Privacy policy

AtomFit

Android and Wear OS app com.crackoncloud.fitness, published by crackoncloud · Last updated 28 August 2026

There is no AtomFit account, and no server of ours. Your workouts, routines, records, measurements and photos are kept in the app's own private storage on your device. We run nothing that could receive them.

The app reaches the network in a handful of places, and every one is listed in §3. Two happen without you asking: crash reporting, and the Google Play services the store itself needs. Usage statistics are off until you switch them on. Both switches are in Settings › Privacy.

1. What the app stores on your device

All of it lives in app-private storage, readable by AtomFit and not by other apps. Uninstalling takes every bit of it with you.

Your training

Your body metrics

Height, weight and body-fat entries are health data. They stay on the device with everything else, and are used only to draw your own charts and to estimate BMI, lean mass and session calories.

Settings and identifiers

android:allowBackup="false" is set: Android's own cloud backup does not copy the app's database off the device. Backups are yours to make, to a folder you choose (§5).

2. Permissions, and exactly what each one is for

PermissionWhat AtomFit does with it
Internet
Network state
Only for the things in §3: sync to your own Drive if you turn it on, Google Play billing, crash reporting, and usage statistics if you opt in. Logging a workout uses no connection at all.
Foreground service
special use, connected device
Keeps the live workout and its rest timer running with the screen off and the app in the background, and keeps a connected heart-rate strap streaming while you train.
Notifications The ongoing workout notification, rest-timer alerts, and training reminders on the days you choose. Declining costs those notices and nothing else.
Wake lock
Vibrate
Stops the device sleeping through a rest interval, and buzzes when one ends.
Nearby devices
Bluetooth scan and connect
Finding and connecting a Bluetooth heart-rate strap, and nothing else. The scan is declared neverForLocation, so it cannot be used to derive your location. On Android 11 and older the platform forced a location permission on any Bluetooth scan; it is declared with maxSdkVersion="30" for exactly that reason and is never used to read your position.
Health Connect
read heart rate, read weight, write exercise
Only if you grant it. AtomFit writes finished sessions to Health Connect, and reads back body weight and heart rate so you do not have to type them twice. The exchange is between the app and Health Connect on your own device; nothing goes to us. You can revoke it in Health Connect at any time.
Camera app, via a share
no camera permission
Photographing a machine or a progress photo hands the job to your own camera app, which writes the result back into AtomFit's private storage. The app holds no camera permission and cannot take a picture on its own.

There is no permission for location, contacts, the microphone, the phone, or all-files access, and none for enumerating the other apps you have installed. The advertising-ID permission that Google's measurement SDK would otherwise add is explicitly removed from the manifest.

3. What leaves the device, and when

Sync, if you turn it on

Sync copies your training data into the appDataFolder of the Google account you sign in with — a hidden area of your own Drive that only this app can read, and that you can delete at any time from Drive's own settings. Your devices read each other's changes from there and merge them locally. We are not in that path. There is no AtomFit server, we hold no keys, and the app requests the drive.appdata scope only: it cannot see, read or touch the rest of your Drive. Sync is off until you sign in, and signing out stops it.

Google Play

Buying or restoring AtomFit Pro goes through Google Play Billing. The app never sees or stores a card, and the entitlement is cached on the device so it survives being offline. What Play collects in the course of that is governed by Google's privacy policy, not this one.

Exports, shares and backups you ask for

An export, a shared session image, a routine sent as a file or a QR code, and an automatic backup all go where you send them — a folder you pick, or an app you choose in the share sheet. They leave on your instruction and go nowhere else.

Imports

Reading an export from another gym log is done entirely on the device, from a file you hand the app. Nothing is uploaded, and we never contact the app it came from.

4. Crash reports and usage statistics

These are two separate switches in Settings › Privacy, and they start in opposite positions.

Neither may carry a workout, a set, a measurement, a photo or an exercise name you typed: analytics events come from a fixed vocabulary in the code, so a user-typed value has no way into a payload. None of it is used for advertising or shared with advertisers. The app contains no advertising SDK, requests no advertising ID, and ad-ID, SSAID and ad-personalisation collection are all disabled in the build. Google acts as our processor for these reports; their handling is covered by Google's own privacy terms.

Both choices are device-local, never sync, and are re-applied on every app start.

5. What you can do with your data

6. Children

AtomFit is a training log for a general audience and is not directed at children under 13. It has no social features, no messaging, no user profiles and no advertising, and it collects no personal information from anyone, of any age.

7. Changes to this policy

If what the app stores or sends changes, this page changes with it and the date at the top is updated. The policy is kept deliberately in step with what the code actually does — a policy that claims more than the app does would be worth nothing.

8. Contact

Questions about this policy, or about anything AtomFit stores: support@crackoncloud.com