SuperLift Privacy Policy
SuperLift ("we", "our", "us") provides workout tracking, strength ranking, training plans, social publishing, direct messaging, optional fitness Challenges, and support. Some features require an account, an additional permission, or approval, and may not be enabled in every version. Premium commerce and AI Coach are currently unavailable. The optional Photo Challenge is a separate feature described below. This policy applies to the SuperLift mobile apps, web app, and related services.
Data We Collect
- Account data: authentication identifier, email address, sign-in provider, and provider-supplied name.
- Profile and fitness data: display name, bio, specialties, social links, sex selection, bodyweight, height, age or optional date of birth, country, units, rank results, athletic test context, and badges. Your date of birth is not displayed on your public profile.
- Profile photos: an optional cropped avatar and its account-linked storage reference. Selecting a photo only previews it; saving uploads it to SuperLift's hosting and Supabase storage for display alongside your profile and activity. Avatars are not sent to Anthropic or used for Photo Challenge scoring.
- Training data: exercises, weights, repetitions, duration, distance, jump measurements, perceived effort, rest time, workout timestamps, estimated 1RM where supported, saved training plans, and plan shares. Personal exercises include the name, note, and measurement format you choose.
- Challenge results: saved scores, timestamps, confirmed video event times, recording parameters, and uncertainty estimates. Optional cloud sync stores permitted result fields for your account, not the original camera or analysis video.
- Photo Challenge: after separate consent, your selected photo is processed by our server and Anthropic. We store an account-linked request identifier, an image hash, daily quota and request status, timestamps, and the structured score or refusal result. The hash is used to prevent a retry from substituting a different image; it is not the image itself.
- Social content: public or audience-limited posts, workout and PR shares, captions, photos, comments, creator content, follows, and related activity.
- Direct messages: message participants, message text, media links, and timestamps.
- Safety data: blocked-user relationships and confidential content reports, including the reason and optional details, internal reporter and reported-user identifiers, the reported subject and a limited evidence snapshot, report status, moderation actions or notes, and audit timestamps.
- Support data: reply email, subject, message, originating page, and subsequent correspondence. A Creator Studio access request also includes the account details you submit; approval status and administrative approval records are stored to control publishing access.
- Historical purchase records: records from purchases previously offered on Android or web, including purchasing email, product, amount, billing period, transaction reference, status, and entitlement or token grant. We do not receive full payment-card details.
- Historical AI Coach data: records from AI Coach previously offered on Android or web, including prompts, recent AI conversation, relevant profile/training context, generated answers or plans, token usage, and an optional attached image.
- Diagnostics: when Sentry is enabled, crash, performance, and other technical diagnostic data such as app/OS version, device information, error traces, and technical identifiers.
What Other People Can See
Profile information, rankings, follow relationships, public posts, shared workouts and PRs, comments, and uploaded social photos may be visible to other signed-in users or, where a public media URL is used, anyone with that URL. Direct messages are intended for their participants and are not public. Content copied, shared, or captured by another person may remain outside our control after you delete it. Content reports and the identity of the person who submitted them are not shown to the reported user.
Your saved avatar is visible to other eligible signed-in users alongside your profile, posts, comments, messages and rankings. Avatar storage uses expiring image links; a copied link can work until it expires, and previously downloaded copies may remain. The app crops and re-encodes the image to remove original photo metadata. You can replace or remove your avatar without changing your training history. Old files are queued for cleanup, and account deletion removes associated avatar files. There is no automated image-content review or manual approval before an avatar appears; profile reporting and blocking remain available.
Saving a workout keeps it in your private training history and does not create a profile post. Publishing a saved workout is a separate action with a confirmation. Sharing workout text through your device's share sheet, or copying it to the clipboard, does not publish a post in SuperLift. Cancelling an external share does not remove a post you previously chose to publish. This does not change the visibility of rankings, PR shares, or plans you choose to share.
Your personal exercise notes and private Challenge journal are not public by default. Eligible Challenge scores appear on a Challenge leaderboard only after a separate Publish action, under a generated player alias. You can withdraw them. Photo scores and volleyball timing results are not eligible for this public Challenge leaderboard. Sharing a social photo is a different feature with the visibility described above.
Camera, Local Video Analysis, and Photo Challenge
The exercise games and jump or volleyball video analysis process camera frames and selected videos on your device or in your browser. These features do not upload the original video or pose frames to our server. Automatic event marks are suggestions you can review and change. Saving or explicitly syncing a result stores the permitted result data, not the video. Normal operating-system and browser caches may retain temporary files; closing a preview is not a guarantee of secure deletion of such caches.
Photo Challenge is different: when enabled, it asks for separate permission before sending your selected photo through our server to Anthropic (Claude) for a subjective, playful score. It is intended only for adults aged 18 or over submitting their own photo. Lighting and posing can affect the result; it is not a health, strength, or medical assessment and does not determine your athletic tier. Confirming your age and ownership is a self-declaration, not an identity or age verification. You can decline and continue using features that do not require this upload.
The app resizes and re-encodes the selected photo, and our endpoint removes image metadata before model processing. SuperLift does not save the submitted photo in its database or include its image payload in application logs. The account-linked request identifier, image hash, timestamps, structured result and quota records are retained separately; they do not currently expire automatically and are removed with the associated account. The hash is account-linked, not anonymous. Anthropic may retain submitted content under its applicable API terms and retention rules; we do not promise zero retention by that provider. Removing the preview or deleting your SuperLift account does not retract a request already received by Anthropic. Our database and application-log limits are not a promise that hosting, operating-system or provider systems retain no technical records or copies. See Anthropic's API retention information.
Photo Challenge allows up to ten counted attempts per account per UTC day across devices. A model refusal or an unconfirmed model request may use an attempt. A retry uses the existing request identifier where possible rather than automatically making another model request. Local rest reminders use device notifications; you can deny or revoke notification permission without giving us access to your notification contents.
Optional workout voice commands use the device's speech-recognition service after permission is granted. The current voice feature does not enforce on-device-only speech recognition, so your operating-system provider may process audio remotely according to its settings and terms. This is separate from the local camera and video analysis described above. You can use the workout controls without voice commands.
Optional AI App Connections (MCP)
When enabled, you can connect a supported AI app after signing in to SuperLift and choosing its access. Read access shares your synced workout history, recorded measurements and saved plans for analysis, summaries and exports. This connection excludes private notes, source identifiers, photos and videos. Plan access lets the AI app propose new plans or edits; a proposal is saved as a plan only after you confirm it in SuperLift. It cannot record a live workout, delete your history or publish content.
We store the connection permissions, expiry and revocation status, hashed authorization credentials, and plan proposals with their confirmation status. Access currently expires after one hour. You can disconnect in Settings under AI connections; this blocks further access but does not recall data already received by the AI app. That provider's own privacy and retention terms apply to those copies. Expired connection records are cleaned up in bounded batches during subsequent connections, not necessarily immediately; associated connection and proposal records are removed on account deletion.
Safety, Reports, Blocking, and Text Filtering
Signed-in users can report supported profiles, posts, comments, workouts, messages, and training plans and can block or unblock other users. Blocking removes follow relationships and prevents the blocked pair from viewing or interacting with each other's covered social content and messages while the block remains active. We use a confidential, service-access-only queue to review reports and record any status or moderation action.
SuperLift may automatically replace certain configured whole-word terms in user-generated text. Automated filtering is limited and may miss harmful content or replace content unexpectedly, so it does not replace user reporting or human review. We review submitted safety reports and respond to content-safety messages sent to a.solodukhov@gmail.com within a reasonable period based on severity. Immediate danger should be reported to local emergency services.
How We Use Data
- Authenticate accounts and keep account data in sync.
- Calculate rankings and provide workout history, exports, plans, social feeds, comments, follows, and direct messages.
- Publish content according to the visibility you select and deliver support responses.
- Run optional Challenges, sync private results when requested, and publish or withdraw eligible Challenge scores according to your choice.
- Provide the separately consented Photo Challenge, enforce its quota, and prevent duplicate or substituted requests.
- Review Creator Studio access requests and enforce publishing approval.
- Summarize demand for personal exercises using normalized names, measurement formats, and counts of distinct users. This administrative summary excludes notes and user identifiers and is not exposed to ordinary clients or sent to a separate analytics service.
- Apply user blocks, filter configured terms, investigate reports, enforce our rules, prevent abuse, and maintain a safety audit trail.
- Administer historical Android/web purchase records, including prior entitlements or token grants, refunds, accounting, disputes, and fraud prevention.
- Store and administer historical AI Coach records from prior Android/web use under the retention terms below. SuperLift does not send new AI Coach requests while the feature is unavailable.
- Secure, operate, troubleshoot, and improve SuperLift.
Processors and Data Sharing
We do not sell personal data and do not use it for cross-app advertising tracking. We share only the data needed to operate a requested feature. The providers we use, or previously used for now-unavailable features, include:
- Supabase: authentication, database, storage, and backend operations.
- Apple and Google: authentication when you choose the corresponding sign-in method.
- Sentry: crash and performance diagnostics when diagnostics are enabled.
- Whop: previously processed checkout, subscriptions, token purchases, refunds, disputes, and payment administration for offers formerly available on Android or web.
- Anthropic: processes the selected Photo Challenge image and scoring instructions after your separate consent when that feature is enabled. It also previously processed AI Coach prompts, relevant context, recent messages, and optional images from Android or web; AI Coach remains unavailable.
- Resend and email providers: delivery and handling of support messages and Creator Studio access requests.
- News publishers: our server periodically collects article metadata and links. Opening an external article takes you to the publisher's service, whose own privacy terms apply.
These providers process, or processed, data under their own privacy terms and applicable contractual or legal safeguards. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer with appropriate protections.
Current Feature and Commerce Policy
SuperLift does not currently offer Premium subscriptions or checkout, Whop purchase links, purchase prices, AI token packs or token purchases, or AI Coach on any platform. Historical purchase and AI records may still be retained and handled as described elsewhere in this policy. Creator Studio publishing requires manual approval rather than a purchase. Photo Challenge, where enabled, is separate from AI Coach and has the consent and daily limit described above.
Retention
- Account, profile, training, social, follow, direct-message, and AI records are generally retained while your account is active. Permanent account deletion removes the authentication account, associated database records, and social-media files stored for that account, subject to the exceptions below and copies made by other people outside our control.
- Personal exercises, synced Challenge records, and Photo Challenge request/quota records are account-linked. Account deletion removes these associated records. Clearing the local Challenge journal alone does not delete an earlier cloud copy; a later explicit sync can restore it. Withdrawing a public Challenge score removes its leaderboard visibility, not the underlying private record.
- News metadata expires after seven days and the shared collection is capped at 200 articles. Expired articles are excluded from responses even if a scheduled cleanup is delayed; scheduled collection also removes expired or excess rows.
- Blocks remain until you unblock the user or either account is deleted.
- Confidential content reports and their audit history may be retained while the relevant accounts exist. If either involved account is deleted, SuperLift removes the reporter and reported-user identifiers, subject and context identifiers, evidence snapshot, report details, moderator notes, and reviewer identifiers. Only de-identified workflow facts such as the report reason, status, action category, and timestamps may remain for safety trend records, dispute handling, and legal compliance.
- Support correspondence is retained while a request is handled and for a reasonable follow-up, security, and recordkeeping period.
- For Android/web purchase audit records, direct account identifiers are erased when the account is deleted. De-identified transaction facts are retained until seven years after the purchase for accounting, tax, fraud prevention, chargebacks, disputes, and legal compliance, then scheduled for deletion. They are not used to recreate a deleted account.
- Diagnostic records follow the retention controls configured with our diagnostic provider.
Your Controls and Account Deletion
Signing out keeps a separate local copy of that account's training history, pending records, plans, personal exercises and unfinished workout draft so that signing back in can restore them. Signing out is not account deletion and does not erase these local copies. The app separates them by account; this is not a claim of device-level encryption. Permanent account deletion uses the separate deletion flow and removes that account's local data on the device performing deletion, subject to the retention exceptions described above. It does not remotely wipe independent copies on other devices.
- You can edit profile fields and delete individual training or social items where the app provides that control.
- You can report supported user content, block or unblock users, and manage your blocked-user list in Settings.
- You can initiate permanent account deletion from Settings in the app. This removes the authentication account, associated database records, imported copies of plans published by that account, and the account's stored social-media files, subject only to the de-identified safety/purchase facts, support/diagnostic retention, and external copies described above.
- For an account linked with Sign in with Apple, SuperLift attempts to revoke the stored Apple authorization before removing the account. If automatic revocation is unavailable, account deletion still completes and the app directs you to remove SuperLift manually under your Apple Account's Sign in with Apple settings. You may separately remove any remaining provider connection in your Apple or Google account settings.
- You can contact support to request access, correction, deletion follow-up, information about retained records, or follow-up on a safety concern.
- You can withdraw camera, photo, microphone, speech-recognition, and notification permissions in device or browser settings. Revoking a permission does not recall content you previously submitted to a provider.
Children
SuperLift is not directed to children under 13, and we do not knowingly collect their personal data. Photo Challenge is restricted to adults aged 18 or over.
Security and International Processing
We use reasonable technical and organizational safeguards, but no service can guarantee absolute security. Our providers may process data outside your country; where required, transfers are protected by applicable legal safeguards.
Changes
We may update this policy as SuperLift changes. The date above identifies the current version.
Contact
Email: a.solodukhov@gmail.com