Privacy Policy
Last updated: September 3, 2026
1. What We Collect
When you use PoolTrack, we collect:
- Account information — your email address, display name, and authentication credentials (managed by Firebase Authentication, including Google OAuth).
- Pool data — water chemistry readings, treatment logs, pool profiles, and chemical inventory you enter into the app.
- Payment information — handled entirely by Stripe. We never see or store your full card number. We store your Stripe customer ID and subscription status.
- Usage data — if you allow product analytics, pages visited, feature usage, device/browser details, and an account identifier.
- Support and AI inputs — questions, pool context, and images or text you choose to send to Ask PoolTrack or reading-import features.
- Operational data — security, error, delivery, and request metadata needed to protect and operate the service. Sensitive fields are scrubbed from error reports.
2. How We Use Your Data
- To provide and operate the PoolTrack service, including chemistry tracking, trend charts, and dosing calculations.
- To process payments and manage your subscription via Stripe.
- To provide optional AI explanations and import tools when you request them.
- To secure, diagnose, and improve the product.
- With your permission, to measure product usage and marketing effectiveness.
We do not sell or rent your pool data. Optional marketing measurement is disabled unless you allow it.
3. Third-Party Services
PoolTrack uses the following services that may process your data:
- Firebase (Google) — authentication, database (Firestore), and hosting. Firebase Privacy Policy
- Stripe — payment processing. Stripe Privacy Policy
- OpenRouter and selected model providers — process the questions, images, and pool context you submit to AI features. Provider handling can vary by selected model. OpenRouter Privacy Policy
- Resend — sends service and reminder emails you enable. Resend Privacy Policy
- Telegram — processes bot messages only if you link your account. Telegram Privacy Policy
- Sentry — receives scrubbed operational error details. Session replay and client performance tracing are disabled. Sentry Privacy Policy
- Google Analytics — receives page and feature events only when you allow product analytics. Google Privacy Policy
- Meta — receives Pixel and consent-linked purchase measurement only when you allow marketing measurement. Meta Privacy Policy
4. Data Storage & Security
Your data is stored in Google Cloud Firestore (nam5 region, United States). All data is transmitted over HTTPS. Authentication is handled by Firebase Auth with industry-standard security practices.
Your pool chemistry data is isolated to your user account and cannot be accessed by other users. Firestore security rules enforce strict per-user access control.
5. Data Retention
We retain account and pool data while your account is active. Account deletion removes the data controlled by PoolTrack; limited backups, security records, and records retained by service providers may remain for their documented retention periods or legal obligations.
After deletion, PoolTrack retains a minimal access-denial receipt containing only the former Firebase user identifier, denial reason, and timestamp so still-valid sessions cannot recreate the account and interrupted deletion can resume safely. It contains no email, profile, billing, or pool data. Stripe webhook processing receipts contain only the Stripe event identifier, event type, processing status, and timestamps (not the Stripe payload or PoolTrack user identifier) and expire after 32 days.
Payment, email, AI, analytics, and messaging providers apply their own documented retention policies.
6. Your Rights
You have the right to:
- Access your data at any time through the app.
- Export a copy of your account data from Settings.
- Correct editable account and pool information in the app.
- Delete your account from Settings.
- Withdraw optional consent at any time using the button below.
If you are in the EU (GDPR) or California (CCPA), you may have additional rights. Contact us to exercise them.
7. Cookies
PoolTrack uses essential browser storage for authentication, security, theme, and your privacy choices. Google Analytics storage and Meta advertising/measurement technologies remain off until you allow their category.
8. Children
PoolTrack is not intended for use by children under 13. We do not knowingly collect data from children.
9. Changes
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice.
10. Contact
For privacy-related questions or data requests, email us at support@pooltrack.app.