Last updated: 15 August 2026 · Controller: Máté Kucsera, Slovakia · kucseramat@gmail.com
IronRoutine records what you eat and how you train. Some of that — body weight, measurements, nutrition and exercise — counts as health data under GDPR Article 9, which is treated as a special category. It is stored only because you chose to enter it, and it is never used for anything but showing it back to you.
Your email address and a hashed password. Your profile (name if given, age, sex, height, weight, goals). Everything you log: food entries, water, workouts and sets, body measurements, planned sessions. Session tokens for your signed-in devices, and the rough time of your last visit.
Passwords are stored as scrypt hashes and cannot be read, by me or anyone else.
No advertising. No analytics or tracking scripts. No third-party sharing, no selling, no profiling. There are no cookies except the one that keeps you signed in.
The server is hosted on a private VPS in Europe. Outgoing email (account confirmation, password resets) goes through an SMTP provider. Barcode lookups you perform are sent to Open Food Facts and USDA FoodData Central as an anonymous product query — those requests contain a barcode or a search word, never your identity or your log.
You can export everything from the Profile page at any time. You can delete your account, which removes your rows immediately and permanently — there is no soft-delete or archive copy, and backups roll off within 30 days. You may also ask for a copy or a correction by email.
Data is kept until you delete it. Unverified accounts are removed after 30 days.
This is a personal project, not a company. It has no certification, no formal audit and no uptime guarantee. Export your data if it matters to you. Nothing here is medical advice — calorie and macro figures are estimates from standard formulas, not a clinical prescription.