Privacy Policy

Last updated: April 22, 2026

Latitude Zero Tech ("we", "our", or "us") built MoveTrack Fitness ("the App") as a commercial application. This Privacy Policy explains how we collect, use, and protect your information when you use the App. The App includes both local-only features and cloud-based social features that require an account.

Account & Authentication

To access social and community features, you must create an account. Authentication is managed by Clerk, a third-party identity service. During signup and login, the following data is collected:

  • Email address
  • Display name
  • Authentication credentials (managed by Clerk, including OAuth providers such as Google and Apple)

Upon account creation, we store the following profile data in our cloud database (Convex): Clerk user ID, username, display name, bio, avatar URL, locale, and timezone. Your Clerk account credentials are stored and managed by Clerk — we do not have access to your passwords.

Information We Collect

Data Stored Locally on Your Device

The following fitness data is stored locally on your device only. We do not have access to it unless you choose to share it via social features:

  • Body measurements: weight, height, body fat percentage, lean mass, skinfold measurements, and body circumferences
  • Workout results: times, repetitions, rounds, loads used, rate of perceived exertion (RPE), and personal records
  • Strength records: one-rep max (1RM) entries for movements
  • Training programs: custom workouts, programs, and training blocks
  • Notes: any text you enter in workout or assessment notes
  • Preferences: unit system (kg/lbs), barbell weight, available plates, sound and haptic settings

Data Stored in the Cloud

When you use social and community features, the following data is stored in our cloud database (Convex):

  • User profile: username, display name, bio, avatar photo, level, XP, and streak
  • Shared workout results: workout data you choose to publish to the social feed
  • Photos: workout photos and check-in images you upload
  • Comments and replies on shared workouts
  • Reactions (fire, strong, fast, champion) on shared content
  • Follow relationships (followers and following)
  • Challenge participation: titles, scores, check-ins, and photos
  • Health sync data: calories, steps, average heart rate, and active minutes (when you enable health integration)
  • Push notification tokens (Expo Push Tokens)
  • Moderation data: reports and block records

Data Collected Automatically

  • Subscription status: We use RevenueCat, a third-party service, to manage in-app purchases and subscriptions. RevenueCat receives your purchase history and subscription status from the Apple App Store or Google Play Store. RevenueCat does not receive any of your fitness data. You can review RevenueCat's privacy policy at revenuecat.com/privacy.
  • Usage analytics: We collect anonymous usage events (e.g., "timer started", "workout completed") to improve the App. These events do not contain personal information and are not linked to your identity.
  • Device identifier: An anonymous identifier is generated and stored locally on your device for the purpose of controlling the use of artificial intelligence features. This identifier is not linked to your personal identity and is used exclusively to manage usage quotas.
  • Error reports: We use Sentry to automatically collect information about app crashes and errors. This data includes technical information such as device type, operating system version, app version, and stack traces. It does not include personal data or workout data.

Social Features & User-Generated Content

The App includes optional social features that allow you to share your fitness journey with others. When you use these features:

  • Your profile (username, display name, bio, avatar, level, XP, streak) is visible to other users who follow you or view your public profile.
  • Workout results you share are published to your followers' social feed.
  • Photos you upload with workouts or check-ins are stored in our cloud storage (Convex Storage) and visible to your followers.
  • Comments, replies, and reactions you post are visible to other users.
  • Your follow relationships (who you follow and who follows you) are stored in our database.

Photos & Media

When you upload photos (workout photos, check-in images, or profile avatars):

  • Photos are stored in Convex Storage with a cache duration of up to 1 year.
  • Workout and check-in photos are visible to your followers in the social feed.
  • Profile avatars are visible to anyone who can see your profile.

Challenges

When you participate in or create challenges:

  • Challenge data includes title, description, scores, check-ins, and photos.
  • Challenges have shareable invite codes that create publicly accessible URLs (e.g., movetrack.app/c/{code}).
  • Challenge participants and their progress are visible to all challenge members.

Push Notifications

If you enable push notifications:

  • Your Expo Push Token is stored in our cloud database (Convex) and linked to your account.
  • Notifications are delivered via the Expo Push API.
  • Notification types include: reactions to your content, comments, new followers, challenge invites, and achievement milestones.
  • You can disable push notifications at any time through your device settings or the App settings.

Health Data Sync

The App can optionally integrate with Apple Health (iOS) and Google Health Connect (Android):

  • When enabled, the App reads health data including calories burned, steps, average heart rate, and active minutes.
  • This data is synced to our cloud database (Convex) and linked to your user account.
  • Health data is used to enrich your workout results and social feed posts.
  • You can revoke health data access at any time through your device's health settings.
  • On iOS, the Apple Watch companion app collects heart rate data during workouts and transmits it to the iPhone app via Watch Connectivity. This data may be synced to our servers when health sync is enabled.

Deep Links & Public URLs

The App uses publicly accessible URLs for certain features:

  • User profiles are accessible at movetrack.app/u/{username}. Usernames are public identifiers.
  • Challenge pages are accessible at movetrack.app/c/{code}.
  • These URLs may display publicly visible information such as username, display name, avatar, and challenge details.

How We Use Your Information

  • Subscription management: To verify your subscription status and restore purchases across devices via RevenueCat.
  • App improvement: Anonymous usage analytics help us understand which features are most used and improve the App experience.
  • Controlling usage quotas for artificial intelligence features.
  • Identifying and fixing app errors and crashes via Sentry.
  • Social features: To display your profile, shared workouts, and social interactions to other users.
  • Notifications: To send you relevant push notifications about social interactions and achievements.
  • Health integration: To enrich your workout data with health metrics from Apple Health or Google Health Connect.

Legal Basis for Processing

We process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):

  • Consent: Social features, health data sync, push notifications, and AI features. You can withdraw consent at any time through the App settings or your device settings.
  • Contract: Subscription management, account creation, and providing the core services you have requested.
  • Legitimate Interest: Analytics, error reporting, security measures, and content moderation to maintain a safe and functional service.

International Data Transfers

Your data is stored on servers located in the United States, operated by our service providers (Convex and Clerk). If you are accessing the App from outside the United States, please be aware that your data may be transferred to, stored, and processed in the United States. We use appropriate safeguards, including Standard Contractual Clauses where applicable, to ensure your data is protected in accordance with this Privacy Policy.

Artificial Intelligence Features

The App offers optional artificial intelligence features, such as smart workout import and training program generation. When using these features:

  • The workout text or image you provide is sent to our backend (Convex), which processes it via the Claude API (Anthropic) and/or the Gemini API (Google).
  • Rest day recovery tips are generated via Claude and cached by date and language in our backend (Convex).
  • Your anonymous device identifier and subscription type are sent exclusively for usage quota control.
  • We do not store the workout content you send. Data is processed in real time and discarded after the response is returned.
  • The daily CrossFit WOD from crossfit.com is automatically parsed via Gemini every 6 hours using publicly available data. No user data is involved.
  • Using these features requires an internet connection.

Data Storage and Security

Fitness data that you do not share (workouts, body assessments, strength records, programs) is stored exclusively on your device in a local database.

Social data (profiles, shared workouts, photos, comments, reactions, follows, challenges, health sync data, notifications, and moderation records) is stored in our cloud database powered by Convex. Convex servers are located in the United States.

AI usage control information (anonymous identifier and monthly usage count) is stored in our backend (Convex) and automatically removed at the end of each usage period.

Photos uploaded to Convex Storage are cached for up to 1 year and are stored until you delete them or delete your account.

We use industry-standard security measures to protect your data, including encrypted connections (HTTPS/TLS) for all data in transit.

Data Export

You may export your workout results to a CSV file at any time using the export feature in the App. This file is generated locally and shared using your device's native sharing options.

Moderation — Blocks & Reports

To maintain a safe community, the App includes moderation features:

  • Reports: When you report content or a user, we store the reporter ID, content type, reason, and any additional details you provide.
  • Blocks: When you block a user, the blocker/blocked pair is stored in our database.
  • Moderation data (reports and blocks) is retained indefinitely to ensure community safety and prevent abuse.

Third-Party Services

The App uses the following third-party services:

Clerk

Authentication and identity management. Stores your login credentials and account information. Privacy Policy

Convex

Cloud backend — stores user profiles, social data, photos, challenges, and notifications. Privacy Policy

RevenueCat

Subscription and purchase management. Privacy Policy

Apple App Store / Google Play

Payment processing. Subject to Apple's Privacy Policy and Google's Privacy Policy.

Expo Push API

Push notification delivery service. Privacy Policy

Apple Health / Google Health Connect

Health data reading (calories, steps, heart rate, active minutes). Data is read with your permission and synced to our servers.

Sentry

App error and crash monitoring. Privacy Policy

Cloudflare

Website CDN and content delivery. Privacy Policy

Anthropic (Claude API)

Artificial intelligence processing for workout import, program generation, and recovery tips. Privacy Policy

Google AI (Gemini API)

Artificial intelligence processing for workout parsing. Terms of Service

We do not use any advertising networks or sell your data to third parties.

Children's Privacy

The App is not directed to children under the age of 13. We do not knowingly collect information from children under 13.

Data Retention

Cloud data is retained while your account is active and deleted upon account deletion request. Moderation records (reports and blocks) may be retained indefinitely for community safety. AI usage quotas are automatically removed at the end of each billing period. Cached photos are retained for up to 1 year or until the associated content is deleted.

Your Rights

You have control over your data. You can:

  • Delete any individual workout result, body assessment, or strength record within the App
  • Export your workout data to CSV
  • Remove all local data by deleting the App from your device
  • Delete your account through the App settings, which triggers a cascading deletion of all your cloud data

European Data Subject Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following additional rights under GDPR:

  • Right of access — request a copy of your personal data
  • Right to rectification — request correction of inaccurate personal data
  • Right to data portability — receive your data in a structured, commonly used format
  • Right to restriction of processing — request that we limit processing of your data
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw consent at any time without affecting prior processing

To exercise any of these rights, please contact us at support@movetrack.app. We will respond to your request within 30 days.

California Privacy Rights (CCPA)

We do not sell, rent, or share personal information for cross-context behavioral advertising. California residents have the right to request access to, deletion of, and information about the categories of personal information collected. To exercise these rights, please contact us at support@movetrack.app.

Account Deletion

When you request account deletion through the App:

  • All your cloud data is permanently deleted, including: profile, follow relationships, comments, reactions, notifications, blocks, reports, challenge check-ins, badges, personal records, workout results, and subscription records.
  • Your Clerk authentication account is deleted separately as part of the process.
  • Uploaded photos may persist in storage briefly until cleanup processes run.
  • The deletion process is batched and may take a few hours to complete fully.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Continued use of the App after changes constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy, please contact us at support@movetrack.app.

Latitude Zero Tech
MoveTrack Fitness — iOS & Android