WaterChamp Privacy Policy

Last updated: September 5, 2026

WaterChamp (“the App”, “we”, “us”) is a hydration and wellness tracking app. This policy explains what data we collect, how we use it, where it goes, and your rights. We designed WaterChamp to keep your data on your device wherever possible.

Data Controller

The data controller responsible for your personal data is Petr Peller, located in the Czech Republic. You can contact us at any time at [email protected].

Data Stored on Your Device

The following data is stored locally on your device only and is never transmitted to us or any external server:

Apple Health (HealthKit)

On iOS, with your permission, the App reads and writes health data via Apple HealthKit:

Reads: Workouts, active energy, steps, and sleep analysis — used to personalize hydration recommendations.

Writes: Dietary water, dietary caffeine, and alcoholic beverages — so your intake appears alongside other health data in Apple Health.

HealthKit data stays within Apple's Health ecosystem on your device. We do not access, store, or transmit your HealthKit data to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the iOS Health permission prompt, which you can withdraw at any time in Settings.

Health Connect (Android)

On Android, with your permission, the App reads and writes health data via Health Connect, the health data store built into Android. The integration is optional — if you do not grant the permissions, the App simply does not use it.

Reads: Exercise sessions, active calories burned, steps, and sleep sessions — used to personalize hydration recommendations.

Writes: Water intake (written as hydration records) and caffeine (written as nutrition records) — so your intake appears alongside other health data in Health Connect.

Alcohol is not written on Android. Health Connect has no record type for alcoholic drinks, so alcohol you log stays on your device, inside the App, and is never written to Health Connect.

Health Connect data lives in the Health Connect data store on your device, under Android's control. We do not access, store, or transmit it to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the Health Connect permission screen. Each permission is separate, and you can withdraw any of them at any time in Health Connect.

Data Shared with Third Parties

We use seven third-party services. All of them receive only limited technical data — never your hydration entries, health data, or on-device profile. We have no user accounts, so this data is not tied to your name or email.

Superwall (subscription analytics)

We use Superwall to manage and measure our subscription and paywall. The Superwall SDK receives:

This data is used solely for analytics (understanding subscription metrics) and app functionality (managing subscription status). It is not used for advertising or tracking across other apps. Superwall's privacy policy: superwall.com/privacy

RevenueCat (subscription analytics)

We use RevenueCat to measure our subscription and to decide which set of plans the App offers. The RevenueCat SDK receives:

Purchases themselves do not go through RevenueCat. Apple or Google processes the payment, and RevenueCat only receives a record of it afterwards. We do not identify you to RevenueCat — no account, no user ID, only an anonymous identifier it generates — and we do not enable its advertising-identifier collection, so it receives neither the IDFA nor the Android advertising ID. This data is used solely for analytics (understanding subscription metrics and comparing plan line-ups). It is not used for advertising or tracking across other apps. RevenueCat's privacy policy: revenuecat.com/privacy

AppsFlyer (install attribution)

We use AppsFlyer to measure which ads lead to installs of the App. The AppsFlyer SDK receives:

Advertising-identifier collection is disabled on both platforms. The iOS build contains no IDFA code and never shows the App Tracking Transparency prompt; the Android build removes the advertising-ID permission and the SDK runs with advertising-ID collection switched off. Attribution instead uses the Google Play Install Referrer on Android, and on iOS a combination of Apple's SKAdNetwork, Apple's AdServices attribution token, and Google's on-device conversion measurement described below. All of these report at campaign level without identifying you. AppsFlyer never receives your hydration entries, health data, or on-device profile.

Google on-device conversion measurement (iOS). The iOS build includes a Google library that measures whether a Google ad led to the install. It reads the Apple vendor ID and a record of Google ad clicks that Google's own apps keep on your device, and matches the two on the device. The result is an encrypted, aggregated token describing the ad click. The library sends nothing by itself; AppsFlyer passes the token to Google Ads so the ad can be credited with the install. No advertising identifier is used, and the token does not identify you.

This data is used solely for analytics (measuring our ad campaigns). It is not used to track you across other apps. AppsFlyer's privacy policy: appsflyer.com/legal/services-privacy-policy

GoMarketMe (affiliate attribution)

We use GoMarketMe to run an affiliate program: creators share links or offer codes for the App and earn a commission when someone they referred subscribes. The GoMarketMe SDK receives:

If you install the App after opening a creator's affiliate link, GoMarketMe compares technical device information from the App with the link click to decide whether that creator referred you. If you redeem a creator's offer code, the referral is established by the code alone. GoMarketMe never receives your hydration entries, health data, or on-device profile.

This data is used solely to credit the creator who referred you and to pay their commission. It is not used for advertising and not sold. GoMarketMe's privacy policy: gomarketme.co/privacy

Expo (app updates)

We use Expo's EAS Update service to deliver bug fixes and small improvements without a full app-store release. When the App starts, the update client contacts Expo's servers (u.expo.dev) to check whether newer app code is available. Expo receives:

This data is used solely to deliver the right update to your device. It is not used for advertising or tracking across other apps. Expo's privacy policy: expo.dev/privacy

DataFast (product analytics)

We use DataFast to count how the App is used. The DataFast SDK receives:

Like every network request, the SDK's requests carry your IP address to DataFast's servers. We never tell DataFast who you are: the App has no accounts and does not call DataFast's identify function. This data is used solely for analytics (understanding which features are used). DataFast's privacy policy: datafa.st/privacy-policy

Sentry (crash and bug diagnostics)

We use Sentry to detect and fix crashes and bugs. The Sentry SDK receives:

We have configured Sentry not to collect your IP address or any personally identifiable information, and we do not set a user identifier, so this data is not linked to you personally. It is used solely to keep the App stable and secure. Sentry's privacy policy: sentry.io/privacy

The one exception is feedback you choose to send us, described next.

Feedback you choose to send

The App has an optional feedback form, reachable from Settings and from the home screen. Nothing is sent unless you fill it in and tap Send.

If you use it, we receive:

These are delivered through Sentry, the same service described above, and we read them there. If you leave the email field blank we have no way to identify you or to reply. If you fill it in, we use it only to reply to you about your message. It is never added to a mailing list, used for marketing, or shared with anyone else.

Unlike the automatic diagnostics above, a message you send with your email address is linked to you, because you chose to tell us who you are.

Android

This section applies to the Android version of WaterChamp. Everything else in this policy applies to both platforms, except where a section says it is specific to iOS.

Purchases go through Google Play Billing. Subscriptions on Android are processed by Google Play. Your payment details go to Google, not to us — we only receive your entitlement status (whether your subscription is active). Google's handling of payment data is described in Google's privacy policy.

Superwall on Android. Superwall (described above) receives the same data on Android, with one difference: instead of the Apple vendor ID, it receives Android device identifiers. It does not receive the Android advertising ID.

RevenueCat on Android. RevenueCat (described above) receives the same data on Android, from Google Play instead of the App Store.

No advertising ID. The App does not collect the Android advertising ID (AAID), just as it does not collect the IDFA on iOS. This includes AppsFlyer: the App removes the advertising-ID permission from the Android build, and install attribution uses the Google Play Install Referrer instead.

Health platform. The Android version connects to Health Connect, not Apple HealthKit — see the Health Connect section above. The Apple Health section applies to iOS only.

Deleting your data on Android. Your data lives on your device, same as on iOS. Delete individual entries in the App, or uninstall the App to remove everything. Android's automatic cloud backup is turned off for WaterChamp, so no copy of your data exists in your Google account backup — uninstalling removes it completely. Anything already written to Health Connect is managed separately, in Health Connect.

Notifications on Android. The App asks for the Android notification permission before sending hydration reminders. You can turn reminders off in the App's settings, or block them entirely in Android Settings > Apps > WaterChamp > Notifications.

Notifications

The App may request permission to send local notifications for hydration reminders. Notifications are scheduled entirely on your device — no data is sent to external push notification services.

The WaterChamp Website

The website at waterchamp.app (including this page) uses the Google tag (gtag.js) to measure whether Google ads lead to visits and app downloads. For visitors in the EEA, the UK, and Switzerland, ad consent defaults to denied: the tag sets no cookies and stores nothing on your device. For visitors elsewhere, Google may set first-party cookies to attribute a visit to an ad click. This data is used solely for measuring our ad campaigns. Google's privacy policy: policies.google.com/privacy

The website also uses DataFast to count page visits: which pages are viewed and which site or search engine the visitor came from. DataFast sets no cookies and stores nothing on your device. Like every web request, the script request carries your IP address to DataFast's servers. DataFast's privacy policy: datafa.st/privacy-policy

Beyond these two, the website uses no analytics or other third-party trackers.

Data We Do Not Collect

Legal Basis for Processing (GDPR)

For users in the EEA and UK, we rely on the following legal bases (GDPR Article 6, and Article 9 for health data):

International Data Transfers

Superwall, RevenueCat, Sentry, Expo, AppsFlyer, and GoMarketMe are based in the United States, so the limited technical data described above is transferred to the US. These transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. DataFast (JustShipIt Pte. Ltd.) is based in Singapore and hosts most of its infrastructure outside the EU, including in the United States; the transfer of the analytics data described above relies on Standard Contractual Clauses under DataFast's data processing agreement. Your hydration entries, health data, and on-device profile are never transferred — they stay on your device.

Data Retention

Your Rights

Everyone can:

If you are in the EEA or UK, you also have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with your local data protection supervisory authority. Because we hold no account and cannot identify you from the anonymous analytics, our ability to act on some requests about that specific data may be limited; the data on your device is always fully under your control in the App. To exercise a right, email [email protected].

Children's Privacy

The App is not directed to children. We do not knowingly collect data from children under 16 (or the minimum digital-consent age in your country, which may be as low as 13). If you believe a child has provided data through the App, please contact us.

Changes to This Policy

We may update this policy from time to time. Changes will be reflected in the “Last updated” date above.

Contact

If you have questions about this privacy policy or your data, contact us at [email protected].