Privacy Policy

Version 1.0 · Last Updated: 2026-02-08

1. Introduction

Welcome to SaunaTracker Pro. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our iOS and watchOS application.

SaunaTracker Pro is a health and wellness application that helps you track heat and cold exposure therapy sessions (such as sauna, steam room, and cold plunge sessions) and monitors health metrics to evaluate session effectiveness.

Your privacy is important to us. We are committed to protecting your personal information and being transparent about our data practices. This policy is designed to help you understand:

2. Who We Are (Data Controller)

Data Controller: JDP Software Pty Ltd, Australia

Privacy Officer: Privacy Officer, JDP Software Pty Ltd
Email: privacy@saunatracker.pro

For users in the European Economic Area (EEA), if you have concerns about our data practices, you have the right to lodge a complaint with your local data protection authority.

For users in Australia, you may contact the Office of the Australian Information Commissioner (OAIC) if you have concerns about how we handle your personal information.

3. Information We Collect

3.1 Health Data from Apple HealthKit

With your explicit permission, SaunaTracker Pro reads and writes the following health data types through Apple HealthKit:

Data TypeReadWritePurposeLawful Basis
Heart Rate and Resting Heart RateYesYes, heart-rate samples may be saved during sessionsMonitor cardiovascular response during sessionsExplicit consent (GDPR Art. 9(2)(a))
Heart Rate Variability (HRV)YesAssess recovery and adaptationExplicit consent (GDPR Art. 9(2)(a))
Blood Oxygen Saturation (SpO2)YesMonitor oxygen levels during sessionsExplicit consent (GDPR Art. 9(2)(a))
Sleep Analysis and Sleep ScoreYesCorrelate sleep quality with session timingExplicit consent (GDPR Art. 9(2)(a))
WorkoutsYesYesRecord and retrieve therapy sessionsExplicit consent + Contract performance
Workout RoutesYes, on Apple Watch when route capture is enabledAttach route information to Apple Health workoutsExplicit consent + Contract performance
Active and Basal EnergyYesYes, active energy may be saved during sessionsMeasure session activity and energy expenditureExplicit consent (GDPR Art. 9(2)(a))
Step CountYesImprove sleep onset and recovery estimatesExplicit consent (GDPR Art. 9(2)(a))
Blood PressureYesEnriched health analysis (if available)Explicit consent (GDPR Art. 9(2)(a))
Blood GlucoseYesEnriched health analysis (if available)Explicit consent (GDPR Art. 9(2)(a))
Body, Wrist, and Sleeping Wrist TemperatureYesEnriched temperature analysis (if available)Explicit consent (GDPR Art. 9(2)(a))
Body MassYes, on Apple WatchSupport workout energy calculationsExplicit consent (GDPR Art. 9(2)(a))
State of Mind and Wellbeing ScoreYesYes, State of Mind may be saved from Apple Watch guided relaxation flowsMood and wellbeing correlation analysis (if available)Explicit consent (GDPR Art. 9(2)(a))

Important: HealthKit data is stored by Apple on your device and in your personal iCloud account. SaunaTracker Pro accesses specific HealthKit data types only after you grant permission and only for the purposes described in this policy. If you enable Premium AI Coaching, the session metrics described below are transmitted to our backend and AI processor to generate coaching insights.

3.2 Account Information

When you sign in with Apple (Sign in with Apple / SIWA):

3.3 App Usage Data

3.4 Technical Data

3.5 Analytics and Tracking

We may use Apple's built-in App Analytics to understand general app usage patterns (e.g., crash reports, aggregate feature usage). This data is anonymised by Apple and cannot identify individual users. We do not use any third-party analytics services.

3.6 Data We Do NOT Collect

4. How We Use Your Information

4.1 Primary Purposes

PurposeLawful Basis
Provide core App functionalityContract performance
Record and display your workout sessionsContract performance
Access HealthKit data for session trackingExplicit consent as gateway
Calculate HCEI scores from health metricsContract performance
Sync data across your devices via iCloudContract performance
Authenticate your identityLegitimate interest (security)
Provide AI-powered insights (Premium subscribers)Explicit consent

4.2 AI Features (Premium Subscription Only)

If you are a Premium subscriber and opt in to AI features:

AI Processing Limits:

4.3 What We Do NOT Do With Your Data

5. How We Share Your Information

5.1 Apple Services

ServiceData SharedPurposeRole
iCloud (CloudKit)App dataCross-device syncData Processor (app data) / Independent Controller (iCloud account)
HealthKitHealth metricsRead/write health dataPlatform Provider
Sign in with AppleAuthentication tokensIdentity verificationIdentity Provider
App StorePurchase statusSubscription verificationPlatform Provider

Note on Apple's Role: Apple acts as a data processor for app data stored in your iCloud private database, and independently as a controller for your iCloud account and platform services. Your iCloud data is protected by Apple's privacy practices and Data Processing Addendum.

5.2 Our Backend Services and AI Processor (Premium AI Features Only)

If you opt in to AI features, session data is transmitted to our backend infrastructure and AI processor:

5.3 Third Parties We Do NOT Share With

6. Data Storage and Security

Data TypeStorage Location
HealthKit dataYour device + your iCloud; AI Coaching session metrics are separately processed as described above if you opt in
App data (workouts, goals)Your device + your iCloud
Account credentialsApple's systems
AI processing dataAWS ap-southeast-2 and OpenAI API processing (transient in our backend)

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, secure authentication via Sign in with Apple, and strict access controls on backend systems.

6.1 Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law (including GDPR 72-hour notification requirements and the Australian Notifiable Data Breaches scheme).

7. Data Retention

Data TypeRetention Period
Workout recordsUntil you delete them
Account informationUntil you delete your account
Consent records7 years after account deletion
Research export filesDeleted automatically after 30 days; deleted or redacted sooner when you delete your account
AI processing dataNot retained by our backend after transient processing; OpenAI API abuse-monitoring logs may be retained for a limited period under OpenAI's API data controls

You can delete your data at any time: individual workouts within the App, all App data by deleting your account in Profile settings, or HealthKit data via iOS Settings.

8. Your Rights

Regardless of your location, you have the right to:

Additional rights apply under GDPR (EEA), the Australian Privacy Act, and CCPA (California). Contact us at privacy@saunatracker.pro to exercise your rights. We will respond within the timeframes required by applicable law (generally 30 days for GDPR and Australian Privacy Act requests, 45 days for CCPA requests).

9. Children's Privacy

You must be at least 17 years old to use SaunaTracker Pro. We do not knowingly collect personal information from anyone under 17. If you believe we have collected information from a child under the applicable age threshold, please contact us immediately at privacy@saunatracker.pro.

10. International Data Transfers

Your App data synced via iCloud is transferred according to Apple's practices, supported by Apple's Data Processing Addendum and Standard Contractual Clauses (SCCs) for transfers outside the EEA.

If you opt in to AI features, data is processed by our AWS infrastructure in ap-southeast-2 (Sydney, Australia) and by OpenAI as our AI processor. For EEA users, Standard Contractual Clauses are in place. A copy of the relevant safeguards is available upon request at privacy@saunatracker.pro.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you through the App. For changes that materially affect how we process your personal data, we will require your affirmative re-acknowledgment.

12. Contact Us

If you have questions about this Privacy Policy or our data practices:

Privacy Officer: JDP Software Pty Ltd
Email: privacy@saunatracker.pro

13. HealthKit Compliance

Our use of HealthKit data complies with Apple's HealthKit guidelines: we only use HealthKit data for health and fitness purposes, we do not use it for advertising, we do not share it with third parties except as described in this policy, and we obtain explicit user consent before accessing HealthKit.

View Previous Versions →