Privacy Policy — Go Lifter
Version 2 · 6 September 2026
This policy covers the Go Lifter application for Android. It is written to be read in full: it runs a few pages, and nothing in it assumes you already know something.
What changed in this version. None of it is a new permission — all of it describes, more precisely than the previous version did, things the app already did:
- the Coach can comment on its own about a workout or a day of eating, without you asking anything. It is a switch, it starts on, and it is now described;
- Android's automatic backup takes your history to your own Google Drive. It is not a copy of ours, but it does leave the device, and the previous version did not say so;
- the list of what reaches the Coach is now complete, and includes nutrition and the Coach's memories;
- the exercise illustrations come from a GitHub server, and the image address carries the name of the exercise;
- the Go Lister connection does not expire after a fixed thirty days: the clock runs from your last use;
- the contact addresses moved to
golifter.app. The old ones, atgolister.app, still work.
The summary
Go Lifter has no account, no login and no server of ours. Everything you record stays on your device. There is no advertising, no tracking, no usage reporting, and the app never requests the Android advertising identifier.
Your data leaves the device in three situations, and this policy describes all three in detail:
- When the Coach talks to the AI provider whose key you supplied yourself — in your questions and, if you leave it on, in the comments it writes on its own when it sees a workout or a day of eating.
- In Android's automatic backup, which copies your history to your own Google Drive, as it does for any app, until you turn it off.
- When you export a file, or press send on an email the app prepared for you to read first.
Outside those three, nothing leaves. And in none of them is there a copy of ours: there is no server for your data to go to.
What stays on the device
There is no server of ours, and therefore no copy of ours. What exists off the device is your Google's backup, described at the end of this section.
- Workouts, sets, routines, records, body measurements, nutrition, goals, health facts and Coach conversations — in one database per Profile, in the app's private storage, which only it can see.
- The Coach's memories — what it distilled from your conversations in order to remember you later —, the coaching notes it wrote per exercise, the automatic comments already generated, the Training Score snapshots, and your gyms with the equipment they hold.
- The readings that already came from Health Connect — sleep, resting heart rate and steps are stored here once read. Revoking the permission stops new readings and does not erase old ones; to erase them, use Erase data.
- Progress photographs — in a private app folder, one per Profile.
- The text read from a training sheet, until you accept or decline the import. The image is not kept: it is already in your gallery, and the app reads it and forgets it. Recognition happens on the device, through a text reader built into the app itself: there is no service, no upload, and nothing from the photograph leaves here.
- AI keys and preferences — encrypted with AES-256-GCM, under a key held in the Android Keystore that never leaves the device.
Uninstalling the app erases all of that from the device, and there is no copy of ours anywhere to be requested back.
Android's automatic backup, which is your Google's and not ours
Go Lifter keeps Android's automatic backup on, as most apps do. That means your Profile database — workouts, sets, body measurements, the health readings already stored, the nutrition diary, the goals, the health facts and the Coach conversations — is copied to your own Google Drive, in the area reserved for app backups, and comes back when you install the app on a new device.
It stays on for a simple reason: turning it off would make you lose your entire history when you change phones, and this app has no cloud sync to act as a safety net.
Three things are deliberately excluded from that backup:
- the progress photographs — the promise that erasing them means no copy exists would not survive a copy on Drive that you neither see nor delete;
- your AI keys;
- the Soundtrack preferences and the exercise catalogue, which the app rebuilds by itself.
In a direct device-to-device transfer the photographs do travel, because that copy is local and end-to-end encrypted — it passes through no server.
That backup is yours, it sits in your Google account, and it follows Google's rules rather than ours. You can turn it off under Android Settings → Google → Backup, and delete what is already there from the same screen.
Health Connect
If — and only if — you grant permission, the app reads from Health Connect:
- Sleep, Resting heart rate and Steps — for the Recovery Score and the Coach's load suggestion.
- Weight, Body fat, Lean body mass and Height — to fill the body table without you typing what your scale already knows.
- Nutrition — to avoid logging the same meal twice.
And it writes back exactly one type: nutrition — the meals you logged yourself, so they appear in the other apps you use. No other type is written.
Thirty days, and no more. The app requests the thirty-day window Health Connect grants by default. It does not request READ_HEALTH_DATA_HISTORY or READ_HEALTH_DATA_IN_BACKGROUND: it does not read your older history, and it reads nothing while closed.
This data is used only for the features above. It is not sold, not shared with third parties for their own purposes, does not feed advertising and does not train any model.
It leaves the device in two circumstances, and only those: to the Coach, if you turn on a switch that starts off — described in the next section, in full —, and to your own Google's backup, along with the rest of your history, as any app does and as the previous section explains.
You can revoke any of these permissions at any time in Health Connect itself, and the app keeps working without them. Revoking stops new readings and does not erase old ones — what was already read is stored on the device, and is erased under Settings → Data and health → Erase data.
The Coach, and everything it takes from here
The Coach is optional. The whole app works without it — logging workouts, building routines, reading history, charts, records and the entire nutrition side need neither network nor key.
To turn it on you supply your own key from an AI provider (Gemini, DeepSeek, OpenAI, OpenRouter, Groq, or any compatible endpoint). No key ships inside the app. Requests go straight from your phone to the provider you chose — there is no server of ours in between.
What travels
The context the question requires. The complete list, because "the necessary context" is not a description anyone can check:
- Training — recent sessions, exercises, sets, loads, records, volume per muscle group, routines and the weekly target.
- Goals and health facts — the targets you wrote and the injuries you declared, with region and severity. These always travel: they are what the Coach is for, and a trainer who does not know about your shoulder programmes on top of it. The same sentence appears on the Settings screen, above the switches.
- Nutrition — calories, protein and your target, when you use the diary. The Coach also consults the food catalogue and may propose an entry.
- The Coach's memories — what it distilled from earlier conversations in order to remember you.
- Your default gym and its equipment, the focus you declared, the Training Score broken down, the direction (losing, gaining or maintaining) and the device's date and time.
Your name never goes with it. This is not a promise of intent: there is an automated check in the app's code that prevents the release of any version in which the name starts being sent.
Three switches control the rest, under Settings → Coach → Privacy:
- Body measurements — starts off. Releases weight, body fat, lean mass and circumferences.
- Device health readings — starts off. Releases sleep, heart rate and steps.
- Workout soundtrack — starts on. Releases what was playing, where that feature exists in your build.
With the first two off, no measurement of your body and no reading from your device leave here — neither on their own nor attached to a goal: the target "reach 78 kg" still travels, and what you weigh today does not. The Coach is told those sections were withheld rather than simply not receiving them — it knows that it does not know.
What those two switches do not cover, and it is fair to say so: the health facts you declared. An injury is what makes the Coach programme around it, and withholding it would be asking for a workout from someone who is not allowed to know why they cannot give it. If you do not want an injury to travel, delete it rather than turning off a switch — and the same sentence appears on the screen where the switches live, so that the two cannot disagree.
And the app has a screen that proves this: Settings → Coach → What the Coach sees assembles exactly the text the next question would send, and sends nothing. You do not have to take this page on trust.
When the Coach speaks without being asked
This switch starts on, and it is the only one on this page that starts on while having a network consequence. It is called Automatic Coach comment, under Settings → Coach, and it has existed since version 1.5.1.
With it on, the app talks to the AI provider in three situations where you wrote nothing:
- when you open the screen of a finished workout, to comment on that session;
- when you open the nutrition tab, to comment on the day;
- when you start a new conversation, at which point it reads the whole previous conversation to extract what is worth remembering — the memories and health facts that appear in the list above.
What travels in those three is the same context as one of your questions, under the same switches, plus a summary of what is on the screen. Turning off the automatic comment does not turn off the Coach: it goes back to speaking only when you ask.
We say this here because a sentence like "nothing leaves unless you talk to the Coach" would be false for anyone who never opened that Settings screen, and it is that person this paragraph is for.
The named exception: Go Lister
If you hold an Ultimate or higher subscription to Go Lister — another product by the same author — you can connect it instead of bringing a key. Then, and only then, your questions pass through a server of ours (api.golister.app), which talks to the model and pays for it.
The content that travels is the same as for any other provider, subject to the same three switches. Three extra headers travel on this route only, and not to other providers: an identifier for the question, whether it asked the model for reasoning, and which part of the app produced it — conversation, workout comment, nutrition comment or distillation. They exist so the server can count usage against your subscription; none of them carries content, and what they reveal is how often you use each feature.
The connection is made in your own browser using OAuth and PKCE: no password of yours ever reaches this app, and what it stores is a token, encrypted like any other key.
That token's deadline is one of use, not of calendar. It is valid while you use the Coach and expires after thirty days without use — and never runs beyond ninety days from the authorisation, at which point you authorise again. The ceiling exists because the reason a deadline is short at all is so that a leaked credential dies, and one that renews without limit would only die in the hands of someone who does not use it. The expiry date is visible on the Provider's line, under Settings.
You can disconnect whenever you want, and disconnecting also drops the token on the server, not only the local copy — when it cannot, the app says so rather than pretending it worked.
A planned change, not yet made. There is an intention for the Coach to become the paid part of the app, and for the Go Lister trial period to be the way to try it before buying. None of that is implemented today, and nothing on this page describes a hypothesis: everything written here applies to the app as it is now. If and when that changes, what changes is who may use the Coach — not what travels, which will remain as described above, under the same switches, and with authorisation collected before anything is sent.
Progress photographs
They stay on the device, compressed, in a private app folder. They are never uploaded anywhere — not to us, not to the Coach, and not to Google's backup, from which they are explicitly excluded so that this sentence is true.
They go to two places, both yours: the archive you export, and a direct transfer from one device to another, which is local and passes through no server. They are deleted when you erase everything or delete the Profile.
Exercise photographs
The catalogue's illustrations do not fit inside the app — roughly 96 MB — so they are fetched when there is a network and cached. They come from a public repository on GitHub (raw.githubusercontent.com). That is a third party, and it is fair to say it was not chosen by you.
That request carries no identifier: no account, no token, no indication of who is asking. What it carries is what any internet request carries — your IP address — and the name of the exercise, which goes in the image's address. Before a workout the app fetches the illustrations for the whole routine at once, so anyone observing that traffic would see which exercises you are about to do, though with no way of knowing who you are.
Deleting
Settings → Data and health → Erase data, with five scopes: Coach memories, conversations, goals, the nutrition diary, or everything. Each one shows how many rows will go before you confirm.
Deleting a Profile deletes its database and its photographs. Uninstalling erases everything from the device.
There is nothing to ask us for: no copy of ours of your data exists to be deleted. The only copy off the device is your own Google's backup, and it is deleted where it lives — Android Settings → Google → Backup.
What the app does not do
- No account, login or registration.
- No advertising, and no ads SDK.
- No usage analytics, telemetry or crash reporting.
- Does not request the Android advertising identifier.
- Does not request location.
- Does not access the camera — photographs arrive through Android's own picker, which needs no permission.
- Does not send your training sheet anywhere. It is read on the device.
- Does not sell, rent or share any data.
Children
Go Lifter is not directed at anyone under 18.
Your rights, and how to exercise them
Since there is no account and no copy of ours on a server, every control is already on your device: the data is yours, it stays with you, and erasing it is immediate and permanent through the five scopes above. Your Google's backup is deleted in that account, as the section What stays on the device explains.
For anything concerning this policy — including rights under Brazil's LGPD — write to [email protected]. For general support, [email protected].
Go Lifter is operated by Joao Ferrete, based in Brazil.
This is not medical advice
The Coach is a language model. It adapts training around what you told it, and it does not diagnose, does not prescribe and does not replace a health professional. Pain that persists, gets worse, or appears out of nowhere is a matter for someone who can examine you.
The app reads sleep, heart rate and steps from Health Connect when you authorise it, and uses that to adjust volume and rest. That is training programming, not clinical assessment.
Reporting a problem
The app has Report a problem under Settings → About, which opens an email pre-filled with the app version, the device model, the Android version, which AI provider and model you configured, and how many rows your profile holds — never your AI key. Nothing is sent until you press send in your own mail application, where you read all of it first.
Reporting a Coach response
Press and hold a Coach response to flag it as dangerous, wrong or inappropriate.
This is the one thing in the app that sends health data out on purpose, which is why it is described here separately. A report is only useful if it carries the sentence being reported, and the question that produced it goes with it — because "double your volume" is dangerous or unremarkable depending on what was asked, and the question is usually where you mentioned an injury.
What goes out: the reason, whatever you write, the configured model and provider, the app version, the question and the response. What does not: your AI key, the rest of the conversation, your training history, your measurements and your photographs.
As with everything else here, the email opens for you to read and edit before sending, and the app never sends anything on its own.