Privacy Policy

We believe privacy is a right, not a feature. This document explains in plain English exactly how TrackTogether handles your data. No legalese traps, no hidden clauses.

Last updated: June 28, 2026Applies globally to all TrackTogether users
TLS 1.2+ Encryption
bcrypt Password Hashing
We Never Sell Your Data
Zero Ad Trackers
No Tracking Cookies
01

Our Commitment to Your Privacy

At TrackTogether, privacy is not a checkbox - it is a design principle. We built this platform with the belief that you should always know exactly what data we hold about you, why we hold it, and what we do with it. We do not sell your data, we do not broker it, and we do not monetize it in any sneaky way.

This policy applies to all users of the TrackTogether web application, API, and any related services (collectively, the “Service”). By using the Service, you agree to the practices described here. If something is unclear, please reach out - we are always happy to explain in plain language.

02

Information We Collect

We collect only what we genuinely need to operate the Service:

  • Account information - your name, email address, and a securely hashed password when you sign up. We do not store your plain-text password, ever.
  • Profile information - an optional display handle, bio, and avatar you choose to share.
  • Usage data - tracker items, checklist states, planner tasks, feed activity, and comments you create inside the Service. This is the core content that makes TrackTogether work.
  • Collaboration data - workspace memberships, shared tracker links, and friend connections you establish.
  • Technical logs - standard server logs (IP address, browser user-agent, request timestamps) retained for up to 30 days solely for security monitoring and debugging. These are not tied to marketing profiles.

We do not collect payment card numbers (we use third-party processors where billing applies). We do not embed third-party advertising trackers. We do not fingerprint your browser.

03

How We Use Your Information

Your data is used exclusively to:

  • Authenticate you and keep your account secure.
  • Render your workspaces, trackers, planner boards, and feed.
  • Enable collaboration features - sharing trackers, inviting teammates, notifying you of updates.
  • Power AI integrations (MCP gateway) - API requests to Claude, ChatGPT, or other connected agents act on your behalf using session-scoped tokens. We do not forward your credentials to AI providers.
  • Diagnose errors and maintain the reliability of the platform.
  • Send transactional emails (password resets, collaboration invites). We do not send unsolicited marketing emails.

We process your data based on the legal grounds of contract performance (you signed up for the Service), legitimate interest (security and abuse prevention), and your explicit consent where required.

ChatGPT & Model Training Notice: We have explicitly configured our Custom GPT integration with OpenAI's model training opt-out. None of the conversation data, tracker records, or user prompts shared with the Custom GPT are used to train or improve OpenAI's language models.

04

Sharing & Disclosure

We do not sell, rent, or trade your personal information. Period. We share data with third parties only in these narrow circumstances:

  • Infrastructure providers - our hosting, database, and CDN vendors process data on our behalf under strict data processing agreements (DPAs). They have no independent right to use your data.
  • Collaborators you choose - when you invite someone to a workspace or share a public tracker link, that person can see the tracker content you have shared. You control this.
  • Legal requirements - we may disclose information if compelled by a valid court order or applicable law. We will notify you when legally permitted to do so and will narrow the scope of any disclosure to the minimum required.
05

Security & Compliance

We take security seriously and implement industry-standard controls to protect your data:

  • Encryption in transit - all traffic between your browser and our servers is encrypted using TLS 1.2+. We enforce HTTPS across every endpoint.
  • Encryption at rest - sensitive database fields and backups are encrypted at rest using AES-256.
  • Password hashing - passwords are hashed using bcrypt with a per-password salt. We never log or store plain-text credentials.
  • Session security - authentication tokens are signed, have defined expiry windows, and are invalidated on logout.
  • OAuth 2.0 - MCP integrations use short-lived, scoped OAuth tokens. We do not store third-party provider credentials.
  • Access controls - internal access to production systems is limited to authorized personnel, authenticated via multi-factor authentication, and logged.

While no system can guarantee absolute security, we continuously review our controls, patch dependencies promptly, and follow responsible disclosure practices. If you discover a security issue, please report it to security@tracktogether.app - we appreciate responsible researchers.

06

Your Rights & Controls

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access - request a copy of the personal data we hold about you.
  • Correction - update inaccurate or incomplete information at any time from your profile settings.
  • Deletion - request deletion of your account and all associated data. We will honor this within 30 days, except where we are legally required to retain certain records.
  • Portability - request an export of your data in a machine-readable format.
  • Objection & restriction - object to or restrict certain processing activities.

To exercise any of these rights, email us at privacy@tracktogether.app. We will respond within 30 days. We do not charge a fee for reasonable requests.

07

Cookies & Local Storage

We use a minimal set of cookies and browser storage mechanisms, all strictly necessary for the Service to function:

  • Authentication session cookie - keeps you logged in across page navigations. It is HttpOnly, Secure, and SameSite=Strict.
  • Theme preference - stored in localStorage to remember your dark/light mode choice. This never leaves your device.

We do not use advertising cookies, third-party tracking pixels, or any cookies that profile your behavior across other websites.

08

Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Active account data - retained indefinitely while your account exists.
  • Deleted account data - fully purged within 30 days of a deletion request, except where legal obligations require otherwise.
  • Server logs - retained for up to 30 days, then permanently deleted.
  • Backups - encrypted backups are retained for up to 90 days on a rolling basis.
09

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Service or applicable law. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify you via email or an in-app notice at least 14 days before the change takes effect.

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the updated terms.

10

Contact Us

We mean it when we say we care about your privacy. If you have a question, concern, or complaint that this policy does not address, please reach out:

We aim to respond to all privacy-related requests within 5 business days.

Privacy is not an afterthought here.

We built TrackTogether to help people collaborate and ship things - not to harvest their data. If you ever have a concern about how we handle your information, please just ask. We will give you a straight answer.