Legal

Privacy Policy

Your entries live on your phone and on a server we run in Bulgaria, so a lost phone doesn't cost you your journal. Here is exactly what is stored, who can reach it, and how to delete it.

Version 2.4 Effective 20 September 2026 English · Български

The short version

We know most people don't read privacy policies. Here's the honest summary before the full document — and everything in it is explained properly, with the reasons, further down.

  • Your entries are kept in two places: on your phone, and on our server. Your phone is still where the app reads from, and the app still works with no signal. But a copy of your mood entries, diary text, food log, goals and profile is sent to a server we run, so that they survive a lost or replaced phone. This changed in September 2026. Before that, the app had no internet connection at all and nothing ever left the device.
  • That means we can technically see your data, and we want to say so plainly. The entries sit in an ordinary database on a machine the app's owner controls. We do not read them, we have no reason to, and nothing in the app or on the server analyses, scores or profiles them — but "we can't see it" is no longer true, and we are not going to keep saying it.
  • Where the server is: Bulgaria. It is a computer the owner runs and physically controls, in the EU. Your entries are not on Amazon, Google or Microsoft. Section 10 explains what that protects you from and, just as importantly, what it doesn't.
  • We don't sell your data, share it, or hand it to advertisers. There is no analytics in the app, no advertising, no tracking, and no third company receiving your entries. The only emails we send are about your account — a password-reset code, a code to confirm your address, and a warning before an unused account is deleted — see Section 2.
  • We ask before we save anything about your health — once, when you sign up. Creating an account needs its own tick box, "I agree to saving my health data," separate from accepting the Terms. Without it, no account is created and nothing is saved — see Section 4.
  • You can delete everything, and it really is deleted. Manage Profile → Delete profile removes the account and every row belonging to it from the server immediately — not "within 30 days", and not marked-as-hidden.
  • If you stop using Health Path, we delete it for you. An account with no sign-in for 12 months is deleted, along with everything in it — see Section 15.
  • Health Path still switches off Android's own automatic backup, so your entries do not go into your Google account. Our server is the backup instead — Section 7.
  • The honest risks of the new design, stated here rather than buried: there is now a copy of very personal writing on a machine that could in principle be broken into, seized, or lost; the machine is one computer in a home, with no data-centre security and no standby; and your data travels over the internet to reach it, encrypted on the way. Version 1 of this policy traded away every one of those risks and paid for it with "lose your phone, lose your journal". This version makes the opposite trade, and you should know which one you're using.

If that's all you needed, you can stop here. If you want the details — what exactly is stored, why, what your rights are, and how to reach us — read on.

1. Who we are

Health Path is made and published by Gabriela Stancheva, a private individual based in Bulgaria. There is currently no registered company behind the app — it is published by one person, in their own name.

We want to be upfront about what that means, because it's a genuine trade-off and you should understand it:

  • What it means for you: there is one accountable person you can contact, whose real name is given below, and who is personally and legally responsible for how this app handles your information.
  • What it means for us: publishing under a personal name rather than a company means the owner carries this responsibility personally, without the liability protection a registered company would give them. We mention it not because it changes your rights, but because we think you should know who you're actually dealing with.

Contact for anything related to privacy or your data:

Do we have a Data Protection Officer?

No, and on today's facts the law does not require one. A Data Protection Officer is mandatory for organisations whose core activity involves processing special-category data — which health data is — on a large scale. The examples the regulators give are hospitals, insurers and large advertising networks.

This is a closer question than it was in version 1.0, and we would rather show our reasoning than assert a conclusion. Health Path now does hold health data centrally, so one half of the test is clearly met. The half that is not met is scale: this is one person's app with a small number of users, running on a single machine. "Large scale" is assessed on the number of people affected, the volume and range of data, how long it is kept, and the geographic reach — and on all of those, an app of this size is not what the provision is aimed at.

This is a threshold we now actually have to watch, and we will. If Health Path grows to the point where the processing could fairly be called large-scale, a Data Protection Officer gets appointed and this section gets rewritten. Version 1.0 could rely on "there is no central copy" to end the discussion. This version cannot.

2. What the app stores, and why

Everything below is stored in two places: on your own device, inside a private storage area that Android reserves for this app and that other apps cannot read, and on Health Path's server, described in Section 3. This is the complete list — there is nothing else the app collects that isn't here.

"Kept until deleted" below is also subject to the 12-month inactivity rule in Section 15: if you don't sign in for a year, we delete the account ourselves.

What it isWhy it existsWhere it livesHow long it's keptHow to delete it
Account email addressYour username, and the address the account emails below are sent toDevice + server; passed to Resend each time an email is sent to youUntil you delete your accountManage Profile → Delete profile
Display nameShown back to you in the appDevice + serverSame as aboveSame as above
PasswordTo confirm it's you when you sign in. Stored only as an argon2id hash on the server, never as text, and not stored on your phone at all — see Section 10Server only, as a hashSame as aboveSame as above
Sign-in session tokenKeeps you signed in for up to 90 days without retyping your password. The phone holds the token; the server holds only a one-way hash of itDevice + server, hashed90 days, or until you sign outSign out, or delete your account
Password-reset codeThe six-digit code for the "forgot password" flow, stored as a hash, with a 15-minute expiry and a five-attempt limitServer only, as a hash15 minutesExpires by itself
Email-confirmation codeThe six-digit code, and matching link, in the "Confirm your email" message, stored as a hash, with a 48-hour expiry and a five-attempt limitServer only, as a hash48 hours, or until usedExpires by itself
Whether your email address is confirmed, and whenSo the app stops asking you to confirm itServerUntil you delete your accountDelete your account
When an inactivity warning was sentSo nobody is sent the same warning twice, and so no account is ever deleted under the 12-month rule without one (Section 15)ServerUntil you next sign inSign in
The emails themselves, as sentResend keeps a record of each account email it delivers: the address, the subject, the message — which contains the code, or for a warning your display name and a date — and whether it arrivedResend30 daysNot individually deletable — it expires by itself
A device identifierA random value generated on your phone at install. It names the phone, not you. It is sent with every sync so that, when the same account is used on two devices, the server can tell which device wrote which entry and settle a conflict the same way on bothDevice + serverUntil you uninstall the appUninstall the app
Onboarding answers, including what you said you'd like support withTo personalise which parts of the app are shown to you, such as seeding your goals listDevice + serverUntil deletedManage Profile → Delete profile
Mood entries — Journal check-ins, the Calendar's daily mood, and the reasons you tag them withThe core of the app: a private, personal mood log for your own reflectionDevice + serverUntil you delete the entry or the accountDelete the entry directly, or delete your account for all at once
Diary notes — free text you write, and their titlesA private space for you to write, for yourselfDevice + serverUntil deletedDelete the note directly, or delete your account
Food-group log — which of the five groups you ate from each day, and optional grams or calories if you've turned that onTo let you look back at your own eating pattern, without judgementDevice + serverUntil deletedDelete the entry, or delete your account
Movement entries — which of the five activity groups you ticked on a daySame purpose: your own record, no scoringDevice + serverUntil deletedDelete the entry, or delete your account
Custom foods and custom activities you've addedSo something you typed in can be placed into a group and logged like any otherDevice + serverUntil deletedDelete the entry, or delete your account
Goals you've selected in My GoalsTo show your chosen intentions back to youDevice + serverUntil deletedDelete your account
Avatar choiceCosmetic — one of seven bundled images, never a photo you uploadDevice + serverUntil deletedDelete your account
Numbers preference — whether grams and calories are shown at allAn opt-in switch, off by default, and most people never need to touch itDevice + serverUntil changedTurn it off in settings, or delete your account
Reminder settingsSo your reminders survive a new phone. The reminders themselves are scheduled by your phone, not sent by us — we never push a notification to youDevice + serverUntil changedChange them in settings, or delete your account
Onboarding-complete flag and similar small internal switchesSo the app remembers where you are in setupDevice + serverUntil deletedDelete your account
Timestamps: when the account was made, when you last signed in, when each entry was last changed, when a session was last usedHow the app and the server agree on which copy of an entry is the newer one. Without them, syncing two devices would silently overwrite the wrong entryDevice + serverSame as the row they belong toDeleted with that row
Your IP addressSeen by the server the way it is by any website you visit. Held briefly, in memory only, to stop someone guessing passwords or hammering the sign-up route; and written into Cloudflare's own edge logs (Section 12)Server, briefly + CloudflareMinutes for the rate limiter; Cloudflare's own retention for the edge logsNot individually deletable — it isn't stored against your account

Recipients: Cloudflare, Inc. and Resend (Plus Five Five, Inc.), and nobody else. Cloudflare carries the encrypted connection between your phone and our server. Resend delivers the three kinds of account email described below, so it receives your email address and the message itself — never your entries, your password, or anything you wrote. Section 12 explains exactly what each of them can and cannot see. Beyond that, nothing in this table is disclosed, sold, or transmitted to any other company, service, or person. There is no analytics company, no advertiser, no crash-reporting vendor, and no other app or partner receiving any of it.

Who can reach it on our side: one person — the app's owner, named in Section 1, who administers the server. There are no employees, no contractors, and no support team with a login. There is no admin screen in the app or on the website that displays anybody's entries; reading them would mean the owner opening the database by hand on the machine itself. We say that not because it is impressive but because it is the truthful answer to "who could look?".

What happens if you don't provide something. An account email, display name and password are required to create and sign in to an account at all — without them you can't use the app. Everything else is optional: if you never use a feature, the only consequence is that the corresponding part of the app has nothing to show you.

You need an account to use Health Path, and creating one includes saying yes to saving your health entries. Your account itself — email, name, password — and your settings are stored on our server as soon as you sign up. So are your moods, notes, food, movement, goals and onboarding answers, once you save them, because you agreed to that with the separate tick box at sign-up — see Section 4. What the app does not offer is a way to use it while keeping those entries on your phone only.

What we do not collect, anywhere, ever: your location, your contacts, photos from your camera roll, your device's advertising ID, browsing history, or any information about how you use other apps. The app has no permission to access any of these, and no code that would even try.

Why does the app need my email? It is your username, it is what makes your account yours across two devices, and it is the address we send account emails to. We never use it to market to you, we do not add you to any list, and we do not give it to anyone other than Resend, which delivers those emails for us.

The only emails Health Path sends, all from no-reply@healthpathapp.com:

  1. A password-reset code, when you ask for one on the "forgot password" screen. It works for 15 minutes.
  2. A code to confirm your email address, when you sign up or ask for a new one. It works for 48 hours. Confirming is optional — nothing in the app is locked if you don't — but an address you have confirmed is the one we can trust to help you back in.
  3. A warning before an unused account is deleted, about 11 months after your last sign-in and again about two weeks later (Section 15).

That is the complete list. No newsletters, no tips, no "we miss you", no marketing of any kind. The messages contain no tracking pixel, and the logo is attached to the email itself rather than loaded from a server, so opening one tells nobody that you did.

3. The server: what it is, where it is, and what reaches it

This is the section that changed most between version 1 and version 2 of this policy, so we are going to be exact rather than reassuring.

Until September 2026, the Health Path app did not ask Android for permission to use the internet at all, and everything in version 1.0 of this policy was built on that. It does now. The app can open a network connection, and it uses it to talk to one place: a Health Path server. It talks to nothing else.

What the app still does on your phone alone

The app is what engineers call offline-first, and this is not a detail — it is why the app still works on a plane or in a basement.

  • Every entry you make is written to your phone first and is read back from your phone. Nothing waits for the network.
  • If the server is unreachable, the app carries on exactly as normal. It quietly keeps a list of what has changed and sends it later.
  • The one thing that does need a connection is creating an account and signing in, because your account now lives on the server rather than on the phone.

What is sent to the server, and when

What is sent is the "Device + server" rows of the table in Section 2 — your profile, your mood entries and their reasons, your diary notes, your food and movement log, your custom foods and activities, your goals, your settings, and the timestamps that tell two devices apart.

It is sent when the app starts, when you bring it back to the foreground, shortly after you write something, and about every five minutes while you have the app open. If a send fails, the app waits and tries again later — it never sits in a tight retry loop draining your battery or your data allowance.

Where the server is

It is a computer the app's owner runs, and physically controls, in Bulgaria — inside the EU. Health Path does not rent space from Amazon, Google, Microsoft or any other cloud provider, and your entries are not stored in one. The database is an ordinary PostgreSQL database on that machine.

The machine has no port open to the internet. Instead it dials outwards to Cloudflare, and Cloudflare passes requests back down that connection. In practice this means there is no door on the server for someone on the internet to try the handle of. Section 10 covers what that does and does not protect you from, and Section 12 covers what Cloudflare can see.

What is never sent, from the app or the server

  • No analytics of any kind. The app contains no analytics tool, no crash-reporting tool, no advertising software and no tracking code. We do not measure which screens you open or how long you spend in them.
  • No location, contacts, photos, camera roll, advertising ID, or browsing history. The app has no permission to reach any of them and no code that would try.
  • None of your entries is sent to any third company. The list of who receives anything is in Section 2 and has two names on it: Cloudflare, which carries the connection, and Resend, which receives only your email address and the account emails we send you.

The honest consequences of this design

Version 1.0 of this policy had a section here explaining what we couldn't do because we held no copy of your data. Most of that has reversed, and the new trade-offs are these.

  • A lost or replaced phone no longer destroys your journal. Sign in on the new phone and your entries come back. This is the single reason the server exists.
  • But there is now a copy of very personal writing on a machine you don't control. It could in principle be broken into, seized under a lawful order, or lost to a hardware failure. We have taken real measures (Section 10) and we are not going to pretend they reduce that risk to zero.
  • We can now technically read your entries, because they sit in a database the owner administers. We don't, there is no feature anywhere that does, and no automated process looks at their contents — but the sentence "we could not look even if we wanted to", which version 1.0 of this policy made, is retired and is not coming back.
  • The server is one computer in a home, not a data centre. It has no standby machine and no failover. If it goes down — a power cut, a failed disk — the app keeps working on your phone, but syncing stops until it is back. We would rather tell you that than let you imagine a rack of redundant hardware.

Why there's no cookie-banner-style pop-up in this app

Some apps and most websites show you a pop-up asking you to accept cookies, or something like them, before you can use them. Health Path doesn't show anything like that, and we'd rather explain why than leave you wondering if we simply skipped a step.

That kind of pop-up exists for a specific reason: to ask your permission before something outside your control — usually another company — reads or writes information on your device for a purpose that isn't strictly needed to give you the feature you asked for, often for tracking or advertising. Health Path doesn't do that.

This stayed true when the server arrived, and here is why. The rule exempts storing things on your device when it is strictly necessary to provide the service you asked for. Everything the app writes to your phone is in that category: the entries themselves, the sign-in token that keeps you signed in, the queue of changes waiting to sync, the device identifier that stops two phones overwriting each other's entries. None of it is advertising, none of it is tracking, none of it is read by another company, and none of it follows you anywhere. Consent for your health data itself is a different question with a different answer — that is Section 4, and there the answer is that consent is required. What this paragraph is about is only the narrow cookie-style rule, and that one genuinely has nothing here to ask you about.

4. Is this "health data" under the law? Yes — and here's what that means

Under EU data protection law, certain categories of personal information get extra legal protection because of how sensitive they are — this includes information about your physical or mental health. It doesn't need to come from a doctor to count: a pattern of entries that reveals something about your mental or physical state counts too.

We've thought about this carefully rather than taking the easy route of calling it ordinary "lifestyle" information, and our honest conclusion is:

  • Your mood entries, in the Journal and the Calendar, are health data. A recurring, dated record of how you're feeling is exactly the kind of thing this protection exists for.
  • Your diary text is health data, and arguably the most sensitive thing in the app, because it's free text. You could write about anything, and for many people using an app built for food guilt and body image, that will include exactly the things this protection is meant to cover.
  • Your food-group log is health data too, even without calories switched on. Given what this app is for, a record of what you did and didn't eat over time is capable of revealing something about your relationship with food — which is why we treat it with the same care as the rest, rather than waving it through as "just a food diary".
  • Your onboarding answers about what you'd like support with, and the goals you select from that list in My Goals, are health data too. The onboarding question asks directly about things like support for restrictive eating and body image, and choosing a goal discloses something about your relationship with food or your body.
  • Your movement log — which of the five activity groups you ticked on a given day — is treated the same way. On its own it is thin, but sitting next to a food log in an app about restrictive eating, a record of exercise can reveal the same thing the food log does. We would rather over-protect it than argue about it.

What follows from this: the law requires us to ask for your clear, explicit "yes" before processing this kind of information — separate from, and in addition to, agreeing to the app's general terms of use. Sending it to a server makes that requirement matter more, not less: version 1 of this app kept health data on your own phone, where the consequence of a weak consent was small. Now there is a central copy.

How we ask. Since 13 September 2026, the sign-up screen has two tick boxes, and both start empty. The first accepts the Terms and this Privacy Policy. The second is only about your health information: "I agree to saving my health data." It covers your moods and the reasons you add, your diary notes, your food log, your movement log, your goals, and your onboarding answers about what you'd like support with, how you feel about food and how you feel in your body.

  • The underlined words "health data" open a short explanation of exactly that list, where it is kept (your account, on our server in Bulgaria), that it is never sold or shared, and how to delete it. Reading it does not tick the box.
  • Without that box, no account is created — and without an account, nothing is saved. The app is built around keeping these entries, so we do not offer an account that quietly throws them away.
  • The yes is recorded with the date and time you ticked the box and the version of this policy in force, and stored with your account — so that, if we are ever asked, we can show that we asked.
  • From 11 to 13 September 2026 the app asked differently: a window the first time each kind of entry was saved, with "Not now" and "Yes, that's okay". A yes given that way still counts. An account from that time that never said yes keeps its onboarding answers and goal choices on the phone only.

Your account email, display name and avatar choice are not health data — they're ordinary account information, handled under a different and lighter legal basis explained in Section 6.

5. Which law applies, and who is responsible

EU data protection law (the GDPR) applies to Health Path, and the app's owner — named in Section 1 — is the "controller". That means one identified person in Bulgaria is legally answerable for everything in this document.

This was already true in version 1.0, when nothing left your phone: the law defines "processing" broadly enough to cover storing information on a device, and the person who decides what an app collects and why is its controller whether or not they ever see the result. Now that there is a server, it is not even a close question. Health Path holds a central copy of your data, so every obligation the law imposes on an ordinary online service applies to it in the ordinary way.

What changed for you, honestly stated. Version 1.0 could say that most of your rights were satisfied automatically, because the only copy was in your own hand. That argument is gone. The rights in Section 9 now have to be honoured against a real database, by a real person, within real deadlines — and that section has been rewritten to say how each one actually works, rather than pointing at your phone.

Three obligations arrived with the server that simply did not exist before, and we would rather name them than let them sit unstated:

  • A duty to keep the data secure, in a way that can be judged — Section 10.
  • A duty to tell you, and the Bulgarian supervisory authority, if it is ever breached — within 72 hours of us becoming aware. Section 10.
  • A duty not to keep it forever — Section 15.

Bulgarian law applies alongside the GDPR, and the Bulgarian supervisory authority (the КЗЛД, contact details in Section 9) is the one that oversees us. If you live elsewhere in the EU or EEA, you can go to your own country's authority instead.

6. Why we're allowed to process each type of data

WhatWhy we're allowed to process it
Account email, display name, password hash, session tokenPerformance of our contract with you (Art. 6(1)(b)) — you asked for an account, and these are what an account is made of
The device identifier, and the timestamps on every entryPerformance of our contract (Art. 6(1)(b)) — without them the sync between your phone and the server cannot decide which version of an entry is current, and it would silently destroy entries
Your IP address, held briefly by the rate limiterOur legitimate interest (Art. 6(1)(f)) in stopping password-guessing and bulk fake sign-ups. This is the one place we rely on that basis, it is the narrow security case the law expressly contemplates (Recital 49), and the data is not linked to your account or kept
Mood entries, diary text, food and movement log, onboarding answers about what you'd like support with, and the goals you select — stored on our serverYour explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), because this is health data (Section 4). It is asked for with its own tick box at sign-up, separate from accepting the Terms, and no account is created without it. Taking the yes back currently means deleting the entries or the account — see the flagged box in Section 4.
Avatar choice, numbers preference, reminder settingsPerformance of our contract — they are settings of the service you asked for, and they are stored so a new phone gets them back

On backups, which are a processing operation in their own right: the server's database is backed up so that a disk failure does not destroy everybody's journal. The basis is the same as for the data being backed up, and the retention is in Section 15.

"Legitimate interest" appears exactly once in that table, and nowhere else. It is a basis that lets an organisation weigh its own interests against yours and decide in its own favour, so we use it only for the rate limiter — where the interest is keeping other people out of your account, the data is an IP address held for minutes, and nothing about it touches your entries. Nothing about your health data rests on it, and if you object to that one use, write to us and we will tell you honestly what would change: the answer is that the protection would weaken, not that we would refuse.

We do not use any of your data for advertising, and we do not build a profile of you to predict or influence your behaviour. Nothing in the app makes an automated decision about you.

7. Android backups — please read this section

Android phones normally back up the data of the apps on them into the owner's Google account. Health Path switches that off for itself.

This is not a setting you have to find. The app tells Android, in its own configuration, not to include Health Path's data in either kind of transfer Android offers:

  • Backups to your Google account — the "Back up to Google Drive" feature. Your diary text, mood history and food log are never copied there.
  • Phone-to-phone transfer, the copy Android offers to make when you set up a new device. Health Path's data is excluded from that too.

We did this originally because everything else in this policy said your entries stayed on your phone, and leaving Android's backup on would have made that untrue.

It stays off now, for a different and equally deliberate reason. Health Path's own server is the backup, and it is one we can describe to you honestly: we can tell you where it is (Bulgaria), who administers it (one named person), how long things are kept (Section 15), and how to make it forget you (Section 9). Google's backup is a copy of your diary sitting in an account we cannot see, cannot describe, and cannot delete on your behalf. Given the choice between two backups, we would rather have the one we can be held to. So the answer is not "we have both" — it is one backup, ours, and it is not Google's.

What this means for you in practice

A lost, broken or replaced phone no longer destroys your entries. Sign in on the new phone and they come back from the server. This is the whole reason the server exists, and it is the opposite of what version 1.0 of this policy had to tell you.

Two honest caveats:

  • What comes back is what was synced. If you wrote entries while the app could not reach the server, and the phone was lost before it next connected, those particular entries were still only ever on that phone.
  • Uninstalling the app does not delete your account. It removes the copy on that phone. The copy on the server stays until you delete the account — deliberately, because otherwise a reinstall would come back empty. If you want everything gone, use Manage Profile → Delete profile before uninstalling, or write to us afterwards.

If you have already used an older version

Health Path has had Android's backup switched off since its first public release, so there should be no old backup of it in your Google account. If you are ever unsure, your Google account's own backup settings will show you what it holds for each app, and you can delete it there. We have no access to that and cannot do it for you.

8. Children and age

Health Path is intended for people 16 years old and up. This is our own choice — it's stricter than the minimum Bulgarian law itself would require for this kind of service, which is 14 — but we think 16 is the right floor for an app that deals directly with body image and food guilt.

If you are a parent or guardian and believe someone under 16 is using Health Path, you or they can delete the account and everything in it at any time, directly in the app (Manage Profile → Delete profile) — that erases it from our server as well as from the phone. You can also write to support@healthpathapp.com and we will do it, and confirm when it's done. We will not ask for proof of anything before deleting a child's account.

9. Your rights, and how they actually work here

Under data protection law you have a set of rights over your personal data. In version 1.0 of this policy most of them were satisfied automatically, because the only copy of anything was on your own phone. That is no longer the answer, so each row below says what we actually do against the copy on our server.

RightHow it works for Health Path
Access — see what's held about youAlmost everything is already visible in the app — Profile, Diary, Calendar, Food and Movement history. For the rest, and for written confirmation of what our server holds about you, write to support@healthpathapp.com and we will answer within one month with the whole of it, not a summary.
Rectification — correct wrong dataEdit any entry directly in the app, any time. The correction reaches the server the next time the app syncs, and it overwrites the old value there rather than sitting beside it.
Erasure — delete your dataDelete an individual entry, or use Manage Profile → Delete profile. Deleting the account deletes it from our server too — every row belonging to you is removed from the database at that moment, not flagged as hidden and not queued for later. Two caveats we would rather state: a deleted entry leaves behind a small marker recording that a row with that identifier was deleted, so a second phone learns to delete it too — the marker holds no content; and the backups in Section 15 keep a copy for up to 30 days before they roll off.
Restriction — limit processing while a dispute is resolvedWrite to us. We can suspend an account so nothing further is synced or changed while a question is being resolved, without deleting anything.
Portability — take your data elsewhere in a usable formatWrite to support@healthpathapp.com and we will send you your entries as a JSON file — structured, machine-readable and complete. Still a gap: this is done by hand today. A one-tap export inside the app is being built, and until it exists this right depends on emailing us, which is slower than it should be. In version 1.0 this right could not be honoured at all, so it is an improvement, not a solved problem.
Objection — object to processingThe only thing on that basis is the rate limiter's brief use of your IP address (Section 6). You can object to it and we will explain what changes.
Withdraw your consentDelete the entries you want gone one at a time, or delete your account for all of them at once. Withdrawing is meant to be as easy as giving — if it isn't, tell us, and that is a defect on our side.
Automated decisionsNot applicable. Nothing in the app or on the server scores, ranks, profiles, or makes any automated decision about you. The server stores your entries and hands them back; it never evaluates them.

How we check it's you. For anything that reveals or deletes data, we need to be reasonably sure we are talking to the account's owner. We will normally ask you to write from the email address the account uses. We will never ask you for your password, and we will never ask you to send us a photo of an identity document unless there is a genuine doubt we can't resolve any other way.

Response time. We reply within one month. If a request is complex we may need up to two further months, and we'll tell you that it's happening and why — we won't just go quiet. There is no charge for any of this.

The right to complain

You have the right to complain to a data protection supervisory authority at any time, whether or not you've contacted us first. In Bulgaria, that's:

If you live elsewhere in the EU or EEA, you can complain to your own country's equivalent authority instead — you don't have to use the Bulgarian one just because we're based here. You also have the right to take the matter to court, in addition to or instead of complaining to a supervisory authority.

10. Security — what actually protects your data, and what doesn't

We'd rather tell you plainly what is and isn't in place than let a vague phrase like "industry-standard security" stand in for specifics. There are three places your data sits — your phone, the connection, and the server — so this section covers all three.

On the connection between your phone and us

  • Everything is encrypted in transit, with HTTPS. Nobody on the café WiFi, on your mobile network, or anywhere between you and us can read what your app sends.
  • The connection is carried by Cloudflare. Section 12 explains what that means for what Cloudflare can technically see, because we would rather you heard it from us.

On our server

  • Your password is hashed with argon2id. That is the algorithm currently recommended for exactly this job — deliberately slow and memory-hungry, so that guessing passwords in bulk is expensive even for someone holding the whole database. It is a real upgrade on what version 1.0 of this policy had to admit to, which was a fast hash on the phone.
  • Your password is never stored on your phone at all any more, in any form.
  • Sign-in tokens are stored only as a one-way hash. If someone stole the database they would not get a usable key to anyone's account. Tokens expire after 90 days and are revoked the moment you sign out.
  • Password-reset codes are stored hashed, expire in 15 minutes, allow five attempts, and can be used once. Email-confirmation codes work the same way, with 48 hours.
  • Emails leave our server over an encrypted connection to Resend. Once delivered, an email is as private as your inbox and no more — like almost all email, it is not end-to-end encrypted. That is why the codes in them expire quickly and work only once.
  • Sign-in gives the same answer for "no such account" and "wrong password", so the server cannot be used to find out whether a given person has a Health Path account.
  • Rate limiting on every route that takes a password, counted both per internet address and per account, so a bot cannot grind through guesses from many machines.
  • The server has no port open to the internet. It makes an outbound connection to Cloudflare and receives requests down it. There is no door to try the handle of.
  • The database is backed up, so a failed disk does not destroy everyone's journal.

On your phone

  • The Android app sandbox. Every Android app's private storage is walled off from every other app on the phone. Another app cannot read Health Path's data without breaking Android's own security model — root access, or an exploit. This is a real protection.
  • Android's own backup is switched off for this app (Section 7), so your entries are not copied into your Google account.

What does not protect your data — stated plainly, because you should know

  • Your entries are stored as ordinary readable text in our database. They are not encrypted with a key only you hold. We could not offer the sync, search and multi-device features if they were, and we are not going to imply an "end-to-end encrypted" property the app does not have. Anyone with administrative access to that machine could read entries. Today that is one person: the owner.
  • The same is true on your phone, inside the app's private storage. The sandbox protects it; a second layer of encryption does not.
  • A rooted phone, or one shared with people you don't trust, is a real risk. If someone has physical access to your unlocked phone, they can read your diary by opening the app.
  • The server is one computer in a home in Bulgaria, not a data centre. It has physical protection no better than a house, no security staff, no standby machine, and no independent security audit or penetration test has been carried out on it. That is the honest description, and if it changes we will change this line.
  • A "data breach" is now possible, where before it was not. Version 1.0 of this policy could say there was no server to hack. There is one now.

If there is ever a breach

If we become aware that your data has been exposed — a break-in, a lost backup, a mistake of ours, anything — then:

  • we notify the Bulgarian supervisory authority (the КЗЛД) within 72 hours of becoming aware of it, as the law requires;
  • if the breach is likely to put you at real risk, we tell you directly, without undue delay, in plain language: what happened, what data was involved, and what you should do;
  • we will not wait to be asked, and we will not describe it as a "security incident" to make it sound smaller than it is.

Because the data here is a diary about food, mood and body image, we treat "likely to put you at real risk" as a low bar. If in doubt, we will tell you.

11. The website — separate from the app, handled separately

This section covers https://healthpathapp.com, the marketing website — not the app itself, which is covered by everything above. If you've only ever used the app and never visited the website, this section doesn't add anything for you.

  • Server logs. Like essentially any website, ordinary web server logs — which record things like IP address and request time, generated automatically by the server software — may be created when you visit. We don't run analytics on top of these logs; the page counting described below is a separate thing.
  • Cookies. This website does not set any cookies.
  • Analytics. This website uses Cloudflare Web Analytics to count page views. It is cookieless: it stores nothing on your device, does not identify you, and cannot follow you to other websites. We see totals only — how many pages were viewed, which pages, roughly which country, and what kind of device. Cloudflare, Inc. acts as our processor for this, as it already does for hosting the site; Section 13 explains what that means. The app itself runs no analytics of any kind (Section 3).
  • Fonts. The website's fonts are served from our own hosting, not from Google's servers, so visiting the site does not send your information to Google by this route. Until 15 August 2026 it did load them from Google on every page, which sent your IP address to Google before you had agreed to anything; we removed it ourselves rather than wait to be asked.
  • The link to TikTok. The footer links to a TikTok profile. That link takes you to a third party's website, which has its own privacy practices and its own tracking, entirely outside our control. Check TikTok's own privacy policy if that concerns you.
  • One form. “Get launch news” asks for a first name and an email address, so we can write to you once — on the day the app is released. It is entirely optional and nothing else on the site depends on it. There is no other form: no contact form, no newsletter, no account.
    • What we do with it: that one announcement, and nothing else. We do not sell or share the list, and we send nothing in the meantime.
    • Who holds it: the form is handled by our own endpoint on Cloudflare, the company that also hosts this website, and addresses are stored in a database in Cloudflare's Western European region. Until 17 August 2026 this form was handled by Formspree (Formspree Inc.) in the United States; we moved it so that an address given here stays in the EU. Cloudflare, Inc. is a US-headquartered company acting as our processor, which is not quite the same as “nothing leaves the EU” — Section 13 says plainly what it does and doesn't mean. What the app sends, and where, is Section 3.
    • Getting off the list: write to support@healthpathapp.com and we delete you from it. The launch email will carry an unsubscribe link.
    • Why we're allowed to: your consent (Art. 6(1)(a) GDPR), given by submitting the form, and withdrawing it is as easy as giving it was.

12. Third parties: Cloudflare, Resend, and Google Play

Cloudflare — the one company in the middle

Since September 2026 there is exactly one company between your phone and our server, and it is Cloudflare, Inc. We would rather explain it properly than list it in a table of "partners".

What it does for us: it gives our API address its HTTPS certificate, it absorbs attacks aimed at the server, and it carries each request down the outbound-only connection our machine makes to it. It is the reason the server can be reached from a phone without a single port being opened at our end. Cloudflare also hosts this website (Section 11) and the launch sign-up list.

What it can technically see: because Cloudflare terminates the HTTPS connection, it handles requests in the clear at its edge before passing them on. In principle that means the content of a sync request passes through their systems. Cloudflare's role is a processor: it acts on our instructions, under its own data-processing terms, it has no right to use your data for its own purposes, and it does not receive a copy of the database. But "nobody can see it but us" would be an overstatement, so we are not making it. Cloudflare also keeps its own connection logs, which include your IP address, under its own retention policy.

Where it is: Cloudflare, Inc. is headquartered in the United States and operates a global network. Section 13 deals with what that means for your data leaving the EU.

Resend — the account emails

What it does for us: it delivers the three kinds of email listed in Section 2 — a password-reset code, a code to confirm your address, and an inactivity warning. Our server hands each message to Resend over an encrypted connection, and Resend sends it to your inbox from no-reply@healthpathapp.com. It is not involved in anything else: it is not on the path between your phone and our server, and it never sees a sync.

What it receives: your email address, the subject line, and the message. The message contains the code or confirmation link, and in an inactivity warning your display name and the date the account would be deleted. It never receives your entries, your diary, your moods, your password, or anything else from Section 2's table.

What it keeps: a record of each message — including its content — for 30 days, so that a message that failed to arrive can be looked into. After that it is deleted. Deleting your Health Path account does not reach into that 30-day record; it runs out by itself.

Its role: processor. The company is Plus Five Five, Inc., trading as Resend. It acts only on our instructions, under a data processing addendum that applies to every Resend customer as part of its terms, and it may not use your address or the messages for its own purposes. Open-tracking and click-tracking are switched off on our sending domain, not merely left unused — so Resend is not told whether you opened a message or followed the link in it. Resend uses sub-processors of its own to deliver mail, in the United States, and its addendum requires it to give us at least 14 days' notice before it adds or replaces one; if one of them ever mattered to what this policy says, Section 14 is how you would hear about it.

Where it is: San Francisco, United States. Our sending domain is set to Resend's eu-west-1 region, so the messages themselves are dispatched from Ireland — but that setting moves only the sending, and we would rather say so than let it read as more than it is: the 30-day copy, the delivery logs and the account records sit in the United States whichever region sends. So this is a real transfer outside the EU, unlike Cloudflare, and Section 13 says what protects it.

Google Play

Health Path is not yet available on Google Play. Once it is published there, Google, as the store operator, will collect its own information as part of running that store — for example your Google account details, payment details if you ever buy anything through Google Play, and device and app information Google collects for its own store operations.

This is Google's own collection, under Google's own privacy policy — we don't control it, and we don't receive any of it. If you want to know what Google Play itself collects about you as a user of the store, Google's own privacy policy is the right place to check, not this document.

That is the complete list: Cloudflare, Resend and Google Play. There is no analytics company, no advertising network, no crash-reporting vendor, no email-marketing service, and no cloud storage provider — your entries are on a machine we own, not rented space. If that list ever grows, this section is where it will say so, and Section 14 says how we will tell you.

13. International data transfers

Where your entries are stored: in the EU. The server is in Bulgaria (Section 3), and the website's sign-up list is in Cloudflare's Western European region (Section 11). The one thing kept outside the EU/EEA is email: Resend holds a copy of each account email we send you, in the United States, for 30 days (below).

Where it is honest to say "it's complicated": Cloudflare. Cloudflare, Inc. is a US-headquartered company, and it carries every request between your phone and our server. Two things follow, and we would rather write both than only the comfortable one:

  • We do not choose to send your data to the United States, and it is not stored there. Cloudflare's network routes traffic through nearby locations, which for a user in Europe means European ones.
  • But a US-headquartered processor handling EU data is legally a transfer question, not a non-question. The safeguard relied on is Cloudflare's own standard data-processing terms, which incorporate the European Commission's Standard Contractual Clauses, together with its published supplementary measures. Cloudflare is also certified under the EU-US Data Privacy Framework.

Resend is a plain transfer, and we say so. When our server sends you an account email, your email address and the message go to Resend, which dispatches it from Ireland but keeps its copy — and its delivery log — in the United States for 30 days. It is limited to what Section 12 lists — never your entries. The safeguards relied on are:

  • Resend is certified under the EU-US Data Privacy Framework, which the European Commission has recognised as giving adequate protection to data sent to certified US companies; and
  • its data processing addendum also includes the European Commission's Standard Contractual Clauses, which apply if that framework ever stops being available.

If this matters a lot to you, the honest advice is that a diary app run by one person cannot offer you an EU-only network path today, and you should weigh that before writing things in it you would not want to travel.

14. Changes to this policy

If we make a meaningful change to this policy — for example adding a feature that changes what data is collected, or building the export mentioned in Section 9 — we will update this document and the effective date at the top. For any change that meaningfully affects what we do with your data, we'll also let you know inside the app itself, not just by quietly editing a web page.

Version 2.0 is exactly that kind of change, and it is the largest one this policy will ever make: an app that sent nothing anywhere now keeps a copy of your entries on a server. We are not going to treat that as a quiet edit. Anyone using Health Path when the change takes effect should be told inside the app, plainly, and asked again — because the consent they gave was to something different. Version 2.1 did that with a question the first time each kind of health information was saved; since version 2.2 it is a separate tick box at sign-up (Section 4).

15. How long we keep your data

Version 1.0 of this policy did not need this section: data lived on your phone, and it lasted exactly as long as you let it. Now that we hold a copy, we owe you a straight answer about how long we hold it — the law calls this storage limitation, and it means we are not allowed to keep things forever just because storage is cheap.

WhatHow long
Your entries, profile and settingsFor as long as your account exists. Deleting an entry deletes it from the server at the next sync; deleting your account deletes all of it at once
An account you stop usingDeleted automatically after 12 months with no sign-in, along with every entry in it — see below
Sign-in sessions90 days, or until you sign out
Password-reset codes15 minutes
Email-confirmation codes48 hours
Copies of account emails, kept by Resend30 days
Rate-limiting records (your IP address)Minutes, in memory only, never written to disk
Database backupsRolling, and no longer than 30 days. A deleted account disappears from the backups as they roll over
Cloudflare's own connection logsCloudflare's retention, under their policy, not ours

The 12-month rule, in plain terms

If you don't sign in to Health Path for 12 months, we delete your account and everything in it. Not archive, not deactivate — delete, the same as if you had pressed the button yourself. It cannot be undone, by you or by us.

We chose this deliberately, and it is a genuine trade-off:

  • Why we do it: the most private thing we could do with a diary about food and body image that nobody is using any more is not to have it. Keeping an abandoned account indefinitely means holding someone's most personal writing for no reason, and every year it sits there is another year it could be exposed by something going wrong.
  • What it costs you: if you take a year away from the app — which people recovering from difficult relationships with food quite reasonably do — and come back, your entries will be gone. Signing in once, at any point in the year, resets the clock.
  • What we do first: warn you. About 11 months after your last sign-in we email your account's address, and if you still haven't signed in, we email again about two weeks later. Signing in after either email cancels the deletion and restarts the clock.
  • No warning, no deletion, and no deletion within a fortnight of one. An account is deleted under this rule only if a warning was actually sent to it, and only once that warning is at least 14 days old. If an email fails to send, the account is kept, and we try the warning again rather than deleting without it. These two sentences are our commitment on the point, and they are enforced in the code that does the deleting, not only here.

If Health Path ever changes shape again

If a paid subscription is added, this policy will need to say which payment processor handles your card and what they, rather than we, hold. If any new company is added to Section 12, or the server moves, we will say so under Section 14 before it happens rather than after.