Back to Home

Privacy Policy

Last updated: April 23, 2026

No Tracking
We don't track you across apps or websites. No advertising identifiers.
No Ads
We don't sell your data. No advertising, no marketing partnerships.
Your Data, Your Control
Access, export, or delete your data at any time. It's yours.

What We Collect

On the Web

  • Waitlist information — name, email address, and consent status when you join the waitlist
  • No cookies or tracking — the website does not use cookies, analytics, or third-party tracking scripts

In the iOS App

  • Health data from Apple Health — with your permission, Sama reads heart rate, blood oxygen saturation (SpO2), step count, sleep duration and quality, and active energy from Apple Health (HealthKit)
  • Account information — you start with an anonymous account; optionally, email address or authentication provider identity (Apple ID, Google) when you sign in
  • Computed metrics — the app generates a daily health score based on your health data
  • Crash reports — error-level logs are sent to Firebase Crashlytics for stability monitoring; health values are never included in crash reports

In the Android App

  • Health data — heart rate, blood oxygen saturation (SpO2), and step count from your SamaWritten wearable via Bluetooth Low Energy
  • Account information — email address or authentication provider identity (Google) when you create or link an account
  • Health Connect integration — with your permission, health data is written to Google Health Connect
  • Device information — wearable device identifier for pairing and data association

How We Use Your Data

On the Web

Your waitlist information is used solely to notify you about SamaWritten availability, updates, and priority access. We do not use it for marketing to third parties.

In the iOS App

Your health data from Apple Health is used to display daily health snapshots, compute a health score, generate trend insights, and deliver a morning briefing notification with your overnight health summary. Account information is used for authentication and optional cloud backup of your health history to Firebase.

In the Android App

Your health data is used to display real-time readings, generate trend charts and health insights, trigger health alerts, and sync data to Health Connect. Account information is used for authentication and optional cloud backup of your health history.

Permissions We Request

iOS Permissions

  • HealthKit (read) — to read heart rate, blood oxygen, step count, sleep, and active energy data from Apple Health
  • Notifications — for your daily morning briefing with overnight health summary (local notifications only; no push notification server is used)
  • Background delivery — to receive updated health data from Apple Health on a periodic schedule (hourly for metrics, daily for sleep)

Sama does not request access to your camera, photos, location, microphone, contacts, or Bluetooth.

Android Permissions

  • Bluetooth Scan & Connect — to find and communicate with your wearable (not used for location tracking)
  • Health Connect — to read and write heart rate, SpO2, and step data
  • Notifications — to alert you about critical health events
  • Foreground Service — to keep the Bluetooth connection alive for continuous monitoring
  • Location (Android 11 and below only) — required by the Android OS for Bluetooth scanning on older devices; SamaWritten does not track your location

Web Permissions

The website does not request any device permissions. No location, camera, microphone, or notification access is required.

Data Storage & Security

On the Web

Waitlist information (name, email, consent status) is stored in a Notion database secured by API authentication. Data is transmitted over HTTPS/TLS.

In the Apps

Health data is stored locally on your device using encrypted storage (CoreData on iOS, Room database on Android) with a 90-day automatic retention policy — older snapshots are pruned automatically. Optionally, daily health snapshots are synced to Firebase Firestore every 15 minutes, secured with user-scoped access controls, encryption in transit (TLS), and encryption at rest (AES-256). Data is associated with your authenticated account and is not accessible to other users.

Authentication credentials are stored using the platform keychain (iOS Keychain / Android Keystore with AES-256-GCM encryption). On iOS, users start with an anonymous account and may optionally sign in with Apple or Google.

Crash Reporting & Feature Configuration

We use Firebase Crashlytics to collect error-level crash reports for app stability. Health values are never included in crash reports — only error types, stack traces, and framework-level messages are sent. We use Firebase Remote Config to manage feature flags (e.g., enabling or disabling specific app features). Remote Config does not collect personal data.

Data Sharing

We do not sell, rent, or share your health data with third parties for advertising or marketing purposes. Your data is shared only with:

  • Apple Health / Health Connect — when you grant permission, Sama reads your heart rate, SpO2, step count, sleep, and active energy data from the platform health store
  • Firebase — for optional cloud backup (Firestore), crash reporting (Crashlytics), and feature configuration (Remote Config), all secured with user-scoped access controls
  • People you choose — the app supports sharing your health data with family members, doctors, or caregivers you explicitly authorize, with time-limited, revocable access

No data is shared with analytics or advertising networks.

Tracking

SamaWritten does not track you across other apps or websites. We do not use advertising identifiers. On iOS, NSPrivacyTracking is set to false. The website does not use cookies, analytics, or tracking scripts.

Data Retention

  • Local device data — automatically pruned after 90 days
  • Cloud backup — retained as long as you maintain an active account
  • Waitlist data — retained until the waitlist program concludes or you request removal

You may request deletion of your account and all associated data at any time.

Your Rights

You have the right to:

  • Access your health data at any time through the app or web dashboard
  • Export your data as a 30-day health summary PDF, shared via your device's share sheet
  • Delete your account and all associated data (local storage, Firestore snapshots, and Firebase Auth account are all removed)
  • Revoke HealthKit, Health Connect, or cloud sync permissions at any time
  • Withdraw consent for data collection at any time through the app settings or by contacting us

Children's Privacy

SamaWritten is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. Continued use of SamaWritten after changes constitutes acceptance of the updated policy.

Contact

For privacy questions, data access requests, or deletion requests:

[email protected]

Request My DataDelete My Data