Health Challenge

Health Challenge — Privacy Policy

Last updated: 2026-08-27

Who we are

Health Challenge is a group habit-tracking app for running a health challenge with a small group of people you already know. The data controller is the operator of healthchallenge.app.

What we collect, and why

We collect only what the challenge needs to work.

Data Why Where it lives
Name, email address, profile photo URL, sign-in provider To identify you to the other participants in your challenge and to sign you in users/{uid}
Time zone and preferred weight unit So deadlines and weights are correct for you users/{uid}
Daily habit entries (water, vegetables, exercise minutes, and whichever other habits your challenge scores) They are what the challenge scores challenges/{id}/dailyLogs
Weekly weigh-in weights To score the weight-loss competition challenges/{id}/weighIns
Your starting weight The week-1 baseline the weight-loss score is measured against challenges/{id}/members
Computed scores and earned badges To show the leaderboards and your progress challenges/{id}/scoreResults, challenges/{id}/achievements
Messages you send to another participant, and announcements an organizer posts To deliver them to the person you sent them to challenges/{id}/threads
People you have blocked, and reports you have filed To stop unwanted messages and to act on abuse challenges/{id}/blocks, reports
Push notification tokens and per-category preferences To send the reminders you have not turned off users/{uid}/notificationTokens, users/{uid}/notificationPrefs
When you last opened the app So we don't send you a reminder about something you are already looking at users/{uid}/engagement
Crash reports and basic usage events To find and fix defects Firebase Crashlytics, Firebase Analytics

We do not collect your contacts, your location, your advertising identifier, or your browsing activity. We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.

Who can see your weight

This is the part most people care about, so it is stated plainly.

Your exact weights are visible only to you and to the organizer of your challenge. They are stored in a separate, access-restricted collection (weighIns), and the security rules permit reads only by you and by that challenge's organizer.

Other participants never see a weight, a starting weight, or a percentage derived from one. What they see is your weight-loss points — a whole number capped at 30 per week — on the leaderboard, alongside your display name. Points cannot be reversed into a weight, because the same points arise from many different weights.

Push notifications never contain a weight or a score derived from one, so nothing sensitive appears on your lock screen.

Messages

Messages are between the people in the conversation. A one-to-one conversation is readable only by its two participants; announcements are readable by everyone in that challenge. We do not read your messages to profile you or to target anything at you.

Three things are worth knowing:

You can block anyone in your challenge at any time. Blocking is between the two of you: it is not announced to them.

Health app data (Apple Health / Health Connect)

This release does not connect to Apple Health or Health Connect. The app does not read from, or write to, either service, and does not request health permissions. Every habit and weigh-in value is entered by you in the app. If a future release adds an optional import, this policy will be updated before it ships.

Analytics and crash reporting

We record a small, fixed set of product events — a challenge was created or joined, a day was logged, a weigh-in happened, a badge was earned, a leaderboard tab was opened. These events carry no weights and no scores: they record that something happened, not what its value was. Events are associated with your Firebase user id, never with your email address or display name.

Crash reports are collected by Firebase Crashlytics to diagnose failures, and are disabled in development builds.

Where your data is processed

Health Challenge runs on Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Crashlytics, Analytics). Google processes this data on our behalf as a service provider. See Google's privacy documentation for their processing details.

How long we keep it

Your data is kept while your account exists. Deleting your account deletes it (see below). Challenge records belonging to other participants are theirs and are kept under their own accounts. Moderation reports are kept after deletion so we can act on repeat abuse.

Your rights

Children

Health Challenge is not directed at children under 13 and we do not knowingly collect their data.

Not medical advice

Health Challenge is a tracking and encouragement tool. It is not a medical device, it does not provide medical advice, and it should not be used to diagnose or treat any condition. Talk to a qualified clinician before making significant changes to your diet or exercise.

Changes

If this policy changes materially we will update the date above and notify participants in the app.

Contact

Questions or requests: support@healthchallenge.app