Privacy Policy
The short version. GlanceVitals reads the Apple Health metrics you choose, read-only, and processes them entirely on your iPhone or iPad. Your health data is never transmitted, never stored on a server, and never logged. There is no account, no advertising, and no tracking across apps or websites. The app and this website do use Google Analytics to count anonymous feature usage and page views — never your health data, which is covered in section 5. The one piece of personal data we ever hold is an email address, and only if you choose to type it into the launch waitlist form on this website — see section 7.
1. Who this policy is from
GlanceVitals is developed and published by Sufiyan Yasa, an individual developer ("we", "us"). This policy explains what the GlanceVitals iOS app and its widget extension do with data. If you have a question about anything here, email me@sufiyanyasa.com.
2. Health data
GlanceVitals requests read-only access to Apple Health, and only to the specific metrics you select. It cannot write to Apple Health, and it never attempts to.
- Health data read from Apple Health is used solely to render your widgets and the in-app dashboard and trends.
- All processing happens on your device. Health values are never sent to us, to any server, or to any third party.
- Health values are never written to application logs or crash diagnostics.
- GlanceVitals does not request access to Clinical Health Records.
- You can review or revoke access at any time in the Health app, under Sharing → Apps, or in iOS Settings → Privacy & Security → Health.
Because health data never leaves your device, the App Store privacy label and the app's privacy manifest declare no collection of Health & Fitness data. That is accurate, and it is enforced by how the app is built rather than by promise alone.
3. What is stored on your device
GlanceVitals saves your settings and your widget configurations in a shared app container on your device, so that the app and its widgets can read the same values. This includes things like your onboarding progress, chosen theme and accent colour, haptics preference, pinned metric, your saved widget layouts, and a local record of whether Pro is unlocked. It also caches the most recent values needed to draw your widgets.
This data stays on the device. It is not backed up to any server we operate. Deleting GlanceVitals removes it.
4. Purchases
GlanceVitals Pro is sold through Apple's App Store. Payment is handled entirely by Apple; we never see or receive your payment card details, billing address, or Apple ID credentials.
We use RevenueCat to validate purchases and determine whether Pro is unlocked. When you buy or restore a purchase, RevenueCat receives the App Store transaction data needed to do that — in App Store privacy-label terms, purchase history, used only for app functionality.
- This is not linked to your identity. GlanceVitals uses RevenueCat's anonymous identifiers and never signs you in or associates a purchase with a name, email address or account.
- It is not used for tracking and not shared with data brokers or advertisers.
- No health data is ever included. RevenueCat receives purchase and device information only, and never anything read from Apple Health.
5. Usage analytics
GlanceVitals includes Google's Firebase Analytics, and this website uses the same Google Analytics 4 property. We use it to answer product questions we otherwise cannot: how many people finish setup, which widget templates are actually built, and where people give up. It is not used for advertising.
- No health data, ever. Events record which metric was involved — "steps", "heart rate" — never the reading itself. This is enforced in the app's own source: the analytics event type can only carry identifiers, counts, periods and error text, and it is checked by an automated test. You can verify it yourself: every analytics event is also written to the diagnostics log in Settings → Diagnostics, which you can read and export.
- What is collected: screens viewed, onboarding progress, whether Apple Health access was requested, widget templates opened and saved, paywall and purchase outcomes, settings changes, and errors. Firebase also collects its own standard measurements, such as session counts, app version and coarse device model.
- Not linked to your identity. There is no account, so there is nothing to link to. Firebase generates a random per-install identifier, which resets if you reinstall the app.
- No advertising identifier. The app links only the base Firebase Analytics library and deliberately omits the component that would collect Apple's Advertising Identifier. This is why GlanceVitals never shows the App Tracking Transparency prompt.
- On this website: Google Analytics runs in cookieless mode — no cookies are set and nothing is stored in your browser, which is why there is no cookie banner. See section 10.
- Processor: Google, under its data processing terms. Legal basis (GDPR): our legitimate interest in understanding and improving the product, limited to data that does not identify you.
6. Feedback you choose to send
GlanceVitals includes an optional feedback form, reachable from Settings → About → Send Feedback and from the occasional in-app review prompt. It is entirely opt-in.
Please read this before using the feedback form. When you submit feedback, the text you typed is posted as an issue on the project's public GitHub repository, github.com/xr1337/Widget-health. Those issues are publicly visible to anyone on the internet. Do not include anything you would not want published — and please do not include personal or health information.
Only the text you type is sent, along with basic technical context such as the app version. No health data and no personal identifiers are attached. If you would rather write privately, email me@sufiyanyasa.com instead.
7. The launch waitlist on this website
GlanceVitals has not been released yet. If you enter your email address into the waitlist form on this website, we store that address so we can tell you when the app is available.
- What we collect: the email address you type, and nothing else. There is no name field, no tracking pixel, and no profile built around it.
- Why: to send you a single notification email when GlanceVitals reaches the App Store. It is not a newsletter, and we will not use it for anything else.
- Where it is stored: submissions are handled by Netlify Forms and held in our Netlify account — see Netlify's privacy policy. The form posts to this site's own domain; no third-party script or advertising network is involved.
- Legal basis (GDPR): your consent, given by submitting the form. You can withdraw it at any time.
- Deletion: email me@sufiyanyasa.com and we will delete your address. We will also delete the whole list once the launch email has been sent.
- Never shared or sold. Your address is not passed to any third party, advertiser or data broker.
This is entirely optional, and it is separate from the app: the waitlist lives on this website only. Installing and using GlanceVitals never requires an email address, and this list is never connected to any health data.
8. What GlanceVitals does not do
- No accounts. There is nothing to create and nothing to sign in to.
- No health data in analytics. The app does include Firebase Analytics (see section 5), but no health reading is ever sent to it, and no crash-reporting service is included.
- No advertising, and no ad network SDKs.
- No tracking. The app does not track you across apps or websites, does not use the Advertising Identifier, and does not present the App Tracking Transparency prompt because it has no reason to.
- No selling or sharing of personal information — under the CCPA's definitions or any other.
- No iCloud or cross-device sync. Your GlanceVitals configuration lives on the device it was created on.
9. The widget extension
The widget extension that draws your Home Screen and Lock Screen widgets is deliberately narrower than the app. It makes no network requests of any kind, does not include the purchases SDK, and reads only the settings and cached values that the main app has already written to the shared on-device container.
10. This website
This website is a static site. It embeds no fonts and no social or advertising trackers. It does load Google Analytics 4 from googletagmanager.com, configured in cookieless mode: it sets no cookies and stores nothing in your browser, which is why you are not asked to accept any. It records page views and two interactions — submitting the waitlist form, and clicking through to the App Store. It never receives health data, because this website never has any. The only thing this site can collect about you personally is an email address you deliberately submit to the launch waitlist, described in section 7. Our hosting provider, Netlify, processes standard server request data (such as IP address and user agent) to serve and protect the site — see Netlify's privacy policy.
11. Children
GlanceVitals is not directed at children under 13, and we do not knowingly collect personal information from anyone — of any age. The app collects no personal data at all. The launch waitlist on this website collects an email address, and is not aimed at children; if you believe a child has submitted one, email us and we will delete it. If you have any other concern, please contact us.
12. Your rights
If you are in the EU, UK, California, or another region with data-protection rights, you have the right to access, correct, delete, or port your personal data, and to object to its processing.
In practice these rights are simple to satisfy here, because we hold almost nothing: your health data and settings are on your device and under your control, and can be removed by deleting the app or revoking Health access. The data any processor holds on our behalf is the anonymous purchase record described in section 4, which is not linked to your identity — which means we generally cannot identify which record is yours even if you ask — and, if you joined the launch waitlist, the email address you submitted. The waitlist address is identifiable, so a request to access or delete it is straightforward: email us and we will action it.
Where processing does occur, our legal basis under the GDPR is the performance of our contract with you (delivering the app and its paid features), our legitimate interest in preventing fraudulent purchases, and — for the launch waitlist only — your consent, which you may withdraw at any time. To exercise any right, or to ask what we hold, email me@sufiyanyasa.com. You also have the right to lodge a complaint with your local supervisory authority.
13. Data retention
On-device data is retained until you delete it or delete the app. Purchase records held by Apple and RevenueCat are retained under their own policies, for as long as needed to keep your entitlement valid and to meet legal and tax obligations.
Waitlist email addresses are kept only until the launch email has been sent, and the list is deleted afterwards. You can have your address removed sooner at any time by emailing us.
14. Not medical advice
GlanceVitals is not a medical device. It displays data that Apple Health already holds, and it is intended for general wellness and personal interest only. It is not intended to diagnose, treat, cure or prevent any disease or condition. Never make a medical decision based on what a widget shows — talk to a qualified healthcare professional.
15. Changes to this policy
If this policy changes, we will update the effective date at the top of this page. Material changes will also be noted in the app's release notes. Continuing to use GlanceVitals after a change means you accept the updated policy.
16. Contact
Sufiyan Yasa — me@sufiyanyasa.com