Luntrack
← Back to app
Legal

Privacy Policy

Last updated: September 1, 2026

Luntrack ("we," "us," or "our") operates the Luntrack fitness and nutrition tracking application and the website at luntrack.com. This policy explains what we collect, why, on what legal basis, who else sees it, and what you can require us to do about it.

Data controller: Luntrack. You can reach us about anything in this policy at privacy@luntrack.com, and we answer data-rights requests within one month.

We have not appointed a Data Protection Officer; we are not required to.

Information We Collect

Account information. Username, email address, and your password stored as a scrypt hash. If you sign in with Google or Apple, we receive an account identifier and your email from them instead of a password.

Health and fitness data. This is the heart of the app, and most of it is "special category" data under GDPR:

  • Age, gender, height, weight and weight history, body-composition goals, activity level and training experience
  • Workouts you log — exercises, sets, reps, loads — and how recovered you report feeling
  • Food you log, by text, photo or barcode, and the calories, macronutrients and micronutrients derived from it
  • Step counts, if you connect Apple Health. We read steps only. We never write anything to Health, and the app works without it.

Precise location. When you start a run or a ride, the app records your GPS position for as long as that activity is running, including while the screen is off, so it can measure distance, pace and your route. The route is stored with that activity. Location is not collected at any other time, and it is never shown to anyone else.

Progress photos. Body progress photos are stored only on your device, in the app's own private storage. They are never uploaded to us, never added to your camera roll, and are tied to the device and the account that took them. We never receive them and cannot recover them.

Things you choose to publish. Your public profile — username, display name, avatar, rank, medals — and any lift video you submit to the leaderboard are visible to other users. Publishing is your decision, item by item, and each can be withdrawn.

AI conversations. Messages you send to the in-app assistant, and photos of meals you ask it to analyse.

Payment data. Subscriptions bought in the app go through Apple; subscriptions bought on the website go through Stripe. We never see or store your card number. We store which plan you are on and the identifiers needed to keep it working.

Technical data. IP address, device and browser type, and country-level location derived from the IP, for security, abuse prevention and aggregate analytics.

Why We Process It, and on What Legal Basis

Under GDPR we need a legal basis for every purpose, and a second, separate condition for health data. Ours are:

  • Running your account — Art. 6(1)(b), performance of our contract with you.
  • Calculating your targets, plans and recommendations, and keeping your health history — Art. 6(1)(b) contract, and Art. 9(2)(a), your explicit consent for the health data itself. You can withdraw that consent at any time (see Your Rights); withdrawing does not affect processing that already happened.
  • Your public profile and the leaderboard — Art. 6(1)(a) consent, given per item, and Art. 9(2)(e) for information you have deliberately made public.
  • Billing and subscriptions — Art. 6(1)(b) contract, and Art. 6(1)(c) legal obligation for tax and accounting records.
  • Security, fraud and abuse prevention — Art. 6(1)(f) legitimate interests. The interest is keeping accounts and the leaderboard from being taken over or gamed; we use the minimum needed (IP, device type, rate counters) and you can object.
  • Transactional email — Art. 6(1)(b) contract.

We do not sell your personal data. We do not use it for advertising, and we do not use it to train AI models.

Do you have to give us this data? Account details are required — without them there is no account. Health data is optional in the legal sense, but it is what the app does: without it Luntrack cannot calculate targets, build a plan, or show progress. Apple Health, location, camera and notifications are each optional and each can be refused or switched off later without losing the rest of the app.

Automated Processing

Luntrack calculates calorie and macro targets, generates training plans, and produces AI nutrition analysis automatically from what you enter. These are suggestions. They do not produce legal effects and nothing is decided about you that restricts your access to anything — so this is not automated decision-making within the meaning of Art. 22. Every number the app derives can be overridden by hand.

Who Else Sees It

We share data only with the providers needed to run Luntrack, and only what each one needs:

  • Apple — in-app subscriptions (privacy policy)
  • Stripe — payments made on the website (privacy policy)
  • Google, Apple — optional sign-in
  • Anthropic, Groq — the text and meal photos you send to the AI assistant are transmitted to these providers to produce a reply. They do not use it to train their models.
  • Cloudflare (R2) — storage for avatars and leaderboard videos
  • Render — hosting and databases

We may also disclose data where the law requires it, or to protect the rights and safety of users.

Where Your Data Goes

Luntrack is operated from, and its data is hosted in, infrastructure located in the United States. The providers listed above are also United States companies. That means personal data of users in the European Economic Area and the United Kingdom is transferred outside those areas.

Those transfers rely on the safeguards each provider offers under Art. 46 — Standard Contractual Clauses, and where applicable certification under the EU–US Data Privacy Framework — as set out in their own data processing terms. You can ask us at privacy@luntrack.com which safeguard applies to a particular provider.

Cookies and Local Storage

The website uses a session cookie to keep you signed in (HTTP-only and secure), and browser local storage for display preferences such as language and units. The mobile app stores your sign-in token in the iOS Keychain.

We use no tracking cookies and no third-party advertising cookies.

How Long We Keep It

  • Account and health data — while your account exists. Delete the account and it is removed within 30 days.
  • Payment and tax records — retained as long as tax law requires, typically 7 years, even after the account is deleted.
  • Security logs — short-lived, for abuse investigation.
  • Progress photos — we never hold them, so there is nothing on our side to delete. Deleting them in the app removes the files from your device.

Your Rights

If you are in the EEA or the UK, GDPR gives you the following. Everyone else gets them too — we do not run two standards.

  • Access (Art. 15) — a copy of the data we hold about you
  • Rectification (Art. 16) — correct anything inaccurate; most of it you can edit yourself in the app
  • Erasure (Art. 17) — delete your account and its data. Settings → Delete account, or ask us.
  • Restriction (Art. 18) — have us hold your data but stop using it while a dispute is resolved
  • Portability (Art. 20) — your data in a structured, machine-readable format; ask us and we will produce it
  • Objection (Art. 21) — object to processing based on our legitimate interests
  • Withdraw consent (Art. 7(3)) — withdraw your consent to health-data processing, or unpublish anything you made public, at any time and as easily as you gave it

Write to privacy@luntrack.com and we will answer within one month. You also have the right to complain to your local data protection supervisory authority — in the EEA you can find yours through the European Data Protection Board.

Children

Luntrack is not intended for children. You must be at least 16 to use it. Some EU member states set a lower age for consent to online services, down to 13; where that applies, the local age governs.

We do not knowingly collect data from anyone below that age. If you believe a child has given us personal data, write to privacy@luntrack.com and we will delete it.

Security

Passwords are stored as scrypt hashes and never in a readable form. Traffic is encrypted with HTTPS. Sign-in tokens are short-lived and can be revoked; the website's session cookie is HTTP-only and secure. Uploaded files are validated by their actual content rather than their filename. Access to production data is restricted and audited.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant supervisory authority as GDPR requires.

The Luntrack Mobile App

The app asks for permissions only when a feature needs them, and each is optional:

  • Camera — meal photos, barcodes, gym machine labels, progress photos, lift videos
  • Photo library — choosing a photo instead of taking one
  • Location — distance, pace and route while a run or ride is active, including in the background
  • Motion & fitness — step count during a run
  • Apple Health — reading your step count; we never write to Health
  • Notifications — reminders you set

Each can be refused at the prompt or turned off later in iOS Settings. Refusing one disables that feature and nothing else.

Changes to This Policy

We may update this policy. When we do we post it here with a new date, and for any material change we email every registered account a summary of what changed. Where a change affects processing you consented to, we will ask for your consent again rather than assume it.

Contact Us

Questions, or to exercise any right above:

Email: privacy@luntrack.com

Website: luntrack.com

Advertisement
Terms of Service Privacy Policy Refund Policy Back to Luntrack