Updated September 2, 2026: named the operating entity (Burner LLC) and added a dedicated Consumer Health Data Privacy Policy for Washington, Nevada, and Connecticut residents. Previous update: August 24, 2026 to add heart rate to the Health Connect read list (session heart-rate summaries). Previous update: August 23, 2026 (Apple Health / Health Connect reads, GPS cardio recording, breach-notification commitment); previous version: July 16, 2026.
Burner (“Burner,” “we,” “us”) is a personal fitness and nutrition tracker for iPhone and Android. This policy explains what data Burner collects, how it is used, and the choices you have. Burner is currently an invite-only beta operated by Burner LLC, a Nevada limited liability company (“Burner LLC”).
The short version: your fitness data exists to power your app experience. We don't sell it, we don't show ads, and we don't use it for cross-app tracking.
Account information. When you sign in with Google or Apple we receive your name (if provided), email address (or Apple private-relay address), and a unique account identifier. We use this to create your account, check the beta invite list, and sync your data across devices.
Fitness and nutrition data you enter. Workouts, sets and weights, cardio sessions (including heart-rate data you record or import), routes you record or import, body weight and measurements, food logs, meal plans, water intake, habits, quiz answers, goals, and settings. This is the core of the product and is stored to provide it.
Apple Health and Health Connect (optional). With your permission, Burner reads a small set of values from Apple Health (iOS) or Health Connect (Android): daily step count, heart rate, resting heart rate, heart rate variability, and sleep. Burner only reads — it never writes to your health store. These values power features on your device (today's step count, readiness inputs for workout suggestions, and — on Android — a heart-rate summary for cardio sessions you record, read over that session's time window); readiness-relevant values such as last night's sleep or resting heart rate may be saved with entries you create, heart-rate samples from a recorded session are saved with that session in your training log, and either may be included in AI coach requests (see Anthropic below). You can revoke access at any time in iOS Settings → Health or the Health Connect app, and Burner keeps working without it.
Location (optional). If you record a cardio session with GPS tracking, Burner collects your precise location for the duration of that recording — including while the screen is locked or the app is in the background, so your route isn't cut off mid-run. The route is saved to your training log and syncs like your other fitness data. Burner does not collect location outside an active recording you started.
Progress photos. Photos you add on the Body screen are stored locally on your device only. They are not uploaded to our servers. They are included in backup files you export.
Camera. The barcode scanner processes camera frames on your device to read barcodes; frames are not stored or transmitted. If you use AI photo food logging, the photo you choose is sent to our server and to Anthropic (see below) to estimate its nutrition, and is not retained after processing.
Connected services (optional). If you connect Strava, we receive your Strava activities (type, time, distance, duration, heart rate, route) to import them into your training log. We access Strava only after you authorize it and you can disconnect at any time.
Food database queries. Food searches and barcodes may be sent to Open Food Facts and the USDA FoodData Central service to look up nutrition information. These queries contain the search text or barcode, not your identity.
Usage analytics. We use PostHog to understand how the app is used and to catch errors: events (for example “workout finished”), device and browser type, app version, and approximate region. Analytics has three modes you control in Settings: Off, Anonymous (default — events are not tied to your account identity), and Identified. Analytics may include session replay of app screens to help us debug problems; replay follows the same mode setting.
Feedback. If you submit feedback, we store the text you write, your account id, app version, and a link to the related session replay so we can investigate.
Burner is offline-first: your data lives in a local database on your device. When you are signed in, it also syncs to our cloud so you can restore it and use multiple devices.
We use these processors:
We do not sell your data, share it with advertisers, or use it for advertising or cross-app tracking. Data is transmitted over TLS. Cloud data is protected by per-account security rules.
Burner necessarily handles health-related information: weight, body measurements, exercise, diet, and — if you grant access — steps, heart-rate, and sleep values from Apple Health or Health Connect, and GPS routes you record. We treat all of it under this policy, share it only with the processors above as needed to run the feature you're using, and never use it for advertising, marketing, or sale. Data read from Apple Health or Health Connect is used only for the features described here and is never shared with third parties other than processors acting on our behalf, consistent with Apple's and Google's platform rules. Burner is not a medical service and does not provide medical advice — see the Terms of Use.
If you are a resident of Washington, Nevada, or Connecticut, the health-related data Burner collects is also covered by those states’ consumer-health-data laws (including Washington’s My Health My Data Act), which give you additional rights and require additional disclosures. Those are set out in our dedicated Consumer Health Data Privacy Policy, which forms part of this policy.
Your data is retained while your account exists. You can:
Feedback records and aggregate analytics (per your analytics mode) may be retained after account deletion; they are not used to identify you.
Data is encrypted in transit (TLS), cloud data is isolated per account by security rules, and access to production systems is limited to the operator. No system is perfectly secure. If a security breach results in the acquisition of your unsecured, individually identifiable health information, we will notify you and the US Federal Trade Commission as required by the FTC Health Breach Notification Rule — without unreasonable delay and no later than 60 days after discovery (sooner where law requires).
Burner is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Burner is operated from the United States and data is processed there. By using Burner you understand your data will be processed in the US.
We'll update this policy as the product evolves, and before any new category of data collection ships. Material changes will be noted in the app. The effective date above always reflects the current version.
Questions or requests: [email protected]