The short version: your health readings stay on your phone. Blood pressure, heart rate, weight, notes, habits and your profile are stored in a database on the device and are never sent to us. What does leave the device is a small amount of technical information used to run, measure and (in Heart Rate Monitor only) advertise the apps, described in full below.
This policy explains what Oxford Fitness Ltd ("we", "us", "our") does with your information when you use:
- AccuRate Heart Rate Monitor (also listed as Heart Rate Monitor) on Android and iOS
- CardioCare on Android
It does not cover our other apps or websites except where they link here. The Terms of Use are a separate document.
1. Who we are
Oxford Fitness Ltd is the data controller for the purposes of the UK GDPR and the EU GDPR.
| Publisher | Oxford Fitness Ltd |
|---|---|
| Contact for privacy and all other enquiries | repsiapp@gmail.com |
We have not appointed a Data Protection Officer; we are not required to. Write to the email above for anything to do with your data and a person will read it.
2. What the apps store on your device
The following is written to storage on your phone, inside the app's own private area. It is not uploaded to us, and we have no way to read it.
Both apps
- Heart rate readings: the beats-per-minute result, the date and time, and any note or label you attach. CardioCare also stores the pulse waveform the measurement was derived from (a list of numbers describing brightness over time — not an image or a video).
- Preferences and app state: unit choices, language, reminder settings, and similar settings needed to run the app.
CardioCare only
Health and measurement records
- Blood pressure readings: systolic, diastolic, pulse, the date and time, and any note you attach.
- Weight entries: the value, the date and time, and any note.
- Tags you create and attach to readings.
Your profile and questionnaire answers
- Age, gender, height and weight.
- Your answers to the first-run health questionnaire — salt, stress, sleep, sugar, nutrition, activity, cholesterol, blood pressure, heart rate and heart disease — and the health goal you chose. These are used only on the device, to pick which starter plan and which advice you are shown.
Habits and routines
- The habits you create or accept from a suggested routine, their schedule, and the record of which ones you completed on which day.
Further preferences
- Which articles you have read or bookmarked, whether first-run has been completed, and whether a subscription is currently active.
The camera
A heart rate measurement works by looking at the colour of your fingertip through the camera while the flash is on. Those camera frames are analysed in memory as they arrive and are never written to storage, never saved as a photo or video, and never transmitted anywhere. Only the resulting number — and, in CardioCare, the derived waveform — are saved, and only on your device. Camera access is used for this and nothing else. The rest of each app remains available if you decline the permission.
Device backup
The apps allow the platform's standard backup. Depending on your device settings, Android may include app data — including your health records — in the automatic backup to your own Google account. On iOS, Heart Rate Monitor data may be included in an iCloud backup to your own Apple ID. That backup is between you and Google or Apple; we have no access to it. You can turn device backup off in system settings, or exclude individual apps where your device offers that option.
3. What leaves your device
Health values never leave the device except if you export or share them (for example a CSV file from CardioCare, or an optional write to Google Fit from Heart Rate Monitor). The technical information below goes to the named providers acting as our processors or, for advertising in Heart Rate Monitor, as independent controllers of their own ad systems.
CardioCare — Google Analytics for Firebase
We record which screens are opened and which actions are taken, so we can see where the app is confusing or broken. Examples of events we record: a measurement was started, finished or failed (and the technical reason it failed); a blood pressure or weight entry was saved; an article was opened or finished; a habit was marked done; the questionnaire was started, a question was skipped, or it was completed; the subscription screen was shown, dismissed or purchased from.
These events carry no health values. We never send your blood pressure numbers, heart rate, weight, age, questionnaire answers, notes or tags. An event records that something happened, not what it said.
Firebase also collects standard technical information automatically: a randomly generated app instance identifier, device model, operating system version, app version, language, and coarse country-level location inferred from your IP address. Firebase does not store your full IP address for analytics purposes.
CardioCare — Firebase Crashlytics
If the app crashes, a report is sent containing the crash stack trace, device model, OS version, app version and a randomly generated installation identifier. It does not contain your health records.
CardioCare — Firebase Performance Monitoring
Anonymous timing information about how quickly screens and network calls complete, with the same category of device information.
CardioCare — Firebase Remote Config
The app asks Google's servers for configuration values that let us change behaviour without shipping an update. This request sends the app instance identifier and device information; it sends nothing about you.
CardioCare — Google Play Billing
If you subscribe, the purchase is handled entirely by Google Play. Your payment card, billing address and Google account details are given to Google, not to us. We never see them. The app stores only a yes/no flag recording whether a subscription is currently active, and re-checks that with Google Play at each launch.
Heart Rate Monitor — analytics
We use Google Analytics (including Google Analytics for Firebase where enabled) to understand how the app is used: how often it is opened, which screens are visited, and similar usage information. This includes a randomly generated identifier, device and app version information, and coarse country-level location inferred from IP address. We use this only to improve the app. It does not include your heart rate values, notes or labels.
Heart Rate Monitor — advertising
Heart Rate Monitor shows ads. We use third-party advertising services including Google AdMob and Meta Audience Network. These services may use cookies or similar identifiers, mobile advertising IDs, and coarse location data for interest-based advertising and measurement. Where a consent prompt is shown in the app, ads that rely on consent are served only after you agree. You can also limit ad tracking in your operating system settings (Android advertising / ad-personalisation settings; iOS Tracking and Privacy settings).
CardioCare does not show advertising and does not use advertising identifiers.
Heart Rate Monitor — Google Fit (optional)
We do not receive information from Google APIs. You may choose to send a heart rate reading to Google Fit on your own account. That write is between you and Google and is subject to the Google API Services User Data Policy, including Limited Use requirements. You can stop this at any time by disconnecting Google Fit in the app or in Google settings.
What we do not do
- We do not require an account, a sign-in, an email address or a name.
- We do not sell your personal information.
- We do not use your health readings to train machine-learning models.
- We do not combine analytics with any other source in order to identify you.
- We do not receive the contents of a CSV export or a Google Fit write; those leave your device only because you sent them.
Voluntary emails you send us (feedback or bug reports) are read by us to reply. We do not sell that correspondence or share it with advertisers.
4. Why we are allowed to process this (UK and EU users)
| What | Purpose | Legal basis |
|---|---|---|
| Health records, profile, questionnaire answers, habits (on device) | Provide the app's core function on your device | Article 6(1)(b) — performance of the contract you enter into by using the app. Because this is health data, we rely on Article 9(2)(a) — your explicit consent, given by choosing to take or enter a reading. The data stays on your device. |
| Analytics events | Understand how the apps are used and improve them | Article 6(1)(f) — our legitimate interest in improving a product we distribute. |
| Crash and performance reports (CardioCare) | Find and fix defects | Article 6(1)(f) — our legitimate interest in a working product. |
| Remote configuration (CardioCare) | Deliver settings and offers | Article 6(1)(f) — our legitimate interest in operating the app. |
| Subscription status (CardioCare) | Give you the features you paid for | Article 6(1)(b) — performance of the contract. |
| Advertising (Heart Rate Monitor only) | Show ads and measure them | Article 6(1)(a) — consent, where required (including for interest-based ads and non-essential identifiers). Strictly necessary ads, where used, rely on Article 6(1)(f). |
| Optional Google Fit write (Heart Rate Monitor) | Save a reading to your Google Fit account at your request | Article 6(1)(a) — consent, given when you connect Google Fit. |
You have the right to object to anything we do on the basis of legitimate interests. Write to repsiapp@gmail.com and tell us what you object to.
5. How long it is kept
- On your device: for as long as you keep it. Delete an individual reading in the app to remove it; clearing the app's storage or uninstalling the app removes all of it at once. There is nothing on our side to delete afterwards.
- Analytics events: retained by Google under our configuration, up to a maximum of 14 months.
- Crash reports (CardioCare): retained by Crashlytics for 90 days.
- Subscription records (CardioCare): held by Google Play under Google's own policies for as long as they need them for billing and tax purposes.
- Advertising identifiers (Heart Rate Monitor): held by Google and Meta under their own policies. Resetting your advertising ID in system settings starts a new identifier.
- Emails you send us: kept only as long as needed to handle your request.
6. Where it goes
Google processes analytics, crash, performance, configuration, billing and (for Heart Rate Monitor) advertising data on servers in the United States and elsewhere. Meta processes advertising data for Heart Rate Monitor in the same way. Where that involves a transfer out of the UK or the EEA, it is covered by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which those providers incorporate into their terms.
Their own policies apply to how they handle data as processors or independent controllers:
- Google Privacy Policy
- Firebase Privacy and Security
- Meta Privacy Policy (Heart Rate Monitor advertising)
7. Your rights
If you are in the UK or the EEA
Under the UK GDPR and the EU GDPR you have the right to: be told what we hold; get a copy of it; have it corrected; have it erased; restrict how we use it; object to processing based on legitimate interests; receive it in a portable form; and withdraw consent at any time without affecting what was done before.
In practice, most of these you can exercise yourself and immediately: the health data is on your phone, so you can read it, correct it, and delete it, without asking anyone. CardioCare can also export records as a CSV file from Settings. For analytics, crash and advertising data, write to repsiapp@gmail.com. We will respond within one month.
You can complain to the Information Commissioner's Office (ico.org.uk) if you are in the UK, or to your national supervisory authority if you are in the EEA. We would rather you told us first, but you are not obliged to.
If you are in California
Under the CCPA as amended by the CPRA:
- We do not sell your personal information.
- CardioCare does not share personal information for cross-context behavioural advertising, and has not done so in the preceding twelve months.
- Heart Rate Monitor may share identifiers (such as advertising IDs) and device/usage information with Google and Meta for interest-based advertising. That is "sharing" under California law. You can opt out by turning off ad personalisation / tracking in system settings, and by writing to repsiapp@gmail.com with the subject line "Do Not Sell or Share".
- The categories we collect are: identifiers (a randomly generated app instance identifier; advertising IDs in Heart Rate Monitor), internet or network activity (which screens and features you used, crash and performance data), geolocation (country only, inferred from IP address), and commercial information (whether you hold a CardioCare subscription). Health information is collected but stays on your device and is never received by us, unless you yourself export or share it.
- The source is you and your device; the business purpose is operating and improving the apps, and showing ads in Heart Rate Monitor. It is disclosed to Google and, for Heart Rate Monitor ads, Meta.
- You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these. Write to repsiapp@gmail.com.
Everyone
You can stop analytics, crash, performance reporting and ads by uninstalling the app. If you want analytics stopped while you keep using the app, write to us at repsiapp@gmail.com and say so.
8. Children
These apps are not intended for children under 13, and we do not knowingly collect information from them.
If you are in the UK or the EEA and are under 16 — or under whatever age your country sets, which may be as low as 13 — you need a parent or guardian's permission to use the apps. If you believe a child has used an app without that permission, write to repsiapp@gmail.com and we will act on it.
9. Security
Your health records live in the app's private storage, which the operating system keeps separate from other apps and, on a device with a screen lock, encrypts at rest. The main practical risks are the ones you control: keep a screen lock on your phone, and think before you share an exported file — once you have sent it, it is out of the app's protection and in whatever app or inbox you sent it to.
No system is perfectly secure, and we do not claim otherwise.
10. Not a medical device
AccuRate Heart Rate Monitor and CardioCare are wellness and self-tracking tools. They are not medical devices, their readings are not diagnoses, and nothing in them is a substitute for professional medical advice. The camera-based heart rate measurement is an estimate. See the Terms of Use for the full statement.
11. Changes to this policy
If we change this policy we will post the new version at https://oxford-fitness.com/privacy.html and update the date at the top. If a change materially affects how your information is handled, we will tell you in the relevant app before it takes effect.
12. Contact
Oxford Fitness Ltd