Privacy Policy
Last updated: 2026-03-15
This Privacy Policy explains how IronQuest ("we", "us", "our") collects, uses, stores, and shares information when you use the IronQuest mobile application and related services.
Contact for privacy requests: privacy@ironquest.at
1. Information We Collect
Data you provide
- Profile settings (display name, online name, body metrics)
- Workout plans, sessions, and set logs
- Nutrition and body tracking entries (protein, creatine, water, calories, weight)
- Social and group actions (group membership, challenges, leaderboard participation)
Data collected automatically
- Device and app identifiers used for registration and data synchronisation
- Push notification token (if notifications are enabled)
- Usage analytics events (via TelemetryDeck, privacy-focused and anonymised)
- Crash diagnostics (only when you approve sending a crash report, via Sentry)
Health platform data (optional)
If you grant Apple HealthKit permissions, IronQuest may read workout enrichment data (heart rate, active energy) to enhance your session records. This data stays on your device unless you choose to sync it.
2. How We Use Your Data
- Provide core fitness tracking features and save your progress
- Synchronise your data with our backend when you are part of a gym group
- Enable social features such as groups, challenges, and leaderboards
- Deliver push notifications you opt into
- Improve reliability, performance, and product quality
3. Data Sharing
We do not sell your personal data. Within groups you join, your workout data is shared according to the share level you choose (participation, feed, or full). You control this per group.
We may share limited data with service providers who help operate IronQuest:
- Infrastructure and cloud hosting providers
- TelemetryDeck (privacy-focused, anonymised analytics; opt-out available in-app)
- Sentry (crash reporting, only with your explicit approval)
- Push notification delivery services
4. Storage and Retention
- Core data is stored locally on your device in an encrypted SQLite database
- Synced and social data is stored on our servers (PostgreSQL, encrypted at rest)
- Data is retained as long as needed to provide the service and meet legal obligations
- You can request deletion at any time (see below)
5. Your Rights and Controls
Depending on your region (including under the GDPR for EU/EEA residents), you may have the right to access, correct, export, or delete your personal data.
- Analytics opt-out:Toggle analytics off in the app's Privacy screen to stop all TelemetryDeck tracking
- Data deletion:Use the "Delete my data" option in the Privacy screen, or email privacy@ironquest.at
- Data export: Available via the Privacy screen in the app
- Group data sharing: Adjust per-group share level or leave groups at any time
6. Security
We use reasonable technical and organisational safeguards to protect your data, including encrypted storage, secure API communication (TLS), and access controls. No storage or transmission method is completely secure, but we strive to protect your information appropriately.
7. Children
IronQuest is not intended for children under 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect data from children.
8. Policy Updates
We may update this policy from time to time. Any update will revise the "Last updated" date at the top. We encourage you to review this page periodically.
9. Contact
For privacy requests, questions, or concerns, contact us at: privacy@ironquest.at