Effective date: 19 September 2026 Last updated: 19 September 2026
jb-health (“the Application”) is a private, single-user, non-commercial application operated by Justin Bailes (“the Operator”) for the Operator’s exclusive personal use.
The Application is not offered to the public. It has no other users, no user registration, no commercial purpose, and no intention of acquiring users. It exists solely to allow the Operator to retrieve the Operator’s own personal health and fitness data from the Operator’s own Google Account and store it on infrastructure the Operator controls.
This policy is published to satisfy Google’s OAuth application requirements and to state plainly what the Application does with the data it accesses.
The Application requests read-only access to the following categories of data from the Operator’s own Google Account, via the Google Health API:
| Scope | Data accessed |
|---|---|
googlehealth.activity_and_fitness.readonly |
Activity and fitness data — workouts, steps, exercise sessions |
googlehealth.health_metrics_and_measurements.readonly |
Health metrics — heart rate, heart rate variability, resting heart rate, blood oxygen saturation, skin temperature, respiratory rate |
googlehealth.sleep.readonly |
Sleep sessions and sleep stage data |
googlehealth.profile.readonly |
Basic Google Health profile information |
googlehealth.irn.readonly |
Irregular Rhythm Notification data |
googlehealth.ecg.readonly |
Electrocardiogram data, where recorded |
googlehealth.location.readonly |
GPS location data recorded during exercise sessions |
The Application requests no write scopes. It cannot create, alter or delete any data in the Operator’s Google Account.
The Application accesses only the account of the individual who authenticates it — that is, the Operator’s own account. It does not access, request, or receive data belonging to any other person.
Retrieved data is used exclusively for the Operator’s personal review and analysis of the Operator’s own health, training and recovery.
The data is not used for:
Retrieved data is stored on a private server controlled by the Operator and on the Operator’s personal computers.
No system is perfectly secure. The Operator accepts the residual risk of self-hosting on the Operator’s own behalf; since the Operator is the only data subject, no other person bears that risk.
The Application does not share retrieved data with any person or organisation for any purpose.
The only third party holding any copy of the data is the cloud storage provider used for the Operator’s server backups (Backblaze B2), acting solely as a storage provider under an account controlled by the Operator and processing the data for no purpose of its own. There are no other recipients, no analytics providers, no advertising networks and no data brokers. Data may be disclosed only where the Operator is compelled to do so by valid legal process, or where the Operator personally chooses to share their own health information — for example, with their own physician.
The Application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Health API User Data and Health Research Policy.
Specifically, the Application:
Data is retained for as long as the Operator finds it useful for personal longitudinal health analysis, which may be indefinite. As the Operator is the only data subject, retention is entirely at the Operator’s discretion.
The Operator may delete stored data at any time by removing it from the Operator’s own infrastructure.
Access granted to the Application can be revoked at any time at:
https://myaccount.google.com/permissions
Revocation immediately prevents the Application from retrieving any further data. It does not delete data already retrieved and stored, which remains under the Operator’s control and may be deleted as described in Section 7.
The Application is not directed at children, is not accessible to anyone other than the Operator, and does not knowingly access the data of any person under 18.
This policy may be updated if the Application’s data handling changes. The effective date at the top of this document will be revised accordingly.
Questions regarding this policy may be directed to jb@cellustar.com.