SnapBP

Privacy & data protection

Privacy Policy

SnapBP is a local-first family blood pressure record and trend tool. This policy explains what information the Android app handles, when information leaves your device, and the choices available to you.

Effective: July 29, 2026 Last updated: July 29, 2026
Local-first You can record and review data without creating or signing in to an account.
Optional sync Google sign-in enables account features and encrypted-in-transit server sync.
No data sale We do not sell health data or use it for advertising or behavioral profiling.

1. Scope and who we are

This Privacy Policy applies to the SnapBP Android application (“SnapBP,” “the App”), and to the optional SnapBP account and synchronization services operated. “We,” “us,” and “our” mean the developer of SnapBP.

Health and medical disclaimer SnapBP is a record-keeping and educational reference tool. It is not a medical device, does not diagnose or treat any condition, and is not a substitute for professional medical advice. Do not delay care based on the App. If you believe you have a medical emergency, contact local emergency services immediately.

2. Information we handle

“Handle” includes information kept only on your device as well as information collected by transmitting it off your device. The information involved depends on the features you choose to use.

Category Examples When handled Where it is stored or sent
Health records Systolic and diastolic blood pressure, pulse, measurement time and site, tags, notes, and record source. When you create, edit, import, or delete a measurement. On your device; sent to the SnapBP server only when you sign in and synchronization is enabled.
Family profile data Name, avatar selection, birth date, gender, weight, height, default-profile status, and profile identifiers. When you create or edit a family profile. Only a name is required by the App. On your device; sent to the SnapBP server only for signed-in synchronization.
Google account data Google account identifier, name or nickname, email address, profile image, and Google ID token. Only when you choose “Sign in with Google.” Processed by Google and the SnapBP authentication server. The ID token is used to verify your sign-in.
Account and security data SnapBP user ID, access and refresh tokens, a randomly generated app device ID, synchronization timestamps, IP address, request time, and security logs. When you sign in, synchronize, refresh a session, or communicate with the server. Authentication data is kept in the App’s private storage; necessary account and security records are processed by the SnapBP server.
Purchase information Lifetime product, localized price, purchase state, and purchase token. When the App checks, purchases, acknowledges, or restores Premium through Google Play. Processed between the App and Google Play. SnapBP does not receive your full card or bank details and does not upload the purchase token to the SnapBP server in the current version.
Preferences Theme, accent color, units, onboarding status, current profile, and Premium entitlement state. When you configure or use the App. Primarily on your device.
Exported reports PDF or CSV reports containing the profile and measurement data you selected. Only when you request an export. Created temporarily in the App cache and disclosed to an app or person only through the destination you choose in the Android share interface.

Local use and Android backup

You may use the core record, history, trend, and educational features without signing in. These records are stored in the App’s private local database. If Android backup or device-to-device transfer is enabled on your device, Android may back up or transfer the local database and non-authentication preferences according to your device and Google account settings. SnapBP excludes access tokens, refresh tokens, and other saved login session fields from Android backup.

Information we do not intentionally collect

The current version does not include advertising or third-party behavioral analytics. We do not collect precise location, contacts, SMS messages, call logs, microphone audio, or payment card numbers. The current release does not request camera permission.

3. How and why we use information

We use information only as reasonably necessary to:

  • save, organize, edit, classify, filter, chart, and export your blood pressure and pulse records;
  • manage family profiles and keep each measurement associated with the profile you selected;
  • authenticate your optional SnapBP account through Google and maintain your signed-in session;
  • synchronize eligible profile and measurement changes across the SnapBP server, resolve updates, and prevent duplicate records;
  • provide, verify, and restore the lifetime Premium purchase through Google Play;
  • operate, secure, troubleshoot, and protect the App and server from abuse or unauthorized access;
  • respond to support, privacy, and account-deletion requests; and
  • comply with applicable legal obligations.

Where applicable law requires a legal basis, we rely on performance of the service you request, your consent or deliberate choice for optional sign-in and sync, our legitimate interests in keeping the service secure and reliable, and compliance with law. You may use SnapBP offline if you do not want to use account synchronization.

Special protection for health information We do not sell health information, use it for targeted advertising, determine credit or insurance eligibility, or use it for purposes unrelated to SnapBP’s health-record features.

4. When information is disclosed

We do not sell your personal information. Information may be disclosed only as follows:

  • Google Sign-In: Google processes the sign-in request and provides the account details you authorize. See the Google Privacy Policy.
  • Google Play Billing: Google processes the purchase, payment method, transaction, and restoration of Premium. We receive only the information needed to determine and acknowledge entitlement.
  • Android backup and device transfer: if enabled by you or your device, Google or the device platform may process a backup or transfer of local App data.
  • SnapBP service providers: infrastructure and hosting providers may process data on our behalf to operate authentication, synchronization, security, and backups. They may use it only to provide those services and under appropriate confidentiality and security obligations.
  • Legal and safety reasons: we may disclose information if reasonably necessary to comply with law, enforce rights, investigate fraud or abuse, or protect users and the public.
  • Business transfer: if the App or its service is reorganized, transferred, or acquired, information may transfer subject to this policy and applicable law.

5. Security

The App uses Android private application storage for local records and HTTPS for communication with the SnapBP server. Authentication tokens are excluded from Android cloud backup. We limit data handling to what is needed for the features described above. No security method is completely reliable, however, and we cannot guarantee absolute security. Protect access to your device, Google account, and any reports you export.

6. Retention and deletion

  • Local data: remains on your device until you delete records or profiles, clear App storage, or uninstall the App. An Android backup created before deletion may remain under your Google backup settings and retention rules.
  • Synced data: is retained while needed to provide your account and synchronization service. Deleted records can remain temporarily as deletion markers so that deletion is synchronized across copies.
  • Account and security records: are retained for the period reasonably necessary for authentication, security, fraud prevention, dispute resolution, and legal compliance.
  • Server backups: deleted information may remain for a limited period in protected backups until those backups rotate, unless a longer period is legally required.
  • Export files: are created in App cache, but any copy you save or send is controlled by you and the selected destination.
  • Google transactions: are retained by Google under Google’s own policies and legal obligations.

7. Request account and server-data deletion

If you used Google Sign-In, you may request deletion of your SnapBP account and the personal and health data associated with that account on the SnapBP server. Deleting your SnapBP account does not delete your Google account.

We may take reasonable steps to verify that the requester controls the account. After verification, we will delete or de-identify the account and associated synchronized profiles and health records without undue delay, except information we must retain for legal, security, fraud-prevention, transaction, or dispute purposes.

A server-side deletion request cannot erase copies that remain only on your offline device or reports you previously exported. Delete those in the App, clear the App’s storage, or uninstall the App. Google Play purchase records are managed by Google and may be retained separately.

8. Your choices and privacy rights

Depending on your location, you may have rights to:

  • access or receive a copy of personal information we hold about you;
  • correct inaccurate profile or account information;
  • delete records, profiles, or your SnapBP account;
  • object to or restrict certain processing;
  • withdraw consent where processing relies on consent; and
  • complain to your local data-protection authority.

You can edit or delete individual records and family profiles in the App, export data as PDF or CSV, sign out to stop new synchronization, and revoke SnapBP’s Google account access through your Google Account settings. Signing out alone does not delete data already synchronized to the server.

We do not sell personal information or “share” it for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. Contact us to exercise a right. We may need to verify your identity and may deny or limit a request where permitted by law.

9. Children and dependent profiles

SnapBP is not directed to children who are below the minimum age required to manage their own online account under applicable law, and they should not create a SnapBP account themselves. An adult caregiver may create a local or synchronized family profile for a child or dependent only when the caregiver has the legal authority and appropriate consent to handle that person’s health information. Please enter only information necessary for the record-keeping purpose.

10. International data transfers

SnapBP, Google, and service providers may process information in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers and apply the protections described in this policy regardless of processing location.

11. Changes to this policy

We may update this policy when the App, our data practices, or legal requirements change. We will update the “Last updated” date and, where required, provide additional notice in the App or request consent. Material changes apply prospectively unless law permits otherwise.

12. Contact us

For privacy questions, support, or account and data deletion requests, contact the developer at danledian0121@gmail.com.