Privacy Policy
SleepsCore ("the app") is a personal health-data dashboard built and operated by a single individual (Joel Sweet, "the developer") for the developer's own personal use. This policy explains what data the app accesses, how it's used, and how it's stored.
1. Who this app is for
SleepsCore is a single-user application. It was built for the developer's personal use only, is not offered publicly, has no account sign-up, and is not intended for use by anyone other than the developer.
2. Information we access
With your explicit consent through Google's OAuth sign-in flow, the app requests read-only access to the following Google Health Connect data types:
googlehealth.activity_and_fitness.readonly— steps and active-zone-minutes.googlehealth.sleep.readonly— sleep session timing, duration, stages, and efficiency.googlehealth.health_metrics_and_measurements.readonly— resting heart rate and heart rate variability.
The app only ever reads this data — it never writes to, modifies, or deletes any data in your Google Health Connect account.
3. How this information is used
The data is used exclusively to power the app's own dashboard: daily and rolling-average views, a custom sleep-quality score, streak/record tracking, and an activity-load (ACWR) calculation. It is used only for the developer's personal health tracking and is not used for any other purpose.
4. Where this information is stored
- Historical data is stored as a static file within the app's own deployment on Cloudflare Pages.
- A small number of manual data-quality overrides (marking a specific night's data as unreliable) are stored in a Cloudflare KV namespace and in your browser's local storage.
- Your Google OAuth refresh token and client credentials are stored server-side as encrypted secrets in Cloudflare's infrastructure. They are never sent to, stored in, or accessible from the browser.
No data is stored on any third-party analytics, advertising, or tracking service. The app does not use cookies, analytics scripts, or any tracking technology.
5. Data sharing
Your data is never sold, rented, licensed, or shared with any third party. It is not used for advertising. It is not used to train any machine-learning or AI model. The only systems that ever see this data are Google's own APIs (as the source) and Cloudflare's infrastructure (as the host), both accessed only by the developer.
6. Data retention and deletion
Data is retained for as long as the app is in use. You (the account holder) can revoke the app's access to your Google account at any time at myaccount.google.com/permissions. To request deletion of any data already stored by the app, contact the developer using the details below.
7. Security
All communication with Google's APIs uses HTTPS. OAuth credentials are held only as server-side secrets and are never exposed to the client. The app's source code is not publicly distributed or offered for installation by others.
8. Children's privacy
This app is not directed at, and is not knowingly used by, children under 13.
9. Changes to this policy
If this policy changes, the "Last updated" date above will be revised accordingly.
10. Contact
Questions about this policy or your data can be sent to joel.sweet02@gmail.com.