Liftin' Connector — Privacy Policy
Effective date: July 23, 2026
This policy covers the Liftin' Connector — the service that links AI assistants (such as ChatGPT, Claude, or Codex) to the workout data you track in the Liftin' iOS app. The Liftin' iOS app itself has its own privacy policy; this document describes only what the Connector does.
Data controller: nstrm AB, Sweden (5592700719) Contact: support@liftinapp.co
The short version
- Your workout data lives in your private iCloud database, managed by Apple. We do not have servers that store your workouts.
- When you ask your AI assistant about your training, the Connector passes the requested data from your iCloud to your assistant — in transit only, never stored by us.
- We store only what's needed to keep you signed in, plus anonymous usage metadata (which tools were used, when, and whether they succeeded — never the content of your workouts).
- We don't sell data, show ads, or use third-party advertising or profiling analytics.
What the Connector is
The Connector is a bridge. On one side is the Liftin' iOS app, which stores your training data in your personal, private iCloud (CloudKit) database. On the other side is the AI assistant you choose to connect. When you ask your assistant something about your training — or ask it to build or adjust a program — the Connector reads or writes your iCloud data on your behalf and returns the result to your assistant.
Data we process
1. Sign-in and connection data (stored)
When you connect an AI assistant, we store:
- Session tokens issued by Apple when you sign in with your Apple account. These let the Connector access your private iCloud data on your behalf. Apple expires these sessions automatically (currently about every 8 hours), after which you sign in again.
- Access tokens identifying your connection from your AI assistant (valid up to 90 days, deleted earlier if your session ends).
- A one-way hashed identifier derived from your iCloud user record. It lets us count users and diagnose problems without knowing who you are. It cannot be reversed into your Apple ID, email, or name.
- The name of the AI client you connect with (for example "ChatGPT" or "Claude").
We never see or store your Apple ID password. Sign-in happens directly with Apple; Apple hands the Connector a limited session token, never your credentials.
2. Workout data (in transit only — never stored)
When your AI assistant requests it, your training data (workouts, exercises, programs, routines, weights, and similar) passes through the Connector between your iCloud database and your assistant. This data is processed transiently in memory to serve the request and is not stored, logged, or retained by the Connector.
3. Usage metadata (stored)
To operate and improve the service, we record events about how the Connector is used: which tool was called (for example "get workout history"), when, whether it succeeded, how long it took, which AI client made the call, and the hashed identifier described above. The content of requests and responses — your actual training data — is never included.
4. Technical logs (short-lived)
Our infrastructure processes IP addresses transiently for security and rate limiting, and keeps standard technical logs for a short period (days, not months) for troubleshooting.
Purposes and legal bases (GDPR)
- Sign-in and connection data — providing the service you requested. Legal basis: performance of a contract (Art. 6(1)(b)).
- Workout data in transit — answering the requests you make through your assistant. Legal basis: performance of a contract (Art. 6(1)(b)).
- Usage metadata — reliability, security, and understanding usage to improve the service. Legal basis: legitimate interest (Art. 6(1)(f)).
- Technical logs — security, abuse prevention, and troubleshooting. Legal basis: legitimate interest (Art. 6(1)(f)).
Who receives your data
- Your AI assistant provider (for example OpenAI for ChatGPT, or Anthropic for Claude). Any data you request through your assistant becomes part of your conversation with it and is handled under that provider's privacy policy. You control what you ask for; we recommend reviewing your assistant provider's data settings.
- Apple stores your training data in your private iCloud database, under Apple's iCloud terms — this is where your data lives regardless of the Connector.
- Fly.io, Inc. (our hosting provider) operates the server infrastructure. The Connector runs on servers located in Stockholm, Sweden. Fly.io is a US company acting as our data processor; transfers are safeguarded by standard contractual clauses.
We do not sell personal data, share it with advertisers, or use it for profiling.
Retention
- Apple session tokens — until Apple expires the session (about 8 hours) or you disconnect.
- Access tokens — up to 90 days, or until the session ends.
- Hashed user identifier and usage metadata — up to 24 months, then deleted.
- Technical logs — a few days.
- Workout data — not retained (in transit only).
Your rights and controls
- Disconnect at any time by removing the Liftin' connector/app in your AI assistant's settings. Sessions also expire automatically.
- Under the GDPR you have the right to access, rectify, erase, and port your data, to object to or restrict processing, and to lodge a complaint with a supervisory authority (in Sweden: Integritetsskyddsmyndigheten, IMY).
- To exercise any right, or to have all Connector data linked to you deleted, email support@liftinapp.co.
- Your workout data itself is under your control in iCloud and in the Liftin' app — deleting data there deletes it at the source.
Children
The Connector is not directed at children under 13, and we do not knowingly process their data.
Changes
If this policy changes materially, we will update the effective date above and note the change on this page.
Contact
nstrm AB support@liftinapp.co