Privacy Policy
TraceIron has no server of its own. Your workouts live on your device and in your own private iCloud.
Last updated: July 29, 2026
1. Data we handle
Data you enter yourself: routine and exercise names, sets, weight, reps, rest times, and notes.
Health data via HealthKit, only if you grant permission: the duration and intensity of your workout sessions, which TraceIron records in Apple's Health app.
Technical identifiers generated on your own device (UUIDs) to relate your routines, exercises, and sets to one another. They are not tied to your real name or to any advertising identifier.
We do not collect third-party analytics, do not show ads, and do not sell or share your data with anyone.
2. Where it is stored
Locally, on your iPhone, iPad, and Apple Watch, via SwiftData.
In your own private iCloud, through automatic sync with CloudKit tied to your own Apple ID. Apple encrypts that data in transit and at rest; TraceIron has no access to it and keeps no parallel copy on any server of our own.
TraceIron does not operate any server or centralized database under our control, except for the specific case described in section 4 (Shared content).
3. HealthKit
If you grant permission, TraceIron records your workout sessions in the Health app so they show up alongside the rest of your physical activity.
We never sell or share health data with advertisers, data brokers, or any other third party, in line with Apple's HealthKit policies.
You can revoke this permission at any time from Settings → Privacy & Security → Health → TraceIron. The app keeps working without it; it simply stops recording your sessions in Health.
4. Shared content
When you use the share feature (swipe-to-share, or batch export), TraceIron uploads a copy of that routine or exercise to Apple's public CloudKit database, generating a short link (e.g. traceiron.com/r/abc123).
That content is accessible to anyone who receives the link, not only to the person importing it; it is not indexed by search engines, but it is not private either. Avoid putting personal or sensitive information in a routine's or exercise's name or notes before sharing it.
Sharing is always an explicit action on your part (never automatic), and anyone importing a link sees nothing about your identity beyond the content you chose to share.
You can ask us to remove already-shared content by writing to the contact address in section 7.
5. Purchases and subscriptions
All payments (monthly or annual Premium subscription, one-time Lifetime purchase, and individual themes such as Toxic or Founder) are processed entirely through Apple via StoreKit 2 and the App Store.
TraceIron never sees, receives, or stores your card or payment details. We only check your purchase status (entitlement) to unlock the corresponding features.
Cancellations, refunds, and subscription management happen directly with Apple, from Settings → [your name] → Subscriptions on your device.
6. Your rights
In line with Law No. 29733 (Peru's Personal Data Protection Law) and equivalent principles in other jurisdictions, you have the right to access, rectify, cancel, and object to the processing of your data.
Since your data lives on your device and in your own iCloud, you have direct control over nearly all of it: deleting the app removes local data, and you can manage or delete your iCloud data from your Apple account settings.
For content you've already uploaded to the public CloudKit database by sharing it (section 4), or for any other request about your data, contact us using the address in section 7.
7. Contact
For any question about this Privacy Policy or about your data, write to support@traceiron.com. We reply personally, since TraceIron is built by a single developer.