Oxford Fitness

Privacy Policy

AccuRate Heart Rate Monitor and CardioCare
Effective: 14 August 2026  ·  Last updated: 15 August 2026

The short version: your health readings stay on your phone. Blood pressure, heart rate, weight, notes, habits and your profile are stored in a database on the device and are never sent to us. What does leave the device is a small amount of technical information used to run, measure and (in Heart Rate Monitor only) advertise the apps, described in full below.

This policy explains what Oxford Fitness Ltd ("we", "us", "our") does with your information when you use:

It does not cover our other apps or websites except where they link here. The Terms of Use are a separate document.

1. Who we are

Oxford Fitness Ltd is the data controller for the purposes of the UK GDPR and the EU GDPR.

PublisherOxford Fitness Ltd
Contact for privacy and all other enquiriesrepsiapp@gmail.com

We have not appointed a Data Protection Officer; we are not required to. Write to the email above for anything to do with your data and a person will read it.

2. What the apps store on your device

The following is written to storage on your phone, inside the app's own private area. It is not uploaded to us, and we have no way to read it.

Both apps

CardioCare only

Health and measurement records

Your profile and questionnaire answers

Habits and routines

Further preferences

The camera

A heart rate measurement works by looking at the colour of your fingertip through the camera while the flash is on. Those camera frames are analysed in memory as they arrive and are never written to storage, never saved as a photo or video, and never transmitted anywhere. Only the resulting number — and, in CardioCare, the derived waveform — are saved, and only on your device. Camera access is used for this and nothing else. The rest of each app remains available if you decline the permission.

Device backup

The apps allow the platform's standard backup. Depending on your device settings, Android may include app data — including your health records — in the automatic backup to your own Google account. On iOS, Heart Rate Monitor data may be included in an iCloud backup to your own Apple ID. That backup is between you and Google or Apple; we have no access to it. You can turn device backup off in system settings, or exclude individual apps where your device offers that option.

3. What leaves your device

Health values never leave the device except if you export or share them (for example a CSV file from CardioCare, or an optional write to Google Fit from Heart Rate Monitor). The technical information below goes to the named providers acting as our processors or, for advertising in Heart Rate Monitor, as independent controllers of their own ad systems.

CardioCare — Google Analytics for Firebase

We record which screens are opened and which actions are taken, so we can see where the app is confusing or broken. Examples of events we record: a measurement was started, finished or failed (and the technical reason it failed); a blood pressure or weight entry was saved; an article was opened or finished; a habit was marked done; the questionnaire was started, a question was skipped, or it was completed; the subscription screen was shown, dismissed or purchased from.

These events carry no health values. We never send your blood pressure numbers, heart rate, weight, age, questionnaire answers, notes or tags. An event records that something happened, not what it said.

Firebase also collects standard technical information automatically: a randomly generated app instance identifier, device model, operating system version, app version, language, and coarse country-level location inferred from your IP address. Firebase does not store your full IP address for analytics purposes.

CardioCare — Firebase Crashlytics

If the app crashes, a report is sent containing the crash stack trace, device model, OS version, app version and a randomly generated installation identifier. It does not contain your health records.

CardioCare — Firebase Performance Monitoring

Anonymous timing information about how quickly screens and network calls complete, with the same category of device information.

CardioCare — Firebase Remote Config

The app asks Google's servers for configuration values that let us change behaviour without shipping an update. This request sends the app instance identifier and device information; it sends nothing about you.

CardioCare — Google Play Billing

If you subscribe, the purchase is handled entirely by Google Play. Your payment card, billing address and Google account details are given to Google, not to us. We never see them. The app stores only a yes/no flag recording whether a subscription is currently active, and re-checks that with Google Play at each launch.

Heart Rate Monitor — analytics

We use Google Analytics (including Google Analytics for Firebase where enabled) to understand how the app is used: how often it is opened, which screens are visited, and similar usage information. This includes a randomly generated identifier, device and app version information, and coarse country-level location inferred from IP address. We use this only to improve the app. It does not include your heart rate values, notes or labels.

Heart Rate Monitor — advertising

Heart Rate Monitor shows ads. We use third-party advertising services including Google AdMob and Meta Audience Network. These services may use cookies or similar identifiers, mobile advertising IDs, and coarse location data for interest-based advertising and measurement. Where a consent prompt is shown in the app, ads that rely on consent are served only after you agree. You can also limit ad tracking in your operating system settings (Android advertising / ad-personalisation settings; iOS Tracking and Privacy settings).

CardioCare does not show advertising and does not use advertising identifiers.

Heart Rate Monitor — Google Fit (optional)

We do not receive information from Google APIs. You may choose to send a heart rate reading to Google Fit on your own account. That write is between you and Google and is subject to the Google API Services User Data Policy, including Limited Use requirements. You can stop this at any time by disconnecting Google Fit in the app or in Google settings.

What we do not do

Voluntary emails you send us (feedback or bug reports) are read by us to reply. We do not sell that correspondence or share it with advertisers.

5. How long it is kept

6. Where it goes

Google processes analytics, crash, performance, configuration, billing and (for Heart Rate Monitor) advertising data on servers in the United States and elsewhere. Meta processes advertising data for Heart Rate Monitor in the same way. Where that involves a transfer out of the UK or the EEA, it is covered by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which those providers incorporate into their terms.

Their own policies apply to how they handle data as processors or independent controllers:

7. Your rights

If you are in the UK or the EEA

Under the UK GDPR and the EU GDPR you have the right to: be told what we hold; get a copy of it; have it corrected; have it erased; restrict how we use it; object to processing based on legitimate interests; receive it in a portable form; and withdraw consent at any time without affecting what was done before.

In practice, most of these you can exercise yourself and immediately: the health data is on your phone, so you can read it, correct it, and delete it, without asking anyone. CardioCare can also export records as a CSV file from Settings. For analytics, crash and advertising data, write to repsiapp@gmail.com. We will respond within one month.

You can complain to the Information Commissioner's Office (ico.org.uk) if you are in the UK, or to your national supervisory authority if you are in the EEA. We would rather you told us first, but you are not obliged to.

If you are in California

Under the CCPA as amended by the CPRA:

Everyone

You can stop analytics, crash, performance reporting and ads by uninstalling the app. If you want analytics stopped while you keep using the app, write to us at repsiapp@gmail.com and say so.

8. Children

These apps are not intended for children under 13, and we do not knowingly collect information from them.

If you are in the UK or the EEA and are under 16 — or under whatever age your country sets, which may be as low as 13 — you need a parent or guardian's permission to use the apps. If you believe a child has used an app without that permission, write to repsiapp@gmail.com and we will act on it.

9. Security

Your health records live in the app's private storage, which the operating system keeps separate from other apps and, on a device with a screen lock, encrypts at rest. The main practical risks are the ones you control: keep a screen lock on your phone, and think before you share an exported file — once you have sent it, it is out of the app's protection and in whatever app or inbox you sent it to.

No system is perfectly secure, and we do not claim otherwise.

10. Not a medical device

AccuRate Heart Rate Monitor and CardioCare are wellness and self-tracking tools. They are not medical devices, their readings are not diagnoses, and nothing in them is a substitute for professional medical advice. The camera-based heart rate measurement is an estimate. See the Terms of Use for the full statement.

11. Changes to this policy

If we change this policy we will post the new version at https://oxford-fitness.com/privacy.html and update the date at the top. If a change materially affects how your information is handled, we will tell you in the relevant app before it takes effect.

12. Contact

repsiapp@gmail.com

Oxford Fitness Ltd