Health Challenge — Privacy Policy
Last updated: 2026-08-27
Who we are
Health Challenge is a group habit-tracking app for running a health challenge
with a small group of people you already know. The data controller is the
operator of healthchallenge.app.
What we collect, and why
We collect only what the challenge needs to work.
| Data | Why | Where it lives |
|---|---|---|
| Name, email address, profile photo URL, sign-in provider | To identify you to the other participants in your challenge and to sign you in | users/{uid} |
| Time zone and preferred weight unit | So deadlines and weights are correct for you | users/{uid} |
| Daily habit entries (water, vegetables, exercise minutes, and whichever other habits your challenge scores) | They are what the challenge scores | challenges/{id}/dailyLogs |
| Weekly weigh-in weights | To score the weight-loss competition | challenges/{id}/weighIns |
| Your starting weight | The week-1 baseline the weight-loss score is measured against | challenges/{id}/members |
| Computed scores and earned badges | To show the leaderboards and your progress | challenges/{id}/scoreResults, challenges/{id}/achievements |
| Messages you send to another participant, and announcements an organizer posts | To deliver them to the person you sent them to | challenges/{id}/threads |
| People you have blocked, and reports you have filed | To stop unwanted messages and to act on abuse | challenges/{id}/blocks, reports |
| Push notification tokens and per-category preferences | To send the reminders you have not turned off | users/{uid}/notificationTokens, users/{uid}/notificationPrefs |
| When you last opened the app | So we don't send you a reminder about something you are already looking at | users/{uid}/engagement |
| Crash reports and basic usage events | To find and fix defects | Firebase Crashlytics, Firebase Analytics |
We do not collect your contacts, your location, your advertising identifier, or your browsing activity. We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.
Who can see your weight
This is the part most people care about, so it is stated plainly.
Your exact weights are visible only to you and to the organizer of your
challenge. They are stored in a separate, access-restricted collection
(weighIns), and the security rules permit reads only by you and by that
challenge's organizer.
Other participants never see a weight, a starting weight, or a percentage derived from one. What they see is your weight-loss points — a whole number capped at 30 per week — on the leaderboard, alongside your display name. Points cannot be reversed into a weight, because the same points arise from many different weights.
Push notifications never contain a weight or a score derived from one, so nothing sensitive appears on your lock screen.
Messages
Messages are between the people in the conversation. A one-to-one conversation is readable only by its two participants; announcements are readable by everyone in that challenge. We do not read your messages to profile you or to target anything at you.
Three things are worth knowing:
- A message notification shows only who sent it, never what it says — because a lock screen is visible to whoever picks up the phone.
- Messages are checked against a blocked-term filter before they are sent, and again on our servers. A message that trips it is refused or removed.
- A reported message is reviewed by us. Reports go to us, not to your organizer and not to the person you reported, and we act on them within 24 hours. See the community guidelines.
You can block anyone in your challenge at any time. Blocking is between the two of you: it is not announced to them.
Health app data (Apple Health / Health Connect)
This release does not connect to Apple Health or Health Connect. The app does not read from, or write to, either service, and does not request health permissions. Every habit and weigh-in value is entered by you in the app. If a future release adds an optional import, this policy will be updated before it ships.
Analytics and crash reporting
We record a small, fixed set of product events — a challenge was created or joined, a day was logged, a weigh-in happened, a badge was earned, a leaderboard tab was opened. These events carry no weights and no scores: they record that something happened, not what its value was. Events are associated with your Firebase user id, never with your email address or display name.
Crash reports are collected by Firebase Crashlytics to diagnose failures, and are disabled in development builds.
Where your data is processed
Health Challenge runs on Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Crashlytics, Analytics). Google processes this data on our behalf as a service provider. See Google's privacy documentation for their processing details.
How long we keep it
Your data is kept while your account exists. Deleting your account deletes it (see below). Challenge records belonging to other participants are theirs and are kept under their own accounts. Moderation reports are kept after deletion so we can act on repeat abuse.
Your rights
- Export. Account → Export my data returns everything we hold about you as JSON, including your weights.
- Deletion. Account → Delete my account permanently deletes your profile, your daily logs, your weigh-ins, your scores, your badges, your direct message conversations, your notification tokens and preferences, and your sign-in. This cannot be undone. If you organize a challenge, that challenge is cancelled rather than deleted, because it contains other participants' entries, which are not ours to destroy on your behalf. Those participants keep their own data and their own deletion right. If you have already uninstalled the app, see delete your account.
- Correction. You can edit your entries while the relevant week is open, and ask your organizer to reopen a closed week.
- Turning off notifications. Per-category toggles are in Notifications; changes take effect immediately.
Children
Health Challenge is not directed at children under 13 and we do not knowingly collect their data.
Not medical advice
Health Challenge is a tracking and encouragement tool. It is not a medical device, it does not provide medical advice, and it should not be used to diagnose or treat any condition. Talk to a qualified clinician before making significant changes to your diet or exercise.
Changes
If this policy changes materially we will update the date above and notify participants in the app.
Contact
Questions or requests: support@healthchallenge.app