XtrkR is operated by De Nihil LLC, a Wyoming limited liability company. In this policy, “I” refers to De Nihil LLC.
XtrkR is built so the data you enter stays on your device, not on servers I operate. There are no XtrkR accounts, no XtrkR cloud database, and no third-party ad or analytics SDKs in the app. Some Apple-provided services and optional features may involve limited data processing outside the app’s local storage environment, as explained below. But as a general matter, I do not have technical access to the health records you store in XtrkR.
For Washington residents and others interested in consumer-health-data-specific disclosures, see the Consumer Health Data Privacy Policy.
XtrkR stores the following categories of data locally on your device using Apple’s native frameworks:
This data is designed to stay on your device unless you choose to use a feature that involves Apple services or you choose to export, back up, or share information yourself.
This privacy policy primarily addresses the XtrkR iOS app. The marketing website at xtrkrapp.com is a separate surface with its own minimal privacy posture.
No cookies. No third-party trackers. No analytics SDKs. The site sets no browser cookies and embeds no Google Analytics, Plausible, Meta Pixel, or similar tracking scripts. You can verify this in your browser’s developer tools.
First-party campaign attribution. When you visit the site with a campaign-tracking URL parameter (e.g. ?ref=reddoor from a clinic’s distribution card), my server logs the visit with three things: an anonymized IP address (IPv4 addresses truncated to the first three octets, IPv6 to the first 64 bits; your full IP is not stored in this campaign-attribution log), a timestamp, and the campaign tag value. Visits without a ?ref= parameter are not logged by this system.
This is attribution (knowing which distribution channels brought you to the site so I can prioritize them), not surveillance. It’s the same kind of measurement a podcast uses when it asks listeners to use a unique promo code per sponsor.
Where the data lives. The log file is stored on my hosting server in a directory only I can access. It is never shared with third parties, never synced elsewhere, and deleted on request to hello@xtrkrapp.com.
Standard server logs. Like every web server in existence, my hosting provider (Hostinger) maintains standard access logs at the infrastructure layer that I do not directly control. These are governed by Hostinger’s own privacy policy.
XtrkR does not currently integrate with Apple Health. It does not read data from or write data to Apple Health. If Apple Health integration is added in a future version, this Privacy Policy will be updated to describe the specific data flows involved.
XtrkR can optionally create encrypted backups to your iCloud Drive. This feature is off by default and only works if you choose to enable it. Backups are encrypted on your device using AES-256-GCM before being saved to your personal iCloud Drive. I cannot access, decrypt, or read those backup files.
If you tip to support development, the app keeps tip records (counts, amounts, currency, dates, and Apple transaction identifiers, with no health, encounter, or partner data) on your device for the supporter thank-you content. I can’t access them.
XtrkR stores your PIN hash and, if you enable backups, your backup-related credentials in the device Keychain. A small set of non-health flags also lives in the Keychain: your trial start date (so the free trial cannot be reset by reinstalling), your age-verification date of birth (so the 18+ gate persists), program or purchase markers (early-tester, launch-offer, purchase-credit, and supporter flags), and housekeeping state such as failed-PIN-attempt counts, lockout times, your biometric-unlock setting, and dates the app uses to detect clock changes and avoid repeating one-time screens. Keychain data is protected by iOS device security and is not synced to iCloud Keychain.
If you choose to add a location to an encounter, that location information is stored locally in the app on your device. If you use the geocoding feature, XtrkR sends those coordinates to Apple’s MapKit service to translate them into a city or place name. XtrkR may also send city names you previously saved to Apple’s geocoding service: for example, background passes at app launch and after a restore or import that resolve previously saved place names, or when rendering your saved locations on the in-app map. These requests go to Apple and are subject to Apple’s privacy terms; your location data is never sent to any server I operate, and I never receive or store it. If you type in the location search, the text you type is sent to Apple’s MapKit service to suggest matching places, and viewing the in-app map loads map imagery from Apple for the area shown. If you never add or search for locations, none of your location data leaves your device.
If you choose to add a planned encounter to your calendar, XtrkR creates an event in a dedicated calendar (named “XtrkR”) in the iOS Calendar database, with your permission via the standard iOS calendar prompt. Anything written there is visible in your Calendar app and syncs wherever your calendar account syncs (e.g., iCloud or Google, per your own calendar settings). This is off unless you use the feature, and you can delete the XtrkR calendar at any time in the Calendar app.
If you choose “Save to Contacts” on a partner, XtrkR creates a contact card (name, the notes on the partner, and the partner’s saved location as a postal address, if you recorded one) in the iOS Contacts database, with your permission via the standard iOS contacts prompt. Anything written there is visible in your Contacts app and syncs wherever your contacts sync (e.g., iCloud, per your own settings). This only happens when you explicitly tap the option, and you can delete the contact at any time.
Photos and videos you choose to save in XtrkR are stored locally in the app on your device. If you create an encrypted backup, those photos and videos can be included in that backup. XtrkR does not upload your photos or videos to servers I operate or share them for advertising or analytics purposes. If you choose to save a photo, video, or share card to your Photos library, that copy lives in the iOS Photos library and syncs according to your own iCloud Photos settings.
All payment processing for in-app purchases is handled by Apple through StoreKit. I do not receive or store your payment card information.
Notifications are generated locally on your device, not pushed from a server. Discreet mode (on by default) uses generic titles for privacy.
XtrkR carries an 18+ rating on the Apple App Store. To use XtrkR, you must be at least 18 years old; on first launch, the app prompts for your date of birth and will not unlock until you reach 18. I do not knowingly process data from anyone under 18.
Since your in-app health records are stored locally, you have direct control over those records. Delete individual records in the app, or delete the app to remove your health data; anything you exported, backed up, or saved to Calendar, Contacts, or Photos stays where you put it. The Keychain items described above, including your PIN hash, any backup credentials, and the non-health flags (trial start date, age-verification date of birth, and program or purchase markers), persist through app deletion; the non-health flags do so by design, to prevent trial resets and repeat age prompts. None of them contain health information. Because XtrkR does not keep a server-side copy of your records, there is no separate deletion request process through me for data stored only on your device.
If you choose to email me at hello@xtrkrapp.com, abuse@xtrkrapp.com, or any of the alias addresses, your message lands in a Google (Gmail) inbox that I control. Email is outside the app’s on-device design: it is ordinary business email, handled with ordinary business tools, under Google’s standard privacy terms.
What I ask of you: please don’t include personal health details (specific medications, test results, partner names, diagnoses) when you write to me. I can almost always help without them.
Security: the Google account uses strong two-factor authentication. Nothing is unbreachable, which is the main reason I ask you to leave health details out of what you send me.
Because the app does not store your data on any server I operate, I have nothing to produce in response to a subpoena, court order, or legal request about your in-app records. If you have emailed me support requests that contain health details, those emails could in principle be reached by a subpoena to me or to Google, which is another reason I ask you not to include health details in the first place. Your device itself may be subject to a warrant or physical seizure by law enforcement; this applies to all data on your phone, not just XtrkR. If you use encrypted iCloud backups, Apple could be compelled to produce the encrypted file, but the file is encrypted with a password I never receive.
XtrkR is designed so that the records you enter are accessible to you on your device, can be deleted by you at any time, and can be exported by you in CSV or encrypted backup form. Because XtrkR does not keep a server-side copy of those records, there is generally no separate access, correction, or deletion workflow through me for data stored only on your device. I do not sell your personal information or disclose your health records for advertising or analytics purposes.
If you believe your personal data has leaked, someone has content about you in their XtrkR, you encounter non-consensual intimate imagery, or you have any other privacy concern, please email abuse@xtrkrapp.com.
Response time: I aim to respond to abuse and privacy reports within 72 hours. As a solo operator, that’s an honest timeline, not a 24-hour promise I can’t keep.
What I can do: Triage bug reports and answer privacy questions. For non-consensual intimate imagery or imagery of minors, I will coordinate with law enforcement and, where relevant, file a report with NCMEC’s CyberTipline.
What I can’t do: Reach into a user’s device to delete content. XtrkR has no server access, no accounts, no cloud sync I control; the data lives on the user’s phone and, if they enable it, in their own encrypted iCloud Drive backup. Reports are handled by triage and, where applicable, referral to law enforcement or NCMEC, not remote deletion.
If I update this policy, I will update the “Last updated” date. Given the app’s local-storage architecture, meaningful changes would likely only occur if the app’s fundamental design or data flows change.
General inquiries, bug reports, and feature requests: hello@xtrkrapp.com
Abuse or privacy concerns (72-hour response): abuse@xtrkrapp.com