← Back to TrackIron
Play Data Safety Answers — TrackIron
Use this page when filling out the Google Play Console → App content → Data safety form. Answers match current product direction: Google sign-in is required (no guest mode), local-first workout/nutrition storage, Supabase cloud sync for profile/leaderboard, and possible future advertising SDKs.
Play Console labels change over time. Map these answers to the closest matching categories in the form. Update this page again when ads or analytics SDKs ship.
1. Overview answers
- Does the app collect or share user data? Yes.
- Is all user data encrypted in transit? Yes (HTTPS for Google Sign-In, Supabase, and any ad/analytics network traffic).
- Can users request that data be deleted? Yes — see Request Data Deletion.
- Do you provide a way for users to request data deletion? Yes (in-app clear data / uninstall for local; email request for cloud).
2. Data collected
Declare collection for the types below. Primary purpose for account/fitness data: App functionality. If ads are enabled, also declare advertising / analytics purposes as applicable.
Personal info
| Type | Collected? | Notes |
| Name |
Yes |
Display / profile name. Stored on device; synced to Supabase. |
| Email address |
Yes |
Required — collected when the user signs in with Google (via Google → Supabase Auth). |
| User IDs |
Yes |
Supabase auth user ID for the signed-in account. |
| Address, phone, race/ethnicity, political/religious beliefs, sexual orientation |
No |
— |
Health and fitness
Yes — declare Health and fitness data. Play treats this category strictly.
- On device: weight, height, age, gender, activity level, calorie goals, workout logs (sets/reps/weights/duration), nutrition entries, personal records, progress metrics.
- Cloud: profile fitness fields (name, weight, height, age, gender, activity level, daily calorie goal) and eligible leaderboard personal records (display name, exercise, weight, reps, estimated 1RM).
- Not uploaded: full workout history, nutrition log, hydration settings, achievements remain on-device only.
Other common categories
| Category | Collected? |
| Financial info | No |
| Location | No (unless an ad SDK later receives approximate location — update if that ships) |
| Photos and videos | No |
| Audio files | No |
| Contacts | No |
| Calendar | No |
| Messages / SMS | No |
| Web browsing | No |
| App activity | Workout/nutrition logging for app functionality; may also include analytics events if an analytics SDK is added |
| Device or other IDs (advertising ID) | Declare Yes when ads/analytics SDKs that use the advertising ID are shipped; otherwise No |
3. Data shared
- Is data shared with third parties? Yes.
- Google: Sign-in (email / account identifiers as part of Google Sign-In + Supabase Auth). If ads are enabled, also Google advertising / AdMob as applicable.
- Supabase: Profile fields and eligible leaderboard PRs. Leaderboard entries (display name + lift details) are visible to other signed-in users.
- Advertising / analytics providers: Share as required by those SDKs when they are active (update Play Console when enabled).
- Sold? No. Data is not sold.
- Purpose of sharing: App functionality (account, sync, leaderboard); Advertising / Analytics when those features are enabled.
4. Processing / ephemeral vs stored
- Data is stored (not only ephemeral): on-device SQLite / app storage; cloud rows on Supabase for signed-in users.
- Sign-in is required — there is no guest-only local mode.
5. Account model
| Item | Behavior |
| Guest mode |
Not available — Google sign-in required |
| Email / Google account |
Yes |
| Local workouts / nutrition / PRs |
Yes (device) |
| Cloud profile sync |
Yes (Supabase) |
| Cloud leaderboard PRs |
Yes, when eligible |
6. Security practices to declare
- Data encrypted in transit (HTTPS).
- Users can request deletion of cloud account/profile/leaderboard data.
- Users can delete local data via Android clear storage / uninstall.
7. Related links for Play Console
If Play Console asks whether health data is collected: answer Yes. If it asks whether that data is shared: answer Yes for cloud profile sync / leaderboard (and for advertising partners only if those SDKs are live).