← Back to App All Apps
PunchTrack

Privacy Policy

PunchTrack for iOS · View app page

Privacy Policy

Effective date: May 2, 2026 · Last updated: July 18, 2026

The microphone never records. Audio is analyzed in memory to detect punches and immediately discarded — nothing is saved or uploaded. You can use PunchTrack entirely without an account, in which case your data never leaves your device. If you create an optional free account, your training data is backed up to our cloud so you can sync across devices and use the social features — and you choose what other athletes can see. No ads, no third-party analytics, and we never sell your data.

CS42.org ("we", "us", "our") built the PunchTrack app as a free application. This page explains what data the App handles, where it goes, and the controls you have over it.

1. Two Ways to Use PunchTrack

  • Without an account ("Continue without account"). Everything — profiles, sessions, statistics, settings — is stored only on your device. Nothing is sent to our servers, and we collect no personal data at all.
  • With a free account. Sign up with an email address and password, or with Sign in with Apple. Your training data is then backed up and synced to our cloud (see Section 2) and you can take part in the social features (see Section 3). Creating an account is always optional — punch detection, workouts, drills, and analytics work fully offline either way.

2. Information We Collect (Account Users Only)

When you create an account, the following is stored in our cloud database, linked to your account and readable only by you (see Section 8 for how it is protected):

  • Account data — your email address and your chosen unique username. Passwords are handled by Firebase Authentication; we never see or store your plain-text password. With Sign in with Apple, Apple provides a verified (optionally relayed) email address.
  • Fighter profiles — name, stance, and any optional fields you choose to fill in: gender, date of birth, weight, height, nationality, country of residence, Instagram/TikTok handles, and profile photo.
  • Training data — session records (type, date, duration, punch counts, hits per minute, power-tier breakdown, workout/drill details) and reaction-drill statistics.
  • App settings — preferences such as units, appearance, and detection options, so they follow you across devices.

Sync is local-first: your device remains the source of truth, and changes are written through to the cloud when you are online.

3. Social Features & What Other Users Can See

If you use the social features (search, follow, leaderboards), a public fighter card is published for your account. It can include: your username and display name, profile photo, nationality and residence flags, Instagram/TikTok handles (if you added them), headline training stats (total punches, session count, streak, best punches-per-minute, this week's punches), and the athletes you follow.

You stay in control:

  • Discoverability toggle — turn it off and other users cannot find or view your fighter card.
  • Recent sessions toggle — sharing of your recent session summaries (up to the last 10) can be switched off independently.
  • Age, weight, and height — each has its own sharing toggle and is only shown if you enable it.
  • Leaderboards — show your username, flag, and punch totals to other signed-in users.
  • Block & report — you can block other users and report inappropriate profiles; reports you submit are stored so we can act on them.

Public fighter cards are visible only to signed-in PunchTrack users, not on the open web.

4. How the Microphone Is Used

PunchTrack requires microphone access to detect the percussive sound of a punch landing on the heavy bag. Here is exactly how it works:

  1. When you start a session, the App opens a real-time audio tap on the microphone.
  2. Each 10-millisecond chunk of input is passed through an in-memory bandpass filter and envelope detector.
  3. Each chunk is immediately overwritten by the next one in a small ring buffer. No audio is ever written to disk.
  4. When the envelope crosses a threshold, a punch event is recorded — only the count and peak amplitude are kept, never the audio.
  5. When you stop the session, the audio engine stops and the buffer is released.

We do not transmit, copy, save, or share microphone input. The microphone is used as a sensor — like the accelerometer in a step counter — not as a recorder. This is true in every mode, with or without an account.

5. Camera and Photo Library

PunchTrack optionally requests camera or photo library access only if you choose to set a profile picture. The photo is stored with your profile on your device; if you are signed in it is included in your cloud backup, and it appears on your public fighter card only if you use the social features. You can skip the profile picture entirely and revoke these permissions at any time in iOS Settings.

The App may also ask for permission to save images when you export a session share card to your photo library. This permission only allows adding images, not reading your library.

6. Apple Health (Optional)

If you enable the Apple Health integration, PunchTrack writes your boxing workouts and estimated active calories to Apple Health. The App requests write-only access: it never reads any data from Apple Health, and your Health data is never sent to our servers. You can revoke this at any time in the Health app or iOS Settings.

7. Notifications (Optional)

Training reminders (a daily streak nudge and a Sunday weekly summary) are local notifications scheduled on your device. We do not send push notifications and no server is involved.

8. Where Your Data Is Stored & Service Providers

Cloud data for account users is stored with Firebase (Firebase Authentication and Cloud Firestore), a Google LLC service. Firebase processes this data on our behalf on Google Cloud infrastructure, which may be located in various countries. Data is encrypted in transit (TLS), and per-account security rules ensure your account data can only be read or written by you. See Firebase's privacy documentation for details.

Firebase is our only service provider. We do not use any advertising networks or third-party analytics SDKs, and we do not sell, rent, or share your personal data with anyone else.

9. Permissions Summary

Permission Required? Purpose
Microphone Yes Detect punch impacts in real time. Audio is processed in memory only and never recorded.
Photo Library No Used only if you choose a profile picture from your library.
Camera No Used only if you choose to take a profile picture.
Add to Photo Library No Save session share cards you export. Cannot read your library.
Apple Health No Write-only: saves workouts and estimated calories to Apple Health. Never read.
Notifications No Local training reminders you schedule. No push notifications.

10. Analytics, Advertising & Tracking

PunchTrack contains no advertising and no third-party analytics or tracking SDKs. The only third-party components are Firebase Authentication and Cloud Firestore, used purely for sign-in and data sync. We do not "track" you in the sense defined by Apple's App Tracking Transparency framework — there is no cross-app or cross-website tracking, so the App Tracking Transparency prompt is never shown.

11. Children's Privacy

PunchTrack's training features are suitable for all ages, but creating an account and using the social features is not intended for children under 13 (or the minimum age for such services in your country). We do not knowingly collect personal information from children under 13; if you believe a child has created an account, contact us and we will delete it. Younger athletes can use the App without an account, in which case no data is collected, and we recommend adult supervision when training on a heavy bag.

12. Data Retention & Deletion

You can delete your data at any time:

  • Delete your account — Profile tab → Account → Delete Account. This permanently removes your cloud data (account, profiles, sessions, public fighter card, and username) and erases the app's data from your device.
  • Sign out — signing out removes your data from that device; your cloud copy is restored the next time you sign in.
  • Without an account — deleting individual profiles in the app, or deleting the app itself, removes all locally stored data. Nothing exists on any server.

We retain cloud data only for as long as your account exists. You can also export a full backup of your data (a .ptbackup file) from the app at any time.

13. Your Rights

If you use PunchTrack without an account, we hold no data about you. If you have an account, you can exercise your rights directly in the app: access and export your data (backup export), correct it (edit your profile), and delete it (Delete Account). If you are in a jurisdiction with applicable privacy laws (GDPR, CCPA, and similar), you may also contact us at the address below to exercise these rights, object to processing, or lodge a complaint with your supervisory authority.

14. Data Security

Local data is protected by iOS's app sandbox and device encryption — we recommend keeping your device updated and using a passcode or biometric lock. Cloud data is encrypted in transit and protected by per-account security rules, so one account can never read another account's private data. Authentication is handled by Firebase Authentication; we never store plain-text passwords.

15. Apple App Store

When you download PunchTrack from the App Store, Apple may collect certain information as described in Apple's Privacy Policy. This data collection is governed by Apple and is outside our control.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and, if the change is material, mentioning it in the app's release notes. You are advised to review this Privacy Policy periodically.

17. Contact Us

If you have any questions or concerns about this Privacy Policy, contact us at hello@cs42.org.

Last updated: July 18, 2026

Looking for something else?

← Back to PunchTrack Terms & Conditions All Apps