IronDesk · Web, Android & Garmin

Privacy policy

Effective and last updated: August 30, 2026

IronDesk processes fitness and workout information only to provide the features you choose to use. IronDesk does not sell personal or health data, use it for targeted advertising, or give a Garmin watch your IronDesk account password or cloud-session credentials.

1. Scope

This policy covers the IronDesk web and progressive web app, the Android Health Connect integrations, and the IronDesk Garmin Connect IQ companion (together, “IronDesk”). IronDesk is provided by FawazLabs. Garmin, Google, GitHub, Supabase, and Firebase operate their own services under their own privacy terms.

2. Information IronDesk processes

3. How IronDesk uses information

IronDesk uses this information to:

4. Garmin permissions and watch storage

The Connect IQ companion requests only the permissions needed for its disclosed workflow:

The watch stores a revocable device token, an active-workout cache, a recovery checkpoint, and a bounded offline synchronization queue. The raw device token is returned to the watch during pairing; IronDesk stores a one-way hash on the server. The watch does not store your IronDesk password, Supabase session, or service-role credential.

Connect IQ synchronization data is sent to the HTTPS server origin configured in the IronDesk watch-app settings. FawazLabs controls that data only when the configured origin is an official FawazLabs-operated IronDesk service; another origin is governed by its operator's privacy practices. When an official IronDesk service is used, only optional average and maximum heart-rate summaries are sent to that service at workout completion. Live samples and any heart-rate information stored in the FIT activity remain subject to Garmin's device and Garmin Connect handling.

5. Storage, service providers, and sharing

Depending on the IronDesk features you enable, information may be stored locally on your browser, Android device, or Garmin watch and may be processed by IronDesk's service and platform providers. Supabase provides account, database, and Connect IQ synchronization services. Firebase may process opt-in Personal Cloud Sync or Crew information. Garmin provides the Connect IQ distribution, device settings, and Garmin activity ecosystem. GitHub hosts this public policy page and the public issue tracker.

If you choose to join a Crew, IronDesk shares your display name, best estimated one-repetition maximum values for supported lifts, weekly session count and training volume, and personal record feed entries containing the exercise and estimated one-repetition maximum with other members of that Crew. IronDesk does not share your full workout or set-by-set history, nutrition data, recovery notes, or Health Connect records with Crew members.

IronDesk does not sell personal or health data or use it for targeted advertising. Information may be disclosed to service providers acting for IronDesk, when you direct IronDesk to share it, or when disclosure is required to protect users, enforce rights, or comply with law.

6. Retention and deletion

Local data remains until you remove it, clear application data, or uninstall the relevant app. Workout records remain until removed through an available product control or an operator-fulfilled deletion request. Device-link and replay-protection records are retained as needed to synchronize safely and prevent duplicate updates. Unlinking a Garmin watch in IronDesk Connections revokes the device and removes records tied to that link. Unlinking does not automatically erase workout history already added to your IronDesk account or an activity already saved in Garmin.

IronDesk does not currently provide fully self-service account deletion. To request access, correction, or deletion of hosted account, device-link, workout, recovery, nutrition, or health data, contact FawazLabs at fawazdevlabs@gmail.com. You may also open a non-private support request on the IronDesk GitHub Issues page, but do not post private health information in a public issue.

7. Your choices

8. Security

IronDesk uses HTTPS for Connect IQ communications, purpose-bound one-time pairing codes, revocable random device tokens, hashed server-side token storage, access controls, and replay-resistant event identifiers. No service can guarantee absolute security, so you should protect access to your devices and accounts and promptly unlink a lost watch.

9. Policy changes

This policy may be updated when IronDesk's features, providers, or legal obligations change. The effective date above identifies the current version. Material changes will be presented through an appropriate IronDesk or Store notice when required.

10. Contact

IronDesk is provided by FawazLabs. For privacy, access, correction, or deletion requests, email fawazdevlabs@gmail.com. Do not include passwords, pairing codes, device tokens, or detailed health measurements in the first message.