Privacy Policy
Last updated August 7, 2026
This Privacy Policy explains how Eccentric (“we”, “us”, or “our”) collects, uses, processes, and protects your information when you use our mobile application (the “App”) and our website located at www.lifteccentric.com (the “Site”), collectively referred to as the “Service”.
Eccentric acts as an analysis and coaching layer for your training data. Your workout equipment and its respective native applications remain the primary sources of data capture.
1. Information We Collect
We collect information to provide, improve, and secure our Service. The types of data we collect depend on how you interact with the Service:
- Account Information. When you create an account or sign in, our authentication provider (Clerk) provides us with your email address and a unique user identifier. We do not see, access, or store your account password.
- Training Data. This includes training plans you author, sets you check off or record, and workout files you import. This data may contain per-rep measurements recorded by your training equipment (such as range of motion, velocity, power, force, and related metrics).
- Recovery Signals & Biometric Data. If you choose to connect third-party accounts or manually enter recovery signals, we collect data such as sleep duration, sleep quality, heart rate, heart rate variability (HRV), resting heart rate (RHR), readiness scores, body weight, and related physiological contexts.
- Usage and Device Data. With your permission, we collect basic, privacy-respecting analytics about how you access and interact with the Service (including device type, operating system version, and general usage patterns) using our product analytics provider (PostHog). This helps us monitor performance and troubleshoot issues. In the EEA, the UK and Switzerland none of it is collected — and the analytics cookie is not set at all — unless you turn it on; elsewhere you can turn it off at any time. Either way, you can change your mind in Your Choices and Rights below.
2. How We Use Your Information
We process your data for the following core purposes:
- To provide and maintain the Service, including storing your training history and generating your performance analytics.
- To correlate your training output with recovery signals (such as sleep and HRV) to provide personalized insights.
- To facilitate communication regarding your account, security alerts, and, if you opt-in, product updates.
- To detect, prevent, and address technical bugs, security vulnerabilities, or policy violations.
3. Strict Health and Biometric Data Policies
We treat your recovery signals and biometric data (collectively, “Health Data”) with the highest level of privacy. The commitments below apply to all of it, whichever wearable or recovery-signal account it came from and whether you connected that account or entered the data yourself. They also hold us to the requirements of the health platforms we connect to:
- No Advertising or Marketing. We do not use Health Data for advertising, marketing, or interest-based profiling.
- No Sale or Lease. We will not sell, rent, lease, or trade your Health Data to third parties, advertising networks, or data brokers under any circumstances.
- Strictly Functional Use. We access and process Health Data solely to provide the analytics dashboard and fitness insights features requested by you, and to improve the core utility of our fitness tools.
4. Who Can See Your Data and How It Is Shared
We do not sell your personal data. Your training and recovery data is yours, and access is restricted by default. We only disclose data in the following instances:
- User-Authorized Connections (Coaches). If you explicitly invite a coach or collaborator to your training account, they will be granted access to view your data. Access is granular: the permission to view or write training plans is managed separately from the permission to view recovery and biometric data. You can change or revoke these permissions at any time.
- Trusted Service Providers. We rely on a small set of third-party vendors who assist us in running the Service. These include our hosting and database providers (Supabase), authentication services (Clerk), email delivery services (Resend), and product analytics (PostHog). These providers are contractually obligated to process data solely on our behalf, maintain strict confidentiality, and secure the data against unauthorized access.
- Legal Obligations. We may disclose information if required to do so by applicable law, regulation, subpoena, or legal process, or to protect the safety, property, and rights of Eccentric, our users, or the public.
5. Account Deletion and Data Retention
We retain your personal information, training records, and recovery data for as long as your account remains active, or as needed to deliver the Service.
In accordance with Google Play and Apple App Store requirements, you have the right to request the permanent deletion of your account and all associated data at any time:
- In-App Deletion: You can initiate complete account deletion directly from the Settings page within the Eccentric mobile app.
- Web-Based Request: If you are unable to log in, you can submit a deletion request through our Account Deletion Page or by sending an email to privacy@lifteccentric.app. You do not need to have the app installed to make this request.
Upon receiving a deletion request, we will permanently delete or anonymize all personal data, training history, and biometric data from our active systems within 30 days. Some data may temporarily persist in secure backups for legal or compliance reasons before being permanently overwritten.
6. Security
We employ industry-standard administrative, physical, and electronic security measures to protect your information both in transit and at rest. Biometric credentials, and the access credentials for every third-party account you connect — every wearable, recovery-signal provider, and piece of training equipment — are encrypted at rest using AES-256-GCM and stored in restricted-access database tables. Each connection type is encrypted with its own key, so one key never unlocks another connection’s credentials. However, no database or transmission over the internet is completely secure, and we cannot guarantee absolute security.
7. Children's Privacy
The Service is not intended for or directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that information from our servers.
8. Your Choices and Rights (GDPR / CCPA)
Depending on your jurisdiction (such as the European Economic Area under GDPR, or California under CCPA), you may hold specific rights, including:
- The right to access and export your training and recovery metrics.
- The right to correct or update inaccurate personal information.
- The right to revoke any third-party wearable or recovery-signal connection at any time, from the same place in the app where you connected it. Where the provider supports it, we also revoke our access on their side.
- The right to opt-out of marketing communications.
- The right to give or withdraw your consent to product analytics at any time, using the control below.
Withdrawing consent is as easy as giving it. This takes effect immediately — it stops collection on this page, not just on the next one.
To exercise any of the other rights above, please contact us at the email address provided below.
9. Changes to this Policy
We may update this Privacy Policy from time to time. When changes are made, we will update the “Last updated” date at the top of this page. For material updates, we will notify you through the Service or via email prior to the changes taking effect.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
Email: privacy@lifteccentric.app