Privacy Policy
Last Updated: March 3, 2026
#
Overview
RBD Guardian is a personal sleep monitoring application. This privacy policy explains how your data is handled.
#
Ownership and Control
This application is owned and operated by the developer. By using RBD Guardian, you acknowledge that:
- This is a personal project, not a commercial service
- The developer maintains full ownership and control of the application
- The developer may modify, suspend, or discontinue the service at any time without notice
#
Data Collection
RBD Guardian collects and stores:
- Account Information: Email address, full name, password (hashed)
- Biometric Data: Heart rate, blood oxygen saturation (SpO2), and accelerometer data from sleep sessions
- Sleep Data: Sleep stage information (awake, light, deep, REM) read from Health Connect
- Session Data: Sleep session timestamps, duration, and quality metrics
- RBD Events: User-reported movement events with optional notes and timestamps
- Device Information: Android device and WearOS watch sensor data
#
Health Connect Integration
The app reads the following data from Google Health Connect:
- Sleep sessions: Sleep stage data to correlate with biometric recordings
- Oxygen saturation (SpO2): Blood oxygen percentage readings recorded during sleep
We only request read access to these specific data types. We do not write data to Health Connect. You can revoke these permissions at any time through your device's Health Connect settings.
#
Data Usage
Your data is used solely for:
- Providing sleep monitoring functionality
- Displaying biometric charts and analysis
- Calculating sleep quality scores
- Enabling doctor-patient data sharing (if you grant permission)
We do NOT:
- Sell your data to third parties
- Use your data for advertising
- Share your data except as required by law
#
Data Security
We implement industry-standard security practices:
- Password encryption (bcrypt hashing)
- JWT authentication with secure tokens
- HTTPS/TLS encryption for data transmission
- Database access controls
- Audit logging for HIPAA-style compliance
HOWEVER:
This application is NOT HIPAA compliant.
Do not use this for clinical or diagnostic purposes.
This is a personal health tracking tool, not a medical device.
#
Data Retention
- Your data is stored indefinitely unless you request deletion
- You may request account deletion by contacting the developer
- Upon deletion, all associated data will be permanently removed within 30 days
#
Your Rights
You have the right to:
- Access your data at any time through the application
- Export your biometric data (via API or UI)
- Delete your account and all associated data
- Revoke doctor access to your data
- Revoke Health Connect permissions at any time
#
Third-Party Services
RBD Guardian does NOT use third-party analytics, advertising, or tracking services.
#
Children's Privacy
RBD Guardian is not intended for use by children under 18. We do not knowingly collect data from children.
#
Changes to This Policy
This privacy policy may be updated at any time. Continued use of the application constitutes acceptance of any changes.
#
Contact
For privacy-related questions or data deletion requests, contact the developer through the GitHub repository:
https://github.com/paulmarsolan/RBD_take2
#
Disclaimer
USE AT YOUR OWN RISK
This application is provided "as-is" without warranties of any kind. The developer is not liable for:
- Data loss or corruption
- Inaccurate biometric readings
- Security breaches
- Service interruptions
- Any medical or health-related decisions made using this data
This is not a medical device. Consult a healthcare professional for medical advice.