← XtrkR

How XtrkR protects your data

Not a promise. An architecture. Here's exactly how it works, and why XtrkR is built so your records stay on your device, not on servers I operate.

YOUR IPHONE XtrkR app SwiftUI SwiftData SQLite (sandboxed) AES-256-GCM backup (opt-in) key derived from your password, never transmitted StoreKit, MapKit, iCloud backup ↔ Apple DATA BOUNDARY THE INTERNET XtrkR app servers ✕ none exist Analytics / Firebase ✕ not used Ad networks ✕ none Data broker sales ✕ nothing to sell
By default, your data stays on this side of the dotted line.

1. By default, everything stays on your iPhone

XtrkR uses Apple's SwiftData framework to store your records in a local database on your device. There is no XtrkR account. There is no XtrkR server storing your records. XtrkR does not store your records in the cloud unless you turn on encrypted iCloud Backup. If you choose to add a plan to your calendar or a partner to Contacts, that entry lives wherever your calendar or contacts sync.

What this means in practice

When you log an encounter, that data is written to a SQLite database inside XtrkR's sandboxed storage on your iPhone. XtrkR does not send that record to a server I operate.

SwiftData + SQLite

2. Limited network calls, only when needed.

XtrkR uses limited Apple-provided network services for specific features. One is Apple's StoreKit framework, which handles in-app purchases. That is Apple's code talking to Apple's servers about whether you made a purchase. I do not see your payment card details.

Another is Apple's MapKit, which the app uses for maps, place search as you type, and turning a location into a city or place name. Those requests go to Apple's servers, not mine.

The third is iCloud, and only if you turn on iCloud Backup: the encrypted backup files go to your own iCloud.

Beyond those Apple-provided services, there are no ad networks, analytics SDKs, or third-party tracking tools in the app. You can optionally share diagnostics from Settings, but the app itself sends nothing to me without your action. The app is otherwise designed to stay quiet on the network.

No third-party SDKs

Many apps bundle third-party libraries that contact outside servers. XtrkR includes none: the app is built only with Apple's frameworks.

Zero external dependencies

3. Encrypted backups (opt-in only)

If you choose to back up your data, XtrkR creates an AES-256-GCM encrypted file and saves it to your personal iCloud Drive. You set the password. The encryption happens on your device before the file is written.

1

You turn on iCloud Backup (premium) and set a backup password you choose

2

Your records are encrypted on-device with AES-256-GCM, using a key derived from that password

3

Encrypted backup files are saved to XtrkR's folder in your iCloud, with your photos and videos copied there, each encrypted separately

4

Only someone with your password can decrypt them. I cannot.

Why AES-256-GCM?

AES-256-GCM is a widely used, standardized encryption mode. The "GCM" part authenticates each encrypted piece, so altered encrypted bytes fail to decrypt instead of opening as garbage.

AES-256-GCM encryption

4. What I cannot do

This isn't a policy decision. It's an architectural constraint. The app is designed so that I cannot:

4b. Photos shared via the Share Extension

If you save a photo or screenshot to XtrkR using the iOS Share Sheet, it is processed entirely on your device:

This iCloud-backup exclusion isn't unique to shared photos: every photo and video you store in XtrkR, however you add it, is marked to be left out of your automatic iCloud device backup. Through XtrkR, your media leaves the device only if you turn on iCloud Backup or export an encrypted backup, and it is encrypted first either way.

You are responsible for what you choose to save. Do not use XtrkR to store unlawful content, including nonconsensual intimate images or images of minors.

5. What about law enforcement?

Because your records live on your device, not on servers I operate, I have nothing to produce about your in-app records in response to a subpoena or legal request. If you have emailed me health details, those emails could be reached, which is one reason I ask you not to include them.

However, your device itself can be subject to a warrant or physical seizure. If law enforcement obtains a valid warrant for your iPhone, the data inside XtrkR, like all data on your phone, could potentially be accessed. This is true of any app that stores data locally.

If you enable encrypted iCloud backups, the encrypted backup file is stored in your iCloud Drive. Apple could be compelled to produce that file in response to a legal request, but it is AES-256-GCM encrypted with a password only you know. Without that password it cannot be decrypted, and the protection is only as strong as the password you choose.

What this means for you

XtrkR's architecture is designed to protect against data breaches, corporate surveillance, and developer access. It does not, and cannot, override the legal authority of a court order directed at your own device. Protect your device with a strong passcode and keep your backup password private.

6. Why this matters for you specifically

If you're using XtrkR to track PrEP adherence, STI test results, encounter history, partner details, or other sensitive health information, you're storing deeply personal data. Many apps in this space require accounts, sync to cloud servers, or include analytics that track user behavior.

That kind of architecture creates risks this app is designed to avoid.

XtrkR was built so your records stay on your device, not because of a privacy promise that could change, but because of an architecture designed around local storage.

Try premium free for 30 days

Full premium access. No credit card. No account. By default your records stay on your iPhone, not on servers I operate.

See pricing