Privacy Policy
Last updated 6 September 2026
Who controls your data
The operator of Meditation Tracker is the data controller for the app and website. For privacy questions, rights requests, or complaints, contact support@meditationtracker.app.
Your camera
The app uses your front camera to check your posture during a session. Frames are processed entirely on your device and are never written to storage, never sent to us, and never sent to anyone else. There is no server that could receive them.
The app may keep derived measurements only: angles, counts, and timestamps — for example “spine 24° at 03:12, violation”. These measurements are stored locally and, if you enable account sync, the session summary is sent to our service. No image, no video, and no frame is retained or uploaded.
What we process
- Session summaries: start time, target length, stillness time, violation count, and why a session ended. These stay on your device unless account sync is enabled.
- Your streak, settings, and onboarding answers on the device.
- Account details (an anonymous account ID, or the name and email supplied by Google), authentication session metadata (which may include IP address and user agent), and subscription entitlement status when sync or sign-in is enabled.
An anonymous account ID is pseudonymous personal data, not a promise that analytics are fully anonymous. We do not use it to identify you from camera frames.
Beta waitlist
If you join the beta list, we store the email address you submit and limited first-touch attribution such as campaign, source, creative, message variant, referrer, and locale. We use it to invite testers and learn which launch messages attract real product interest. We do not store your IP address, browser fingerprint, or camera data with a signup. Contact us to remove your waitlist record or unsubscribe from beta updates.
Analytics
We collect bounded, pseudonymous product events — such as that a session started, a violation occurred, or the paywall was viewed — to understand where the app is too strict or too confusing. Events can be linked to the app account that sent them, but do not contain your name, email, camera frames, pose coordinates, or advertising ID.
If error reporting is enabled in a release, we receive technical crash details needed to diagnose failures. Camera images, screenshots, view hierarchies, and default personally identifying fields are disabled.
Optional product notifications
Product news and offers are off by default. If you opt in, we store a Firebase notification token together with platform, app version, locale, timezone, permission state, and recent registration time so we can select the intended audience. You can opt out in Settings; the app unregisters the token and asks Firebase to delete its local copy. Account deletion also removes server-side notification records.
Account sync and deletion
When sync is enabled, the app creates an anonymous account so your session history can reach the service. You may connect it to Google to carry that history to another device. You can permanently delete the account and associated synced data from Settings in the app, or request deletion from our account-deletion page.
Purposes, legal bases, and retention
We process data to provide posture-verified sessions and account sync (performance of the service), to process subscriptions and meet legal obligations, to send product notifications only when you opt in (consent), and to keep the service secure and improve reliability (legitimate interests). You may withdraw notification consent in Settings and object to analytics by contacting us.
Local data remains until you delete it or uninstall the app. Synced account data is retained while the account is active and erased when you delete the account, subject to a short legal or security hold. Waitlist records are kept only for the beta and launch period, analytics for up to 12 months, and push tokens until opt-out or account deletion. Apple, Google, RevenueCat, and infrastructure providers may retain records under their own policies and legal obligations.
Your rights and international processing
Depending on where you live, you may request access, correction, deletion, restriction, portability, or object to processing. Email support@meditationtracker.app from the address linked to your account; we may verify ownership before acting. We aim to respond within one month for GDPR requests and within the applicable Thailand PDPA timeframe.
We use service providers for hosting, authentication, crash reporting (if enabled), push notifications, Google sign-in, and subscription status. Some providers may process data outside the EEA or Thailand. We use contractual or other legally required transfer safeguards and can provide details on request.
Billing
Subscriptions are processed by Apple or Google. We use RevenueCat to check whether your subscription is active. We never see your card details; Apple and Google do not give them to us.
Children
The service is not directed to children. If you believe a child has provided personal data, contact us and we will review and delete it where required.
Contact
Questions or a deletion request: support@meditationtracker.app