Skip to content
BackSkookum Lifts

Privacy Policy

Last updated: 25 April 2026

This policy explains what data Skookum Lifts (“we”, “us”) collects when you use the app at lifts.skookum.coach, why we collect it, who it is shared with, and the rights you have over it. We have written it in plain English. If anything is unclear, email us at the address at the bottom of the page.

Who runs Skookum Lifts

Skookum Lifts is an independent project built and operated by Stu Mullan. We are the data controller for the personal information described below.

What we collect

We only collect data that is needed to run the app:

  • Account details. Your email address and a hashed password (handled by Supabase Auth), plus an optional display name.
  • Training data. Programmes, exercises, sets, reps, weights, RPE, rest timers, workout logs, and personal records that you create or that the app generates as you train.
  • Nutrition data. Meals, foods, macro targets, meal templates, and food preferences that you log.
  • Wearable data (optional). If you connect Garmin, we sync readiness, sleep, and heart-rate metrics that the AI coach uses for training recommendations.
  • Third-party credentials (optional). If you connect Garmin or AnyList, we store the credentials needed for that integration encrypted at rest.
  • Feedback you send. If you use the in-app feedback button, we store the text you submit and any screenshot you attach.
  • Technical data. Standard server logs (IP address, user agent, request timestamps) generated by our hosting and database providers, kept for security and debugging.

We do not use third-party advertising trackers, we do not sell your data, and we do not run external analytics scripts (Google Analytics, Meta Pixel, etc.) on the site.

How we use it

  • To let you sign in and access your own data.
  • To provide the core features of the app. workout tracking, programme building, nutrition logging, and progress charts.
  • To generate AI coaching responses when you ask the in-app coach a question (see “AI features” below).
  • To diagnose bugs and improve reliability when you submit feedback.
  • To meet our legal obligations.

AI features

When you use the AI coach or generate insights, we send a summary of the relevant training data (recent workouts, programme context, readiness signals) to OpenRouter, which routes the request to the underlying language-model provider (typically Anthropic). We do not send your email, password, payment details, or third-party credentials. Requests are not used to train models. You can avoid AI processing entirely by not using the coach features.

Where your data lives

Your account and training data is stored in our database, hosted by Supabase. The web app and its API routes run on Vercel. Both providers may process and store data in regions outside your country, including the United States and the European Union. Each operates under contractual safeguards (Standard Contractual Clauses where required) for international transfers.

Sub-processors

The companies that process data on our behalf:

  • Supabase. authentication, database, storage.
  • Vercel. application hosting and edge logs.
  • OpenRouter / Anthropic. AI coaching responses (only when you use those features).
  • Garmin. only if you connect a Garmin account for wearable sync.
  • AnyList. only if you connect AnyList for recipe import.

Cookies and local storage

We use a small number of essential cookies and browser storage entries to keep you signed in and to remember preferences (e.g. units, recent workout state). We do not use cookies for tracking or advertising.

How long we keep it

Account and training data is kept for as long as your account is active. If you delete your account, we delete or anonymise the associated personal data within 30 days, except where we are required to retain it (for example, accounting records or security logs). Backups are rotated and overwritten on a rolling basis.

Your rights

Depending on where you live, you may have the right to:

  • access a copy of the data we hold about you,
  • correct anything that is inaccurate,
  • delete your account and your data,
  • export your data in a portable format,
  • object to or restrict certain processing,
  • lodge a complaint with your local data-protection authority.

You can delete your account and all associated data from the Settings page, or by emailing us at the address below. We will respond within 30 days.

Security

Passwords are hashed by Supabase Auth and never stored in plain text. Third-party credentials (Garmin, AnyList) are encrypted at rest. All traffic to and from the app is sent over HTTPS. No system is perfect. if you discover a security issue, please email us so we can fix it.

Children

Skookum Lifts is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove the data.

Changes to this policy

If we make a material change to this policy we will update the “Last updated” date at the top of this page and, for significant changes, notify you in the app or by email.

Contact

Questions, requests, or complaints: email privacy@skookum.coach.