Magic Track Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how Magic Digital, LLC ("we," "us," or "Magic Track") handles information when you use the Magic Track iOS app ("the App"). We built Magic Track with user privacy as a cornerstone: we ask for as little data as possible, and the things we do collect are clearly described below. Most of the data flows are opt-in.
Magic Track is an independent app and is not affiliated with, endorsed by, or sponsored by The Walt Disney Company or any of its affiliates.
1. Overview
We never ask for your real name, phone number, GPS or precise location, contacts, microphone access, or access to read your existing photos.
You may optionally share an email address with us in two places: through Sign in with Apple (where you choose whether to share your real email or a "Hide My Email" relay) and through the Contact Support form (where the email field is clearly marked optional and utilized by us only when replies to the form submission are necessary).
Our cloud providers (Apple, Google Firebase, and RevenueCat) automatically receive your IP address, which can reveal your approximate location (country or region). This is standard for any internet-connected app and we don't store IP addresses in our own systems beyond what these providers retain.
Your logs and associated data stay on your device unless you turn on Cloud Backup, which uploads an encrypted snapshot to our secure cloud.
Photos you save from the App go only to your photo library and are never uploaded to us.
We share your logged statistics with aggregated community stats only if you turn on "Share My Stats with Community" in Settings → Privacy or via the initial install pop-up prompt. This is off by default.
We collect crash reports only if you turn on "Help Improve the App" in Settings → Privacy or via the initial install pop-up prompt. This is off by default.
We offer a paid subscription. Subscriptions are billed by Apple; we never see your payment card.
We never sell your data. We don't show you ads. We don't track you across other apps or websites.
2. What Information We Collect
2.1 Information Stored Only on Your Device
By default, everything you create in Magic Track is stored locally on your iPhone and is never sent to us unless you turn on Cloud Backup (Section 2.10) including:
Your visit logs (attractions, restaurants, shows, meet and greets, snacks, transportation, resort stays, resort visits, custom snacks, custom characters, and trip reports), including any free-text notes you type in them.
Earned badges, milestone progress, and Experience Level.
Your in-app preferences and settings.
Any photos saved by you from the App to your Photo Library.
We do not have access to information that lives only on your device.
2.2 Sign in with Apple
Magic Track uses Sign in with Apple for account-based features such as Cloud Backup, community Usernames, and subscription entitlement. When you sign in:
What Apple sends us, always: a stable, opaque identifier that uniquely represents you to our App. This identifier cannot be used to look you up across other apps.
What Apple sends us, only if you allow it via the Apple prompt: your name, and either your real email address or a private "Hide My Email" relay address. If you share these, we store them in a private profile record on our backend that only you and we can access; they are never shown to other users and are deleted when you delete your account.
If you choose to hide your name or email at the Apple prompt, we never receive that information. We do not send marketing or promotional emails. The only time we will use an email address you have shared with us is to reply to a support ticket or other inquiry you have initiated. Additionally, if you sign up for the email mailing list on our website we may send you updates and marketing emails (each email from the mailing list contains an "Unsubscribe" button). If you would like us to delete an email address you previously shared (including a "Hide My Email" relay address), the most complete way to remove it is to delete your account, as described in Section 9.
We use your Sign in with Apple identifier only to:
Look up and restore your Cloud Backup on a new device.
Attribute your contributions to community totals (anonymously to other users — see Section 2.3).
Verify your subscription, free trial, or promotional entitlement.
Attribute support tickets you submit so we can respond.
2.3 Community Stats (Optional, Off by Default)
If you turn on "Share My Stats with Community" in Settings → Privacy, or via the initial install pop-up prompt, the App contributes data from your activity to community features that are visible to all users. Specifically:
Aggregated counts: the community-wide number of times an attraction has been logged, a restaurant visited, a show seen, a character met, a snack logged, a transportation ride taken, a resort stayed at (including nights), and so on.
Combined wait time and duration statistics: your reported wait times and ride durations fed into community-wide averages and ranges.
Combined dining ratings: the food, service, and value ratings you give restaurants, fed into community-wide averages.
"Rarity" counts for badges: how many opted-in users have earned each badge.
Community records: single-achievement highlights (for example, the highest number of times one user has logged a particular attraction in a single day).
Community leaderboards: for attractions that have a score, the App maintains a top-score leaderboard. If you submit a qualifying score, your score, the date you set it, and your Username (if you have chosen to display one — see Section 2.5) will be publicly visible to other users on that leaderboard. Without a displayed Username, your entry appears under a generic anonymous label ("AnonyMouse User") with no identifying name attached.
Custom characters and custom snacks you create are never included in community stats; only items from the App's built-in catalogs are counted.
Your contributions are tied to your Sign in with Apple identifier (or anonymous User ID if you have not utilized Sign in with Apple) on our backend. Other users see only the data described above; they never see your free-text notes, your full log history, the items you logged that are not part of one of the features above, or any other personal information about you.
You can turn "Share My Stats with Community" off at any time in Settings → Privacy. Turning it off stops new logs from being shared; totals you already contributed remain in the anonymous community aggregates (see Section 7).
2.4 Custom Catalog Suggestions (Optional, Off by Default)
If "Share My Stats with Community" is on and you create a custom character, snack, or similar item not in the built-in catalog, the App may submit the item's name and related catalog details (its variant or appearance, the park/area/resort and location where you logged it, and its category) to us so we can review it for inclusion in future updates. These suggestions are linked to your account identifier on our backend but are used only to improve the App's built-in catalogs; the internal review report we generate from them is aggregate-only and contains no account identifiers, and we do not publish them attached to your identity.
2.5 Optional Username
You may set an optional Username in Settings to display alongside your contributions on community leaderboards and records. Creating a Username requires Sign in with Apple. Usernames must be 3–20 characters (letters, numbers, and underscores), must be unique, and are screened against a blocklist of inappropriate terms.
Showing your Username is itself opt-in and off by default. You may opt in to showing your Username publicly by turning on "Show Username on Community Records" in Settings → Privacy, or via the in-app prompt shown when you first save a Username. This may be turned off at any time in Settings → Privacy. The Username is your choice and can be edited or removed by you at any time; removal is always allowed immediately. Your Username is not your real name unless you choose to make it so. Reference the App's Terms of Service for further Username rules.
To preserve the integrity of community leaderboards and records, a blockout period applies between Username changes. The length of the blockout, and the rules that apply during the blockout window, are described in the App at the time you make a change.
2.6 Crash and Diagnostic Reports (Optional, Off by Default)
If you turn on "Help Improve the App" in Settings → Privacy, the App enables Firebase Crashlytics. When the App crashes, Crashlytics receives from your device:
Crash details (the type of crash and the technical stack trace).
Basic device and app information (iOS version, device model, App version, App build number).
A randomly generated, per-install diagnostic identifier ("install ID").
As with any internet connection, Google's servers receive your IP address when a report is uploaded (see Section 1). The IP address is not stored as part of the crash report itself.
Crash reports do not include your name, your logs, your photos, your contacts, your precise location (GPS), your Username, your email, or any free-text content you entered in the App.
When Crashlytics detects a new type of crash, a technical summary (the crash type, where in the App it occurred, and the App version — with no user identifiers) is posted to the private internal triage board described in Section 2.7 so we can prioritize a fix.
You can turn this off at any time in Settings → Privacy by toggling off "Help Improve the App". When off, no crash data is collected or sent, and any unsent reports on your device are deleted.
2.7 Contact Support Form
When you tap "Contact Support" in Settings and send a message via the form, the App writes a structured ticket to a secured Firestore database. The ticket contains:
The category you selected (Bug Report, Feature Request, Question, Report a Username, Other).
The message you typed.
Your email address, only if you chose to enter one in the optional email field. We use it solely to reply to your message should we need more information or want to provide an update pertaining to the inquiry.
Your account identifier (your Sign in with Apple identifier, or an anonymous app identifier if you haven't signed in with Apple).
Auto-attached diagnostic context: the App version and build number, your device model, your iOS version, your device locale (e.g., en-US), and the install ID (Section 2.6) so we can correlate the ticket with a crash trail if you've opted into diagnostics.
We do not auto-attach your name or any of your logged data. We apply fair-use limits to the number of tickets an account can submit per day to prevent abuse. Tickets are stored in Firestore and mirrored to an internal administration application that we use internally to track and respond to incoming requests. Access to the administration application board is limited to authorized personnel of Magic Digital, LLC.
You control what you type; if you want to remain pseudonymous, leave the email field blank and do not include identifying details in the message body.
2.8 Subscriptions, Free Trial, and Purchases
Magic Track offers a paid subscription that unlocks continued access to the app features. Subscription handling is summarized below; the specific subscription tier, length, and price are disclosed in the App and on the App Store before purchase.
Billing. All purchases are processed by Apple through your Apple ID. Magic Track never sees your payment card number, billing address, or full Apple ID. Your subscription is governed by Apple's standard terms, including Apple Media Services Terms.
Auto-renewal. Subscriptions auto-renew at the end of each billing period unless you cancel at least 24 hours before renewal. You can view, cancel, or change your subscription at any time in Settings → Apple Account → Subscriptions on your iPhone.
Free trial. Where a free trial is offered, it requires no payment method and begins when you log your first experience in the App. To grant and manage the trial, our server records the trial grant against your account identifier through RevenueCat, our subscription-management provider. You will not be charged during the trial and you will not be automatically charged when it ends. If the trial ends and you have not subscribed, the App becomes read-only for creating new logs; your existing data remains fully accessible on your device. You must choose to subscribe to continue using all features of the App.
Promotional codes, referral codes and complimentary access. From time to time we may offer promotional codes, referral codes, or grant complimentary access to eligible early testers. When you redeem a code, we store the code you redeemed and the grant details (such as the bonus length and timestamps) with your account identifier so each code can only be used once, and we rate-limit redemption attempts to prevent abuse. These records are deleted when you delete your account. No additional personal information is collected for promotional or complimentary access.
What we receive. To verify your subscription is active, we receive an anonymous, opaque purchase identifier and entitlement status from Apple via RevenueCat. We never receive your payment instrument or full Apple ID. RevenueCat also automatically processes the technical information listed in Section 4.
Refunds. Apple handles refunds for in-app purchases through the App Store. Visit https://reportaproblem.apple.com to request one.
2.9 Photo Library
The App asks for permission to save photos (such as your generated trip report and badge share images) to your Photo Library. Saving happens only when you choose it from the share sheet. The App does not read or browse your existing photos.
2.10 Cloud Backup (Optional)
If you turn on Cloud Backup in Settings, the App uploads an encrypted snapshot of your local Magic Track data (your visit logs (including any notes you typed in them), earned badges, trip reports, custom snacks, and custom characters) to our secure cloud storage. Cloud Backup requires Sign in with Apple: the snapshot is keyed to your Sign in with Apple identifier so that, when you install Magic Track on a new device and sign in with the same Apple ID, you can restore your data.
What is stored. A single compressed snapshot of your local Magic Track data. The snapshot does not include your photo library, your in-app preferences, or any data outside of Magic Track.
Where it is stored. Google Firebase Cloud Storage, hosted on US-based infrastructure. The snapshot is encrypted in transit (TLS) and at rest (Google Firebase).
Who can access it. Only you. Our backend rules permit reads and writes only to the Sign in with Apple identifier that owns the backup. We do not access the contents of your backup except to restore it to your device on request.
Versioning. Each backup overwrites the previous one. We do not retain historical versions on our side.
Restoring. Restores merge into your device: anything you logged on the new device is kept, and backup records are added alongside it.
Deleting your backup. In Settings → Cloud Backup, toggle off to delete the existing backup and stop future ones from being created. Deleting the App from your device does not delete the Cloud Backup; you must use the Settings toggle off option (or contact us for assistance).
3. How We Use Information
We use the information described above only to:
Provide and improve the App's features (including community totals, rarities, and Cloud Backup).
Verify and manage your subscription, trial, or promotional entitlement.
Diagnose and fix crashes (when you opt in).
Respond to your support requests.
Protect the App from abuse, fraud, and security threats.
We do not:
Sell or rent your data to anyone.
Show you advertising.
Use your data to build a marketing profile of you.
Share your data with data brokers.
Track you across other apps or websites.
4. Third-Party Services and What They Automatically Collect
Magic Track uses the following third-party services. Each has its own privacy practices. In addition to the information we describe in Section 2, each provider automatically receives certain technical information as part of normal operation, most importantly your IP address which can reveal your approximate location (typically country or region, not a precise GPS location).
Apple — Sign in with Apple, App Store distribution, and in-app subscription billing. In addition to what Apple shares with us (Section 2.2), Apple processes your Apple ID, IP address, device information, and purchase records under its own terms. See https://www.apple.com/legal/privacy/.
Google Firebase (Google LLC) — Authentication, Firestore database, Cloud Storage (Cloud Backup), Cloud Functions, Crashlytics, and App Check. Firebase automatically receives your IP address, a randomly assigned anonymous device identifier (the Firebase installation ID), App version, device model, operating system version, and the time of each request. Firebase uses this information to operate the service, prevent abuse, and (for Crashlytics) group similar crashes. We do not use Firebase Analytics or any cross-app advertising identifiers in Magic Track. See https://firebase.google.com/support/privacy.
RevenueCat — Subscription entitlement management. RevenueCat receives your account identifier (the same pseudonymous ID we use for your account) along with your IP address, Apple's Identifier for Vendor (IDFV — an identifier scoped to apps from the same developer), device model, operating system version, App version, device locale, and a record of subscription events (trial and promotional grants, purchase, renewal, cancellation). RevenueCat uses this information to verify your entitlement, detect fraudulent purchases, and provide their service to us. See https://www.revenuecat.com/privacy.
We only share information with these providers as needed to provide the App's features. We do not direct them to use your data for advertising or for tracking you across other apps or websites.
The App may also contain links that open in your browser (for example, to our website, the App Store, or partner communities such as a Facebook group). Those external sites and services are governed by their own privacy policies, not this one.
5. Data Sharing and Disclosure
We do not share your information with third parties except:
As described in Section 4 (service providers acting on our behalf).
If required by law, valid legal process, or to protect the rights, property, or safety of Magic Digital, LLC, our users, or the public.
In connection with a merger, acquisition, or sale of all or a portion of our business. We would notify users before any such transfer changes how their data is handled.
6. Data Security
We use industry-standard security practices to protect your information, including encryption in transit (TLS) and encryption at rest for Cloud Backup snapshots and our Firebase data. Access to our backend systems is limited and authenticated. Firebase App Check (using Apple's App Attest) helps us reject requests that don't come from the legitimate App. No system is perfectly secure, however; we cannot guarantee absolute security and ask you to keep your Apple ID credentials private.
7. Data Retention and Deletion
Local data (your logs, badges, settings) remains on your device until you delete the App, sign out, or delete your account.
Cloud Backup remains in our secure cloud until you delete it in Settings → Cloud Backup or until your account is deleted (Section 9). We do not delete Cloud Backups automatically.
Community contributions (aggregated counts and leaderboard entries) remain in our community totals indefinitely so the totals remain accurate. Aggregated counts are not individually deletable; your leaderboard entries and account-specific records are removed upon account deletion.
Support tickets (in Firestore and on the Trello board, including any email you chose to share) are retained for as long as needed to resolve your inquiry and for a reasonable period afterward for record-keeping, typically up to 24 months, and are deleted when you delete your account.
Subscription and promotional-grant records (entitlement status, anonymous purchase identifiers, promo-code redemptions) are retained as long as needed for entitlement verification, refunds, and bookkeeping, and as required by tax and accounting laws. Records held with your account identifier are deleted when you delete your account.
Crash reports are retained by Firebase Crashlytics for up to 90 days, after which they are automatically deleted.
Connection logs held by our service providers (IP addresses tied to requests) are retained according to each provider's policy and are typically purged within a short window.
Referral program data. If you generate a referral code, we store the code, the date it was created, a count of how many times it has been redeemed, and whether you have received the one-time referral reward. If you redeem a code, we store a record of the redemption, including which code you redeemed, so we can enforce the one-code-per-account limit and credit the code's owner. This data is used only to operate the referral program and is not used for advertising or shared with third parties. Deleting your account permanently deletes your referral code and all of your referral records. If you participated in the referral program, the referral records of other users you exchanged codes with (for example, a friend who redeemed your code) keep a randomly generated internal account identifier after your account is deleted. This identifier is not your name, email address, or Apple ID, and because the records connecting it to you are deleted as described above, it cannot be tied back to you.
8. Children's Privacy
Magic Track is not directed to children under the age of 13. We do not knowingly collect personal information from children under the age of 13. Sign in with Apple is gated by Apple's Family Sharing and Screen Time controls, and community Usernames and Cloud Backup both require Sign in with Apple. If you believe a child under the age of 13 has provided personal information through the App, please contact us so we can take appropriate action.
9. Your Rights and Choices
You can at any time:
Turn off "Share My Stats with Community" in Settings → Privacy.
Turn off "Help Improve the App" in Settings → Privacy.
Turn off "Show Username on Community Records," or edit or remove your Username, in Settings.
Delete and stop creating Cloud Backups in Settings → Cloud Backup.
Manage or cancel your subscription in Settings → Apple Account → Subscriptions on your iPhone.
Sign out in the App's Settings — this uploads a final Cloud Backup (if you have Cloud Backup on) and then clears all Magic Track data from that device; your cloud data remains available for when you sign back in.
Delete the App from your device to remove all local data (this does not delete your Cloud Backup or cancel your subscription).
Delete your account permanently — see "How to Delete Your Account" below.
Depending on where you live, you may have additional rights (see Sections 10 and 11).
How to Delete Your Account
You can permanently delete your Magic Track account at any time. We provide two paths.
In the App (recommended). Open Settings → Account → Delete My Account (shown as Delete All Data if you haven't signed in with Apple), then confirm. If you signed in with Apple, you will be asked to confirm once more with Apple; this final confirmation also revokes Magic Track's access to your Apple ID.
When you delete in-app, we will:
Delete your Cloud Backup snapshot from Cloud Storage.
Delete your user profile, claimed Username, leaderboard standings and other Community records tied to you (high scores, single-day and all-time records, streaks, and similar per-user stats), your support ticket history (including any email you shared and the copies of your tickets on our internal triage board), your promotional-code redemption records, and any pending catalog suggestions from our Firestore database.
Delete your subscription-management record (the RevenueCat subscriber record, including trial and promotional grant history).
Clear the diagnostics identifier (install ID) stored on your device and stop associating any future diagnostics with you.
Delete your Sign in with Apple identifier from Firebase Authentication and revoke the App's access to your Apple ID.
Sign you out, erase all Magic Track data from your device, and reset the App to its first-launch state.
These steps typically complete within a minute or two, after which the App resets to a fresh state.
By email (fallback). If you can't use the in-app control (for example, you've lost access to the device) email support@magictrackapp.com from the address tied to your Sign in with Apple account, or include enough detail for us to identify your account. We will process the request within 30 days as required by applicable law.
What deletion removes. Your Cloud Backup, user profile, Username, leaderboard standings and Community records (high scores, single-day and all-time records, streaks, badge progress, and similar per-user stats), support tickets (including any email you shared, and their copies on our internal triage board), promotional-code redemption records, pending catalog suggestions, your subscription-management (RevenueCat) record, the diagnostics (install-ID) identifier stored on your device, and your Sign in with Apple identifier.
What survives deletion. Aggregated community totals (for example, the all-time number of times an attraction has been logged) remain in our community statistics because they are anonymized rollups and cannot be traced back to you. Anonymized crash reports you previously submitted (only if you turned on diagnostics) may remain in Crashlytics under its standard retention (typically up to 90 days) and then age out automatically. These reports are keyed only to an anonymous install ID, never to your account or Apple ID, and the records that connected that install ID to your account are deleted as described above, so they cannot be tied back to you.
This action is irreversible. Once your account is deleted, your Cloud Backup cannot be restored. If you reinstall the App and sign in again, you will start fresh.
10. Notice to California Residents (CCPA / CPRA)
California residents have the right to:
Know what personal information we collect about them.
Request deletion of their personal information.
Correct inaccurate personal information.
Opt out of the "sale" or "sharing" of personal information.
Limit the use of sensitive personal information.
We do not "sell" or "share" personal information as those terms are defined under California law. We do not use personal information for cross-context behavioral advertising. We do not knowingly collect sensitive personal information.
To exercise your California privacy rights, contact us at the email below. We will not discriminate against you for exercising these rights.
11. Notice to Residents of the European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are located in the EEA, the UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent laws, including the right to access, correct, delete, or port your personal data, and to object to or restrict our processing of it.
The legal bases on which we rely are:
Consent — for opt-in community stat sharing, crash reporting, and Cloud Backup (you can withdraw at any time in Settings).
Contract performance — for fulfilling subscriptions, trials, and promotional grants, providing Cloud Backup/restore, and responding to your support tickets.
Legitimate interests — for diagnosing crashes, providing support, and protecting the App from abuse.
To exercise your rights or for any complaint, contact us at the email below. You also have the right to lodge a complaint with your local data protection authority.
12. International Data Transfers
Our service providers (Apple, Firebase, RevenueCat, Trello) may process data on servers located in the United States and other countries. By using the App, you understand that information may be transferred to and stored in countries other than your own. Where required by law, we rely on standard contractual safeguards for these transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time as the App evolves. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, surface a notice in the App. Continued use of the App after a change indicates acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or our handling of your information, please contact us at support@magictrackapp.com