Welcome to SaunaTracker Pro. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our iOS and watchOS application.
SaunaTracker Pro is a health and wellness application that helps you track heat and cold exposure therapy sessions (such as sauna, steam room, and cold plunge sessions) and monitors health metrics to evaluate session effectiveness.
Your privacy is important to us. We are committed to protecting your personal information and being transparent about our data practices. This policy is designed to help you understand:
Data Controller: JDP Software Pty Ltd, Australia
Privacy Officer: Privacy Officer, JDP Software Pty Ltd
Email: privacy@saunatracker.pro
For users in the European Economic Area (EEA), if you have concerns about our data practices, you have the right to lodge a complaint with your local data protection authority.
For users in Australia, you may contact the Office of the Australian Information Commissioner (OAIC) if you have concerns about how we handle your personal information.
With your explicit permission, SaunaTracker Pro reads and writes the following health data types through Apple HealthKit:
| Data Type | Read | Write | Purpose | Lawful Basis |
|---|---|---|---|---|
| Heart Rate | Yes | Monitor cardiovascular response during sessions | Explicit consent (GDPR Art. 9(2)(a)) | |
| Heart Rate Variability (HRV) | Yes | Assess recovery and adaptation | Explicit consent (GDPR Art. 9(2)(a)) | |
| Blood Oxygen Saturation (SpO2) | Yes | Monitor oxygen levels during sessions | Explicit consent (GDPR Art. 9(2)(a)) | |
| Sleep Analysis | Yes | Correlate sleep quality with session timing | Explicit consent (GDPR Art. 9(2)(a)) | |
| Workouts | Yes | Yes | Record and retrieve therapy sessions | Explicit consent + Contract performance |
| Blood Pressure | Yes | Enriched health analysis (if available) | Explicit consent (GDPR Art. 9(2)(a)) | |
| Blood Glucose | Yes | Enriched health analysis (if available) | Explicit consent (GDPR Art. 9(2)(a)) | |
| Body Temperature | Yes | Enriched health analysis (if available) | Explicit consent (GDPR Art. 9(2)(a)) | |
| State of Mind | Yes | Mood correlation analysis (if available) | Explicit consent (GDPR Art. 9(2)(a)) |
Important: HealthKit data is stored by Apple on your device and in your personal iCloud account. SaunaTracker Pro accesses specific HealthKit data types only after you grant permission and only for the purposes described in this policy.
When you sign in with Apple (Sign in with Apple / SIWA):
We may use Apple's built-in App Analytics to understand general app usage patterns (e.g., crash reports, aggregate feature usage). This data is anonymised by Apple and cannot identify individual users. We do not use any third-party analytics services.
| Purpose | Lawful Basis |
|---|---|
| Provide core App functionality | Contract performance |
| Record and display your workout sessions | Contract performance |
| Access HealthKit data for session tracking | Explicit consent as gateway |
| Calculate HCEI scores from health metrics | Contract performance |
| Sync data across your devices via iCloud | Contract performance |
| Authenticate your identity | Legitimate interest (security) |
| Provide AI-powered insights (PRO subscribers) | Explicit consent |
If you are a PRO subscriber and opt in to AI features:
AI Processing Limits:
| Service | Data Shared | Purpose | Role |
|---|---|---|---|
| iCloud (CloudKit) | App data | Cross-device sync | Data Processor (app data) / Independent Controller (iCloud account) |
| HealthKit | Health metrics | Read/write health data | Platform Provider |
| Sign in with Apple | Authentication tokens | Identity verification | Identity Provider |
| App Store | Purchase status | Subscription verification | Platform Provider |
Note on Apple's Role: Apple acts as a data processor for app data stored in your iCloud private database, and independently as a controller for your iCloud account and platform services. Your iCloud data is protected by Apple's privacy practices and Data Processing Addendum.
If you opt in to AI features, session data is transmitted to our backend infrastructure:
| Data Type | Storage Location |
|---|---|
| HealthKit data | Your device + your iCloud |
| App data (workouts, goals) | Your device + your iCloud |
| Account credentials | Apple's systems |
| AI processing data | AWS ap-southeast-2 (transient) |
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, secure authentication via Sign in with Apple, and strict access controls on backend systems.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law (including GDPR 72-hour notification requirements and the Australian Notifiable Data Breaches scheme).
| Data Type | Retention Period |
|---|---|
| Workout records | Until you delete them |
| Account information | Until you delete your account |
| Consent records | 7 years after account deletion |
| AI processing data | Not retained (transient) |
You can delete your data at any time: individual workouts within the App, all App data by deleting your account in Profile settings, or HealthKit data via iOS Settings.
Regardless of your location, you have the right to:
Additional rights apply under GDPR (EEA), the Australian Privacy Act, and CCPA (California). Contact us at privacy@saunatracker.pro to exercise your rights. We will respond within the timeframes required by applicable law (generally 30 days for GDPR and Australian Privacy Act requests, 45 days for CCPA requests).
You must be at least 17 years old to use SaunaTracker Pro. We do not knowingly collect personal information from anyone under 17. If you believe we have collected information from a child under the applicable age threshold, please contact us immediately at privacy@saunatracker.pro.
Your App data synced via iCloud is transferred according to Apple's practices, supported by Apple's Data Processing Addendum and Standard Contractual Clauses (SCCs) for transfers outside the EEA.
If you opt in to AI features, data is processed by our AWS infrastructure in ap-southeast-2 (Sydney, Australia). For EEA users, Standard Contractual Clauses are in place. A copy of the relevant safeguards is available upon request at privacy@saunatracker.pro.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you through the App. For changes that materially affect how we process your personal data, we will require your affirmative re-acknowledgment.
If you have questions about this Privacy Policy or our data practices:
Privacy Officer: JDP Software Pty Ltd
Email: privacy@saunatracker.pro
Our use of HealthKit data complies with Apple's HealthKit guidelines: we only use HealthKit data for health and fitness purposes, we do not use it for advertising, we do not share it with third parties except as described in this policy, and we obtain explicit user consent before accessing HealthKit.