← Back to Legal

Privacy Policy

Effective date: 22 February 2026 · Last updated: 12 August 2026 · Version 1.4
Summary: HealthSeeker keeps all of your personal data — routines, workout history, preferences and wallet details — on your device. We never collect personal information and never see your workout content. The only data that leaves your device is anonymous, aggregate usage counts (for example "app opened" or "workout completed"), which carry no personal data and cannot identify you. See Section 2.3.

1. Data Controller

HealthSeeker is developed and maintained by an independent developer operating under Australian law.

For the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.

2. What Data HealthSeeker Collects

HealthSeeker is designed with a privacy-first architecture. All of your personal data — routines, workout history, preferences and wallet details — remains exclusively on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences) and is never transmitted to us. The only data that leaves your device is the anonymous, aggregate usage analytics described in Section 2.3, which contain no personal data and no workout content.

2.1 Data stored locally on your device

Data typePurposeLegal basis (GDPR)
Wallet public addressDisplay wallet connection status (opt-in)Consent (Art. 6(1)(a))
Wallet app nameShow which wallet was used to sign inConsent (Art. 6(1)(a))
SGT status & member numberDisplay Seeker Genesis Token verificationConsent (Art. 6(1)(a))
Workout preferencesExercise timer settings, hold durations, rest intervalsContract (Art. 6(1)(b))
Routine configurationsCustom workout routines and exercise sequencesContract (Art. 6(1)(b))
Workout history & progressCompleted workout records, progress statistics, streaksContract (Art. 6(1)(b))
Engagement dataStreak counts and daily interaction countersContract (Art. 6(1)(b))
App preferencesSound, vibration, workout-mode and notification settingsContract (Art. 6(1)(b))

2.2 Sanctions region screening (no location permission)

HealthSeeker performs a sanctions-region check solely for regulatory compliance — to detect whether the device is associated with a jurisdiction subject to international sanctions. The App holds no location permission and does not access GPS or network location. Screening:

Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. The check uses only coarse device-configuration signals, is never stored or transmitted, and involves no location data.

2.3 Anonymous usage analytics

HealthSeeker sends anonymous, aggregate usage events to our own analytics service (a Vercel serverless function at healthseeker-analytics.vercel.app) so we can understand how many people use the app and roughly where. This is strictly privacy-preserving:

You can switch this off entirely. Settings › Privacy › Fully Offline Mode stops every one of these events at the source, including the app_open event sent at launch. With it on, HealthSeeker makes no network request of its own; the only remaining network activity is wallet sign-in and Pro purchase or restore, which happen solely when you start them. The setting is stored on your device and persists across restarts.

Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) in understanding aggregate product usage. Because the data is anonymous and aggregate (GDPR Recital 26), it does not identify you and does not require consent. You may object at any time using the setting above.

2.4 Data we do NOT collect

3. Server-Side Data Storage

HealthSeeker does not store any of your personal data on a server. We operate one backend service — the anonymous analytics service described in Section 2.3 — whose database holds only aggregate counts (per event, country and day). It has no column for, and never receives, any identifier that could be linked to you. Your routines, workout history, preferences and wallet details exist exclusively in your device's app-private storage and are inaccessible to other applications.

4. External Network Requests

HealthSeeker works fully offline for all of its core features — workout timing, routine management, progress tracking and exercise information are generated and stored entirely on your device. It makes network requests only for these limited purposes:

Solana RPC providers: To verify Seeker Genesis Token status, submit payments, and restore purchases, the App sends your wallet's public address to Solana RPC providers: api.mainnet-beta.solana.com and, as a fallback, solana-rpc.publicnode.com (Allnodes). These providers receive your IP address and the public address. Private keys never leave your wallet.

Note: Wallet sign-in itself uses local inter-process communication between HealthSeeker and your wallet app during the optional Sign In With Solana (SIWS) process. That communication stays entirely on your device and does not involve any external servers. See Section 5 for details.

5. Mobile Wallet Adapter (MWA)

Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between HealthSeeker and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:

6. Data Security

We implement the following security measures to protect locally stored data:

7. Data Retention and Deletion

All data is stored locally on your device and is retained until you explicitly delete it. You can delete all HealthSeeker data at any time by:

Android Auto Backup: If Android Backup is enabled on your device, the App's settings and progress data are included in your device's encrypted Google backup, survive uninstalling the App, and may be restored when you reinstall. Wallet data is always excluded from backup. You can exclude the App from backup in Android Settings or delete the backup from your Google account.

We hold no copy of your data on our servers; apart from any Google backup you control (above), deletion from your device constitutes complete deletion.

8. International Data Transfers

HealthSeeker does not transfer personal data internationally, because it does not send personal data anywhere. The anonymous analytics events (Section 2.3) are processed by Vercel's global edge network and stored as aggregate counts; as this data is anonymous and contains no personal information, it is not a transfer of personal data under GDPR. Wallet SGT verification queries a public Solana RPC endpoint and carries only your public wallet address (a public ledger identifier), not personal data we hold.

9. Your Rights

9.1 European Economic Area & United Kingdom (GDPR / UK GDPR)

If you are located in the EEA or UK, you have the following rights under the GDPR:

9.2 Australia (Privacy Act 1988)

Under the Australian Privacy Principles (APPs), you have the right to:

9.3 California, USA (CCPA / CPRA)

If you are a California resident, you have the right to:

9.4 Japan (Act on Protection of Personal Information — APPI)

If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.

9.5 South Korea (Personal Information Protection Act — PIPA)

If you are located in South Korea, you have the right to:

All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.

9.6 Singapore (Personal Data Protection Act — PDPA)

If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.

10. Children's Privacy

HealthSeeker is not directed at, marketed to, or intended for use by children under the age of 13 (or the higher minimum age of digital consent in your jurisdiction, where one applies). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.

11. Automated Decision-Making

HealthSeeker performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's features. You may contact us to contest this decision.

12. Data Protection Impact Assessment

We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:

13. Do Not Track

HealthSeeker does not track individual users, build profiles, or perform any cross-app or cross-session tracking. Our only analytics are anonymous, aggregate counts that cannot identify you (Section 2.3), so there is no individual tracking to disable and Do Not Track (DNT) signals are inherently honoured.

14. Local Storage Disclosure (ePrivacy)

For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: HealthSeeker stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of HealthSeeker after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

16. Contact

For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:

We aim to respond to all privacy inquiries within 30 days.

17. Governing Law

This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.