Privacy Policy
Effective date: 12 July 2026
01 Data we access
With your explicit consent via Google sign-in, Apex Trace requests read-only access to your Google Health data:
- activity & fitness (steps, calories, active-zone minutes, workouts, heart rate),
- sleep (sessions, stages, and attached SpO₂, heart-rate variability, and skin-temperature values),
- health metrics & measurements (e.g., resting heart rate, breathing rate),
- nutrition (food/calorie intake you've logged, and the sodium, sugar, and saturated-fat values in it) — shown so you can track intake against your calorie budget,
- your Google profile display name (via the standard
openidandprofilesign-in scopes), shown in the app's profile header so you can see who is signed in. We read the name from the sign-in token on your device; we do not request your email, fetch your profile photo, or send your name anywhere. It is stored only on your device and deleted when you disconnect.
Apex Trace never asks for write access and cannot modify your health data.
02 How your data is used
Your data is used solely to provide the app's visible features to you: rendering dashboards, charts, and trends, and computing scores and coaching insights. All processing — including every insight and recommendation — happens on your device. Nothing is sent to any server operated by us, and there are no advertising or behavioral-analytics SDKs in the app. The one optional exception is crash reporting, described in section 6 — it is off by default and never contains your health data.
Some insight and coach summaries are written by your phone's built-in, on-device AI (Apple Intelligence on iPhone, Gemini Nano on supported Android devices). This text is generated entirely on your device — your health data is never sent to any AI service, cloud model, or server to produce it, and is never used to train any model. You can turn these AI summaries off in the You tab; when on-device AI isn't available, the app simply hides those cards. Any reminders or alerts the app sends are local notifications generated on your device — there is no push server involved.
03 Body Age estimation (optional body measurements)
Apex Trace includes an optional Body Age feature that estimates your physiological age relative to your chronological age, based on cardio fitness. To use it, you can enter your date of birth, biological sex, height, and weight in the app, and optionally your waist circumference (which improves accuracy).
- This information is stored only on your device — it is never transmitted to us, to Google, or anywhere else.
- It is used solely to compute the on-device Body Age estimate. All calculation happens locally on your phone; your measurements never leave it.
- The Body Age feature is entirely optional. The rest of the app works without it.
- Disconnect (in the You tab) deletes these measurements from your device along with all other personal data.
04 Where your data lives
- Retrieved health data is cached in a private, app-sandboxed database on your device so the app works offline.
- Sign-in tokens are stored in your device's secure storage (iOS Keychain / Android encrypted storage).
- Apart from optional crash reports (section 6), the only network traffic the app generates is between your device and Google (sign-in and the Google Health API), always over encrypted connections (TLS 1.2+). The optional diagnostic export described in section 5 travels only where you send it via the system share sheet: the app never initiates a network connection to deliver it.
05 How we protect your data
Apex Trace handles sensitive health data, and the app is built around the following protection mechanisms:
- Encryption in transit. Every network connection the app makes uses HTTPS with TLS 1.2 or higher. The app contains no plaintext-HTTP endpoints, and its network layer is restricted to a fixed allowlist of hosts: Google sign-in, the Google Health API, and — only when you opt in — the crash-reporting endpoint described in section 6. It cannot send data anywhere else.
- Encryption at rest. Sign-in tokens are stored in hardware-backed OS secure storage (iOS Keychain with a device-only protection class / Android EncryptedSharedPreferences), where the operating system encrypts them with hardware-protected keys. Cached health data is stored in the app's private sandbox, protected by the platform's storage encryption (iOS Data Protection / Android file-based encryption) and inaccessible to other apps.
- Access control. Sign-in uses the industry-standard OAuth 2.0 Authorization Code flow with PKCE. The app requests read-only scopes, so it can never modify your Google Health data. Access tokens are short-lived and sent only in encrypted request headers, never in URLs; the refresh token is revoked at Google when you disconnect. Because the app has no backend, no human — including the developer — can access your data.
- Backups and logs. Sign-in tokens and the health-data cache are excluded from device backups. Tokens are redacted from all application logs; health data is never written to logs in release builds and never appears in crash reports (section 6).
- Secure development. Every release passes automated static security analysis (SAST) and dependency-vulnerability scanning in our build pipeline, plus a static security scan of the release binaries. As an app accessing sensitive Google API scopes, Apex Trace additionally undergoes the independent CASA (Cloud Application Security Assessment) security review required by Google. We maintain a vulnerability-disclosure process and a documented incident-response plan; you can report suspected vulnerabilities to the contact in section 13.
- Diagnostic export (optional, user-initiated). A hidden support tool lets you create an encrypted snapshot of selected health data to send to Apex Trace support when diagnosing a problem. It is only accessible after deliberately tapping the app version label five times and accepting two explicit warnings. You choose which data categories to include; sign-in credentials and your Google identity are never included. The file is encrypted on your device using a key that only Apex Trace support can decrypt. The app writes only the encrypted file and hands it to the system share sheet: it makes no network connection to deliver it; you decide where to send it. The temporary file is deleted immediately after the share sheet returns (including if you cancel).
06 Optional crash reporting
To help us fix bugs, you can turn on "Share crash reports" in the app's You tab. This is off by default.
- When enabled, technical reports about app errors are sent to Sentry (Functional Software, Inc.), a crash-reporting service acting as our processor.
- A report contains only diagnostics: the type of error, a technical stack trace, the app version, and your device model and OS version, keyed to a random identifier that is not connected to your Google account.
- Reports never contain your health data, your sign-in tokens, your name or Google identity, screenshots, or the content of any request to Google. The reporting tool's automatic capture of such material is disabled in our configuration.
- You can turn the toggle off at any time to stop all future reports. Sentry retains received reports for a limited period (around 90 days) and then deletes them. Disconnecting your Google account also resets the random identifier.
07 In-app purchases (unlocking data sync; optional Supporter subscription)
Apex Trace is free and fully usable on built-in sample data. Connecting and syncing your real Google Health data is unlocked by a single one-time in-app purchase.
- The purchase is processed entirely by the app store — Apple (App Store) or Google (Google Play) — acting as the seller and payment processor. We never see or store your payment details.
- To handle the purchase, the store processes a purchase identifier for billing and restore purposes; this identifier is not linked to your health data or your Google account inside the app.
- The app keeps only a simple on-device "unlocked" flag so it remembers you paid; it re-checks this with the store when it launches. We run no server and do no server-side receipt validation.
- Your purchase identifier and product information are never written to our logs and never included in a crash report (section 6).
- Because the unlock is tied to your purchase (not to your Google account), disconnecting Google Health does not revoke it — you won't be charged again.
You can also optionally support development with an auto-renewing monthly Supporter subscription (you choose one of a few fixed price tiers). It is entirely optional — the app stays free and fully usable without it — and it grants only cosmetic extras (a "Supporter" badge by your name and a few chart color palettes).
- Like the unlock above, the subscription is sold and processed entirely by the app store (Apple or Google) as the seller and payment processor; we never see or store your payment details.
- The store processes a purchase/subscription identifier for billing, renewal, and restore purposes; this identifier is not linked to your health data or your Google account inside the app.
- The app keeps only an on-device "Supporter active" flag (with the time it was last confirmed) so it knows whether to show the cosmetic extras; it re-checks this with the store. We run no server and do no server-side receipt or subscription validation.
- Your subscription identifier and product information are never written to our logs and never included in a crash report (section 6).
- The subscription auto-renews monthly until you cancel. You manage or cancel it at any time through your App Store / Google Play subscription settings (also linked from the app); we cannot start, change, or cancel it for you. If it lapses, the cosmetic extras simply turn off.
08 Sharing and selling
We do not sell, share, transfer, or disclose your health data to anyone. We technically cannot: the app has no backend and your health data never reaches us. The only data that ever leaves your device for a non-Google destination is the optional, health-data-free crash report described in section 6 and, only when you explicitly create and send one, the encrypted diagnostic export described in section 5, which only Apex Trace support can decrypt. The in-app purchase and the optional Supporter subscription (section 7) are handled by the app store and carry no health data.
09 Limited Use disclosure
Apex Trace's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide user-facing features of the app; it is never used for advertising, never sold, never used to train AI models, and no humans (including the developer) can read it.
10 Data retention & deletion
- The app keeps a rolling cache (up to ~90 days) of your data on-device.
- Disconnect (in the app's You tab) revokes the app's access with Google and deletes all cached health data and tokens from your device.
- Uninstalling the app deletes all app data.
- You can revoke Apex Trace's access at any time at myaccount.google.com/permissions; the app then loses all access and clears its local data on next launch.
- Because we store nothing server-side, there is no additional copy for us to delete.
11 Children
Apex Trace is not directed at children under 16 and should not be used with a child's Google account.
12 What Apex Trace is not
Apex Trace displays estimates for general wellness purposes. It is not a medical device and provides no medical advice or diagnosis.
13 Changes & contact
We'll update this policy here and note material changes in release notes. Questions or requests: support@apextrace.app.