Privacy policy

Last updated: 17 September 2026

Who is responsible

Baak is made by Floor Schouwman. Questions about your data go to the address on the support page.

What Baak reads

Baak reads data from Google Health with your permission. Three read permissions are requested, and nothing else.

PermissionWhat Baak reads from it
activity_and_fitness.readonlysteps per hour and per day, active minutes, zone minutes, active calories, workouts (time, type, duration, distance, heart rate), sedentary periods
sleep.readonlysleep sessions: start and end, sleep stages (deep, light, REM, awake), sleep duration and sleep period
health_metrics_and_measurements.readonlyheart rate variability, resting heart rate, heart rate through the day, respiratory rate, oxygen saturation, skin temperature deviation during sleep, VO₂max

Baak fetches today plus thirty days of history, each time you open or refresh the app.

Baak asks for no access to your location, contacts, calendar, camera, microphone or photos. Your iPhone's motion sensor drives the lighting on the cards; those readings never leave your device and are not stored anywhere.

Where it is kept, and for how long

On your iPhone. The most recent snapshot sits in a folder shared by the app and the widgets, so your widgets can show something without opening the app. Your goals and theme live there too. The session token is in the iOS keychain.

On the server. Baak uses one Cloudflare Worker as a step between you and Google. It stores your Google refresh token, your current access token, and when your session was created. Nothing else.

Your health data is not kept on the server. It is fetched from Google, turned into the numbers the app shows, and sent back to your phone in the same request.

The session token itself is not stored: the server keeps only an irreversible hash of it, so the contents of that storage cannot be used to fetch data on your behalf.

A session expires automatically after 60 days unused, and after 180 days regardless.

What Baak does not do

The server logs errors so failures can be found. Those logs contain no health values, tokens or OAuth codes.

Processors

PartyRole
Google (Google Health API)the source of your data, with your permission
Cloudflareruns the Worker and the key store for sessions
Appledistribution through the App Store and TestFlight

Deleting your data

In the app: Menu → Privacy and your data → Disconnect and delete data. That withdraws access at Google, erases your session from the server, and erases the stored snapshot from your phone and your widgets.

If the withdrawal at Google fails, the app says so, and you can do it yourself in your Google account under "Apps with access to your account".

Your rights

You can request access, correction or deletion, and object to processing. Because Baak keeps no health data of its own, an access request in practice concerns your session data; your health data itself you request from Google.

Children

Baak is not intended for children under 16.

Not a medical device

Baak is a wellness app. The numbers are estimates based on data from a wrist device, not medical measurements, and cannot diagnose, treat or rule out any condition. If you are worried about your health, your doctor is the right place.

Changes

Changes appear on this page with a new date. For significant changes, Baak asks for your consent again.