How it worksPricingLibraryBlog
Start diagnosis

A diagnostic for lifters who stopped progressing. Honest answers in, one clear bottleneck and the plan to break it out.

contact@liftdecode.com
Product
  • Start diagnosis
  • How it works
  • Pricing
  • Fix library
  • FAQ
Company
  • About
  • Blog
  • Contact
Legal
  • Privacy policy
  • Terms of service
  • Refunds & cancellation
© 2026 LiftDecode. All rights reserved.Training and nutrition education — not medical advice.
Privacy policy · Last updated: 2026-09-25

What we keep, and what we don’t.

LiftDecode stores your answers because they are the product, your email because you sign in with it, and your payment status because you paid. Here is the rest, in plain English.

The short version
  • ›Your diagnosis answers and reports are stored in a Postgres database (Neon, US East) for as long as your account exists; nightly backups in Cloudflare R2 are deleted after 30 days.
  • ›Sign-in is by email code through Clerk. No password. Payments are by Stripe; we never see card numbers.
  • ›Analytics is FlowGlance, only if you accept it. With deep capture on, it records what you type into forms, images you upload, and your signed-in email — not just page views.
  • ›Five cookies in total: Clerk session, Stripe, ld_anon, ld_consent, FlowGlance. The first three are essential.
  • ›Delete everything by emailing contact@liftdecode.com. We reply within 2 business days.
  • ›Not medical advice, and you must be 16 or older. See the terms.
On this page
  1. 01Who we are and how to reach us
  2. 02What we collect, and why
  3. 03The legal basis we rely on
  4. 04Who processes your data for us
  5. 05Cookies
  6. 06How long we keep things
  7. 07Your rights, and how to use them
  8. 08Where your data goes
  9. 09Security
  10. 10Changes to this policy
01

Who we are and how to reach us

This site, liftdecode.com, is operated by LiftDecode (“we”, “us”). For anything in this policy — a question, a copy of your data, a deletion — email contact@liftdecode.com. We reply within 2 business days. We are the controller of the personal data described here.

You must be at least 16 to use LiftDecode. We do not knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.

02

What we collect, and why

Your diagnosis answers and reports

The answers you give in the diagnostic, the track you chose, how long you took, and the result the engine produced (findings, clearances, the 4-week plan and your check-offs). This is the product: without it there is no report. We also keep the engine version so an old report is never silently recomputed.

An anonymous owner token

If you take the diagnostic before signing in, a random token in the ld_anon cookie is the only thing linking that browser to that result. It contains no personal data. When you sign in, the assessment is claimed by your account.

Your account

Your email address, a Clerk user id, and timestamps (created, last seen). Sign-in is email plus a 6-digit code — we never hold a password for you. We do not ask for your name, age, weight or any health history.

Payment status

Which product you bought (single report or membership), the Stripe customer, checkout session, subscription and invoice identifiers, the amount, currency, any promo code, the email Stripe used, and whether the purchase was refunded. We never see or store card numbers; Stripe handles those entirely.

Member tools

If you use the plateau tracker: the lifts and measurements you log, with dates, units and notes.

Contact messages

Name, email and message from the contact form, plus the IP address and browser user-agent that sent it, so we can tell people from bots and answer you.

Email you send us

If you email contact@liftdecode.com — or any address at this domain — the whole message is kept: sender, subject, body and the mail headers, in our database and in the mailbox we answer from, so we can reply and keep the thread.

Technical and error logs

When something breaks we record the error name, message, stack, route and a coarse fingerprint so we can fix it. Rate-limit counters are keyed by route and IP address and expire on their own.

Analytics (FlowGlance)

We use one analytics service, FlowGlance, to understand how the diagnostic is used. It records page views, clicks, scroll depth, the path you take through the site, and JavaScript errors. Because we have deep capture switched on, it also records the text you type into forms on this site and images you upload, and once you are signed in it is told your email address so your sessions can be identified (mainly so we can exclude our own traffic and follow up on a bug you report). FlowGlance runs only if you accept it in the cookie banner; choose “Essential only” and it is not loaded. See Cookies for how to change your mind later.

03

The legal basis we rely on

  • Performing our contract with you — storing answers and producing reports, running your account, taking payment, granting access, answering your messages.
  • Our legitimate interests — keeping the service secure (rate limits, error logs, the honeypot on the contact form), preventing fraud and abuse, and improving the questions and rules based on aggregate patterns.
  • Your consent — for FlowGlance analytics. You can withdraw it at any time; see Cookies.
  • Legal obligations — keeping payment records for tax and accounting purposes.
04

Who processes your data for us

We keep the list short and each provider only sees what it needs for its job.

  • Neon — our Postgres database, hosted in the US East region. Holds everything in the “What we collect” section except card data.
  • Clerk — sign-in. Holds your email address, sends the 6-digit code, and issues the session cookies.
  • Stripe — payments. Holds your card details and billing information; sends us the identifiers and status listed above.
  • FlowGlance — analytics, only with your consent, as described above.
  • Vercel — hosts the site and its server code; sees request logs (IP address, URL, user-agent) in the ordinary course of serving pages.
  • Cloudflare — DNS; inbound email for liftdecode.com (Cloudflare Email Routing receives every message to an address at this domain and hands it to our server through a Cloudflare Email Worker, which also delivers contact-form notifications to us); and nightly backups of our database, stored encrypted at rest in Cloudflare R2 and deleted after 30 days.

We do not sell personal data, do not share it with advertisers, and do not use it to train language models. We disclose it only to the providers above, or if the law requires it.

05

Cookies

These are all of them:

  • Clerk session cookies (essential) — keep you signed in. Set when you sign in; removed when you sign out or the session expires.
  • Stripe (essential) — set by Stripe during checkout for fraud prevention and to complete the payment.
  • ld_anon (essential) — lets an anonymous visitor own the diagnosis they just completed and come back to their result. Random token, no personal data, kept for 90 days.
  • ld_consent — remembers whether you accepted or declined analytics so the banner does not reappear.
  • FlowGlance (analytics) — only if you accepted analytics in the banner; nothing is set while the choice is still open. Used to tell one visit from another and to link sessions to your account once signed in.

To change your choice, delete the ld_consent cookie in your browser and the banner will ask again on your next visit. Blocking essential cookies will stop sign-in and checkout from working.

06

How long we keep things

  • Assessments, reports, plan check-offs, tracker entries — for as long as your account exists. Anonymous assessments that are never claimed by an account are kept so the ld_anon cookie can find them again, and may be deleted after the cookie’s 90 days have passed.
  • Account — until you ask us to delete it.
  • Payment records — as long as tax and accounting law requires, typically 7 years, even after the account is deleted. Card details are Stripe’s and follow Stripe’s retention.
  • Contact messages and email you send us — until the conversation is closed and no longer needed, then deleted.
  • Backups — a nightly copy of the database is kept for 30 days, then deleted. Anything you ask us to delete disappears from the backups within that window.
  • Error logs and rate-limit counters — error records are cleared once resolved; rate-limit windows expire within minutes.
  • Analytics — per FlowGlance’s retention; we can ask FlowGlance to delete the sessions linked to your email on request.
07

Your rights, and how to use them

Wherever you live, you can ask us to show you the data we hold about you, correct it, delete it, restrict or object to how we use it, or give you a copy in a portable format. If you are in the EU/EEA, UK, Switzerland, California or another place with a privacy law, these are legal rights; everywhere else we honour them anyway.

To use any of them, email contact@liftdecode.com from the address on your account so we can verify it is you. Deletion removes your account, assessments, reports and tracker data, and cancels any active membership; payment records we are legally required to keep are retained, and copies in nightly backups expire within 30 days. We respond within 2 business days and complete requests within 30 days.

If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to your local data-protection authority.

08

Where your data goes

Our database and hosting are in the United States, and our providers operate globally. If you are outside the US, your data is transferred there. Our providers rely on standard contractual clauses or equivalent safeguards for those transfers, and we choose providers with strong security practices.

09

Security

All traffic is encrypted in transit. There are no passwords to steal: sign-in is by one-time code. Card data never touches our servers. Access to the database is limited to the operator and to the site’s own server code. Anonymous results are protected by a long random token, not a guessable id. No system is perfectly secure; if we ever learn of a breach affecting your data we will tell you without undue delay.

10

Changes to this policy

When we change something that matters — a new provider, a new category of data, a new use — we update the date at the top and, if you have an account, tell you by email before it takes effect. Minor wording fixes just update the date.

Related
Terms of serviceRefunds & cancellationContact

Questions about this page? Email contact@liftdecode.com — we reply within 2 business days.