Gentler is a fitness and health tracking app that uses HealthKit data to monitor workouts, heart rate variability (HRV), sleep patterns, and other health metrics for personalized fitness insights.
This app cleared every trust check that applied to it, with no red flags.
The five trust checks
Quick Verdict
Best for: People who keep workout and activity data on their own
What It Means For You
Health and workout metrics stay on the device and are not sent to any third-party service. App usage and session data is shared with Mixpanel for analytics and Adjust for attribution. Advertising identifier access requires explicit user consent before it can be activated.
Quick Verdict
Best for: People who keep workout and activity data on their own
What It Means For You
Health and workout metrics stay on the device and are not sent to any third-party service. App usage and session data is shared with Mixpanel for analytics and Adjust for attribution. Advertising identifier access requires explicit user consent before it can be activated.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Version diff is on the Developer plan. See developer plans.
Context Tags
Package
app.gentler.activity
Version
5.12.9 (Build 668)
Analysis Date
Jul 29, 2026
Classes Analyzed
86,934
Feedback helps us improve our analysis
A highly secure fitness tracking app with on-device health metrics and HTTPS enforcement throughout. Analytics SDKs are properly gated, external browsing is sandboxed, and HealthKit data never leaves the device. Gentler Activity reflects strong security discipline across its core data flows.
Data Security: 0 findings
Network Security: 0 findings
Code Safety: 0 findings
Privacy: 0 findings
Third parties that may receive data from the app:
Security: 97/100
Privacy: 90/100
The app's privacy practices could be strengthened by:
Remove Development Diagnostics from Release Builds
A Sentry development transport component is compiled into the release build. Removing development-only diagnostic tooling from production builds is recommended practice for minimizing the app's exposed surface.
Scope Review for Error-Reporting Ingest Key
The Sentry ingest key is embedded in the binary, which is standard practice for client-side error reporting. Confirming that the key's permissions are scoped to error ingestion only is a good operational hygiene step.
Review Session Replay Configuration
A Sentry session replay capability is compiled into the build but does not appear to be active. Confirming it remains disabled or removing it from the build would eliminate any future risk of session capture being inadvertently enabled.
App Type: Health and fitness tracking (high data sensitivity)
Classes Analyzed: 86,934
Third-Party Services: 5 (Mixpanel, Adjust, RevenueCat, Sentry, Lottie)
Context Tags: health, fitness, healthkit, analytics, tracking, attribution
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of iOS applications, intended to help people make informed decisions about app security and privacy.
Developer: Not available
Version: 5.12.9 (Build 668)
Analysis Date: 2026-07-29
Package: app.gentler.activity
Developer not yet contacted