, what we are doing about it, and what you should do. We will tell you even where it is embarrassing to do so.

19. Children

FitLiftPro is not intended for children. You must be at least 16 to create an account in the UK and the EEA, and at least 13 elsewhere, or older where your local law requires it. These are the same ages set out in our Terms of Service.

We do not knowingly collect data from anyone below these ages. If we learn that we have, we delete the account and its data. If you believe a child has created an account, email support@fitliftpro.com and we will investigate and act.

20. Region-specific information

United Kingdom

We are a UK company and the UK GDPR and Data Protection Act 2018 apply to our processing. Health data is processed under Article 9(2)(a) on the basis of your explicit consent. Our lead supervisory authority is the Information Commissioner's Office, and you may complain to it at ico.org.uk. Transfers to the United States are made under the UK International Data Transfer Addendum.

European Economic Area

Where the EU GDPR applies to you, it applies to us as a controller outside the Union offering services to people in it. Health data is processed under Article 9(2)(a). You may complain to the supervisory authority in your own country. Transfers to the United States are made under the European Commission's Standard Contractual Clauses. Our representative in the Union is named in section 1.

The United Kingdom is not part of the EEA, and this policy deliberately does not treat the two as interchangeable: the applicable law, the transfer instrument and the authority you complain to are different in each case.

California

We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not engage in cross-context behavioural advertising. Because we do not sell or share, and run no targeted advertising, there is nothing for an opt-out preference signal such as Global Privacy Control to opt out of; we also do not respond to Do Not Track browser signals, because we do not track.

The categories of personal information we collect:

Statutory categoryWhat it is hereSold or shared?
IdentifiersName, email address, account identifier, IP addressNo
Internet or network activityDiagnostic logs and connection informationNo
Geolocation data (sensitive)Precise walking routesNo
Health information (sensitive)Measurements, workouts, walks, health-platform dataNo
Audio, electronic, visual or similar informationProgress photographsNo
Commercial informationWhether you hold a subscriptionNo
InferencesNone. We draw none.N/A

Health data and precise geolocation are sensitive personal information. We use them only to provide the service you asked for, and never to infer characteristics about you. You have the right to know, access, delete, correct, limit the use of sensitive personal information, and to non-discrimination for exercising those rights, and to appeal a decision we make on a request.

Other United States jurisdictions

Residents of US states with comprehensive privacy laws — including, among others, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and Washington — have rights to access, correct, delete and port their data, to opt out of targeted advertising, sale and profiling, and to appeal a refused request. We do not conduct targeted advertising, sales or profiling at all. Consumer health data is handled in line with Washington's My Health My Data Act; we do not collect consumer health data for any purpose other than providing the app to you, and we never sell it.

Everywhere else

FitLiftPro is available worldwide. We apply the standards in this policy to every user, wherever they live, rather than offering weaker protection where the local law happens to allow it. Where your country's law gives you rights beyond those described here, those rights still apply and we will honour them — write to us and say what you need.

21. Changes to this policy

We will update this page when our practices change, and change the "last updated" date. If a change materially affects your rights or how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

We will not reduce your rights under this policy without your explicit consent.

If we ever introduce something new — a data type we do not collect today, a new provider, or a new purpose — we will describe it here first and ask for your consent where consent is required. We will not quietly repurpose information you gave us for something else. Previous versions of this policy are available on request from support@fitliftpro.com.

22. Contacting us and complaining

Questions, requests and complaints: support@fitliftpro.com.

If you are unhappy with our response you may complain to the Information Commissioner's Office (ico.org.uk), which is our lead supervisory authority, or to the data protection authority in the country where you live. We would rather you told us first so we can put it right.