Last updated: September 1, 2026
Luntrack ("we," "us," or "our") operates the Luntrack fitness and nutrition tracking application and the website at luntrack.com. This policy explains what we collect, why, on what legal basis, who else sees it, and what you can require us to do about it.
Data controller: Luntrack. You can reach us about anything in this policy at privacy@luntrack.com, and we answer data-rights requests within one month.
We have not appointed a Data Protection Officer; we are not required to.
Account information. Username, email address, and your password stored as a scrypt hash. If you sign in with Google or Apple, we receive an account identifier and your email from them instead of a password.
Health and fitness data. This is the heart of the app, and most of it is "special category" data under GDPR:
Precise location. When you start a run or a ride, the app records your GPS position for as long as that activity is running, including while the screen is off, so it can measure distance, pace and your route. The route is stored with that activity. Location is not collected at any other time, and it is never shown to anyone else.
Progress photos. Body progress photos are stored only on your device, in the app's own private storage. They are never uploaded to us, never added to your camera roll, and are tied to the device and the account that took them. We never receive them and cannot recover them.
Things you choose to publish. Your public profile — username, display name, avatar, rank, medals — and any lift video you submit to the leaderboard are visible to other users. Publishing is your decision, item by item, and each can be withdrawn.
AI conversations. Messages you send to the in-app assistant, and photos of meals you ask it to analyse.
Payment data. Subscriptions bought in the app go through Apple; subscriptions bought on the website go through Stripe. We never see or store your card number. We store which plan you are on and the identifiers needed to keep it working.
Technical data. IP address, device and browser type, and country-level location derived from the IP, for security, abuse prevention and aggregate analytics.
Under GDPR we need a legal basis for every purpose, and a second, separate condition for health data. Ours are:
We do not sell your personal data. We do not use it for advertising, and we do not use it to train AI models.
Luntrack calculates calorie and macro targets, generates training plans, and produces AI nutrition analysis automatically from what you enter. These are suggestions. They do not produce legal effects and nothing is decided about you that restricts your access to anything — so this is not automated decision-making within the meaning of Art. 22. Every number the app derives can be overridden by hand.
We share data only with the providers needed to run Luntrack, and only what each one needs:
We may also disclose data where the law requires it, or to protect the rights and safety of users.
Luntrack is operated from, and its data is hosted in, infrastructure located in the United States. The providers listed above are also United States companies. That means personal data of users in the European Economic Area and the United Kingdom is transferred outside those areas.
Those transfers rely on the safeguards each provider offers under Art. 46 — Standard Contractual Clauses, and where applicable certification under the EU–US Data Privacy Framework — as set out in their own data processing terms. You can ask us at privacy@luntrack.com which safeguard applies to a particular provider.
The website uses a session cookie to keep you signed in (HTTP-only and secure), and browser local storage for display preferences such as language and units. The mobile app stores your sign-in token in the iOS Keychain.
We use no tracking cookies and no third-party advertising cookies.
If you are in the EEA or the UK, GDPR gives you the following. Everyone else gets them too — we do not run two standards.
Write to privacy@luntrack.com and we will answer within one month. You also have the right to complain to your local data protection supervisory authority — in the EEA you can find yours through the European Data Protection Board.
Luntrack is not intended for children. You must be at least 16 to use it. Some EU member states set a lower age for consent to online services, down to 13; where that applies, the local age governs.
We do not knowingly collect data from anyone below that age. If you believe a child has given us personal data, write to privacy@luntrack.com and we will delete it.
Passwords are stored as scrypt hashes and never in a readable form. Traffic is encrypted with HTTPS. Sign-in tokens are short-lived and can be revoked; the website's session cookie is HTTP-only and secure. Uploaded files are validated by their actual content rather than their filename. Access to production data is restricted and audited.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant supervisory authority as GDPR requires.
The app asks for permissions only when a feature needs them, and each is optional:
Each can be refused at the prompt or turned off later in iOS Settings. Refusing one disables that feature and nothing else.
We may update this policy. When we do we post it here with a new date, and for any material change we email every registered account a summary of what changed. Where a change affects processing you consented to, we will ask for your consent again rather than assume it.
Questions, or to exercise any right above:
Email: privacy@luntrack.com
Website: luntrack.com