LiFit
HomeFeaturesPartner with LiFitPrivacyTerms
Download app

LIFIT LEGAL

Privacy Policy

This Privacy Policy explains how LiFit LLC handles information when you use the LiFit mobile application, website, and related services.

Effective: July 11, 2026Last updated: September 2, 2026
Contents
Introduction and scopeInformation you provideAccount and authentication informationProfile information and visibilityFitness and workout informationNutrition and hydration informationBodyweight, measurements, and progressPhotos, videos, and uploaded mediaSocial activity and communicationsGym and location informationDevice and technical informationPush notificationsAnalytics and diagnosticsAdvertising and trackingPurchases and subscriptionsInformation stored on your deviceHow we use informationHow information is disclosedService providers and external servicesData retentionAccount deletionYour privacy choicesSecurityChildren's privacyPrivacy rights and international usersChanges to this policyContact us
← Back to LiFitRead the Terms of Service →
This is a first draft based on LiFit's current technical implementation. Dates and policy decisions explicitly identified as unfinished must be finalized before production use.
01

Introduction and scope

LiFit LLC ("LiFit," "we," "us," or "our") provides LiFit, a fitness platform for workout tracking, nutrition logging, progress analysis, gym communities, and social fitness features. This policy applies to the LiFit mobile app, https://lifit.app, and related services that link to it.

LiFit is a fitness technology service. It is not a healthcare provider, and the service is not a substitute for medical care or professional health advice.

02

Information you provide

The information we receive depends on the features you choose to use. Some profile and fitness fields are optional, while an email address and account credentials are needed for standard account access.

  • Account details such as email address, username, display name, authentication provider, and account timestamps.
  • Profile details such as biography, profile photo, fitness goal, training experience, preferred training days, gym, and visibility settings.
  • Optional physical and demographic details such as birthday or birth year, sex or gender, height, bodyweight, and waist, neck, or hip measurements.
  • Content and communications you submit, including posts, captions, comments, direct messages, reports, photos, videos, workout recaps, nutrition recaps, and support messages.
03

Account and authentication information

LiFit supports email-and-password authentication, Google Sign-In, Sign in with Apple, and phone-based Firebase authentication flows in the audited app. Authentication is provided through Firebase Authentication. Depending on the method you choose, Firebase and the identity provider may process your email address, phone number, provider identifier, display name, authentication tokens, and related sign-in information.

LiFit stores a username lookup record so users can sign in by username. The current implementation associates that record with the account email address and user ID.

04

Profile information and visibility

Your display name, username, profile photo, biography, gym affiliation, profile status, follower relationships, and selected activity may be shown to other signed-in users. LiFit offers public or private profile settings and separate controls to hide bodyweight, height, and gym information in the app interface.

A private profile generally requires another user to follow you before the interface shows restricted workouts, statistics, achievements, and posts. These controls govern the current app experience; the technical consistency report identifies backend access rules that must be tightened before launch so they enforce the same expectations.

05

Fitness and workout information

When you use workout features, LiFit stores workout names, dates and times, duration, exercises, sets, repetitions, weight, volume, notes, ratings, personal records, workout plans, custom exercises, favorites, active-workout state, training statistics, streaks, and achievements. Workout information is used to save your history, calculate summaries and trends, identify personal records, resume workouts, and generate recap cards.

Workout records are intended for your tracking experience unless you choose to share them in a post or make them available through your profile. A shared recap can contain workout title, exercises, duration, set or volume totals, personal records, and other details included in the generated card or post.

06

Nutrition and hydration information

LiFit stores foods, meal types, serving information, meal timestamps, calories, protein, carbohydrates, fat, recipes, ingredients, saved meals, favorite or recently used foods, nutrition targets, daily summaries, and water intake and targets. This information is used to maintain nutrition history, calculate daily and weekly summaries, show trends, and generate achievements or recap cards.

When you search the USDA food database, LiFit sends the search terms through an authenticated Firebase callable to the U.S. Department of Agriculture FoodData Central API and returns matching food and nutrient information. LiFit does not include your user ID in the USDA request, although Firebase processes the authenticated request and the API operator may process ordinary network information such as an IP address.

07

Bodyweight, measurements, and progress

LiFit stores bodyweight history, height, waist, neck and hip measurements, sex or gender, birthday or birth year, fitness goals, training experience, streaks, and derived statistics when you provide or generate them. The data model also supports body-fat percentage and goal weight, but the audited app has no verified current writer for those two fields. The app uses available details to display progress charts and calculate fitness or body-composition estimates.

These estimates are informational only. They may be incomplete or inaccurate and are not medical measurements, diagnoses, or advice.

08

Photos, videos, and uploaded media

If you choose to add a profile image or social media, LiFit accesses the selected photo or video and uploads it to Firebase Storage. Social images may be resized or converted before upload, and videos may be compressed and may include a generated thumbnail. Profile photos, post media, and their download URLs are associated with your account or post.

LiFit may request camera access when you choose to take a photo for a workout, nutrition, or social post, and photo-library access when you choose existing media. The audited app does not use microphone audio as a separate feature, although a selected video may contain audio.

Deleting a post invokes server-side cleanup for its Firestore interactions and associated Firebase Storage image, video, and thumbnail files. A post-deletion backend trigger provides additional cleanup when a post is removed through another supported path. Account deletion removes the account's profile media and post-media folders from Firebase Storage.

09

Social activity and communications

LiFit stores friend and follow relationships, follow requests, blocks, likes, comments, post reports, activity notifications, gym membership, and direct messages. Direct-message records include participants, profile snapshots, message text, sender, timestamps, read state, unread counts, and a last-message preview.

Friend-feed posts are intended for the relevant social audience, and gym posts are intended for members of the selected gym community. Posts can include profile identifiers, captions, tags, photos, videos, workout summaries, or meal summaries. Likes, comments, follower relationships, gym membership, and leaderboards may reveal your participation to other users.

Direct messages are available to thread participants. LiFit may access content when reasonably necessary to operate the service, investigate reports, enforce rules, comply with law, or protect users and the service.

10

Gym and location information

When you choose the nearby-gym feature, LiFit requests your current precise location while the feature is in use. The app uses the coordinates to query nearby gym records. When the build is configured with a Google Places API key, it may also send latitude, longitude, search terms, and search radius to Google Places to find gyms. The audited code does not store the device's raw current coordinates in your user profile.

If you join or create a gym community, LiFit stores the selected gym identifier and name, membership timestamp, and gym-related profile fields. Gym records can include a gym's business name, address, Google place identifier, and geographic coordinates. Other signed-in users may see gym membership, community activity, and leaderboard information subject to app controls.

You may deny or later disable location access in device settings. You can still use other LiFit features, but nearby-gym discovery may not work.

11

Device and technical information

Firebase and the app may process technical information needed to connect, authenticate, synchronize, secure, and troubleshoot the service. This can include IP address, platform, app version, Firebase installation or authentication identifiers, App Check attestation information, request timestamps, and operational logs.

LiFit uses Firebase App Check with Apple App Attest and a DeviceCheck fallback in production on Apple platforms and Google Play Integrity in production on Android. Those services process device or app-attestation signals to help detect unauthorized clients. The app also creates short in-memory diagnostic messages and debug logs; some debug-only logging currently includes post payloads and user-document data and should not be enabled in production builds.

12

Push notifications

If you allow notifications, LiFit and Firebase Cloud Messaging process a push-notification token, a hashed token identifier, platform name, active status, timestamps, notification preferences, reminder times, and time-zone offset. Notification payloads may contain routing details such as a post, workout, actor, or meal identifier.

The app provides controls for social notifications, follow activity, workout reminders, and meal reminders. You can change those preferences in LiFit and can disable push notifications for LiFit in your device settings. Signing out or deleting an account deletes the current device's token record. LiFit also deletes permanently invalid or unregistered tokens reported by Firebase and runs a daily cleanup for token records that have not been created or refreshed for 30 days.

13

Analytics and diagnostics

The current mobile source includes Firebase Analytics and records bounded product events for profile sharing, referral and attribution flows, pending-link navigation, and related conversion steps. Depending on the event, parameters can include a share or referral identifier, link source, destination type, app platform, and whether a supported action completed. LiFit uses this information to understand feature use, measure referral flows, diagnose failures, and improve the service.

The audited source does not include Firebase Crashlytics. Firebase's active infrastructure services may still generate ordinary operational, security, and diagnostic records. LiFit must keep its app-store disclosures synchronized with the exact release build and enabled Firebase settings.

14

Advertising and tracking

LiFit uses Google AdMob to show ads to free-tier users. Ads may appear as sponsored native cards in the Friends, Discover, and Gym feeds and as a video interstitial after a successful workout or meal log, limited to one impression per signed-in user per local day. Pro users do not receive these standard ads.

Google may process an advertising identifier when available and permitted, consent status, IP-derived information, device and app information, approximate location, and ad-request, impression, or interaction information to deliver, personalize where permitted, limit, measure, prevent fraud in, and report on ads. LiFit stores a date value on the device for each signed-in account to enforce the daily post-log ad limit.

On iOS, LiFit uses Apple's App Tracking Transparency flow before requesting permission to track across other companies' apps or websites. If you decline, LiFit does not receive permission to access the IDFA for tracking. Google may still serve contextual or otherwise non-personalized ads and process information needed for ad delivery, security, fraud prevention, frequency capping, and measurement. You can change tracking permission in iOS Settings.

LiFit uses Google's User Messaging Platform to request consent and provide privacy choices where required. Depending on where you live, personalized advertising or certain advertising disclosures may be treated as targeted advertising, a sale, or sharing under applicable law. You can review or change available choices through Ad Privacy Choices in LiFit's settings. Google handles advertising data under its own privacy terms and controls.

15

Purchases and subscriptions

The current mobile source includes a LiFit Pro purchase, restore, and entitlement flow through RevenueCat. The flow is active only when the release build is configured with the appropriate public RevenueCat platform SDK key. RevenueCat uses the signed-in Firebase user ID as LiFit's app-user identifier and may process store product and offering identifiers, purchase and entitlement status, expiration and management information, price and currency, transaction identifiers, and device or store metadata needed to provide subscription services.

Apple App Store or Google Play processes the payment method and store transaction. LiFit does not receive a full payment-card number. LiFit's backend may receive RevenueCat webhook events and current-customer information to maintain server-owned entitlement records, including purchase, renewal, cancellation, billing-issue, expiration, refund, price, currency, and product information. Store and RevenueCat configuration, disclosures, and test evidence must be verified before the Android offering is enabled.

16

Information stored on your device

LiFit uses shared preferences on the device to save an onboarding draft and legacy workout state such as workout history, personal records, totals, and bodyweight during migration to Firestore. Shared preferences are not secure storage. Completed onboarding clears its draft. Account deletion clears LiFit SharedPreferences, temporary files, and image caches and requests deletion of Firestore's local persistent cache on the device processing deletion.

17

How we use information

LiFit uses information described in this policy to:

  • Create, authenticate, maintain, secure, and support accounts.
  • Save and synchronize workouts, meals, progress, settings, and social activity across devices.
  • Calculate totals, trends, estimates, achievements, streaks, personal records, and recap cards.
  • Provide feeds, gym communities, follow relationships, messages, comments, likes, reports, and notifications.
  • Find nearby gyms when requested and return external USDA food-database results when you search for foods.
  • Prevent abuse, enforce service rules, debug failures, and protect LiFit, users, and others.
  • Comply with applicable law and respond to valid legal requests.
18

How information is disclosed

LiFit discloses information to service providers when needed to provide their functions; to other users when you use profiles, posts, gym, follow, leaderboard, comment, like, or messaging features; at your direction when you use the system share sheet; and when required for legal, safety, fraud-prevention, or rights-protection purposes.

Information may also be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate notice where required.

19

Service providers and external services

Current services identified in the audited app include:

  • Google Firebase: Authentication, Cloud Firestore, Firebase Storage, Cloud Messaging, Cloud Functions, App Check, and supporting infrastructure.
  • Firebase Analytics: bounded product, referral, share, navigation, and conversion events that can include content, profile, gym, source, platform, and completion identifiers.
  • Google Sign-In and Sign in with Apple: optional identity-provider authentication.
  • Google Places: conditionally active nearby-gym and gym-search requests when the build includes an API key; requests can include location coordinates and search terms.
  • USDA FoodData Central: food-search terms submitted through LiFit's authenticated Firebase callable.
  • Google Mobile Ads and User Messaging Platform: ad delivery, consent management, frequency limiting, measurement, reporting, and fraud prevention for free-tier users.
  • RevenueCat: LiFit Pro product offerings, purchase and restore operations, subscription entitlement status, and server-side subscription synchronization when the build and backend are configured.
  • Apple and Google platform services: app distribution, device permissions, notifications, integrity or attestation, and operating-system functions.
20

Data retention

LiFit generally keeps account information and associated data while your account remains open, unless you use an available control to delete particular content earlier. Account deletion removes supported account, profile, media, workout, nutrition, social, message, and notification records from LiFit's active systems.

LiFit's approved category schedule pseudonymizes clearly nonfinancial attribution events after 24 months; deletes rejected or withdrawn partner applications after 90 days; pseudonymizes rejected or disabled partner records after one inactive year; deletes gym-claim evidence media after 90 days and the decision audit after three years; deletes resolved fraud or moderation records after 24 months unless an active legal need applies; and keeps administrative audit records pseudonymous for three years.

Minimal commission financial evidence is excluded from the general scheduled cleanup and retained for seven years under LiFit's approved accounting and legal/compliance decision.

LiFit does not maintain scheduled Firestore database backups. Firebase, Google Cloud, Apple, Google, and other infrastructure providers may still process limited operational, security, delivery, and diagnostic information under their own service terms and retention practices.

Posts, interactions, and uploaded media

When you delete a post, server-side cleanup deletes its supported Firestore interactions and associated Firebase Storage image, video, and thumbnail files. A backend deletion trigger provides additional cleanup when a post is removed through another supported path.

During successful account cleanup, the server deletes posts authored by the account, their supported Firestore interactions, and the account's profile and post-media folders from Firebase Storage.

Direct messages, reports, and activity

Successful account cleanup deletes direct-message threads containing the account and deletes the messages in those threads. This removes the conversation from the other participant's account as well.

The cleanup also deletes the account's likes and reports on other posts, comments identified by current or legacy account identifiers, activity records, social references, gym memberships, routines and schedule overrides, saved routines, user-owned public routine/content share snapshots, and recognized legacy default-database records. The backend checks supported database and Storage paths for residual account data and reports a failure when a known residual remains.

Notification tokens

When account deletion begins, LiFit deletes the current device's notification-token record and requests deletion of the device token from Firebase Cloud Messaging. Account cleanup also deletes the account's notification-token subcollection.

Uninstalling the app does not directly notify LiFit. If Firebase later reports that a token is invalid or unregistered, LiFit deletes the corresponding token record. LiFit also runs a daily cleanup that deletes notification-token records that have not been created or refreshed for 30 days.

21

Account deletion

You may start account deletion through the app. LiFit requires reauthentication using the account's password, Google, Apple, or phone sign-in method. The app then deletes the current notification-token record and calls the account-cleanup Cloud Function. Before erasing LiFit's active Firebase records, that function requests permanent deletion of the corresponding RevenueCat customer record using the signed-in Firebase user ID. A missing RevenueCat customer is treated as already deleted; another provider failure stops the cleanup so the request can be retried.

If Firestore cleanup succeeds, the app next deletes the Firebase Authentication account and signs out. If cleanup or Authentication deletion fails, the app displays an error so you can try again; because Firestore cleanup runs before Authentication deletion, partial cleanup is possible if a later step fails.

For an email request, LiFit's approved standard is to acknowledge the request within two business days and complete it within 30 calendar days unless LiFit discloses an applicable legal hold. Identity is verified through recent authentication or a single-use account-email link; LiFit will not ask for a password by email.

  • The cleanup deletes the root user profile and supported workouts, routines, routine overrides, saved routines, plans, nutrition records, bodyweight history, statistics, preferences, achievements, notification records, and user subcollections in the named Firestore database, and sweeps recognized legacy records in the default database.
  • It deletes authored posts and their Firestore interactions, the account's interactions on other posts, follow relationships and requests, blocks, activity references, username records, custom exercises, and nested gym membership documents.
  • It deletes public shared-routine and shared-content snapshots owned by the account.
  • It deletes direct-message threads containing the account and their messages, including the other participant's server copy of those conversations.
  • It deletes profile photos, post photos, videos, thumbnails, and recognized current or legacy account-media folders from Firebase Storage.
  • After sign-out it clears SharedPreferences, LiFit temporary files, in-memory image caches, and requests deletion of Firestore's local persistent cache on the device processing deletion. Active listeners may delay the SDK cache purge, but the deleted user is signed out and cannot refresh deleted account data.
Action required

Deleting the RevenueCat customer does not cancel or change an Apple App Store or Google Play subscription. The approved category-specific retention schedule is implemented in source and still requires deployment verification. Minimal commission financial evidence is retained for seven years for accounting and legal obligations.

22

Your privacy choices

Depending on the feature, you can:

  • Edit profile fields and change public/private profile, bodyweight, height, and gym visibility settings.
  • Delete individual completed workouts, meal entries, saved meals, recipes, workout plans, posts, and comments where the app provides that control.
  • Block and unblock users, manage follow requests, and report posts.
  • Change notification categories in LiFit and system notification or location access in device settings.
  • Review or change available advertising consent and opt-out choices through Ad Privacy Choices in LiFit settings, and change iOS tracking permission in device settings.
  • Delete your account through the app.
23

Security

LiFit uses authentication, Firebase security rules, App Check, and access controls intended to protect information. No method of storage or transmission is completely secure, and LiFit cannot guarantee absolute security.

The technical audit identified Firestore rules that do not currently enforce the profile privacy represented in the interface and permit overly broad authenticated access to user records. Those rules must be corrected and tested before production release.

24

Children's privacy

LiFit is not intended for anyone under 15, and people under 15 may not create an account or use the service. LiFit uses the birthday provided during onboarding to prevent an underage user from completing setup.

Users must provide an accurate birth date. If LiFit reasonably determines that an account bypassed or used false information to evade the 15+ requirement, LiFit will disable and delete the account and its associated information, subject to applicable law. If you believe someone under 15 provided information to LiFit, contact us using the information below.

25

Privacy rights and international users

Depending on where you live, applicable law may provide rights regarding access, correction, deletion, restriction, portability, or objection. LiFit will evaluate verified requests under the law that applies to the request. This policy does not promise rights that do not apply or a response period that has not been confirmed.

LiFit uses service providers that may process information in countries other than your own, including the United States. The business owner must confirm the service's target countries and any required international-transfer safeguards before production.

26

Changes to this policy

We may update this policy when LiFit's features, providers, or legal obligations change. We will post the revised policy with a new last-updated date and provide any additional notice required by applicable law.

27

Contact us

Privacy questions may be sent to privacy@lifit.app. General support is available at support@lifit.app. LiFit's business mailing address is 187 Liberty Rd, Picayune, MS 39466, United States.

support@lifit.appprivacy@lifit.applegal@lifit.app
Return to the LiFit websiteRead the Terms of Service
LiFit

One connected place for training, nutrition, progress, and community.

ExploreHomeFeaturesApp Store
CompanyPrivacy PolicyTerms of ServiceDelete accountSupport
Get in touchsupport@lifit.applifit.app
© 2026 LiFit LLCTRAIN · TRACK · PROGRESS