Consumer health data privacy notice
Draft for review. This is not an effective published legal notice.
Blue Sparrow, an independent solo developer based in India, provides this notice for consumer health data handled through LastTime. Privacy contact: privacy@bluesparrow.dev.
Categories, sources and purposes
Categories: Any health-related routine names, dates, notes, photos, readings or targets you choose to record, and interval summaries derived locally from those records. LastTime does not require these categories or calculate diagnoses.
Sources: Information you enter or select, intervals calculated locally from your history, and your own encrypted Drive records restored or synchronized at your request. LastTime does not obtain health information from data brokers, medical systems or wearable services. Support correspondence may also contain health information if you choose to include it.
Purposes: Keep the personal records and history you choose, calculate your chosen intervals and targets, show local reminders, and provide optional encrypted device sync and recovery. Health-related content is not used to recommend treatment or medication. Support content is used only to address your request and necessary privacy/security obligations.
Recipients and sharing
Personal content is processed locally. If you enable Drive, Google stores encrypted health-related records; Netcup holds an encrypted recovery-key envelope and limited account metadata, not those records. Our recovery service can access the key transiently. Email providers and the developer may see health content you voluntarily send for support. Necessary providers are limited to the requested function.
We do not sell consumer health data, share it for advertising, provide it to affiliates for independent use, or use location-based geofencing to identify people seeking healthcare. Operational Google/Firebase, Netcup and RevenueCat services may process app/account/billing metadata, but they do not receive personal record contents through those operational functions. A recipient you choose for a readable export receives the selected content.
Consent and rights
We obtain any consent required for collection or sharing beyond what is necessary to provide your requested product or service. Separate sharing consent is requested where required; this notice is not consent. New categories or purposes receive the required notice and choices first.
Where applicable you may confirm/access consumer health data, obtain information about recipients, withdraw consent and request deletion from us and relevant processors or recipients. Use app controls or email the privacy contact with the app name and request. We verify identity proportionately and respond within the applicable deadline, ordinarily 45 days where that period applies, explaining any permitted extension.
If a request is declined, email "Consumer health privacy appeal" to the same contact for review. We explain the result and how to contact the relevant authority, including the Washington Attorney General where applicable. We do not penalize you for exercising these rights.
Withdrawal stops future optional transfers; deleting cloud records is a separate action. Restricted backup deletion may follow a legally permitted schedule; pending/failed deletion and any required retention are explained. We instruct applicable processors and recipients as required. We cannot remotely erase inaccessible device copies or exports independently held by recipients you selected.