1. Who is responsible
LiftBud is part of the independently operated Bud Apps project, presently operated from Norway. Formal legal-entity details, a dedicated privacy contact address, and any required representative details have not yet been published and must be completed before broader public release.
Until a dedicated privacy channel is published, contact the project through the official Bud repository at https://github.com/JonasG-DEV/Bud.
2. Data we process
The service processes only data used by its implemented features. Depending on how you use LiftBud, this can include:
- Account email, password hash, account timestamps, authentication state, and Google or Facebook provider identifiers when those sign-in methods are used.
- Profile information such as display name, username, preferred unit, training goal, experience level, rest-timer preference, training-day and session-duration preferences, and profile image.
- Programs, routines, exercise selections, set targets, workout sessions, exercise order, logged sets, repetitions, weight, RPE, RIR, set type, notes, completion times, and feeling ratings.
- Progress and personal-record values derived from completed workout data.
- Bud relationships and requests, Social posts, comments, likes, attached completed-workout references, and uploaded Social images.
- AI program questionnaire answers, including goal, experience, days, duration, equipment, and optional focus or exclusions, plus generated proposals and programs you choose to save.
- Technical diagnostics shown in the app, API errors, server logs, request timing, device model, Android version, app version, and health status where produced by current diagnostics and infrastructure.
3. Where data comes from
Most data comes directly from you when you register, configure your profile, log training, upload media, use Social, or answer the AI questionnaire. Google and Facebook provide the verified identity information required for provider sign-in. LiftBud derives progress and record summaries from your logged training.
4. Why we use data
- Create and secure your account, authenticate you, and preserve Remember me behavior.
- Store and display your profile, programs, routines, workouts, history, progress, and personal records.
- Operate Bud relationships and show authorized Social content, comments, likes, images, and workout attachments.
- Generate and validate a program proposal when you explicitly request it, then save it only after you accept it.
- Diagnose failures, protect the service, enforce ownership controls, and maintain reliability.
- Meet legal obligations and respond to valid requests where applicable.
5. Legal bases
Where the GDPR or similar law applies, account and product data is generally processed to provide the service you request. Security, abuse prevention, diagnostics, and limited service improvement may rely on legitimate interests balanced against user rights. Provider sign-in and optional uploads are initiated by you; consent is used where law specifically requires it. Legal obligations may require limited processing or preservation.
7. International transfers
Authentication, hosting, and AI providers may process data outside Norway or the European Economic Area depending on their configured service region. Appropriate transfer safeguards must be confirmed for the final production provider configuration before broad public release. This draft does not claim safeguards that have not yet been documented.
8. Device and server storage
Bud Core stores canonical account, profile, training, and Social records on the server. Uploaded profile and Social images are stored in server-managed media directories and referenced from the database.
On Android, a Bud session may be kept only for the current app process or persisted locally when Remember me is enabled. Cached profile and Social images and limited app preferences may also be stored on the device. Passwords, Google ID tokens, Facebook access tokens, and raw authorization headers are not intentionally stored in diagnostics reports.
The static Website portal uses sessionStorage by default and localStorage only when Remember me is selected. The current Website does not use advertising or behavioral-analytics cookies. Provider SDKs may set or access their own storage when you choose provider sign-in.
9. Retention and deletion
Account and training data is retained while needed to provide the internal-alpha service or until it is deleted through an available product action or supported request. Social posts, comments, relationships, likes, and uploaded images can be removed through the implemented owner actions where available.
LiftBud does not yet enforce a comprehensive automatic retention schedule or provide self-service account deletion. Backups and operational logs may persist for a limited operational period, but no fixed period is claimed until it is implemented and documented. Uninstalling the app does not delete server data.
10. Security
Current safeguards include password hashing, authenticated owner-scoped API routes, HTTPS for the public API, server-side provider credentials, input validation, and diagnostics sanitization. No system is perfectly secure. This policy does not claim encryption at rest, certification, or controls that have not been implemented and verified.
11. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data and to complain to a data-protection authority. Profile and some content can be corrected or deleted through current app controls. Other requests can be raised through the official project contact while a dedicated privacy channel is being established.
Disconnecting a sign-in method does not automatically delete the underlying Bud account or its training data. Logging out or clearing local session data removes local access but does not delete server records.
12. Children
LiftBud is not currently designed or intentionally offered as a service for children. The project has not yet implemented age-verification or parental-consent tooling. Do not provide a child's personal data without first confirming that the use is lawful and appropriate.
13. Changes and contact
This policy will change when the implemented product, providers, retention, or legal details materially change. The Last updated date changes only for substantive content updates.
The current contact path is the official Bud repository at https://github.com/JonasG-DEV/Bud. Dedicated privacy contact details and professional legal review remain outstanding before broad public release.