This policy describes how the Health Tracking Journal ("we," "the app") handles information
for a private personal wellness journaling tool used by the account holder and an invited
support viewer.
Who we are
Health Tracking Journal is a personal web application hosted at
https://bipolar-tracker.com/.
Access is limited to individuals who create an email account or are invited as a companion.
Information we collect
Journal content: Log entries you create (text, dates, wellness level
labels, optional metadata, and assessment summaries).
Account email: Email address used to sign in when Supabase auth is
enabled.
Mobile phone numbers (SMS program only): Numbers used to send
high-priority wellness alerts - the account holder's number and one support contact number
configured by the account holder. Numbers are not collected through a public signup form;
they are configured for this private use.
Technical data: Standard logs from our hosting and database providers
(e.g. request timestamps, errors) needed to operate the service. We also store the
IP address associated with account signup and later sign-in or journal activity, for
security, abuse prevention, and coarse location context. IP records are removed from
live systems when you delete your account (a copy may be retained in our account
archive with other deleted-account data).
Fitbit / Google Health (optional): If you connect Fitbit, we access
activity and sleep data through the
Google Health API (OAuth scopes:
googlehealth.activity_and_fitness.readonly and
googlehealth.sleep.readonly). We receive daily summaries such as steps, active
minutes, sleep duration, sleep stages, sleep efficiency, and resting heart rate. We do not
access your Google Account password. Companions invited to your journal cannot view this
wearable data.
Usage analytics (optional): If enabled, we use
Google Analytics 4 on the public web app to understand aggregate usage
(e.g. which screens are opened, sign-up funnel steps, journal activity counts). This may
include campaign parameters from links you used to reach the site (such as
utm_source). We do not use analytics for advertising or sell analytics data.
How we use information
Store and display your journal and wellness level state.
Run optional automated assessment of entries (via configured API services).
Send transactional SMS only when you explicitly trigger a high-priority
alert, as described in our
SMS program and consent page.
Maintain security, fix bugs, and comply with law (including stored signup and activity IP addresses for abuse review and coarse location context).
Display Fitbit / Google Health trends on your dashboard and include them in clinical export
summaries you generate (only when you connect Fitbit).
We do not use your information for advertising or sell your phone numbers.
Google user data (Fitbit / Google Health)
This section describes how Bipolar Tracker (Health Tracking Journal) accesses,
uses, stores, and shares data obtained through Google APIs when you connect Fitbit via Google
Health, in accordance with the
Google API Services User Data Policy
including the Limited Use requirements.
Access: Only after you start connect in Account settings (or onboarding),
sign in to Google, and grant the activity and sleep read scopes listed above.
Use: We use this data only to show personal wellness trends in the app and
in exports you request. We do not use Google Health data for advertising, credit, insurance,
or employment decisions, or to train generalized AI models.
Storage: OAuth tokens and derived daily summaries are stored in our
Supabase database (same region as other journal data). Tokens are used only
to sync and refresh access; we do not sell them.
Sharing: We do not sell or share Google Health data with third parties except
processors that host the service (Supabase, and Google when you authorize OAuth). Companions
cannot see Fitbit data. We do not transfer this data to others for their independent use.
Retention: Summaries and tokens remain until you disconnect Fitbit in the
app or request deletion (see Data deletion).
Revocation: Disconnect Fitbit in Account settings to revoke our access and
delete stored summaries and tokens from our database. You can also revoke the app at
Google Account permissions.
SMS and mobile numbers
Wellness alert texts are sent through Twilio. Twilio processes message
delivery and may retain message metadata as described in
Twilio's Privacy Policy.
No sale or sharing for marketing: Mobile numbers are used only to deliver
alerts for this app. We do not sell, rent, or share phone numbers with third parties for
their marketing purposes.
Opt-out: Reply STOP to any message from our Twilio number
to unsubscribe. Reply HELP for help. Message and data rates may apply.
Frequency: SMS is sent only when an alert is manually triggered, not on a
marketing schedule.
Service providers
We use trusted processors to run the app, including:
Amazon Web Services (Amplify) - hosting the web application.
Twilio - sending SMS messages.
Google Analytics - aggregate website and app usage metrics when the
measurement tag is enabled (see
Google Privacy Policy).
Hotjar (Contentsquare) - session recordings and heatmaps on the public
login experience when enabled (see
Hotjar Privacy Policy).
Optional AI providers - if enabled, journal text may be sent for entry
assessment or summaries (only when those features are configured).
These providers process data on our behalf under their own terms and privacy policies.
Storage and security
Journal data is stored in a hosted database with industry-standard access controls. No method
of transmission or storage is 100% secure; we take reasonable steps to protect your data for
a personal tool of this scale.
Retention
Journal entries are kept until you delete them or the account holder removes them from the
system. SMS delivery logs may be retained by Twilio according to Twilio's policies.
Your choices
Stop receiving SMS by replying STOP.
Opt out of Google Analytics and Hotjar/Contentsquare in your browser: open the site, open developer
tools → Console, run
localStorage.setItem('ga-opt-out', '1'); location.reload();
To opt back in, run
localStorage.removeItem('ga-opt-out'); location.reload();
Request correction or deletion of journal data by contacting the account administrator.
Do not use the app if you do not agree with this policy.
Children
This app is not directed at children under 13 and is not intended for general public use.
Changes
We may update this policy from time to time. The "Effective" date at the top will change when
we do. Continued use of the app after changes means you accept the updated policy.