trackd co

Privacy Policy

Version 1.3 · Effective 20 June 2026

Supersedes v1.2.

This Privacy Policy explains how Trackd Co Pty Ltd (ACN 698 405 462, ABN 35 698 405 462), an Australian private company based in the Australian Capital Territory, Australia ("Trackd", "we", "us", "our"), collects, uses, stores, and shares your personal information when you use the Trackd application and the website at trackdco.app (the "Service"). It forms part of, and should be read with, our Terms of Service and Medical Disclaimer.

Trackd is available to users worldwide. Depending on where you live, additional rights and protections may apply to you — see Sections 13 (EU/UK), 14 (United States), and 15 (Consumer Health Data).

1. The sensitivity of your data, and your consent

Trackd handles health-related information: the substances you track, your doses, the bloodwork you upload, your body metrics, and your journal notes. In many places this counts as "sensitive", "special-category", or "consumer health" personal information that gets extra legal protection. We treat all of your protocol, bloodwork, body-metric, journal, and uploaded-image data as sensitive.

The Service cannot work without processing this information, so when you create your account we ask for your explicit, specific consent through a separate consent step (distinct from accepting our Terms of Service). You give this consent by ticking a dedicated box that reads, in substance: "I explicitly consent to Trackd collecting and processing my health-related information (the compounds I track, doses, bloodwork, body metrics, photos and journal entries) to provide the Service to me." We record the version of this policy you consented to, and the date and time you did so. You can withdraw this consent at any time, as described in Section 9.

2. Information we collect

Information you give us

  • Account information: your email address and password, handled through Supabase Auth. We do not store your password in readable form.
  • Date of birth and age: we collect your date of birth and use it to confirm you are at least 18 (this is checked on our server). We record your 18+ confirmation.
  • Profile and settings: preferences and configuration you set in the app, including an optional profile photo (avatar).
  • Protocol data: cycles, the compounds you add, inventory items, doses you log, injection sites, and schedules.
  • Journal and subjective markers: daily journal entries and the markers you record, including side-effect markers.
  • Body metrics: measurements you choose to record, such as bodyweight.
  • Bloodwork: the lab files you upload and any biomarker values associated with them.
  • Progress photos: any progress photos you choose to upload, which are stored in a private, access-controlled bucket.

Information collected automatically

  • Authentication and session data: strictly-necessary cookies and local storage used to keep you signed in.
  • Basic technical logs: limited server and security logs from our hosting provider.
  • Device timezone: your device's timezone (for example, "Europe/London"), recorded when you use notifications and used only to schedule reminders at the right local time. Turning notifications off stops its use.

We do not use product analytics, error-monitoring, or advertising trackers, and we do not set analytics or advertising cookies — we use only strictly-necessary cookies and local storage. If we add any analytics in future, we will update this policy and seek consent where the law requires it.

3. How we use your information

We use your information to:

  • provide and operate the Service, including computing your inventory figures and where your biomarkers sit relative to reference ranges (these are derived live and shown only to you);
  • authenticate you and keep your account secure;
  • respond to your support requests; and
  • meet our legal obligations.

We do not use your health data for advertising, and we do not sell or "share" (as privacy laws such as the CCPA define those terms) your personal information.

We currently send only essential account and security emails, through our authentication provider. We do not yet operate a separate transactional or marketing email service. If we introduce paid plans, we will also send the billing emails needed to operate your subscription. If we introduce marketing emails in future, we will only send them with your consent and will include a working unsubscribe link, and we will update this policy first.

4. Legal bases for processing (where the GDPR applies)

Where laws such as the UK or EU GDPR apply, we rely on: performance of our contract with you (to run the Service); your explicit consent under Article 9 (for your sensitive health data); our legitimate interests (keeping the Service secure and working); and compliance with legal obligations. You can withdraw consent at any time, as described in Section 9.

5. How and where your data is stored

Your data is held with our infrastructure and service providers. Our database, authentication, and file storage are provided by Supabase, in its Sydney, Australia region (ap-southeast-2). Our application hosting and content delivery are provided by Vercel (United States, with a global content-delivery network). These are currently our only two service providers that handle your data.

Uploaded files (bloodwork and progress photos) are kept in private, access-controlled storage buckets and are only ever served to you through short-lived signed URLs. Database access is enforced row-by-row so that one user cannot read another user's data.

All data is encrypted at rest (AES-256) and in transit (TLS), including the database, the storage buckets, and our database backups. We keep encrypted daily database backups so that we can recover after a failure; these are retained on a rolling 7-day cycle and then overwritten. Uploaded files held in storage are not included in these database backups.

Our sub-processors

We use the following providers to operate the Service. Each acts on our instructions and is bound by a data-processing agreement. They may only use your information to provide their service to us, and we do not sell your personal information to any of them.

  • Supabase: database, authentication, and file storage (Sydney, Australia).
  • Vercel: application hosting and content delivery (United States, with a global content-delivery network).

These are our only active sub-processors. When we introduce paid plans, payments will be handled by a third-party payment processor (such as Stripe). If we later add an email or analytics provider, we will update this list and this policy before that provider goes live. We treat the addition of a new sub-processor that handles your sensitive data as a material change (see Section 16).

6. Sharing and disclosure

We do not sell or rent your personal information. We share it only: with the sub-processors listed above, so they can help us run the Service; where we are required to by law or valid legal process; or as part of a business transfer (such as a merger or sale). In a business transfer involving your sensitive health data, we will require the recipient to be bound by privacy protections at least as protective as this policy, and we will take reasonable steps to notify you. If we receive a request for your data from law enforcement or a government agency, we will check that the request is legally valid, disclose only what we are legally compelled to disclose, and, unless the law prohibits us from doing so, take reasonable steps to tell you about the request.

7. Data retention and deletion

We keep your data while your account is active.

Within the app, individual cycles are archived rather than permanently deleted when you finish them, so your history is preserved and longitudinal tracking keeps working. Archived data is retained (and remains visible to you) until you delete your account; it is not data you have erased.

Full account deletion. You can request full deletion of your account at any time using the in-app "Delete my account" control, which sends your deletion request to us. We erase your account and all associated data — including your uploaded bloodwork files and progress photos — within 30 days of your request, except anything we are legally required to retain for a limited period. (One-tap, immediate self-service deletion is planned for after our beta.) Residual copies of database records may remain in our encrypted database backups for up to 7 days before they are overwritten; uploaded files are deleted from storage directly and are not held in database backups.

8. Security

We take reasonable technical and organisational measures to protect your information, including:

  • encryption of data in transit (HTTPS/TLS) and at rest (AES-256), covering the database, storage, and backups;
  • row-level security on every table, so each user can only reach their own data;
  • private, access-controlled storage buckets for bloodwork and progress photos, served only via short-lived signed URLs; and
  • least-privilege key handling — no secret or service-role key is exposed in the app; only the public, publishable key is used on the front end.

No method of storage or transmission is perfectly secure. Please help protect your account by keeping your password confidential.

If a data breach occurs that is likely to result in serious harm to you, we will notify you and the relevant regulator, including the Office of the Australian Information Commissioner under Australia's Notifiable Data Breaches scheme, as required by law, and we will tell you what happened, what data was involved, and what we are doing about it. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, and affected individuals without undue delay.

9. Your rights

Depending on where you live, you may have rights to access, correct, export (in a portable form), or delete your personal information, to restrict or object to certain processing, and to withdraw consent. You may also have the right to complain to a data-protection regulator.

How to exercise your rights, and how to complain. To exercise any of these rights, or to make a privacy complaint, contact us at legal@trackdco.app. We will acknowledge a complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, in Australia you can complain to the Office of the Australian Information Commissioner (OAIC, oaic.gov.au), and elsewhere to your local data-protection regulator.

We will honour whatever privacy rights the law of your home country gives you: when you make a request, we will assess it under the law that applies to you and respond as that law requires, even if the right is not listed above. We do not discriminate against you for exercising any privacy right. Because the Service cannot operate without processing the protocol and health-related information you enter, withdrawing your consent to that processing means closing your account. We will explain this to you before acting on such a request.

10. International data transfers

The Service is offered worldwide, and one of our two providers (Vercel) is in the United States, so some of your information may be stored or processed outside the country you live in (primarily in Australia and the United States). When that happens, we take the steps required by applicable law to protect it.

  • For disclosures from Australia, we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles (APP 8).
  • Where UK or EU law applies to a transfer outside the UK/EEA, we rely on appropriate safeguards such as the standard contractual clauses recognised under UK and EU law (which our providers offer in their data-processing agreements) or an applicable adequacy decision.

Copies of the relevant safeguards are available on request at legal@trackdco.app.

11. Children

Trackd is for adults only. The Service is not directed to anyone under 18, and we do not knowingly collect personal information from minors. If we learn we have, we will delete it.

12. Cookies and local storage

We use only strictly-necessary cookies and local storage, for example to keep you signed in and to operate the app. We do not use analytics or advertising cookies. If this changes, we will update this section and seek consent where required.

13. EU and UK users (GDPR)

If you are in the European Economic Area or the United Kingdom, the GDPR / UK GDPR gives you the rights set out in Section 9, and in particular: the right of access to your data; the rights to rectification and erasure; the right to restrict or object to processing; the right to data portability; and the right to withdraw consent at any time without affecting processing carried out before withdrawal. Our lawful bases are described in Section 4, and for your health data we rely on your explicit consent under Article 9. You have the right to lodge a complaint with your local supervisory authority. For questions about this policy or our processing, contact us at legal@trackdco.app.

14. United States users (including California)

Trackd is a consumer self-tracking app. We are not a HIPAA-covered entity or business associate, and HIPAA protections do not apply to the information you enter; your information is instead protected by this policy and by the consumer-privacy laws that apply to you.

If you are a resident of California or another US state with applicable consumer-privacy laws, you may have rights to know what personal information we collect and how we use it, to access and delete it, to correct it, to limit the use and disclosure of sensitive personal information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information (including as those terms are defined under the CCPA/CPRA), and we do not use your sensitive health-related information for any purpose other than providing the Service to you. To exercise any state-law right, contact us at legal@trackdco.app; we will verify your request and respond as the law requires.

15. Consumer Health Data (Washington, Nevada, Connecticut, and similar US state laws)

Some US states have specific consumer-health-data laws (such as Washington's My Health My Data Act and Nevada's SB 370). Where those laws apply to you, this section serves as our consumer-health-data notice.

  • What we collect and why. The consumer health data we collect is the protocol, bloodwork, body-metric, journal, and progress-photo information you enter, described in Section 2. We collect it only to provide the Service to you — to record, organise, compute, and display your own data back to you.
  • Sources. This data comes directly from you (and the files you choose to upload).
  • How it is shared. We do not sell your consumer health data, and we do not share it for advertising. We disclose it only to the sub-processors in Section 5 who help us operate the Service, and where required by law (Section 6).
  • Consent. We collect and process your consumer health data on the basis of the explicit consent you give at signup (Section 1). We do not collect or share it beyond what is necessary to provide the Service without separate consent.
  • Your rights. You have the right to confirm whether we are processing your consumer health data, to access it, to withdraw your consent, and to delete it. To delete it, use the in-app "Delete my account" control (Section 7) or contact legal@trackdco.app; on deletion we will also direct our processors to delete it. To exercise any of these rights, contact legal@trackdco.app.

16. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes — including any change that expands how we collect, use, or share your sensitive data, or that adds a new sub-processor handling your data — we will take reasonable steps to notify you in advance, in the app or by email, and we will update the effective date at the top of this document. Where a material change requires it, we will ask for your fresh consent before the change applies to your data, rather than relying on notice alone.

17. Contact

For privacy questions, to exercise your rights, or to make a complaint, contact us at legal@trackdco.app.

← Back to home