HealthSeeker is developed and maintained by an independent developer operating under Australian law.
com.healthseeker.appFor the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.
HealthSeeker is designed with a privacy-first, local-only architecture. All data remains exclusively on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences). No data is transmitted to any server we operate, because we do not operate any servers.
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| Wallet public address | Display wallet connection status (opt-in) | Consent (Art. 6(1)(a)) |
| Wallet app name | Show which wallet was used to sign in | Consent (Art. 6(1)(a)) |
| SGT status & member number | Display Seeker Genesis Token verification | Consent (Art. 6(1)(a)) |
| Workout preferences | Exercise timer settings, hold durations, rest intervals | Contract (Art. 6(1)(b)) |
| Routine configurations | Custom workout routines and exercise sequences | Contract (Art. 6(1)(b)) |
| Workout history & progress | Completed workout records, progress statistics, streaks | Contract (Art. 6(1)(b)) |
| Engagement data | Streak counts and daily interaction counters | Contract (Art. 6(1)(b)) |
| App preferences | Display settings, theme preferences, notification settings | Contract (Art. 6(1)(b)) |
HealthSeeker requests Android coarse location permission solely for regulatory compliance — specifically to detect whether the device is located in a jurisdiction subject to international sanctions. This permission:
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. We have conducted a balancing test and determined that the compelling legal obligation to screen for sanctioned regions outweighs the minimal privacy intrusion of a single on-device coarse location check that is never stored or transmitted.
HealthSeeker does not operate any backend servers, databases, cloud storage, or analytics infrastructure. We have no server-side systems capable of receiving, storing, or processing user data. All data exists exclusively in your device's app-private storage and is inaccessible to other applications.
HealthSeeker is a fully offline application. Unlike apps that fetch data from external services, HealthSeeker makes no network requests to any third-party APIs. All workout timing, routine management, progress tracking, and exercise information is generated and stored entirely on your device.
Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between HealthSeeker and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:
We implement the following security measures to protect locally stored data:
EncryptedSharedPreferences with AES-256-SIV encryption (via Google Tink)All data is stored locally on your device and is retained until you explicitly delete it. You can delete all HealthSeeker data at any time by:
Since no data is stored on our servers, deletion from your device constitutes complete deletion.
HealthSeeker does not transfer personal data to our servers (we have none). Since HealthSeeker makes no external API calls, there are no international data transfers associated with the app's functionality. The only data that leaves the app sandbox is the local MWA communication with your wallet app, which stays entirely on your device.
If you are located in the EEA or UK, you have the following rights under the GDPR:
Under the Australian Privacy Principles (APPs), you have the right to:
If you are a California resident, you have the right to:
If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.
If you are located in South Korea, you have the right to:
All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.
If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.
HealthSeeker is not directed at, marketed to, or intended for use by children under the age of 16 (or 13 in jurisdictions where that threshold applies, including the United States under COPPA). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.
HealthSeeker performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's features. You may contact us to contest this decision.
We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:
HealthSeeker does not track users in any way and therefore inherently honours Do Not Track (DNT) signals. There is no tracking to disable.
For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: HealthSeeker stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of HealthSeeker after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:
We aim to respond to all privacy inquiries within 30 days.
This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.