Privacy Policy
Last updated: 11 September 2026
1. Overview and who we are
This Privacy Policy explains what data ProLyft ("we", "us") collects, why we collect it, how long we keep it and the choices you have. It applies to the ProLyft mobile app, our website at prolyftapp.com and related services. The controller of your personal data is MuscleHealth OÜ, registry code 17596698; you can reach us about any privacy matter at support@prolyftapp.com. We never show ads, we never sell your personal data, and we use no advertising trackers. We use no product analytics today and run no analytics SDK. Section 10 sets that out in full, including the one narrow exception — the crash reports Apple and Google pass to us while the app is in beta testing.
2. Data we collect
This is the data we collect, grouped by kind. Section 5 explains what we use it for and section 13 how long we keep it. Account and identity: your email address and password (stored only as a salted hash by our authentication provider) or, if you use Apple or Google sign-in, the account identifier, email address and name those providers return. Profile: name, username, nickname, profile picture, date of birth, gender, language and unit preferences. Body and training data — the record the app exists to keep, and the input to your estimates: body weight and height if you enter them, experience level, and your training history — workouts, exercises, sets, reps, loads, RPE, durations, distances, rest, personal records, streaks, unlocked achievements and any free-text notes you add to a set or exercise. Training setup: your available equipment, weekly target, active programme and schedule. Social: your nickname, who you follow, who follows you, follow requests and users you have blocked. Reports of abuse: if you report another user, we store your account identifier, the account you reported, the reason you chose, the note you write if you write one, and a copy of that account's nickname and profile picture as they stood when you reported them, so the evidence cannot be edited away before we look at it. If someone reports you, the same record is about you, and the reporter's identity is not shown to you. Purchases: your subscription status, the store product and transaction identifiers Apple or Google return through our subscription provider RevenueCat (section 11), and whether a free trial has already been used — we never receive your card or payment details. App settings: notification mode, keep-screen-awake, achievement pop-ups and tutorial progress. Technical: the UTC time-zone offset saved with each workout; the contents of any email you send us; and, when the app checks for a code update, a randomly generated installation identifier together with your platform, the app's runtime version and release channel, and, if a recent update failed to launch, the identifiers of those updates so a broken release is not served to you again. That identifier belongs to the update service described in section 11: it is not linked to your ProLyft account and it is not stored in our database. Abuse prevention: like any request on the internet, a request to our servers carries the IP address your device is connecting from. We use it only to limit automated abuse of account creation and of our email sending — it is not stored as an address but as a one-way hash under a key we hold, it is not linked to your account, your profile or your training data, and it is never used to identify you, to locate you or to track you. Those values are kept for a few days and then erased (section 13), and our basis is our legitimate interest in keeping the service secure (section 4). Separately, as with any web request, the address is visible to our hosting provider's servers and appears in their technical logs, kept for a short period for security and fault diagnosis and likewise not tied to your account. Device permissions: the app asks the operating system for three things, each only at the moment it is needed. Access to your photo library, when you tap to change your profile picture — we receive the single image you choose, never a listing of your library. Permission to save an image, when you export a share card to your photos. And notification permission, requested once when you start a workout, so that the running session can appear as an ongoing notification and workout reminders can be posted; both are created on your device rather than sent from a server (section 11). We do not ask for camera, microphone, location, contacts or calendar access. We do not collect usage-analytics events, your precise location, your contacts, your photo library beyond a picture you deliberately upload, or any advertising identifier.
3. Health and fitness data
Body weight, height and a detailed training history say something about your physical condition, and in the EU, EEA and UK data of this kind can qualify as health data — a special category with extra protection. We treat it that way. You provide it voluntarily and we process it on the basis of your explicit consent, given when you enter it and withdrawable at any time by clearing the values or deleting your account. Body metrics are optional: the app works without them, though weight-based estimates and tailored programmes will be less accurate. We never share your health or training data with advertisers, insurers, employers or data brokers, and we never use it to build a profile of you for anyone but you.
4. Legal basis for processing
Where the GDPR applies, we rely on: performance of our contract with you — running your account, storing and syncing your workouts and delivering paid features; your explicit consent — body and health data, and the optional social and sharing features; our legitimate interests — keeping the service secure, preventing and investigating abuse and acting on reports of it (including the abuse prevention described in section 2), delivering updates and fixes to the app, diagnosing faults, whether you report them or the update service tells us a release has failed to launch, and defending legal claims, balanced so they do not override your rights; and compliance with legal obligations, such as keeping records of purchases. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
5. How we use your data
We use your data to log and sync your workouts across your devices; to calculate statistics, personal records, streaks and progress; to tailor training programmes, suggested loads and exercise substitutions to your profile, equipment and history; to run the social features you choose to use; to review reports of abuse and enforce our Terms; to prevent automated account creation and abuse of our email sender, as described in section 2; to send the transactional emails the service needs, such as welcome and password reset; to manage subscriptions and entitlements; and to answer your support requests. We do not use your personal data for advertising.
6. Automated personalisation
Your suggested programme, session loads and exercise substitutions are generated automatically from the data you enter — body metrics, experience level, available equipment and training history. These are training suggestions only. They produce no legal or similarly significant effect, they are never used to profile you for a third party, and you can override, change or ignore any of them.
7. How and where your data is stored
ProLyft is offline-first: your workout and body data is saved to a local database on your device first, then synced in the background to our cloud backend (Supabase) so you can restore it and use it across devices. Our production database, authentication service and file storage run on Supabase hosted on Amazon Web Services in the eu-west-1 region (Ireland) — inside the European Union and the EEA. In other words, the primary store of your account, profile, body and training data stays in the EU. Cloud data is protected by per-user access rules enforced by the database itself, so only your account can read your rows. Your sign-in tokens are held in the iOS Keychain or Android Keystore rather than in plain storage. When you sign out or delete your account, the app clears your training data from the device — but only if everything has already reached the cloud. If even one record is still waiting to sync, nothing is cleared: your local data stays on the phone in full until a later sign-in can upload it. That is deliberate, because losing an unsynced workout would be the worse outcome, and it is not unusual — finishing or abandoning a workout shortly before signing out is enough to trigger it. Either way, data left on the device is never shown to another account signing in on the same phone. Copies may also remain in backups you make of your own phone, which are outside our control.
8. Social features and what others can see
If you use the social features, this is what leaves your account. Any signed-in user who searches can find you by your nickname, username or name, and sees those three fields plus your profile picture. Someone whose follow request you have accepted additionally sees your current streak and your longest streak. A follower you promote to close friend also sees how many workouts you have completed this month and this year, and your five most recent personal records with the exercise, the reps, the weight and the date. No other user sees your email address, your date of birth, your body metrics, your individual sessions, your notes, your routines or your schedule. Blocking someone removes the follow relationship in both directions, takes you out of their search results and prevents further interaction; we keep a record of the block so that it stays enforced. Share cards you export are images created on your device that may carry your nickname and your training numbers; once you post one outside ProLyft, it is beyond our control and this policy no longer governs it.
9. Your profile picture
Profile pictures are served from a public web address, the same way most apps serve avatars. That means the image file itself can be opened by anyone who has the link, including people who are not signed in to ProLyft — so choose a picture you are comfortable being seen outside the app. The address contains your account identifier, the same identifier described in section 11. Nothing else is served this way: your training, body, account and social data are not. When an account is permanently deleted — after the 7-day restore window described in section 13 — the picture is removed from storage along with it and the link stops working. Copies that other people have already saved are, as with any image on the internet, outside our control.
10. What we never do
We do not sell or rent your personal data. We show no third-party advertising and we never use your data for advertising. We do not track you across other apps or websites, we request no advertising identifier, and we use no attribution or ad-network SDKs. We run no product analytics today: no analytics SDK, no analytics processor, and no behavioural events — no screen views, no feature usage, no session tracking. We also run no crash-reporting service. We do intend to add product analytics in a later release, to understand faults and improve the app; when we do, we will name the provider and its place of processing in section 11, list what it collects in section 2, and tell you in the app before it starts collecting anything. There is one narrow exception today: while ProLyft is in TestFlight or Google Play internal testing, Apple and Google collect crash reports at the operating-system level and pass them to us (section 11). That ends at public release, and it carries no account, profile, body or training data. On health data specifically: we do not sell or share your training or health data, and the planned link with Apple Health and Health Connect will not change that. It is designed to read only — activities your watch or another app has already recorded flow into your ProLyft activity list, so that a run you logged elsewhere counts toward your streak. Nothing flows the other way. The integration is not built yet, it will stay off until you connect it, and it will ship with a disconnect-and-delete action that removes what was imported. If we ever add an outbound write, it will be opt-in and described here first.
11. Service providers
We use a small number of processors, each handling only what its job requires, and the place of processing is named for each. Supabase — authentication, database, file storage and cloud sync; place of processing Ireland, in the EU (see section 7), and this is where your account and training data lives. Resend — delivery of transactional email such as welcome and password-reset messages; it processes your email address; place of processing the United States. Apple and Google — optional sign-in; if you use it, they confirm your identity and return an account identifier, email address and name; place of processing Ireland and the United States. Apple App Store and Google Play — subscription purchases; each is the merchant of record, which means the payment contract is between you and them: they take the money and they issue the receipt. We never see or receive your card number or bank details; all that reaches us is the product identifier, a transaction identifier and whether the subscription is active, and it reaches us by way of RevenueCat rather than directly from the stores. Cancellations and refunds are handled in your store account. Place of processing Ireland and the United States. RevenueCat (RevenueCat, Inc.) — subscription management. It sits between the stores and us and tells us which subscription your account holds. It receives the subscription events Apple and Google relay — the product identifier, a transaction identifier, the purchase and expiry dates, whether a free trial has already been used, and renewal, cancellation and refund events — together with your ProLyft account identifier, which is what matches a purchase to the right account, and the platform and app version its SDK attaches. That identifier is not your name or your email address, but it is stable, it is the identifier your account carries across our systems, and if you have uploaded a profile picture it also appears in that picture's public web address (section 9) — so we treat it as personal data rather than as anonymous. RevenueCat receives no email address, no nickname, no body metrics, no training data and no notes, and it takes no money. Place of processing the United States. Expo (650 Industries, Inc.) — the build toolchain, and over-the-air delivery of app updates; place of processing the United States. When the app starts, and when you come back to it after a long time away, it asks Expo's update service (u.expo.dev) whether newer app code is available. That request carries a randomly generated installation identifier stored on your device, your platform, the app's runtime version and release channel, and, if a recent update failed to launch, the identifiers of those updates so a broken release is not served to you again. Like any request to any server on the internet, it also reveals your IP address to the server that receives it — that server is Expo's, not ours; the address never reaches our systems, we keep no copy of it, and there is no IP field on your account. The request carries no account, profile, body or training data, and the installation identifier is not linked to your ProLyft account or stored in our database. You cannot switch this off inside the app: it is how we ship fixes without waiting for a store release. Our content management provider — the system our exercise library is authored in. No account, workout or body data is ever sent to it: content flows one way, into the app. Exercise images load from its image CDN, so, as with any web request, your device's IP address is visible to the server that serves the image; it is not passed on to us and we keep no copy of it. Place of processing the United States and its CDN edge locations. Apple TestFlight and Google Play internal testing — beta distribution, while ProLyft is in beta. To take part you give Apple or Google the email address on your store account, they tell us which testers have installed a build, and they pass us crash reports and any feedback you send from the test build. That is processing by Apple and Google on our behalf, for the beta only; it ends when the app is publicly released, and you can leave a test programme at any time in TestFlight or Google Play. Reports of abuse are reviewed by us, on our own infrastructure (Supabase, Ireland). No outside moderation provider or reviewer is involved. Finally, workout reminders and the live-session notification are created locally on your device by the app itself, so no push token is created and no push-notification service receives anything about you.
12. International transfers
Your account, profile, body and training data is stored in the European Union — Supabase on AWS eu-west-1 in Ireland, as described in section 7 — so our primary database involves no transfer outside the EEA at all. Only a few supporting services sit outside the EEA, and only for the narrow data each one needs: Resend, which receives your email address in order to deliver transactional mail; Apple and Google, if you use their sign-in or buy a subscription through their stores; RevenueCat, which receives the subscription events and the account identifier described in section 11; Expo, which receives the update-check data; and our content management provider's image CDN, which sees your IP address when you load an exercise image. Where personal data does leave the EEA or the UK, we rely on the transfer mechanisms available under the GDPR — principally the European Commission's Standard Contractual Clauses in our agreements with those providers, the UK Addendum where relevant, and the EU–US Data Privacy Framework where the recipient is certified under it. You can ask us for details of these safeguards at support@prolyftapp.com.
13. How long we keep your data
Account, profile, body and training data: for as long as your account exists. Individual records you delete: a deleted workout, exercise or routine disappears from the app immediately and is permanently erased from our database by a daily job 30 days later. Deleted accounts: deletion starts a 7-day restore window, and signing back in within those 7 days restores everything. After 7 days a daily job permanently deletes your account, and the database cascade removes your profile, workouts, sets, personal records, streaks, achievements, custom exercises, routines, schedules, follows and blocks. That same job also removes your profile picture file from storage. Reports of abuse: kept while the report is open and, once it has been actioned or dismissed, kept afterwards as the record of that decision, so that repeated behaviour can be recognised. If the person who filed a report deletes their account, their identity and their written note are erased from the report and the rest of it stands; if the reported account is deleted, the report goes with it. Abuse prevention: the hashed values described in section 2 are erased a few days after they arise. Backups: residual copies may persist in encrypted backups for a short period before being overwritten. Purchase records: Apple and Google are the merchants of record for every subscription — they take the payment and issue the receipt — so the transaction record is theirs, held under their own policies and the tax law that requires them to keep it. Deleting your ProLyft account does not erase it and we cannot erase it for you; ask the store directly. On our side, RevenueCat holds the subscription events described in section 11, and we keep the accounting records Estonian law requires for seven years. Support email: kept while we handle your request and for a reasonable period afterwards.
14. Your rights
Depending on where you live — for example under the GDPR in the EU and EEA, the UK GDPR, or state privacy laws in the United States — you may have the right to access your personal data, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent you have given. In the app you can view and edit your profile and body metrics, edit or delete individual workouts, and delete your account entirely. To object to or restrict a particular kind of processing, or to receive a machine-readable copy of your data, email support@prolyftapp.com — we handle these requests manually and will respond within 30 days. We do not charge for this and we will never treat you differently for exercising a right. If you are unhappy with how we handle a request, you may complain to the data-protection authority where you live. Because we are established in Estonia, our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, info@aki.ee, www.aki.ee). Your choices, in one place. Body and health data: withdraw your consent by clearing the values in your profile. Social: make yourself unreachable by removing your followers and leaving requests unapproved, or block an individual user. Subscriptions: manage, downgrade or cancel in your Apple App Store or Google Play account settings — that is the only place a subscription can be cancelled, because Apple and Google are the merchants of record (section 11). Notifications: turn them off in Settings or in your device's system settings. Photo access: revoke it in your device's system settings; only the profile-picture feature needs it. Beta builds: leave the test programme in TestFlight or Google Play. Everything else: delete your account in Settings, which starts the 7-day window described in section 13.
15. Children
ProLyft is designed for adults and teenagers, and the minimum age for an account is 13. It is not directed at young children and we do not market it to them. Article 8 of the GDPR sets the age for consenting to a service like this at 16 and lets each EU and EEA country lower it, but no further than 13; below the age that applies where you live, a parent's or guardian's consent is needed. Estonia has set it at 13, so if you live in a country that has kept a higher age, you can use ProLyft with a parent's or guardian's consent until you reach it. We do not knowingly collect personal data from a child below the age that applies to them: if we learn that we hold data from a child under 13, or from a child below their own country's age without the necessary consent, we delete the account and the data behind it. A parent or guardian who believes their child has created an account can write to support@prolyftapp.com with the nickname or the email address on it, and we will remove it. Where the country you live in sets an age below which a child cannot agree to a service like this on their own, that rule applies whatever the app itself allows.
16. Security
We protect your data with encryption in transit, encryption at rest by our hosting provider, per-user access rules enforced inside the database rather than only in the app, sign-in tokens stored in the device's secure keychain, server-side checks on entitlement and social actions so they cannot be altered from a modified client, and rate limits on account creation and on verification email (section 2). No method of storage or transmission is 100% secure. If a personal-data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as the GDPR requires; and where the breach is likely to result in a high risk to you, we will tell you as well, without undue delay.
17. Changes and contact
We will announce material changes to this policy in the app before they take effect and update the date at the top of this page. If a change concerns health data or adds a new processor, we will ask for your consent again where the law requires it. Questions, requests to exercise your rights, or anything else about your data: support@prolyftapp.com. The company acting as controller, and its postal address, are in section 1.