Privacy Policy
Last updated: August 11, 2026 · Effective: August 11, 2026
Thus And Also Technologies Private Limited, a private limited company incorporated under the laws of India and doing business as Trackr (also referred to as "Ember Labs Studio") ("Company", "we", "our", or "us"), operates the Trackr mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard your information when you use the Service, and the rights and choices available to you.
We act as the data controller (and, where applicable, the "Data Fiduciary" under India's DPDP Act and "Business" under the CCPA) for the personal information described here. This policy is written to be global-launch-ready and applies to users worldwide, with region-specific rights set out in Section 13.
Health data, in plain terms. Trackr is a wellness companion that processes sensitive health and fitness information — including data you enter and data from Apple Health / Google Health Connect — to generate personalized nutrition, movement, and wellness guidance. We process this data only with your explicit, opt-in consent, we never sell it, we never use it for advertising, and we do not allow our AI providers to train their models on it. You can withdraw consent and delete your data at any time. The details are below.
Health data also has its own dedicated policy: Consumer Health Data Privacy Policy, which sets out in more detail what health data we hold, who receives it, how we ask permission, and how to exercise your rights over it.
1. Information We Collect
Information You Provide
When you create an account or use the Service, you may provide us with:
- Name, email address, and profile information
- Date of birth, gender, height, and weight
- Dietary preferences, allergies, and nutritional goals
- Family member profiles (names, ages, dietary needs) created by you
- Food logs, meal plans, and recipe preferences
- Workout data, exercise history, and fitness goals
- Health context you choose to share (e.g. conditions, medications, lab reports, blood markers) to personalize guidance
- Chat messages, photos, and voice input sent to Ember (our AI companion)
- Feedback, support requests, and survey responses
Information Collected Automatically
When you use the Service, we may automatically collect:
- Device information (model, operating system, unique identifiers)
- Usage and interaction data (features accessed, time spent, interaction patterns)
- Crash reports and performance diagnostics
- IP address and approximate location (city-level)
- App version and update history
Health & Fitness Data
With your explicit permission, we may collect health and fitness data from:
- Apple HealthKit (steps, active energy, heart rate, sleep, weight)
- Google Health Connect (steps, calories burned, heart rate, sleep, weight)
- Bluetooth-connected devices (smart scales, fitness trackers)
See Section 2 for how this sensitive data is handled.
Camera & Photos
With your permission, we access your device camera and photo library to:
- Scan food for AI-powered nutritional analysis
- Scan barcodes for product identification
- Capture images (including form-check videos and lab reports) for analysis and chat interactions with Ember
What happens to an image depends on how you sent it, and the difference is not obvious from the app, so we would rather set it out here. A photo of food sent through the camera for instant recognition is analysed in the moment and not stored. An image you send into a chat with one of your coaches, a lab report or document you upload, and a progress photo you save are all kept until you delete them or close your account — they stay so your coaches can refer back to them. Section 10 sets out retention, and the section above explains how to delete them.
2. Sensitive & Health Data — Explicit Consent
Health and fitness data is treated as a special category of personal data under the GDPR (Article 9), as sensitive personal data under India's DPDP Act, and as sensitive personal information under the CCPA/CPRA. We hold it to a higher standard:
- We process it only on the basis of your explicit, opt-in consent, requested separately in-app before any health integration or health-context feature is enabled.
- We use it solely to provide the personalized nutrition, movement, sleep, and wellness features you ask for.
- We do not sell health data, do not share it for cross-context behavioral advertising, and do not use it for advertising of any kind.
- We do not permit our AI sub-processors to use your health data to train or improve their models (see Section 5).
- You can withdraw consent at any time in the app; withdrawal stops future processing and you may also delete the underlying data (Section 11).
Data obtained through Apple HealthKit and Google Health Connect is additionally governed by Apple's and Google's platform requirements: it is never used for advertising, never sold to data brokers, and never shared for purposes unrelated to your health and fitness within the Service.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, secure, and improve the Service
- Generate personalized meal plans, recipes, and nutritional recommendations
- Create and manage workout and movement programs tailored to your goals
- Power Ember's AI conversations, food/photo recognition, lab interpretation, and contextual understanding
- Track your nutritional intake, fitness progress, and health metrics
- Generate shopping lists optimized for your meal plans
- Send you relevant notifications (meal reminders, workout prompts, progress updates)
- Analyze aggregated, de-identified usage patterns to improve the Service
- Process subscriptions, prevent fraud, and provide customer support
- Comply with legal obligations and enforce our Terms
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another region requiring a legal basis, we rely on the following:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; delivering core features | Contract (Art. 6(1)(b)) |
| Processing health, fitness & medical-context data for personalization | Explicit consent (Art. 9(2)(a)) |
| Health-platform integrations (HealthKit / Health Connect), camera, notifications | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, service improvement, analytics | Legitimate interests (Art. 6(1)(f)) |
| Billing records, legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. AI & Automated Processing
Trackr is an AI-powered product. To deliver its features, content you provide — including chat messages, food photos, form-check videos, health documents you upload, and relevant health context — is sent to and processed by third-party AI providers acting as our sub-processors (currently DeepSeek, OpenAI, Google Gemini, and ElevenLabs; see Section 6).
- These providers process your content only to generate the response or analysis you requested, under API terms that prohibit using your data to train their models.
- We read the health documents you choose to upload, extract the values they contain, and use those values as context when building and adjusting your plans. Trackr does not diagnose any condition and does not provide a clinical interpretation of your results.
- We use observability tooling (Langfuse) to monitor AI quality and cost. Prompts and responses logged for this purpose include health context; access is restricted to operational needs.
- AI outputs (meal plans, calorie estimates, workout programs, and summaries of what you have told us) are automated estimates for general wellness purposes, may contain errors, and are not medical advice, a diagnosis, or a clinical interpretation of your health data. They can be inaccurate even when they sound precise and detailed. Trackr is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
Decisions made automatically
Much of what Trackr produces is generated automatically, without a person reviewing it first. So that you know which decisions those are, they include:
- Your daily calorie, macronutrient and micronutrient targets, and your estimated energy expenditure — calculated from your body data, age, sex and stated goals, and applied to your account.
- The meals, recipes and shopping lists in your plan, and how portions are scaled across a household.
- Your training programme, and adjustments to its intensity — for example easing a session after a run of poor sleep.
- Readiness and recovery estimates.
- Nutrition values for foods we cannot match exactly, which are an AI estimate rather than a measurement, and which then feed your totals.
- Notes our system keeps about you, drawn automatically from your conversations.
- Which health signals are surfaced to you, and when a coach suggests you speak to a doctor.
- When and how often we contact you, which adapts over time based on how you have responded before.
You can ask a person to review any of it. If an automated output affects you and you disagree with it, write to privacy@healthtrackr.me. You have the right to obtain human intervention, to explain your point of view, and to contest the outcome — and a person, not a system, will consider it.
6. How We Share Data & Sub-Processors
We do not sell your personal information. We share it only with the service providers ("sub-processors") that operate the Service on our behalf, each bound by contractual confidentiality and data-protection obligations:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage (PostgreSQL on AWS) | Account, profile, logs, health data, uploaded files |
| Railway | Backend application hosting | Data in transit during processing |
| DeepSeek | The language models that generate coaching, plans and replies. Established in China — see Section 7 | Chat content and the health context needed to answer, including your profile and goals |
| OpenAI | Food-photo recognition, reading uploaded health documents, speech-to-text, embeddings | Images, documents, audio and text content |
| Google (Gemini) | Exercise form-check video analysis | Form-check video and related context |
| ElevenLabs | Live voice coaching calls | Call audio and conversation transcripts |
| LiveKit | Real-time audio transport carrying voice calls between your device and ElevenLabs | Live audio stream and connection metadata |
| Langfuse | AI quality and cost monitoring | Prompts sent to and responses from AI models, which include health context |
| PostHog | Product analytics & session diagnostics | Usage events, device, masked session data |
| Sentry | Crash reporting | Crash diagnostics, device info, account identifier |
| New Relic | Server performance monitoring | Request diagnostics and identifiers |
| Expo | App updates and push notification delivery | Device and version information, notification content |
| Google Firebase (FCM) | Android push notification delivery | Device token, notification content |
| Cloudflare | Sending our email — family invites, sign-in and account mail, replies to feedback | Email address, message content |
| Cloudinary | Serving recipe and exercise images to your device | Your device's IP address and which recipe or exercise was viewed |
| RevenueCat | Subscription management | Purchase/subscription status |
| Apple / Google | App distribution, in-app purchases, health platforms | Purchase data; health data you authorize |
| Meta (WhatsApp) | Coaching messages — only if you turn this on | Phone number, message content |
| Grocery provider | Grocery ordering — only if you connect one | Basket contents, delivery address |
| Open Food Facts | Barcode product lookup | The scanned barcode |
| OpenStreetMap | Resolving a city name you type (sent via our servers, so your device address is not exposed) | The text you typed |
| OpenWeatherMap | Weather for your stored city | Your city |
| Tavily | Research lookups supporting coaching answers | Search queries derived from your context |
We may also disclose information when required by law, to enforce our Terms, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, financing, or transfer of assets (including a future transfer of the app to an affiliated corporate account), subject to this policy. We keep an up-to-date sub-processor list and will update this section as our providers change.
7. International Data Transfers
We are based in India, and our sub-processors operate in India, the United States, the European Union, China, and other countries. Your personal information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws and different levels of government access to data.
We use AI models from providers in both the United States and China, chosen for what each does best: US providers handle image recognition, document reading and speech, and DeepSeek, established in China, generates most coaching text. What reaches them is your message, the health context needed to answer it, and your first name so your coaches can address you. We do not send your email address, phone number, or payment details, and nothing we send would let a provider contact you or bill you. Payment details never leave Apple or Google.
China is not covered by a European Commission adequacy decision, so transfers there rely on our contract with the provider rather than on an adequacy finding. Where we transfer personal data out of the EEA, UK, or other regions that restrict transfers, we rely on appropriate safeguards or on transfers to countries recognized as providing adequate protection. If you would like to know what applies to your data, write to privacy@healthtrackr.me.
8. Cookies, Analytics & Session Recording
Our website uses only essential cookies necessary for it to function. We do not use third-party advertising cookies.
Within the app, we use PostHog for product analytics and, in limited cases, session diagnostics to understand how features are used and to fix problems. Where session recording is enabled, text inputs and images are masked so that the content of what you type or capture is not recorded. We use this data to improve the Service, not to identify you for marketing. You can object to analytics processing by contacting us at privacy@healthtrackr.me and we will act on it. Trackr is a mobile app rather than a website, and it does not currently detect "Do Not Track" or Global Privacy Control browser signals — those signals are not transmitted by an app. We say so rather than claim a control we have not built.
9. Data Storage & Security
Your data is stored on secure, encrypted servers managed by Supabase (hosted on AWS infrastructure). We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Access controls enforced in the application layer, so that a request can only reach the account it is authenticated for; row-level security is enabled in the database as an additional safeguard
- JWT-based authentication with secure token handling
- Regular security reviews and dependency updates
- Access controls limiting employee data access to operational needs
While we strive to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
10. Data Retention
Different kinds of data have different lifespans, and we would rather set them out than give you a single number that is only true of some of it.
| Category | How long we keep it |
|---|---|
| Recordings of voice coaching calls | Deleted within 30 days. We only keep a recording if you have separately agreed to it. Withdraw that permission and existing recordings are deleted straight away. |
| Transcripts of those calls | Kept as part of your coaching history, until you delete them or close your account. The recording and the transcript have different lifespans. |
| Account and profile | While your account is open. |
| Health, nutrition, movement and sleep history | While your account is open — this history is what lets your coaches see change over time. You can delete individual entries at any point. |
| Conversations and coaching memory | While your account is open. Deletable in app settings. |
| Uploaded documents and images | While your account is open, or until you delete them. |
| Subscription and billing records | As long as tax and accounting law requires, after account closure. |
| Security and diagnostic logs | A limited period for security and legal purposes. |
If you delete your account, we delete or anonymize your personal data — including stored files and images — within 30 days, except where retention is required by law (e.g. tax and accounting records) or for the establishment, exercise, or defense of legal claims. Where you have asked us to delete data, we also remove it from backup systems as those cycle, which can take up to six months.
We set these periods by reference to why we hold the data, how sensitive it is, the risk if it were exposed, and what the law requires.
11. Account & Data Deletion
You are always in control of your data. You can:
- Delete your account in-app — Profile → Privacy & data → Delete account. This permanently removes your account and associated personal data (subject to the legal-retention exceptions in Section 10). If you created a family that other people are still part of, deletion will ask you to hand that family over or remove it first — we will not delete shared household records out from under the people relying on them. Nothing is deleted until you resolve it, and then deletion proceeds in full.
- Request deletion by email — write to privacy@healthtrackr.me and we will process your request within 30 days.
Full step-by-step instructions are available at healthtrackr.me/delete-account.
12. Children & Minors
Trackr accounts are for adults. The Service is not directed to children, and you must be 18 or over — or the age of digital consent where you live, whichever is higher — to create your own account.
Trackr is built for households, so an adult can add family members, including children, to their own account. This lets meal planning work for everyone who eats at the table. Information about a family member — their age, dietary needs, allergies, and any health context the adult provides — is held under the adult's account and governed by this policy.
By adding someone to your household, you are confirming that you are entitled to provide their information — as their parent or legal guardian, or with their agreement. Please do not enter another person's health information otherwise.
A parent or guardian can review, correct, or delete a family member's information at any time in the app, or by contacting us. We do not use children's information for advertising, targeted advertising, tracking, or behavioural monitoring.
If you believe a child has created their own account, or that a child's information has reached us without proper authority, contact privacy@healthtrackr.me and we will delete it promptly.
13. Your Privacy Rights by Region
Everyone
Subject to applicable law, you may request to access, correct, delete, export (port), or restrict processing of your personal data, and withdraw consent. To exercise any right, contact privacy@healthtrackr.me. We respond within 30 days (extendable where the law permits) and will not discriminate against you for exercising your rights.
European Economic Area & United Kingdom (GDPR)
You have the rights of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection (including to processing based on legitimate interests), and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority. Our EU/UK-facing requests are handled by our privacy contact below; where required, we will appoint an Article 27 representative.
India (Digital Personal Data Protection Act, 2023)
As a Data Principal, you may access and correct your data, request erasure, nominate another person to exercise rights in case of incapacity, and raise grievances with our Grievance Officer (Section 16). You may escalate unresolved grievances to the Data Protection Board of India.
California (CCPA / CPRA)
You have the right to know what personal and sensitive personal information we collect and how it is used and disclosed, to delete it, to correct it, and to opt out of "sale" or "sharing."
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding twelve months. Because of this, we do not offer a "Do Not Sell or Share My Personal Information" link — there is nothing to opt out of.
We collect sensitive personal information — health and biometric-adjacent data, and precise information about your body — and we use and disclose it only for the purposes permitted under CCPA regulations without a right to limit: performing the services you asked for, ensuring security and integrity, short-term transient use, and verifying or maintaining service quality. We do not use or disclose it to infer characteristics about you. Because of this, we do not offer a "Limit the Use of My Sensitive Personal Information" link.
You may exercise these rights, including via an authorized agent (who must present written authority signed by you), at privacy@healthtrackr.me. We may need to verify your identity before acting. We will not discriminate against you for exercising any right. If we refuse a request, you may appeal — see "Appeals" below.
Other U.S. States
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Maryland, and others) have similar rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling. Contact us to exercise them.
Washington and Nevada residents: your consumer health data rights, including the right to withdraw consent and to obtain a list of the third parties we have shared health data with, are set out in our Consumer Health Data Privacy Policy.
Oregon residents may request a list of the specific third parties to which we have disclosed personal data.
Appeals
If we refuse a privacy request, we will tell you why. You may appeal by replying to our decision or writing to privacy@healthtrackr.me with the word "Appeal". A different person will review it, and we will respond in writing within 45 days with our reasoning.
If we deny your appeal you may complain to your regulator: your local supervisory authority in the EEA or UK, the Data Protection Board of India, or your State Attorney General in the United States. Washington State residents may file at atg.wa.gov/file-complaint.
How long we take
We respond to most requests within 30 days. Where the law allows more time for complex requests we may take up to 45 days, with one further 45-day extension, and we will tell you inside the first period if that happens. Requests under India's DPDP Act are answered within 90 days at the latest.
14. Data Breach Notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay and in accordance with applicable law (including the GDPR 72-hour timeline and India's DPDP breach-notification requirements).
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. For material changes, we will provide more prominent notice (such as in-app notice or email) and, where required, seek your renewed consent. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact, DPO & Grievance Officer
For any question, request, or complaint about this policy or your data, contact us:
- Legal Entity: Thus And Also Technologies Private Limited
- Brand / DBA: Trackr (operated as Ember Labs Studio)
- Country of Incorporation: India
- CIN: U74999DL2017PTC310852
- GSTIN: 07AAGCT1417P1Z1
- Registered Office: 19/13, West Patel Nagar, Central Delhi, Delhi — 110008, India
- Grievance Officer / Privacy Contact: Himanshu Garg — privacy@healthtrackr.me
- Support: support@healthtrackr.me
- Website: healthtrackr.me
We aim to acknowledge grievances within 72 hours and resolve them within the timelines required by applicable law.