Liftpact
This is a translation. The legally binding version is the German one: Datenschutzerklärung. In case of any discrepancy, the German wording applies.
Liftpact is a safe, gamified gym social space. Privacy matters to us: we collect only what the app needs to work, and we run no tracking and no advertising.
Panagiotis Chaitidis
Viersenerstr. 5, 41751 Viersen, Germany
Email: kontakt@liftpact.de
On sign-up: your email address and a password (stored encrypted). Optionally a display name and username (@) so friends can find you. If you sign in with "Sign in with Apple", we receive an identifier provided by Apple and — unless you hide it — your email address. If you use "Sign in with Google", we receive an identifier, your email address and your name from Google (you can change the name afterwards). If an account with the same email address exists, the Google sign-in is added to that account. When you sign up with an email address, we send you a confirmation email; the account can be used once you confirm it.
Inside the app you can record voluntarily:
This content is private by default, or visible only to the people you have chosen (crew, friends) — controlled by the privacy settings in your profile. Nothing is public by default.
If you allow notifications, we store a device token so we can send you reminders, friendship and message alerts. On iPhone they are delivered via the Apple Push Notification service (APNs), on Android via Google's Firebase Cloud Messaging (FCM). The title and text of each notification pass through Apple or Google respectively. You can turn notifications off at any time in your device settings.
On iPhone Liftpact works with Apple Health, on Android with Health Connect. The same applies to both: Liftpact asks for a data type only when you tap the feature that needs it, and only accesses it after your device has asked for your permission. You can allow or deny each data type separately.
The values read are treated differently: some are stored in your account, others never leave your device. We do not read any health data other than what is listed here — except for your Apple Watch's readings during a workout (see below). The name of each data type in Health Connect is given in brackets.
Steps (Steps). Requested when you allow the connection to Apple Health or Health Connect during onboarding or on the steps card. Liftpact reads your daily totals for up to the last 30 days and stores them as daily values in your account — exactly as if you had entered them by hand.
Sleep (SleepSession) and resting heart rate (RestingHeartRate). Requested when you tap "Include sleep and resting heart rate". Both are evaluated on your device only, for the hint whether a hard training day makes sense today. These two values never leave your device and do not reach our servers.
Active calories (ActiveCaloriesBurned). If you allow it separately on the home screen under "Your day", Liftpact reads the active energy you burned today and shows it there. This daily value is shown on your device only, not stored, and does not reach our servers.
Requested when you tap the import from Apple Health or Health Connect in the running section. Liftpact then reads the sessions of the last 30 days — runs, walks, hikes, bike rides, swimming, rowing and elliptical — and with them:
This summary (date, start time, type, duration, distance, average heart rate, calories) is stored in your account so that your runs count in your history, streak and leaderboard. We do not read strength workouts from Health — the app records those itself.
If you start a workout on your Apple Watch, the watch measures your heart rate and active calories during it and displays them; the heart rate is also shown on your iPhone. For strength workouts these values are not stored — neither by us nor as a separate workout in Apple Health. During a GPS run, the measured heart rate feeds into the run's average heart rate (see section 2f).
Liftpact also writes data to Apple Health or Health Connect — but only if you have allowed it:
For all data Liftpact receives from Apple Health or Health Connect — in line with Apple's requirements for HealthKit and Google's for Health Connect (Limited Use):
You can revoke access at any time: on iPhone under Settings → Privacy & Security → Health → Liftpact, on Android in the Health Connect settings under the app permissions for Liftpact. Daily values and runs already imported stay in your account until you delete them or delete your account. Anything Liftpact has already written to Apple Health or Health Connect stays there until you delete it there.
The legal basis is your explicit consent (Art. 9(2)(a) GDPR), as these values can constitute health data. Without this permission the app works unchanged — manual entry remains.
So that we can see which features are actually used and where users get stuck, Liftpact stores technical events together with your user identifier. An event is, for example: app started, checked in, set saved, joined a crew, nudge sent, permission granted or denied, or which area of the app you opened (such as "Workout" or "Rank" — only the name of the area, no content and no dwell time).
The legal basis is our legitimate interest in improving the app (Art. 6(1)(f) GDPR). You may object to this processing at any time — write to the address given in section 1.
In the body section you can voluntarily store progress photos to see changes over time. These photos are technically separated from all other images in the app and are visible only to you:
The legal basis is the performance of the user relationship (Art. 6(1)(b) GDPR); where a photo allows conclusions about health data, we additionally rely on your explicit consent (Art. 9(2)(a) GDPR), which you give by uploading and can withdraw at any time for the future by deleting the photo.
In the Food section you can log what you eat, entirely voluntarily. These entries are visible only to you — they never appear in the feed, in crew views or in leaderboards, and they are not shared with anyone.
The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR); in so far as nutrition entries allow conclusions about health data, we additionally rely on your explicit consent (Art. 9(2)(a) GDPR), which you give by making an entry and can withdraw for the future at any time by deleting it.
Scanning uses the camera. In doing so:
To find the nutrients behind a barcode, and when you search for a food by its name, we query the open food database Open Food Facts in addition to our own database. What matters for you:
You buy Liftpact Plus and the streak shields from Apple on iPhone and from Google Play on Android, not from us. We receive no payment data — no card number, no billing address, no name.
What we store is the signed receipt issued by Apple, so that we can unlock your subscription and process a refund:
We need this to verify that a purchase is genuine and belongs to your account (Apple returns an identifier we set at purchase time), and to reverse it on a refund. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
For a purchase through Google Play, our server verifies the purchase receipt signed by Google and asks Google for the current state of the purchase. We store:
When you buy, the app passes an identifier of your account to Google so that the purchase can be matched to your account. Purposes and legal bases are the same as for Apple.
How long we keep purchase receipts: as long as your account exists. If you delete your account, we delete the purchase receipts stored with us along with it. Billing is handled by Apple or Google; invoices and payment data are held there, not by us — you will still find your purchases there after the deletion.
Cancelling, prices and refunds are handled solely by Apple or Google Play. We have no view into that and cannot change anything; on iPhone your route is Settings → your name → Subscriptions, on Android the Play Store app → Profile → Payments & subscriptions.
When you record a run, walk, hike or bike ride with GPS, the app uses your location — only while the recording is running, and only after you have granted your device's location permission. Liftpact only asks for the "while using the app" permission, no background location permission. So that the recording continues while the screen is locked:
To draw the map, your device loads map tiles directly from OpenFreeMap (tiles.openfreemap.org, map data from OpenStreetMap). In doing so OpenFreeMap receives — as with any web request — your IP address and learns which map area is being loaded. We do not transmit an account identifier or the route itself. Tiles are only loaded when the app shows a map — during a recording and for your GPS runs. The legal basis is providing the feature you use (Art. 6(1)(b) GDPR).
With the boxing timer and the boxing coach you train boxing, kickboxing or Muay Thai in rounds. For this we store:
The app saves both on your device first and then uploads them to your account, so nothing is lost to a dead spot and everything is there again on a new device.
The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR).
You can invite friends to Liftpact with your personal invite code. For this we store:
Once an invite is successful, the inviting person receives a notification with the invited account's display name. The data is deleted with your account. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR); redeeming a code is voluntary.
Invite link. Instead of the code, a link of the form
liftpact.de/r/CODE can be shared. The page behind it only
shows the code and links to the app stores; it does not check the code
and stores nothing. If the app is installed, the link opens it directly
and fills in the code. On Android, the page adds the code
to the Google Play link; after installation the app reads it once from
Google Play via the Play Install Referrer API and fills it
in. On iPhone, the page copies the code to the clipboard;
the app only reads the clipboard when you tap “Paste” while signing up.
In every case, the code is only redeemed when you sign up or tap
“Redeem”.
Creator codes. Some creators offer their followers a discount on Liftpact Plus. You redeem these discount codes with Apple or Google, not with us; the discount is granted by Apple or Google. The purchase receipt we receive from Apple or Google (see section 2e) names the redeemed offer. From it we store which creator code your subscription belongs to, when it started and whether it was a test purchase. In the app, the creator sees only numbers (how often their code was redeemed, how many of these subscriptions are active) — never who redeemed it. We use the assignment to settle accounts with the creator. The legal basis is our legitimate interest in this settlement (Art. 6(1)(f) GDPR). The assignment is deleted with your account.
If a saved workout is clearly below your own average on several exercises, the app asks what caused it. Answering is voluntary; closing the card saves nothing. If you answer, we store with that workout:
The app then suggests no increase for these exercises next time, does not count the day as a setback, and shows you patterns in the analysis (for example "on days with little sleep 8 % weaker on average"). The entries are only visible to you — never in your crew, feed or leaderboards — and are included in the data export.
"Ill / pain" and "cycle" are health data. The legal basis is the feature you requested (Art. 6(1)(b) GDPR), for the health entries additionally your explicit consent (Art. 9(2)(a) GDPR), which you give by tapping them. You can withdraw it at any time: if you switch "cycle" off in the settings, you can delete your previous cycle entries along with it; deleting the workout or your account deletes all entries.
The app stores data with Supabase Inc. (database, authentication, file storage), with whom a data processing agreement is in place. This project's database and file storage are located in the Frankfurt am Main region, Germany (AWS eu-central-1). Where Supabase as a US provider has access beyond that, or processing takes place outside the EU, this is safeguarded by appropriate guarantees (EU standard contractual clauses). Push notifications are delivered via Apple (APNs) on iPhone and via Google (Firebase Cloud Messaging) on Android. Emails (confirmation, forgotten password) are sent through the mail server of our domain provider STRATO GmbH (Berlin). With "Sign in with Google", sign-in is handled by Google Ireland Ltd.; we only receive the details listed above, no other data from your Google account. For barcode and name searches our server queries Open Food Facts (see section 2d) — only the barcode digits or the search term are sent there, never anything about you. Purchases and subscriptions are handled by Apple or Google Play; we only receive confirmation that a purchase belongs to your account and until when it is valid — no payment data. Your device loads the map tiles for GPS runs from OpenFreeMap (see section 2f).
We do not sell data and do not pass it on for advertising purposes. No cross-app tracking takes place.
We store your data for as long as your account exists. You can delete your account at any time directly in the app (Profile → "Delete account"). This irreversibly removes your profile and the associated data (workouts, runs, boxing sessions and programmes, streak, rank, posts, photos, messages, friendships, food diary, your own foods, recipes and goals, water, lifestyle details, reports you submitted and the purchase receipts from section 2e) — including the usage events named in section 2b. The GPS routes that exist only on the device are also deleted on the device on which you trigger the deletion.
If you signed in with "Sign in with Apple", deleting on iPhone additionally revokes the sign-in with Apple, so Liftpact no longer appears among the apps using Sign in with Apple in your Apple Account. For this you confirm once with Face ID or your passcode. If this step fails (e.g. without a network connection), your account is deleted anyway.
Anything Liftpact has written to Apple Health or Health Connect (section 2a) stays there after your account is deleted, until you delete it there. Billing for purchases is handled by Apple or Google; invoices and payment data are held there (section 2e).
If you voluntarily give a reason or a note when deleting, we store this text without any link to your account in order to improve the app.
Under the GDPR you have the right to:
Please contact the email address given above. You also have the right to lodge a complaint with a data protection supervisory authority (e.g. the State Commissioner for Data Protection of North Rhine-Westphalia).
Liftpact's age rating in the App Store is 13+; on Google Play the age rating shown there applies. We do not knowingly collect data from children under 13. If we learn that an account belongs to a child under 13, we delete it together with the associated data.
Independently of that, the following applies in Germany: processing we base on your consent — Apple Health or Health Connect, push notifications and progress photos — requires the consent of a guardian for users under 16 (Art. 8 GDPR). All three features are optional: without them the app works unchanged.
We adapt this policy when the app or the legal situation changes. The current version published here applies.
As of October 2026 · Legal notice · Deutsch