WaterChamp Privacy Policy
Last updated: September 5, 2026
WaterChamp (“the App”, “we”, “us”) is a hydration and wellness tracking app. This policy explains what data we collect, how we use it, where it goes, and your rights. We designed WaterChamp to keep your data on your device wherever possible.
Data Controller
The data controller responsible for your personal data is Petr Peller, located in the Czech Republic. You can contact us at any time at [email protected].
Data Stored on Your Device
The following data is stored locally on your device only and is never transmitted to us or any external server:
- Hydration entries — water intake amounts, timestamps, beverage types, caffeine, alcohol, and custom notes
- Personal settings — daily goals, notification preferences, tracking limits, and display preferences
- Metabolism profile — body weight, biological sex, age, activity level, climate, and pregnancy status (used to calculate personalized hydration goals)
- Custom beverages — names, nutritional values, and favorites
- Streak and check-in data — daily usage tracking for motivation
Apple Health (HealthKit)
On iOS, with your permission, the App reads and writes health data via Apple HealthKit:
Reads: Workouts, active energy, steps, and sleep analysis — used to personalize hydration recommendations.
Writes: Dietary water, dietary caffeine, and alcoholic beverages — so your intake appears alongside other health data in Apple Health.
HealthKit data stays within Apple's Health ecosystem on your device. We do not access, store, or transmit your HealthKit data to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the iOS Health permission prompt, which you can withdraw at any time in Settings.
Health Connect (Android)
On Android, with your permission, the App reads and writes health data via Health Connect, the health data store built into Android. The integration is optional — if you do not grant the permissions, the App simply does not use it.
Reads: Exercise sessions, active calories burned, steps, and sleep sessions — used to personalize hydration recommendations.
Writes: Water intake (written as hydration records) and caffeine (written as nutrition records) — so your intake appears alongside other health data in Health Connect.
Alcohol is not written on Android. Health Connect has no record type for alcoholic drinks, so alcohol you log stays on your device, inside the App, and is never written to Health Connect.
Health Connect data lives in the Health Connect data store on your device, under Android's control. We do not access, store, or transmit it to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the Health Connect permission screen. Each permission is separate, and you can withdraw any of them at any time in Health Connect.
Data Shared with Third Parties
We use seven third-party services. All of them receive only limited technical data — never your hydration entries, health data, or on-device profile. We have no user accounts, so this data is not tied to your name or email.
Superwall (subscription analytics)
We use Superwall to manage and measure our subscription and paywall. The Superwall SDK receives:
- Purchase history — subscription status, transactions, trial starts, renewals, and cancellations
- Device identifiers — Apple vendor ID and bundle ID (not the advertising identifier / IDFA)
- Product interaction — app sessions, app installs, and paywall views
- Device information — device model, OS version, locale, timezone, and country (derived from IP address)
- A few coarse, non-identifying app attributes for audience targeting — your unit preference (ml/oz), a daily-goal band (e.g. “2000–2999 ml”, not your exact goal), whether notifications and Apple Health are enabled, and which onboarding version you saw
This data is used solely for analytics (understanding subscription metrics) and app functionality (managing subscription status). It is not used for advertising or tracking across other apps. Superwall's privacy policy: superwall.com/privacy
RevenueCat (subscription analytics)
We use RevenueCat to measure our subscription and to decide which set of plans the App offers. The RevenueCat SDK receives:
- Purchase history — subscription status, transactions, trial starts, renewals, and cancellations
- Paywall views — which set of plans was shown to you, so we can compare one line-up against another
- Device information — platform, app version, and country (derived from IP address)
Purchases themselves do not go through RevenueCat. Apple or Google processes the payment, and RevenueCat only receives a record of it afterwards. We do not identify you to RevenueCat — no account, no user ID, only an anonymous identifier it generates — and we do not enable its advertising-identifier collection, so it receives neither the IDFA nor the Android advertising ID. This data is used solely for analytics (understanding subscription metrics and comparing plan line-ups). It is not used for advertising or tracking across other apps. RevenueCat's privacy policy: revenuecat.com/privacy
AppsFlyer (install attribution)
We use AppsFlyer to measure which ads lead to installs of the App. The AppsFlyer SDK receives:
- Install and launch events — that the App was installed and opened
- Purchase events — that a subscription or trial started, with the product, price, and currency (not your payment details — those never leave the app store)
- Device information — device model, OS version, language, and your IP address (as with any internet request; used to deliver the response and derive a coarse region)
- On iOS: the Apple vendor ID (IDFV) — an identifier shared only among our own apps; not the advertising identifier
Advertising-identifier collection is disabled on both platforms. The iOS build contains no IDFA code and never shows the App Tracking Transparency prompt; the Android build removes the advertising-ID permission and the SDK runs with advertising-ID collection switched off. Attribution instead uses the Google Play Install Referrer on Android, and on iOS a combination of Apple's SKAdNetwork, Apple's AdServices attribution token, and Google's on-device conversion measurement described below. All of these report at campaign level without identifying you. AppsFlyer never receives your hydration entries, health data, or on-device profile.
Google on-device conversion measurement (iOS). The iOS build includes a Google library that measures whether a Google ad led to the install. It reads the Apple vendor ID and a record of Google ad clicks that Google's own apps keep on your device, and matches the two on the device. The result is an encrypted, aggregated token describing the ad click. The library sends nothing by itself; AppsFlyer passes the token to Google Ads so the ad can be credited with the install. No advertising identifier is used, and the token does not identify you.
This data is used solely for analytics (measuring our ad campaigns). It is not used to track you across other apps. AppsFlyer's privacy policy: appsflyer.com/legal/services-privacy-policy
GoMarketMe (affiliate attribution)
We use GoMarketMe to run an affiliate program: creators share links or offer codes for the App and earn a commission when someone they referred subscribes. The GoMarketMe SDK receives:
- Install and launch events — that the App was installed and opened
- Purchase events — that a subscription or trial started, read from the app store's transaction record (the product, price, and currency — not your payment details, which never leave the app store)
- Device information — device model, OS version, locale, and your IP address (as with any internet request; used to deliver the response and derive a coarse region)
- An SDK-generated install identifier — created by GoMarketMe for the installation; not an advertising identifier
If you install the App after opening a creator's affiliate link, GoMarketMe compares technical device information from the App with the link click to decide whether that creator referred you. If you redeem a creator's offer code, the referral is established by the code alone. GoMarketMe never receives your hydration entries, health data, or on-device profile.
This data is used solely to credit the creator who referred you and to pay their commission. It is not used for advertising and not sold. GoMarketMe's privacy policy: gomarketme.co/privacy
Expo (app updates)
We use Expo's EAS Update service to deliver bug fixes and small improvements without a full app-store release. When the App starts, the update client contacts Expo's servers (u.expo.dev) to check whether newer app code is available. Expo receives:
- A per-install identifier — a random ID (the “EAS-Client-ID”) created when the App is first installed and sent with every update check. It identifies the installation, not you, and it is not an advertising identifier
- Your IP address — as with any internet request; used to deliver the response
- Technical update metadata — platform (iOS or Android), the App's version, runtime version, and update channel
This data is used solely to deliver the right update to your device. It is not used for advertising or tracking across other apps. Expo's privacy policy: expo.dev/privacy
DataFast (product analytics)
We use DataFast to count how the App is used. The DataFast SDK receives:
- Screen views — which screens and steps you open, such as an onboarding step, the drink picker, or the settings screen
- Anonymous usage counters — the same counters described under Sentry below: that an action happened and where it came from, never the amount, the drink, your goal, or when you drank it
- Permission answers — whether you granted or refused notification or Health access, and which screen asked. Never any health data
- Technical context — device model, OS version, app version, language, and time zone
- A random visitor ID — the App creates a random ID on first launch and keeps it on your device, so DataFast can tell a returning user from a new one and group screen views into sessions. It is not linked to your name, email, Apple ID, or Google account, and it is not an advertising identifier. Uninstalling the App removes it
Like every network request, the SDK's requests carry your IP address to DataFast's servers. We never tell DataFast who you are: the App has no accounts and does not call DataFast's identify function. This data is used solely for analytics (understanding which features are used). DataFast's privacy policy: datafa.st/privacy-policy
Sentry (crash and bug diagnostics)
We use Sentry to detect and fix crashes and bugs. The Sentry SDK receives:
- Crash and error reports — stack traces and the technical state at the time of an error
- Performance data — anonymous timing samples from a fraction of sessions
- Diagnostic logs — anonymous technical breadcrumbs leading up to an error, such as which screen you opened
- Technical context — device model, OS version, and app version
- Anonymous usage counters — that an action happened and where it came from (for example "a drink was logged from the widget", that a daily goal was reached, or that notification or Health access was granted or refused), so we can see which features are used. These carry no measurements: never the amount, the drink, your goal, or when you drank it
- Achievement unlocks — the name of an achievement sticker at the moment you unlock it, so we can see which ones people reach. A few names describe the milestone itself, such as a caffeine-free day or a month without alcohol. We receive the name only, never the entries behind it
We have configured Sentry not to collect your IP address or any personally identifiable information, and we do not set a user identifier, so this data is not linked to you personally. It is used solely to keep the App stable and secure. Sentry's privacy policy: sentry.io/privacy
The one exception is feedback you choose to send us, described next.
Feedback you choose to send
The App has an optional feedback form, reachable from Settings and from the home screen. Nothing is sent unless you fill it in and tap Send.
If you use it, we receive:
- Your message — whatever you write in the box
- Your email address — only if you choose to type one into the optional field
These are delivered through Sentry, the same service described above, and we read them there. If you leave the email field blank we have no way to identify you or to reply. If you fill it in, we use it only to reply to you about your message. It is never added to a mailing list, used for marketing, or shared with anyone else.
Unlike the automatic diagnostics above, a message you send with your email address is linked to you, because you chose to tell us who you are.
Android
This section applies to the Android version of WaterChamp. Everything else in this policy applies to both platforms, except where a section says it is specific to iOS.
Purchases go through Google Play Billing. Subscriptions on Android are processed by Google Play. Your payment details go to Google, not to us — we only receive your entitlement status (whether your subscription is active). Google's handling of payment data is described in Google's privacy policy.
Superwall on Android. Superwall (described above) receives the same data on Android, with one difference: instead of the Apple vendor ID, it receives Android device identifiers. It does not receive the Android advertising ID.
RevenueCat on Android. RevenueCat (described above) receives the same data on Android, from Google Play instead of the App Store.
No advertising ID. The App does not collect the Android advertising ID (AAID), just as it does not collect the IDFA on iOS. This includes AppsFlyer: the App removes the advertising-ID permission from the Android build, and install attribution uses the Google Play Install Referrer instead.
Health platform. The Android version connects to Health Connect, not Apple HealthKit — see the Health Connect section above. The Apple Health section applies to iOS only.
Deleting your data on Android. Your data lives on your device, same as on iOS. Delete individual entries in the App, or uninstall the App to remove everything. Android's automatic cloud backup is turned off for WaterChamp, so no copy of your data exists in your Google account backup — uninstalling removes it completely. Anything already written to Health Connect is managed separately, in Health Connect.
Notifications on Android. The App asks for the Android notification permission before sending hydration reminders. You can turn reminders off in the App's settings, or block them entirely in Android Settings > Apps > WaterChamp > Notifications.
Notifications
The App may request permission to send local notifications for hydration reminders. Notifications are scheduled entirely on your device — no data is sent to external push notification services.
The WaterChamp Website
The website at waterchamp.app (including this page) uses the Google tag (gtag.js) to measure whether Google ads lead to visits and app downloads. For visitors in the EEA, the UK, and Switzerland, ad consent defaults to denied: the tag sets no cookies and stores nothing on your device. For visitors elsewhere, Google may set first-party cookies to attribute a visit to an ad click. This data is used solely for measuring our ad campaigns. Google's privacy policy: policies.google.com/privacy
The website also uses DataFast to count page visits: which pages are viewed and which site or search engine the visitor came from. DataFast sets no cookies and stores nothing on your device. Like every web request, the script request carries your IP address to DataFast's servers. DataFast's privacy policy: datafa.st/privacy-policy
Beyond these two, the website uses no analytics or other third-party trackers.
Data We Do Not Collect
- No name or account information, and no accounts at all
- No email address, unless you choose to type one into the optional feedback form described above
- No location data
- No photos, camera, or contacts
- No advertising identifiers (Apple IDFA or Android advertising ID)
- No tracking across other apps
- No data sold to third parties
Legal Basis for Processing (GDPR)
For users in the EEA and UK, we rely on the following legal bases (GDPR Article 6, and Article 9 for health data):
- Providing the App you requested — performance of a contract, and your device permissions. Most processing happens only on your device.
- Apple Health and Health Connect data — your explicit consent (Article 9(2)(a)), given through the iOS Health prompt or the Android Health Connect permission screen, and processed only on your device.
- Subscriptions and purchases (Superwall, RevenueCat) — performance of a contract and our legitimate interest in operating and improving the subscription.
- Crash and bug diagnostics (Sentry) — our legitimate interest in keeping the App stable and secure. You may object at any time by contacting us; note that this may reduce our ability to diagnose problems you report.
- App updates (Expo) — our legitimate interest in keeping the App up to date, stable, and secure.
- Install attribution (AppsFlyer) — our legitimate interest in measuring which ads lead to installs, using only the limited technical data described above and no advertising identifiers.
- Affiliate attribution (GoMarketMe) — our legitimate interest in crediting the creator who referred you and paying their commission, using only the limited technical data described above.
- Feedback you send us — your consent, given by choosing to fill in and submit the form. You can withdraw it at any time by asking us to delete your message.
International Data Transfers
Superwall, RevenueCat, Sentry, Expo, AppsFlyer, and GoMarketMe are based in the United States, so the limited technical data described above is transferred to the US. These transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. DataFast (JustShipIt Pte. Ltd.) is based in Singapore and hosts most of its infrastructure outside the EU, including in the United States; the transfer of the analytics data described above relies on Standard Contractual Clauses under DataFast's data processing agreement. Your hydration entries, health data, and on-device profile are never transferred — they stay on your device.
Data Retention
- On-device data — kept until you delete it in the App or uninstall the App.
- Sentry diagnostics — typically retained for about 90 days (our Sentry plan's default), after which it is deleted.
- Superwall analytics — retained in accordance with Superwall's retention policy.
- DataFast analytics — retained in accordance with DataFast's retention policy.
- Expo update logs — retained in accordance with Expo's retention policy.
- AppsFlyer attribution data — retained in accordance with AppsFlyer's retention policy.
- GoMarketMe affiliate data — retained in accordance with GoMarketMe's retention policy.
Your Rights
Everyone can:
- Delete your data — deleting an entry, or uninstalling the App, removes locally stored data. HealthKit data is managed through the Apple Health app; Health Connect data is managed in Health Connect.
- Revoke HealthKit access (iOS) — Settings > Health > Data Access & Devices > WaterChamp.
- Revoke Health Connect access (Android) — Settings > Security & privacy > More privacy settings > Health Connect > App permissions > WaterChamp (on Android 13, open the separate Health Connect app). Permissions can be withdrawn one at a time or all at once.
- Disable notifications — on iOS: Settings > Notifications > WaterChamp; on Android: Settings > Apps > WaterChamp > Notifications.
If you are in the EEA or UK, you also have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with your local data protection supervisory authority. Because we hold no account and cannot identify you from the anonymous analytics, our ability to act on some requests about that specific data may be limited; the data on your device is always fully under your control in the App. To exercise a right, email [email protected].
Children's Privacy
The App is not directed to children. We do not knowingly collect data from children under 16 (or the minimum digital-consent age in your country, which may be as low as 13). If you believe a child has provided data through the App, please contact us.
Changes to This Policy
We may update this policy from time to time. Changes will be reflected in the “Last updated” date above.
Contact
If you have questions about this privacy policy or your data, contact us at [email protected].