Privacy policy
IronLedger logs your training on your device and does not require an account. We do not sell data, we do not run advertising, and there is no paid tier, so there is nothing we gain from knowing more about you than the app needs to work.
If you sign in, your training record also syncs to our database, where we can read it. Health data moves only when you switch a connection on. You can export everything to CSV or Excel at any time, and delete it from this page when you want it gone.
What this policy covers
This policy applies to the IronLedger mobile app on iOS and Android, and to this website. It describes what data exists, where it lives, and who can reach it. It does not cover the separate privacy practices of Apple, Google, Strava or Oura, each of which governs its own platform.
Data stored on your device
Your training record is written locally first. Sessions, sets, loads, reps, RPE and RIR values, notes, form-check videos, programs and personal records are all stored on the device you logged them on. No account is required to log training, and if you never sign in, the local copy is the only copy.
- •Logging works fully without an account, and nothing is uploaded while you are signed out
- •Form-check videos are stored on the device with the set and are never uploaded
- •Uninstalling the app removes local data on most platforms, so export first if you want to keep it
Data on our servers
If you create an account and sign in, IronLedger syncs your training record so it survives a lost phone and reaches your other devices. That copy is stored in our database and is readable by us, which is the honest position: it is not end-to-end encrypted, and we could be compelled to produce it. It is protected by row-level security so that no other user can read it, and it is transmitted over TLS.
- •Workout sessions, including every logged set, load, rep, RPE and RIR value
- •Programs, custom exercises and personal records
- •Your account email address and display name
- •Nothing syncs until you sign in, and signing out stops it
Health permissions
Health data is read or written only after you enable a connection and the operating system grants the permission. IronLedger writes completed strength workouts to Apple Health and reads body weight so calorie estimates use a current number. On Android, workout sync runs through Health Connect under its own permission model.
- •Permissions are requested when you turn a connection on, never at first launch
- •A workout written to Apple Health has to be deleted in Apple Health, because iOS does not allow an app to remove a record it already handed over
- •Revoking a permission stops the sync immediately and does not affect your local log
Third-party connections
Strava receives completed sessions if you connect it, and Oura provides a daily readiness score if you connect it. Both are optional, both move data in one direction only, and each is governed by that company’s own privacy policy once data reaches them.
Analytics and crash reports
The app carries no advertising and no advertising SDKs, and nothing here is sold or shared for marketing. It does use two third-party services, named here rather than described vaguely.
PostHog records product analytics: which screens are opened and which actions are taken. When you are signed in, your account identifier is attached to those events, so this is not anonymous.
Sentry records crashes and performance. A crash report can include a screenshot of the app taken at the moment it failed, along with the view hierarchy. If the app crashes while your training is on screen, that screenshot will contain it.
Your rights and choices
You can export your full training record to CSV or Excel at any time, delete your local data from the app, delete your account and the synced copy that belongs to it, and revoke any health permission from your phone’s settings. Most of these do not require contacting us at all.
Changes to this policy
Material changes will be reflected in the last-updated date at the top of this page. A change that expands what data is collected will be announced before it takes effect, not after. Questions go to support@ironledger.app.