Privacy Policy

Sprinting Gear Circuit

Effective date: 2026-10-07

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Sprinting Gear Circuit stores practice template names, group names, available equipment, ordered exercise requests, template identifiers and modification timestamps on your iPhone. Level completion, the current round, undo history, hints, language, sound and motion preferences, and the cached daily challenge are also stored locally. A random installation secret is created automatically and kept in iOS Keychain; pending synchronization requests, including the secret needed to authorize them, are stored in a private local SQLite queue. The backend receives practice templates and modification timestamps, stores them in PostgreSQL under a SHA-256 hash of the installation secret, and keeps deletion markers and revoked-secret hashes. Progress and app preferences are not sent to the backend. Requests to the API and public website expose network information such as IP address, request path, time and response status to the hosting infrastructure. There is no user account, advertising identifier, location collection or analytics SDK. Permanently rejected template requests remain in a separate local SQLite recovery area, with the original local session available for editing. They are removed from that recovery area when a corrected save or deletion succeeds.

How we use information

Local storage makes all four modes playable without a connection and preserves your sessions after reopening the app. The installation secret restricts server access to this installation. Template data is used only to synchronize your practice sessions and resolve newer edits. The daily challenge endpoint returns a date and one of the bundled offline puzzle levels without identifying an installation. Deletion markers prevent stale requests from restoring a deleted template; revoked-secret hashes prevent old requests from recreating deleted installation data. Infrastructure request information and minimal application error messages support operation, abuse prevention and fault diagnosis.

Service providers and sharing

The application backend and its PostgreSQL database are hosted on Railway, which processes requests and infrastructure logs to provide the service. The iOS app uses Apple system networking, Keychain and local notification services. Local reminders do not use a remote push provider. No advertising, analytics, email delivery, social login or other external data integration is installed. Template contents and installation secrets are not deliberately written to application logs. Hosting infrastructure may retain request metadata under its own operational practices. Data is not sold or shared for advertising.

Data retention

Local records remain until you delete them or remove the app. The Keychain secret may survive app removal under iOS behavior, so use Delete all my data before uninstalling if you want an explicit deletion request. Templates remain in the live server database until you delete a template or all installation data. Template deletion removes its content but retains its identifier, timestamp and installation hash as a synchronization deletion marker. Deleting all installation data removes templates and their markers; the revoked installation hash and revocation time remain to prevent replay. No automatic expiry for these technical records is configured. Application data and the pending queue are excluded from normal iCloud device backup by the app. This deployment does not configure scheduled database backups; any infrastructure recovery copies and logs are governed by Railway operations, and no fixed retention period or immediate purge of every infrastructure copy is promised.

Deleting your information

Delete a practice template from Practice Run to remove its local copy and queue the matching server deletion. Delete all my data in Settings clears local progress, templates, preferences, the daily cache and the Keychain secret, cancels reminders, and retains only the pending authorized server-deletion request until it succeeds. If offline, server deletion is delayed until the app reconnects; keep the app installed and open it online to allow that request to complete. Server deletion revokes the old secret and removes its live template data. A new installation secret is used for later templates. Losing the secret without completing deletion means the app cannot recover or identify those records through login. Contact dulciegreenaway@icloud.com for privacy questions, without sending your installation secret.

Permissions and your choices

The only optional permission is local notifications for a daily reminder. The app requests it only when you enable the reminder in Settings. You can turn off the reminder in the app or withdraw notification permission in iPhone Settings; iOS will then prevent delivery. No camera, microphone, contacts, photos or location permission is requested. The game, templates and planner remain usable when reminders are denied.

Your privacy rights

You can view and edit your templates in Practice Run and delete templates or all installation data using the app controls. Depending on where you live, you may have rights to access, correct, delete or restrict processing of personal data and to complain to a relevant data protection authority. Direct privacy requests to dulciegreenaway@icloud.com. Because there is no account or verified email identity, we may need enough non-secret information to understand a request and cannot promise to recover data after loss of the installation secret. Do not include confidential player details in group names.

Security

Production API requests use HTTPS. The server validates each installation token and scopes database operations to its hash, validates template shape and sizes, and uses database transactions for conflict handling and deletion. The installation secret is randomly generated per installation and stored in Keychain with device-only access after first unlock. Local files and the queue reside in the app sandbox under iOS device protection; the app does not add a separate encryption layer to the queued requests. Server database credentials stay in the hosting environment and are not embedded in the app. No method of storage or transmission is guaranteed to be completely secure.

Children’s privacy

The product is intended for coaches and recreational players, not as a service designed to collect children’s personal information. It does not request ages or create player accounts. Coaches should use neutral group labels and avoid entering children’s names or sensitive information in templates. A parent or guardian who believes personal information about a child was entered may use the deletion controls on that installation or contact dulciegreenaway@icloud.com.

Changes to this policy

This policy describes the current app and backend practices. If these practices change, the policy at /privacy will be updated and its effective date changed. Material changes may also be explained in the application. Review this page when you want to see the current policy. Privacy contact: dulciegreenaway@icloud.com.