IronDesk · Web, Android & Garmin
Privacy policy
Effective and last updated: August 30, 2026
IronDesk processes fitness and workout information only to provide the features you choose to
use. IronDesk does not sell personal or health data, use it for targeted advertising, or give
a Garmin watch your IronDesk account password or cloud-session credentials.
1. Scope
This policy covers the IronDesk web and progressive web app, the Android Health Connect
integrations, and the IronDesk Garmin Connect IQ companion (together, “IronDesk”). IronDesk
is provided by FawazLabs. Garmin, Google, GitHub, Supabase, and Firebase operate their own
services under their own privacy terms.
2. Information IronDesk processes
-
Account and settings data: an account identifier, email address, profile
name, optional height and date of birth, training goals and preferences, units, equipment,
program state, nutrition targets, and connection settings when you choose to sign in or
enable cloud features.
-
Workout data: workout plans and sessions, exercise names, sets, weight,
repetitions, RPE, rest time, completion state, timestamps, generated-program state, and
derived totals or trends.
-
Body, cardio, recovery, and nutrition data: information you choose to enter,
connect, or import, such as bodyweight and body-fat measurements; cardio activity, distance,
duration, calories, heart-rate summaries, and zones; sleep and sleep efficiency, resting
heart rate, HRV, soreness, fatigue, stress, readiness, and notes; and meals, calories,
macronutrients, and hydration.
-
Imported files and records: when you choose to import an activity or health
file, current IronDesk workflows read the source file locally and may store normalized
activity or metric records in your account together with import metadata such as the source
file name, size, format, warnings, and source provenance. Current workflows do not retain
the original source-file contents.
-
Garmin Connect IQ data: a one-time pairing code, a device label and linked
device identifier, token and synchronization metadata, the active workout sent to the
watch, confirmed set changes, offline event identifiers, completion timestamps, and
optional average and maximum heart-rate summaries when available.
-
Garmin activity files: the watch app can create and save a strength-training
FIT activity, which may include heart-rate information, on the Garmin device. Garmin may
synchronize that activity to Garmin Connect according to your Garmin settings and Garmin's
privacy terms.
-
Health Connect data: depending on the Android component and permissions you
enable, IronDesk may read daily aggregates for steps, heart rate, resting heart rate, sleep,
weight, body-fat percentage, calories, exercise duration, and VO2 max, or selected
record-level data for sleep, resting heart rate, HRV, weight, active calories, distance, and
exercise sessions. Record-level data may include timestamps and source-app or source-device
provenance; exercise sessions may additionally include an activity title and notes. The main
Android app can also write a completed
IronDesk exercise session to Health Connect only when you separately enable that permission.
IronDesk does not request background-health access, medical records, exercise routes, or raw
location.
-
Operational data: service providers may process ordinary request and
security information needed to deliver the service, prevent abuse, diagnose failures, and
protect accounts.
3. How IronDesk uses information
IronDesk uses this information to:
- display, record, synchronize, and reconcile your workouts and completed sets;
- create a Garmin strength activity and show rest-timer and workout status;
- show fitness, recovery, readiness, and training trends;
- process imports and create exports that you request;
- share the limited Crew information described below when you choose to join a Crew;
- prevent duplicate or stale offline watch updates;
- maintain linked-device security, investigate errors, and provide support; and
- comply with applicable legal obligations.
4. Garmin permissions and watch storage
The Connect IQ companion requests only the permissions needed for its disclosed workflow:
-
Communications to exchange a one-time pairing code for a revocable device
token, download the active workout, and upload confirmed set and workout-completion events
over HTTPS;
- Fit to create, lap, stop, save, recover, or discard the Garmin strength activity; and
- Sensor to read live heart-rate samples while an activity is recording.
The watch stores a revocable device token, an active-workout cache, a recovery checkpoint, and
a bounded offline synchronization queue. The raw device token is returned to the watch during
pairing; IronDesk stores a one-way hash on the server. The watch does not store your IronDesk
password, Supabase session, or service-role credential.
Connect IQ synchronization data is sent to the HTTPS server origin configured in the IronDesk
watch-app settings. FawazLabs controls that data only when the configured origin is an official
FawazLabs-operated IronDesk service; another origin is governed by its operator's privacy
practices. When an official IronDesk service is used, only optional average and maximum
heart-rate summaries are sent to that service at workout completion. Live samples and any
heart-rate information stored in the FIT activity remain subject to Garmin's device and
Garmin Connect handling.
5. Storage, service providers, and sharing
Depending on the IronDesk features you enable, information may be stored locally on your
browser, Android device, or Garmin watch and may be processed by IronDesk's service and platform
providers. Supabase provides account, database, and Connect IQ synchronization services.
Firebase may process opt-in Personal Cloud Sync or Crew information. Garmin provides the
Connect IQ distribution, device settings, and Garmin activity ecosystem. GitHub hosts this
public policy page and the public issue tracker.
If you choose to join a Crew, IronDesk shares your display name, best estimated one-repetition
maximum values for supported lifts, weekly session count and training volume, and personal
record feed entries containing the exercise and estimated one-repetition maximum with other
members of that Crew. IronDesk does not share your full workout or set-by-set history,
nutrition data, recovery notes, or Health Connect records with Crew members.
IronDesk does not sell personal or health data or use it for targeted advertising. Information
may be disclosed to service providers acting for IronDesk, when you direct IronDesk to share
it, or when disclosure is required to protect users, enforce rights, or comply with law.
6. Retention and deletion
Local data remains until you remove it, clear application data, or uninstall the relevant app.
Workout records remain until removed through an available product control or an
operator-fulfilled deletion request. Device-link and replay-protection records are retained as
needed to synchronize safely and prevent duplicate updates. Unlinking a Garmin watch in
IronDesk Connections revokes the device and removes records tied to that link. Unlinking does
not automatically erase workout history already added to your IronDesk account or an activity
already saved in Garmin.
IronDesk does not currently provide fully self-service account deletion. To request access,
correction, or deletion of hosted account, device-link, workout, recovery, nutrition, or
health data, contact FawazLabs at
fawazdevlabs@gmail.com. You may also open a
non-private support request on the
IronDesk GitHub Issues page,
but do not post private health information in a public issue.
7. Your choices
- Pairing the Garmin companion and enabling Health Connect are optional.
- You can unlink a Garmin watch in IronDesk Connections.
-
Clearing the watch app's data or uninstalling it removes the credential stored on that
watch, but does not by itself remove the server-side device link.
- You can manage or revoke Health Connect permissions in Android settings.
- You can pause optional cloud synchronization and remove imported summaries.
- You can clear local data, uninstall the app, or request deletion of hosted data.
8. Security
IronDesk uses HTTPS for Connect IQ communications, purpose-bound one-time pairing codes,
revocable random device tokens, hashed server-side token storage, access controls, and
replay-resistant event identifiers. No service can guarantee absolute security, so you should
protect access to your devices and accounts and promptly unlink a lost watch.
9. Policy changes
This policy may be updated when IronDesk's features, providers, or legal obligations change.
The effective date above identifies the current version. Material changes will be presented
through an appropriate IronDesk or Store notice when required.
10. Contact
IronDesk is provided by FawazLabs. For privacy, access, correction, or deletion requests,
email fawazdevlabs@gmail.com. Do not include
passwords, pairing codes, device tokens, or detailed health measurements in the first
message.