1. Scope and key commitments
This Privacy Policy applies to the Trace mobile application, the trackwithtrace.com website, and related services operated by AppEcho Labs LLC (“AppEcho,” “Trace,” “we,” “us,” or “our”).
- We do not sell your personal information or health data.
- We do not use health data for targeted advertising, marketing profiles, data-broker products, or cross-app tracking.
- We do not send notes, symptom labels, medication names, severity values, report contents, Apple Health values, or Apple Health permission choices to analytics or attribution providers.
- You can use Trace without connecting Apple Health, and you control what you export or share.
Trace is a consumer wellness and personal-record tool. AppEcho is not a health care provider, health plan, or health care clearinghouse, and Trace is generally not governed by the Health Insurance Portability and Accountability Act (“HIPAA”). Other privacy and consumer-health laws may apply. Our separate Consumer Health Data Privacy Policy provides additional disclosures and rights relating specifically to consumer health data.
2. Information we collect
Information you provide
- Account information: email address, authentication provider, account identifier, and any name provided by Apple, Google, or another sign-in provider.
- Health and wellness entries: symptoms, severity, mood, energy, meals, sleep, medications, interventions, menstrual or cycle context, possible triggers, notes, tags, daily impact, and other information you choose to track.
- Preferences and goals: templates, reminders, tracked factors, report preferences, onboarding responses, and settings.
- Communications: information you include in support, feedback, privacy, or other messages to us.
- Website submissions: an email address or other information you submit for early access, product updates, or support.
Information collected through the app
- Apple Health summaries: if you opt in, Trace may read sleep duration, step count, workouts, resting heart rate, and menstrual-flow information. Trace processes raw samples on your device and stores only daily summaries needed for features you use. Menstrual-flow information is not imported, analyzed, or displayed unless you separately enable cycle context in Trace.
- Weather context: if you enable automatic weather, Trace receives local conditions such as temperature, pressure, pressure trend, cloud cover, and condition category for today’s check-in.
- Subscription information: plan, entitlement status, trial status, purchase and renewal status, and expiration date. We do not receive your complete payment-card number.
- Technical and product-usage information: app version, platform, device and operating-system information, crash or diagnostic information, IP-derived technical logs, push-notification tokens, app lifecycle events, and limited feature events.
- Acquisition information: source, channel, campaign, ad-group, creative or keyword identifiers, storefront, referral or deep-link information, and non-health funnel events. Trace is configured not to collect IDFA, GAID, or other advertising identifiers.
Information Trace creates
Trace generates summaries, charts, reports, and cautious observations about associations in your entries. These are not diagnoses and do not establish that one factor caused or treated a symptom.
3. Sources of information
We receive information from:
- you, when you enter information or contact us;
- your device and the Trace app;
- Apple Health and Apple Weather, only when you enable the applicable feature and grant permission;
- sign-in providers such as Apple and Google;
- app stores and subscription infrastructure, including Apple and RevenueCat; and
- service providers supporting hosting, security, analytics, attribution, notifications, and customer support.
4. How we use information
We use personal information to:
- create and secure your account;
- save and sync check-ins, personalize tracking, surface patterns, generate reports, and provide features you request;
- process subscriptions, trials, renewals, and entitlements;
- send reminders and service communications you request;
- provide support and respond to privacy requests;
- maintain, troubleshoot, secure, and improve Trace without using your health content for advertising;
- measure non-health product usage and acquisition performance under the restrictions described below;
- detect fraud, abuse, security incidents, or violations of our Terms; and
- comply with law and enforce our legal rights.
5. How we disclose information
We disclose information only as reasonably necessary for the purposes below:
- Cloud and app operations: Google Firebase supports authentication, cloud storage, functions, synchronization, and messaging.
- Sign-in: Apple and Google process information when you choose their sign-in services.
- Subscriptions: Apple, Google Play where applicable, and RevenueCat process purchases and subscription entitlements.
- Restricted analytics: PostHog receives only allow-listed product events and non-health properties.
- Restricted attribution: AppsFlyer receives limited acquisition and non-health funnel information, without advertising identifiers or health content.
- Professional advisers and vendors: lawyers, auditors, security providers, and support vendors may receive the minimum information needed to perform services for us under confidentiality obligations.
- Legal and safety reasons: we may disclose information when we reasonably believe it is required by valid law or legal process, or necessary to protect rights, safety, and security. We review requests and may challenge overbroad or inappropriate demands where permitted.
- Business transaction: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and protections consistent with this policy.
- At your direction: when you export a report or use your device’s share sheet, the recipient and destination are chosen by you. Once shared, the recipient’s practices control that copy.
Service providers may process information only to perform services for us or as otherwise permitted by law. We do not permit them to use Trace health data for their own advertising.
6. Apple Health and location
Apple Health
Apple Health access is optional and read-only. Trace does not write to Apple Health. You choose which supported data types to permit in Apple’s system settings and can change those permissions there. Trace treats missing data as unavailable, not as a zero or proof that permission was denied. Apple Health data is used only to provide health and wellness features you request and is never used for advertising, marketing, data-broker products, or unrelated profiling. Deleting information in Trace does not delete the original information from Apple Health.
Location and Apple Weather
Trace requests location only if you enable automatic weather. Precise coordinates are handled within the device’s native Apple Weather flow solely to request current local conditions. AppEcho does not receive, store, log, export, or send your coordinates to analytics, and does not join them to your health profile. Your device communicates with Apple Weather under Apple’s terms and privacy practices. Trace may store the resulting weather category with today’s check-in so you can review or exclude it.
7. Analytics and attribution
Trace uses PostHog for limited product analytics and AppsFlyer for limited acquisition attribution. We configure these services for a health app: no session replay, no advertising identifier, no behavioral-advertising audience building, and no health-content payloads. For Apple Ads, AppsFlyer receives Apple's privacy-preserving standard attribution payload without IDFA or an App Tracking Transparency prompt.
Allow-listed analytics may include events such as onboarding completion, a check-in being completed, a reminder being enabled, a report being created, a paywall being viewed, or a subscription beginning. Event properties are limited to non-sensitive information such as platform, app version, plan type, or a non-sensitive template category. After sign-in, PostHog may use your Firebase user ID—not your email—as a product-analytics identifier. AppsFlyer is not given your Firebase user ID; its attribution remains associated with an install-scoped AppsFlyer identifier and must not be joined to your health entries for advertising or profiling.
8. Retention and deletion
We keep account, preference, and health information while your account is active and as needed to provide Trace. You may delete individual entries at any time. You may also request an export or delete your account in Trace settings.
When account deletion succeeds, Trace removes the account’s profile and check-ins from active production systems. Deletion from archived or backup systems may take up to six months, where permitted by law; backup copies are isolated from ordinary use until overwritten. We may retain limited non-health records when reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, enforcing agreements, or documenting a privacy request. We may retain aggregated or deidentified information that cannot reasonably be linked back to you.
App-store transaction records are controlled by the applicable store and may remain subject to its retention rules. Deleting Trace does not cancel an active subscription; cancel through your app-store account.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, data minimization, and restricted analytics. No system is perfectly secure, and we cannot guarantee absolute security. Protect your device and credentials, and contact us promptly if you suspect unauthorized access.
If a qualifying breach occurs, we will provide notices required by applicable law, including the Federal Trade Commission’s Health Breach Notification Rule where it applies.
10. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- confirm whether we process your personal information;
- access or receive a portable copy of information;
- correct inaccurate information;
- delete information;
- withdraw consent for future processing;
- opt out of sale, targeted advertising, or certain profiling (Trace does not sell personal information or use it for targeted advertising); and
- appeal a decision on your privacy request.
Use the export and deletion controls in Trace settings or email support@trackwithtrace.com. Put “Privacy Request” in the subject and describe the right you want to exercise. We may verify your identity before acting. If we deny a request, you may appeal by replying with “Privacy Appeal” in the subject. We will not unlawfully discriminate against you for exercising privacy rights.
You may use an authorized agent where applicable. We may request proof of authorization and verify your identity directly. If we cannot resolve a concern, you may contact your state attorney general or privacy regulator.
11. Age requirement
Trace is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and delete it as appropriate.
12. U.S. processing
AppEcho is based in the United States. Trace and its service providers may process information in the United States and other countries where privacy laws may differ from those where you live. Trace is currently offered under this U.S.-focused policy and is not directed to jurisdictions where our processing would be unlawful.
13. Changes to this policy
We may update this policy as Trace changes or law requires. We will post the revised policy with a new effective date and provide additional notice when a change is material. Where required, we will ask for consent before collecting, using, or disclosing health data in a materially new way.
14. Contact us
AppEcho Labs LLCAlexandria, Virginia 22304
United States
support@trackwithtrace.com