Legal

Privacy Policy

Health Path has no server. Everything you write stays on your own phone, and we never receive it. Here is exactly what that means.

Version 1.0 Effective {{EFFECTIVE_DATE}} English · Български The effective date is set on the day Health Path is published — this policy is final, and that field is the only thing waiting.

The short version

We know most people don't read privacy policies. Here's the honest summary before the full document — everything in it is explained properly, with the reasons, further down.

  • Your data stays on your phone. Health Path has no server. There is no "Health Path cloud" your entries go to.
  • We cannot see your data. Not your mood entries, not your diary, not your food log, not your email address. There is no wire connecting your phone to us. We could not look even if we wanted to.
  • We don't sell it, because we never have it. There's nothing to sell, share, or hand to an advertiser.
  • Uninstalling the app deletes your data, and so does the app's own "delete everything" option. Because we hold no copy anywhere, deletion inside Health Path is complete and immediate — not "deleted from our servers within 30 days," but gone, because there was never a second copy on our side, and no copy anywhere else either.
  • Health Path also switches off Android's own automatic backup, so your phone does not copy your entries into your Google account. Section 7 explains this properly, including what it costs you.
  • This is the downside, and we want to be honest about it. If you forget your password, lose your phone, get a new one, or uninstall the app, your entries are gone and nobody can bring them back — not you, not us, not Google. We don't have a copy to restore from, and we've deliberately stopped your phone from keeping one. This is the price of the privacy above, and you should decide whether it's a price you want to pay.
  • We still have real legal obligations to you even though we never see your data. "We don't have your data" doesn't mean "the law doesn't apply to us." It applies. It's just that most of what it asks for, you already have, because it's on your own phone.

If that's all you needed, you can stop here. If you want the details — what exactly is stored, why, what your rights are, and how to reach us — read on.

1. Who we are

Health Path is made and published by Gabriela Stancheva, a private individual based in Bulgaria. There is currently no registered company behind the app — it is published by one person, in their own name.

We want to be upfront about what that means, because it's a genuine trade-off and you should understand it:

  • What it means for you: there is one accountable person you can contact, whose real name is given below, and who is personally and legally responsible for how this app handles your information.
  • What it means for us: publishing under a personal name rather than a company means the owner carries this responsibility personally, without the liability protection a registered company would give them. We mention it not because it changes your rights, but because we think you should know who you're actually dealing with.

Contact for anything related to privacy or your data:

Do we have a Data Protection Officer?

No, and under the law we're not required to. A Data Protection Officer is mandatory for organisations that, among other things, process large volumes of sensitive data as their core, systematic, large-scale activity — typically hospitals, insurers, large ad networks. Health Path is a single developer's app with no server and no centralised copy of anyone's data; on the facts as they stand today, that threshold isn't met. If that ever changes — for instance if Health Path adds a server, or the number of people using it grows large enough that our processing could reasonably be called "large scale" even without one — we will revisit this and appoint one if the law then requires it.

2. What the app stores, and why

Everything below is stored only on your own device, inside a private storage area that Android reserves for this app and that other apps cannot read. Nothing in this table is sent anywhere. This is the complete list — there is nothing else the app collects that isn't here.

What it isWhy it existsHow long it's keptHow to delete it
Account email addressSo you can create and sign back into your local account on this deviceUntil you delete your account or uninstall the appManage Profile → delete account, or uninstall
Display nameShown back to you in the appSame as aboveSame as above
Password, as a salted hash — never as plain text (see Section 10)To confirm it's you when you sign inSame as aboveSame as above
Onboarding answers, including what you said you'd like support withTo personalise which parts of the app are shown to you, such as seeding your goals listUntil deleted or uninstalledManage Profile → delete account
Mood entries — Journal check-ins and the Calendar's daily moodThe core of the app: a private, personal mood log for your own reflectionUntil you delete the entry, delete your account, or uninstallDelete the entry directly, or delete your account for all at once
Diary notes — free text you writeA private space for you to write, for yourselfUntil deleted or uninstalledDelete the note directly, or delete your account
Food-group log — which of the five groups you ate from each day, and optional grams or calories if you've turned that onTo let you look back at your own eating pattern, without judgementUntil deleted or uninstalledDelete the entry, or delete your account
Custom foods you've addedSo a food you typed in can be placed into a group and logged like any otherUntil deleted or uninstalledDelete the entry, or delete your account
Goals you've selected in My GoalsTo show your chosen intentions back to youUntil deleted or uninstalledDelete your account
Avatar choiceCosmetic — one of seven bundled images, never a photo you uploadUntil deleted or uninstalledDelete your account
Numbers preference — whether grams and calories are shown at allAn opt-in switch, off by default, and most people never need to touch itUntil changed or uninstalledTurn it off in settings, or delete your account
Onboarding-complete flag and similar small internal switchesSo the app remembers where you are in setupUntil deleted or uninstalledDelete your account

Recipients: none. Nothing in this table is disclosed, sold, or transmitted to any other company, service, or person — including us. There is no one else this data is given to.

What happens if you don't provide something. An account email, display name and password are required to create and sign in to an account at all — without them you can't use the app. Everything else is optional: if you never use a feature, the only consequence is that the corresponding part of the app has nothing to show you.

What we do not collect, anywhere, ever: your location, your contacts, photos from your camera roll, your device's advertising ID, browsing history, or any information about how you use other apps. The app has no permission to access any of these, and no code that would even try.

Why does the app need my email? Because accounts are entirely local to your device, your email address here is just a username you chose. It is never verified by sending you an email, and never used to contact you, market to you, or identify you to anyone else. It exists purely so you can sign back into the app on this device.

3. The fact this whole policy is built on: the app has no internet connection

This is the single most important technical fact about Health Path, so we want to state it plainly rather than bury it in an appendix.

Health Path's Android app does not request permission to use the internet. Not "asks for it but tries to minimise use" — it does not ask for it at all. Without that permission, Android itself blocks the app from opening any network connection. This isn't a policy we chose to follow; it's the operating system stopping it at the door. We independently checked the app's code and confirmed:

  • No part of the app makes an outgoing network request.
  • There is no analytics tool, no crash-reporting tool, no advertising software, and no tracking code of any kind built into the app.
  • There is no Health Path server. Not "a server we don't currently use" — there is no server that exists to send anything to.

One small technical honesty note. The app uses a font (Inter) via a library called Google Fonts, which is designed to fetch that font from Google's servers if it isn't already available. Because the app has no internet permission, this fetch is blocked by Android before it can send a single byte — it fails silently and the app falls back to your phone's own default font. We mention it because we said we'd be exhaustive, not because it does anything: no data leaves your device through this or any other path.

The honest consequence of this design

Because we never receive a copy of your data, we also can't do some things a normal online service could:

  • We cannot recover a forgotten password. There is no reset link we can email you, because we don't hold your account outside your device.
  • We cannot restore lost data. If your phone is lost, stolen, damaged beyond repair, replaced, or the app is uninstalled, your entries are gone. We don't have a second copy to send back, because one was never made — and, as Section 7 explains, the app deliberately stops your phone from making one either.
  • We cannot tell you anything about yourself that you don't already have. Whatever the app knows about you is already visible to you, right now, in the app.

We think this trade — real privacy in exchange for no safety net if you lose your device — is the right one for an app that asks people to write honestly about food, mood and body image. But it is a real trade-off, and you should go in knowing it, not discover it the day you need a backup that doesn't exist.

Why there's no cookie-banner-style pop-up in this app

Most websites, and some apps, show you a pop-up asking you to accept cookies before you can use them. Health Path doesn't show anything like that, and we'd rather explain why than leave you wondering whether we simply skipped a step.

That kind of pop-up exists for a specific reason: to ask your permission before something outside your control — usually another company — reads or writes information on your device for a purpose that isn't strictly needed to give you the feature you asked for, often for tracking or advertising. Health Path doesn't do that, and can't. Everything the app stores on your device is written and read only by the app itself, and only for the feature you're actively using: your mood entries so the Journal can show them back to you, your diary text so it's still there next time you open the app. The rule that requires that kind of pop-up is aimed squarely at the situation where an outside party could reach onto your device. Here, nobody but you and the app itself ever can, so there is genuinely nothing for a consent pop-up to ask permission for.

4. Is this "health data" under the law? Yes — and here's what that means

Under EU data protection law, certain categories of personal information get extra legal protection because of how sensitive they are — this includes information about your physical or mental health. It doesn't need to come from a doctor to count: a pattern of entries that reveals something about your mental or physical state counts too.

We've thought about this carefully rather than taking the easy route of calling it ordinary "lifestyle" information, and our honest conclusion is:

  • Your mood entries are health data. A recurring, dated record of how you're feeling is exactly the kind of thing this protection exists for.
  • Your diary text is health data, and arguably the most sensitive thing in the app, because it's free text — you could write about anything, and for many people using an app built for food guilt and body image, that will include exactly the things this protection is meant to cover.
  • Your food-group log is health data too, even without calories switched on. Given what this app is for, a record of what you did and didn't eat over time is capable of revealing something about your relationship with food, which is why we treat it with the same care rather than waving it through as "just a food diary."
  • Your onboarding answers about what you'd like support with, and the goals you select from that list, are health data too. That question asks directly about things like support for restrictive eating and body image, and choosing a goal discloses something about your relationship with food or your body.

What follows from this. The law requires us to ask for your clear, explicit agreement before processing this kind of information — separate from, and in addition to, agreeing to the app's general terms of use.

You can withdraw your agreement at any time by deleting your account, which removes the data it covered.

Your account email, display name and avatar choice are not health data — they're ordinary account information, handled under a lighter legal basis explained in Section 6.

5. "But it never leaves my phone — does the law even apply?"

It's a fair question, and we want to answer it honestly rather than give a reassuring but inaccurate answer.

Short answer: yes, EU data protection law applies to Health Path, even though nothing is transmitted anywhere. The law defines "processing" personal data very broadly — it includes collecting, storing and organising information, regardless of whether it's on a server or on your own phone, and regardless of who can see the result. The person who decided what data the app collects and why is legally the "controller" of that data, even though they never receive a copy of it. There's no court ruling that settles this exact scenario with total certainty, but the reasoning is well established, and we'd rather draft this policy on the safer, more protective assumption than lean on a technicality.

What this means in practice is genuinely good news for you. Being a controller comes with obligations — being transparent about what's collected and why, having a lawful reason to collect it, letting you access, correct and delete it. Because your data lives only on your device, almost every one of those is already satisfied automatically, just by how the app is built:

  • Access? You can already see everything, right now, in the app.
  • Correction? You can already edit any entry directly.
  • Deletion? You can already delete anything, instantly, with nothing left behind anywhere else.

The offline design doesn't take Health Path outside the law's reach. It just means the law asks for things the app already does by default.

6. Why we're allowed to process each type of data

WhatWhy we're allowed to process it
Account email, display name, password hashNecessary to provide the account feature you're using — the basic "we need this to run the service you asked for" basis
Mood entries, diary text, food-group log, onboarding answers about what you'd like support with, and goals selectedYour explicit agreement, given because this is treated as health-related data (Section 4). You can withdraw it at any time by deleting your account. Note the gap flagged in Section 4: this agreement is not yet captured through a dedicated step, so today it rests on onboarding's general acceptance.
Avatar choice, numbers preferenceYour own direct choice in the app's settings

We do not rely on "legitimate interest" as a basis for anything in this app. That basis involves a balancing test against your interests, and we'd rather ask you directly than rely on our own judgement about what's legitimate.

We do not use any of your data for advertising, and we do not build a profile of you to predict or influence your behaviour. Nothing in the app makes an automated decision about you.

7. Android backups — please read this section

Android phones normally back up the data of the apps on them into the owner's Google account. Health Path switches that off for itself.

This is not a setting you have to find. The app tells Android, in its own configuration, not to include Health Path's data in either kind of transfer Android offers:

  • Backups to your Google account (the "Back up to Google Drive" feature). Your diary text, mood history and food log are never copied there.
  • Phone-to-phone transfer, the copy Android offers to make when you set up a new device. Health Path's data is excluded from that too.

We did this because everything else in this policy says your entries stay on your phone, and leaving Android's backup switched on would have made that untrue. The data would have gone to your own Google account rather than to us — we would still never have seen it — but it would have left your device, and we'd rather the sentence be simply true than true with an asterisk.

What this costs you, which is not small

If you lose your phone, replace it, factory reset it, or uninstall Health Path, your entries are permanently gone. There is no copy anywhere. We can't restore them, because we never had them. Google can't restore them, because we told Android not to keep them. You can't restore them either.

This is a real trade-off and we would rather you meet it here than discover it on the day you upgrade your phone. An app that kept a backup would be able to move your journal to a new device; the cost of that convenience is a copy of your health data sitting in an account we can't see and can't promise anything about. We chose the version with no copy. If that is the wrong trade for you, it is a fair reason not to use Health Path, and we'd rather say so plainly than have you find out later.

If you have already used an older version

Health Path has had this setting switched off since its first public release, so there should be no old backup of it anywhere. If you are ever unsure, your Google account's own backup settings will show you what it holds for each app, and you can delete it there. We have no access to that and cannot do it for you.

8. Children and age

Health Path is intended for people 16 years old and up. This is our own choice — it's stricter than the minimum Bulgarian law itself would require for this kind of service, which is 14 — but we think 16 is the right floor for an app that deals directly with body image and food guilt.

If you are a parent or guardian and believe someone under 16 is using Health Path with an account containing their information, you or they can delete that account and all its data at any time, directly in the app, with nothing left behind anywhere else afterward.

9. Your rights, and how they actually work here

Under data protection law you have a set of rights over your personal data. Below, each one is explained honestly for what it means in an app where we never hold a copy of anything.

RightHow it works for Health Path
Access — see what's held about youEverything is already visible to you, right now, in the app. If you'd still like written confirmation from us, email us and we'll reply substantively, though we hold nothing beyond what you already see.
Rectification — correct wrong dataEdit any entry directly in the app, any time.
Erasure — delete your dataDelete an individual entry, or use Manage Profile's full "delete everything" option. Both are immediate and complete — there is no second copy anywhere, because the app also switches off Android's own backup (Section 7).
Restriction — limit processing while a dispute is resolvedWith no central copy, the most meaningful version of this is simply not using the app, or a specific feature, while you decide what you want.
Portability — take your data elsewhere in a usable formatNot yet available. This is the one right the app does not currently satisfy: there is no export feature, and "you can already see it in the app" is not the same as a portable copy. We are building an export you can generate on your device and share wherever you like, and we say so plainly rather than claim this right is already honoured.
Objection — object to processingWe don't process anything on the basis this right targets (Section 6), so this mainly overlaps with withdrawing your agreement, below.
Withdraw your agreementDelete the specific entries covered — mood check-ins, diary notes or food-group logs — one at a time from where you see them, or delete your account for all at once. We know that's more effort than the single tap it took to agree; if a lighter "stop keeping this" switch would help you, tell us.
Automated decisionsNot applicable. The app doesn't score, rank, or make any automated decision about you.

Response time. If you contact us about any of the above, we'll reply within one month. If a request is complex we may need up to two further months, and we'll tell you if that's the case and why.

The right to complain

You have the right to complain to a data protection supervisory authority at any time, whether or not you've contacted us first. In Bulgaria, that's:

If you live elsewhere in the EU or EEA, you can complain to your own country's equivalent authority instead — you don't have to use the Bulgarian one just because we're based here. You also have the right to take the matter to court, in addition to or instead of complaining to a supervisory authority.

10. Security — what actually protects your data, and what doesn't

We'd rather tell you plainly what is and isn't in place than let a vague phrase like "industry-standard security" stand in for specifics.

What protects your data

  • The Android app sandbox. Every Android app's private storage is, by design, walled off from every other app on the phone. Another app cannot read Health Path's data without breaking Android's own security model. This is a real, meaningful protection, not a formality.
  • Your password is not stored as plain text. It's stored as a salted hash — a one-way scrambled version, combined with a random value unique to your account, that cannot be reversed back into your original password.

What does not protect your data, stated honestly

  • Your entries are not encrypted at rest. Your mood, diary and food-log content is stored as ordinary readable text inside the app's private storage area. It's protected by the sandbox above, but not by a second layer of encryption on top of that.
  • The password hashing method is a fast one, not a slow one built specifically to resist offline cracking. In plain terms: if someone obtained the raw storage file — which requires root access to your phone or physical access to an unlocked device, not something achievable remotely since nothing is transmitted — a fast hash is crackable at speed with the right hardware. We're upgrading this; it's a known limitation and we're not hiding it.
  • A rooted phone, or a phone shared with people you don't trust, is a real risk. The protections above assume a normal, non-rooted phone that only you have access to.

Because there is no server, the usual meaning of "data breach" — a company's servers being hacked — cannot happen to Health Path. There is no server to hack. The realistic remaining risk sits entirely at the device level: a rooted phone, a lost unlocked phone, or a future bug in the app itself. If we ever became aware of a defect that put your data at risk in a way traceable to how we built the app, we would treat that seriously and notify affected users and, where required, the supervisory authority — even though the classic breach scenario doesn't apply here.

11. The website — separate from the app, handled separately

This section covers https://healthpathapp.com, the marketing website — not the app itself, which is covered by everything above. If you've only ever used the app and never visited the website, this section doesn't add anything for you.

  • Server logs. Like essentially any website, ordinary web server logs — which record things like IP address and request time, generated automatically by the server software — may be created when you visit. We don't run analytics on top of this.
  • Cookies. This website does not set any cookies.
  • Analytics. This website does not run any analytics or tracking script.
  • Fonts. The website's fonts are served from our own hosting, not from Google's servers, so visiting the site does not send your information to Google by this route. Until 15 August 2026 it did load them from Google on every page, which sent your IP address to Google before you had agreed to anything; we removed it ourselves rather than wait to be asked.
  • The link to TikTok. The footer links to a TikTok profile. That link takes you to a third party's website, which has its own privacy practices and its own tracking, entirely outside our control. Check TikTok's own privacy policy if that concerns you.
  • One form. “Get launch news” asks for a first name and an email address, so we can write to you once — on the day the app is released. It is entirely optional and nothing else on the site depends on it. There is no other form: no contact form, no newsletter, no account.
    • What we do with it: that one announcement, and nothing else. We do not sell or share the list, and we send nothing in the meantime.
    • Who holds it: the form is handled by Formspree (Formspree Inc.), which stores the submissions for us and tells us when one arrives. Formspree is based in the United States, so an address given here does leave the EU — see Section 13. It is the only route by which anything you give Health Path goes abroad; the app itself still sends nothing anywhere (Section 4).
    • Getting off the list: write to support@healthpathapp.com and we delete you from it. The launch email will carry an unsubscribe link.
    • Why we're allowed to: your consent (Art. 6(1)(a) GDPR), given by submitting the form, and withdrawing it is as easy as giving it was.

12. Third parties: Google Play

Health Path is not yet available on Google Play. Once it is published there, Google, as the store operator, will collect its own information as part of running that store — for example your Google account details, payment details if you ever buy anything through Google Play, and device and app information Google collects for its own store operations.

This is Google's own collection, under Google's own privacy policy — we don't control it, and we don't receive any of it. If you want to know what Google Play itself collects about you as a user of the store, Google's own privacy policy is the right place to check, not this document.

Beyond the Google Play store relationship itself, Health Path uses no other third-party service or component of any kind. There is no analytics company, no advertising network, no crash-reporting vendor and no cloud provider in the picture, because there is no data flow for any of them to sit on.

13. International data transfers

From the app: none. Your data doesn't leave your device, so the question of transferring it to another country — inside or outside the EU and EEA — doesn't arise. Android's own backup was the one route by which your entries could have reached a server abroad, and Section 7 explains why the app switches it off.

From the website: one, and only if you choose it. If you give us your name and email on the “Get launch news” form (Section 11), those two pieces of information are stored by Formspree Inc. in the United States. Nothing else you do on the website or in the app is transferred anywhere. If you would rather your address did not leave the EU, don't use the form — write to support@healthpathapp.com instead and we will note you by hand.

14. Changes to this policy

If we make a meaningful change to this policy — for example adding a feature that changes what data is collected, or building the export mentioned in Section 9 — we will update this document and the effective date at the top. For any change that meaningfully affects what we do with your data, we'll also let you know inside the app itself, not just by quietly editing a web page.

15. Looking ahead: if Health Path ever moves online

Everything above describes Health Path as it exists today: fully local, no server, no account beyond your own device. If that ever changes — an online-synced account, a paid subscription requiring payment processing, or a server-based feature — this section will need to cover, at minimum:

  • The identity of any new company involved in handling the data, such as a cloud hosting provider, what they do with it, and where their servers are.
  • Whether any data then leaves the EU or EEA, and if so what legal safeguard applies to that transfer.
  • How account data would be secured in transit and stored on a server, replacing the "there is no server" position in Section 10.
  • A real breach-notification process, since "there is no server to hack" would no longer be true.
  • How payment data would be handled if a paid tier goes live, including which payment processor is used and what they, rather than we, would hold.
  • Updated answers for Access and Portability, since those rights would then need to be honoured against a real central copy rather than being automatically satisfied by on-device storage.