← ghealth

Privacy Policy

Last updated: 27 August 2026

ghealth is single-user personal software. The person who operates it is its only user, and their health data is stored only on the computer or server they run it on. It is not a service offered to the public, it has no user accounts beyond its operator, and it does not transmit health data to the developer or to any third party.

1. Who this covers

This policy describes how a ghealth installation handles data. Each installation serves exactly one person: its operator, signing in with a password they set themselves.

2. What data ghealth accesses

With explicit consent through Google's OAuth screen, ghealth requests read-only access to these Google Health scopes:

ghealth never requests write, update, or delete permissions and cannot modify or remove anything in a Google Health account.

3. How the data is used

Retrieved data is used for one purpose: to display, summarize, and let the operator query their own health history. It is not analyzed for any other purpose, not used to train models, not used to build profiles, and not used for advertising.

4. Where the data is stored

In a SQLite database file on the machine the operator runs ghealth on — their own computer, or a server they control. OAuth tokens are stored beside it with restricted file permissions. When ghealth is reachable over the network, every page and API endpoint that exposes health data requires the operator's password or an access token; connections are made over HTTPS.

5. Who the data is shared with

No one. ghealth makes network requests only to Google's own authentication and Health API endpoints in order to fetch the operator's data. It contains no analytics, no telemetry, no crash reporting, and no third-party services. The developer of ghealth has no access to any installation's data.

6. Google API Services User Data Policy

ghealth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Retention and deletion

Data is kept until the operator deletes it, which they do by deleting the application's data directory or volume. Google access can be revoked at any time at myaccount.google.com/permissions, which immediately stops any further retrieval.

8. Children

ghealth is not directed at children under 13 and is not intended for their use.

9. Changes

If this policy changes, the revised version is posted on this page with an updated date.

10. Contact

Questions about this policy can be raised via github.com/benpursley.

ghealth is not affiliated with, endorsed by, or a product of Google LLC or Fitbit LLC.