Threshld — Privacy Policy

Effective date: 2026-05-17  ·  Last updated: 2026-05-17

Threshld ("the App", "we") is a personal health and recovery tracking app built by Claudiu Cioloca for Android. This policy explains what data the App handles, where it lives, and what control you have over it.

Questions: threshld.app@gmail.com


1. Summary

2. Data we handle

2.1 Account data (Google Firebase)

2.2 Profile constants you enter (Firestore)

Used to compute recovery, recovery, and capacity scores. Stored so the app works across devices and reinstalls.

2.3 Derived scores (Firestore)

Stored under users/{your-uid}/daily_scores/{date}.

2.4 Health Connect data (stays on your device)

Record typePurpose
Heart rateHR trends; resting HR estimates; sleep-stage cross-checks
Heart rate variability (RMSSD)Compute recovery and recovery
Sleep sessionsCompute sleep score; show sleep stages
StepsDaily activity totals; ACWR training load
Exercise / workout sessionsShow workouts; derive training load and zones
WeightBody metrics chart
Respiratory rateDisplay in vitals
Body temperatureDisplay in vitals
Resting heart rateDisplay and trends

With your optional permission, Threshld also writes HRV records to Health Connect when you enter HRV manually, so other Health Connect apps see a single coherent dataset. Revocable at any time.

Raw Health Connect records never leave your device. Cached locally in an on-device SQLite database so the app works offline.

2.5 Diagnostic data

2.6 What we do NOT collect

3. How we use your data

We do not sell or rent data, share with advertisers / brokers / marketers, use your data to train ML models, transfer Health Connect data to third parties, or use Health Connect data for advertising.

4. Where your data is stored

DataLocation
Raw Health Connect recordsYour device only (Health Connect + on-device SQLite cache)
Account profile and derived scoresGoogle Firestore (Firebase project vitals-app-86c74)
Auth credentialsGoogle Firebase Authentication
Subscription stateGoogle Firestore (verified via Google Play Billing)
Crash reportsGoogle Firebase Crashlytics

Cloud data is processed by Google as our infrastructure provider. See Google Privacy & Terms and Firebase Data Processing terms.

5. Permissions we request

The App does NOT declare ACTIVITY_RECOGNITION, location, contacts, camera, microphone, or SMS permissions.

6. Your rights

EU / UK users have additional rights under GDPR (access, rectification, restriction, objection, portability). California residents have rights under CCPA/CPRA (know, delete, opt-out — we do not sell data). Email threshld.app@gmail.com to exercise.

7. Data retention

8. Children

Threshld is not directed at children under 16 and we do not knowingly collect data from them. If you believe a child has provided data, email threshld.app@gmail.com and we will delete it.

9. Security

If you spot an issue, email threshld.app@gmail.com.

10. Changes to this policy

We will update this page when data practices change. The "Last updated" date reflects the most recent change. Material changes will be surfaced in-app before they take effect.

11. Contact

Controller: Claudiu Cioloca
Email: threshld.app@gmail.com
App: Threshld (com.threshld.app)