Privacy Policy
Effective 27 July 2026
The short version. Lensatic records your training on your phone and keeps it there. Nothing is uploaded until you create an account and turn on cloud backup. Nothing is shown to another person unless you separately switch on leaderboards, which are off by default and share a username and three numbers — nothing else. There is no advertising and no third-party tracking in the app, and no analytics of your training — the one exception is that signing in with Google lets Google collect data for its own analytics, which is explained below and easy to avoid. Your routes, heart rate, and workout history are never sold, rented, or shared for marketing.
Who is responsible
Lensatic is an independent app built and operated by an individual developer, not a company, and is not affiliated with or endorsed by the U.S. Department of Defense or any military service. Questions about this policy or your data: [email protected].
What stays on your device
By default, everything. The app stores all of the following in a private database on your phone, inside the app's own sandbox, where no other app can read it:
- Recorded activities — GPS route points, distance, pace, elevation, duration, and calorie estimates for runs, rucks, and land-nav sessions
- Heart-rate samples, when you connect a chest strap or import them from Health Connect
- Strength and conditioning workouts, sets, reps, and loads
- Fitness-test results and assessment baselines
- Your selected pipeline, plan progress, lesson and course progress, targets, achievements, and pace counts
- Daily check-ins — sleep, soreness, energy, motivation, resting heart rate, and any notes you add
- Sleep recorded by a tracker, if you connect Apple Health or Health Connect — how long you slept and when, kept separately from what you report yourself in a check-in
- Body weight over time — the weigh-ins you enter, and any a scale writes to Apple Health or Health Connect
- Wear & Tear — the body area, side, severity over time, and notes for any ache or injury you choose to record
- Nutrition — a daily total of calories and protein, carbohydrate and fat, read from Apple Health or Health Connect if you connect them. Daily totals only; the app never reads or stores the individual foods you logged
- App settings and units
Check-ins, aches and nutrition are on your device only. They are not uploaded even when cloud backup is on, they are never part of a leaderboard, and no one else can see them. Profile → Danger Zone → Delete all data erases them along with everything else.
Uninstalling the app deletes this database and everything in it. If you have never enabled cloud backup, that is the end of your data — there is no copy anywhere else.
Location
The app requests location access so it can measure a run, ruck, or land-nav leg. Precise location is required for distance, pace, splits, and the route map — an approximate location cannot produce those numbers.
Background location. If you grant it, the app keeps recording while your screen is off or another app is in front, which is what makes a two-hour ruck usable. Android shows a permanent notification the entire time a recording is running. Location is collected only while a session is actively recording — never in the background at other times, and never to build a profile of where you go.
Location data is written to the on-device database. It leaves your phone only as part of a synced activity, if you have turned on cloud backup.
Health and fitness data
With your permission, Lensatic connects to Android Health Connect — or Apple Health on iPhone — so that data your other devices and apps already record does not have to be entered twice. It is entirely optional, and the app works without it.
What it reads, and why each one:
- Heart rate — so a session has heart-rate data even without a chest strap
- Workouts and distance — so a run or swim recorded on a Garmin, Samsung or Apple Watch appears in your log without being re-entered
- Sleep — so a night can be shown against the session that followed it
- Body weight — because weight feeds the calorie model for rucking, where a stale figure quietly skews every estimate
- Biological sex (Apple Health only) — to select the correct fitness-test scoring scale
- Nutrition — daily calories and macros, if you log food in MyFitnessPal, Cronometer or a similar app, so your eating can be shown against your training. Daily totals only; the individual foods you logged are never read
It writes back your completed runs, rucks, distance, calories, heart rate and route, so other fitness apps can see them.
Data obtained through Health Connect is used for one purpose: showing you your own training. Specifically, it is never used for advertising or marketing, never sold or transferred to data brokers, information resellers, or advertising platforms, and never used to train machine-learning or AI models. You can revoke Health Connect access at any time in Android settings, and it is entirely optional — the app works without it.
Bluetooth. Heart-rate strap support uses Bluetooth to talk to the sensor you choose. The app does not use Bluetooth to derive your location, and does not scan for or catalog nearby devices for any other purpose.
Optional account and cloud backup
Cloud backup is off until you create an account. If you do, the following is stored on servers operated by Supabase in the United States:
- Your email address, and a password stored only as a cryptographic hash
- The training records listed above — activities with their route data, workouts, plan progress, active plans, fitness profile, pace counts, achievements, and settings
Each account can read and write only its own rows; this is enforced by the database itself, not just by the app. The single exception is the opt-in leaderboard described below, which is off unless you turn it on. The purpose is backup and moving your history to a new phone. This data is not used for advertising, is not shared with anyone else, and is not sold.
You can sign out at any time from the profile screen, which stops syncing and leaves your local data intact.
Leaderboards
Leaderboards are off by default. You are not on them, and nothing about you is visible to any other user, until you turn on the switch at Profile → Leaderboards. They require an account and a username, because a leaderboard identifies people by handle.
When you turn them on, other signed-in users can see:
- Your username — the handle you chose, not your email address, which is never shown to anyone
- Your total miles this week, and your miles under a pack this week
- Your current streak of consecutive days trained
- Your position in each of those three rankings
That is the complete list. Routes, maps, individual sessions, dates, times, pace, heart rate, body weight, pack weight, fitness-test results, check-ins, and aches are never visible to another user, and there is no way to reach any of them from a leaderboard. There is no feed, no followers, no profile page, and no messaging.
The rankings are calculated on the server from activities you have already synced, and the server sends back only a list of usernames and numbers. Sessions you typed in by hand are excluded from leaderboards, so a ranking reflects sessions the app recorded or read from a watch.
Your timezone — for example America/New_York — is stored with your profile when you join, and is used for one thing: deciding when your week and your day begin, so a Sunday evening session is counted in the right week. It is not a location and is not used as one.
Turning the switch off removes you immediately. Nothing is cached, so you disappear from every board as soon as it is next drawn, and your username stops being visible to other users. Deleting your account removes you as well.
The only other services involved
- Map tiles. Route maps are drawn with tiles from OpenFreeMap. Requesting a tile reveals your IP address and the approximate map area being viewed to that provider, as any map or web request would. No account, identifier, or training data is sent.
- Signing in with Apple or Google. Both are optional — an email and password works just as well, and neither is used unless you choose it. Whichever you pick, all this app receives is a token confirming the account is yours. We never receive your password. Google’s sign-in software collects more than that for Google’s own purposes: Google’s published declaration lists your name, email address, phone number, approximate location, device identifier and app usage — some of it for their analytics. That data goes to Google, not to us; we never see it, and we cannot switch it off while offering Google as an option. The app tells you this before the Google sheet opens, and backing out costs nothing. Sign in with Apple publishes no such declaration and collects none of it.
- Supabase. Hosts the optional account and backup database described above.
- Cloudflare. Serves this website. It does not receive data from the app.
There is no advertising network, no crash-reporting SDK, and no social-media tracker in the app, and nothing here analyzes your behavior for us. The single exception is the sign-in software described above: if you choose Google, Google collects data for its own analytics. Choose Apple or an email address and no analytics of any kind are involved.
Sharing a workout
When you share an activity, the app builds an image on your device and hands it to Android's share sheet. You choose where it goes. Nothing is published anywhere by default, and the app has no feed, no followers, and no public profile pages. The one place other users can see anything about you is the opt-in leaderboard described above.
Keeping and deleting your data
- On your phone: kept until you delete the activity or uninstall the app.
- In cloud backup: kept while your account exists. Deleting an activity in the app deletes it from the server too.
- Deleting your account: use Profile → Danger Zone → Delete account in the app, which erases the account, every row belonging to it, and the copy on your phone immediately. You can also email [email protected] from your account address and it will be done within 30 days. See Delete Your Account for the detail of what is removed.
Security
Traffic between the app and the backup server is encrypted in transit with TLS. On-device data sits in the app's private storage, protected by Android's app sandbox and your device lock screen. No system is perfect, and this is an independently built app — treat cloud backup as convenience, not as an archive of record.
Children
Lensatic is built for adults preparing for military selection courses and is not directed at children under 13. It does not knowingly collect data from them.
Your rights
You can see everything the app holds about you inside the app itself, since that is the whole of it. To request a copy of what is in cloud backup, or its deletion, write to [email protected]. Depending on where you live you may have additional rights over access, correction, deletion, or portability; the same address handles those requests.
Changes
If this policy changes, the effective date above changes with it, and material changes will be noted in the app. Continuing to use Lensatic after a change means the updated policy applies.