Privacy Policy for BPM Lab
1. Overview
This Privacy Policy explains what information the BPM Lab mobile application (the "App") processes, how it is used, and the choices and rights you have. Batvinnikau Yauheni ("we", "us", "our") acts as the data controller for the purposes described below.
The App helps you measure and track heart-rate and general wellness information for informational and educational purposes only — it is not a medical device and does not provide medical diagnosis (see our Terms of Use). The core processing of your health and profile data takes place locally on your device; we do not operate user accounts, and your measurement history is not uploaded to us. The only feature that transmits content off your device is the optional AI assistant (see Section 2.4). The App is supported by advertising (see Section 6); it does not offer paid subscriptions or in-app purchases.
By using the App, you acknowledge the practices described in this Privacy Policy. Where required by law, we rely on your consent, which you may withdraw at any time (see Sections 6 and 13). This Privacy Policy is intended to be consistent with the information disclosed in the App's Google Play Data safety section.
2. Data We May Process
2.1 Health and wellness data
The App may process health- or wellness-related information, including:
- Heart rate, estimated using your device camera and photoplethysmography (PPG);
- Heart rate variability (HRV) metrics, including, where available, SDNN, RMSSD, pNN50 and similar derived values;
- Calculated wellness indicators, including stress level, energy level, health index and heart age, and similar App-generated estimates;
- Manually entered values, including blood pressure, blood oxygen (SpO₂), blood glucose, weight/BMI, water intake and other values you choose to log;
- Step / activity counts, where you enable step tracking.
To measure heart rate and HRV, the App uses your device camera as a light sensor (PPG). All image frames and signal data captured during a measurement are processed locally on your device and are discarded immediately afterward. The App does not take photographs, does not record video, and does not access your photo gallery for measurement.
Unless the App expressly states otherwise, blood pressure, SpO₂, glucose and similar values are records you enter manually.
2.2 Profile data entered by the user
You may voluntarily provide profile information used to personalise results and to support local calculations (for example, Heart Age), including:
- sex / gender and age (which you may provide during onboarding),
- name, height and weight.
You can view, edit or clear this information in the App at any time.
2.3 Technical and usage data
To keep the App working, secure, and to support advertising and analytics, we or our service providers may process:
- device and network information (device model, operating system version, language, time zone, mobile network/carrier, IP address);
- advertising identifier (e.g. Google Advertising ID / GAID) and similar identifiers;
- app diagnostics, crash reports, and general usage/interaction data (features used, sessions).
We do not need a server-side account for the App's core functionality; your health and profile records are stored locally (see Section 5).
2.4 AI assistant (AI chat)
The App includes an optional AI assistant feature. Using it is your choice, and it is the only feature of the App that sends content off your device.
How your message travels. When you choose to send a message to the AI assistant:
- the text of your message, and any image you attach, are transmitted to our own server (
heart--app.com), operated by Batvinnikau Yauheni; - our server forwards the content to a third-party AI service provider to generate a response;
- the response is returned to the App.
Transmission is protected with encryption in transit (HTTPS/TLS).
What is not sent. Your stored health measurements, your measurement history and your profile data are not attached to the message and are not sent automatically. Only what you type or attach yourself is sent, and only at the moment you send it.
Please note that anything you type into the chat is transmitted exactly as you wrote it. Do not enter information you consider sensitive or that could identify you — including health details you would not want to leave your device.
You can stop using the AI assistant at any time, and you withdraw your consent to this processing simply by not using the feature. Messages are additionally processed by the AI provider under its own terms and privacy policy.
3. Device Permissions
The App may request the following Android permissions, each used only for the stated purpose:
- Camera — to estimate heart rate via PPG. The camera is accessed only in the foreground during an active measurement, never in the background; frames are processed locally and discarded immediately. No photos or videos are taken, stored, or shared, and the App does not access your photo gallery.
- Notifications (POST_NOTIFICATIONS) — to deliver reminders and wellness notifications you enable. Notifications are scheduled locally on your device.
- Physical activity / activity recognition — to count steps, where you enable step tracking.
Where you enable continuous step counting, the App runs a foreground service so that Android does not stop the count in the background. Android requires such a service to display a persistent notification; that notification is how you can tell the feature is active, and you can switch the feature off in the App at any time. The service counts steps only — it does not access the camera, your location, or any other sensor.
You can grant or revoke these permissions at any time in your device settings.
4. How We Use Data
We use the data described above to:
- provide the App's core functionality (take measurements, calculate results, store your history locally);
- personalise results and calculations (for example, using age/sex for Heart Age);
- deliver reminders and notifications you enable;
- display and measure advertising (see Section 6);
- understand performance, diagnose crashes and improve the App (see Section 7);
- provide user support and comply with legal obligations.
Results are estimates for informational purposes and are not medical diagnoses.
5. Where Data Is Processed and Stored
- Health and profile data — all measurements, manually logged values and your profile — are stored locally on your device. They are not uploaded to our servers, and they are not attached to AI-chat messages, advertising requests or analytics events. They remain on your device until you delete individual records, clear the App's data, or uninstall the App.
- AI-chat content (the text and any image you send) is transmitted to our server (
heart--app.com) and onward to our AI provider, as described in Section 2.4. - Technical and usage data, and advertising data, are processed by our service providers (advertising, analytics, crash reporting) as described in Sections 6 and 7.
- Data handled by our server and by our providers may be processed outside your country (see Section 12).
6. Advertising
The App is supported by advertising and is shown to all users (there is no paid ad-free option). To serve ads, we work with third-party advertising and mediation partners.
- Data used for advertising: advertising identifier (e.g. GAID), IP address, device and usage information, and interactions with ads. Our advertising partners may collect this information through their SDKs to serve and measure ads, including, where permitted, personalised (interest-based) advertising.
- Advertising partners: AppLovin MAX (mediation), and through it Google AdMob, Pangle (ByteDance), Mintegral and Vungle (Liftoff). Each partner processes data under its own privacy policy.
- Your health and profile data are never used for advertising and are never shared with advertising partners.
- Rewarded ads: some optional features can be unlocked by voluntarily watching a rewarded ad. Watching is your choice; declining does not remove core functionality.
Your advertising choices:
- You can reset or delete your advertising identifier, or opt out of ad personalisation, in your Android device settings (Settings → Google → Ads → "Opt out of Ads Personalisation" / "Delete advertising ID").
- Consent (EEA/UK): where required, we (and our mediation partner) present a consent request before serving personalised ads, and you may change or withdraw your choice at any time. Where you decline, you may still see non-personalised ads.
- US state privacy laws: see Section 13.2 for how to exercise "Do Not Sell or Share My Personal Information" choices.
7. Analytics and Diagnostics
We use the following tools, all provided by Google:
- Firebase Analytics — product analytics: which features are used, session and engagement data. Analytics data is exported to Google BigQuery for our own reporting.
- Firebase Crashlytics — crash and stability diagnostics, so that we can find and fix errors.
- Firebase Remote Config — remote configuration of App behaviour (for example, advertising settings). It delivers configuration values to the App; it does not collect your content.
These tools process usage and device information and identifiers under Google's privacy policy. Your health measurements and profile data are never sent to these tools — neither as event values, nor as event or parameter names. Where an event needs to identify a device, it uses a pseudonymous installation identifier, not your name, email address or any health value.
8. Sharing With Third Parties
We do not sell your personal information for money. We may share limited data as follows:
| Category | Purpose |
|---|---|
| Advertising & mediation partners (AppLovin MAX; Google AdMob, Pangle, Mintegral, Vungle) | Serve and measure ads (device/ad identifiers, IP, ad interactions) — not health/profile data |
| Google — Firebase Analytics, Crashlytics, Remote Config; BigQuery | Product analytics, crash diagnostics, remote configuration |
Our own server (heart--app.com, operated by Batvinnikau Yauheni) | Receive and relay AI-assistant messages (your message text and any attached image) |
| Third-party AI service provider | Generate responses in the AI assistant |
| Google Play services | App distribution, integrity, and platform functionality |
| Legal / safety recipients | Where required by law, court order, or to protect rights, safety and service integrity |
Note: depending on your jurisdiction, the use of personalised advertising identifiers may be treated as a "sale" or "sharing" of personal information. We provide the opt-out and consent mechanisms described in Sections 6 and 13. Health and profile data are excluded from advertising sharing in all cases.
9. Data Retention
- Health and profile data stored locally are retained until you delete them, clear the App's data, or uninstall the App.
- Technical, advertising and analytics data are retained by us and our providers only as long as necessary for the purposes described here or as required by law, after which they are deleted or anonymised.
- AI-chat messages pass through our server. We retain them only for as long as needed to deliver the response and to keep the service working and secure, after which they are deleted or anonymised. They are additionally retained by the AI provider according to its own policies.
10. Security
We use reasonable technical and organisational measures to protect information:
- data transmitted to our server and to our service providers is protected using encryption in transit (HTTPS/TLS);
- your health and profile records stay on your device and are not uploaded, which removes the largest category of transfer risk;
- the App's local data is excluded from Android system backups, so it is not copied into cloud backups or extracted through a USB backup;
- access to our server is restricted and monitored.
No method of transmission or storage is completely secure, and security also depends on the safeguards and settings of your own device. In particular, records stored locally may be accessible if your device is lost or stolen while unlocked, or if it has been modified (for example, rooted). We recommend protecting your device with a screen lock.
11. Your Controls and Choices
You can:
- delete individual records or clear all App data within the App;
- edit or remove profile data (name, sex/gender, age, height, weight);
- manage or revoke device permissions (camera, notifications, activity) in device settings;
- manage advertising choices and consent (Section 6);
- uninstall the App to remove locally stored data.
How to delete your data. The App does not require an account, and your health and profile records are stored only on your device. You can delete them at any time by (1) deleting individual records in the App, (2) clearing the App's data in Android Settings → Apps → BPM Lab → Storage → Clear data, or (3) uninstalling the App, which removes all locally stored data. To request deletion of any limited data held by our service providers (for example, advertising, analytics, or AI-chat data associated with your identifiers), contact us at batvinnikauyauheni@gmail.com and we will action your request as required by applicable law.
Step-by-step instructions, and the exact format for a deletion request by email, are on our Data & Account Deletion page.
To exercise the statutory rights described in Section 13, contact us at batvinnikauyauheni@gmail.com.
12. International Data Transfers
Because core health and profile data stay on your device, we do not perform operator-controlled international transfers of that data.
However, our advertising, analytics and AI providers, and the server that handles AI-assistant messages, may process technical/usage data and AI-chat content in countries other than yours, including outside the EEA/UK. Where required, such transfers rely on appropriate safeguards (for example, Standard Contractual Clauses).
13. Regional Privacy Rights
13.1 European Economic Area (EEA) and United Kingdom (GDPR / UK GDPR)
We process personal data on the following legal bases: your consent (in particular for personalised advertising and any processing of health-related data), performance of a contract, legitimate interests (App improvement, security, non-personalised advertising), and legal obligations.
You have the rights to access, rectify, erase, restrict, and port your data, to object to processing, and to withdraw consent at any time. Data stored locally can be controlled directly in the App. You may lodge a complaint with your local supervisory authority; in the UK, the Information Commissioner's Office (ico.org.uk).
13.2 United States — California (CCPA/CPRA) and other state laws
You have the right to know, access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising, and to non-discrimination. We do not sell your data for money and we never sell or share health or profile data for advertising. To opt out of personalised advertising, use the device-level controls in Section 6 or contact us at batvinnikauyauheni@gmail.com ("Do Not Sell or Share My Personal Information"). Similar rights apply under other US state privacy laws.
13.3 Brazil (LGPD)
You may access, correct, anonymise, delete and port personal data, and obtain information about sharing. Locally stored data can be controlled within the App.
13.4 Japan (APPI)
Health-related information is treated as "special care-required personal information" and is processed locally with your consent. You may request disclosure, correction, or deletion.
13.5 China (PIPL)
Heart-rate and related data are processed locally without transfer to our servers. The App requests your consent before processing camera-based biometric measurements. You may request access, correction, or deletion.
13.6 Russia (Federal Law No. 152-FZ)
Health measurement data is stored locally on your device without external transfer. Note that if you choose to use the AI assistant, the content you type is transmitted as described in Section 2.4. You may request access, correction, or deletion.
13.7 Singapore (PDPA) and other jurisdictions
Where applicable local law grants additional rights, we honour them. Contact us at batvinnikauyauheni@gmail.com to make a request.
14. Children's Privacy
The App is not directed to children under 13 (or the higher minimum age required in your jurisdiction, such as 16 in parts of the EEA). We do not knowingly collect personal information from children under that age. If we learn that we have inadvertently done so, we will delete it. Parents or guardians who believe a child has provided personal information should contact us at batvinnikauyauheni@gmail.com.
15. Changes to This Privacy Policy
We may update this Privacy Policy when the App's functionality, our data practices, third-party services, or legal requirements change. We will update the "Last Updated" date and, where appropriate, provide additional notice. Your continued use of the App after an update constitutes acceptance where permitted by applicable law.
16. Contact Us
Service Operator: Batvinnikau Yauheni
Support Email: batvinnikauyauheni@gmail.com