HealthBit

Privacy Policy

Last updated: July 2, 2025

HealthBit (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fitness social platform available at healthbit.app and our Android application.

By using HealthBit, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.

1. Data We Collect

1.1 Account Information

  • Full name, email address, and profile photo
  • Username and public biography
  • City and country (for local leaderboards and challenges)

1.2 Fitness & Health Data

  • Activity logs: type, distance, duration, elevation, calories burned
  • GPS route data (polylines) collected from connected fitness apps
  • Body weight (optional, used only for calorie estimation)
  • Fitness integration access tokens (Google Fit, Health Connect)
  • Heart rate and workout metrics from supported integrations

1.3 Location Data

We collect GPS location data through fitness integrations (e.g., Google Fit, Health Connect) when you sync activities. Route polylines are stored to render maps of your activities. We do not track your location in real time without your explicit action of syncing an activity. City-level location is stored for leaderboard and challenge features.

1.4 Social Data

  • Posts, comments, and reactions you create or receive
  • Follow relationships (who you follow, who follows you)
  • Direct messages (end-to-end not encrypted — do not share sensitive info)
  • Stories and story views

1.5 Payment Data

Payment processing is handled by Stripe, Inc. We do not store your card number, CVV, or banking details. We store only a Stripe Customer ID and subscription status to manage your Pro membership.

1.6 Usage & Analytics Data

  • Feature usage events (e.g., “feed viewed”, “challenge joined”) via PostHog analytics
  • Device type, operating system, and browser (for compatibility)
  • Push notification preferences and tokens

2. How We Use Your Data

  • To provide and improve HealthBit features (feed, leaderboard, challenges, AI coaching)
  • To calculate XP, levels, streaks, and badges
  • To generate AI-powered insights via Google Gemini (only non-PII fitness data is shared)
  • To send transactional emails (welcome, weekly reports) via Resend
  • To process Pro subscription payments via Stripe
  • To send push notifications for activity updates, streaks, and challenges
  • To display location-based leaderboards and city challenges
  • To comply with legal obligations

3. Third-Party Services

We share minimal data with the following trusted third-party providers:

ProviderPurposeData Shared
SupabaseDatabase & authenticationAll user data (stored securely in Frankfurt, EU)
Google GeminiAI fitness coaching & insightsFitness stats only (no name, email, or payment data)
StripePayment processingEmail, name (for billing). Card data never touches our servers.
ResendTransactional emailEmail address, name
Firebase / FCMPush notificationsDevice push token
PostHogProduct analyticsAnonymous usage events, user ID (no email or fitness data)
Google OAuthSign-in & Google Fit accessName, email, profile photo (with consent)

4. Data Retention

  • Your account data is retained as long as your account is active
  • Activity and fitness data is retained until you delete your account
  • Push notification tokens are removed when you unsubscribe or delete your account
  • Analytics events are retained for up to 24 months by PostHog
  • Stripe billing records are retained per Stripe's data retention policy (7 years)
  • Backup data may be retained for up to 30 days after account deletion

5. Your Rights (India DPDP Act 2023 & GDPR)

You have the right to:

  • Access — request a copy of all data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — permanently delete your account and all associated data via Settings → Danger Zone → Delete Account, or by emailing us
  • Portability — request your data in a machine-readable format
  • Opt-out — opt out of AI nudges and weekly reports in Settings → Notifications
  • Withdraw consent — disconnect Google Fit/Health Connect integrations at any time

Account Deletion: You can delete your account at any time from Settings → Danger Zone → Delete Account. This permanently deletes all your data including activities, posts, messages, and payment history from our systems. Stripe billing records are subject to Stripe's own retention policy.

6. Cookies & Local Storage

We use session cookies for authentication (via Supabase Auth) and localStorage for user preferences. We do not use third-party advertising cookies. Analytics (PostHog) uses localStorage to store an anonymous session ID.

7. Security

All data is transmitted over HTTPS. Database access is controlled by Row-Level Security (RLS) policies — no user can access another user's private data. Payment data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.

8. Children's Privacy

HealthBit is not directed at children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification. Continued use of HealthBit after changes constitutes acceptance of the updated policy.

10. Contact Us

For privacy-related inquiries, data deletion requests, or to exercise your rights:

HealthBit

Email: privacy@healthbit.app

Jurisdiction: Mumbai, Maharashtra, India

Governing Law: Indian law, including the Digital Personal Data Protection Act 2023