ironbit-privacy

Ironbit — Privacy Policy

Last updated: 22 September 2026 Publisher: Quan Dao Contact: daominhquan1106@gmail.com

Ironbit is an offline-first workout tracker. Training works without an account or network. This policy explains what data the app and its service providers handle, why it is handled, and the choices available to you.

The short version

Data that stays on your device

The following data is not included in Cloud Save:

When Cloud Save is not connected, workouts and player data also remain local. Local data stays on the device until you erase it, clear the app’s data, or uninstall the app.

Data handled when you use the app

1. Usage analytics — off until you enable it

Ironbit uses Google Analytics for Firebase to understand whether features work and where the app needs improvement, but collection begins only after you turn on Settings → Data & Privacy → Usage Analytics. Event categories can include app launches and screens; onboarding and workout-lifecycle actions such as starting, saving, or discarding; rest and notification interactions; feature, character, cosmetic, and Gem Store interactions; character class; and reduced-motion setting. Gem Store events record only which pack was viewed or started, such as “800 gems”. Ironbit does not put your name, email, body metrics, exercise names, repetitions, weights, workout contents, prices, transaction IDs, receipts, purchase outcomes, or Cloud Save account ID into Analytics.

When Usage Analytics is enabled, Google Analytics automatically assigns a pseudonymous app-instance identifier to an installation and can process app and device information, operating-system version, app version, product interactions, and general location derived from masked IP addresses. Ironbit does not connect this identifier to Cloud Save identity or workout contents.

Turn the same switch off at any time to withdraw consent. Ironbit immediately closes its own event gate, disables future Analytics collection, denies Analytics storage consent, and asks Firebase to reset device-side Analytics identity and queued data. Google’s resetAnalyticsData operation cannot retract data already received by Google.

Ironbit does not use Google Ads linking, BigQuery export, Analytics User-ID, advertising personalization, Advertising ID/IDFV collection, or cross-app tracking. It does not request App Tracking Transparency permission because it does not link Ironbit data with data from other companies’ apps or websites for tracking.

See Google’s Privacy Policy, How Google uses data, and Google Analytics data collection.

2. Crash reports — off by default, opt-in

If you opt in, Ironbit uses Sentry to receive crash diagnostics such as an error, stack trace, app version, device model, and operating-system version. This helps identify and fix failures.

Sentry starts only after Settings → Data & Privacy → Crash Reports is enabled and the app is launched again. Ironbit configures Sentry not to send default personally identifying information and disables performance tracing. It does not deliberately attach names, email addresses, body metrics, workout contents, or the Cloud Save account ID to crash reports.

See Sentry’s Privacy Policy.

3. Optional Apple or Google account and Cloud Save

Cloud Save is optional. If you choose it, Apple or Google authenticates you and Supabase processes:

Cloud Save stores the current successful recovery snapshot and one previous generation. It is not live synchronization: one phone is the active cloud-backup writer at a time, and Ironbit asks before replacing a different local or cloud dataset.

Supabase processes the account and recovery data in the configured general Americas region. Operator database backups are encrypted before private Cloudflare R2 storage and expire after seven days. See Apple’s Privacy Policy, Google’s Privacy Policy, Supabase’s Privacy Policy, and Cloudflare’s Privacy Policy.

4. Gem purchases (iPhone)

Gem packs are optional consumable in-app purchases sold through Apple on iPhone. Gems buy cosmetic avatar frames only. Apple processes the payment under its own terms and privacy policy; Ironbit never receives your card number, billing address, or Apple ID password.

Buying gems requires Cloud Save, so purchased gems can be recovered. When you buy a pack, the app sends Apple’s signed transaction record to Ironbit’s verification service on Supabase. The service checks Apple’s signature and stores a purchase receipt with your Cloud Save account: the Apple transaction ID, which pack was bought, the gem amount, the purchase time, and whether it was a test (Sandbox) or real purchase. The receipt exists so each purchase is credited exactly once. The gems are then added to your gem ledger, which is part of your Cloud Save backup.

Apple manages refunds and your purchase history. See Apple’s Privacy Policy.

5. Support messages

If you email support, the publisher receives your email address and the information you choose to include. Support messages are used only to answer the request, investigate the issue, and keep necessary support records. Do not send passwords, provider tokens, or other sensitive credentials.

How data is used and shared

Data is used to operate Ironbit, provide an optional recovery backup, understand product usage, protect data integrity, answer support requests, and fix crashes. It is shared only with the processors named above for those purposes.

The publisher requires every processor that receives Ironbit user data—including Apple, Google, Supabase, Cloudflare, Firebase, and Sentry—to protect that data to the same or an equivalent standard as this policy and Apple’s applicable privacy requirements, and to process it only for the stated purposes.

Ironbit does not sell personal data, show ads, build advertising profiles, or combine Cloud Save identity with Firebase or Sentry telemetry. Ironbit does not track you across apps or websites owned by other companies.

Your choices and deletion controls

Deleting a Cloud Save account removes the account, player backup, and purchase receipts from the live service. Encrypted operator backups age out under the seven-day retention policy. Deleting the app alone removes local data but does not delete an optional cloud account; use Delete Cloud Account first if you want both removed.

Retention

Children’s privacy

Ironbit is not directed to children under 13 or the minimum digital-consent age in their country. The publisher does not knowingly collect personal data from children. If you believe a child has provided personal data, contact the publisher so it can be investigated and deleted.

Changes to this policy

Material changes will be posted on this page with an updated date.

Contact and support

Questions, support requests, and privacy requests: Quan Dao — daominhquan1106@gmail.com

Support information: Ironbit Support