Privacy Policy

Last updated: June 22, 2026  ·  Effective: June 22, 2026

Thus And Also Technologies Private Limited, a private limited company incorporated under the laws of India and doing business as Trackr (also referred to as "Ember Labs Studio") ("Company", "we", "our", or "us"), operates the Trackr mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard your information when you use the Service, and the rights and choices available to you.

We act as the data controller (and, where applicable, the "Data Fiduciary" under India's DPDP Act and "Business" under the CCPA) for the personal information described here. This policy is written to be global-launch-ready and applies to users worldwide, with region-specific rights set out in Section 13.

Health data, in plain terms. Trackr is a wellness companion that processes sensitive health and fitness information — including data you enter and data from Apple Health / Google Health Connect — to generate personalized nutrition, movement, and wellness guidance. We process this data only with your explicit, opt-in consent, we never sell it, we never use it for advertising, and we do not allow our AI providers to train their models on it. You can withdraw consent and delete your data at any time. The details are below.

1. Information We Collect

Information You Provide

When you create an account or use the Service, you may provide us with:

Information Collected Automatically

When you use the Service, we may automatically collect:

Health & Fitness Data

With your explicit permission, we may collect health and fitness data from:

See Section 2 for how this sensitive data is handled.

Camera & Photos

With your permission, we access your device camera and photo library to:

Images are processed for analysis and are not stored permanently on our servers unless you explicitly save them (e.g. to your food log).

2. Sensitive & Health Data — Explicit Consent

Health and fitness data is treated as a special category of personal data under the GDPR (Article 9), as sensitive personal data under India's DPDP Act, and as sensitive personal information under the CCPA/CPRA. We hold it to a higher standard:

Data obtained through Apple HealthKit and Google Health Connect is additionally governed by Apple's and Google's platform requirements: it is never used for advertising, never sold to data brokers, and never shared for purposes unrelated to your health and fitness within the Service.

3. How We Use Your Information

We use the information we collect to:

4. Legal Bases for Processing (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or another region requiring a legal basis, we rely on the following:

PurposeLegal basis
Creating and operating your account; delivering core featuresContract (Art. 6(1)(b))
Processing health, fitness & medical-context data for personalizationExplicit consent (Art. 9(2)(a))
Health-platform integrations (HealthKit / Health Connect), camera, notificationsConsent (Art. 6(1)(a))
Security, fraud prevention, service improvement, analyticsLegitimate interests (Art. 6(1)(f))
Billing records, legal and regulatory complianceLegal obligation (Art. 6(1)(c))

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. AI & Automated Processing

Trackr is an AI-powered product. To deliver its features, content you provide — including chat messages, food photos, form-check videos, lab reports, and relevant health context — is sent to and processed by third-party large language model (LLM) and AI providers acting as our sub-processors (currently OpenAI, OpenRouter, and Google Gemini; see Section 6).

6. How We Share Data & Sub-Processors

We do not sell your personal information. We share it only with the service providers ("sub-processors") that operate the Service on our behalf, each bound by contractual confidentiality and data-protection obligations:

Sub-processorPurposeData involved
SupabaseDatabase, authentication, file storage (PostgreSQL on AWS)Account, profile, logs, health data
OpenAIEmbeddings, AI memory, language modelsChat, food/text content, embeddings
OpenRouterRouting for chat-completion language modelsChat & planning prompt content
Google (Gemini)Vision, food identification, form-check, lab parsingImages, lab reports, related context
PostHogProduct analytics & session diagnosticsUsage events, device, masked session data
LangfuseAI observability (quality, token cost)Prompt/response metadata
RailwayBackend application hostingData in transit during processing
ResendTransactional email deliveryEmail address, message content
RevenueCatSubscription managementPurchase/subscription status
Apple / GoogleApp distribution, in-app purchases, health platformsPurchase data; health data you authorize

We may also disclose information when required by law, to enforce our Terms, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, financing, or transfer of assets (including a future transfer of the app to an affiliated corporate account), subject to this policy. We keep an up-to-date sub-processor list and will update this section as our providers change.

7. International Data Transfers

We are based in India and our sub-processors operate in India, the United States, the European Union, and other countries. Your personal information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws.

Where we transfer personal data out of the EEA, UK, or other regions that restrict transfers, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum), or transfers to countries recognized as providing adequate protection. You may request a copy of the relevant safeguard by contacting us.

8. Cookies, Analytics & Session Recording

Our website uses only essential cookies necessary for it to function. We do not use third-party advertising cookies.

Within the app, we use PostHog for product analytics and, in limited cases, session diagnostics to understand how features are used and to fix problems. Where session recording is enabled, text inputs and images are masked so that the content of what you type or capture is not recorded. We use this data to improve the Service, not to identify you for marketing. You can object to analytics processing by contacting us, and we honor "Do Not Track" / Global Privacy Control signals where required by law.

9. Data Storage & Security

Your data is stored on secure, encrypted servers managed by Supabase (hosted on AWS infrastructure). We implement industry-standard security measures including:

While we strive to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

10. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g. tax and accounting records) or for the establishment, exercise, or defense of legal claims.

Chat history and AI memory associated with Ember conversations can be deleted at any time through app settings.

11. Account & Data Deletion

You are always in control of your data. You can:

Full step-by-step instructions are available at healthtrackr.me/delete-account.

12. Children & Minors

The Service is not directed to, and we do not knowingly create direct accounts for, children under the age required in your jurisdiction (generally 13; 18 where local law requires, including under India's DPDP Act). We do not knowingly collect personal information directly from children below the applicable age without verifiable parental consent.

Where the Service supports family use, profiles for children are created and managed by a parent or legal guardian through their own account, and that data is governed by the parent's account and consent. A parent or guardian may review, edit, or delete a child's profile at any time, or contact privacy@healthtrackr.me. If you believe we have inadvertently collected information from a child without proper consent, contact us and we will promptly delete it.

13. Your Privacy Rights by Region

Everyone

Subject to applicable law, you may request to access, correct, delete, export (port), or restrict processing of your personal data, and withdraw consent. To exercise any right, contact privacy@healthtrackr.me. We respond within 30 days (extendable where the law permits) and will not discriminate against you for exercising your rights.

European Economic Area & United Kingdom (GDPR)

You have the rights of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection (including to processing based on legitimate interests), and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority. Our EU/UK-facing requests are handled by our privacy contact below; where required, we will appoint an Article 27 representative.

India (Digital Personal Data Protection Act, 2023)

As a Data Principal, you may access and correct your data, request erasure, nominate another person to exercise rights in case of incapacity, and raise grievances with our Grievance Officer (Section 16). You may escalate unresolved grievances to the Data Protection Board of India.

California (CCPA / CPRA)

You have the right to know what personal and sensitive personal information we collect and how it is used and disclosed, to delete it, to correct it, and to opt out of "sale" or "sharing." We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information beyond the purposes permitted by law. You may exercise these rights, including via an authorized agent, at privacy@healthtrackr.me.

Other U.S. States

Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, and others) have similar rights to access, correct, delete, and opt out of targeted advertising and sale; contact us to exercise them.

14. Data Breach Notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay and in accordance with applicable law (including the GDPR 72-hour timeline and India's DPDP breach-notification requirements).

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. For material changes, we will provide more prominent notice (such as in-app notice or email) and, where required, seek your renewed consent. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16. Contact, DPO & Grievance Officer

For any question, request, or complaint about this policy or your data, contact us:

We aim to acknowledge grievances within 72 hours and resolve them within the timelines required by applicable law.