Legal & policy
Privacy Policy
How StillPulse handles local data, Wear OS, Health Connect, cloud data, subscriptions, website operations, and your choices.
Last updated
On this page
- 1. Controller and scope
- 2. Local app data
- 3. Accounts and Google Sign-In
- 4. Optional heart-rate sources: Wear OS and Health Connect
- 5. Cloud session data
- 6. Subscriptions and RevenueCat
- 7. Feedback, support, and email
- 8. Website analytics and language preference
- 9. Purposes and legal bases
- 10. Recipients and international transfers
- 11. Retention and review
- 12. Security
- 13. Your GDPR rights
- 14. Private summaries, not profiling
- 15. Changes
1. Controller and scope
The controller is Robert Roszak, service address: ul. Kazimierza Morawskiego 5/127, 30-102 Cracow, Poland, email: support@stillpulse.app. This policy covers the StillPulse Android phone app, Wear OS companion, stillpulse.app, support, and related services. StillPulse is intended for adults aged 18 or older.
2. Local app data
Sessions, protocol settings, procedural-audio selections, check-ins, program progress, reminders, heart-rate telemetry, private statistics, and generated PDF/CSV exports may remain only on the device. Local reminders use Android notification scheduling. Data that never leaves the device is not collected by the controller.
During a direct Wear OS session, the watch stores heart-rate values, measurement time, session identifier, and sequence number until the paired phone acknowledges them. Unconfirmed samples are removed after acknowledgement or expire after no more than 24 hours.
Local data remains until it is removed in the app, app storage is cleared, or the app is uninstalled. Exported files remain wherever the user saves or shares them.
3. Accounts and Google Sign-In
Supabase processes account identifiers, email address, authentication identities, session tokens, and account state. Users may sign in by magic link, password, or Google OAuth. Google shares the basic openid, email, and profile information authorized by the user. OAuth client secrets are stored only in Supabase configuration.
The purposes are authentication, account security, requested synchronization, and account management. The legal bases are performance of the service contract and the controller's legitimate interest in service security.
4. Optional heart-rate sources: Wear OS and Health Connect
For direct Wear OS biofeedback, the user prepares a session on the paired Android phone, opens StillPulse on a compatible Wear OS 3+ watch, and explicitly presses Start. Wear OS Health Services provides heart-rate values and measurement time only during that session. The watch sends samples to the phone through the encrypted Wear OS Data Layer; no location, steps, calories, passive heart-rate monitoring, HRV, or beat-to-beat intervals are requested.
After an in-app disclosure and explicit choice, StillPulse may instead read heart-rate values and measurement timestamps from Health Connect. Health Connect is an optional, read-only alternative; StillPulse does not write data to it and does not require it for ordinary sessions.
Wear OS sensor permission, Health Connect read access, and cloud-history synchronization are separate controls. Without acknowledged cloud-history consent, StillPulse does not upload practice data. Withdrawal stops future processing under that control but does not automatically erase earlier cloud records.
5. Cloud session data
For signed-in users, Supabase may store account data, subscription entitlement, and privacy-consent events. Only after optional cloud-history consent may it also store synchronized session settings and time, check-ins, goals and context, telemetry, heart-rate samples, and derived biofeedback values.
Account and cloud data are kept until account deletion or an earlier valid request, subject to narrowly required security or compliance records.
6. Subscriptions and RevenueCat
Google Play processes payment and purchase information. RevenueCat processes app user identifiers, product and entitlement state, and purchase events to verify Premium access. StillPulse does not receive full payment-card details. Processed RevenueCat webhook payloads are reduced or deleted after handling where operationally possible.
7. Feedback, support, and email
The in-app feedback form sends a category, message, locale, app version, submission identifier, and an email address only if the user consents to a reply. It does not attach account ID, session data, heart-rate data, device identifier, or diagnostics. Supabase stores the submission; Resend sends a minimal administrative notification containing only category and identifier.
Support email is processed to answer the request. Feedback contact email is erased when the submission is closed. Feedback text is kept only while it has a continuing product or compliance purpose.
8. Website analytics and language preference
In production, Vercel Web Analytics processes anonymous page views using privacy-preserving identifiers including a hash that changes daily. Speed Insights processes Web Vitals and technical performance data. StillPulse sends no custom analytics events and strips query parameters before analytics delivery. The purpose is to understand site reliability and improve pages; the legal basis is legitimate interest.
The functional cookie stillpulse_locale stores a deliberate PL/EN choice for up to one year. It is not used for tracking or advertising.
9. Purposes and legal bases
- Contract or pre-contract steps: accounts, requested app functionality, subscriptions, support, and synchronized service delivery.
- Explicit consent or explicit user action: session-only Wear OS heart-rate reading, Health Connect reading, cloud synchronization of practice history, and optional feedback contact.
- Legitimate interests: security, abuse prevention, service reliability, limited website analytics, and defending legal claims.
- Legal obligation: records that must be retained under applicable law.
10. Recipients and international transfers
Recipients may include Supabase, Google (Google Sign-In, Google Play, Wear OS Health Services and Data Layer, Health Connect), RevenueCat, Resend, Vercel, and professional advisers when necessary. Some providers may process data outside the EEA using adequacy decisions or appropriate safeguards such as Standard Contractual Clauses. Provider terms and regions should be reviewed before each release.
11. Retention and review
Data is kept only for the stated purpose or a valid legal need. Account/cloud data lasts until account deletion; local data until local removal; feedback contact until closure. Technical metadata and consent events are kept only as long as reasonably needed for reliability or demonstrating compliance.
StillPulse performs a data-purpose and retention review at least every six months and removes records without a continuing purpose.
12. Security
StillPulse applies data minimization, TLS in transit, platform-secured local secrets, database access controls, Row Level Security, restricted service credentials, idempotent writes, and operational log redaction. No system can guarantee absolute security.
13. Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent at any time without affecting earlier lawful processing; and complain to the Polish supervisory authority (UODO). Contact support@stillpulse.app. Identity verification may be required before fulfilling a request.
14. Private summaries, not profiling
Statistics shown in StillPulse summarize the user's own practice history. They are not advertising profiles, automated eligibility decisions, product-engagement telemetry, medical diagnosis, or monitoring by the controller.
15. Changes
Material changes will be published in both English and Polish with an updated date. Where a new consent is legally or functionally required, the app will ask again before the affected processing continues.