Privacy Policy URL: https://www.rirlift.com/privacy/
Privacy Policy
RIRLift is a local-first training log for iPhone and Apple Watch. This policy explains what information the app and website handle, why it is used, and which controls are available to you.
Effective date: September 25, 2026
Summary
RIRLift does not sell personal information and does not include third-party advertising. The app stores routines, exercises, sets, RIR, notes, workout history, and weekly volume locally first on your devices. If iCloud is available, the app backs up your training log and training preferences to your private iCloud database so they can be restored after reinstall. Network services are also used for purchase status, support requests, crash, error, and performance diagnostics, explicit product analytics, selected logs, measurement of RIRLift's own App Store ad campaigns, connected-AI features you explicitly enable, and backend operations. The web planner at app.rirlift.com has no accounts and stores your drafts in your own browser.
Workout data
Your training log is stored on your iPhone and Apple Watch. iPhone and Apple Watch sync data with each other so planned routines, active workouts, completed sessions, support ID, and purchase access can stay consistent across devices. If iCloud is available, RIRLift backs up routines, custom exercises, full workout history, training units, weekly hard-set target, and muscle-map model preference to your private iCloud database. The current app version does not upload your full training log to a RIRLift account-sync backend. Product analytics may include summary workout metrics such as duration, exercise count, set count, and whether a workout used substitutions, but not your exercise names, notes, or full set-by-set log.
Apple Health
If you grant permission, RIRLift can save completed strength workouts to Apple Health. During Apple Watch workouts, RIRLift can read heart rate and active energy recorded by Apple Watch for the workout session and store a workout heart-rate summary in your local training log. On iPhone, RIRLift can read matching workout records when you choose to delete a workout from both RIRLift and Apple Health. Limited HealthKit diagnostic metadata, such as a RIRLift workout ID, HealthKit source bundle identifier, operation status, and error messages, may be sent to logs to troubleshoot Health integration issues. Apple Health permissions are controlled by iOS and watchOS settings, and Health data is not used for advertising or tracking.
Connected AI, Coach, and ChatGPT plugins
RIRLift can connect your training log to an AI service you choose, such as Claude or ChatGPT. This user-chosen connection is off by default. When you connect one, RIRLift uploads a replaceable training snapshot to its Cloudflare backend and binds access to a revocable grant for this installation. The snapshot can include your app version, unit and reply-language preferences, current program and routines; recent workout dates, duration, routine names, exercises, sets, reps, load, bodyweight, timed-work duration, and RIR; and derived summaries such as weighted muscle volume, estimated strength trends, effort accuracy, consistency, personal records, and modeled muscle freshness. It does not include your name, email, workout notes, heart rate, or other Apple Health data.
The connected service receives only the parts of that snapshot needed when you ask it to use RIRLift. Its handling of that copy is governed by your agreement with that service. If you ask the service to send a program to RIRLift, RIRLift stores the proposed program as a pending draft for you to review; it does not become part of your training until you approve it in the app. Pending drafts expire after 30 days, and resolved or expired draft records are removed later as part of routine cleanup.
A new snapshot replaces the previous one rather than creating a server-side history. Disconnecting an AI or unpairing a browser revokes that connection's access and removes its pending drafts. RIRLift stops uploading and deletes the snapshot after you have disconnected every AI and unpaired every browser that used it. You can manage both connections from the app at any time.
Coach is RIRLift's built-in AI feature and is separate from those user-chosen connections. When you send a message to Coach, RIRLift sends that message and the training context selected for the request through RIRLift's service to Google Vertex AI. Depending on where you opened Coach and what you asked, that context can include relevant routines, recent workouts, exercise progress, training volume, recovery, the current or completed workout, and Coach preferences you saved.
The same request is also processed by TypeSafe (api.typesafe.ai), a second AI service RIRLift uses to decide which of your training records a reply needs and to check each draft reply against the records it cites before you see it. TypeSafe receives your message, the training context selected for the request, the recent conversation, and the draft reply with the records it cites. TypeSafe does not train on this data. It retains it only as long as needed to process the request under its data-processing terms, and it is based in the United States, so that data is transferred outside the European Economic Area under the safeguards in those terms.
Coach conversations, confirmed memories, session feedback, and accepted-change review records are stored locally. After you accept the Coach disclosure, these records also participate in your private iCloud backup when it is available. Coach archives are separated by iCloud account. Unsent drafts and pending request credentials remain on the device. You can inspect and remove Coach records in the app; deletion records prevent an older iCloud copy from restoring removed conversations or memories. RIRLift's backend temporarily stores the request, selected tool results, and response to support interrupted requests and checked delivery, and to diagnose requests that fail or are cancelled. This content expires no later than 24 hours after the request begins, including retries. An hourly cleanup removes expired content; longer-lived quota records contain usage metadata rather than conversation or training content. It also stores authentication, operation, purchase-access, and usage metadata needed to verify access, prevent duplicate or concurrent requests, and enforce usage limits. Coach analytics can record events such as a request, completion, failure, cancellation, or proposal action, together with technical IDs, mode, outcome, and error code; raw chat messages and assistant responses are not sent in this telemetry. Firebase Anonymous Authentication provides an anonymous account identity, and Firebase App Check verifies that requests originate from the app. Existing purchases and RevenueCat identities remain unchanged; for the hosted Coach allowance, the server separately verifies Apple's signed purchase data and current status.
Purchases
RevenueCat handles purchase, restore, entitlement, and paywall state for RIRLift Pro. RIRLift uses a local device ID as the RevenueCat app user ID so your Pro access can be restored and synced. The backend also stores RevenueCat webhook events and entitlement projections, including app user ID, product ID, environment, purchase dates, renewal and expiration dates where applicable, and event identifiers, to reconcile your purchase or subscription status. When RevenueCat notifies the backend that your access changed, the backend also records a purchase-confirmation event to RIRLift's own product analytics; that event carries the app user ID, product ID, environment, entitlement, and those dates, and no training data.
Support requests
When you submit the support form, RIRLift stores the topic, reply email, optional support ID, message, source, user agent, ticket status, and timestamps. This information is used to answer the request, diagnose reliability issues, and protect the support form from abuse.
Analytics and crash reporting
RIRLift uses PostHog EU Cloud for explicit product analytics, selected logs, and handled error reporting. The app identifies analytics with a generated local device or support ID and basic entitlement status. The app disables broad screen-view capture, element autocapture, and session replay. Events focus on activation, summary workout completion metrics, watch sync, paywall views, purchases, restores, and reliability. RIRLift also uses Sentry for crash, error, and performance diagnostics.
The rirlift.com website records page views and App Store button clicks in PostHog EU Cloud, sent by our server rather than your browser, without cookies and without storing anything on your device. Each event records the page, the referring site, any campaign tags in the link, your country and time zone, and your device type. To count unique visitors, PostHog combines your IP address and browser user-agent with a random value that is replaced every day and deleted within a few days, and discards the IP address and user-agent before storing the event. The result identifies a visit for at most one day and cannot be linked to you or to later visits.
Advertising measurement
RIRLift advertises itself on the App Store, and uses Google Analytics for Firebase, provided by Google, to measure which of its own campaigns produced a purchase. When you complete a purchase in the app, RIRLift sends Google a purchase event carrying the product identifier, the price you paid, and its currency. That event, and the app's own start-up events, are linked to a pseudonymous app-instance identifier that Firebase generates for this installation of the app, together with the technical context that identifier already carries: app version, device model, operating system version, language, and an approximate region derived from your IP address. The measurement is linked to that app-instance identifier, not to your name or your email address. Nothing from your training log is sent to Google: no workouts, sets, RIR, routines, exercises, notes, or Apple Health data.
When RIRLift advertises inside another company's app, Apple may send that advertising network a SKAdNetwork postback about the install. The networks RIRLift runs or may run such campaigns with are Google, Reddit, and Meta, and those are the networks that can receive one. A postback is prepared and signed by Apple, not by the app: it reports that an install followed an ad, and it carries no name, no email address, no device identifier, and no advertising identifier. Apple delays each postback and withholds detail that falls below its own privacy thresholds. A network whose ad was shown but did not win the attribution can also receive a postback recording that it did not win. RIRLift sends these networks nothing itself, and no part of your training log reaches any of them. RIRLift also advertises on the App Store itself; those campaigns are measured through Apple's own attribution API described in the next paragraph, not through SKAdNetwork.
RIRLift does not use Apple's advertising identifier (IDFA). The app links the IDFA-free build of Google's SDK, so it cannot read that identifier and never shows an App Tracking Transparency prompt, and its privacy manifest declares tracking as false. RIRLift does not track you across other companies' apps or websites, does not build or share advertising audiences, and does not use your data for personalized advertising. Apple's own attribution API is used in the opposite direction: it tells RIRLift which App Store campaign, ad group, or keyword an install came from, and those campaign identifiers are stored with the app's product analytics described above.
Web planner
The web planner at app.rirlift.com lets you build a training program in a browser and send it to the app. It has no accounts and no sign-in. Programs you build are held in your browser's local storage on your own device. When you choose to send a program to your phone, the program itself may be stored briefly on RIRLift servers so the phone can fetch it: this holds the program content only, is not linked to you or to any device or account identifier, and is deleted automatically after a day. Nothing is stored server-side until you ask to send a program, and your training log is never uploaded by the planner. The planner writes programs to the app; it never reads or writes your workouts, sets, or records.
The planner uses PostHog EU Cloud for anonymous usage measurement, configured without cookies and without persistent identifiers, so visits cannot be linked to each other or to you across days. Events record only how the planner itself is used, such as that a program was built or a delivery method was chosen. Program names, routine names, and exercise selections are not sent to analytics.
Shared program pages
The planner can publish a program to a public page at www.rirlift.com/p/…. This is the one place where content you write becomes readable by anyone, so it is worth being precise about it. Publishing is never automatic: it happens only when you press the share button, and the planner warns you first.
A published page holds the program you wrote — its name, the names of your training days, the exercises, and any notes you added. Do not put other people's names or health details in those fields if you intend to share the page. The page holds nothing else: no account, no device identifier, no IP address, and no part of your training log. The page address is a long random value that is not listed anywhere and is not guessable, and search engines are told not to index it unless you opt in when you publish.
You can delete a published page at any time from the planner in the browser you created it in, which keeps the delete key for you; the key is also shown once at creation so you can keep it elsewhere. Deleting removes the page and its record immediately, though a copy already held by a content delivery cache can remain readable for up to five minutes. A page that nobody opens for twelve months is removed automatically. If a page carries something that should not be public, report it with the form at the bottom of the page; reports go to the same inbox as other support requests and are read by a person.
Sharing and processors
RIRLift uses service providers only to operate the app and website: Apple platforms and Apple Health, Apple iCloud for private backup and restore, RevenueCat for purchases, PostHog EU Cloud for analytics and logs, Sentry for crash, error, and performance diagnostics, Google (Google Analytics for Firebase, and Google Ads) for measuring RIRLift's own App Store campaigns, Google Vertex AI and TypeSafe for Coach as described above, and Cloudflare for hosting, backend services, connected-AI snapshots, program drafts, and support-ticket storage. When you connect an AI service, Anthropic or OpenAI receives the requested training data under your agreement with that service, not as a RIRLift analytics or advertising provider. Separately from those service providers, the advertising networks described above — Google, Reddit, and Meta — can receive Apple's SKAdNetwork postbacks for RIRLift's own campaigns. When they do, they act on their own behalf rather than as RIRLift's service providers, because the postback is sent by Apple and is used by the network to measure its own advertising. Those providers are based in the United States, so the advertising-measurement data described above is transferred outside the European Economic Area under the safeguards set out in each provider's own data-processing and advertising terms. RIRLift does not sell your data. The only data shared with an advertising network is the measurement described above, for RIRLift's own campaigns; nothing is shared for third-party ad targeting, audience building, or personalized advertising.
Retention and controls
- Training data remains on your devices until you delete it in the app or remove the app data.
- Private iCloud backups are managed through the iCloud account and app data controls on your Apple devices.
- Apple Health access can be changed in iOS and watchOS Health permissions.
- Support requests are kept as long as needed to respond, investigate issues, prevent abuse, or satisfy legal obligations.
- Purchase and backend operational records are kept as needed to provide access, restore purchases, and maintain auditability.
- Analytics, logs, and diagnostics are kept as needed to understand app use, troubleshoot reliability, and operate the service.
- Advertising-measurement events sent to Google are kept under the data-retention setting configured for RIRLift's Google Analytics property.
- Programs you build in the web planner stay in your browser until you clear them; a program sent to your phone is deleted from RIRLift servers automatically after a day.
- A connected-AI snapshot replaces the prior snapshot and is deleted after you disconnect every AI and unpair every browser that used it; pending AI program drafts expire after 30 days.
Children
RIRLift is not directed to children under 13. If you believe a child has submitted personal information through the support form, contact support so it can be reviewed and removed where appropriate.
Changes
This policy may be updated as RIRLift changes. Material updates will be posted on this page with a new effective date.
Contact
Use the support page for privacy questions, data questions, purchase help, accessibility, or account support.