Privacy Policy
Effective 24 July 2026
The short version. Lensatic records your training on your phone and keeps it there. Nothing is uploaded until you create an account and turn on cloud backup. There is no advertising, no analytics, and no third-party tracking in the app — your routes, heart rate, and workout history are never sold, rented, or shared for marketing.
Who is responsible
Lensatic is an independent app built and operated by an individual developer, not a company, and is not affiliated with or endorsed by the U.S. Department of Defense or any military service. Questions about this policy or your data: privacy@lensatic.fit.
What stays on your device
By default, everything. The app stores all of the following in a private database on your phone, inside the app's own sandbox, where no other app can read it:
- Recorded activities — GPS route points, distance, pace, elevation, duration, and calorie estimates for runs, rucks, and land-nav sessions
- Heart-rate samples, when you connect a chest strap or import them from Health Connect
- Strength and conditioning workouts, sets, reps, and loads
- Fitness-test results and assessment baselines
- Your selected pipeline, plan progress, targets, achievements, and pace counts
- App settings and units
Uninstalling the app deletes this database and everything in it. If you have never enabled cloud backup, that is the end of your data — there is no copy anywhere else.
Location
The app requests location access so it can measure a run, ruck, or land-nav leg. Precise location is required for distance, pace, splits, and the route map — an approximate location cannot produce those numbers.
Background location. If you grant it, the app keeps recording while your screen is off or another app is in front, which is what makes a two-hour ruck usable. Android shows a permanent notification the entire time a recording is running. Location is collected only while a session is actively recording — never in the background at other times, and never to build a profile of where you go.
Location data is written to the on-device database. It leaves your phone only as part of a synced activity, if you have turned on cloud backup.
Health and fitness data
With your permission, Lensatic connects to Android Health Connect to read heart rate recorded by your watch or band, so a workout has heart-rate data even without a chest strap, and to write your completed runs, rucks, distance, calories, and heart rate back so other fitness apps can see them. It reads only heart rate, and only for sessions you are logging.
Data obtained through Health Connect is used for one purpose: showing you your own training. Specifically, it is never used for advertising or marketing, never sold or transferred to data brokers, information resellers, or advertising platforms, and never used to train machine-learning or AI models. You can revoke Health Connect access at any time in Android settings, and it is entirely optional — the app works without it.
Bluetooth. Heart-rate strap support uses Bluetooth to talk to the sensor you choose. The app does not use Bluetooth to derive your location, and does not scan for or catalogue nearby devices for any other purpose.
Optional account and cloud backup
Cloud backup is off until you create an account. If you do, the following is stored on servers operated by Supabase in the United States:
- Your email address, and a password stored only as a cryptographic hash
- The training records listed above — activities with their route data, workouts, plan progress, active plans, fitness profile, pace counts, achievements, and settings
Each account can read and write only its own rows; this is enforced by the database itself, not just by the app. The purpose is backup and moving your history to a new phone. This data is not used for advertising, is not shared with anyone else, and is not sold.
You can sign out at any time from the profile screen, which stops syncing and leaves your local data intact.
The only other services involved
- Map tiles. Route maps are drawn with tiles from OpenFreeMap. Requesting a tile reveals your IP address and the approximate map area being viewed to that provider, as any map or web request would. No account, identifier, or training data is sent.
- Supabase. Hosts the optional account and backup database described above.
- Cloudflare. Serves this website. It does not receive data from the app.
There is no advertising network, no analytics or crash-reporting SDK, and no social-media tracker in the app.
Sharing a workout
When you share an activity, the app builds an image on your device and hands it to Android's share sheet. You choose where it goes. Nothing is published anywhere by default, and the app has no feed, no followers, and no public profiles.
Keeping and deleting your data
- On your phone: kept until you delete the activity or uninstall the app.
- In cloud backup: kept while your account exists. Deleting an activity in the app deletes it from the server too.
- Deleting your account: email privacy@lensatic.fit from your account address and the account and every row belonging to it will be erased within 30 days.
Security
Traffic between the app and the backup server is encrypted in transit with TLS. On-device data sits in the app's private storage, protected by Android's app sandbox and your device lock screen. No system is perfect, and this is an independently built app — treat cloud backup as convenience, not as an archive of record.
Children
Lensatic is built for adults preparing for military selection courses and is not directed at children under 13. It does not knowingly collect data from them.
Your rights
You can see everything the app holds about you inside the app itself, since that is the whole of it. To request a copy of what is in cloud backup, or its deletion, write to privacy@lensatic.fit. Depending on where you live you may have additional rights over access, correction, deletion, or portability; the same address handles those requests.
Changes
If this policy changes, the effective date above changes with it, and material changes will be noted in the app. Continuing to use Lensatic after a change means the updated policy applies.