← Back to DAUNTRA

Legal

Privacy Policy

Effective date: 27 August 2026

Scope

This policy explains how DAUNTRA handles information in the Android app, public website, API, and waitlist.

Account and profile data

The app processes your full name, email address, a one-way password hash, and—when supplied—date of birth, gender, weight, height, and fitness level. Passwords are not stored as plaintext.

Workout, nutrition, and body information

  • Workouts: workouts, exercises, sets, reps, load, duration, history, programs, schedules, and personal records or statistics derived from that history.
  • Nutrition: meals, foods, calories, macro- and micronutrients, food searches, targets, and nutrition history.
  • Body/profile: optional weight, height, date of birth, gender, and fitness level used for fitness features and insights.

Authentication and security

Access and refresh tokens maintain authenticated sessions. The app stores session credentials in operating-system secure storage. Email verification, password-reset codes, token revocation, and verified-email deletion codes are used where applicable. Production traffic is transmitted using HTTPS/TLS.

Technical, analytics, and crash data

Hosting infrastructure may process IP address, timestamps, requested route, response status, browser/user-agent, and diagnostic data to operate and secure the service. If configured for a production app build, PostHog receives limited interaction and lifecycle events plus SDK-provided app/device context. DAUNTRA does not intentionally send email, profile, workout, or nutrition fields to PostHog, and session replay is disabled. If Sentry is configured, it receives crash and performance diagnostics plus limited activity breadcrumbs such as event names and coarse counts or ranges. Raw workout, nutrition, profile, and authentication values are excluded; default PII collection, screenshots, and Sentry replay are disabled.

The public website is hosted on Cloudflare Workers. Cloudflare Web Analytics provides aggregate website traffic and performance analytics. Cloudflare Web Analytics is cookie-free and does not collect or use visitors' personal data. Website PostHog code remains disabled unless deployment explicitly opts in; when enabled it receives selected website interaction events and browser exception diagnostics, while session recording remains disabled.

Camera and barcode scanning

Camera permission is used to scan food barcodes with Google ML Kit on the device. DAUNTRA does not retain or transmit camera images or video. The detected barcode value may be sent to a food-data service for product details. Google ML Kit may collect limited SDK diagnostics, such as app/device configuration, performance and usage metrics, and an installation identifier.

Service providers

  • Render hosts the API and database and therefore processes stored app data and server request metadata.
  • Resend receives the destination email and transactional message content for verification, reset, and deletion codes.
  • USDA FoodData Central and Open Food Facts receive food-search or barcode/product requests; account profile data is not included in those catalogue lookups.
  • ExerciseDB or a self-hosted compatible service supplies exercise catalogue data and media without requiring account profile data.
  • PostHog and Sentry provide optional analytics and crash diagnostics only when configured.
  • Google ML Kit performs on-device barcode recognition and limited SDK diagnostics as described above.
  • Cloudflare hosts and serves the public website and provides Cloudflare Web Analytics. Supabase stores waitlist email addresses.

How information is used and shared

Information is used for authentication, workout and nutrition tracking, programs, statistics, Lab Insights, support, security, service reliability, and requested waitlist communications. It is disclosed to processors only as needed for these functions. DAUNTRA does not sell personal information.

Retention and account deletion

Delete your account in the app under Profile → Account → Delete Account, or use the public account deletion page. The application hard-deletes the account/profile and associated schedules, programs/program exercises, workouts/sets, nutrition history, account-linked app analytics records, and revoked-token records from the active database. Pre-auth anonymous events that are not linked to an account may remain under a rotated anonymous identifier. Limited security logs or provider backups may remain until routine expiry where required for security, legal compliance, or disaster recovery; they are not used to restore the deleted account.

Waitlist emails are retained while needed for early-access communications or until a verified deletion request is completed, subject to limited provider backups and legal/security retention.

Security and your choices

Credential hashing, access controls, short-lived access tokens, restricted service credentials, and HTTPS reduce risk, but no internet service can promise absolute security. You may update profile data, disable camera permission in device settings, request waitlist removal, or delete the app account.

Contact

For privacy or account-data questions, email privacy@dauntra.com.