Cadence Lift Privacy Policy

Last updated: September 5, 2026

Privacy at a glance

Cadence Lift is a strength-training log from LightPath Apps. It has no account, advertising, analytics SDK, or cross-app tracking. Workout history, routines, body measurements, reminders, preferences, and local Coach chats are stored on your device unless you deliberately use one of the optional off-device features described below.

Version 1.2 does not create new iCloud workout backups or new hosted workout links. Sharing is through files, images, text, and the system share sheet. The iPhone app retains a temporary read-only recovery path for old Cadence 1.1.x iCloud archives so affected users can restore and export a user-owned JSON copy.

Data stored on your device

  • Sessions, exercises, sets, weights, reps, RPE, timestamps, and notes
  • Workout templates, reminders, rest-timer settings, and preferences
  • Body-weight and body-composition entries
  • Coach profile fields and local Coach conversations
  • Your current store product and transaction proof used to check Cadence Pro access
  • A random installation identifier used for abuse prevention and support

Cadence uses SwiftData on iPhone and Room on Android. Deleting the app removes its ordinary local database. On Android, Clear storage does the same without uninstalling. Data that Cadence wrote into Apple Health or Health Connect remains in that health store until you remove it there.

AI Coach — optional and adults only

Coach is optional and available only after you confirm that you are 18 or older and accept its versioned privacy disclosure. Everything else in Cadence works without Coach. If you do not send a Coach message, Cadence does not send Coach content.

When you send a message, Cadence may include:

  • Recent exercises, sets, weights, reps, RPE, workout notes, and bodyweight
  • Your training goal and optional Coach profile, including goals, limitations, experience, and facts you asked it to remember
  • The Coach conversation needed to answer the current message

The request goes to a LightPath Cloudflare Worker and then to Google's paid Gemini API through Cloudflare AI Gateway. Each app request also carries a random installation ID and platform attestation to the LightPath Worker for abuse prevention. The Worker does not include that installation ID or the attestation material in the Gemini prompt.

Cloudflare is instructed not to collect the raw Coach request or response body. Cloudflare retains operational metadata such as provider, model, token counts, status, cost, and duration. Google may retain the prompt, contextual training data, and generated response for up to 55 days for abuse monitoring and required disclosures unless the project has approved zero-data retention. Google states that paid-service content is not used to improve its general AI products; policy-enforcement systems and authorized review of flagged content may still process it.

Deleting a local Coach chat removes the device copy. Cadence does not have an established way to delete Google's abuse-monitoring copy early or locate it using your Support ID; it expires under Google's retention policy.

Purchases and subscriptions

Cadence Pro is sold through Apple App Store or Google Play subscriptions. The store processes payment details; Cadence does not receive your card or bank information. The App receives a product identifier and store transaction ID or purchase token, then sends that proof to LightPath's Cloudflare service. The service asks Apple or Google whether the subscription is current before it allows an AI Coach request.

The App keeps the current store proof on your device as needed to restore and authorize access; on Android this includes the current Google Play purchase token. Our Cloudflare service does not log or retain the raw transaction ID or purchase token, and it never sends that proof to Gemini. The service may cache a one-way hash and active/expiry verdict for up to five minutes, never beyond the subscription's expiration. Store authentication and subscription records remain subject to Apple or Google's policies. You can view, cancel, or manage the subscription through your store account.

Rest-timer Live Activity relay — iPhone only

When Live Activities are enabled, Cadence sends a push token, timer target, current exercise name, set number, and random installation ID to its Cloudflare relay so Apple can update the Lock Screen and Dynamic Island. Pending jobs are removed when delivered, canceled, or stale. Rate-limit counters expire within their hour or day window. Android rest-timer alarms are local and do not use this relay.

Apple Health and Health Connect

Health integrations are optional and controlled by system permission. With permission, Cadence can write completed workouts and manually logged body measurements. It can read supported body measurements when you request an import. On iPhone, the optional readiness display may read recent sleep and HRV signals; the Apple Watch companion can collect heart rate and active energy during an active workout. On Wear OS, heart rate is used locally on the watch for display and optional set-timing detection; the heart-rate values are not sent to a LightPath server.

Apple Health and Health Connect data is governed by the platform health store. Except for bodyweight or other context explicitly included in a Coach request after consent, Cadence does not send health-store data to a LightPath server.

User-owned export and sharing

Cadence can export or share JSON, Markdown, text, and an image card. The app creates these locally and hands them to the destination you select through the system file picker or share sheet. LightPath does not receive those exports. Once you choose a destination, that destination's privacy terms apply.

Legacy iCloud recovery — iPhone only

Cadence 1.1.x offered iCloud workout backup. Version 1.2 no longer creates, uploads, replaces, or deletes iCloud workout backups. For one migration release, an affected user can deliberately open Settings → Data → Recover old iCloud backup to read an existing archive from that user's private Apple CloudKit database, restore it locally, and export JSON.

LightPath cannot browse that private archive. The existing record remains unchanged during the 1.2 recovery path while LightPath obtains and follows Apple's guidance for cleanup and removal of the temporary recovery bridge.

Historical hosted workout links

Builds before 1.2 could publish a chosen workout at an unlisted URL. Version 1.2 cannot create new hosted workout links. An existing link remains public to anyone who has it until it expires: after about 30 days without a view and no later than 90 days after creation. Local sharing does not create a hosted link.

Security, attestation, and support records

Coach and Live Activity relay requests use a random installation ID, IP rate limits, and platform integrity checks such as Apple App Attest or Google Play Integrity. Short-lived rate counters expire within 24 hours. App Attest public-key and counter records persist so later requests can be verified. A Coach request also includes the current Cadence Pro purchase proof, which the Worker verifies with Apple or Google and removes before calling Gemini. Attestation providers and app stores process their own technical and transaction records under their terms.

Settings → Contact can prefill a random Support ID. If you choose to email us, we receive your message and normal email headers. The Support ID can help correlate LightPath-controlled support and installation-ID rate-limit records. It is not forwarded to Gemini and cannot locate Google's abuse-monitoring copy or a separate App Attest key record.

What Cadence does not use

  • No advertising networks or advertising identifiers
  • No behavioral analytics or cross-app tracking
  • No account, login, contact upload, location, camera, or microphone access
  • No sale of workout, health, Coach, or support data

Retention and deletion

  • Local app data remains until you delete it or uninstall the app.
  • Where zero-data retention is not approved, Google's Coach abuse-monitoring copy expires within 55 days.
  • Cloudflare stores Coach operational metadata rather than raw Coach text; its exact operational retention is controlled in the LightPath gateway account.
  • Relay jobs and rate counters expire automatically as described above.
  • Raw purchase proof is used for store verification and not retained by the Worker; a hashed verdict lasts at most five minutes and never beyond subscription expiry.
  • Historical hosted links expire within 90 days.
  • The legacy private iCloud record remains unchanged by Cadence 1.2's read-only recovery.

See the Cadence data-deletion page for platform-specific steps and the limits of a support request.

Age and medical disclaimer

Cadence Lift 1.2 and its AI Coach are intended for adults 18 and older. Cadence is a fitness log, not a medical device, and Coach output is not medical advice, diagnosis, or treatment. Consult a qualified healthcare professional for medical questions.

International processing

Cloudflare, Google, Apple, and email providers may process optional request data outside your country. Their terms and regional safeguards apply to their processing. LightPath uses these services only for the app functions described above.

Changes and contact

Material changes will appear here with a new revision date. Because Cadence has no account or mailing list, we cannot notify every user directly.