Privacy Policy
Last updated: August 11, 2026 • Effective: August 11, 2026
Key Points at a Glance
- Your readings, medications, notes and tags are stored in a database on your phone. There is no account, and we hold no copy of them
- Two things do leave your phone, and both are described in full below: photos you take with “Scan your monitor” (Section 2.5) and anonymous app-usage and crash data (Sections 2.2, 5.1, 5.3)
- Scan is optional. When the App cannot read your monitor on the device, it sends the photo to our server and on to OpenAI to read the numbers — and your readings are visible on the display in that photo. If you would rather nothing left your phone, type the numbers in instead
- Syncing with Apple Health / Health Connect is optional and off by default — that exchange stays on your own device (Section 2.4)
- We use Firebase (Analytics, Crashlytics, Remote Config, Cloud Functions, Cloud Messaging, Firestore) and RevenueCat — payment is processed entirely by Apple or Google
- No advertising SDKs, no advertising ID, no ad targeting. We do not sell, rent or trade your data
- Your health data is never used for advertising, insurance, lending or employment decisions
- “Delete all my data” in Settings erases everything the App stores on your phone (Section 8.3). You can also export everything to Excel or PDF
- No registration, no login, no password
1. Introduction
This Privacy Policy explains how Simple Blood Pressure Monitor ("the App", "we", "us", "our"), developed and operated by Borys Kusmirek ("Data Controller"), collects, uses, stores, and protects your information. This policy applies to both the iOS and Android versions of the App.
Data Controller: Borys Kusmirek
Contact email: favamvv@gmail.com
By using the App, you acknowledge that you have read and understood this Privacy Policy. The legal bases we rely on, including where we rely on your consent, are set out in Section 4.
2. Information We Collect
2.1. Health Data You Enter (Stored on Your Device)
The following data is entered by you and stored in a local SQLite database on your device. We have no server-side copy of it, no account to hold it in, and no way to read it:
- Systolic and diastolic blood pressure readings (mmHg)
- Pulse / heart rate measurements (bpm)
- Body weight (optional, if you choose to log it)
- Measurement context: arm used and body position (optional)
- Medications you track (name, dosage, schedule) and their association with readings
- Date and time of each measurement
- Personal notes you attach to readings
- Tags you assign to readings (e.g., morning, evening, after meds, stress, rest, after exercise)
- Custom tags you create
Your readings are not uploaded to us as data. There are, however, three situations in which information about your health can move off the device, and we want you to see them stated plainly:
- “Scan your monitor” photos. The display in the photo shows your reading, and some photos are sent to a server for reading. This is fully described in Section 2.5.
- Apple Health / Health Connect sync, if you turn it on. This exchange happens on your own device, between the App and your operating system’s health store — not with us. See Section 2.4.
- Files you export yourself (Excel or PDF) and then send somewhere. See Section 8.
Beyond those, the analytics and crash data described in Section 2.2 record that a feature was used, not the values you recorded. The App does not put your systolic, diastolic, pulse, weight, notes or tag text into any analytics event or crash report.
Under GDPR, blood pressure and pulse data are classified as "Special Category Data" (Article 9). For the data described in this section we act as a controller only in a limited sense: it is stored on your device under your control. Where we do process special category data — the scan photo — the legal basis is set out in Section 4.
2.2. Usage and Technical Data (Collected Automatically)
When you use the App, the following data is collected automatically by integrated third-party services to help us keep the App working and improve it. None of it contains your blood pressure values, notes or tag text:
| Data Type | Purpose | Collected By |
|---|---|---|
| App instance identifier (anonymous) | Distinguishing unique app installations | Firebase Analytics |
| App usage events — e.g. that a reading was added (with only true/false flags for “had tags” and “had notes”), a reminder was set, a paywall was shown, a purchase completed, data was exported, imported or deleted, onboarding finished | Understanding how users interact with the App | Firebase Analytics |
| Device information (OS version, app version, device model) | Ensuring compatibility, debugging issues | Firebase Analytics |
| Approximate location (country/region level only, derived from IP address) | Understanding geographic usage patterns | Firebase Analytics |
| Crash reports: stack traces, device model, OS and app version, and the sequence of events leading to a crash | Finding and fixing crashes and fatal errors | Firebase Crashlytics |
| A/B test group assignment | Optimizing the app experience via feature experiments | Firebase Remote Config |
| Push notification device token | Allowing us to send app announcements and reminders from our side | Firebase Cloud Messaging |
| Anonymous sign-in identifier (created only when you use “Scan your monitor”) | Authorising the call to our scan server so strangers cannot use it | Firebase Authentication |
| Anonymous user identifier, purchase history, subscription status | Managing subscriptions, verifying entitlements, fraud prevention | RevenueCat |
2.3. Information We Do NOT Collect
- We do not collect your name, email address, phone number, or any personally identifiable account credentials
- We do not require account registration or login. The App does create an anonymous Firebase sign-in in the background, but only when you use “Scan your monitor” (Section 5.5), and it carries no name, email or password
- We do not collect precise location (GPS) data
- We do not access your contacts or your microphone, and the App requests no microphone permission
- We do not collect an advertising ID. The App ships no advertising SDK, and the Android build explicitly removes the
AD_IDandACCESS_ADSERVICES_AD_IDpermissions that the analytics library would otherwise add - We do not use ad trackers or collect data for ad targeting, and we run no advertising in the App
- The camera is used only when you choose “Scan your monitor”. What happens to that photo is described in the next section — please read it.
2.4. Apple Health & Health Connect (Optional Sync)
The App offers an optional, off-by-default integration with Apple Health (HealthKit) on iOS and Health Connect on Android. If — and only if — you enable Health Sync in the App’s settings and grant permission through the operating system’s permission dialog, the App will:
- Write your blood pressure, heart rate, and weight entries to Apple Health / Health Connect, so they are available to you in your device’s health app
- Read blood pressure, heart rate, and weight data from Apple Health / Health Connect, in order to display it in the App and to let you import readings recorded by other apps or devices
This exchange happens entirely on your device, between the App and the health data store managed by your operating system. Health data obtained from Apple Health or Health Connect:
- is used solely to display your readings, statistics, trends, and insights within the App, and to enable the export features you invoke;
- is not transmitted to our servers or to any third party. We do record a count of how many readings an import brought in, as an analytics event — the number of readings, never the readings themselves;
- is never used for advertising, marketing, credit, insurance, employment assessment, or any form of profiling;
- is never sold or shared.
You can revoke access at any time: on iOS via Settings → Privacy & Security → Health, and on Android via the Health Connect app’s permission settings, or simply by turning Health Sync off in the App. Disabling sync stops all reads and writes immediately. Note that data previously written to Apple Health may be included in your iCloud Health sync if you have that enabled — that synchronization is governed by Apple’s privacy policy, not ours.
2.5. “Scan Your Monitor” — Camera Photos and Cloud Processing
“Scan your monitor” is an optional feature, available to Premium subscribers, that lets you photograph your blood pressure monitor instead of typing the numbers. You start every scan yourself; the App never opens the camera or sends a photo on its own.
When you take a scan photo, the App works in two steps:
- On your device first. The photo is read by the text-recognition engine built into your operating system (Apple Vision on iOS, ML Kit on Android). If all three values — systolic, diastolic and pulse — are read successfully, the process stops there and the photo does not leave your phone.
- In the cloud, if step 1 falls short. If any of the three values could not be read on the device — a dim display, glare, an unusual layout — the App encodes the photo and sends it over an encrypted connection to a Cloud Function we operate on Google Cloud (United States). That function passes the image to OpenAI’s API, which returns the three numbers, and the function sends only those numbers back to your phone.
What this means in plain terms: your monitor’s display — and therefore that reading — is inside the photo. When a scan falls through to step 2, an image of your blood pressure reading is sent to our server and to OpenAI. You cannot tell from the screen which of the two paths a given scan took, so please assume that any scan may be sent. If you do not want this to happen, do not use Scan: enter your numbers with the dial instead. Every feature of the App works without it.
What is kept, and by whom:
- On your device: the photo is written to the App’s temporary storage while it is being read. The App does not add it to your photo library and does not store it in your reading history or database. Temporary files are cleaned up by your operating system.
- On our server: the Cloud Function does not save your photo. It holds the image in memory only for the length of the request (30 seconds at most), forwards it, returns three numbers, and writes nothing — the photo is not placed in any database, file store, or log of ours, and we do not keep the values the model returns.
- At OpenAI: once the image reaches OpenAI it is covered by OpenAI’s data policy for API traffic, not by ours. OpenAI states that data sent through its API is not used to train its models, and that abuse-monitoring logs — which can contain the content of a request — are retained for up to 30 days, unless a longer period is required by law or is reasonably necessary to prevent harm. We rely on that published policy (see OpenAI: Data controls in the OpenAI platform); we have no visibility into OpenAI’s systems and cannot independently verify it.
The photo is sent with no name, no email address, and no link to your readings. The request carries the image plus the anonymous Firebase credentials that authorise it — whose only purpose is to stop people who do not have the App from calling our server (Section 5.5) — and nothing else that we add. We do not use scan photos for training, analytics, profiling, advertising, or any purpose other than reading the three numbers back to you.
2.6. Feature Requests (Optional)
The App includes a feature-request board where you can suggest and vote on ideas. If you choose to submit or like a request, the following is written to our Cloud Firestore database:
- The title and description you type. Please do not include health details or anything identifying — approved requests are visible to every user of the App.
- A random identifier generated on your device the first time you use the board. It is not derived from your device, your name or anything about you; it exists so that you can see your own pending requests and remove them, and so that a request can only be liked once per device.
- The time of submission, the like count, and the identifiers that liked it.
Opening the board queries Firestore for approved requests and for any pending ones of your own, which sends that random identifier to Google but writes nothing. If you never open the board, no identifier is created and nothing is stored. You can delete your own request from within the App.
3. How We Use Your Information
- Health data on your device: Processed on your device by the App to display your readings, calculate averages and trends, generate charts, categorize blood pressure levels, produce insights, and enable you to export your data. If you enable the optional Health Sync (Section 2.4), the App also exchanges blood pressure, heart rate, and weight data with Apple Health / Health Connect on your device.
- Scan photos: Used for one purpose only — extracting systolic, diastolic and pulse so they can be pre-filled into a new reading (Section 2.5).
- Firebase Analytics data: Used in aggregate to understand feature usage patterns, improve app performance, and optimize the onboarding and subscription experience.
- Firebase Crashlytics data: Used to find, prioritise and fix crashes and fatal errors.
- Firebase Remote Config data: Used to determine which version of certain app screens you see (A/B testing) to optimize the user experience. No health data is used for experiment targeting.
- Firebase Cloud Messaging: Used to send app announcements and re-engagement messages from our side.
- Feature requests: Used to decide what to build next, and shown publicly in the App once approved.
- RevenueCat data: Used to verify your subscription entitlements, manage purchase restoration across devices, and prevent subscription fraud. Actual payment processing is handled entirely by Apple (App Store) or Google (Play Store) — we never receive your credit card or financial information.
We do not sell, rent, trade, or share your personal or health data with advertisers, data brokers, insurance companies, employers, or marketing platforms. Your health data is never used for advertising, profiling, insurance scoring, lending decisions, or any purpose other than the ones described in this policy.
4. Legal Basis for Processing (GDPR)
For users in the European Union / European Economic Area, we rely on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Health data stored and displayed on your device | Not applicable — this data stays on your device under your control; we hold no copy |
| Scan photo sent for cloud reading (special category data, Art. 9) | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — no photo is ever sent unless you choose to start a scan. You can withhold or withdraw it by not using the feature and entering numbers manually |
| App usage analytics (Firebase Analytics) | Legitimate interest (Art. 6(1)(f)) — improving app quality and user experience |
| Crash and error diagnostics (Firebase Crashlytics) | Legitimate interest (Art. 6(1)(f)) — keeping the App stable and safe to use |
| A/B testing (Firebase Remote Config) | Legitimate interest (Art. 6(1)(f)) — optimizing app features |
| Feature requests (Cloud Firestore) | Consent (Art. 6(1)(a)) — nothing is written unless you submit or like a request |
| Subscription management (RevenueCat) | Performance of contract (Art. 6(1)(b)) — fulfilling your subscription purchase |
| Reminders and push messages | Consent (Art. 6(1)(a)) — see the note below on how permission is requested |
A note on notification permission. On Android, the App asks for notification permission with the system prompt. On iOS, the App requests provisional authorization for push messages, which lets them arrive quietly in Notification Center without a prompt the first time; you can then keep or turn them off from the notification itself, or in Settings → Notifications. Scheduled reminders you set up in the App always require the standard permission prompt.
You may withdraw consent for notifications at any time in your device settings or within the App. You may object to analytics or crash-diagnostics processing by contacting us (see Section 15).
5. Third-Party Services
The App integrates the following third-party services. Each operates as a data processor under their respective terms and privacy policies:
5.1. Firebase Analytics (Google LLC / Google Ireland Limited)
- Purpose: Understanding how users interact with the App, measuring feature adoption, identifying performance issues
- Data collected: App instance identifier, usage events, device type, OS version, app version, session duration, approximate country/region. Event parameters are limited to non-health values such as a feature name, a subscription product ID, a true/false flag, or a count
- Data processor: Google LLC (US) / Google Ireland Limited (for EEA users)
- Retention: Google retains user-level Analytics records for the period configured for our Firebase project, up to a maximum of 14 months; aggregated, non-identifying reports derived from that data are retained by Google indefinitely
- Opt-out: The App does not currently include an in-app analytics switch. You can stop all collection by uninstalling the App, and you can email us at favamvv@gmail.com to object to analytics processing or ask us to delete the data associated with your installation
- Privacy policy: Google Privacy Policy • Firebase Privacy & Security
5.2. Firebase Remote Config (Google LLC / Google Ireland Limited)
- Purpose: Delivering app configuration and managing A/B tests for feature optimization (e.g., which promotional screens are displayed)
- Data collected: Firebase Installation ID (anonymous identifier) transmitted as part of configuration requests
- No health data is transmitted via this service
- Privacy policy: Firebase Privacy & Security
5.3. Firebase Crashlytics (Google LLC / Google Ireland Limited)
- Purpose: Automatically reporting crashes and fatal errors so they can be fixed
- Data collected: Stack traces, exception messages, a Crashlytics installation identifier, device model, operating system version, app version, and device state at the time of the crash (such as available memory). We do not attach your name, email, or any of your readings to crash reports
- When it runs: Crash reporting is enabled in all released versions of the App
- Data processor: Google LLC (US) / Google Ireland Limited (for EEA users)
- Retention: Google retains crash reports for up to 90 days from the date of the crash
- Privacy policy: Firebase Privacy & Security
5.4. Firebase Cloud Functions & OpenAI (scan processing)
- Purpose: Reading the systolic, diastolic and pulse values from a photo of your monitor when your device could not read them itself (Section 2.5)
- Data sent: The photo you took, and nothing else. No name, no email, no reading history, no device identifier beyond the anonymous sign-in described in Section 5.5
- Data processors: Google LLC (Cloud Functions, United States) and OpenAI, L.L.C. (United States), as a sub-processor of the image
- Retention: Our function stores nothing — the image exists only in the memory of the server handling your request, for at most 30 seconds. OpenAI states that API data is not used to train its models and that abuse-monitoring logs, which may contain request content, are kept for up to 30 days unless a longer period is legally required
- Privacy policies: Firebase Privacy & Security • OpenAI Privacy Policy • OpenAI data controls
5.5. Firebase Authentication — Anonymous Sign-In (Google LLC / Google Ireland Limited)
- Purpose: Proving that a scan request comes from the App and not from a stranger on the internet. This is the only reason it exists
- When it happens: The first time you use “Scan your monitor”. If you never use Scan, no account is ever created
- Data collected: A randomly generated user ID with no name, email address, password, or health data attached to it, and no link to your readings
- Retention: The anonymous account record remains in our Firebase project. It cannot be used to identify you
- Privacy policy: Firebase Privacy & Security
5.6. Cloud Firestore (Google LLC / Google Ireland Limited) — feature requests only
- Purpose: Storing the feature-request board (Section 2.6)
- Data collected: The title and description you write, a random device-generated identifier, a timestamp, and like counts. Approved requests are publicly readable by other users of the App
- Not stored here: your readings, medications, notes, tags, or any other health data
- Retention: Until you delete your request in the App, or we remove it. Requests we decline may be deleted by us at any time
- Privacy policy: Firebase Privacy & Security
5.7. Firebase Cloud Messaging (Google LLC / Google Ireland Limited)
- Purpose: Delivering push messages we send — app announcements and occasional reminders to come back and log a reading
- Data collected: A device push token issued by Google, and a flag in Firebase Analytics recording that this installation can receive push messages. We do not attach your push token to your readings
- Retention: Tokens rotate over time, and a token stops being deliverable once the App is uninstalled
- Opt out: Turn off notifications for the App in your device’s system settings
- Privacy policy: Firebase Privacy & Security
5.8. RevenueCat, Inc.
- Purpose: Managing in-app subscriptions, validating purchases, and providing access to premium features
- Data collected: Anonymous app user identifier ($RCAnonymousID), purchase history (product IDs, transaction dates, expiration dates), subscription status, entitlements, app version, OS, device type
- Data processor: RevenueCat, Inc. (United States)
- Payment processing: All payment processing is handled by Apple (App Store) or Google (Play Store). We never receive your credit card number, billing address, or other financial information.
- Retention: Transaction data is retained for the duration of your use of the App plus up to 6 years for legal and tax compliance
- Data Processing Addendum: RevenueCat’s DPA incorporating Standard Contractual Clauses is part of their Terms of Service
- Privacy policy: RevenueCat Privacy Policy
5.9. Local Notifications (flutter_local_notifications)
- Purpose: Sending you daily blood pressure measurement reminders at times you choose
- Data collected: None transmitted externally. Notification schedules are stored on your device only.
- Permission: Requires your notification permission, which you can revoke at any time in your device’s system Settings → Notifications → Blood Pressure
6. Data Sharing and Disclosure
- Readings, medications, notes and tags: Not shared with anyone. They stay in the database on your device.
- Scan photos: Shared with Google (Cloud Functions) and OpenAI, solely to read the numbers off the display, and only for scans your device could not read on its own. See Section 2.5.
- Usage, crash and subscription data: Shared with Google (Firebase) and RevenueCat only as described in Section 5, strictly for the purposes stated.
- Feature requests: Text you submit is stored in Cloud Firestore and, once approved, shown publicly to other users of the App.
- We do not share data with data brokers, advertisers, marketing platforms, insurance companies, or employers.
- We may disclose information if required by law, court order, or governmental regulation, or if necessary to protect our legal rights.
7. Data Storage and Retention
| Data Category | Storage Location | Retention Period |
|---|---|---|
| Health data (readings, medications, notes, tags) | Your device only (SQLite) | Until you delete it in the App, use “Delete all my data”, or uninstall the App |
| Notification preferences and reminder schedules | Your device only | Until you change settings, use “Delete all my data”, or uninstall the App |
| Scan photo — on our server | Google Cloud Functions (US), in memory only | Not stored. Held only for the duration of the request (30 seconds maximum) |
| Scan photo — at OpenAI | OpenAI servers (US) | Per OpenAI’s published API policy: not used for training; abuse-monitoring logs kept up to 30 days unless a longer period is legally required |
| Firebase Analytics (user-level) | Google servers (US/EU) | Up to 14 months, per the setting configured for our Firebase project |
| Firebase Crashlytics crash reports | Google servers (US/EU) | Up to 90 days |
| Anonymous Firebase sign-in ID (scan only) | Google servers (US/EU) | Retained in our Firebase project; contains no personal details |
| Feature requests you submit | Cloud Firestore (Google servers) | Until you delete the request, or we remove it |
| RevenueCat subscription data | RevenueCat servers (US) | Duration of use + up to 6 years (legal compliance) |
8. Data Export, Portability, and Deletion
8.1. Export
You can export your blood pressure readings at any time from the App’s Settings screen, as an Excel (.xlsx) spreadsheet or as a PDF report. The exported file is saved to your device. Once exported, the file is under your sole control — any further sharing, storage, or transmission of that file is your responsibility.
8.2. Import
You may import readings from an Excel file back into the App, and — if Health Sync is enabled — from Apple Health or Health Connect.
8.3. “Delete all my data”
Settings contains a Delete all my data option. It asks you to confirm twice, showing your reading count before the final step, and then erases the following from your device:
- Every blood pressure reading, including the weight, arm and body position recorded with it
- Every medication, and every link between a medication and a reading
- Every tag, including custom tags you created (the standard tag list is then restored, empty of any association with you)
- Every scheduled reminder and medication notification, and your reminder times
- Your default systolic, diastolic and pulse values
- Your streak history and streak-freeze state, and your reading count
- The data shown in the home-screen widget
- Any readings still queued from an Apple Watch that have not been imported yet
It is immediate and cannot be undone. There is no backup, on our side or anywhere else.
What it deliberately does not touch:
- Apple Health / Health Connect samples. Readings the App previously wrote there belong to your operating system’s health store and are shared with every other app you have authorised. Only your health app can remove them — on iOS via the Health app, on Android via Health Connect. The App will not delete data it does not own.
- Your display preferences — theme, language and weight unit. These describe the App, not you.
- Files you already exported and saved or shared elsewhere.
- Data already held by third parties — Firebase Analytics and Crashlytics records, RevenueCat subscription history, any feature request you submitted, and any abuse-monitoring log OpenAI may hold from a scan. Deleting on-device data cannot reach these. To have them removed, email us (Section 15); note that subscription records may have to be kept for tax and legal compliance.
9. Your Rights
9.1. All Users
- Access & export: Export all your health data to Excel or PDF at any time, free of charge
- Delete health data: Delete individual readings within the App, erase everything on the device with “Delete all my data” (Section 8.3), or uninstall the App
- Avoid cloud scan processing: Simply do not use “Scan your monitor”. Manual entry keeps every reading on the device
- Opt out of analytics and crash reporting: Contact us at favamvv@gmail.com, or uninstall the App
- Disable notifications: Revoke notification permission in your device’s system Settings at any time
- Cancel subscription: Cancel anytime via your device’s subscription management (see our Terms of Service)
9.2. EU/EEA Users (General Data Protection Regulation)
Under the GDPR, you have the following rights regarding personal data we process:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate personal data
- Right to erasure / "Right to be forgotten" (Art. 17): Request deletion of your personal data
- Right to restrict processing (Art. 18): Request that we limit how we use your data
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format — the App’s Excel export does exactly this for your readings
- Right to object (Art. 21): Object to processing based on legitimate interest (analytics, crash diagnostics)
- Right to withdraw consent (Art. 7(3)): Stop using Scan, turn off notifications, or delete a feature request at any time; withdrawal does not affect the lawfulness of prior processing
- Right to lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, contact us at favamvv@gmail.com. We will respond within 30 days.
Note on health data. Your readings, medications, notes and tags live on your device and we hold no copy, so we cannot access, retrieve, correct or delete them for you — the App gives you direct control instead (Section 8.3). For data we or our processors do hold — analytics, crash reports, subscription records, feature requests — we will act on your request. Scan photos are not stored by us, so there is nothing for us to retrieve or delete; a request concerning OpenAI’s abuse-monitoring logs would have to be directed to OpenAI, and we will help you where we can.
9.3. California Users (CCPA/CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act, you have the following rights:
- Right to know: Request what personal information we collect, use, and share
- Right to delete: Request deletion of your personal information
- Right to correct: Request correction of inaccurate personal information
- Right to opt out of the sale or sharing of personal information: We do not sell or share your personal information as defined by the CCPA/CPRA
- Right to limit use of sensitive personal information: Your blood pressure and pulse data is Sensitive Personal Information under the CPRA. Almost all of it stays on your device, outside our reach. The exception is a scan photo, which shows your reading and is sent for processing when your device cannot read it — we use it only to return those numbers to you, and never to infer characteristics about you. You can limit this completely by not using Scan
- Right to non-discrimination: We will not discriminate against you for exercising any of these rights
Categories of personal information collected in the preceding 12 months:
- Identifiers: Anonymous app installation ID (Firebase), anonymous sign-in ID used for Scan, push notification token, anonymous subscription identifier (RevenueCat), and a random device identifier if you use the feature-request board
- Commercial information: Subscription purchase history (via RevenueCat)
- Internet or network activity: App usage events, crash diagnostics, device and OS information
- Sensitive personal information: Health data contained in a scan photo, for scans processed in the cloud (Section 2.5)
- Content you choose to submit: Feature-request text
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
9.4. Washington State Users (My Health My Data Act)
Under the Washington My Health My Data Act (MHMDA), your blood pressure and pulse data is "consumer health data."
- The readings you enter and store in the App are kept on your device. We do not collect, share, or sell them.
- If you use “Scan your monitor” and your device cannot read the display, the photo — which shows a reading — is collected by us for the sole purpose of extracting those three numbers and returning them to you, and is processed by OpenAI as our service provider. We do not sell it, and we do not use it for any other purpose. Section 2.5 sets out exactly what is kept and for how long.
- You can avoid this collection entirely by entering your readings manually.
- You may request deletion of consumer health data we hold by emailing favamvv@gmail.com. We will confirm and act on your request; see Section 8.3 for what is and is not within our reach.
9.5. Other US State Privacy Laws
We respect the privacy rights of users in all US states with comprehensive privacy legislation, including but not limited to Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. If you are a resident of any of these states and wish to exercise your privacy rights, please contact us at favamvv@gmail.com.
10. International Data Transfers
The readings stored on your device are not transferred anywhere.
The following are processed on servers outside the EU/EEA, principally in the United States: scan photos (Google Cloud Functions and OpenAI), usage and crash data (Firebase Analytics and Crashlytics), push tokens (Firebase Cloud Messaging), feature requests (Cloud Firestore), and subscription data (RevenueCat). These transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework (where applicable)
- Additional technical and organizational security measures implemented by Google, OpenAI and RevenueCat
11. Data Security
- Your on-device health data is protected by your device’s built-in security features, including screen lock, full-disk encryption, and secure enclave (where available)
- Your reading history is not stored in any database we operate, so there is no server-side copy of it that could be breached
- Everything the App does send — scan photos, analytics, crash reports, subscription checks — travels over encrypted HTTPS/TLS connections. Our scan endpoint rejects requests that do not come from an authenticated App install, and the API key it uses is held server-side and never shipped inside the App
- Firebase, OpenAI and RevenueCat employ industry-standard encryption for data in transit and at rest
- We follow the principle of data minimization: the scan request carries the photo and nothing else, and analytics events carry counts and flags rather than your measurements
- No transmission over the internet can be guaranteed to be completely secure. Where a feature involves sending data, we tell you plainly, so that you can choose not to use it
12. Children’s Privacy
The App is not directed at children under 13 years of age (or 16 years of age in the European Union under GDPR). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has used the App, please contact us at favamvv@gmail.com and we will take steps to delete any associated data.
13. Health and Medical Disclaimer
This App is NOT a medical device. It has not been evaluated, cleared, or approved by the FDA (U.S. Food and Drug Administration), CE (European Conformity), or any other medical regulatory authority worldwide. The App is intended solely for personal health tracking and informational purposes.
- The App does not provide medical advice, diagnosis, prognosis, or treatment recommendations
- Blood pressure readings are entered by you, or read from a photo of your own monitor, and are not independently measured or verified by the App. Automatic scanning can misread a display — always check the numbers before saving them
- The blood pressure categories displayed (Hypotension, Normal, Prehypertension, Hypertension Stage 1, Hypertension Stage 2) are based on general medical guidelines and are for informational reference only
- Always consult a licensed physician or qualified healthcare professional for medical advice, diagnosis, or treatment
- Do not disregard professional medical advice, delay seeking medical treatment, or change prescribed medication based on information from this App
- In a medical emergency, contact your local emergency services immediately
In accordance with Regulation (EU) 2025/327 (European Health Data Space), we confirm that your health data is never used for advertising, insurance underwriting, lending decisions, employment decisions, or any purpose other than those described in this policy.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, third-party services, or applicable laws. When we make material changes:
- We will update the "Last updated" date at the top of this page
- For significant changes, we may provide additional notice within the App
Your continued use of the App after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise any of your privacy rights, or want to report a concern, please contact us:
- Developer: Borys Kusmirek
- Email: favamvv@gmail.com
We will acknowledge your request within 5 business days and respond substantively within 30 days. If we need additional time, we will notify you of the reason and expected timeline.
Disclaimer: This Privacy Policy is provided for informational purposes and is intended to be as comprehensive and accurate as possible. However, it does not constitute legal advice. We recommend consulting with a qualified attorney if you have specific legal concerns about data privacy.