Legal

Privacy Policy

Last updated: October 7, 2026

Baro is a personal health dashboard for iOS and Android. Your health data stays yours. Baro has no developer-owned health-data server, no Baro account system, no advertising, and no analytics or tracking SDKs.

What this policy covers

This policy covers the Baro iOS and Android apps. Both apps use read-only access to health data that you authorize. They turn that data into readiness, sleep, strain, stress, activity, and trend views on your device.

iOS: Google Health data

On iOS, Baro connects directly from your iPhone to the Google Health API using your Google sign-in. The app requests read-only access for these categories:

Activity & fitnessHeart & body metricsSleepTracker statusProfileECG recordsIrregular rhythm records

Baro asks for tracker status, profile and heart rhythm access only when you first open the feature that uses it: your tracker's battery and last sync on the Devices page, your age to fill in your birth date for Fitness Age, and your ECG readings and irregular rhythm notifications on the Heart rate page, shown exactly as your device recorded them.

Depending on what your device and account provide, this can include steps, distance, workouts, active-zone and heart-rate-zone time, calories, floors, sedentary and activity periods, heart rate, resting heart rate, HRV, blood oxygen, respiratory rate, temperature, weight, body fat, VO₂ max, altitude, and sleep sessions and stages. Baro does not request Google Health write access.

Android: Google Health data

On Android, Baro connects directly from your phone to the Google Health API using Google's authorization service. It requests read-only access to supported activity, heart and body, and sleep data when you connect, and read-only access to tracker status, your health profile and heart rhythm records only when you first open the feature that uses them.

Activity & fitnessHeart & body metricsSleepTracker statusProfileECG recordsIrregular rhythm records

Baro does not use Health Connect and does not request Google Health write access.

Data you enter

On iOS, you may enter profile details such as sex, date of birth, waist, height, and weight, plus journal entries, habits, and goals. These details stay in the app's private storage on your device and are used only for the features you choose.

How Baro uses data

Baro uses authorized health data and information you enter to calculate and display its user-facing dashboard, scores, explanations, history, trends, and goals. Processing happens on your device. We do not use health data for advertising, credit decisions, data brokerage, or training shared AI or machine-learning models. We do not sell health data.

Storage and security

iOS: Synced health data is stored in Baro's private on-device database, protected by the iOS app sandbox and iOS Data Protection, and excluded from device backups. The Google refresh token is stored in the iOS Keychain and bound to that device. Connections to Google's sign-in and Health API services use encrypted HTTPS.

Android: Baro uses the Internet permission only for encrypted HTTPS connections to Google's authorization and Health API services. Supported health history is stored locally in its private Room/SQLite database for the dashboard, trends, and personal baselines. Android app backup is disabled. Baro has no developer-owned health-data server, analytics, or tracking SDKs.

No health data from either app is sent to Baro servers because Baro has no server that receives or stores it.

Sharing and third parties

Baro does not share health data with advertisers, analytics providers, data brokers, or other third parties. On iOS, you can explicitly create a health share card and send it using the app or service you choose in the system share sheet. Nothing is shared unless you take that action, and the chosen destination's privacy practices then apply.

Google provides authorization and Google Health data to the iOS and Android apps under your authorization. Baro does not request your Google account profile or email address. It reads your age from your Google Health profile to fill in your birth date for Fitness Age. Habesha Labs does not receive authorization credentials on a developer server.

Baro is not affiliated with Fitbit or Google.

Google API Services

Baro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your controls and deletion

On iOS, use Settings → Disconnect to stop syncing, remove the Google connection from Baro, and securely erase Baro's synced health database and journal data from that device. You can also revoke the app in your Google Account settings. Deleting the app removes its remaining local app data; a fresh install also clears any prior Google token before use.

On Android, use Baro Settings to reconnect Google Health or use your Google Account settings to revoke the Google grant. Deleting Baro removes its private on-device data, but does not delete source records held by Google Health. Manage or delete those records at the source.

This website

This static website is delivered by Cloudflare, which may process standard request information needed to serve the page. To count visits and clicks on this website, we use PostHog, hosted in the EU. It runs without cookies, doesn't store anything on your device, and discards your IP address. It never runs in the Baro apps, and the website never receives health data from them.

Children

Baro is not directed to children under 13.

Changes

We'll update this page and the "last updated" date if this policy changes.

Contact

Questions or privacy requests? Email hello@openfithealth.com.