IronTrack Privacy Policy
Effective date: 25 August 2026
IronTrack is a workout tracking application. This policy explains the data IronTrack processes and how users can control or delete it.
Data we process
Account/security: first and last name, email address, password hash, role, authentication/security metadata, password-reset metadata, and account timestamps. Plain-text passwords are not stored.
Fitness/progress: workouts, descriptions, dates, exercises, sets, weights, repetitions, rest periods, warm-up flags, notes, body weight, goals, target weight, body measurements, strength goals, workout templates, progress photos, and reminder settings when you use those features.
Subscriptions: plan, status, billing period, store provider, product ID, transaction/purchase identifier, renewal status, and subscription dates. IronTrack does not store payment-card details.
AI Coach: after a first-use in-app disclosure and consent, AI Coach may send OpenAI your current message, recent chat history in that session, primary goal, current/target body weight, weekly workout goal, recent completed workouts, exercise names, working-set weights/repetitions, strength goals, and personal-record information. IronTrack does not intentionally include your account email, password, progress photos, or body-measurement records in the AI prompt. Anything you type into the chat can become part of the message sent.
Technical: the app stores an auth token in secure device storage and schedules local notifications when enabled. Production builds contain no advertising or analytics SDKs. IronTrack hosting may process IP addresses, timestamps, and security logs to operate and protect the service.
Purposes and legal bases
Data is used to provide account access, workout/progress storage, statistics, Premium features, subscription entitlement synchronization, reminders, security/abuse prevention, and AI Coach responses requested by the user. Depending on applicable law, this is based on performance of the requested service, legitimate security/operational interests, legal obligations, and consent for optional AI data sharing.
Service providers
- Railway: currently hosts the IronTrack API and PostgreSQL database.
- OpenAI: processes AI Coach prompts only when the feature is used after consent. OpenAI states API inputs/outputs are not used to train models by default unless the API customer opts in. IronTrack sends Responses API requests with response-state storage disabled (store=false). OpenAI may still retain customer content in abuse-monitoring logs for up to 30 days under the API account's applicable data-retention controls unless another eligible retention configuration applies.
- Google Play / Apple App Store: process store purchases, payment information, subscription billing, cancellation, and store-side transaction records when store subscriptions are enabled.
IronTrack does not sell personal data.
Retention and deletion
Account and fitness data are kept while the account exists and as needed to provide requested features. Password-reset tokens expire after a short period.
Users can delete their account in the app at Profile > Account & security > Delete account or through the public account deletion page. Successful deletion removes the account and associated IronTrack workout/progress data from the active IronTrack database.
Deleting IronTrack does not automatically cancel Google Play/App Store billing. Store-side transaction records are controlled by the store. Data already sent to OpenAI remains subject to OpenAI's applicable API retention period.
Security
IronTrack uses HTTPS for production API traffic, password hashing, server-side authorization checks, rate limiting on sensitive endpoints, and secure device storage for authentication tokens.
Your choices and rights
You can edit certain information, delete supported progress records, withdraw AI Coach consent in the app, and delete the entire account. Additional access, correction, restriction, objection, deletion, or portability rights may apply depending on your location.
Children
IronTrack is not designed as a child-directed service. Users must meet the minimum age required by applicable law for use without parent/guardian authorization.
Contact
For privacy or support inquiries, contact IronTrack at irontracksupport@gmail.com.
Changes
This policy may be updated as the app, service providers, or legal requirements change. The effective date identifies this version.