Privacy Policy

Last updated: April 7, 2026

This Privacy Policy explains how HealthLists collects, uses, and protects personal data when you use the HealthLists Android app and web app.

1. Data We Collect

  • Account data: email address, password hash, optional display name, and Google account ID (if you use Google Sign-In).
  • App content: workouts, nutrition logs, tasks, challenge participation, and profile preferences you create in the app.
  • Optional health data (only if you grant permissions): steps, sleep, heart rate, active calories, and distance from Health Connect.
  • Device and diagnostics data: technical logs needed to operate, secure, and troubleshoot the service.
  • Advertising-related data: for free tiers, Google AdMob may process advertising identifiers and related ad signals.

2. Permissions and Sensitive Access

  • Camera: used for barcode scanning only.
  • Activity recognition: used for step tracking features.
  • Health Connect permissions: used only for the specific health metrics you allow.

3. How We Use Data

  • To provide core app functionality, including authentication, syncing, and your personalized tracking data.
  • To maintain app security, prevent abuse, and fix technical issues.
  • To deliver ads in non-premium/ad-supported experiences.
  • To communicate important account and security notifications (for example, password reset emails).

4. Third-Party Services

HealthLists integrates with third-party services such as Google Sign-In, Google Play services (including AdMob), and Open Food Facts. These providers may process data according to their own privacy policies.

5. Data Sharing

We do not sell personal data. We may share limited data with infrastructure and service providers that help us run HealthLists, or when required by law.

6. Data Retention and Deletion

We retain account and usage data while your account is active and as needed for legitimate operational and legal purposes. You can request account/data deletion by contacting us.

7. Children

HealthLists is not directed to children under 13. If you believe a child has provided personal data, contact us so we can remove it.

8. Security

We use reasonable technical and organizational safeguards, but no system can be guaranteed 100% secure.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date on this page.

10. Contact

For privacy questions or deletion requests, contact: privacy@healthlists.org