
Privacy Policy
Last updated July 2026
LIFFT (“we”, “us”) provides software that helps healthcare providers and trainers support their patients and clients between visits. This policy explains what we collect, how we use it, and your choices.
Who controls the data
When a clinic or trainer uses LIFFT, they are the controller of their patients’ health information; LIFFT acts as their service provider (processor). For protected health information (PHI) in the United States, we operate under a Business Associate Agreement (BAA) with each covered entity. We only process PHI as needed to provide the service.
What we collect
Account data: name, email, role, and (for providers) professional credentials such as NPI or certifications.
Health & adherence data: assigned exercises and completions, daily pain check-ins (body-map locations, pain intensity, optional notes), posture-alert events, scores, and messages between a patient and their provider.
Technical data: device/browser info and basic usage events used to keep the service reliable and secure.
How we use it
To deliver the service to your provider or trainer, calculate adherence scores, generate reports for your care team, secure the platform, and improve the product. We do not sell your personal information.
De-identified research & benchmarking
We may create de-identified and aggregated data (stripped of identifiers so it cannot reasonably be linked back to you) for research, population health, benchmarking, and insurer reporting. De-identification follows recognized standards. Identifiable health information is never used for these purposes without appropriate consent or authorization. You can ask your provider about how your clinic handles this.
Security
Data is encrypted in transit and at rest, access is restricted to authorized roles within your organization, and activity is logged. No system is perfectly secure, but we work to protect your information using industry practices.
Your choices & rights
Depending on where you live, you may have rights to access, correct, export, or delete your data. Because your provider controls your record, please direct requests to them; we will support them in fulfilling your request.
Retention
We retain data for as long as your provider maintains your record or as required by law, then delete or de-identify it.
Contact
Questions? Email cj.28pineda@gmail.com.