Privacy Policy
1. About This Policy
This Policy explains how Trero obtains, uses, stores, and deletes user information. Please review it before using the app.
2. Information Collected
| Category | Main items | Purpose |
|---|---|---|
| Account data | UID, email address, display name, auth provider data, creation timestamp | Sign-in, account management, public profile sync |
| Workout logs | Exercise ID, exercise name, muscle group, date, set number, weight, reps, memo, logged timestamp | History, analytics, goal progress calculation, and CSV export features |
| Body composition data | Weight, body fat %, muscle %, waist, memo, recorded timestamp | Body composition history, charts, derived metrics such as BMI |
| Social data | Public profile, friend requests, accepted relationships, blocks, reports, reactions | Providing friend and reaction features |
| Local settings and on-device data | Unit system, height, goal weight, rest timer sound, completion counts used for in-app prompts, onboarding state, locally saved profile image | Preferences, calculations, and on-device user experience |
| Usage analytics data | Event information such as sign-in type, onboarding completion, workout start/finish, goal creation/update, body-record save, paywall exposure, and share actions, plus usage-state properties such as sign-in state and plan type. | App improvement, usage understanding, and feature-flow evaluation |
| Biometric sign-in credentials | Saved email-login credentials in Keychain | Face ID / Touch ID sign-in |
Collected information is used for account features, history display, analytics features, friend features, usage measurement, and support. Stored data and usage analytics data are handled separately for different purposes.
3. Optional Access
- HealthKit: Used to write weight and body fat percentage when saving, and to manually import the latest values from the body-record screen. Core app functions remain available if permission is not granted.
- Notifications: Used for rest-timer completion, a same-day 20:00 reminder when no workout has been logged, and a weekly summary every Monday at 09:00.
- Camera: Used to scan QR codes for adding friends.
- Face ID / Touch ID: Used for biometric sign-in when saved credentials are available.
4. Third-Party Services
| Service | Provider | Purpose |
|---|---|---|
| Firebase Authentication | Google LLC | Email / Apple authentication |
| Cloud Firestore | Google LLC | Storage of user, workout, body composition, and social data |
| Cloud Functions | Google LLC | Server-side processing for some features |
| Firebase Analytics | Google LLC | Usage measurement, app improvement, and feature-flow evaluation |
| StoreKit / App Store | Apple Inc. | Purchase, restore, and entitlement checks for Trero Pro |
| Apple Health | Apple Inc. | Write on save and manual import for weight and body fat percentage |
5. Storage Locations
- Cloud storage: Account, workout, body composition, and friend-related data are stored on Firebase / Google Cloud.
- Usage analytics: Event information and usage-state properties may be processed on Google infrastructure through Firebase Analytics.
- On-device storage: Settings values, onboarding state, completion counts used for guidance display, profile images, workout caches, and Keychain credentials are stored locally.
- HealthKit-linked data: Read and written within the scope of Apple Health permissions.
6. Data Deletion
You can delete your account from the in-app Settings screen. Email accounts and Apple accounts may require re-authentication before deletion. After account deletion, related cloud-stored data and authentication information are removed in sequence.
7. Children's Privacy
The app is not intended for children under 13, and it is not designed to intentionally collect personal information from children under 13.
8. Contact
Email: freetokyo2020@yahoo.co.jp
How the Android version handles your data
The following describes the Android version (Android 9.0 and later). Everything above applies to iOS; only the points below differ on Android.
The Android version uses the same Cloud Firestore backend as the iOS version. Firebase Authentication signs you in, and your records are stored on Google's infrastructure under your account (storage and deletion work exactly as described for iOS above). The on-device database acts as a local copy.
Both cloud backup and device-to-device transfer are disabled (allowBackup="false" plus data_extraction_rules.xml). When you change devices, just sign in again — your records live on the server under your account and come back with you.
With your permission, Trero uses Health Connect on your device. It reads body fat and weight. It writes body fat, exercise and weight.
Health data handled through Health Connect is used solely to calculate and display results inside the app. It is never used for advertising, shared with data brokers, or disclosed to third parties. You can revoke Health Connect permission at any time in your device settings.
The only external services used are Firebase Authentication (sign-in), Cloud Firestore (storing and syncing your records) and Google Play Billing (purchases). Google processes all payments; card details never reach the developer.
The only device permissions the app requests are showing notifications and exact-time reminders. Each is asked for only when you use the matching feature, and declining leaves the rest of the app usable.
Uninstalling the app does not delete the data tied to your account. To remove it, delete your account from the app's settings screen (the same procedure described for iOS above).
Controller, contact and your rights
This app is provided by freetokyo, an independent developer, who acts as the data controller. For any question about this policy or about personal data, contact freetokyo2020@yahoo.co.jp. We normally reply within five business days.
If you are in the EU, the EEA or the UK, the GDPR gives you the right to access, rectify, erase, restrict and port your personal data, to withdraw consent and to object to processing. You may also lodge a complaint with your national supervisory authority.
If you are a California resident, the CCPA/CPRA gives you the right to know, delete and correct the personal information collected about you, and to opt out of its sale or sharing. We do not sell or share personal information.
Where this app stores data only on your device, we have no access to it, so most of these rights are exercised directly on the device: delete or export inside the app, or delete the app. We will still answer any request you send us.
Retention: on-device data is kept until you delete it or remove the app. Support emails are deleted 24 months after the request is closed.