Privacy Policy for TrackIron

Last updated: July 10, 2026

Publisher: Shrikant Deokrishna Hiwase
(Individual developer — not a company or organization.)

Contact: shrikant.hiwase@gmail.com

App: TrackIron (com.trackiron.app)

Request Data Deletion · Play Data Safety Answers

1. Introduction

This Privacy Policy describes how TrackIron (“we”, “the app”, “I”) handles information when you use this Android app. TrackIron is published by Shrikant Deokrishna Hiwase, an individual developer (not a company). I am committed to protecting your privacy and being transparent about my practices.

Google Play requirement: This policy is provided to meet Google Play’s disclosure requirements and to help you understand how I treat personal and sensitive data.

2. Two ways to use the app

You can use TrackIron in one of two modes:

Sign-in is optional. Core logging features work in guest mode without an account.

3. Information the app processes

3.1 Data stored on your device (local)

Whether you use guest mode or sign in, the app stores most information locally on your device (including a local SQLite database and app storage). This may include:

What stays local only: Your full workout history, nutrition log, hydration settings, achievements, and detailed progress calculations are not uploaded to my servers as part of normal use. They remain on your device unless you clear app data or uninstall the app.

3.2 Account sign-in with Google

If you choose to sign in with Google, the app uses Google’s sign-in flow and passes a token to Supabase Auth to create or restore your account. Google’s handling of your Google account is governed by Google’s Privacy Policy.

When you sign in, I may receive:

I use this information to identify your account, restore your session, and sync the cloud data described in Section 3.4.

If you use the app as a guest, Google account identifiers and Supabase authentication are not used.

3.3 Data collected through the app (profile setup and edits)

When you complete signup or edit your profile, the app processes fitness-related inputs you provide, such as name, weight, height, age, gender, activity level, and daily calorie goal.

These fields are stored locally and, if you are signed in with Google, synced to Supabase when you create or update your profile.

3.4 Cloud services (Supabase)

Signed-in users connect to a cloud backend hosted on Supabase. Supabase provides authentication, database hosting, and related infrastructure. Supabase’s privacy practices are described in Supabase’s Privacy Policy.

When you are signed in, the app may transmit the following to Supabase:

Profile sync (tied to your account ID and email): name, weight, height, age, gender, activity level, daily calorie goal, and timestamps. Profile data is updated on Supabase when you complete signup or change profile fields in the app while signed in.

Leaderboard personal records, when eligible: your display name (from your profile), exercise name, weight, reps, estimated one-rep max, and submission date.

PRs are uploaded only when all of the following apply:

Leaderboard visibility: Other users who are signed in can view leaderboard entries, which include display names and exercise performance data (exercise name, weight, reps, and estimated one-rep max). Email addresses and full profiles are not shown on the leaderboard.

Reading the leaderboard: When you open the home-screen leaderboard while signed in, the app fetches the current top entries from Supabase. If you are not signed in or the request fails, the app may show local or sample data instead.

3.5 Notifications

The app may schedule local notifications on your device (for example, hydration reminders). These are delivered by the operating system’s notification system. I do not collect the content of those notifications on any server I control.

3.6 Device data and analytics

I do not use third-party advertising or analytics SDKs in the app to track you across other companies’ apps or websites.

Standard device and OS information may be processed by Google Play, Google (sign-in), and Supabase (network requests) as part of installing, updating, authenticating, and operating the app, per their respective policies.

4. How I use information

I use the information described above to:

I do not sell your personal information.

5. Legal bases (where applicable)

If laws such as the GDPR apply, I rely on appropriate bases such as performance of a contract (providing the app you requested), consent (where required), and legitimate interests (operating and securing the service), as applicable. Sign-in and cloud sync are optional; you may use guest mode without creating an online account.

6. Sharing, third parties, and retention

6.1 Third-party services

Provider Purpose Their policy
Google Google Sign-In Google Privacy Policy
Supabase Authentication, profile storage, leaderboard database Supabase Privacy Policy
Google Play App distribution and updates Google Play Terms

6.2 Sharing with other users

If you submit an eligible PR to the leaderboard while signed in, your display name and lift details may be visible to other signed-in users on the global leaderboard, as described in Section 3.4.

6.3 Legal disclosures

I may disclose information if required by law or to protect rights and safety.

6.4 Retention

Cloud data may be stored in the region where the Supabase project is hosted. Processing may occur in countries with different data protection laws than your own.

7. Your choices and rights

Depending on your region, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing.

Your choices in the app:

Server-side data: To request deletion of your Supabase profile, auth account, and/or leaderboard entries, email me using the contact address at the top of this policy. Step-by-step instructions are on the Request Data Deletion page.

8. Security

I use reasonable measures to protect information, including HTTPS for network traffic and Supabase Row Level Security so each signed-in user can read/write only their own profile and PR rows (while leaderboard entries remain readable to other signed-in users as described above). No method of transmission or storage is 100% secure; I cannot guarantee absolute security.

9. Children’s privacy

TrackIron is not directed to children under 13 (or the minimum age required in your jurisdiction). I do not knowingly collect personal information from children under 13. If you believe I have done so, please contact me and I will take steps to delete such information.

10. International users

If you use the app from outside the country where I live, your information may be processed in countries (including Supabase hosting regions) that may have different data protection laws.

11. Changes to this policy

I may update this Privacy Policy from time to time. I will post the new version and update the “Last updated” date. Continued use of the app after changes means you accept the updated policy.

12. Contact

For privacy questions, contact me at: shrikant.hiwase@gmail.com

You may also use the contact details on the app’s Google Play store listing.