Last updated: August 23, 2026
TrackNTrain is a fitness and nutrition app. We collect data you give us (profile, workouts, food logs, etc.) and use it to power features in the app. We do not sell your data, do not use it for cross-context behavioral advertising, and do not use it to train AI models. You can download all your data, delete your account, or revoke any consent at any time at Settings → Data & Rights.
TrackNTrain, operated by Head Northward LLC (a Virginia limited liability company) (the "Service," "we," "us"), is a consumer fitness application. For privacy inquiries, contact privacy@trackntrainapp.com.
The categories below cover everything we collect from or about you.
We ask for your birth year at signup. Age is a required input to a fitness app — it changes what is safe to recommend — so we want to be specific about every place it is used:
We do not use your age or birth year to target advertising to you, we do not include it in the aggregate audience counts we share with advertisers, and we do not sell it. We store your birth year only — not your full date of birth — for accounts created after this policy took effect. Age is also not used to set pricing.
If your birth year is wrong, you can correct it at Settings → Edit Profile. Changing it re-runs the calculations above.
We share your data only with service providers who help us run the Service, under written Data Processing Agreements that bind them to use your data only on our instructions:
We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising. We do not pipe your health data to ad networks.
If you are a Washington State resident, the My Health My Data Act (RCW 19.373) gives you specific rights regarding your "consumer health data." TrackNTrain qualifies as a "regulated entity" under this law.
Categories of consumer health data we collect: body measurements; fitness and exercise data; nutritional intake; sleep data; health conditions, allergies, and limitations; mental wellness indicators; reproductive and pregnancy data (when self-reported); goals and self-reported objectives; biometric identifiers (face, profile photos, body scan photos when uploaded).
Sources: directly from you; from connected health services you authorize (Apple HealthKit, Google Fit, Fitbit, Strava); from AI-generated estimates based on your inputs.
Purposes: personalizing the Service; generating recommendations; tracking your progress; enabling features you opt into.
Third parties: only the service providers listed above, as processors on our instructions. We do not sell consumer health data and do not share it with advertisers or data brokers.
Your MHMDA rights: right to know, access, request deletion (within 30 days), withdraw consent, and appeal denials. Exercise these at Settings → Data & Rights or by emailing privacy@trackntrainapp.com.
Geofence policy: TrackNTrain does not use geofencing within 2,000 feet of any in-person health care services entity (gyms, fitness centers, mental health providers, reproductive clinics, hospitals, substance abuse facilities). Your "my gym" association is your own self-declared selection — we do not detect, track, or notify you based on physical presence at a health facility. If we ever introduce such a feature, we will request your specific separate consent first.
California residents have these rights:
We respond within 45 days. To exercise any right: visit Settings → Data & Rights or email privacy@trackntrainapp.com.
Residents of Colorado, Virginia, Connecticut, Utah, Texas, Oregon, and other US states with comprehensive privacy laws have substantially similar rights to those described for California. The same Settings flow and email contact apply.
The following categories are designated as Sensitive Personal Information (CA CPRA) and "consumer health data" (WA MHMDA):
These categories are collected only with explicit opt-in consent, never sold or shared for advertising, never used for non-service profiling, and deleted on request within 30 days.
We do not use your personal information for cross-context behavioral advertising. We do not send your health data, workout history, food logs, or any other personal information to Meta, Google Ads, TikTok, or any ad network.
If you opt in to personalized ads, the free tier may show ads chosen for relevance from a limited set of non-sensitive signals — specifically: the page you're viewing; the workout equipment you listed; the sports or activities you listed; the general area you chose in your profile (your selected city, region, or gym — never your precise device location); and general dietary lifestyle preferences you listed, such as vegan, vegetarian, pescatarian, keto, or paleo (so, for example, a plant-based food brand can reach people who eat vegan). If you do not opt in, your ads are not matched to you — you simply see general ads. Pro users see no ads. Users aged 15-17 see only a limited set of age-appropriate ads — never age-restricted categories (supplements, alcohol, or diet products) and never ads targeted to them. You can opt out of personalized ads at Settings → Privacy; ads themselves are part of the free tier, and Pro removes them entirely.
We do not use, for choosing the ads you see, any of the following: your fitness or health goals; your sex, age, or birth year; your logged workouts, meals, or calories; your body measurements, weight, or body-scan photos; injuries; food allergies; medical or allergy-related diets (such as gluten-free, dairy-free, or nut-free); religious dietary practices (such as halal or kosher); sleep; mental-health signals; pregnancy status; or any other health or special-category information. We would only ever propose using such data for ads behind a separate, explicit opt-in — and today we do not.
We may share aggregate, de-identified audience statistics with current or prospective advertisers, limited to adults 18 and over who have opted in to data sharing — for example, how many are in a given city or region, play a particular sport, use certain equipment, or follow a dietary lifestyle. These are counts only: they never identify you or include your profile, minors are never included, and any group of fewer than 50 people is hidden so no individual can be singled out. We never share counts of health-related categories (such as injuries, medical diets, or pregnancy).
We keep the number of things stored on your device small enough to list them all:
We do not use third-party advertising cookies, ad-network tags, or tracking pixels, and we do not track you across other apps or websites. Ads shown in TrackNTrain are served by us from our own database.
Changing your mind. You can turn analytics and marketing emails on or off at any time in Settings → Privacy. Turning analytics off stops collection on that device immediately and applies to your other devices next time you open the app. You can also clear everything we have stored on a device through your browser's “clear site data” controls, though that will also sign you out.
We use artificial intelligence to power several features. So you can make informed choices, here is where AI is involved in the app:
These features are powered by OpenAI's API as a service provider (see “Who We Share With”). We do not use your personal data to train AI models (see “AI Training Disclosure” below).
AI can make mistakes. AI-generated information may be inaccurate or incomplete and is not medical, nutritional, or professional advice. Use your own judgment and consult a qualified professional before acting on it. AI-generated content is labeled in the app.
We do not train any AI model on your personal data. TrackNTrain does not develop or fine-tune AI models. We use OpenAI's API services, and per the OpenAI API agreement, data submitted via the API is not used to train OpenAI's models.
Under the FTC Health Breach Notification Rule, we are obligated to notify you of any breach of your unsecured health information. If a breach affects 500 or more users we notify affected users and the FTC within 60 days, and notify prominent media in any state where 500+ residents are affected. For smaller breaches we maintain an internal log and submit annual aggregated reports to the FTC.
Direct messages when you delete your account. One-to-one conversations you were part of are deleted in full — both your messages and the other person's copy of that conversation. In a group conversation, your messages, name, and photo are removed, and you no longer appear as a member; the conversation itself continues for the remaining members, whose own messages we cannot delete on your behalf. After this, nothing in that group identifies you.
We treat profile photos, body scan progress photos, and any face data extracted from photos as biometric data. We do not use facial recognition, identity matching, or any automated biometric processing. For Illinois (BIPA) and Texas (CUBI) residents: we do not collect, capture, retain, or disseminate biometric identifiers as defined under those laws. If our practices change, we will obtain explicit written consent first.
Users aged 15-17 receive enhanced protections:
Users under 15 cannot create accounts. If we learn a user is under 15, the account is suspended and data deleted.
We have zero tolerance for child sexual abuse material (CSAM) and the sexual exploitation of minors. When we become aware of apparent CSAM — whether reported by a user or otherwise identified — we act in accordance with U.S. federal law (18 U.S.C. § 2258A):
This means that if you upload such material, the relevant content and account data — including identifiers and metadata — may be preserved and disclosed to NCMEC and law enforcement as required by law, notwithstanding other retention or deletion provisions in this policy. We may similarly preserve and disclose information to comply with legal process or to protect the safety of our users.
All privacy and data rights are exercised through:
We respond within 45 days of receipt (extendable by up to 45 additional days with notice). Appeals are reviewed within 45 days. We do not charge for these requests.
TrackNTrain is currently US-only. When we launch internationally, we will update this notice with EU/UK-specific disclosures including a designated Data Protection Officer, lawful basis for processing, and Standard Contractual Clauses for cross-border transfers.
We will notify you of material changes by email and via in-app notification at least 30 days before they take effect. Material changes include any new category of data collected, any new third party with whom data is shared, or any reduction of your rights.