trackd
TermsPrivacyDelete account
Legal

Privacy Policy

Effective date: September 1, 2026

This Application collects very little Personal Data from its Users — and none of your training data. Read the summary below for the whole picture in one screen; the full policy follows.

Policy summary

Personal Data processed for the following purposes, using the following services:

PurposeServicePersonal Data
Registration and authenticationSign in with Apple · GoogleEmail address; first name; account identifier
Hosting and infrastructureSupabase (EU — Frankfurt)Account data; licence status; usage counters; community and feedback data
Handling paymentsApple App Store · Google PlayNothing reaches us — the store takes the payment and tells us only that a licence is active
Checking purchases are genuineRevenueCatStore transaction identifier; licence tier and status; account identifier
Crash reportingSentry (EU — Frankfurt)Stack trace, device model, OS and app version — deliberately never linked to your account
Platform servicesApple App Store · Google PlayAggregate store statistics we cannot link to you
Push notificationsApple APNs · Google FCMDevice push token
Product email you opted intoEmail delivery providerEmail address; consent record
Community roadmapManaged directlySuggestion text; votes; private "not for me" signals
FeedbackManaged directlyRating; review text
Storing your training dataYour own cloud account — iCloud or Google DriveNone reaches us. Plans, sets, weights and notes stay in a folder you control
What is not on this list: advertising, interest-based ads, tracking SDKs, analytics tools, device advertising identifiers, contacts access, social profiles, or any handling of your training history on our side. There is nothing to opt out of, because none of it exists.
Owner and Data Controller. trackd — Estrada Nacional 13, Vivenda E, 4740-575 Esposende, Portugal. VAT number: PT 514 942 428. Contact: hello@trackd.pro.
  1. Owner and Data Controller
  2. Types of Data Collected
  3. Mode and Place of Processing
  4. Purposes of Processing
  5. Detailed Information on Processing
  6. Device Permissions
  7. Communications and Notifications
  8. Retention Time
  9. Security
  10. Personal Data of Children
  11. Your Rights Under the GDPR
  12. Changes to this Policy
  13. Contact

1Owner and Data Controller

trackd — Estrada Nacional 13, Vivenda E, 4740-575 Esposende, Portugal. VAT number: PT 514 942 428. Owner contact email: hello@trackd.pro.

Your use of trackd is also subject to our Terms of Service. Terms used here without definition have the meaning given there.

2Types of Data Collected

2.1Data we collect

Among the types of Personal Data this Application collects, by itself or through third parties, there are: email address; first name; account identifier; sign-in provider; licence and payment information; coarse usage counters; suggestion, vote and feedback text; marketing consent records; device push token; crash reports (stack trace, device model, OS and app version — never linked to your account); and anything you include when you contact us.

2.2Data we never receive — your training

Plans, workouts, logged sets, weights, effort ratings and notes are stored on your device and synced to storage trackd creates in your own cloud account — an app folder in iCloud Drive, or a file trackd creates in Google Drive. That folder is yours, held under your provider's terms — the provider is not processing it on our behalf, and we have no access to it. In guest mode, nothing leaves your device at all.

Where the connected cloud is Google Drive, access uses Google’s non-sensitive “drive.file” scope, which grants trackd access only to files trackd itself creates — never to anything else in your Drive. trackd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: data obtained through Google APIs is used only to provide the sync you can see, and is never used for advertising, never sold, and never used to train AI or machine-learning models.

2.3Mandatory and optional Data

Email address and account identifier are necessary to provide the Service; without them we cannot maintain your account or licence. Everything else — suggestions, votes, feedback, marketing consent, push notifications, a profile photo — is optional, and declining has no effect on how the app works.

2.4Trackers and cookies

The app uses no cookies, trackers, advertising identifiers, or third-party analytics SDKs. The one diagnostic tool is crash reporting (Section 5.9), which is deliberately configured so a report can never be traced back to you.

3Mode and Place of Processing

3.1Methods of processing

We take appropriate security measures to prevent unauthorised access, disclosure, modification, or destruction of Data. Processing is carried out using computers and IT-enabled tools, following organisational procedures strictly related to the purposes indicated. Besides us, Data may be accessible to external parties appointed as Data Processors where necessary — a hosting provider, a payment processor, an email delivery provider. An updated list may be requested from us at any time.

3.2Place

The account database is hosted in the European Union (Frankfurt). Some providers — notably the app stores, RevenueCat and the platform push services — may process Data outside the EEA. Crash reports are stored in Sentry’s EU region (Frankfurt), although Sentry itself is a United States company. Those transfers rely on the EU Data Privacy Framework where applicable and on standard contractual clauses, with supplementary measures where needed.

4Purposes of Processing

Data concerning you is processed to allow us to provide the Service, comply with legal obligations, respond to enforcement requests, protect our rights and interests, detect fraudulent or malicious activity, and for the purposes listed in the summary above — each one detailed in Section 5.

PurposeData usedLegal basis
Your account and licence; service email such as receipts and security noticesAccount, licencePerformance of a contract
Understanding whether the app is useful and where people drop offCoarse usage countersLegitimate interests
Running the roadmap, one vote per personCommunityConsent
Improving the app from what you tell usFeedbackConsent
Optional product emailEmail, consent recordConsent, or legitimate interests for existing customers
Proving consent was givenConsent recordLegal obligation
Tax, accounting, dispute resolutionLicence, correspondenceLegal obligation, legitimate interests

We will not use Personal Data for materially different, unrelated, or incompatible purposes without telling you first.

5Detailed Information on Processing

5.1Registration and authentication

Sign in with Apple or Google. Used to create your account and to connect the app to your own cloud storage. Personal Data: email address; first name; account identifier. If you sign in with Apple using a private relay address, we only ever see that relay address.

5.2Hosting and infrastructure

Supabase (Supabase Inc., EU region — Frankfurt), acting as our Data Processor. Hosts the account database: account data, licence status, usage counters, community and feedback data. Row-level security means an account can only read its own rows.

5.3Handling payments

Apple (App Store) and Google (Google Play). They take the payment as seller of record and act as independent controllers for it, under their own privacy policies. We are never told your card details, your billing address, or the address you use with the store — no payment Data reaches us at all.

RevenueCat (RevenueCat, Inc., United States), acting as our Data Processor. Checks that a purchase is genuine and tells us which licence to grant. Personal Data: store transaction identifier; licence tier and status; account identifier.

5.4Platform services

Apple App Store and Google Play. Distribute the app and provide us with aggregate statistics — installs, crashes, ratings — that we cannot link to an individual User. Personal Data: usage data in aggregate.

5.5Push notifications

Apple APNs and Google FCM. Deliver notifications if you allow them. Personal Data: device push token.

5.6Product email

Email delivery provider. Sends the email you opted into and processes unsubscribes. Personal Data: email address; consent record.

5.7Community roadmap and feedback

Managed directly. Suggestions you submit, your votes, private "not for me" signals, ratings and review text. Suggestions may be rephrased and published anonymously for community voting. Personal Data: the text you write; account identifier.

5.8Beta testing

Pre-release builds are tested internally through TestFlight and Google Play internal testing by people we invite directly. If you are not an invited tester, no Data of yours is processed for this purpose.

5.9Crash reporting

Sentry (Functional Software, Inc., United States — data stored in Sentry’s EU region, Frankfurt), acting as our Data Processor. When the app or this website hits an error, a report is sent so we can fix it: the stack trace, device model, operating system and app version. It is deliberately configured to carry no identity — no account identifier is ever attached, and the report does not store your IP address — so a crash can never be traced back to you. Your training data is never included.

6Device Permissions

Depending on your device, the app may ask for the permissions below. They must be granted by you before the respective information can be accessed, and you can revoke them at any time in your device settings. Revoking a permission may affect the related feature only.

  • Notifications — to tell you when a rest timer ends, or when a community idea goes up for voting or ships.
  • Photo library / camera — only if you choose to set a profile photo. The image stays on your device and in your own cloud folder; it is not uploaded to us.
  • Cloud storage access — to read and write the app's own folder in your cloud account. The app cannot see the rest of your drive.

We do not request contacts, location, microphone, or health-data permissions, and trackd does not read from or write to Apple Health or Google Fit.

7Communications and Notifications

7.1Service email

Purchase receipts, licence notices, and security messages are part of the contract and cannot be switched off while you hold an account.

7.2Optional email

When you set up the app you can tick "Keep me posted about trackd". The box is unticked by default. If you tick it, we may write to you about the product, releases, the community, and what we are working on. If you have purchased a licence we may also email you about the product under the ePrivacy rule for existing customers. Every message carries a one-click unsubscribe, and unsubscribing never affects your licence.

8Retention Time

Personal Data is processed and stored for as long as required by the purpose it was collected for, and may be kept longer where a legal obligation or your consent requires it. Specifically:

  • Account and licence: while your account is open, then deleted within 30 days — except invoices, kept 10 years under Portuguese tax law.
  • Usage counters: 24 months.
  • Community data: while relevant to the roadmap; shipped items may remain as an anonymous record.
  • Feedback: 24 months, or until you ask us to delete it.
  • Consent records: for as long as needed to prove consent, then deleted.

Once a retention period expires the Data is deleted, and the rights of access, erasure, rectification and portability can no longer be exercised over it.

9Security

Data in transit is encrypted with TLS; the database is encrypted at rest with row-level access rules. Administrative access is restricted and requires multi-factor authentication. No method of transmitting or storing data is completely secure, but if a breach affects your rights we will notify the CNPD within 72 hours and you without undue delay.

10Personal Data of Children

trackd is intended for people aged 16 and over, and we do not knowingly collect Personal Data from anyone younger. If you believe a child has provided us Personal Data, contact us and we will delete it as quickly as possible.

11Your Rights Under the GDPR

11.1What you can do yourself, immediately

  • Access and portability — Export in Settings produces your complete training history as one machine-readable file.
  • Erasure — Delete account in Settings removes your account, licence record, votes, feedback and usage counters from our database. Roadmap suggestions are detached from your account rather than deleted, so the public board stays intact — they carry no link to you afterwards. Invoices are kept for ten years under Portuguese tax law. Your cloud folder is yours: delete it in your provider if you want it gone. See Delete your account for the step-by-step.
  • Rectification — edit anything in the app; it is your file.
  • Withdraw consent — unsubscribe from any email, or ask us to delete a suggestion or review.

11.2What to ask us for

You also have the right to restriction of processing, to object to processing based on legitimate interests (including the usage counters), to obtain confirmation of whether we process your Data and a copy of it, and to have it transmitted to another controller where technically feasible. Email us and we will respond within 30 days, free of charge.

11.3Complaints

You may lodge a complaint with your competent supervisory authority — in Portugal, the CNPD.

11.4No profiling

We carry out no profiling and no automated decision-making.

12Changes to this Policy

We may update this Policy as the product evolves. We will change the effective date above and, for anything material, tell you in the app before it takes effect. One commitment does not change: your training data stays in your own cloud.

13Contact

Questions or requests about privacy: hello@trackd.pro.

trackd — Estrada Nacional 13, Vivenda E, 4740-575 Esposende, Portugal · VAT number PT 514 942 428 · hello@trackd.pro
© 2026 trackdtrackd.proTermsPrivacyDelete accountContact