LiftDecode stores your answers because they are the product, your email because you sign in with it, and your payment status because you paid. Here is the rest, in plain English.
This site, liftdecode.com, is operated by LiftDecode (“we”, “us”). For anything in this policy — a question, a copy of your data, a deletion — email contact@liftdecode.com. We reply within 2 business days. We are the controller of the personal data described here.
You must be at least 16 to use LiftDecode. We do not knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.
The answers you give in the diagnostic, the track you chose, how long you took, and the result the engine produced (findings, clearances, the 4-week plan and your check-offs). This is the product: without it there is no report. We also keep the engine version so an old report is never silently recomputed.
If you take the diagnostic before signing in, a random token in the ld_anon cookie is the only thing linking that browser to that result. It contains no personal data. When you sign in, the assessment is claimed by your account.
Your email address, a Clerk user id, and timestamps (created, last seen). Sign-in is email plus a 6-digit code — we never hold a password for you. We do not ask for your name, age, weight or any health history.
Which product you bought (single report or membership), the Stripe customer, checkout session, subscription and invoice identifiers, the amount, currency, any promo code, the email Stripe used, and whether the purchase was refunded. We never see or store card numbers; Stripe handles those entirely.
If you use the plateau tracker: the lifts and measurements you log, with dates, units and notes.
Name, email and message from the contact form, plus the IP address and browser user-agent that sent it, so we can tell people from bots and answer you.
If you email contact@liftdecode.com — or any address at this domain — the whole message is kept: sender, subject, body and the mail headers, in our database and in the mailbox we answer from, so we can reply and keep the thread.
When something breaks we record the error name, message, stack, route and a coarse fingerprint so we can fix it. Rate-limit counters are keyed by route and IP address and expire on their own.
We use one analytics service, FlowGlance, to understand how the diagnostic is used. It records page views, clicks, scroll depth, the path you take through the site, and JavaScript errors. Because we have deep capture switched on, it also records the text you type into forms on this site and images you upload, and once you are signed in it is told your email address so your sessions can be identified (mainly so we can exclude our own traffic and follow up on a bug you report). FlowGlance runs only if you accept it in the cookie banner; choose “Essential only” and it is not loaded. See Cookies for how to change your mind later.
We keep the list short and each provider only sees what it needs for its job.
We do not sell personal data, do not share it with advertisers, and do not use it to train language models. We disclose it only to the providers above, or if the law requires it.
ld_anon cookie can find them again, and may be deleted after the cookie’s 90 days have passed.Wherever you live, you can ask us to show you the data we hold about you, correct it, delete it, restrict or object to how we use it, or give you a copy in a portable format. If you are in the EU/EEA, UK, Switzerland, California or another place with a privacy law, these are legal rights; everywhere else we honour them anyway.
To use any of them, email contact@liftdecode.com from the address on your account so we can verify it is you. Deletion removes your account, assessments, reports and tracker data, and cancels any active membership; payment records we are legally required to keep are retained, and copies in nightly backups expire within 30 days. We respond within 2 business days and complete requests within 30 days.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to your local data-protection authority.
Our database and hosting are in the United States, and our providers operate globally. If you are outside the US, your data is transferred there. Our providers rely on standard contractual clauses or equivalent safeguards for those transfers, and we choose providers with strong security practices.
All traffic is encrypted in transit. There are no passwords to steal: sign-in is by one-time code. Card data never touches our servers. Access to the database is limited to the operator and to the site’s own server code. Anonymous results are protected by a long random token, not a guessable id. No system is perfectly secure; if we ever learn of a breach affecting your data we will tell you without undue delay.
When we change something that matters — a new provider, a new category of data, a new use — we update the date at the top and, if you have an account, tell you by email before it takes effect. Minor wording fixes just update the date.
Questions about this page? Email contact@liftdecode.com — we reply within 2 business days.