Privacy Policy
Track Anything · last updated 6 September 2026
Track Anything is a personal organizer with an optional friends feature. This policy describes what the app stores, where it stores it, what another person can see, and how to get rid of it. Everything listed below is something the app really keeps; there is no advertising and no analytics anywhere in it.
What is collected
- Your account — an email address and a password. The password is never stored; only a one-way hash of it is kept, which cannot be turned back into your password.
- Your profile — a display name and a handle. These are what other people search for and what a friend sees next to your entries. If you do not choose them, the app fills them in when the account is created.
- A provider account identifier — if you sign in with Apple, Google or Facebook, the identifier that provider gives for your account is stored beside your account, so the same provider account signs you back in to the same data. Signing in with Apple stores one thing more, a token from Apple; the sign-in section below says what it is for.
- What you track — the tasks, habits, projects, events, goals and tracker entries you create, including anything you type into them.
- Friends and sharing — your friend connections and whether each one is pending, accepted or declined; the per-friend sharing switches described below; anyone you have blocked; tracker templates you send or receive; and the in-app notifications those produce.
- Reports you file — if you report an account, a friend request or a tracker template someone sent you, the app stores the account you named, the reason you picked and the note you typed, up to 1000 characters. Only the people who run the app read it. The person you reported is never told and is never shown what you wrote.
- Sign-in and security records — a log of what grants or removes access to your account, and one record for each device that is signed in. Sign-ins also record your IP address. The section on sign-in and security records below sets out what is kept and why.
- Two-factor secrets — only if you turn two-factor on: the shared secret your authenticator app is set up with, and one-way hashes of your recovery codes.
- Settings — theme, first day of the week and clock format. These stay on your device. They are written to the app's own storage on the phone and are never sent to the server, which is also why they do not follow you to another device.
What is not collected
- No advertising identifiers, and no advertising.
- No analytics or usage tracking of any kind.
- No location, contacts, photos, health data, or device sensors. The optional Face ID or fingerprint lock is carried out by your device, which tells the app only whether it succeeded.
- No third-party trackers, and no SDK that profiles you or reports your activity to anyone else.
- No push service. Reminders are scheduled on your own device, so no server holds a list of what you asked to be reminded about or when.
Signing in with Google, Apple or Facebook
Signing in with a provider is optional — an email address and a password work just as well. If you do use one, the app includes Google's Firebase Authentication SDK, which carries out the sign-in and hands this app a signed token proving who you are.
- What comes back is your email address, whether the provider has verified it, a provider account identifier, and, when the provider offers it, your display name.
- Sign in with Apple leaves one more thing behind. Apple's sheet hands the app a single-use code, and the app trades that code with Apple for a refresh token, which is kept beside your account. It is there for one reason: it is the only thing that can tell Apple to withdraw this app's access when you delete your account, which is what Apple requires of every app that offers Sign in with Apple. Deletion is the only thing it is ever used for: it reads nothing from Apple, it is left out of your data export, and it is deleted with your account. If Apple cannot be reached while you are signing in, the single-use code is held instead and traded at deletion. Google and Facebook leave no such token.
- Your password for that provider is never seen by this app.
- The sign-in itself is handled by the provider you choose (Google, Apple or Facebook) and by Firebase Authentication, so those companies necessarily see that a sign-in happened. Their handling of that is governed by their own privacy policies.
- These SDKs are used only to sign you in. They are not used for advertising, analytics or tracking, and no tracker entry, task or anything else you write is ever sent to them.
Sign-in and security records
The app keeps a security log of the things that grant or take away access to your account: sign-ins, password changes and resets, sessions being signed out, and two-factor being turned on or off. Every entry records what happened and when. A sign-in also records a short device label — iPhone, Android or Web, never your full browser or device fingerprint — and the IP address the request came from. Alongside that, each signed-in device has a record of its own, with that same short label and when it was last used.
All of this exists so that you can read it. Settings has a Security activity screen that shows the log and the list of signed-in devices, so that a sign-in you did not make is something you can notice and act on, and any device can be signed out from there. The IP address is the part that makes an unfamiliar sign-in recognisable as unfamiliar. It is never used for advertising, analytics, profiling, or working out where you are, and it is never handed to anyone else. The log belongs to your account, so deleting the account deletes it.
The app also emails the account address when a new sign-in happens and when the password changes, for the same reason.
Where it is kept
Your account and your entries are stored on a single server operated for this app, reached over an encrypted connection (HTTPS). A copy of what you write is also kept on your own device so the app keeps working without a network; that copy is encrypted with AES-256-GCM before it is written, with the key held in the device's keychain. Entries made offline are sent to the server when it is reachable again.
Who it is shared with
Another person can see something of yours only through a friend connection, and then only the kinds of thing you have switched on for that particular person. Nothing is shared by default.
- Both sides have to agree. One of you sends a request and the other accepts it. Until that has happened, nothing of yours is visible to them.
- You choose the kinds, one friend at a time. For each friend separately you switch on whichever of habits, tasks, goals, events, meetings, milestones and projects that person may see, and whether they may see your trackers. Every switch starts off.
- What a switched-on kind shows. Those entries as you wrote them, including the notes, dates and places you typed into them. Trackers are the exception: a friend sees a tracker's setup — its name, icon, colour and how it is captured — and never its entries, its streak, or the reminder times in it.
- It is read-only. A friend can look. Nothing in the app lets them add to, complete, change or delete anything of yours.
- Each direction is separate. What you show a friend and what that friend shows you are two independent settings. Accepting a request does not mirror theirs, and turning something on for them does not turn anything on for you.
- An accepted friend sees the email address on your account, along with your display name and handle.
- Being findable. Anyone signed in can search for you by display name or handle, or by typing your email address in full. Results show a display name and a handle; your email address appears only to someone who already typed the whole of it.
- You can undo any of it. Turn a switch off, remove the connection, or block the person. Each takes effect immediately. Blocking also removes what the two of you had between you, hides each of you from the other's search, and stops further requests.
Sending someone a tracker template is a copy, not a link. They receive the tracker's setup, and if they accept it they get a tracker of their own made from it. Whatever either of you records in it afterwards belongs to its own owner and is not visible across.
Beyond that, nobody. Your data is not sold, rented, or shared with advertisers, data brokers, or any other company. Two suppliers necessarily handle a narrow part of it so that the app can work: the email provider that carries the app's messages sees your address and what those messages say, and, if you use social sign-in, the provider you chose and Firebase see that a sign-in happened. Apple is told one thing more: that an account which used Sign in with Apple has been deleted, because saying so is what withdraws this app's access. Anything else is disclosed only if legally compelled, or to protect the service from abuse.
Deleting your account
You can delete your account from inside the app, under Settings. Deleting it removes your account, everything you tracked, your friend connections and blocks, the tracker templates you sent or received, your notifications, your signed-in devices, your security log and the Apple token described above from the server. This is immediate and cannot be undone. Export your data first if you want to keep it — the button sits directly above deletion in Settings for that reason.
Reports are deliberately kept. If you filed one it stays — the account you named, the reason you picked and the note you wrote — with your account id removed from it, so the report no longer points back at you. Anything you typed in the note stays as you typed it. A report is a record of somebody else's conduct, and if your own deletion erased it, anyone could report a person, close their account and take the record away with them. A report that names you, rather than one you filed, is deleted with your account.
Backups of the server database are kept for 14 days before they rotate out, on the server and in one copy held off it, so a deleted account can still exist inside a backup until the last one taken before the deletion has rotated away.
If a support or administrator account has ever acted on your account — confirming it, signing its sessions out, changing its role, or deleting it — the record of that action names the account and is kept afterwards. A decision on a report filed about you is recorded the same way: reading it, acting on it or dismissing it writes an entry holding your email address, and that entry is kept after both the report and your account are gone. It is a record of what staff did, and it holds nothing you tracked.
If you signed in with Apple, deleting your account here also tells Apple to withdraw this app's access, which is what takes Track Anything out of Sign in with Apple on your Apple ID. It happens at the moment you delete, using the token described above. If Apple cannot be reached just then, your account is still deleted and the entry on Apple's side can outlive it; you can remove that one yourself in Settings, your name at the top, Sign-In & Security, Sign in with Apple, Track Anything, Stop Using Apple Account.
Google and Facebook are not the same. Each holds its own record that you used it with this app, and deleting your account here cannot reach it. To remove it, revoke the app in the provider's own settings:
- Google — myaccount.google.com, Security, then Your connections to third-party apps and services, Track Anything, Delete all connections.
- Facebook — Settings & privacy, Settings, Apps and websites, Track Anything, Remove.
Children
Track Anything is not directed at children under 13 and does not knowingly collect their data.
Changes
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and the new version appears here.
Contact
Questions about this policy or about your data: afonsodossantosjulia@gmail.com.
The rules for using the app, and what happens to an account that breaks them, are in the terms of use.