Privacy Policy
Last updated: September 19, 2026
The short version
We built Progress Cam to help you track your progress without worrying about your data. Your information stays on your device and in your personal iCloud account. We don't sell data, show ads, or lock you in. Simple as that.
Your data, and where it lives
Your progress data
- The trackers you create and all the entries you log
- Photos you attach to your progress
- All of it lives only on your iPhone or iPad and in your personal iCloud (CloudKit). We never collect it, and it is never sent to our servers
- The one exception is an image you choose to attach to a support chat message. Those upload to a private storage bucket, are limited to 10 MB and to JPEG, and are deleted when you delete your account
Your iCloud backup
- Your data automatically backs up to your personal iCloud account for safekeeping
- This covers your trackers and photos, plus your profile name, photo, and bio, so they follow you to a new phone
- This is encrypted by Apple, so only you can access it
- You control this in Settings, then your name, then iCloud, then Saved to iCloud, then Progress
Apple Health (optional)
- If you link a tracker to Apple Health, the app reads your most recent value for that measurement (weight, body fat, lean body mass, height, waist, or BMI) so you can import it
- Entries you log can be written back to Apple Health when you have linked that tracker
- This only happens when you tap to link or import, never in the background
- Health data stays on your device and in your own iCloud. It is never sent to our servers, never used for advertising, and never shared with anyone
- You can revoke access anytime in the Health app under Sharing, then Apps
If you sign in with Apple (optional)
- We store your Apple sign-in ID so your chat thread and your Pro access follow you to a new device
- If Apple shares your name or email with us at sign-in, we keep them on your device to personalise the app. Your name is attached to messages you send in chat so the developer knows who is writing
- Signing out removes the Apple ID and email from the device. Your in-app display name, about text, and profile photo stay, along with their iCloud key-value backup, until you delete them yourself or delete your account
If you use chat (optional)
- Messages get stored on our backend
- Chat is not tied to your iCloud account. Every install holds one anonymous backend session. Your conversation is keyed by your Apple sign-in ID if you are signed in with Apple, and otherwise by a random ID the app generates for that install. Signing in with Apple moves the thread to the device you are using
- Each message you send carries exactly this: your display name as you set it in the app, the name Apple gave us if you are signed in, your device model, your iOS version, and your subscription status, so the developer can actually help with the bug you are describing
- If you turn on notifications, your device's Apple push token is stored on our backend so we can tell you when the developer replies. It is deleted when you delete your data, or automatically once Apple reports it as dead
- You can delete them anytime in the app
Notifications
- Support chat notifications, whether pushed from our backend or shown by the app itself, carry only generic text such as a note that there is a new support message or a reply. Message content never appears in a notification
- Reminder notifications for your own trackers include the tracker name
- A tracker you have protected with Face ID or a passcode is never named in any notification
Home Screen widgets
- If you add a widget, the app copies that tracker's name, its latest value, your streak, and a downscaled version of the photo you picked into a container shared with the widget on your device
- Trackers protected with Face ID or a passcode are left out of widgets entirely
- None of this leaves your device
Progress Pro (if you subscribe)
- Purchases and renewals are handled entirely by Apple. We never see or store your payment details
- Your subscription status comes from Apple, signed and tied to your Apple ID. We keep a copy of the yes-or-no answer on your device so the app works offline
- From version 2.3.1 we use RevenueCat to measure our subscription revenue. The app contacts RevenueCat when it starts up, and when you start a trial, subscribe, renew, or cancel, RevenueCat receives the purchase details Apple reports for that transaction. With each request it receives a random ID it generates for your install, Apple's identifier for vendor (an ID Apple gives our apps on your device, not an advertising ID), and basic device information (device model, iOS version, country or locale, app version, and IP address). It never receives your photos, trackers, entries, name, email, or Apple sign-in ID, and it never decides whether you have Pro. That still comes from Apple
- To cancel, manage the subscription in your Apple ID settings
Stats we track locally
- How many times you open the app
- Your XP and level progress
- Most of this stays on your device. The one exception: if you are signed in with Apple, we record on our server how many of your free reel exports you have used, tied to your Apple sign-in ID. That is the only thing about your usage we keep
What we don't collect
- Your phone number, contacts, or any account you did not choose to connect. If you sign in with Apple or use chat, we hold only the name and email Apple gives us and whatever you type
- Your location
- Advertising identifiers, tracking pixels, or any usage analytics. The only outside SDK besides Apple and Supabase is RevenueCat, and it sees subscription purchases only, as described above. The only device identifiers involved are the Apple push token, a random ID the app generates for itself so your chat thread has an owner, and the random install ID and Apple identifier for vendor that RevenueCat receives
- Your browsing history
- Biometric data (Face ID stays on your device)
How we keep your data safe
On your device
Your trackers live in a secure, encrypted database on your phone.
In iCloud
Data syncs through CloudKit directly to your iCloud. We never see it.
In Apple Health
Health values move between the app and Apple Health on your device only. Nothing leaves the phone.
In chat
Messages travel over an encrypted connection and are stored on our Supabase backend, encrypted at rest by Supabase. They are not end to end encrypted. Access is locked to your own session by database rules, and the developer can read your thread, because that is how support works. Do not send anything in chat you would not want the developer to see. Your progress photos never go through chat unless you attach one yourself.
How long we keep it
- Support conversations, and any image attached to one, are deleted 90 days after the last message in the thread
- Push notification tokens are removed when they stop working, or when you delete your account data
- The moderation record for an account that abused chat is kept for as long as the block is needed
- Subscription records held by RevenueCat are kept for as long as we need them for subscription accounting, or until you ask us to delete them
- Your trackers, entries, and photos have no expiry, because we never hold them. They stay on your device and in your iCloud until you delete them
Your rights
You can:
- See everything you have logged inside the app, and share any photo, comparison, or reel you make
- Delete individual entries, whole trackers, or your entire account and all its data, from Profile, then Settings, then Delete account and all data
- Deleting your account wipes your trackers and photos from this device and your iCloud. On our backend it deletes your chat messages, read receipts, push tokens, conversation rows, and any images you uploaded to chat. That deletion runs on the server and is checked, not just requested by the app
- If your device cannot reach the server at the time, the deletion is queued and retried automatically the next times you open the app
- Three small things survive on purpose, to stop abuse and to stop the free exports being reset by deleting and reinstalling: the anonymous session record, the internal link binding your ID to that session, and the one-line record of how many free reel exports were already used. None of them contain anything you wrote, photographed, or sent
- Turn off iCloud sync whenever you want, in iOS Settings
- The in-app deletion does not reach RevenueCat. To have your subscription records there deleted, write to support@eldrenlabs.com. Your subscription itself stays with your Apple Account, so Restore Purchases still works afterwards
If the law gives you more
Wherever you live, you can also ask us for a copy of the support data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop using it, and ask for it in a portable form. Write to support@eldrenlabs.com and we will answer within one month.
Who else is involved
We use a few services to make the app work:
- AppleFor iCloud sync, purchases, push notifications, Sign in with Apple, and the on-device intelligence behind insights. Insights are generated on your phone by Apple's on-device model. Nothing about your progress is sent anywhere to produce them
- SupabaseFor the optional support chat: your messages and any images you attach, your push token, an anonymous account that proves the thread is yours, the record of how many free reel exports were used, and a moderation list used only if an account abuses chat
- RevenueCat, Inc.For subscription reporting, from version 2.3.1: the App Store purchase and renewal records of Progress Pro, a random install ID, Apple's identifier for vendor, and basic device information, used only to see our own subscription revenue, trials, and cancellations. Never used for advertising or to track you across other apps or websites. Its privacy policy is at revenuecat.com/privacy
No advertising networks. No usage analytics. No data brokers. We do not sell or share your data with anyone. We do not use personal data to train large language models, and we do not use it for targeted advertising or for profiling.
Consumer health data
Our separate consumer health data privacy policy, for Washington, Nevada, and Connecticut, is at eldrenlabs.com/progress-cam/consumer-health-data.
If you are in the EU, the EEA, or the UK
Who is responsible
Eldren Labs is the data controller for the support chat, push notifications, and subscription records described above. You can reach us at support@eldrenlabs.com. Your trackers, entries, and photos are not part of this, because they stay on your device and in your own iCloud, under your Apple Account, and we cannot read them.
Why we are allowed to use it
- For the support conversation and the reply notification we rely on Article 6(1)(b), performing the service you asked for
- For the record of an account blocked from chat we rely on Article 6(1)(f), our legitimate interest in keeping the support channel usable
- For subscription records sent to RevenueCat we rely on Article 6(1)(f), our legitimate interest in understanding and running our subscription business
- If a support message happens to describe your health, we rely on your explicit consent under Article 9(2)(a). You choose what to write, and you can ask us to delete it at any time
Where it goes
Support data is held by Supabase on infrastructure in Oregon, United States. Transfers out of the EEA and the UK rely on the European Commission's Standard Contractual Clauses (2021/914) and the UK Addendum, which form part of Supabase's data processing agreement (checked September 12, 2026). Subscription records are processed by RevenueCat, Inc. in the United States. Its data processing addendum incorporates the same Standard Contractual Clauses and the UK Addendum for those transfers (checked September 16, 2026).
Your rights, and complaints
You have the rights listed in section 04, and you can exercise them by writing to support@eldrenlabs.com. If you think we have handled your data badly you can complain to your national data protection authority, or to the Information Commissioner's Office if you are in the UK. We do not sell or share your personal information, we run no advertising or usage analytics, and we do not profile you or make automated decisions about you.
Children's privacy
Progress is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has used the app and left data with us, get in touch and we'll remove it.
Questions?
Reach out anytime through the developer chat in the app, by email at support@eldrenlabs.com, or through eldrenlabs.com/contact.
Updates to this policy
We'll update this if things change. The date at the top shows when we last updated it.