Last updated: 17 September 2026
Baak is made by Floor Schouwman. Questions about your data go to the address on the support page.
Baak reads data from Google Health with your permission. Three read permissions are requested, and nothing else.
| Permission | What Baak reads from it |
|---|---|
activity_and_fitness.readonly | steps per hour and per day, active minutes, zone minutes, active calories, workouts (time, type, duration, distance, heart rate), sedentary periods |
sleep.readonly | sleep sessions: start and end, sleep stages (deep, light, REM, awake), sleep duration and sleep period |
health_metrics_and_measurements.readonly | heart rate variability, resting heart rate, heart rate through the day, respiratory rate, oxygen saturation, skin temperature deviation during sleep, VO₂max |
Baak fetches today plus thirty days of history, each time you open or refresh the app.
Baak asks for no access to your location, contacts, calendar, camera, microphone or photos. Your iPhone's motion sensor drives the lighting on the cards; those readings never leave your device and are not stored anywhere.
On your iPhone. The most recent snapshot sits in a folder shared by the app and the widgets, so your widgets can show something without opening the app. Your goals and theme live there too. The session token is in the iOS keychain.
On the server. Baak uses one Cloudflare Worker as a step between you and Google. It stores your Google refresh token, your current access token, and when your session was created. Nothing else.
Your health data is not kept on the server. It is fetched from Google, turned into the numbers the app shows, and sent back to your phone in the same request.
The session token itself is not stored: the server keeps only an irreversible hash of it, so the contents of that storage cannot be used to fetch data on your behalf.
A session expires automatically after 60 days unused, and after 180 days regardless.
The server logs errors so failures can be found. Those logs contain no health values, tokens or OAuth codes.
| Party | Role |
|---|---|
Google (Google Health API) | the source of your data, with your permission |
Cloudflare | runs the Worker and the key store for sessions |
Apple | distribution through the App Store and TestFlight |
In the app: Menu → Privacy and your data → Disconnect and delete data. That withdraws access at Google, erases your session from the server, and erases the stored snapshot from your phone and your widgets.
If the withdrawal at Google fails, the app says so, and you can do it yourself in your Google account under "Apps with access to your account".
You can request access, correction or deletion, and object to processing. Because Baak keeps no health data of its own, an access request in practice concerns your session data; your health data itself you request from Google.
Baak is not intended for children under 16.
Baak is a wellness app. The numbers are estimates based on data from a wrist device, not medical measurements, and cannot diagnose, treat or rule out any condition. If you are worried about your health, your doctor is the right place.
Changes appear on this page with a new date. For significant changes, Baak asks for your consent again.