Privacy Policy
Fitness Data Sync for iOS
Last updated: July 3, 2026
Broadhead Software ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how Fitness Data Sync handles your information.
Summary
Fitness Data Sync is designed with privacy as a core principle. We do not collect, store, or transmit your personal health data to our servers. All data processing happens locally on your device.
Information We Access
To provide our service, Fitness Data Sync accesses:
- Fitbit Account Data: We use Fitbit's official API to read your fitness and health data, including steps, distance, calories, sleep, and heart rate data.
- Google Health Data: If you connect a Google account, we use the Google Health API to read your activity, body measurement, sleep, and profile data. See the "Google Health Data" section below for details.
- Apple Health Data: With your permission, we write synced data to Apple Health on your device.
Google Health Data
When you choose to connect your Google account, Fitness Data Sync requests read-only access to the Google Health API so it can copy your data into Apple Health on your device. We request the following categories of data:
- Activity & fitness (googlehealth.activity_and_fitness.readonly): steps, distance, active energy/calories, floors climbed, heart rate, resting heart rate, heart rate variability, and VO₂ max.
- Health metrics & measurements (googlehealth.health_metrics_and_measurements.readonly): weight, body fat percentage, blood oxygen (SpO₂), respiratory rate, and skin temperature.
- Sleep (googlehealth.sleep.readonly): sleep sessions and sleep stages.
- Profile (googlehealth.profile.readonly): basic profile information used to correctly normalize and attribute the data imported into Apple Health.
How we use it: We use Google Health data solely to read your data from Google and write a copy of it into Apple Health (HealthKit) on your device. This is the core, user-facing function of the app.
How it is stored: All processing happens on your device. We operate no servers that receive your Google Health data. OAuth access and refresh tokens are stored securely in your device's keychain, and synced data is written to Apple Health, which you control.
How it is shared: We never sell, rent, or transfer your Google Health data to any third party. It is never used for advertising, retargeting, personalized or interest-based advertising, or credit or lending decisions. No human at Broadhead Software reads your Google Health data.
Revoking access: You can disconnect your Google account at any time from within the app, which revokes the app's authorization and removes the locally stored tokens. You can also revoke access from your Google Account permissions page.
How We Use Your Information
Your Fitbit data is used solely to sync it to Apple Health on your device. We:
- Process all health data locally on your iPhone
- Do not upload your health data to any external servers
- Do not share your health data with third parties
- Do not use your health data for advertising or marketing
- Do not sell your data to anyone
Data Storage
Fitness Data Sync stores minimal data on your device:
- Fitbit authentication tokens: Stored securely in your device's keychain to maintain your connection to Fitbit.
- Sync preferences: Your app settings are stored locally on your device.
- Sync history: A record of when syncs occurred is stored locally to prevent duplicate data.
Your health data is never stored by our app; it is read from Fitbit and written directly to Apple Health.
Data Security
We take the security of your sensitive health data seriously and apply the following data protection mechanisms:
- On-device processing: Your sensitive health data is processed entirely on your device. It is never transmitted to, or stored on, any Broadhead Software server. Because your data never leaves your device, there is no server-side copy that could be breached, and no Broadhead Software employee or system can access it.
- Encryption in transit: All communication with the Fitbit API and the Google Health API is performed over encrypted connections using industry-standard HTTPS/TLS. Data is never transmitted over unencrypted channels.
- Encryption at rest: OAuth access and refresh tokens are stored in the iOS Keychain, which encrypts them at rest using the device's hardware-backed encryption and protects them with your device passcode and biometric authentication (Face ID or Touch ID). Synced health data is written to Apple Health (HealthKit), which stores it encrypted on your device.
- Least-privilege access: We request only read-only access and only the minimum scopes required to sync your data. We do not request write access to your Fitbit or Google Health accounts.
- No third-party data sharing: The app contains no analytics, tracking, or advertising SDKs, and we never sell, rent, or transfer your data to third parties.
- Revocation and deletion: You can disconnect your account at any time from within the app, which immediately revokes authorization and deletes the locally stored tokens. Deleting the app removes all locally stored data.
Third-Party Services
Fitness Data Sync interacts with:
- Fitbit API: To retrieve your fitness data. Fitbit's use of your data is governed by Fitbit's Privacy Policy.
- Apple HealthKit: To write data to Apple Health. Apple's use of your data is governed by Apple's Privacy Policy.
Data Retention
We do not retain any of your health data. Authentication tokens remain on your device until you sign out of your Fitbit account within the app or delete the app. You can revoke Fitness Data Sync's access to your Fitbit account at any time through your Fitbit account settings.
Children's Privacy
Fitness Data Sync does not collect personal information from anyone, including children. All health data is processed locally on your device and is never transmitted to us. The app is not directed to children under the age of 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Limited Use Disclosure
Fitness Data Sync's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact Us
If you have any questions about this Privacy Policy, please contact us at: