Privacy
What I Publish
Short version: this site tracks you not at all, and tracks me on purpose.
What this site collects about you
No analytics script, advertising pixel, cookie or account system. The pages are static files served by Cloudflare, and they load their typefaces from Google Fonts, so your browser also requests those files from Google. The health API behind the Health page keeps request logs for a few days (at most seven) to debug it: the address requested, the time, and the connection details Cloudflare attaches to a request, which can include your IP address, approximate location and browser. They are used for nothing else.
Whose data the Health page shows
Mine, published deliberately. It is read every minute from my personal Google account through the Google Health API, with read-only permissions. It reaches that account from a Fitbit Air band, Apple Health on my iPhone and WHOOP. I am both the subject of the data and the person choosing to publish it. Nothing is collected about anyone else.
What is published, and when
Measurement records with their original values, precision, units and timestamps: intraday heart rate, oxygen saturation, HRV, activity intervals, body measurements, workouts, and sleep sessions with their stages. Some types are daily summaries supplied by Google and are marked as such. I choose to publish readings as soon as they are imported, including the current day. This can reveal recent activity and sleep times. Availability depends on the device syncing to Google; the current day is partial and can change. Everything published is readable on the Health page and through a public JSON API, without an API key.
What is never published
Three different things, handled in three different ways:
- Never requested. The location permission, so GPS routes and coordinates never reach this system. Besides the read-only health, activity and sleep permissions, the connection only receives my email address, to confirm the account is mine; it is not stored.
- Stored, but kept private. The access tokens, encrypted with AES-256-GCM under a key held as a Worker secret, the identifier of the Google account they belong to, and sync logs. Blood glucose and core body temperature, which no device has supplied so far, would be archived but not published unless I decide otherwise.
- Discarded before storage. Google resource and account identifiers inside records, device install identifiers, and free-text notes and names. Records are built from an explicit allow-list of measurement fields.
Where it is stored
In a Cloudflare D1 database in my own Cloudflare account, as compressed JSON. Stored history is retained: the first import covered 30 days, and older ranges can be imported.
Who receives it
Cloudflare, which hosts the site, the API and the database. And, by design, anyone who opens the Health page or queries the API. The API asks search engines not to index its responses. The data is not sold, not shared with advertisers and not used for advertising.
Google API Services
This site's use of information received from Google APIs adheres to the Google Health API Developer and User Data Policy, including the Limited Use requirements. My selected measurements are deliberately shared through the Health page and public JSON API, and for no other purpose.
Revoking access
I can disconnect the integration at any time, which revokes its permission and stops the sync, and so can Google. Disconnecting does not delete the archive: records already published stay public until I delete them. Copies in search engine caches or web archives are outside my control.
Last updated 23 September 2026 · Questions: marcos@aguayo.es