Privacy Policy
Last updated: June 22, 2026 · Effective: June 22, 2026
Thus And Also Technologies Private Limited, a private limited company incorporated under the laws of India and doing business as Trackr (also referred to as "Ember Labs Studio") ("Company", "we", "our", or "us"), operates the Trackr mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard your information when you use the Service, and the rights and choices available to you.
We act as the data controller (and, where applicable, the "Data Fiduciary" under India's DPDP Act and "Business" under the CCPA) for the personal information described here. This policy is written to be global-launch-ready and applies to users worldwide, with region-specific rights set out in Section 13.
Health data, in plain terms. Trackr is a wellness companion that processes sensitive health and fitness information — including data you enter and data from Apple Health / Google Health Connect — to generate personalized nutrition, movement, and wellness guidance. We process this data only with your explicit, opt-in consent, we never sell it, we never use it for advertising, and we do not allow our AI providers to train their models on it. You can withdraw consent and delete your data at any time. The details are below.
1. Information We Collect
Information You Provide
When you create an account or use the Service, you may provide us with:
- Name, email address, and profile information
- Date of birth, gender, height, and weight
- Dietary preferences, allergies, and nutritional goals
- Family member profiles (names, ages, dietary needs) created by you
- Food logs, meal plans, and recipe preferences
- Workout data, exercise history, and fitness goals
- Health context you choose to share (e.g. conditions, medications, lab reports, blood markers) to personalize guidance
- Chat messages, photos, and voice input sent to Ember (our AI companion)
- Feedback, support requests, and survey responses
Information Collected Automatically
When you use the Service, we may automatically collect:
- Device information (model, operating system, unique identifiers)
- Usage and interaction data (features accessed, time spent, interaction patterns)
- Crash reports and performance diagnostics
- IP address and approximate location (city-level)
- App version and update history
Health & Fitness Data
With your explicit permission, we may collect health and fitness data from:
- Apple HealthKit (steps, active energy, heart rate, sleep, weight)
- Google Health Connect (steps, calories burned, heart rate, sleep, weight)
- Bluetooth-connected devices (smart scales, fitness trackers)
See Section 2 for how this sensitive data is handled.
Camera & Photos
With your permission, we access your device camera and photo library to:
- Scan food for AI-powered nutritional analysis
- Scan barcodes for product identification
- Capture images (including form-check videos and lab reports) for analysis and chat interactions with Ember
Images are processed for analysis and are not stored permanently on our servers unless you explicitly save them (e.g. to your food log).
2. Sensitive & Health Data — Explicit Consent
Health and fitness data is treated as a special category of personal data under the GDPR (Article 9), as sensitive personal data under India's DPDP Act, and as sensitive personal information under the CCPA/CPRA. We hold it to a higher standard:
- We process it only on the basis of your explicit, opt-in consent, requested separately in-app before any health integration or health-context feature is enabled.
- We use it solely to provide the personalized nutrition, movement, sleep, and wellness features you ask for.
- We do not sell health data, do not share it for cross-context behavioral advertising, and do not use it for advertising of any kind.
- We do not permit our AI sub-processors to use your health data to train or improve their models (see Section 5).
- You can withdraw consent at any time in the app; withdrawal stops future processing and you may also delete the underlying data (Section 11).
Data obtained through Apple HealthKit and Google Health Connect is additionally governed by Apple's and Google's platform requirements: it is never used for advertising, never sold to data brokers, and never shared for purposes unrelated to your health and fitness within the Service.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, secure, and improve the Service
- Generate personalized meal plans, recipes, and nutritional recommendations
- Create and manage workout and movement programs tailored to your goals
- Power Ember's AI conversations, food/photo recognition, lab interpretation, and contextual understanding
- Track your nutritional intake, fitness progress, and health metrics
- Generate shopping lists optimized for your meal plans
- Send you relevant notifications (meal reminders, workout prompts, progress updates)
- Analyze aggregated, de-identified usage patterns to improve the Service
- Process subscriptions, prevent fraud, and provide customer support
- Comply with legal obligations and enforce our Terms
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another region requiring a legal basis, we rely on the following:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; delivering core features | Contract (Art. 6(1)(b)) |
| Processing health, fitness & medical-context data for personalization | Explicit consent (Art. 9(2)(a)) |
| Health-platform integrations (HealthKit / Health Connect), camera, notifications | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, service improvement, analytics | Legitimate interests (Art. 6(1)(f)) |
| Billing records, legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. AI & Automated Processing
Trackr is an AI-powered product. To deliver its features, content you provide — including chat messages, food photos, form-check videos, lab reports, and relevant health context — is sent to and processed by third-party large language model (LLM) and AI providers acting as our sub-processors (currently OpenAI, OpenRouter, and Google Gemini; see Section 6).
- These providers process your content only to generate the response or analysis you requested, under API terms that prohibit using your data to train their models.
- AI outputs (meal plans, calorie estimates, workout programs, interpretations of health data) are automated estimates for informational purposes, may contain errors, and are not medical advice. Always consult a qualified professional for medical decisions.
- We use observability tooling (Langfuse) to monitor AI quality and cost; where prompts or outputs are logged for this purpose, access is restricted to operational needs.
- We do not make decisions producing legal or similarly significant effects about you solely by automated means without a lawful basis and appropriate safeguards.
6. How We Share Data & Sub-Processors
We do not sell your personal information. We share it only with the service providers ("sub-processors") that operate the Service on our behalf, each bound by contractual confidentiality and data-protection obligations:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage (PostgreSQL on AWS) | Account, profile, logs, health data |
| OpenAI | Embeddings, AI memory, language models | Chat, food/text content, embeddings |
| OpenRouter | Routing for chat-completion language models | Chat & planning prompt content |
| Google (Gemini) | Vision, food identification, form-check, lab parsing | Images, lab reports, related context |
| PostHog | Product analytics & session diagnostics | Usage events, device, masked session data |
| Langfuse | AI observability (quality, token cost) | Prompt/response metadata |
| Railway | Backend application hosting | Data in transit during processing |
| Resend | Transactional email delivery | Email address, message content |
| RevenueCat | Subscription management | Purchase/subscription status |
| Apple / Google | App distribution, in-app purchases, health platforms | Purchase data; health data you authorize |
We may also disclose information when required by law, to enforce our Terms, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, financing, or transfer of assets (including a future transfer of the app to an affiliated corporate account), subject to this policy. We keep an up-to-date sub-processor list and will update this section as our providers change.
7. International Data Transfers
We are based in India and our sub-processors operate in India, the United States, the European Union, and other countries. Your personal information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws.
Where we transfer personal data out of the EEA, UK, or other regions that restrict transfers, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum), or transfers to countries recognized as providing adequate protection. You may request a copy of the relevant safeguard by contacting us.
8. Cookies, Analytics & Session Recording
Our website uses only essential cookies necessary for it to function. We do not use third-party advertising cookies.
Within the app, we use PostHog for product analytics and, in limited cases, session diagnostics to understand how features are used and to fix problems. Where session recording is enabled, text inputs and images are masked so that the content of what you type or capture is not recorded. We use this data to improve the Service, not to identify you for marketing. You can object to analytics processing by contacting us, and we honor "Do Not Track" / Global Privacy Control signals where required by law.
9. Data Storage & Security
Your data is stored on secure, encrypted servers managed by Supabase (hosted on AWS infrastructure). We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security policies in the database
- JWT-based authentication with secure token handling
- Regular security reviews and dependency updates
- Access controls limiting employee data access to operational needs
While we strive to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
10. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g. tax and accounting records) or for the establishment, exercise, or defense of legal claims.
Chat history and AI memory associated with Ember conversations can be deleted at any time through app settings.
11. Account & Data Deletion
You are always in control of your data. You can:
- Delete your account in-app — Profile / Settings → Account → Delete Account. This permanently removes your account and associated personal data (subject to the legal-retention exceptions in Section 10).
- Request deletion by email — write to privacy@healthtrackr.me and we will process your request within 30 days.
Full step-by-step instructions are available at healthtrackr.me/delete-account.
12. Children & Minors
The Service is not directed to, and we do not knowingly create direct accounts for, children under the age required in your jurisdiction (generally 13; 18 where local law requires, including under India's DPDP Act). We do not knowingly collect personal information directly from children below the applicable age without verifiable parental consent.
Where the Service supports family use, profiles for children are created and managed by a parent or legal guardian through their own account, and that data is governed by the parent's account and consent. A parent or guardian may review, edit, or delete a child's profile at any time, or contact privacy@healthtrackr.me. If you believe we have inadvertently collected information from a child without proper consent, contact us and we will promptly delete it.
13. Your Privacy Rights by Region
Everyone
Subject to applicable law, you may request to access, correct, delete, export (port), or restrict processing of your personal data, and withdraw consent. To exercise any right, contact privacy@healthtrackr.me. We respond within 30 days (extendable where the law permits) and will not discriminate against you for exercising your rights.
European Economic Area & United Kingdom (GDPR)
You have the rights of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection (including to processing based on legitimate interests), and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority. Our EU/UK-facing requests are handled by our privacy contact below; where required, we will appoint an Article 27 representative.
India (Digital Personal Data Protection Act, 2023)
As a Data Principal, you may access and correct your data, request erasure, nominate another person to exercise rights in case of incapacity, and raise grievances with our Grievance Officer (Section 16). You may escalate unresolved grievances to the Data Protection Board of India.
California (CCPA / CPRA)
You have the right to know what personal and sensitive personal information we collect and how it is used and disclosed, to delete it, to correct it, and to opt out of "sale" or "sharing." We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information beyond the purposes permitted by law. You may exercise these rights, including via an authorized agent, at privacy@healthtrackr.me.
Other U.S. States
Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, and others) have similar rights to access, correct, delete, and opt out of targeted advertising and sale; contact us to exercise them.
14. Data Breach Notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay and in accordance with applicable law (including the GDPR 72-hour timeline and India's DPDP breach-notification requirements).
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. For material changes, we will provide more prominent notice (such as in-app notice or email) and, where required, seek your renewed consent. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact, DPO & Grievance Officer
For any question, request, or complaint about this policy or your data, contact us:
- Legal Entity: Thus And Also Technologies Private Limited
- Brand / DBA: Trackr (operated as Ember Labs Studio)
- Country of Incorporation: India
- CIN: U74999DL2017PTC310852
- GSTIN: 07AAGCT1417P1Z1
- Registered Office: 19/13, West Patel Nagar, Central Delhi, Delhi — 110008, India
- Grievance Officer / Privacy Contact: Himanshu Garg — privacy@healthtrackr.me
- Support: support@healthtrackr.me
- Website: healthtrackr.me
We aim to acknowledge grievances within 72 hours and resolve them within the timelines required by applicable law.