Privacy policy
1. Overview
Recovery Coach ("the app") is a single-user personal application operated by an individual ("the owner") for personal use. It reads the owner's own health and activity data and renders a private training and recovery dashboard. There is exactly one user. The app is not offered to the public, and no third party can create an account or submit data.
2. Data the app reads
With the owner's explicit OAuth consent, the app reads the owner's own data from the Google Health API, using the minimum read-only scopes required:
googlehealth.activity_and_fitness.readonly— exercise sessions, steps, distance, active-zone minutes and time-in-heart-rate-zone, used to enrich logged training sessions (average heart rate, percentage of time in Zone 2, pace).googlehealth.health_metrics_and_measurements.readonly— resting heart rate, HRV and related measurements, used for daily recovery metrics.googlehealth.sleep.readonly— sleep sessions and stages, used for recovery trends.googlehealth.profile.readonly— account identity, used once to confirm account linkage.
The app also stores training entries the owner logs manually (session type, duration, perceived effort, fueling and notes).
3. How data is used
- Displaying the owner's own training and recovery dashboard.
- Enriching manually logged sessions with matching device data (by date and session type).
- Nightly synchronization and change-triggered updates, so the dashboard stays current.
Data is used for no other purpose. There is no advertising, no analytics profiling, no sale of data, and no sharing with any third party.
4. Storage and security
- Data is stored in a private Google Cloud Firestore database (asia-east2, Hong Kong), encrypted at rest.
- Firestore denies all direct client access; data is reachable only through the app's own authenticated server.
- OAuth credentials are held in Google Cloud Secret Manager, never in source code.
5. Sharing
The app does not share, sell, rent or disclose personal data to anyone. Data never leaves the owner's private Google Cloud project except to be displayed back to the owner.
6. Google API Services User Data Policy
The app's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Retention and deletion
Data is retained while the app is in use by the owner. The owner may request complete deletion of all stored data at any time by emailing hello@contemporary.hk; deletion is carried out within 30 days.
8. Changes to this policy
Any changes to this policy will be published on this page with an updated effective date.
9. Contact
For any question about this policy or the app's data handling: hello@contemporary.hk.