Effective date: September 1, 2026
UpLift is operated by Ashish Dhiman, based in Belgium ("we," "us," or "our"). This policy explains what information UpLift handles, why it is handled, where it is stored, and the choices available to you.
The app is a workout tracker. You can use UpLift as a guest without an account. You can also create an account for cloud backup, restore, and sync across your devices.
Information we handle
Guest information
A guest can use UpLift without an account. A guest's workout data, body metrics, profile name, and avatar stay on the device.
We do not collect an email address or account identifier from a guest. A guest has no Firebase Authentication record and no Cloud Firestore profile. Guest data never reaches Cloud Firestore.
Firebase Core initializes when the app starts, including during guest use. The app also includes the Apple and Google sign-in SDKs, whose privacy manifests declare their own data practices. Guest use therefore does not mean the app contains no third-party SDK. It does mean that no guest workout, body, or profile data is sent to Cloud Firestore.
Account and sign-in information
An account holder can sign in to use cloud features. Depending on the method chosen, we handle:
- a Firebase account identifier;
- an email address;
- a name or display name, when supplied by Google, Apple, or the account holder;
- the sign-in provider; and
- account creation, update, and authentication timestamps.
UpLift supports Google Sign-In, Sign in with Apple, and passwordless email-link sign-in. Authentication emails are transactional and are not used for marketing. If an account holder uses Apple's Hide My Email feature, we may receive an Apple relay address instead of a personal email address.
Firebase Authentication and the sign-in providers may also process technical information such as IP address, device and operating-system information, app version, user-agent information, and authentication identifiers. They use this information to provide authentication, prevent abuse, maintain their services, and meet their own declared analytics or diagnostic purposes. The Google Sign-In SDK privacy manifest also declares name, email address, phone number, coarse location, identifiers, and technical usage data. UpLift does not ask for or store phone numbers or location in its own profile data.
Profile information
A guest's profile name and avatar stay on the device. An account holder may provide or generate the following profile information:
- display name;
- height;
- preferred height and weight units;
- fitness goal;
- automatic avatar style and whether a local photo or monogram is shown;
- onboarding status; and
- profile creation and update timestamps.
Most profile fields are optional. An account holder's profile information is stored in Cloud Firestore under the Firebase account identifier.
Workout and body information
To provide workout logging, history, charts, export, backup, and restore, UpLift handles:
- workout dates, completion state, and timestamps;
- exercise names and identifiers, including names created in the app;
- set order, repetitions, and weight lifted;
- body weight and body-fat percentage entries;
- sync state, deletion records, and related technical metadata; and
- stable identifiers used to keep records consistent across devices.
Guest workout and body information stays on the device. An account holder's information is also backed up to Cloud Firestore under the account. Height, body weight, body-fat percentage, fitness goals, and workout records may be considered health or fitness information.
UpLift does not read Apple Health, HealthKit, motion sensors, heart-rate data, step data, or other health-sensor information.
Profile photos
If you choose a profile photo, UpLift may ask for permission to use the camera or photo library. The selected image is cropped and saved in the app's local documents storage. The photo is not uploaded to Firebase or an avatar service. For an account holder, Cloud Firestore stores only whether the app should display the local photo or the automatic monogram.
You can use UpLift without adding a photo. Choosing the monogram removes the app's local photo copy after confirmation. The original image in your Photos library is not changed.
Device-local information
The app stores the following information on the device:
- a uid-scoped SQLite copy of workouts, exercises, sets, body metrics, custom exercises, favorites, and pending cloud-sync operations;
- a Firestore offline cache for account holders, cleared on sign-out and account deletion;
- theme, unit, comparison, and active-workout-session preferences; and
- a uid-scoped avatar photo, if you add one.
A guest's data remains on the device until the guest deletes it from Profile or deletes the app. An account holder's local workout data may remain on the device after sign-out, but the app scopes it to the account that created it. It is removed when account deletion completes successfully or when the app and its data are removed from the device.
Workout exports
If you export workouts, UpLift creates a CSV, Markdown, or JSON file on your device and gives it to the iOS share sheet. You decide which app, service, or person receives it. The temporary file is deleted after the share sheet returns when cleanup succeeds. Any recipient you choose handles the shared file under its own privacy practices.
How we use information
We use information to:
- provide local workout logging, history, charts, editing, and exports;
- show and update a local guest profile or an account-holder profile;
- authenticate account holders and maintain their accounts;
- back up, restore, and synchronize account-holder information across devices signed in to the same account;
- remember app preferences;
- secure the app, prevent abuse, and troubleshoot service operation; and
- respond to privacy or support requests.
We do not use your information for advertising, data brokerage, targeted marketing, or cross-app tracking. We do not sell personal information.
UpLift does not include a first-party behavioral analytics or crash-reporting product. Firebase and Google Sign-In SDK privacy manifests nevertheless declare limited diagnostic, identifier, device, location, and usage-data processing for app functionality and provider analytics. UpLift does not use that provider information to build an advertising profile or track you across other companies' apps or websites.
Data retention and deletion
We retain cloud account data while an account exists and as needed to provide the app. Device-local information remains until it is removed through the app, account deletion, operating-system cleanup, or app removal.
An account holder can delete an account from Profile > Delete Account. The app requires fresh authentication before deletion. For passwordless email-link accounts, this means completing a fresh sign-in link.
When account deletion completes successfully, UpLift removes:
- cloud workouts, custom exercises, body metrics, and sync metadata;
- the Cloud Firestore profile;
- uid-scoped local SQLite data;
- the local avatar photo, on a best-effort basis;
- the on-device Firestore offline cache, on a best-effort basis; and
- the Firebase Authentication account.
A guest has no account to delete, so Profile > Delete Account does not apply. Instead, a guest can use Profile > Delete local data to delete local workout and profile data. This covers workout data, body metrics, the profile name, and the avatar. Deleting the app also removes this guest data from the device.
When a guest creates an account, the guest's local workout history and body metrics move into that account. They then become subject to the cloud storage, retention, and deletion terms in this policy. If the account already has data, the person chooses either the guest data or the account data. The other side is permanently deleted. UpLift does not merge the two histories.
Account deletion is performed in stages. If a required stage fails, the app does not report false success and may leave some information available for a later retry. If in-app deletion fails, contact privacy@thunderstackai.com.
Google states that Firebase Authentication information is removed from its live and backup systems within 180 days after the associated Firebase user is deleted. Other provider backups or operational records may remain temporarily under the provider's retention schedules or where required by law.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information.
Within the app, you can:
- edit profile information;
- add, edit, or delete workouts and body metrics;
- export workout history;
- delete local guest data, if you are a guest; and
- delete your account, if you are an account holder.
For an access, correction, deletion-failure, or other privacy request, email privacy@thunderstackai.com. We may need to verify your identity before completing a request.
Security
We use safeguards intended to protect information. These include the iOS app sandbox and uid-scoped local database access. For account holders, they also include Firebase Authentication, deployed owner-scoped Firestore security rules, and HTTPS transport. Google states that Firebase Authentication and Cloud Firestore encrypt data in transit and at rest. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
International processing
Google Firebase and the authentication providers operate internationally. Account-holder information may be processed in countries other than the one where the account holder lives. Firebase Authentication is operated from data centers in the United States, and Cloud Firestore may process account-holder information in Google infrastructure associated with the configured database location and its service terms.
Children
UpLift is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact privacy@thunderstackai.com so we can review and remove it where appropriate.
Changes to this policy
We may update this policy when the app or its data practices change. We will update the effective date and provide an appropriate in-app or website notice for material changes. App Store privacy answers will also be updated when collection or use changes.
Contact
- Operator: Ashish Dhiman
- Location: Belgium
- Email:
privacy@thunderstackai.com - Privacy policy:
https://thunderstackai.com/uplift/privacy
Service-provider information
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase privacy and security information: https://firebase.google.com/support/privacy