Privacy Policy - jb-health

Privacy Policy — jb-health

Effective date: 19 September 2026 Last updated: 19 September 2026

1. Overview

jb-health (“the Application”) is a private, single-user, non-commercial application operated by Justin Bailes (“the Operator”) for the Operator’s exclusive personal use.

The Application is not offered to the public. It has no other users, no user registration, no commercial purpose, and no intention of acquiring users. It exists solely to allow the Operator to retrieve the Operator’s own personal health and fitness data from the Operator’s own Google Account and store it on infrastructure the Operator controls.

This policy is published to satisfy Google’s OAuth application requirements and to state plainly what the Application does with the data it accesses.

2. Data the Application accesses

The Application requests read-only access to the following categories of data from the Operator’s own Google Account, via the Google Health API:

Scope Data accessed
googlehealth.activity_and_fitness.readonly Activity and fitness data — workouts, steps, exercise sessions
googlehealth.health_metrics_and_measurements.readonly Health metrics — heart rate, heart rate variability, resting heart rate, blood oxygen saturation, skin temperature, respiratory rate
googlehealth.sleep.readonly Sleep sessions and sleep stage data
googlehealth.profile.readonly Basic Google Health profile information
googlehealth.irn.readonly Irregular Rhythm Notification data
googlehealth.ecg.readonly Electrocardiogram data, where recorded
googlehealth.location.readonly GPS location data recorded during exercise sessions

The Application requests no write scopes. It cannot create, alter or delete any data in the Operator’s Google Account.

The Application accesses only the account of the individual who authenticates it — that is, the Operator’s own account. It does not access, request, or receive data belonging to any other person.

3. How the data is used

Retrieved data is used exclusively for the Operator’s personal review and analysis of the Operator’s own health, training and recovery.

The data is not used for:

4. Storage and security

Retrieved data is stored on a private server controlled by the Operator and on the Operator’s personal computers.

No system is perfectly secure. The Operator accepts the residual risk of self-hosting on the Operator’s own behalf; since the Operator is the only data subject, no other person bears that risk.

5. Data sharing

The Application does not share retrieved data with any person or organisation for any purpose.

The only third party holding any copy of the data is the cloud storage provider used for the Operator’s server backups (Backblaze B2), acting solely as a storage provider under an account controlled by the Operator and processing the data for no purpose of its own. There are no other recipients, no analytics providers, no advertising networks and no data brokers. Data may be disclosed only where the Operator is compelled to do so by valid legal process, or where the Operator personally chooses to share their own health information — for example, with their own physician.

6. Limited Use disclosure

The Application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Health API User Data and Health Research Policy.

Specifically, the Application:

7. Retention and deletion

Data is retained for as long as the Operator finds it useful for personal longitudinal health analysis, which may be indefinite. As the Operator is the only data subject, retention is entirely at the Operator’s discretion.

The Operator may delete stored data at any time by removing it from the Operator’s own infrastructure.

8. Revoking access

Access granted to the Application can be revoked at any time at:

https://myaccount.google.com/permissions

Revocation immediately prevents the Application from retrieving any further data. It does not delete data already retrieved and stored, which remains under the Operator’s control and may be deleted as described in Section 7.

9. Children’s data

The Application is not directed at children, is not accessible to anyone other than the Operator, and does not knowingly access the data of any person under 18.

10. Changes to this policy

This policy may be updated if the Application’s data handling changes. The effective date at the top of this document will be revised accordingly.

11. Contact

Questions regarding this policy may be directed to jb@cellustar.com.