Effective date: August 18, 2026
Up Lift is operated by Ashish Dhiman, based in Belgium ("we," "us," or "our"). This policy explains what information Up Lift handles, why it is handled, where it is stored, and the choices available to you.
The app is a workout tracker. It stores workout information on your device and backs up account data to Google Firebase so it can be restored for the same signed-in account.
Information we handle
Account and sign-in information
You must sign in to use Up Lift. Depending on the method you choose, we handle:
- a Firebase account identifier;
- your email address;
- your name or display name, when supplied by Google, Apple, or you;
- the sign-in provider you use; and
- account creation, update, and authentication timestamps.
Up Lift supports Google Sign-In, Sign in with Apple, and passwordless email-link sign-in. Authentication emails are transactional and are not used for marketing. If you use Apple's Hide My Email feature, we may receive an Apple relay address instead of your personal email address.
Firebase Authentication and the sign-in providers may also process technical information such as IP address, device and operating-system information, app version, user-agent information, and authentication identifiers to provide authentication, prevent abuse, maintain their services, and meet their own declared analytics or diagnostic purposes. The Google Sign-In SDK privacy manifest also declares name, email address, phone number, coarse location, identifiers, and technical usage data. Up Lift does not ask for or store your phone number or location in its own profile data.
Profile information
You may provide or generate the following profile information:
- display name;
- height;
- preferred height and weight units;
- fitness goal;
- automatic avatar style and whether a local photo or monogram is shown;
- onboarding status; and
- profile creation and update timestamps.
Most profile fields are optional. Profile information is stored in Cloud Firestore under your Firebase account identifier.
Workout and body information
To provide workout logging, history, charts, backup, and restore, Up Lift handles:
- workout dates, completion state, and timestamps;
- exercise names and identifiers, including names you create;
- set order, repetitions, and weight lifted;
- body weight and body-fat percentage entries;
- sync state, deletion records, and related technical metadata; and
- stable identifiers used to keep records consistent across devices.
This information is stored locally in the app and backed up to Cloud Firestore under your account. Height, body weight, body-fat percentage, fitness goals, and workout records may be considered health or fitness information.
Up Lift does not read Apple Health, HealthKit, motion sensors, heart-rate data, step data, or other health-sensor information.
Profile photos
If you choose a profile photo, Up Lift may ask for permission to use the camera or photo library. The selected image is cropped and saved in the app's local documents storage. The photo itself is not uploaded to Firebase or an avatar service. Cloud Firestore stores only whether the app should display the local photo or the automatic monogram.
You can use Up Lift without adding a photo. Choosing the monogram removes the app's local photo copy after confirmation. The original image in your Photos library is not changed.
Device-local information
The app stores the following information on your device:
- a uid-scoped SQLite copy of workouts, exercises, sets, body metrics, custom exercises, favorites, and pending cloud-sync operations;
- a Firestore offline cache;
- theme, unit, comparison, and active-workout-session preferences; and
- a uid-scoped avatar photo, if you add one.
Local workout data may remain on the device after sign-out, but the app scopes it to the account that created it. It is removed when account deletion completes successfully or when the app and its data are removed from the device.
Workout exports
If you export workouts, Up Lift creates a CSV, Markdown, or JSON file on your device and gives it to the iOS share sheet. You decide which app, service, or person receives it. The temporary file is deleted after the share sheet returns when cleanup succeeds. Any recipient you choose handles the shared file under its own privacy practices.
How we use information
We use information to:
- authenticate you and maintain your account;
- show and update your profile;
- log, display, edit, chart, export, back up, and restore workouts and body metrics;
- synchronize your information across devices signed in to the same account;
- remember app preferences;
- secure the app, prevent abuse, and troubleshoot service operation; and
- respond to privacy or support requests.
We do not use your information for advertising, data brokerage, targeted marketing, or cross-app tracking. We do not sell personal information.
Up Lift does not include a first-party behavioral analytics or crash-reporting product. Firebase and Google Sign-In SDK privacy manifests nevertheless declare limited diagnostic, identifier, device, location, and usage-data processing for app functionality and provider analytics. Up Lift does not use that provider information to build an advertising profile or track you across other companies' apps or websites.
Data retention and deletion
We retain cloud account data while your account exists and as needed to provide the app. Device-local information remains until it is removed through the app, account deletion, operating-system cleanup, or app removal.
You can delete your account from Profile > Delete Account. The app requires fresh authentication before deletion. For passwordless email-link accounts, this means completing a fresh sign-in link.
When account deletion completes successfully, Up Lift removes:
- cloud workouts, custom exercises, body metrics, and sync metadata;
- the Cloud Firestore profile;
- uid-scoped local SQLite data;
- the local avatar photo, on a best-effort basis; and
- the Firebase Authentication account.
Deletion is performed in stages. If a required stage fails, the app does not report false success and may leave some information available for a later retry. If in-app deletion fails, contact privacy@thunderstackai.com.
Google states that Firebase Authentication information is removed from its live and backup systems within 180 days after the associated Firebase user is deleted. Other provider backups or operational records may remain temporarily under the provider's retention schedules or where required by law.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information.
Within the app, you can:
- edit profile information;
- add, edit, or delete workouts and body metrics;
- export workout history; and
- delete your account.
For an access, correction, deletion-failure, or other privacy request, email privacy@thunderstackai.com. We may need to verify your identity before completing a request.
Security
We use safeguards intended to protect information, including Firebase Authentication, deployed owner-scoped Firestore security rules, HTTPS transport, uid-scoped local database access, and the iOS app sandbox. Google states that Firebase Authentication and Cloud Firestore encrypt data in transit and at rest. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
International processing
Google Firebase and the authentication providers operate internationally. Information may be processed in countries other than the one where you live. Firebase Authentication is operated from data centers in the United States, and Cloud Firestore may process data in Google infrastructure associated with the configured database location and its service terms.
Children
Up Lift is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact privacy@thunderstackai.com so we can review and remove it where appropriate.
Changes to this policy
We may update this policy when the app or its data practices change. We will update the effective date and provide an appropriate in-app or website notice for material changes. App Store privacy answers will also be updated when collection or use changes.
Contact
- Operator: Ashish Dhiman
- Location: Belgium
- Email:
privacy@thunderstackai.com - Privacy policy:
https://thunderstackai.com/uplift/privacy
Service-provider information
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase privacy and security information: https://firebase.google.com/support/privacy