Legal
Privacy Policy
Health Path has no server. Everything you write stays on your own phone, and we never receive it. Here is exactly what that means.
The short version
We know most people don't read privacy policies. Here's the honest summary before the full document — everything in it is explained properly, with the reasons, further down.
- Your data stays on your phone. Health Path has no server. There is no "Health Path cloud" your entries go to.
- We cannot see your data. Not your mood entries, not your diary, not your food log, not your email address. There is no wire connecting your phone to us. We could not look even if we wanted to.
- We don't sell it, because we never have it. There's nothing to sell, share, or hand to an advertiser.
- Uninstalling the app deletes your data, and so does the app's own "delete everything" option. Because we hold no copy anywhere, deletion inside Health Path is complete and immediate — not "deleted from our servers within 30 days," but gone, because there was never a second copy on our side, and no copy anywhere else either.
- Health Path also switches off Android's own automatic backup, so your phone does not copy your entries into your Google account. Section 7 explains this properly, including what it costs you.
- This is the downside, and we want to be honest about it. If you forget your password, lose your phone, get a new one, or uninstall the app, your entries are gone and nobody can bring them back — not you, not us, not Google. We don't have a copy to restore from, and we've deliberately stopped your phone from keeping one. This is the price of the privacy above, and you should decide whether it's a price you want to pay.
- We still have real legal obligations to you even though we never see your data. "We don't have your data" doesn't mean "the law doesn't apply to us." It applies. It's just that most of what it asks for, you already have, because it's on your own phone.
If that's all you needed, you can stop here. If you want the details — what exactly is stored, why, what your rights are, and how to reach us — read on.
1. Who we are
Health Path is made and published by Gabriela Stancheva, a private individual based in Bulgaria. There is currently no registered company behind the app — it is published by one person, in their own name.
We want to be upfront about what that means, because it's a genuine trade-off and you should understand it:
- What it means for you: there is one accountable person you can contact, whose real name is given below, and who is personally and legally responsible for how this app handles your information.
- What it means for us: publishing under a personal name rather than a company means the owner carries this responsibility personally, without the liability protection a registered company would give them. We mention it not because it changes your rights, but because we think you should know who you're actually dealing with.
Contact for anything related to privacy or your data:
Gabriela Stancheva69 Bulgaria Blvd., 1404 Sofia, Bulgaria
support@healthpathapp.com
https://healthpathapp.com
Do we have a Data Protection Officer?
No, and under the law we're not required to. A Data Protection Officer is mandatory for organisations that, among other things, process large volumes of sensitive data as their core, systematic, large-scale activity — typically hospitals, insurers, large ad networks. Health Path is a single developer's app with no server and no centralised copy of anyone's data; on the facts as they stand today, that threshold isn't met. If that ever changes — for instance if Health Path adds a server, or the number of people using it grows large enough that our processing could reasonably be called "large scale" even without one — we will revisit this and appoint one if the law then requires it.
2. What the app stores, and why
Everything below is stored only on your own device, inside a private storage area that Android reserves for this app and that other apps cannot read. Nothing in this table is sent anywhere. This is the complete list — there is nothing else the app collects that isn't here.
| What it is | Why it exists | How long it's kept | How to delete it |
|---|---|---|---|
| Account email address | So you can create and sign back into your local account on this device | Until you delete your account or uninstall the app | Manage Profile → delete account, or uninstall |
| Display name | Shown back to you in the app | Same as above | Same as above |
| Password, as a salted hash — never as plain text (see Section 10) | To confirm it's you when you sign in | Same as above | Same as above |
| Onboarding answers, including what you said you'd like support with | To personalise which parts of the app are shown to you, such as seeding your goals list | Until deleted or uninstalled | Manage Profile → delete account |
| Mood entries — Journal check-ins and the Calendar's daily mood | The core of the app: a private, personal mood log for your own reflection | Until you delete the entry, delete your account, or uninstall | Delete the entry directly, or delete your account for all at once |
| Diary notes — free text you write | A private space for you to write, for yourself | Until deleted or uninstalled | Delete the note directly, or delete your account |
| Food-group log — which of the five groups you ate from each day, and optional grams or calories if you've turned that on | To let you look back at your own eating pattern, without judgement | Until deleted or uninstalled | Delete the entry, or delete your account |
| Custom foods you've added | So a food you typed in can be placed into a group and logged like any other | Until deleted or uninstalled | Delete the entry, or delete your account |
| Goals you've selected in My Goals | To show your chosen intentions back to you | Until deleted or uninstalled | Delete your account |
| Avatar choice | Cosmetic — one of seven bundled images, never a photo you upload | Until deleted or uninstalled | Delete your account |
| Numbers preference — whether grams and calories are shown at all | An opt-in switch, off by default, and most people never need to touch it | Until changed or uninstalled | Turn it off in settings, or delete your account |
| Onboarding-complete flag and similar small internal switches | So the app remembers where you are in setup | Until deleted or uninstalled | Delete your account |
Recipients: none. Nothing in this table is disclosed, sold, or transmitted to any other company, service, or person — including us. There is no one else this data is given to.
What happens if you don't provide something. An account email, display name and password are required to create and sign in to an account at all — without them you can't use the app. Everything else is optional: if you never use a feature, the only consequence is that the corresponding part of the app has nothing to show you.
What we do not collect, anywhere, ever: your location, your contacts, photos from your camera roll, your device's advertising ID, browsing history, or any information about how you use other apps. The app has no permission to access any of these, and no code that would even try.
Why does the app need my email? Because accounts are entirely local to your device, your email address here is just a username you chose. It is never verified by sending you an email, and never used to contact you, market to you, or identify you to anyone else. It exists purely so you can sign back into the app on this device.
3. The fact this whole policy is built on: the app has no internet connection
This is the single most important technical fact about Health Path, so we want to state it plainly rather than bury it in an appendix.
Health Path's Android app does not request permission to use the internet. Not "asks for it but tries to minimise use" — it does not ask for it at all. Without that permission, Android itself blocks the app from opening any network connection. This isn't a policy we chose to follow; it's the operating system stopping it at the door. We independently checked the app's code and confirmed:
- No part of the app makes an outgoing network request.
- There is no analytics tool, no crash-reporting tool, no advertising software, and no tracking code of any kind built into the app.
- There is no Health Path server. Not "a server we don't currently use" — there is no server that exists to send anything to.
One small technical honesty note. The app uses a font (Inter) via a library called Google Fonts, which is designed to fetch that font from Google's servers if it isn't already available. Because the app has no internet permission, this fetch is blocked by Android before it can send a single byte — it fails silently and the app falls back to your phone's own default font. We mention it because we said we'd be exhaustive, not because it does anything: no data leaves your device through this or any other path.
The honest consequence of this design
Because we never receive a copy of your data, we also can't do some things a normal online service could:
- We cannot recover a forgotten password. There is no reset link we can email you, because we don't hold your account outside your device.
- We cannot restore lost data. If your phone is lost, stolen, damaged beyond repair, replaced, or the app is uninstalled, your entries are gone. We don't have a second copy to send back, because one was never made — and, as Section 7 explains, the app deliberately stops your phone from making one either.
- We cannot tell you anything about yourself that you don't already have. Whatever the app knows about you is already visible to you, right now, in the app.
We think this trade — real privacy in exchange for no safety net if you lose your device — is the right one for an app that asks people to write honestly about food, mood and body image. But it is a real trade-off, and you should go in knowing it, not discover it the day you need a backup that doesn't exist.
Why there's no cookie-banner-style pop-up in this app
Most websites, and some apps, show you a pop-up asking you to accept cookies before you can use them. Health Path doesn't show anything like that, and we'd rather explain why than leave you wondering whether we simply skipped a step.
That kind of pop-up exists for a specific reason: to ask your permission before something outside your control — usually another company — reads or writes information on your device for a purpose that isn't strictly needed to give you the feature you asked for, often for tracking or advertising. Health Path doesn't do that, and can't. Everything the app stores on your device is written and read only by the app itself, and only for the feature you're actively using: your mood entries so the Journal can show them back to you, your diary text so it's still there next time you open the app. The rule that requires that kind of pop-up is aimed squarely at the situation where an outside party could reach onto your device. Here, nobody but you and the app itself ever can, so there is genuinely nothing for a consent pop-up to ask permission for.
4. Is this "health data" under the law? Yes — and here's what that means
Under EU data protection law, certain categories of personal information get extra legal protection because of how sensitive they are — this includes information about your physical or mental health. It doesn't need to come from a doctor to count: a pattern of entries that reveals something about your mental or physical state counts too.
We've thought about this carefully rather than taking the easy route of calling it ordinary "lifestyle" information, and our honest conclusion is:
- Your mood entries are health data. A recurring, dated record of how you're feeling is exactly the kind of thing this protection exists for.
- Your diary text is health data, and arguably the most sensitive thing in the app, because it's free text — you could write about anything, and for many people using an app built for food guilt and body image, that will include exactly the things this protection is meant to cover.
- Your food-group log is health data too, even without calories switched on. Given what this app is for, a record of what you did and didn't eat over time is capable of revealing something about your relationship with food, which is why we treat it with the same care rather than waving it through as "just a food diary."
- Your onboarding answers about what you'd like support with, and the goals you select from that list, are health data too. That question asks directly about things like support for restrictive eating and body image, and choosing a goal discloses something about your relationship with food or your body.
What follows from this. The law requires us to ask for your clear, explicit agreement before processing this kind of information — separate from, and in addition to, agreeing to the app's general terms of use.
An honest gap, stated rather than glossed over. The app does not yet have a separate consent step for this. Today, the general acceptance during onboarding is the only agreement the app captures, and it does not ask you specifically about mood, diary, food-group, onboarding-support and goals data the way the law expects. We are building that step. Until it ships, this is the accurate position, and we'd rather tell you than describe a screen that doesn't exist.
You can withdraw your agreement at any time by deleting your account, which removes the data it covered.
Your account email, display name and avatar choice are not health data — they're ordinary account information, handled under a lighter legal basis explained in Section 6.
5. "But it never leaves my phone — does the law even apply?"
It's a fair question, and we want to answer it honestly rather than give a reassuring but inaccurate answer.
Short answer: yes, EU data protection law applies to Health Path, even though nothing is transmitted anywhere. The law defines "processing" personal data very broadly — it includes collecting, storing and organising information, regardless of whether it's on a server or on your own phone, and regardless of who can see the result. The person who decided what data the app collects and why is legally the "controller" of that data, even though they never receive a copy of it. There's no court ruling that settles this exact scenario with total certainty, but the reasoning is well established, and we'd rather draft this policy on the safer, more protective assumption than lean on a technicality.
What this means in practice is genuinely good news for you. Being a controller comes with obligations — being transparent about what's collected and why, having a lawful reason to collect it, letting you access, correct and delete it. Because your data lives only on your device, almost every one of those is already satisfied automatically, just by how the app is built:
- Access? You can already see everything, right now, in the app.
- Correction? You can already edit any entry directly.
- Deletion? You can already delete anything, instantly, with nothing left behind anywhere else.
The offline design doesn't take Health Path outside the law's reach. It just means the law asks for things the app already does by default.
6. Why we're allowed to process each type of data
| What | Why we're allowed to process it |
|---|---|
| Account email, display name, password hash | Necessary to provide the account feature you're using — the basic "we need this to run the service you asked for" basis |
| Mood entries, diary text, food-group log, onboarding answers about what you'd like support with, and goals selected | Your explicit agreement, given because this is treated as health-related data (Section 4). You can withdraw it at any time by deleting your account. Note the gap flagged in Section 4: this agreement is not yet captured through a dedicated step, so today it rests on onboarding's general acceptance. |
| Avatar choice, numbers preference | Your own direct choice in the app's settings |
We do not rely on "legitimate interest" as a basis for anything in this app. That basis involves a balancing test against your interests, and we'd rather ask you directly than rely on our own judgement about what's legitimate.
We do not use any of your data for advertising, and we do not build a profile of you to predict or influence your behaviour. Nothing in the app makes an automated decision about you.
7. Android backups — please read this section
Android phones normally back up the data of the apps on them into the owner's Google account. Health Path switches that off for itself.
This is not a setting you have to find. The app tells Android, in its own configuration, not to include Health Path's data in either kind of transfer Android offers:
- Backups to your Google account (the "Back up to Google Drive" feature). Your diary text, mood history and food log are never copied there.
- Phone-to-phone transfer, the copy Android offers to make when you set up a new device. Health Path's data is excluded from that too.
We did this because everything else in this policy says your entries stay on your phone, and leaving Android's backup switched on would have made that untrue. The data would have gone to your own Google account rather than to us — we would still never have seen it — but it would have left your device, and we'd rather the sentence be simply true than true with an asterisk.
What this costs you, which is not small
If you lose your phone, replace it, factory reset it, or uninstall Health Path, your entries are permanently gone. There is no copy anywhere. We can't restore them, because we never had them. Google can't restore them, because we told Android not to keep them. You can't restore them either.
This is a real trade-off and we would rather you meet it here than discover it on the day you upgrade your phone. An app that kept a backup would be able to move your journal to a new device; the cost of that convenience is a copy of your health data sitting in an account we can't see and can't promise anything about. We chose the version with no copy. If that is the wrong trade for you, it is a fair reason not to use Health Path, and we'd rather say so plainly than have you find out later.
If you have already used an older version
Health Path has had this setting switched off since its first public release, so there should be no old backup of it anywhere. If you are ever unsure, your Google account's own backup settings will show you what it holds for each app, and you can delete it there. We have no access to that and cannot do it for you.
8. Children and age
Health Path is intended for people 16 years old and up. This is our own choice — it's stricter than the minimum Bulgarian law itself would require for this kind of service, which is 14 — but we think 16 is the right floor for an app that deals directly with body image and food guilt.
Honest gap to flag. The app does not currently ask for or verify your age anywhere in its sign-up flow. The 16+ floor is a policy we've committed to, not something the app technically enforces yet. We're stating this openly rather than implying an age check exists when it doesn't.
If you are a parent or guardian and believe someone under 16 is using Health Path with an account containing their information, you or they can delete that account and all its data at any time, directly in the app, with nothing left behind anywhere else afterward.
9. Your rights, and how they actually work here
Under data protection law you have a set of rights over your personal data. Below, each one is explained honestly for what it means in an app where we never hold a copy of anything.
| Right | How it works for Health Path |
|---|---|
| Access — see what's held about you | Everything is already visible to you, right now, in the app. If you'd still like written confirmation from us, email us and we'll reply substantively, though we hold nothing beyond what you already see. |
| Rectification — correct wrong data | Edit any entry directly in the app, any time. |
| Erasure — delete your data | Delete an individual entry, or use Manage Profile's full "delete everything" option. Both are immediate and complete — there is no second copy anywhere, because the app also switches off Android's own backup (Section 7). |
| Restriction — limit processing while a dispute is resolved | With no central copy, the most meaningful version of this is simply not using the app, or a specific feature, while you decide what you want. |
| Portability — take your data elsewhere in a usable format | Not yet available. This is the one right the app does not currently satisfy: there is no export feature, and "you can already see it in the app" is not the same as a portable copy. We are building an export you can generate on your device and share wherever you like, and we say so plainly rather than claim this right is already honoured. |
| Objection — object to processing | We don't process anything on the basis this right targets (Section 6), so this mainly overlaps with withdrawing your agreement, below. |
| Withdraw your agreement | Delete the specific entries covered — mood check-ins, diary notes or food-group logs — one at a time from where you see them, or delete your account for all at once. We know that's more effort than the single tap it took to agree; if a lighter "stop keeping this" switch would help you, tell us. |
| Automated decisions | Not applicable. The app doesn't score, rank, or make any automated decision about you. |
Response time. If you contact us about any of the above, we'll reply within one month. If a request is complex we may need up to two further months, and we'll tell you if that's the case and why.
The right to complain
You have the right to complain to a data protection supervisory authority at any time, whether or not you've contacted us first. In Bulgaria, that's:
Комисия за защита на личните данни (КЗЛД)Commission for Personal Data Protection
гр. София 1592, бул. „Проф. Цветан Лазаров" № 2
Telephone: 02 915 3518
Email: kzld@cpdp.bg
Web: www.cpdp.bg
If you live elsewhere in the EU or EEA, you can complain to your own country's equivalent authority instead — you don't have to use the Bulgarian one just because we're based here. You also have the right to take the matter to court, in addition to or instead of complaining to a supervisory authority.
10. Security — what actually protects your data, and what doesn't
We'd rather tell you plainly what is and isn't in place than let a vague phrase like "industry-standard security" stand in for specifics.
What protects your data
- The Android app sandbox. Every Android app's private storage is, by design, walled off from every other app on the phone. Another app cannot read Health Path's data without breaking Android's own security model. This is a real, meaningful protection, not a formality.
- Your password is not stored as plain text. It's stored as a salted hash — a one-way scrambled version, combined with a random value unique to your account, that cannot be reversed back into your original password.
What does not protect your data, stated honestly
- Your entries are not encrypted at rest. Your mood, diary and food-log content is stored as ordinary readable text inside the app's private storage area. It's protected by the sandbox above, but not by a second layer of encryption on top of that.
- The password hashing method is a fast one, not a slow one built specifically to resist offline cracking. In plain terms: if someone obtained the raw storage file — which requires root access to your phone or physical access to an unlocked device, not something achievable remotely since nothing is transmitted — a fast hash is crackable at speed with the right hardware. We're upgrading this; it's a known limitation and we're not hiding it.
- A rooted phone, or a phone shared with people you don't trust, is a real risk. The protections above assume a normal, non-rooted phone that only you have access to.
Because there is no server, the usual meaning of "data breach" — a company's servers being hacked — cannot happen to Health Path. There is no server to hack. The realistic remaining risk sits entirely at the device level: a rooted phone, a lost unlocked phone, or a future bug in the app itself. If we ever became aware of a defect that put your data at risk in a way traceable to how we built the app, we would treat that seriously and notify affected users and, where required, the supervisory authority — even though the classic breach scenario doesn't apply here.
11. The website — separate from the app, handled separately
This section covers https://healthpathapp.com, the marketing website — not the app itself, which is covered by everything above. If you've only ever used the app and never visited the website, this section doesn't add anything for you.
- Server logs. Like essentially any website, ordinary web server logs — which record things like IP address and request time, generated automatically by the server software — may be created when you visit. We don't run analytics on top of this.
- Cookies. This website does not set any cookies.
- Analytics. This website does not run any analytics or tracking script.
- Fonts. The website's fonts are served from our own hosting, not from Google's servers, so visiting the site does not send your information to Google by this route. Until 15 August 2026 it did load them from Google on every page, which sent your IP address to Google before you had agreed to anything; we removed it ourselves rather than wait to be asked.
- The link to TikTok. The footer links to a TikTok profile. That link takes you to a third party's website, which has its own privacy practices and its own tracking, entirely outside our control. Check TikTok's own privacy policy if that concerns you.
- One form. “Get launch news” asks for a first name and an email address, so we can write to you once — on the day the app is released. It is entirely optional and nothing else on the site depends on it. There is no other form: no contact form, no newsletter, no account.
- What we do with it: that one announcement, and nothing else. We do not sell or share the list, and we send nothing in the meantime.
- Who holds it: the form is handled by Formspree (Formspree Inc.), which stores the submissions for us and tells us when one arrives. Formspree is based in the United States, so an address given here does leave the EU — see Section 13. It is the only route by which anything you give Health Path goes abroad; the app itself still sends nothing anywhere (Section 4).
- Getting off the list: write to support@healthpathapp.com and we delete you from it. The launch email will carry an unsubscribe link.
- Why we're allowed to: your consent (Art. 6(1)(a) GDPR), given by submitting the form, and withdrawing it is as easy as giving it was.
One thing here is still being settled. The form went live on 15 August 2026 and addresses given to it are stored from that date. What is not yet named on this page is the specific safeguard we rely on to send your address to the United States, and our processing agreement with Formspree; both are being put in place, and this note will say so plainly until they are. If you'd rather not give an address while this line is still here, write to support@healthpathapp.com instead and we'll note you by hand.
12. Third parties: Google Play
Health Path is not yet available on Google Play. Once it is published there, Google, as the store operator, will collect its own information as part of running that store — for example your Google account details, payment details if you ever buy anything through Google Play, and device and app information Google collects for its own store operations.
This is Google's own collection, under Google's own privacy policy — we don't control it, and we don't receive any of it. If you want to know what Google Play itself collects about you as a user of the store, Google's own privacy policy is the right place to check, not this document.
Beyond the Google Play store relationship itself, Health Path uses no other third-party service or component of any kind. There is no analytics company, no advertising network, no crash-reporting vendor and no cloud provider in the picture, because there is no data flow for any of them to sit on.
13. International data transfers
From the app: none. Your data doesn't leave your device, so the question of transferring it to another country — inside or outside the EU and EEA — doesn't arise. Android's own backup was the one route by which your entries could have reached a server abroad, and Section 7 explains why the app switches it off.
From the website: one, and only if you choose it. If you give us your name and email on the “Get launch news” form (Section 11), those two pieces of information are stored by Formspree Inc. in the United States. Nothing else you do on the website or in the app is transferred anywhere. If you would rather your address did not leave the EU, don't use the form — write to support@healthpathapp.com instead and we will note you by hand.
The safeguard for this transfer is not named here yet. The form has been live since 15 August 2026 (Section 11), so addresses given to it are stored in the United States from that date; the legal mechanism we rely on for that will be named here as soon as it is settled. Until then, not using the form is the way to keep your address inside the EU.
14. Changes to this policy
If we make a meaningful change to this policy — for example adding a feature that changes what data is collected, or building the export mentioned in Section 9 — we will update this document and the effective date at the top. For any change that meaningfully affects what we do with your data, we'll also let you know inside the app itself, not just by quietly editing a web page.
15. Looking ahead: if Health Path ever moves online
None of this section applies today. It is here so that if the app ever changes shape, this policy already has the right skeleton to be filled in and republished, rather than being written from scratch under time pressure.
Everything above describes Health Path as it exists today: fully local, no server, no account beyond your own device. If that ever changes — an online-synced account, a paid subscription requiring payment processing, or a server-based feature — this section will need to cover, at minimum:
- The identity of any new company involved in handling the data, such as a cloud hosting provider, what they do with it, and where their servers are.
- Whether any data then leaves the EU or EEA, and if so what legal safeguard applies to that transfer.
- How account data would be secured in transit and stored on a server, replacing the "there is no server" position in Section 10.
- A real breach-notification process, since "there is no server to hack" would no longer be true.
- How payment data would be handled if a paid tier goes live, including which payment processor is used and what they, rather than we, would hold.
- Updated answers for Access and Portability, since those rights would then need to be honoured against a real central copy rather than being automatically satisfied by on-device storage.