TrackNTrain

Privacy Policy

Last updated: August 23, 2026

At a Glance

TrackNTrain is a fitness and nutrition app. We collect data you give us (profile, workouts, food logs, etc.) and use it to power features in the app. We do not sell your data, do not use it for cross-context behavioral advertising, and do not use it to train AI models. You can download all your data, delete your account, or revoke any consent at any time at Settings → Data & Rights.

Who We Are

TrackNTrain, operated by Head Northward LLC (a Virginia limited liability company) (the "Service," "we," "us"), is a consumer fitness application. For privacy inquiries, contact privacy@trackntrainapp.com.

What Data We Collect

The categories below cover everything we collect from or about you.

  • Account. Email, username, display name, password (hashed), profile photo, bio.
  • Profile and health. Birth year, sex, height, weight, body composition, fitness goals, experience level, equipment access, sports, injuries, dietary restrictions, food allergies, pregnancy status (when self-reported).
  • Activity and logs. Workouts, sets/reps/weights, food intake, sleep data, sport metrics, personal records, body measurements, body scan photos.
  • Content. Posts, comments, captions, hashtags, photos, videos, messages.
  • AI conversation. Your chat history with the AI trainer, including what you ask and what the AI replies.
  • AI trainer memory (Pro). If you have Pro, we also derive and store short factual notes from your conversations — things like an injury you mention, your training schedule, equipment you have access to, dietary restrictions, or a goal you state — so the trainer does not have to be re-told them in every conversation. These notes are stored separately from the conversation itself and are limited in number; when the limit is reached, the least-used notes are deleted to make room. You can view every note we hold, delete any of them individually, or delete all of them, at any time, from the Memory panel on the AI Trainer screen. Free accounts do not have this feature and we do not build these notes for them.
  • Location (optional). When you search for fitness centers or set a "my gym," we associate you with a place but do not track your live GPS coordinates.
  • Device and usage. IP address, browser/device info, pages visited, feature usage, errors.

How We Use Your Data

  • Personalizing AI trainer advice, macro/calorie targets, and content recommendations.
  • Generating workout, meal, and recovery suggestions tailored to you.
  • Showing your progress (charts, streaks, history).
  • Enabling social features you choose to use (mimic, sharing, leaderboards, challenges).
  • Operating, securing, and improving the Service.
  • Communicating with you (transactional emails always; marketing only with consent).

How We Use Your Age

We ask for your birth year at signup. Age is a required input to a fitness app — it changes what is safe to recommend — so we want to be specific about every place it is used:

  • Eligibility and guardian consent. To confirm you meet our minimum age, and to require verified parent/guardian consent for users aged 15-17 before the account can be used.
  • Safety separation between minors and adults. To keep accounts we identify as minors out of adult discovery, search, and accountability-partner matching, and to keep adults out of minors' matching pools.
  • Calorie and macro targets. Age is a direct variable in the Mifflin-St Jeor equation we use to estimate your basal metabolic rate, and it influences protein and fiber recommendations. Without it, your targets would be wrong.
  • Workout programming. To adjust training volume, warm-up and recovery time, joint-friendly exercise substitutions, and progression pace, and to surface tracks (such as mobility and functional strength) that suit your stage of life.
  • AI trainer context. Your age is included in the context we give the AI trainer so its advice is appropriate for you rather than generic.
  • Content relevance. To weight your recommended feed toward content that is relevant to your stage of life, so older users are not shown a feed built entirely for a younger audience.
  • Ad restrictions for minors. To block age-restricted ad categories (such as supplements, alcohol, or diet products) from users aged 15-17.

We do not use your age or birth year to target advertising to you, we do not include it in the aggregate audience counts we share with advertisers, and we do not sell it. We store your birth year only — not your full date of birth — for accounts created after this policy took effect. Age is also not used to set pricing.

If your birth year is wrong, you can correct it at Settings → Edit Profile. Changing it re-runs the calculations above.

Who We Share With (Service Providers Only — Never Sold)

We share your data only with service providers who help us run the Service, under written Data Processing Agreements that bind them to use your data only on our instructions:

  • Supabase — database, authentication, file storage.
  • Vercel — application hosting.
  • OpenAI — AI trainer chat and food/meal/workout AI features. Per the OpenAI API agreement, your data is not used to train OpenAI's models.
  • Google Maps Platform — fitness center search.
  • Resend — transactional email.
  • USDA FoodData Central — nutrition database lookups.
  • Nutritionix — branded-food and restaurant nutrition lookups.
  • RevenueCat — subscription billing and purchase validation. Receives your purchase and subscription status; card details are handled by the Apple App Store, Google Play, or our payment processor and are never seen by us.
  • Strava (only if you connect it) — imports the activities and workout data you choose to sync. Connecting is optional, and you can disconnect at any time in Settings, which stops any further transfer.
  • Apple Push Notification service and Google Firebase Cloud Messaging — deliver push notifications to your device. They receive a device token, not the content of your health data.
  • Upstash — rate limiting that protects sign-in and posting from abuse.
  • Cloudflare — media storage and delivery (photos and videos you upload), plus network security for the Service. This includes Cloudflare Turnstile, which protects our sign-up and sign-in forms from automated abuse. Turnstile runs in invisible mode: it checks your browser in the background and does not ask you to identify traffic lights or solve a puzzle. It does not use your data for advertising and does not track you across sites. Cloudflare's Turnstile Privacy Addendum describes what it collects.
  • PostHog (when enabled, with your consent) — anonymized product analytics.
  • Sentry (when enabled) — error tracking.

We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising. We do not pipe your health data to ad networks.

Washington Consumer Health Data Privacy Notice (MHMDA)

If you are a Washington State resident, the My Health My Data Act (RCW 19.373) gives you specific rights regarding your "consumer health data." TrackNTrain qualifies as a "regulated entity" under this law.

Categories of consumer health data we collect: body measurements; fitness and exercise data; nutritional intake; sleep data; health conditions, allergies, and limitations; mental wellness indicators; reproductive and pregnancy data (when self-reported); goals and self-reported objectives; biometric identifiers (face, profile photos, body scan photos when uploaded).

Sources: directly from you; from connected health services you authorize (Apple HealthKit, Google Fit, Fitbit, Strava); from AI-generated estimates based on your inputs.

Purposes: personalizing the Service; generating recommendations; tracking your progress; enabling features you opt into.

Third parties: only the service providers listed above, as processors on our instructions. We do not sell consumer health data and do not share it with advertisers or data brokers.

Your MHMDA rights: right to know, access, request deletion (within 30 days), withdraw consent, and appeal denials. Exercise these at Settings → Data & Rights or by emailing privacy@trackntrainapp.com.

Geofence policy: TrackNTrain does not use geofencing within 2,000 feet of any in-person health care services entity (gyms, fitness centers, mental health providers, reproductive clinics, hospitals, substance abuse facilities). Your "my gym" association is your own self-declared selection — we do not detect, track, or notify you based on physical presence at a health facility. If we ever introduce such a feature, we will request your specific separate consent first.

California Consumer Privacy Rights (CCPA / CPRA)

California residents have these rights:

  • Right to know categories of personal information collected, sources, purposes, and third-party recipients.
  • Right to access a copy of your specific personal information.
  • Right to delete your personal information (subject to legal exceptions).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell or share, but the "Do Not Sell or Share My Personal Information" link is provided in the footer and Settings as required.
  • Right to limit use of sensitive personal information. Includes precise geolocation (when used), health data, biometric identifiers, and account credentials.
  • Right to non-discrimination for exercising privacy rights.

We respond within 45 days. To exercise any right: visit Settings → Data & Rights or email privacy@trackntrainapp.com.

Other State Privacy Rights

Residents of Colorado, Virginia, Connecticut, Utah, Texas, Oregon, and other US states with comprehensive privacy laws have substantially similar rights to those described for California. The same Settings flow and email contact apply.

Sensitive Personal Information

The following categories are designated as Sensitive Personal Information (CA CPRA) and "consumer health data" (WA MHMDA):

  • Precise geolocation (when used)
  • All body measurements and composition
  • All workout, sleep, food, and supplement logs
  • Health conditions, allergies, injuries, medications
  • Reproductive and pregnancy data
  • Mental health and mood data
  • Biometric identifiers (face, body scan photos)
  • AI trainer conversation content
  • AI trainer memory notes (these often describe injuries or physical limitations, so we treat them as health data)

These categories are collected only with explicit opt-in consent, never sold or shared for advertising, never used for non-service profiling, and deleted on request within 30 days.

Targeted Advertising and Profiling

We do not use your personal information for cross-context behavioral advertising. We do not send your health data, workout history, food logs, or any other personal information to Meta, Google Ads, TikTok, or any ad network.

If you opt in to personalized ads, the free tier may show ads chosen for relevance from a limited set of non-sensitive signals — specifically: the page you're viewing; the workout equipment you listed; the sports or activities you listed; the general area you chose in your profile (your selected city, region, or gym — never your precise device location); and general dietary lifestyle preferences you listed, such as vegan, vegetarian, pescatarian, keto, or paleo (so, for example, a plant-based food brand can reach people who eat vegan). If you do not opt in, your ads are not matched to you — you simply see general ads. Pro users see no ads. Users aged 15-17 see only a limited set of age-appropriate ads — never age-restricted categories (supplements, alcohol, or diet products) and never ads targeted to them. You can opt out of personalized ads at Settings → Privacy; ads themselves are part of the free tier, and Pro removes them entirely.

We do not use, for choosing the ads you see, any of the following: your fitness or health goals; your sex, age, or birth year; your logged workouts, meals, or calories; your body measurements, weight, or body-scan photos; injuries; food allergies; medical or allergy-related diets (such as gluten-free, dairy-free, or nut-free); religious dietary practices (such as halal or kosher); sleep; mental-health signals; pregnancy status; or any other health or special-category information. We would only ever propose using such data for ads behind a separate, explicit opt-in — and today we do not.

We may share aggregate, de-identified audience statistics with current or prospective advertisers, limited to adults 18 and over who have opted in to data sharing — for example, how many are in a given city or region, play a particular sport, use certain equipment, or follow a dietary lifestyle. These are counts only: they never identify you or include your profile, minors are never included, and any group of fewer than 50 people is hidden so no individual can be singled out. We never share counts of health-related categories (such as injuries, medical diets, or pregnancy).

Cookies and Local Storage

We keep the number of things stored on your device small enough to list them all:

  • Sign-in cookies (strictly necessary). Set by our authentication provider to keep you signed in and to protect against request forgery. These cannot be turned off — without them you cannot stay logged in. They are not used for advertising and are not shared.
  • Your privacy choices (local storage). Your answers to the consent banner are stored on the device so we can honour them before anything else loads.
  • Analytics (optional, off unless you turn it on). If — and only if — you opt in, our product-analytics provider sets identifiers to count feature usage. Screen recording is disabled, and we filter out any property that could carry health data.
  • A short-lived link cookie when you connect Strava, used only to verify that the connection request came from you. It is cleared immediately after.

We do not use third-party advertising cookies, ad-network tags, or tracking pixels, and we do not track you across other apps or websites. Ads shown in TrackNTrain are served by us from our own database.

Changing your mind. You can turn analytics and marketing emails on or off at any time in Settings → Privacy. Turning analytics off stops collection on that device immediately and applies to your other devices next time you open the app. You can also clear everything we have stored on a device through your browser's “clear site data” controls, though that will also sign you out.

Use of Artificial Intelligence (AI)

We use artificial intelligence to power several features. So you can make informed choices, here is where AI is involved in the app:

  • AI Coach / trainer chat — answers fitness and nutrition questions and adapts guidance to your goals, history, and equipment.
  • Food photo recognition — estimates the food and its macros from a photo you take.
  • Coach's workout & meal suggestions — generates personalized workout and meal ideas.
  • Exercise swaps — suggests alternative exercises for a movement.
  • Goal feasibility checks — flags whether a goal and its timeline look realistic.
  • Smart entry & search — parses pasted text, captions, and nutrition labels into logged items, and assists food search.
  • Calorie & macro targets — generates your recommended daily calories and macro split, and builds your training roadmap.
  • Content safety checks — automatically screens posts, comments, captions, and uploaded photos and video frames for content that breaks our rules (for example bullying, harassment, or nudity). These checks are automated and can lead to a warning, a strike, or content being removed or held for review. You can appeal any enforcement decision — see “Your Rights”.
  • Audio check on uploads — when a video's soundtrack is ambiguous, a short sample of the audio is transcribed to tell music apart from speech, so we can apply music and copyright rules.
  • Trainer memory — pulls durable facts out of your AI Coach conversations (for example an injury you mention) so the coach remembers them in later chats. You can view and delete these.

These features are powered by OpenAI's API as a service provider (see “Who We Share With”). We do not use your personal data to train AI models (see “AI Training Disclosure” below).

AI can make mistakes. AI-generated information may be inaccurate or incomplete and is not medical, nutritional, or professional advice. Use your own judgment and consult a qualified professional before acting on it. AI-generated content is labeled in the app.

AI Training Disclosure

We do not train any AI model on your personal data. TrackNTrain does not develop or fine-tune AI models. We use OpenAI's API services, and per the OpenAI API agreement, data submitted via the API is not used to train OpenAI's models.

Health Data Breach Notification

Under the FTC Health Breach Notification Rule, we are obligated to notify you of any breach of your unsecured health information. If a breach affects 500 or more users we notify affected users and the FTC within 60 days, and notify prominent media in any state where 500+ residents are affected. For smaller breaches we maintain an internal log and submit annual aggregated reports to the FTC.

Data Retention

  • Active account data — while account is active; logs deleted within 30 days of account deletion.
  • AI trainer conversation history — auto-deleted after 90 days; immediately deletable on request. Conversations flagged by our safety systems (for example, messages indicating risk of self-harm or harm to others) are retained for legal and safety review.
  • AI trainer memory notes (Pro)these outlast the conversations they came from. A note derived from a message is kept even after that message is deleted at 90 days, because its purpose is to persist. Notes are held while your Pro subscription is active and are deleted when they are displaced by newer notes, when you delete them yourself, when you delete your health data, or when you delete your account. If your Pro subscription ends, your notes are paused rather than deleted — they are retained but no longer used — so that resubscribing restores them; if you do not resubscribe, they are deleted automatically after 12 months. You can delete them immediately instead, at any time.
  • Body scan photos — while account is active; deleted within 30 days of account deletion.
  • Inactive accounts — deletion warning at 24 months; deleted at 36 months unless you log in.
  • Deleted account data — removed from primary database within 30 days; from backups within 90 days.
  • Security and breach logs — 6 years (FTC HBNR retention).

Direct messages when you delete your account. One-to-one conversations you were part of are deleted in full — both your messages and the other person's copy of that conversation. In a group conversation, your messages, name, and photo are removed, and you no longer appear as a member; the conversation itself continues for the remaining members, whose own messages we cannot delete on your behalf. After this, nothing in that group identifies you.

Biometric Data

We treat profile photos, body scan progress photos, and any face data extracted from photos as biometric data. We do not use facial recognition, identity matching, or any automated biometric processing. For Illinois (BIPA) and Texas (CUBI) residents: we do not collect, capture, retain, or disseminate biometric identifiers as defined under those laws. If our practices change, we will obtain explicit written consent first.

Minors (Users 15-17)

Users aged 15-17 receive enhanced protections:

  • Stricter default privacy settings (private profile by default).
  • No targeted advertising of any kind. Only non-targeted, age-appropriate ads are shown — never age-restricted categories (supplements, alcohol, or diet products).
  • No profiling for engagement-based feature recommendations.
  • DMs from non-followed adults off by default; enabled only with guardian approval.
  • Plain-language privacy disclosure at signup; default opt-out of non-essential data collection.

Users under 15 cannot create accounts. If we learn a user is under 15, the account is suspended and data deleted.

Child Safety and Illegal Content

We have zero tolerance for child sexual abuse material (CSAM) and the sexual exploitation of minors. When we become aware of apparent CSAM — whether reported by a user or otherwise identified — we act in accordance with U.S. federal law (18 U.S.C. § 2258A):

  • We preserve the content and related account information rather than immediately deleting it, so it can be provided to authorities.
  • We report apparent CSAM to the National Center for Missing & Exploited Children (NCMEC) via the CyberTipline, and cooperate with NCMEC and law enforcement.
  • We remove the content from public view and take action on the responsible account, up to permanent termination.

This means that if you upload such material, the relevant content and account data — including identifiers and metadata — may be preserved and disclosed to NCMEC and law enforcement as required by law, notwithstanding other retention or deletion provisions in this policy. We may similarly preserve and disclose information to comply with legal process or to protect the safety of our users.

How to Exercise Your Rights

All privacy and data rights are exercised through:

We respond within 45 days of receipt (extendable by up to 45 additional days with notice). Appeals are reviewed within 45 days. We do not charge for these requests.

International Transfers and GDPR

TrackNTrain is currently US-only. When we launch internationally, we will update this notice with EU/UK-specific disclosures including a designated Data Protection Officer, lawful basis for processing, and Standard Contractual Clauses for cross-border transfers.

Updates to This Privacy Policy

We will notify you of material changes by email and via in-app notification at least 30 days before they take effect. Material changes include any new category of data collected, any new third party with whom data is shared, or any reduction of your rights.

Contact