TrackCold

Privacy Policy

Effective: August 18, 2026

This Privacy Policy explains how TrackCold ("we", "us") collects, uses, and protects information in connection with the TrackCold iPhone app (the "App"), including its Apple Watch companion, Live Activities, and widgets, and the TrackCold website at trackcold.com (the "Website").

1. Summary

  • Your session content stays yours. Your written notes, the exact temperatures you record, any heart-rate and related biometrics captured during a session, and your stored session history live on your device and, if you enable it, sync through your own private iCloud. We have no server that receives them, and they are never sent to a third party.
  • The App uses three third-party services: Firebase Analytics and Firebase Crashlytics (Google) for anonymous usage and crash data, and RevenueCat for subscription management. To be precise about the boundary: Firebase does receive anonymous facts about a workout — that one was completed, its cold type, its duration, and its round count — but never your notes or the exact temperatures you record, and never your stored history. What each service receives is itemized in sections 2 and 5.
  • No cross-app tracking. The App displays no advertising, does not use the advertising identifier (IDFA), and never asks for permission to track you across other apps or websites. We do not share your information with advertising networks or data brokers.
  • The App does not require an account.
  • The Website uses Google Analytics 4 to understand aggregate visitor behavior. It does not personally identify you.
  • We do not sell your personal information.

2. Information collected by the App

The App is designed to operate without an account. The following data may be processed:

  • Session data — durations, temperatures you enter, ritual configurations, notes, and timestamps. Stored on your device. If iCloud is enabled in iOS Settings, this data is also synced via your private iCloud account, which is end-to-end encrypted by Apple.
  • HealthKit data — only if you grant permission. The App may write workout entries (mindful sessions, water temperature readings) to Apple Health and read your activity data to enrich session context. HealthKit data never leaves your device under our control; it is governed by Apple's HealthKit framework.
  • Subscription status — payments are processed by Apple via StoreKit. Apple remains the merchant of record; we never receive your payment method, Apple ID, or billing address. We use RevenueCat to verify and manage entitlement to Asgard premium features. RevenueCat receives purchase and transaction data — product identifiers, purchase, renewal and expiry dates, country of purchase, and an app-generated anonymous user identifier. It does not receive your session data.
  • Usage analytics (Firebase Analytics) — the App sends anonymous behavioral events to Google's Firebase Analytics so we can understand which features are used and where people get stuck. Examples: a workout was started or completed, which cold type and mode were selected, how many rounds a session had, how long it lasted, that a paywall was viewed, and which subscription product was viewed or purchased. Firebase also records standard device context — device model, operating system version, app version, language, coarse region, and a Firebase-generated app instance identifier.
    What is deliberately excluded: your name, your free-text session notes, and the exact temperatures you record. These are treated as session content and are never sent off your device. Analytics collection is enabled when the App launches.
  • Crash reports (Firebase Crashlytics) — when the App crashes or hits a serious error, Google's Firebase Crashlytics receives a crash report: the stack trace, device model, operating system and app version, the state of the app at the time, and an anonymous installation identifier. This is used only to find and fix bugs.
  • Apple diagnostics — separately, Apple may share aggregated crash and usage reports with us if you have opted in via iOS Settings → Privacy & Security → Analytics & Improvements → Share with App Developers. These are provided by Apple and do not personally identify you.

3. Information collected by the Website

  • Google Analytics 4 — measurement ID G-L9C4ZR53T6. Collects pageviews, referrer, approximate geographic region (city-level, derived from IP), device type, browser, screen size, language, and aggregate behavior (scroll depth, time on page). Google may set cookies in your browser. IP addresses are anonymized prior to storage by Google in regions where required.
  • Server access logs — our hosting provider (Vercel) records standard request metadata including IP address, user-agent, requested URL, and timestamp. Used for security, debugging, and abuse prevention. Retained for a limited period per the provider's policies.

4. How we use information

  • To operate, maintain, and improve the App and Website.
  • To verify subscription entitlement (Apple StoreKit and RevenueCat data).
  • To understand which features are used and where people get stuck (App analytics, in aggregate only).
  • To diagnose and fix crashes and errors (crash reports).
  • To understand which content is useful (Website analytics, in aggregate only).
  • To respond to your inquiries when you contact us.

5. Third parties

We work with the following service providers. Each is bound by their own privacy policy:

We do not share your information with advertising networks, data brokers, or other third parties for their own marketing purposes. We do not sell your personal information.

6. Cookies

The Website sets cookies via Google Analytics (_ga, _ga_*). These are used to distinguish users for analytics purposes. The App itself does not use cookies. You can clear or block cookies in your browser at any time; doing so will not affect your ability to use the Website.

7. Your rights

Depending on where you live (e.g., the EU/EEA, UK, California), you may have rights to access, correct, delete, or restrict processing of your personal information, and to object to certain processing or withdraw consent. To exercise any of these rights, email trackcold@suur.io. Because the App is account-less and stores most data on your device, you can also delete your data directly by uninstalling the App or clearing it from within the App's settings.

8. Children

TrackCold is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will take appropriate steps.

9. Data retention

Your session data is retained on your device (and in your iCloud) until you delete it. Subscription receipts and entitlement records are retained as required by Apple's and RevenueCat's policies and our financial-record obligations. App analytics and crash reports are retained per Firebase's retention settings (analytics events currently 14 months; crash reports currently 90 days). Website analytics data is retained per Google Analytics' default retention setting (currently 14 months). Aggregated, non-identifying data may be kept longer.

10. Security

We use reasonable technical and organizational measures to protect information. iCloud data is encrypted by Apple. The Website is served over HTTPS. No system is perfectly secure; you use the App and Website at your own discretion.

11. International transfers

The service providers we use (Apple, Google, Vercel) operate globally and may process data in countries other than your own. They participate in international data-transfer mechanisms (e.g., Standard Contractual Clauses) where applicable.

12. Changes

We may update this Privacy Policy. The "Effective" date at the top reflects the latest version. Material changes will be communicated through the App or Website. Continued use after a change constitutes acceptance.

13. Contact

Questions, requests, or concerns: trackcold@suur.io