← Back to Legal

Privacy Policy

Effective date: 22 February 2026 · Last updated: 22 February 2026 · Version 1.0
Summary: HealthSeeker stores all data locally on your device. We do not operate servers, collect personal information, or track your behaviour. There are no external API calls — HealthSeeker is a fully offline workout timer and tracking app.

1. Data Controller

HealthSeeker is developed and maintained by an independent developer operating under Australian law.

For the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.

2. What Data HealthSeeker Collects

HealthSeeker is designed with a privacy-first, local-only architecture. All data remains exclusively on your device in app-private storage (Android SharedPreferences and EncryptedSharedPreferences). No data is transmitted to any server we operate, because we do not operate any servers.

2.1 Data stored locally on your device

Data typePurposeLegal basis (GDPR)
Wallet public addressDisplay wallet connection status (opt-in)Consent (Art. 6(1)(a))
Wallet app nameShow which wallet was used to sign inConsent (Art. 6(1)(a))
SGT status & member numberDisplay Seeker Genesis Token verificationConsent (Art. 6(1)(a))
Workout preferencesExercise timer settings, hold durations, rest intervalsContract (Art. 6(1)(b))
Routine configurationsCustom workout routines and exercise sequencesContract (Art. 6(1)(b))
Workout history & progressCompleted workout records, progress statistics, streaksContract (Art. 6(1)(b))
Engagement dataStreak counts and daily interaction countersContract (Art. 6(1)(b))
App preferencesDisplay settings, theme preferences, notification settingsContract (Art. 6(1)(b))

2.2 Coarse location (ACCESS_COARSE_LOCATION)

HealthSeeker requests Android coarse location permission solely for regulatory compliance — specifically to detect whether the device is located in a jurisdiction subject to international sanctions. This permission:

Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. We have conducted a balancing test and determined that the compelling legal obligation to screen for sanctioned regions outweighs the minimal privacy intrusion of a single on-device coarse location check that is never stored or transmitted.

2.3 Data we do NOT collect

3. No Server-Side Data Storage

HealthSeeker does not operate any backend servers, databases, cloud storage, or analytics infrastructure. We have no server-side systems capable of receiving, storing, or processing user data. All data exists exclusively in your device's app-private storage and is inaccessible to other applications.

4. No External API Calls

HealthSeeker is a fully offline application. Unlike apps that fetch data from external services, HealthSeeker makes no network requests to any third-party APIs. All workout timing, routine management, progress tracking, and exercise information is generated and stored entirely on your device.

Note: The only network communication that occurs is the local inter-process communication between HealthSeeker and your wallet app during the optional Sign In With Solana (SIWS) process. This communication stays entirely on your device and does not involve any external servers. See Section 5 for details.

5. Mobile Wallet Adapter (MWA)

Wallet sign-in uses Solana's Mobile Wallet Adapter protocol, which operates entirely locally between HealthSeeker and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:

6. Data Security

We implement the following security measures to protect locally stored data:

7. Data Retention and Deletion

All data is stored locally on your device and is retained until you explicitly delete it. You can delete all HealthSeeker data at any time by:

Since no data is stored on our servers, deletion from your device constitutes complete deletion.

8. International Data Transfers

HealthSeeker does not transfer personal data to our servers (we have none). Since HealthSeeker makes no external API calls, there are no international data transfers associated with the app's functionality. The only data that leaves the app sandbox is the local MWA communication with your wallet app, which stays entirely on your device.

9. Your Rights

9.1 European Economic Area & United Kingdom (GDPR / UK GDPR)

If you are located in the EEA or UK, you have the following rights under the GDPR:

9.2 Australia (Privacy Act 1988)

Under the Australian Privacy Principles (APPs), you have the right to:

9.3 California, USA (CCPA / CPRA)

If you are a California resident, you have the right to:

9.4 Japan (Act on Protection of Personal Information — APPI)

If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.

9.5 South Korea (Personal Information Protection Act — PIPA)

If you are located in South Korea, you have the right to:

All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.

9.6 Singapore (Personal Data Protection Act — PDPA)

If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.

10. Children's Privacy

HealthSeeker is not directed at, marketed to, or intended for use by children under the age of 16 (or 13 in jurisdictions where that threshold applies, including the United States under COPPA). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.

11. Automated Decision-Making

HealthSeeker performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's features. You may contact us to contest this decision.

12. Data Protection Impact Assessment

We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:

13. Do Not Track

HealthSeeker does not track users in any way and therefore inherently honours Do Not Track (DNT) signals. There is no tracking to disable.

14. Local Storage Disclosure (ePrivacy)

For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: HealthSeeker stores configuration data on your device using Android SharedPreferences and EncryptedSharedPreferences. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of HealthSeeker after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

16. Contact

For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:

We aim to respond to all privacy inquiries within 30 days.

17. Governing Law

This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.