Privacy Policy — Liftotta
Last updated: September 21, 2026
This policy describes how data is processed in the “Liftotta” mobile applications for iOS and Android (identifier com.opharana.liftotta; hereinafter, “the app”). The data controller is OPHARANA LLC, with its registered address at 99 Wall Street, Suite 1432, 10005, New York (United States), and contact email hello@opharana.com.
1. Summary
- Your workouts are yours. The app works without an account and stores your workouts, routines, custom exercises and settings on your device. If you create an account, which is optional and free, we also keep a copy in the cloud so that you do not lose them when you switch phones, and you can delete the account at any time from within the app.
- We do not sell your data or share it with third parties for purposes other than those described here, and we do not send marketing emails.
- The app is free and shows ads from Google AdMob, which processes your device's advertising identifier. In the European Economic Area (EEA), the United Kingdom and Switzerland, we ask for your consent before loading any ad. It also shows in-house ads from TuIAgencia, the owner's agency, which do not use personal data.
- Payments are processed by Apple or Google; we never see your payment details.
2. Data we process
2.1. Your workouts and settings (on your device)
Everything you log in the app (workouts, sets, weights, reps, notes, routines, exercises you create, personal records, streak and settings, including the language you choose) is stored in your device's local storage. If you do not create an account, we do not receive it, we cannot see it and we cannot recover it if you delete the app or switch phones without a system backup (iCloud on iOS, Google backup on Android). From Settings you can export a copy of your data at any time; when you share a workout, you are the one who decides with whom and through which channel.
The app does not ask you for health data, body measurements or your location, and it does not access your contacts, your camera or your photos.
2.2. Optional account and cloud backup
You can create an account with your email and a password, with Google or with Apple. If you do, we process: your email address (Apple lets you hide it behind a relay address), a user identifier, the sign-in method you use, your name if your provider shares it with us, the language in which you use the app and your platform (so that we can write service notices and emails to you in your language), and a copy of your workouts, routines, custom exercises and settings, which is synced across your devices. Your password is stored encrypted (as a hash): we never see it.
This data is hosted on Supabase, in the European Union (Ireland region), and is accessible only with your session. To protect sign-up and sign-in against bots, we use Cloudflare Turnstile, which processes your IP address and technical data about your device. Service emails (confirming your account and resetting your password) are sent through Resend. We do not send advertising by email.
2.3. Notifications
If you allow it, the app alerts you when your rest between sets is over. These are local notifications, scheduled on your own device: they do not go through our servers and we do not record any notification identifier.
2.4. Technical data
When checking for updates, the app connects to the Expo update service, which temporarily processes your IP address and technical connection data (app and operating system version) in order to deliver the right version. This data is not linked to your identity.
2.5. Advertising (Google AdMob)
The app shows ads through Google AdMob: a banner, full-screen ads at natural breaks (for example, when you finish a workout) and optional rewarded videos. Google may process, among other data: the device's advertising identifier (IDFA on iOS, AAID on Android), device data, approximate location derived from the IP address, ad interactions and diagnostic data from its SDK. This processing is governed by Google's Privacy Policy and its information on how data is used on partner sites and apps. We never send anything you log in your workouts to advertising services.
In addition, the app shows in-house ads from TuIAgencia, the owner's services agency. These ads are served inside the app, do not use the advertising identifier or any personal data, and do not profile you. If you tap one, the tuiagencia.com website opens in your browser.
2.6. In-app purchases
The app offers one optional in-app purchase: “No ads” (a one-time payment, not a subscription). All purchases are processed entirely by Apple (App Store) or Google (Google Play), depending on your platform, under their own privacy policies.
We do not receive or store your card, bank account or billing details, or your postal address: the store only confirms to us that a purchase has been completed. To validate the purchase and make it possible to restore it, we use RevenueCat, which receives an anonymous installation identifier and the store receipt, without your name or your email address.
Refunds and payment disputes are handled through Apple or Google, not through us.
2.7. When you write to us
If you write to us at hello@opharana.com, we process your email address and whatever you tell us for the sole purpose of handling your question, your issue or the exercise of your rights.
3. Purposes and legal bases (GDPR)
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and maintaining your account and signing you in | Email address, user identifier, sign-in method, name | Performance of a contract (6.1.b) |
| Storing the cloud backup and syncing it across your devices | Workouts, routines, custom exercises and settings | Performance of a contract (6.1.b) |
| Writing service notices and emails to you in your language | Email address, language, platform | Performance of a contract (6.1.b) |
| Protecting sign-up and sign-in against bots and abuse | IP address and technical data about the device | Legitimate interest (6.1.f) |
| Delivering app updates and protecting the service against abuse | Technical data, IP address | Legitimate interest (6.1.f) |
| Applying in-app purchases and allowing them to be restored | Anonymous installation identifier, purchases made and receipt | Performance of a contract (6.1.b) |
| Personalized advertising | Advertising identifier and the data described in section 2.5 | Consent (6.1.a), collected through Google's consent form (UMP) and, on iOS, the tracking permission (ATT) |
| Non-personalized (contextual) advertising | Limited technical data (IP address for general geography and frequency capping) | Legitimate interest (6.1.f) or limited consent, depending on your choice in the consent form |
| Handling your inquiries and the exercise of your rights | Email address and the content of your message | Legal obligation (6.1.c) for GDPR rights; legitimate interest (6.1.f) for all other inquiries |
4. Advertising and your consent
- EEA, United Kingdom and Switzerland: before loading any Google ad, the app shows Google's consent form (User Messaging Platform, UMP). You can accept personalized advertising or decline it; in that case, non-personalized ads are shown.
- iOS: in addition, the system shows Apple's tracking prompt (App Tracking Transparency). If you do not allow it, the IDFA is not used and ads are not personalized.
- Changing your mind: inside the app, under Settings → “Ad privacy options”; on iOS, Settings → Privacy & Security → Tracking; on Android, Settings → Google → Ads, where you can reset or delete your advertising ID.
- Training ad-free at no cost: in every workout you can choose to watch two short videos, and you will not see any more ads until you finish it.
- Removing ads: the one-time “No ads” purchase completely disables ad loading in the app.
5. Data recipients
| Provider | Role | More information |
|---|---|---|
| Apple / Google Play | App distribution and purchase processing | apple.com/legal/privacy · policies.google.com/privacy |
| Google (AdMob / UMP) | Advertising and consent management | policies.google.com/privacy |
| Supabase | Accounts and the cloud backup database (EU, Ireland) | supabase.com/privacy |
| Cloudflare (Turnstile) | Bot protection for sign-up and sign-in | cloudflare.com/privacypolicy |
| Resend | Sending service emails | resend.com/legal/privacy-policy |
| RevenueCat | Purchase validation and restoration | revenuecat.com/privacy |
| Expo (650 Industries) | Delivery of app updates | expo.dev/privacy |
| Vercel | Hosting of this website | vercel.com/legal/privacy-policy |
We do not sell your data or share it with any third parties other than those listed above.
6. International transfers
The data controller is established in the United States, and the providers listed above also process data outside the European Economic Area (EEA), mainly in the United States. These transfers rely on the Standard Contractual Clauses approved by the European Commission and/or on adequacy decisions (such as the EU-U.S. Data Privacy Framework).
7. Retention
Your workouts and settings remain on your device until you delete them or uninstall the app. Your account data and the cloud backup are kept for as long as you keep the account and are deleted when you delete it. The emails you send us are kept for as long as it takes to handle your inquiry and, afterwards, for the time needed to demonstrate that we dealt with it. Data processed by Google for advertising purposes and by RevenueCat for purchases is retained for the periods published by each provider.
8. How to delete your account and your data
Your account: inside the app, go to Settings → Account and tap “Delete my account”; we will ask you to confirm. Your account and the entire cloud backup (workouts, routines, custom exercises and settings) are deleted immediately and permanently. If you cannot get into the app, write to us from the account's email address at hello@opharana.com and we will delete it for you.
The data on your device: simply uninstall the app (or clear its data from the system settings). The “No ads” purchase remains linked to your store account and you can restore it if you reinstall the app.
9. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing, data portability and withdrawal of consent by writing to hello@opharana.com. We will reply within one month.
You also have the right to lodge a complaint with a supervisory authority; in Spain, the Agencia Española de Protección de Datos, the Spanish data protection authority (aepd.es).
10. Minors
The app is not directed at children under 14 and we do not knowingly collect data from minors. We do not verify age. If you are a parent or guardian and you believe a minor is using the app, you can prevent its use with the device's parental controls (Screen Time on iOS, Family Link or the Google Play controls on Android) or write to us at hello@opharana.com.
11. Security
The app's communications with the services listed above are encrypted (TLS). Your workouts are stored in the app's private space on your device, protected by the operating system itself, and the cloud backup is accessible only with your session. If you turn on the Face ID or fingerprint lock, the check is performed by your phone's system: the app only learns whether it succeeded or not, and never receives your biometric data.
12. Changes to this policy
If we change this policy, we will publish the new version at this same URL (https://liftotta.com/en/privacidad) and update the date at the top. Material changes will be flagged in the app or on the store listings.
13. Language
This policy is published in several languages to make it easier to read. In the event of any discrepancy between versions, the Spanish version prevails.
14. Contact
OPHARANA LLC
99 Wall Street, Suite 1432, 10005, New York, United States
hello@opharana.com