Privacy Policy

Last updated: July 20, 2026

Ironhold ("we", "our", "the app") is a fitness tracking application developed by an independent developer. Your privacy is important to us. This policy explains what data the app collects, how it is used, and your rights.

1. Data We Collect

Account Information

When you sign in with Apple or Google, we receive your name and email address solely to create your account. We do not sell or share this information with third parties.

Health & Fitness Data

With your permission, Ironhold reads the following HealthKit data:

and writes the following HealthKit data:

HealthKit data is stored on your device and in your personal iCloud account. We never access your HealthKit data on our servers.

Workout & Nutrition Data

Exercises, sets, meals, and body measurements you log are stored locally on your device and synced to your private iCloud account via Apple CloudKit. This data is only accessible to you.

Apple Watch

If you install the Apple Watch app, details of your in-progress workout — the exercise list, the sets you have logged, and your rest timer — are sent between your iPhone and your Apple Watch over Apple's device-to-device connection so you can log sets from your wrist. This stays between your own two devices; it does not pass through our servers, and nothing is stored on the Watch. Your iPhone remains the only place this data is saved.

Progress Photos

Photos taken within the app are stored locally on your device in the app's sandbox. They are not uploaded to any server or synced via iCloud.

Food Search

When you search for foods, your search text is sent to our food search server (api.nicolaa.tech), which looks up results from OpenFoodFacts and USDA FoodData Central and caches them so searches are fast. Search queries are not linked to your account or identity.

When you log a food from the search results, the app also reports the search term and the product you picked, together with a random anonymous token, so that popular foods can rank higher for everyone. This token is generated on your device, is not derived from any device or account identifier, and cannot be linked to you.

Barcode scans query OpenFoodFacts directly.

Referrals

If you use the referral feature, your referral code and a second random token are sent to our server so we can count how many people you referred and award the reward you earned. This token is also randomly generated and not derived from any device or account identifier, but unlike the search token it is stored in the iOS Keychain so it survives reinstalling the app — this is what stops the same person claiming a referral repeatedly. It is kept separate from the search token, and the two are never linked. If you claimed someone's code, the app also sends the number of workouts you have completed — a count only, with no detail about them — so the referral counts once you have genuinely used the app. The server stores only your referral code, this token, which code you claimed, and the dates each was registered, claimed and counted — the date it counted is what determines when a referral reward expires. If you never use a referral code, nothing is sent.

Meal Photo Scanning (Pro)

If you use the optional "Scan Meal" feature, the photo you take is sent to our food search server and forwarded to Anthropic's Claude API to identify the foods and estimate nutrition. Photos are processed and immediately discarded — we do not store them, and Anthropic does not use API data to train its models. This only happens when you explicitly take or choose a photo to scan; progress photos and other images never leave your device.

Feedback

If you send feedback through the in-app form, the text you write — together with your device model, iOS version, and app version to help us debug — is sent to our feedback service (admin.nicolaa.tech) and stored there. No email address, account identity, or device identifier is attached. Please don't include personal information in feedback messages.

2. How We Use Your Data

3. Data Sharing

We do not sell, rent, or share your personal data with third parties. Your fitness data stays between you and Apple's iCloud infrastructure.

The only external services the app communicates with are:

4. Data Storage & Security

All personal data is stored either on your device or in your private iCloud container. The only servers we operate are the food search server and the feedback service described above — they store anonymous search queries, cached food data from public databases, anonymous popularity statistics, anonymous feedback submissions, referral codes and their claim records, and anonymous daily usage counters (e.g. how many workouts were logged that day — never who logged them). Aside from meal photos you explicitly scan (which are processed and immediately discarded), they never receive or store your account, health, workout, or body data. Authentication tokens are stored securely in the iOS Keychain.

5. Subscriptions

Ironhold Pro is available as a monthly or annual auto-renewing subscription. Current pricing is shown in the App Store and in the app before you purchase. Payment is processed by Apple. You can manage or cancel your subscription at any time through your Apple ID settings. See Apple's subscription support page for details.

6. Children's Privacy

Ironhold is not directed at children under 13. We do not knowingly collect personal information from children.

7. Your Rights

You can delete your account and all associated data from within the app (Profile → Settings → Delete Account). This removes all locally stored data and your iCloud sync data. Anonymous food search statistics on our server contain no identifying information and cannot be linked back to you. Referral records are also kept: they contain only a referral code, a random token, which code was claimed, and the dates it was claimed and counted, with no personal information. Because that token is deliberately stored in the Keychain so a referral cannot be claimed repeatedly, it is not removed by deleting the app or your account. If you would like your referral record deleted, contact us through the in-app feedback form.

8. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision.

9. Contact

If you have questions about this privacy policy, you can reach us through the in-app feedback form (Settings → Feedback).