This Privacy Policy describes how TrackIron (“we”, “the app”, “I”) handles information when you use this Android app. TrackIron is published by Shrikant Deokrishna Hiwase, an individual developer (not a company). I am committed to protecting your privacy and being transparent about my practices.
Google Play requirement: This policy is provided to meet Google Play’s disclosure requirements and to help you understand how I treat personal and sensitive data.
TrackIron requires Google sign-in to use the app. There is no guest mode. When you sign in, the app uses Supabase (see Section 3.4) to authenticate you and store a limited copy of certain data online, as described below.
The app stores most information locally on your device (including a local SQLite database and app storage). This may include:
What stays local only: Your full workout history, nutrition log, hydration settings, achievements, and detailed progress calculations are not uploaded to my servers as part of normal use. They remain on your device unless you clear app data or uninstall the app.
The app uses Google’s sign-in flow and passes a token to Supabase Auth to create or restore your account. Google’s handling of your Google account is governed by Google’s Privacy Policy.
When you sign in, I may receive:
I use this information to identify your account, restore your session, and sync the cloud data described in Section 3.4.
When you complete signup or edit your profile, the app processes fitness-related inputs you provide, such as name, weight, height, age, gender, activity level, and daily calorie goal.
These fields are stored locally and synced to Supabase when you create or update your profile while signed in.
The app connects to a cloud backend hosted on Supabase. Supabase provides authentication, database hosting, and related infrastructure. Supabase’s privacy practices are described in Supabase’s Privacy Policy.
The app may transmit the following to Supabase:
Profile sync (tied to your account ID and email): name, weight, height, age, gender, activity level, daily calorie goal, and timestamps. Profile data is updated on Supabase when you complete signup or change profile fields in the app.
Leaderboard personal records, when eligible: your display name (from your profile), exercise name, weight, reps, estimated one-rep max, and submission date.
PRs are uploaded only when all of the following apply:
Leaderboard visibility: Other signed-in users can view leaderboard entries, which include display names and exercise performance data (exercise name, weight, reps, and estimated one-rep max). Email addresses and full profiles are not shown on the leaderboard.
Reading the leaderboard: When you open the home-screen leaderboard, the app fetches the current top entries from Supabase. If the request fails, the app may show local or sample data instead.
The app may schedule local notifications on your device (for example, hydration reminders). These are delivered by the operating system’s notification system. I do not collect the content of those notifications on any server I control.
TrackIron may show advertisements in current or future versions of the app. If ads are enabled, the app may use third-party advertising SDKs (for example, Google AdMob or similar providers). Those providers may process device identifiers (such as the advertising ID), approximate location, and usage signals needed to deliver, measure, and personalize ads, subject to their own privacy policies and your device ad settings.
The app may also use analytics or crash-reporting tools to understand how the app performs and to fix issues. When such tools are used, they may process device and usage information as described by the provider.
Standard device and OS information may also be processed by Google Play, Google (sign-in / ads), and Supabase (network requests) as part of installing, updating, authenticating, monetizing, and operating the app, per their respective policies.
When advertising or analytics providers are added or changed, I will update this Privacy Policy and the Play Data Safety disclosures as needed.
I use the information described above to:
I do not sell your personal information.
If laws such as the GDPR apply, I rely on appropriate bases such as performance of a contract (providing the app you requested), consent (where required, including for certain advertising or analytics), and legitimate interests (operating and securing the service), as applicable.
| Provider | Purpose | Their policy |
|---|---|---|
| Google Sign-In; may also include advertising / AdMob if ads are enabled | Google Privacy Policy | |
| Supabase | Authentication, profile storage, leaderboard database | Supabase Privacy Policy |
| Google Play | App distribution and updates | Google Play Terms |
| Advertising / analytics providers | Serving ads, measuring performance, crash or usage analytics (when enabled) | As linked in this policy or in-app disclosures when those SDKs are active |
If you submit an eligible PR to the leaderboard, your display name and lift details may be visible to other signed-in users on the global leaderboard, as described in Section 3.4.
I may disclose information if required by law or to protect rights and safety.
Cloud data may be stored in the region where the Supabase project is hosted. Processing may occur in countries with different data protection laws than your own.
Depending on your region, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing.
Your choices in the app and on your device:
Server-side data: To request deletion of your Supabase profile, auth account, and/or leaderboard entries, email me using the contact address at the top of this policy. Step-by-step instructions are on the Request Data Deletion page.
I use reasonable measures to protect information, including HTTPS for network traffic and Supabase Row Level Security so each signed-in user can read/write only their own profile and PR rows (while leaderboard entries remain readable to other signed-in users as described above). No method of transmission or storage is 100% secure; I cannot guarantee absolute security.
TrackIron is not directed to children under 13 (or the minimum age required in your jurisdiction). I do not knowingly collect personal information from children under 13. If you believe I have done so, please contact me and I will take steps to delete such information.
If you use the app from outside the country where I live, your information may be processed in countries (including Supabase hosting regions) that may have different data protection laws.
I may update this Privacy Policy from time to time. I will post the new version and update the “Last updated” date. Continued use of the app after changes means you accept the updated policy.
For privacy questions, contact me at: shrikant.hiwase@gmail.com
You may also use the contact details on the app’s Google Play store listing.