← Back to home

Legal

Privacy Policy and Terms of Use for TrackFull.

Last updated: February 2026

1. Data Controller

TrackFull ("the App", "we", "us") is the data controller responsible for the personal data collected through this application. By using the App, you acknowledge that you have read and understood this Privacy Policy.

This policy complies with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable national data protection laws.

2. Data We Collect

We collect the following categories of personal data:

Account & Identity

  • Email address and username (required for account creation)
  • Date of birth and gender (used for fitness calculations)
  • Profile picture (chosen from a predefined set — no uploaded photos)

Health & Fitness Data

  • Body metrics: weight and height
  • Fitness goal and activity level
  • Workout logs: exercises, sets, repetitions, weights, dates
  • Nutrition diary entries (if used)
  • Gym check-in location (name and city only — no GPS coordinates)

Social & Activity Data

  • Posts, comments, and reactions shared in the social feed
  • Friends list and group memberships
  • Achievements, streaks, and personal records

Technical & Usage Data

  • App preferences (theme, notification settings)
  • Subscription status (Pro / Free), managed via RevenueCat
  • Anonymous error and crash reports (via Firebase Crashlytics, if enabled)

3. Legal Basis for Processing

We process your personal data under the following legal bases (Article 6 GDPR):

  • Contract performance (Art. 6(1)(b)): Processing your account data, workout logs, and subscription status is necessary to provide the service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): Improving app functionality, preventing abuse, and securing user accounts.
  • Consent (Art. 6(1)(a)): Sending push notifications for workout reminders and streak alerts (you may withdraw consent at any time in Settings → Notifications).

4. How We Use Your Data

  • Providing core app features: workout tracking, nutrition diary, progress analytics
  • Personalising your experience (recommended workouts, fitness stats)
  • Displaying your public profile to friends and group members (only data you choose to share)
  • Processing and verifying your subscription via RevenueCat
  • Sending push notifications you have opted into
  • Maintaining security and detecting fraudulent activity

5. Data Sharing & Third Parties

We do not sell your personal data. We share data only with the following trusted sub-processors, each bound by data processing agreements:

  • Google Firebase (Google LLC): Authentication, cloud database (Firestore), and storage. Data may be stored in EU or US data centers. Google is Privacy Shield certified and provides Standard Contractual Clauses (SCCs).
  • RevenueCat, Inc.: Subscription management and receipt validation. RevenueCat processes only the data necessary to validate purchases and manage entitlements.
  • OpenAI, Inc.: AI Coach conversations and food scan images are processed by OpenAI to generate responses. Only the content you submit (messages and photos) is sent. OpenAI does not use this data to train its models under our API agreement. See OpenAI's privacy policy at openai.com/privacy.
  • Apple / Google: In-app purchase transactions are processed by the respective app store platform under their own privacy policies.

6. Data Retention

We retain your personal data for as long as your account is active. Upon account deletion, all personal data is permanently erased within 30 days, except where retention is required by law (e.g. financial transaction records).

Anonymised and aggregated analytics data (containing no personal identifiers) may be retained indefinitely for product improvement purposes.

7. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate or incomplete data directly in the app settings.
  • Right to erasure (Art. 17): Delete your account and all associated data via Settings → Delete Account.
  • Right to data portability (Art. 20): Export your workout data in CSV or JSON format via Settings → Export Your Data.
  • Right to object (Art. 21): Object to processing based on legitimate interest by contacting us.
  • Right to restrict processing (Art. 18): Request that we restrict the processing of your data in certain circumstances.

To exercise any of these rights, please contact us at the address below. You also have the right to lodge a complaint with your national data protection authority (e.g. CNIL in France).

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data transmission (TLS/HTTPS)
  • Firebase Security Rules restricting data access to authorised users only
  • Authentication tokens with automatic expiry
  • No storage of payment card data (handled exclusively by Apple/Google)

9. Children's Privacy

The App is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us and we will promptly delete the data.

10. Changes to This Policy

We may update this Privacy Policy periodically. When we make significant changes, we will notify you via an in-app notification or email. Continued use of the App after the effective date constitutes acceptance of the updated policy.

11. Contact

For any questions, data requests, or complaints regarding this Privacy Policy, please contact us at:

Email: support@trackfull.app
Response time: Within 30 days as required by GDPR