Privacy policy
Your training data deserves plain language.
This policy explains what Gym Trackr collects, why it is needed, when a record becomes public, how long access lasts, and how to delete your account.
Summary
Gym Trackr is a paid training service. It uses account, subscription, training, social, and diagnostic data to provide and protect the app. Gym Trackr does not sell personal data, show third-party advertising, or use personal data for cross-app tracking.
Training records are private by default. A workout receipt becomes available on the public web only when you explicitly create a share link. Anyone who possesses an active receipt link can view its privacy-filtered contents.
Data we collect
Account and identity
- Your account identifier, sign-in provider information, email address when supplied by Apple, display name, and optional profile image or avatar.
- Authentication session information used to keep your account signed in securely.
Subscription and purchase status
- Product identifier, entitlement state, trial or subscription status, renewal or expiry timing, and transaction-derived identifiers needed to validate and restore access.
- A device-verification identifier and Apple-signed purchase evidence used by the authenticated restore service to bind a valid purchase to the correct account.
- Paywall and subscription-flow interactions associated with your Gym Trackr account so access can be presented, restored, and supported correctly.
- Apple processes your payment details. Gym Trackr does not receive your full payment-card or bank-account information.
Fitness, training, and recovery information
- Programmes, templates, planned workouts, completed workouts, exercises, sets, repetitions, loads, rest, effort or RIR, timestamps, personal records, and notes you enter.
- Goals, schedule, available equipment, exercise familiarity, preferences, and onboarding answers used to build or explain a programme.
- Optional recovery check-ins, including energy, sleep, performance, soreness, and pain details that you choose to provide. Gym Trackr treats these as sensitive health-related information and does not diagnose a condition.
- Coach recommendations, their evidence references, and whether you accepted or dismissed a proposed change.
Pacts, safety, and sharing
- Pact membership, your display name and avatar within a Pact, weekly plan target and normalized follow-through, preset kudos, invitation metadata, and membership changes.
- Reports and blocks used to enforce member safety. Report reasons are restricted and are not a public feed.
- A privacy-filtered receipt payload when you create a public workout receipt link. The service stores only a cryptographic hash of the raw share token.
App, device, and diagnostic information
- App settings, units, notification preferences, and security state stored on your device and, where applicable, with your account.
- Sanitized crash, performance, and technical diagnostic data used to keep the service reliable. Session replay is disabled and the app is configured not to send default personal information to crash reporting.
- Restricted server security and webhook-delivery records used to prevent abuse, verify subscription events, and diagnose failed operations.
How we use data
Gym Trackr uses personal data to:
- authenticate your account and enforce paid access;
- store, synchronize, and restore your training record;
- generate and adapt a programme using your stated constraints and recorded training evidence;
- operate private Pacts and the sharing features you choose to use;
- provide account export, deletion, safety, fraud prevention, support, and service reliability; and
- comply with legal, tax, accounting, subscription, refund, and security obligations.
Gym Trackr does not use health or fitness information for advertising and does not sell it to data brokers.
Where data is processed
Gym Trackr uses service providers only for defined operational purposes:
- Apple for Sign in with Apple, App Store distribution, subscription billing, and transaction verification.
- Supabase for authentication, account-backed cloud storage, synchronization, public receipt lookup, and server functions.
- Superwall for presenting the subscription purchase flow, account-linked paywall interactions, and communicating signed subscription lifecycle events.
- Sentry for sanitized crash, performance, and technical diagnostics.
These providers process data under their own security and retention controls. Gym Trackr does not permit them to use training data for third-party advertising.
Public receipts and private Pacts
Workout receipt links
Creating a receipt link is optional. The public projection may include a workout title, exercise names, completed set counts, selected set evidence, duration when chosen, and factual personal-record comparisons. It excludes your account ID, profile, programme identifiers, private notes, pain and soreness answers, Pact data, and raw internal record IDs.
A receipt URL is a bearer link: anyone who receives or forwards it can view the filtered receipt until it expires or is revoked. Do not post a link somewhere you do not want it seen.
Pacts
Pacts are invitation-only groups for two to six paid members. Members see each other’s display name or avatar, original weekly plan target, normalized plan follow-through, and preset kudos. They do not see exercises, sets, loads, volume, workout notes, body data, recovery answers, or pain information.
A Pact invitation link does not expose the Pact name or member list on the public website. Acceptance occurs only inside the authenticated paid app.
How long data is kept
- Account and training data: retained while your account is active so the service can synchronize and restore it. Synchronization tombstones may remain during the account lifetime to prevent deleted items from returning on another device.
- Public workout receipts: public lookup stops after 90 days by default, or earlier when revoked or when the owning account or workout is deleted. An expired or revoked database record may remain privately associated with the account until account deletion.
- Pact invitations: invitations stop working after seven days, after their allowed use, or when revoked. Hashed invitation records may remain with the Pact until the Pact or owning account is deleted.
- Subscription integrity records: signed webhook and store-transaction records may remain after account deletion where needed to process renewals, refunds, prevent entitlement fraud, or meet legal and accounting duties. At deletion, the account and Superwall profile links and the additional AppTransaction correlation identifier are removed; minimum restricted transaction and cryptographic proof-replay identifiers may remain. Those residual records are not used for advertising.
- Diagnostics, logs, and backups: retained for limited operational, security, and disaster-recovery periods under the relevant provider settings, then aged out or deleted according to those controls.
Your choices and controls
- Review or edit your profile and app preferences.
- Export your account data before deletion.
- Create, list, revoke, or avoid public receipt links.
- Leave a Pact, revoke your invitations, report, or block.
- Manage notifications through the app and iOS settings.
- Manage or cancel your subscription through Apple’s App Store subscription settings.
Account deletion
In Gym Trackr, open your profile, choose Delete account, and confirm the irreversible request. The authenticated deletion service removes the Gym Trackr authentication principal and primary profile-owned cloud records. The app then makes a best-effort removal of account data, cached Pact data, notifications, and pending sync work from that device.
Account deletion also makes profile-owned public receipt links unavailable. Retained webhook and purchase-integrity evidence is unlinked from the deleted profile as described above, but minimum transaction and proof-replay identifiers may remain. Limited security, provider-log, or backup records may also remain for the purposes described in the retention section.
Deleting your Gym Trackr account does not cancel billing through Apple. Cancel or manage the subscription separately in App Store settings.
If you cannot access the app, contact support@gymtrackr.app from the address associated with your account. We may need to verify the request before acting.
Security
Gym Trackr uses authenticated access, row-level database controls, least-privilege function grants, transport encryption, token hashing for public links, rate controls, and restricted service credentials. No internet service can guarantee absolute security.
If you believe your account or a share link has been exposed, revoke the link where available, secure your Apple account, and contact support.
Children
Gym Trackr is not directed to children under 13. If you are under the age of majority where you live, use the service only with permission from a parent or legal guardian.
Policy changes and contact
This policy may change as the service or legal requirements change. The effective date above will be updated, and material changes may also be communicated in the app.
Questions, privacy requests, or deletion support: support@gymtrackr.app.