Privacy Policy

Last updated: 2026-09-12

Badger is a local-first workout tracker. Your training data lives on your device in a local SQLite database. Nothing is sent to a server automatically. This policy explains what is stored, what can leave the device (only when you initiate it), and your rights. Everything below describes the app unless it says otherwise; the About this website section covers badger.fit itself, which is a separate thing with separate answers.

Data stored only on your device

The following is stored on your phone and is never sent to us:

  • Workouts, sets, and exercises (including weight, reps, distance, duration, RPE, RIR, notes, comments, and - if you switch it on - the end-of-set heart rate read from Apple Health or Health Connect).
  • Routines, routine days, and predefined sets.
  • Body measurements and body-weight history, including any weigh-ins imported from Apple Health or Health Connect. Imported readings are saved in Badger's local database exactly like ones you type in, so they behave the same way everywhere else in the app - including in backups (see below).
  • Gyms, machines, attachments, and their links to exercises.
  • Photos you add to a machine or attachment. They are saved as ordinary image files in Badger's own storage on your device. They are included in backup files only when the Back up equipment photos setting is on - off by default (see below). That covers both the backups Badger uploads to your own Drive and any backup file you export and share yourself; they are never sent to us either way. Deleting the machine or attachment, or removing the photo, deletes the file.
  • All app settings, preferences, and the debug log ring buffer.
  • The most recent crash report, if Badger terminated unexpectedly. Saved as a plain-text file (crash_report.txt) containing the exception, stack trace, and the last ~500 lines of the in-memory log buffer. Only the latest crash is kept - a new crash overwrites the previous file, and sending it via feedback (see below) deletes it.

Data sent automatically off the device

None. Badger does not send your workout data, identifiers, usage metrics, analytics, or telemetry to any server. There is no account, no sign-in, and no background sync in this version.

Data that can leave your device only when you initiate it

  • Manual backups - you tap Manual backup in Settings to open the system share sheet and save a .workout_backup file wherever you choose (local storage, your own Drive, email-to-self, etc.).
  • CSV exports - workout history CSV exports open the share sheet.
  • AI context copies - Copy context for AI assembles a plain-text summary of your training (your training notes, active program, recent sessions, records, gym equipment, and avoided exercises) on your device and shows it to you in full. Tapping Copy places it on your clipboard; tapping Share opens the system share sheet. Badger sends it nowhere - where it goes next is entirely your choice, and if you paste it into an AI service, that service's own privacy policy applies to it from that point. It deliberately excludes body measurements, any health data, and your workout, set, exercise and machine comments.
  • Debug log exports - the last ~500 lines of in-memory logs can be exported as a plain-text file via the share sheet.
  • Feedback emails - the Send feedback screen opens your email client with a pre-filled draft to feedback@badger.fit. You review and send it from your own email app. If a crash occurred since the last launch, a toggle offers to attach the stored crash report; you can also attach diagnostic logs. Nothing is sent automatically - you always hand-off to your mail app and press send.
  • Cloud backup (opt-in) - when you enable Cloud backup in Settings, Badger signs in to your Google account (using Google Sign-In) and uploads backup archives to a hidden app-data folder on your Google Drive. The folder is private to Badger - it is not visible in the Drive UI and cannot be accessed by other apps. Badger requests only the drive.appdata scope (no access to your other Drive files). Backups contain your local SQLite database and a sanitized copy of your app settings (excluding any authentication tokens). Photos you added to machines or attachments are not included by default, to keep backups small - restoring onto a new device brings back your equipment without its pictures. A separate setting on the cloud backup screen, Back up equipment photos, includes them; it is off unless you turn it on. With it on, the photos travel inside the same backup archives in the same private app-data folder - no extra files, no other destination - and a restore puts them back on the new device. Up to 5 rolling backups are kept plus event backups before destructive actions. You can disable cloud backup, delete all cloud backups, or revoke Badger's access from your Google account at any time. No data goes anywhere else.

Apple Health and Health Connect (opt-in)

Badger can exchange three specific things with your phone's health store - Apple Health on iOS, Health Connect on Android. All of them are off by default, each is a separate switch in Settings, and each also has to be granted in the health app's own permission screen - for that one thing only, so allowing heart rate does not give Badger your weight history. No switch alone moves any data.

  • Writing workouts - when you turn this on, each finished workout is saved to your health store as a strength training session. Badger writes when it started and when it ended, and nothing else. There is deliberately no calorie estimate: a strength-training calorie figure cannot account for rest, body composition, or effort, so it would be a guess presented as a measurement. Badger does not write exercises, weights, reps, or notes.
  • Reading body weight - when you turn this on, Badger reads body-weight readings from your health store and saves them in your local body tracker as ordinary entries. Badger reads body weight only; no other health category is requested. Because these readings are saved locally like any other entry, they are included in your backups - the manual backup file and, if you have enabled it, the cloud backup to your own Google Drive.
  • Reading heart rate - when you turn this on, Badger reads heart-rate samples from your health store for the period a workout was running, and keeps a single value per set: your heart rate at the end of that set, in beats per minute. It is stored with the set in Badger's local database, so it is included in your backups in the same way as your weights and reps. The samples Badger reads are used to work out that one number and are then discarded - Badger does not keep a copy of your heart-rate history, and does not store any other health measurement. Reading happens only when a workout finishes and when you open its summary shortly afterwards; there is no background monitoring, and Badger never writes heart rate back to your health store.

Nothing read from your health store is sent to us or to anyone else. You can turn any of them off at any time, and you can revoke Badger's access from Apple Health or Health Connect directly. Turning them off stops any further exchange; readings already saved in your body tracker stay there until you delete them.

Device permissions

  • Camera and photos - requested only when you choose to add a photo to a machine or attachment, and only at that moment. Badger reads the single image you pick; it does not browse, index, or upload your photo library. Decline, and everything except equipment photos works exactly as before.
  • Notifications - used for the rest timer, the set timer, the active-workout notification, and the workout reminders you schedule yourself. All of them are local notifications raised by the app on your own device; none involve a server.
  • Health data - requested only when you turn on one of the Apple Health / Health Connect switches described above, and only for the specific categories that switch needs. Decline, and everything else in Badger works exactly as before.

Third parties present in the app

  • Your phone's store rating sheet - after a session that sets an all-time personal record, Badger may ask your phone to show its standard "rate this app" sheet. The sheet belongs to Apple or Google, not to Badger, and your phone decides whether to show it and how often. Badger sends nothing with the request and is told nothing back: not whether the sheet appeared, not what you rated it, not whether you wrote anything. Any review you do leave is between you and the store.
  • Apple Health / Health Connect - only used when you opt in (see above). These are your phone's own health stores; data exchanged with them stays on your device and is governed by Apple's or Google's handling of that store, not by us.
  • Google Drive - only used when you opt in to cloud backup (see above). Data is stored in Badger's private app-data folder on your Drive; it is not shared with us or with any other party.

No analytics SDKs, no advertising SDKs, no crash-reporting SDKs. Fonts are bundled inside the app rather than fetched from a font service, so displaying text makes no network request. Firebase integration is scaffolded in the codebase for possible future features but is not initialized or used in this version.

What the app explicitly does not do

  • No analytics, metrics, or telemetry. (The website counts page views; see About this website. The app does not, and never talks to the website.)
  • No advertising or ad-tracking SDKs.
  • No user profiling or behavioral tracking.
  • No account required to use Badger. Google Sign-In is only used if you opt in to cloud backup, and only to upload/download your own backup files to your own Drive.
  • No cloud sync of live workout data - only opt-in backup archives.
  • No third-party SDKs that send us anything. The three above are your phone's own services, used only when you opt in or when your phone chooses to show its rating sheet.

About this website

Everything above is about the Badger app. This section is about badger.fit, the site you are reading now. They are separate: the app sends nothing anywhere, and the site counts visits.

We use GoatCounter, an open-source, privacy-focused analytics tool, to see which pages people read and where they arrive from. It is how we know whether a help page is worth keeping and whether anyone found the site at all.

It sets no cookies and stores nothing in your browser: no cookies, no localStorage, no cache entries, nothing that survives your visit. There is no consent banner because there is nothing to consent to storing.

Per page you view, it records:

  • The page path and the time.
  • The referrer, meaning the site or link that sent you here.
  • Your browser, operating system, and screen width.
  • Your country, worked out from your IP address at the moment of the request.
  • Whether you tapped one of the store links, recorded as a plain counter with nothing attached to it.

Your IP address is not stored. It is combined with your browser's user agent to produce a random session identifier held in memory for up to eight hours, so that reading four pages counts as one visit rather than four. That identifier is not tied to you, expires on its own, and cannot be turned back into an IP address. The full user agent is not stored either.

There is no profile, no cross-site tracking, no advertising, and no data sold or shared. Nothing here identifies you, and none of it is connected to anything in the app: the app never contacts this site, so your training data and your reading of this page have no way of meeting. Any content blocker or tracker-blocking browser stops the script, and the site works exactly the same without it.

The site is hosted on GitHub Pages, which, like any web host, processes the requests needed to serve you the page.

Your rights

Deleting the app removes your workout data. Since we don't store a copy, there's nothing for us to delete on our side. If you have emailed us feedback that included personal information and want it deleted from our mailbox, email privacy@badger.fit.

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we have collected, to request deletion, and to opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise these rights, email privacy@badger.fit.

Children

Badger is not directed at children under 13 and we do not knowingly collect information from them.

Updates

If we change this policy we will update the Last updated date at the top and, for material changes, call it out in the app. Continued use of the app after an update constitutes acceptance.

Contact

Privacy questions: privacy@badger.fit
General: hello@badger.fit