Privacy Policy
Last updated: July 29, 2026
OpenFit Health ("OpenFit") is a personal health dashboard for iOS and Android. Your health data stays yours. OpenFit has no developer-owned health-data server, no OpenFit account system, no advertising, and no analytics, crash-reporting, or health-data tracking SDKs.
What this policy covers
This policy covers the OpenFit iOS and Android apps. Both apps use read-only access to health data that you authorize. They turn that data into readiness, sleep, strain, stress, activity, and trend views on your device.
iOS: Google Health data
On iOS, OpenFit connects directly from your iPhone to the Google Health API using your Google sign-in. The app requests read-only access for these categories:
Depending on what your device and account provide, this can include steps, distance, workouts, active-zone and heart-rate-zone time, calories, floors, sedentary and activity periods, heart rate, resting heart rate, HRV, blood oxygen, respiratory rate, temperature, weight, body fat, VO₂ max, altitude, and sleep sessions and stages. OpenFit does not request Google Health write access.
Android: Google Health and Health Connect data
On Android, OpenFit connects directly from your phone to the Google Health API using Google’s authorization service. Health Connect remains available as an optional on-device fallback. Both paths are read-only.
Depending on what your source provides and what you authorize, this can include steps, distance, exercise sessions, zone time, calories, floors, sedentary and activity periods, heart rate, resting heart rate, HRV, blood oxygen, respiratory rate, temperature, weight, body fat, VO₂ max, altitude, and sleep sessions and stages. OpenFit does not request Google Health or Health Connect write access.
Data you enter
On iOS, you may enter profile details such as sex, date of birth, waist, height, and weight, plus journal entries, habits, and goals. These details stay in the app's private storage on your device and are used only for the features you choose.
How OpenFit uses data
OpenFit uses authorized health data and information you enter to calculate and display its user-facing dashboard, scores, explanations, history, trends, and goals. Processing happens on your device. We do not use health data for advertising, credit decisions, data brokerage, or training shared AI or machine-learning models. We do not sell health data.
Storage and security
iOS: Synced health data is stored in OpenFit's private on-device database, protected by the iOS app sandbox and iOS Data Protection, and excluded from device backups. The Google refresh token is stored in the iOS Keychain and bound to that device. Connections to Google's sign-in and Health API services use encrypted HTTPS.
Android: OpenFit connects to Google’s sign-in and Health API services over encrypted HTTPS and stores supported health history in its private on-device database for the dashboard, trends, and personal baselines. Google’s authorization service manages the Android grant and short-lived access. Health Connect data stays in its system-managed store unless OpenFit reads supported records into its private on-device cache. Android app backup is disabled.
No health data from either app is sent to OpenFit servers because OpenFit has no server that receives or stores it.
Sharing and third parties
OpenFit does not share health data with advertisers, analytics providers, data brokers, or other third parties. On iOS, you can explicitly create a health share card and send it using the app or service you choose in the system share sheet. Nothing is shared unless you take that action, and the chosen destination's privacy practices then apply.
Google provides sign-in and Google Health data to the iOS and Android apps under your authorization. Health Connect provides Android’s optional on-device health-data access and controls. These providers process source data under their own terms and privacy policies.
Android beta feedback
Private Android beta builds include the Firebase App Distribution feedback SDK. The beta registers an anonymous Firebase install ID so Firebase can identify the app installation and release. The SDK is not included in the Google Play release.
If you enable the optional feedback notification, tapping it while OpenFit is open captures the current OpenFit screen and opens a form. Nothing is uploaded unless you tap Send. When you send, Firebase App Distribution provides the OpenFit developer with your note, the attached screenshot if selected, and the beta build identity. The screenshot can contain health information visible on the screen, so review it, crop or hide anything you do not want shared, or send the note without the screenshot. Firebase does not attach other photos, files, notifications, passwords, OAuth codes, or a raw health export.
Google API Services
OpenFit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your controls and deletion
On iOS, use Settings → Disconnect to stop syncing, remove the Google connection from OpenFit, and securely erase OpenFit's synced health database and journal data from that device. You can also revoke OpenFit in your Google Account settings. Deleting the app removes its remaining local app data; a fresh install also clears any prior OpenFit Google token before use.
On Android, use OpenFit Settings to reconnect Google Health, use your Google Account settings to revoke the Google grant, or use Health Connect to change its optional read permissions. Deleting OpenFit removes its private on-device data and beta feedback state, but does not delete source records held by Google Health or written to Health Connect by Fitbit or another app. Manage or delete those records at the source.
This website
This static website is delivered by Cloudflare, which may process standard request information needed to serve the page. We do not place advertising or analytics scripts on this page, and the website never receives health data from the OpenFit apps.
Children
OpenFit Health is not directed to children under 13.
Changes
We'll update this page and the "last updated" date if this policy changes.
Contact
Questions or privacy requests? Email [email protected].