~/terminal/lift/privacy

privacy

last updated 27 september 2026

the short version: lift has no server and no account system, so your training data has nowhere to reach me even if I wanted it. the only personal information I ever hold is an email address, and only if you typed one into the beta form or the app-request board yourself.

who I am

lift is made by one person, james skinner, trading as terminal (terminal-lib.com). for anything in this document, including a request to delete your data, write to support@terminal-lib.com. under uk gdpr I am the data controller for the beta mailing list. for the data inside the app, see below — there is no controller relationship, because I never receive it.

what the app stores, and where

everything you log — workouts, sets, exercises, templates, notes, bodyweight and body measurements — is written to a database on your own iPhone. that local copy is the source of truth, and the app works entirely off it.

if you are signed in to icloud, the app also backs that database up to your private Apple icloud database — not continuous syncing, a backup pass, which runs when you open the app, when you come back to it, right after you save a workout, and whenever you tap "backup now" in settings. private means exactly what it sounds like: the data sits in your personal icloud account, under your apple account's protection, and I have no credentials, no dashboard and no technical means to read it. I can see aggregate counts of records in my developer console — never contents, and never anything tied to a person. on a new phone signed in to the same icloud account, lift restores from this backup automatically.

turn icloud off and the app carries on working with the local copy alone. nothing is lost day to day by declining to back up — you just have no restore if you lose the device.

health data

lift can read from and write to Apple Health, and only with permissions you grant explicitly and can revoke at any time in the Health app. specifically:

each of those four is a separate switch and all four are off until you turn them on.

health and fitness data obtained through HealthKit is never used for advertising, marketing, or any use-based data mining. it is never sold, and it is never shared with a third party, service provider or anyone else. it is not transmitted off your device to me under any circumstances. it is used solely to show you your own training and body measurements inside the app. under uk gdpr health data is special category data, which is part of why the app is built so that it never leaves your own devices and your own icloud account.

on your phone only

rest-timer alerts and reminders are notifications scheduled locally on your iPhone; nothing is sent to me to make them happen. importing or exporting a csv file reads and writes that file on your device only — it is never uploaded anywhere.

support emails

the help & support screen in the app opens your own mail app with a message pre-filled to support@terminal-lib.com, including your lift version and build number, your ios version, and your device model, so I can diagnose a problem without a round trip asking what you're on. it's sent from your own mail app, so I only get what you choose to send. that's on the basis of legitimate interests — answering the request you just opened the email to make.

the beta mailing list

if you enter your email address on this site, I store that address and the date you submitted it. that is all — no name, no ip address, no location, no tracking pixel in the emails.

the list is never sold, rented, shared, or used for anything other than the two emails described above.

the app request board

the request board lets you vote for a possible app or suggest one. to keep votes useful, I ask for an email address and send a one-click verification link. a verified address can cast one vote per request and undo it later; there is no account or password.

this website

this site sets no advertising or cross-site tracking cookies, which is why you weren't shown a consent banner. the request board sets one strictly functional, secure cookie after you verify an email. it remembers the verified browser so you can vote again or undo a vote without an account; it lasts up to 390 days and is not used to profile or track you.

I use cloudflare web analytics, which is cookieless and reports only aggregates — how many people viewed a page, roughly which country, which referrer. it does not build a profile of you and it cannot identify you. cloudflare also handles hosting and serves the site, and processes request metadata such as ip addresses transiently for security and delivery, as any host must.

the beta signup and request-board forms are protected by cloudflare turnstile, which checks that you are not a bot without setting cookies or tracking you across sites.

fonts are served from this domain rather than a font cdn, so loading the page tells no third party that you visited.

your rights

under uk gdpr you can ask for a copy of what I hold, ask for it corrected, or ask for it deleted. this includes beta-list and request-board data. write to support@terminal-lib.com and I will respond within 30 days. you also have the right to complain to the information commissioner's office.

your training data isn't covered by those requests for the simple reason that I don't have it. to delete it, delete the app and, if you backed up, remove lift's data from icloud in your iPhone settings.

children

lift isn't directed at children under 13 and I don't knowingly collect anything from them.

changes

if this document changes materially I'll update the date at the top, and email the list if the change affects it.