HealthSeeker is developed and maintained by an independent developer operating under Australian law.
com.healthseeker.appFor the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.
HealthSeeker is designed with a privacy-first architecture. All of your personal data — routines, workout history, preferences and wallet details — remains exclusively on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences) and is never transmitted to us. The only data that leaves your device is the anonymous, aggregate usage analytics described in Section 2.3, which contain no personal data and no workout content.
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| Wallet public address | Display wallet connection status (opt-in) | Consent (Art. 6(1)(a)) |
| Wallet app name | Show which wallet was used to sign in | Consent (Art. 6(1)(a)) |
| SGT status & member number | Display Seeker Genesis Token verification | Consent (Art. 6(1)(a)) |
| Workout preferences | Exercise timer settings, hold durations, rest intervals | Contract (Art. 6(1)(b)) |
| Routine configurations | Custom workout routines and exercise sequences | Contract (Art. 6(1)(b)) |
| Workout history & progress | Completed workout records, progress statistics, streaks | Contract (Art. 6(1)(b)) |
| Engagement data | Streak counts and daily interaction counters | Contract (Art. 6(1)(b)) |
| App preferences | Sound, vibration, workout-mode and notification settings | Contract (Art. 6(1)(b)) |
HealthSeeker performs a sanctions-region check solely for regulatory compliance — to detect whether the device is associated with a jurisdiction subject to international sanctions. The App holds no location permission and does not access GPS or network location. Screening:
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. The check uses only coarse device-configuration signals, is never stored or transmitted, and involves no location data.
HealthSeeker sends anonymous, aggregate usage events to our own analytics service (a Vercel serverless function at healthseeker-analytics.vercel.app) so we can understand how many people use the app and roughly where. This is strictly privacy-preserving:
app_open or workout_completed).You can switch this off entirely. Settings › Privacy › Fully Offline Mode stops every one of these events at the source, including the app_open event sent at launch. With it on, HealthSeeker makes no network request of its own; the only remaining network activity is wallet sign-in and Pro purchase or restore, which happen solely when you start them. The setting is stored on your device and persists across restarts.
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) in understanding aggregate product usage. Because the data is anonymous and aggregate (GDPR Recital 26), it does not identify you and does not require consent. You may object at any time using the setting above.
HealthSeeker does not store any of your personal data on a server. We operate one backend service — the anonymous analytics service described in Section 2.3 — whose database holds only aggregate counts (per event, country and day). It has no column for, and never receives, any identifier that could be linked to you. Your routines, workout history, preferences and wallet details exist exclusively in your device's app-private storage and are inaccessible to other applications.
HealthSeeker works fully offline for all of its core features — workout timing, routine management, progress tracking and exercise information are generated and stored entirely on your device. It makes network requests only for these limited purposes:
Solana RPC providers: To verify Seeker Genesis Token status, submit payments, and restore purchases, the App sends your wallet's public address to Solana RPC providers: api.mainnet-beta.solana.com and, as a fallback, solana-rpc.publicnode.com (Allnodes). These providers receive your IP address and the public address. Private keys never leave your wallet.
Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between HealthSeeker and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:
We implement the following security measures to protect locally stored data:
EncryptedSharedPreferences with AES-256-SIV encryption (via Google Tink)All data is stored locally on your device and is retained until you explicitly delete it. You can delete all HealthSeeker data at any time by:
Android Auto Backup: If Android Backup is enabled on your device, the App's settings and progress data are included in your device's encrypted Google backup, survive uninstalling the App, and may be restored when you reinstall. Wallet data is always excluded from backup. You can exclude the App from backup in Android Settings or delete the backup from your Google account.
We hold no copy of your data on our servers; apart from any Google backup you control (above), deletion from your device constitutes complete deletion.
HealthSeeker does not transfer personal data internationally, because it does not send personal data anywhere. The anonymous analytics events (Section 2.3) are processed by Vercel's global edge network and stored as aggregate counts; as this data is anonymous and contains no personal information, it is not a transfer of personal data under GDPR. Wallet SGT verification queries a public Solana RPC endpoint and carries only your public wallet address (a public ledger identifier), not personal data we hold.
If you are located in the EEA or UK, you have the following rights under the GDPR:
Under the Australian Privacy Principles (APPs), you have the right to:
If you are a California resident, you have the right to:
If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.
If you are located in South Korea, you have the right to:
All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.
If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.
HealthSeeker is not directed at, marketed to, or intended for use by children under the age of 13 (or the higher minimum age of digital consent in your jurisdiction, where one applies). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.
HealthSeeker performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's features. You may contact us to contest this decision.
We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:
HealthSeeker does not track individual users, build profiles, or perform any cross-app or cross-session tracking. Our only analytics are anonymous, aggregate counts that cannot identify you (Section 2.3), so there is no individual tracking to disable and Do Not Track (DNT) signals are inherently honoured.
For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: HealthSeeker stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of HealthSeeker after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:
We aim to respond to all privacy inquiries within 30 days.
This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.