We don't track you across apps or websites. No advertising identifiers.
No Ads
We don't sell your data. No advertising, no marketing partnerships.
Your Data, Your Control
Access, export, or delete your data at any time. It's yours.
What We Collect
On the Web
Waitlist information — name, email address, and consent status when you join the waitlist
No cookies or tracking — the website does not use cookies, analytics, or third-party tracking scripts
In the iOS App
Health data from Apple Health — with your permission, Sama reads heart rate, blood oxygen saturation (SpO2), step count, sleep duration and quality, and active energy from Apple Health (HealthKit)
Account information — you start with an anonymous account; optionally, email address or authentication provider identity (Apple ID, Google) when you sign in
Computed metrics — the app generates a daily health score based on your health data
Crash reports — error-level logs are sent to Firebase Crashlytics for stability monitoring; health values are never included in crash reports
In the Android App
Health data — heart rate, blood oxygen saturation (SpO2), and step count from your SamaWritten wearable via Bluetooth Low Energy
Account information — email address or authentication provider identity (Google) when you create or link an account
Health Connect integration — with your permission, health data is written to Google Health Connect
Device information — wearable device identifier for pairing and data association
How We Use Your Data
On the Web
Your waitlist information is used solely to notify you about SamaWritten availability, updates, and priority access. We do not use it for marketing to third parties.
In the iOS App
Your health data from Apple Health is used to display daily health snapshots, compute a health score, generate trend insights, and deliver a morning briefing notification with your overnight health summary. Account information is used for authentication and optional cloud backup of your health history to Firebase.
In the Android App
Your health data is used to display real-time readings, generate trend charts and health insights, trigger health alerts, and sync data to Health Connect. Account information is used for authentication and optional cloud backup of your health history.
Permissions We Request
iOS Permissions
HealthKit (read) — to read heart rate, blood oxygen, step count, sleep, and active energy data from Apple Health
Notifications — for your daily morning briefing with overnight health summary (local notifications only; no push notification server is used)
Background delivery — to receive updated health data from Apple Health on a periodic schedule (hourly for metrics, daily for sleep)
Sama does not request access to your camera, photos, location, microphone, contacts, or Bluetooth.
Android Permissions
Bluetooth Scan & Connect — to find and communicate with your wearable (not used for location tracking)
Health Connect — to read and write heart rate, SpO2, and step data
Notifications — to alert you about critical health events
Foreground Service — to keep the Bluetooth connection alive for continuous monitoring
Location (Android 11 and below only) — required by the Android OS for Bluetooth scanning on older devices; SamaWritten does not track your location
Web Permissions
The website does not request any device permissions. No location, camera, microphone, or notification access is required.
Data Storage & Security
On the Web
Waitlist information (name, email, consent status) is stored in a Notion database secured by API authentication. Data is transmitted over HTTPS/TLS.
In the Apps
Health data is stored locally on your device using encrypted storage (CoreData on iOS, Room database on Android) with a 90-day automatic retention policy — older snapshots are pruned automatically. Optionally, daily health snapshots are synced to Firebase Firestore every 15 minutes, secured with user-scoped access controls, encryption in transit (TLS), and encryption at rest (AES-256). Data is associated with your authenticated account and is not accessible to other users.
Authentication credentials are stored using the platform keychain (iOS Keychain / Android Keystore with AES-256-GCM encryption). On iOS, users start with an anonymous account and may optionally sign in with Apple or Google.
Crash Reporting & Feature Configuration
We use Firebase Crashlytics to collect error-level crash reports for app stability. Health values are never included in crash reports — only error types, stack traces, and framework-level messages are sent. We use Firebase Remote Config to manage feature flags (e.g., enabling or disabling specific app features). Remote Config does not collect personal data.
Data Sharing
We do not sell, rent, or share your health data with third parties for advertising or marketing purposes. Your data is shared only with:
Apple Health / Health Connect — when you grant permission, Sama reads your heart rate, SpO2, step count, sleep, and active energy data from the platform health store
Firebase — for optional cloud backup (Firestore), crash reporting (Crashlytics), and feature configuration (Remote Config), all secured with user-scoped access controls
People you choose — the app supports sharing your health data with family members, doctors, or caregivers you explicitly authorize, with time-limited, revocable access
No data is shared with analytics or advertising networks.
Tracking
SamaWritten does not track you across other apps or websites. We do not use advertising identifiers. On iOS, NSPrivacyTracking is set to false. The website does not use cookies, analytics, or tracking scripts.
Data Retention
Local device data — automatically pruned after 90 days
Cloud backup — retained as long as you maintain an active account
Waitlist data — retained until the waitlist program concludes or you request removal
You may request deletion of your account and all associated data at any time.
Your Rights
You have the right to:
Access your health data at any time through the app or web dashboard
Export your data as a 30-day health summary PDF, shared via your device's share sheet
Delete your account and all associated data (local storage, Firestore snapshots, and Firebase Auth account are all removed)
Revoke HealthKit, Health Connect, or cloud sync permissions at any time
Withdraw consent for data collection at any time through the app settings or by contacting us
Children's Privacy
SamaWritten is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. Continued use of SamaWritten after changes constitutes acceptance of the updated policy.
Contact
For privacy questions, data access requests, or deletion requests: