Privacy Policy
Last updated: August 6, 2026
This policy explains what data trackmyage ("we", "us") collects on trackmyage.com and app.trackmyage.com, what happens to it, and how to have it deleted. trackmyage is a health dashboard, so most of what you put into it is health data. Health data is sensitive, and this policy is written to be read, not skimmed.
The short version. We collect your email address and the health data you choose to add. It is stored in a database on our own server and used for exactly one thing: showing you your own dashboard. We do not sell it, we do not run advertising trackers, and you can have all of it deleted by sending one email to hello@trackmyage.com.
1. What we collect
Account
Your email address, plus when the account was created and last signed in. We do not ask for your name.
Wearable data, if you connect Garmin
To connect Garmin you enter your Garmin email and password once. They are used at that moment to sign in to Garmin and obtain access tokens. The password itself is not stored; the tokens are stored on our server and used to fetch your data on a schedule, roughly every 30 minutes. What we fetch and store: sleep sessions (times, duration, sleep stages, sleep score, resting heart rate, HRV), activities (type, duration, calories, heart rate), and daily metrics (VO2 max, fitness age, body battery, resting heart rate, HRV). Disconnecting Garmin in settings stops the syncing.
Meals
Photos you take of meals are resized and stored on our server, together with the meal description and the estimated calories and macros. Each photo is sent to Google's Gemini API once (again if you edit the meal) to produce those estimates.
Health check reports
A report you upload is sent to Google's Gemini API to extract the measured values: markers, numbers, units, reference ranges, and the examination date. Those extracted values are what we store. The report file itself is not stored; it is discarded after extraction. The extraction is instructed not to return names, clinic or doctor details, addresses, patient IDs, or any other identifier, so those never enter our database.
Manual entries
Whatever you type in yourself: weight, daily mood and energy check-ins, and your goal settings.
Server logs
Like almost every server on the internet, ours keeps standard technical logs, which include IP addresses. Traffic to the Service passes through Cloudflare, which sees the same standard connection data on the way.
2. What we do not collect
- No advertising trackers. We use one analytics service, DataFast, for aggregate visit counts on our pages; it is described in section 3 and it never sees your health data.
- No card details. Paid subscriptions are processed by Stripe, and the card details you enter go to Stripe, never to our servers. What we do store is your subscription status and Stripe's identifiers for your customer and subscription records. The first 9 people never pay and have no payment data anywhere.
- We do not sell personal data, and we do not use your data to train AI models.
3. Who else processes your data
Six third parties touch data, each for one narrow job:
- Google Gemini API. Receives meal photos and uploaded report files to produce the analysis you asked for, under Google's API terms. This is the only place your photos and reports go.
- Garmin. If you connect it, we fetch your data from your Garmin account using the stored tokens. Garmin's own handling of your data is covered by Garmin's privacy policy.
- Google sign-in. If you sign in with Google, Google tells us your verified email address. We store the email address and nothing else from Google.
- Cloudflare. Sits in front of our server and proxies all traffic, as it does for a large part of the internet.
- DataFast. Analytics (datafa.st) on our web pages. It tells us in aggregate how many people visit and which pages they view. It never receives anything you store in your account.
- Stripe. Handles payment for paid subscriptions. Stripe receives your email address and the payment details you enter on Stripe's own checkout page; what we get back is your subscription status.
Nobody else gets your data. There is one deliberately public number: the landing page shows how many people have signed up. That is a single aggregate count and contains nothing about any individual.
4. Where your data lives
Everything is stored in a database and photo folder on a server we operate. Your dashboard is visible only to your own account and to server administration. Cookies used: a signed session cookie (bodyage_session, 30 days) that keeps you signed in, and a short-lived cookie during Google sign-in. No third party cookies.
5. How long we keep it, and how to delete it
Your data is kept for as long as your account exists, because showing long term trends is the point of the Service. Sign-in links expire after 7 days. Deleting a meal deletes its photo from the server. To delete your account and everything in it, email hello@trackmyage.com from your account address and we will delete it and confirm, within 30 days at the latest.
6. Security
Connections are encrypted with TLS, session cookies are signed and inaccessible to page scripts, sign-in tokens are stored only as hashes, and access to the server is restricted. No system is perfectly secure, and we do not promise otherwise, but health data is treated here as what it is: the most sensitive thing on the box.
7. Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it, at any time, by emailing hello@trackmyage.com. Where laws such as the GDPR apply to you, these are your legal rights; we honor the same requests for everyone regardless of where you live.
8. Children
The Service is not directed at children and is only for people 18 or older. We do not knowingly collect data from anyone under 18.
9. Changes to this policy
If this policy changes, the date at the top changes with it. If a change means your data is used in a new way, we will point it out inside the Service before it takes effect, not after. The same applies if trackmyage is ever sold or handed to a new owner: we will tell you before your data changes hands, and you can have your account deleted first.
10. Contact
Privacy questions and deletion requests: hello@trackmyage.com.