Privacy Policy
Effective September 29, 2026
This Privacy Policy explains what information Rackd collects when you use our mobile application and website (collectively, the "Service"), how we use it, and the choices you have. We've tried to write it in plain language. If something isn't clear, email us at support@rackdlife.com.
1. Who We Are
"Rackd" refers to the Rackd application and the team that builds it. We are based in the United States. You can reach us any time at support@rackdlife.com.
2. Information We Collect
Information you give us
- Account information. When you sign up — directly with email and password, or through Google Sign-In or Sign in with Apple — we receive your email address and an authentication identifier. If you sign in with Apple using "Hide my email," we only see the relay address Apple gives us.
- Profile information. Display name, profile picture (if you set one), default difficulty preference, and any other profile fields you fill in.
- Workout activity. Workouts you complete, custom workouts you create or fork, exercise selections, durations, weights, reps, and the timestamps of those activities.
- Social information. Friend codes you share or enter, the friend connections you form within the app, and — if you create or join a team — the team's name and description, your membership in it, and the workouts you contribute to it.
- Phone number (optional). You can add a phone number to your profile so friends who already have your number in their contacts can find you. It is optional, you can remove it at any time, and we never use it as a sign-in method or send you SMS.
- Contacts (optional, opt-in). If you choose to look for friends from your contacts, and grant contacts permission, the app reads the names, phone numbers, and email addresses in your address book. Please read "Finding friends from your contacts" below for exactly what leaves your device and what we keep — the short version is that raw contact details never leave your phone, and we never store anything about people who don't use Rackd.
- Support communications. If you email us, we keep your message and any reply we send.
- Creator applications. If you apply to launch an app on rackdlife.com, we receive your name, email address, the handle or link where your audience follows you, your audience size, and anything else you choose to tell us. We use it only to review your application and contact you about it.
Finding friends from your contacts
This feature is entirely optional. It does nothing unless you open it, grant contacts permission, and tap to search. If you never do, we never see anything about your contacts.
When you do use it:
- Your contacts' phone numbers and email addresses are converted on your device into cryptographic digests (HMAC-SHA256, keyed with a value our server issues to the signed-in app). The names, numbers, and addresses themselves never leave your device — we do not receive, transmit, or store your address book, and we never read your contacts' names at all.
- Only those digests are sent to our server, where they are re-keyed with a second secret that never leaves our servers and compared, in memory, against the digests of Rackd users who have turned on contact discovery for themselves. We treat these digests as personal information rather than anonymous data, and protect them accordingly.
- We return the matches, and then we discard every digest you sent. Digests belonging to people who are not Rackd users are never written to storage, never logged, and never used to build a profile, a social graph, or an invitation list. We do not contact anyone in your address book.
- Matching only ever surfaces someone who has opted in on their side too. You can turn your own discoverability off at any time in the app under Profile → Privacy, which removes your match key from our index.
We use this only to show you which of your existing contacts already use Rackd. We do not use it for advertising, we do not sell it, and we do not share it with anyone.
Information we collect automatically
- Device and diagnostic data. Through Firebase Crashlytics and Firebase Performance Monitoring, we collect device type, operating system version, app version, anonymized device identifiers, and crash reports, so we can fix bugs and improve performance.
- Usage analytics. Through PostHog, we collect information about how you interact with the app — which screens you visit, which features you use, and events like completing a workout or starting a subscription. Once you sign in, these events are associated with your Rackd account identifier, along with a small set of attributes we use to understand usage: whether you have an active subscription and which plan, your sign-up date, how many workouts you've completed, your app environment, and a partner code if you joined through one. We do not send PostHog your name, email address, phone number, or the contents of your workouts. You can turn analytics off in the app under Profile → Privacy.
- Push-notification tokens. If you allow notifications, we store the Firebase Cloud Messaging (FCM) token issued by your device so we can send you the notifications you've opted into.
- Anti-abuse signals. Through Firebase App Check, we collect a device-attestation token (Apple App Attest on iOS, Play Integrity on Android) to verify requests come from a genuine instance of the app.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service — sign you in, store your workouts and history, recommend workouts, sync your data across devices.
- Personalize your experience — show workouts that match your stated focus, equipment, and difficulty.
- Connect you with people you choose — friend codes, QR codes and invite links you share, team invitations and join requests, and, if you opt in, showing you which of your existing contacts already use Rackd.
- Communicate with you — push notifications you opt into (workout reminders, friend requests, kudos, team activity, and workouts shared with you), and operational emails (security alerts, account changes).
- Improve Rackd — analyze aggregated usage to find bugs, prioritize features, and measure performance.
- Protect Rackd and our users — detect abuse, enforce our Terms, and comply with legal obligations.
We do not sell your personal information. We do not use your workout activity for advertising, and we do not share it with advertisers.
4. How We Share Information
We share information only as described below:
- Service providers. We use Google's Firebase platform (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, App Check, Crashlytics, Performance Monitoring) to run the Service. Firebase processes data on our behalf under Google's Firebase Privacy Policy. We use PostHog for product analytics and error reporting; PostHog processes that data on our behalf on servers in the European Union. Neither provider is permitted to use your information for their own purposes.
- Sign-in providers. If you sign in with Google or Apple, those providers receive a record of your sign-in event. They do not receive your workout data.
- Subscription billing (when applicable). If we add paid subscriptions, billing is handled through Apple, Google, and RevenueCat. We receive transaction status from RevenueCat but never your payment-card details.
- Other Rackd users. Once you accept a friend connection (via friend code), the following information is automatically shared with that friend: your display name, profile picture, your current and longest workout streaks, your total workout count, the name and timestamp of each workout you complete, and any "kudos" reactions either of you sends to the other. Friends do not see your custom workouts unless you explicitly share one. You can revoke a friend connection at any time, which prevents future activity from being shared, but past activity remains in the receiving friend's feed until it ages out.
- Your team. If you join a team, the other members of that team see your display name, profile picture, and the workouts you complete while you are a member, including your contribution toward any team goal. The team leader additionally sees join requests you send. A team's name, description, photo, and member count are visible to any signed-in Rackd user, so that an invite link or join code can resolve to a team; by default a team also appears in the browsable "join a team" list, which the leader can switch off when creating it. The team's roster and its activity feed are visible only to its members. Leaving a team stops future activity from being shared with it; activity already posted to the team's feed remains until it ages out.
- Legal compliance. We may disclose information if required by law, subpoena, or court order, or to protect Rackd, our users, or the public from harm.
- Business transfers. If Rackd is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will give you notice before your data becomes subject to a different privacy policy.
5. Data Retention
We keep your information for as long as your account is active. If you delete your account, we delete your profile, workout history, custom workouts, friend connections, team memberships, phone number, and authentication record within 30 days, except where we are required to retain something for a legal or accounting reason. Aggregated, de-identified analytics data may be retained.
Contacts are not retained. The digests your device sends when you search your contacts are held only in memory for the moment it takes to run the comparison, and are discarded when the request finishes. We do not keep a copy of your address book, and we never store anything derived from contacts who are not Rackd users. The only contact-related value we store is the match key derived from your own phone number and email address, kept while you have contact discovery switched on and deleted when you switch it off or delete your account.
6. Your Rights and Choices
Access and correction
You can view and edit most of your information directly in the app — display name, photo, default difficulty, custom workouts. For anything else, email support@rackdlife.com.
Account deletion
You can delete your account at any time. In the app: Profile → Delete Account. Once you confirm, we permanently remove your profile, workout history, custom workouts, and friend connections, and your authentication record, within 30 days. If you'd rather not use the in-app option, email support@rackdlife.com from the address tied to your account and we'll process it for you.
Push notifications
You can turn off push notifications in your device settings (iOS: Settings → Rackd → Notifications). Granular per-category controls (e.g., kudos vs friend requests) may be added inside the app in a future release.
Contact discovery and contacts permission
Contact discovery is off until you turn it on. Two separate controls apply:
- Whether others can find you. Profile → Privacy → contact discovery. Turning it off removes your match key from our index, so you stop appearing in anyone's contact search.
- Whether Rackd can read your contacts. Your device's permission (iOS: Settings → Rackd → Contacts; Android: Settings → Apps → Rackd → Permissions). Revoking it stops the app reading your address book. On iOS you may also grant access to only selected contacts, and Rackd works normally with a limited selection.
Removing the phone number from your profile also removes it from the match index.
Analytics opt-out
You can disable analytics collection in the app under Profile → Privacy. Disabling analytics will not affect your ability to use the Service.
Region-specific rights
Depending on where you live, you may have additional rights — for example, the right to access, port, or delete your information (under the GDPR if you are in the EU/UK, or under the CCPA if you are in California). To exercise any of these rights, email support@rackdlife.com. We will not discriminate against you for exercising your rights.
7. Children
Rackd is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, email support@rackdlife.com and we will delete it.
8. Security
We use industry-standard practices to protect your information — TLS encryption in transit, encryption at rest in Firebase, App Check device attestation, and tightly scoped Firestore security rules. No system is perfectly secure; if we discover a breach affecting your information, we will notify you in accordance with applicable law.
9. International Users
Rackd's servers are operated by Google Cloud Platform, and your information may be processed in the United States or in other countries where Google operates infrastructure. By using Rackd, you consent to your information being transferred to and processed in these locations.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we'll notify you in the app, by email, or by posting a prominent notice on rackdlife.com. The "Effective" date at the top tells you when the current version took effect.
11. Contact
Questions, concerns, or privacy requests? Email us at support@rackdlife.com.