WaterChamp Privacy Policy

Last updated: September 17, 2026

WaterChamp (“the App”, “we”, “us”) is a hydration and wellness tracking app. This policy explains what data we collect, how we use it, where it goes, and your rights. We designed WaterChamp to keep your data on your device wherever possible.

Data Controller

The data controller responsible for your personal data is Petr Peller, located in the Czech Republic. You can contact us at any time at support@waterchamp.app.

Data Stored on Your Device

The following data is stored locally on your device only and is never transmitted to us or any external server:

Apple Health (HealthKit)

On iOS, with your permission, the App reads and writes health data via Apple HealthKit:

Reads: Workouts, active energy, steps, and sleep analysis — used to personalize hydration recommendations.

Writes: Dietary water, dietary caffeine, and alcoholic beverages — so your intake appears alongside other health data in Apple Health.

HealthKit data stays within Apple's Health ecosystem on your device. We do not access, store, or transmit your HealthKit data to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the iOS Health permission prompt, which you can withdraw at any time in Settings.

Health Connect (Android)

On Android, with your permission, the App reads and writes health data via Health Connect, the health data store built into Android. The integration is optional — if you do not grant the permissions, the App simply does not use it.

Reads: Exercise sessions, active calories burned, steps, and sleep sessions — used to personalize hydration recommendations.

Writes: Water intake (written as hydration records) and caffeine (written as nutrition records) — so your intake appears alongside other health data in Health Connect.

Alcohol is not written on Android. Health Connect has no record type for alcoholic drinks, so alcohol you log stays on your device, inside the App, and is never written to Health Connect.

Health Connect data lives in the Health Connect data store on your device, under Android's control. We do not access, store, or transmit it to any external server. It is never used for advertising or sold to third parties. Health data is a special category of personal data under GDPR (Article 9); we process it only on your device and only on the basis of the explicit consent you give through the Health Connect permission screen. Each permission is separate, and you can withdraw any of them at any time in Health Connect.

Data Shared with Third Parties

We use the third-party services described below. They receive only the data described in this policy — never your hydration entries, health data, or on-device profile. The App has no login accounts. Notification registrations are linked to a RevenueCat customer identifier, but not to your name, email, Apple ID, or Google account.

Superwall (subscription analytics)

We use Superwall to manage and measure our subscription and paywall. The Superwall SDK receives:

This data is used solely for analytics (understanding subscription metrics) and app functionality (managing subscription status). It is not used for advertising or tracking across other apps. Superwall's privacy policy: superwall.com/privacy

RevenueCat (subscription analytics)

We use RevenueCat to measure our subscription and to decide which set of plans the App offers. The RevenueCat SDK receives:

Purchases themselves do not go through RevenueCat. Apple or Google processes the payment, and RevenueCat receives a record of it afterwards. RevenueCat generates a pseudonymous App User ID. If you allow notifications, we store that ID with your push notification registration so we can associate the registration with the correct subscription customer. We do not enable RevenueCat's advertising-identifier collection. Subscription data supports subscription analytics, plan selection, and matching notification registrations to subscription customers. We do not use this link to track you across other companies' apps or websites. RevenueCat's privacy policy: revenuecat.com/privacy

AppsFlyer (install attribution)

We use AppsFlyer to measure which ads lead to installs of the App. The AppsFlyer SDK receives:

Advertising-identifier collection is disabled on both platforms. The iOS build contains no IDFA code and never shows the App Tracking Transparency prompt; the Android build removes the advertising-ID permission and the SDK runs with advertising-ID collection switched off. Attribution instead uses the Google Play Install Referrer on Android, and on iOS a combination of Apple's SKAdNetwork, Apple's AdServices attribution token, and Google's on-device conversion measurement described below. All of these report at campaign level without identifying you. AppsFlyer never receives your hydration entries, health data, or on-device profile.

Google on-device conversion measurement (iOS). The iOS build includes a Google library that measures whether a Google ad led to the install. It reads the Apple vendor ID and a record of Google ad clicks that Google's own apps keep on your device, and matches the two on the device. The result is an encrypted, aggregated token describing the ad click. The library sends nothing by itself; AppsFlyer passes the token to Google Ads so the ad can be credited with the install. No advertising identifier is used, and the token does not identify you.

This data is used solely for analytics (measuring our ad campaigns). It is not used to track you across other apps. AppsFlyer's privacy policy: appsflyer.com/legal/services-privacy-policy

GoMarketMe (affiliate attribution)

We use GoMarketMe to run an affiliate program: creators share links or offer codes for the App and earn a commission when someone they referred subscribes. The GoMarketMe SDK receives:

If you install the App after opening a creator's affiliate link, GoMarketMe compares technical device information from the App with the link click to decide whether that creator referred you. If you redeem a creator's offer code, the referral is established by the code alone. GoMarketMe never receives your hydration entries, health data, or on-device profile.

This data is used solely to credit the creator who referred you and to pay their commission. It is not used for advertising and not sold. GoMarketMe's privacy policy: gomarketme.co/privacy

Expo (app updates and push delivery)

We use Expo's EAS Update service to deliver bug fixes and small improvements without a full app-store release. When the App starts, the update client contacts Expo's servers (u.expo.dev) to check whether newer app code is available. Expo receives:

This data is used solely to deliver the right update to your device. It is not used for advertising or tracking across other apps. Expo's privacy policy: expo.dev/privacy

DataFast (product analytics)

We use DataFast to count how the App is used. The DataFast SDK receives:

Like every network request, the SDK's requests carry your IP address to DataFast's servers. We never tell DataFast who you are: the App has no accounts and does not call DataFast's identify function. This data is used solely for analytics (understanding which features are used). DataFast's privacy policy: datafa.st/privacy-policy

Sentry (crash and bug diagnostics)

We use Sentry to detect and fix crashes and bugs. The Sentry SDK receives:

We have configured Sentry not to collect your IP address or any personally identifiable information, and we do not set a user identifier, so this data is not linked to you personally. It is used solely to keep the App stable and secure. Sentry's privacy policy: sentry.io/privacy

The one exception is feedback you choose to send us, described next.

Feedback you choose to send

The App has an optional feedback form, reachable from Settings and from the home screen. Nothing is sent unless you fill it in and tap Send.

If you use it, we receive:

These are delivered through Sentry, the same service described above, and we read them there. If you leave the email field blank we have no way to identify you or to reply. If you fill it in, we use it only to reply to you about your message. It is never added to a mailing list, used for marketing, or shared with anyone else.

Unlike the automatic diagnostics above, a message you send with your email address is linked to you, because you chose to tell us who you are.

Android

This section applies to the Android version of WaterChamp. Everything else in this policy applies to both platforms, except where a section says it is specific to iOS.

Purchases go through Google Play Billing. Subscriptions on Android are processed by Google Play. Your payment details go to Google, not to us — we only receive your entitlement status (whether your subscription is active). Google's handling of payment data is described in Google's privacy policy.

Superwall on Android. Superwall (described above) receives the same data on Android, with one difference: instead of the Apple vendor ID, it receives Android device identifiers. It does not receive the Android advertising ID.

RevenueCat on Android. RevenueCat (described above) receives the same data on Android, from Google Play instead of the App Store.

No advertising ID. The App does not collect the Android advertising ID (AAID), just as it does not collect the IDFA on iOS. This includes AppsFlyer: the App removes the advertising-ID permission from the Android build, and install attribution uses the Google Play Install Referrer instead.

Health platform. The Android version connects to Health Connect, not Apple HealthKit — see the Health Connect section above. The Apple Health section applies to iOS only.

Deleting your data on Android. Your hydration entries live on your device, same as on iOS. Delete individual entries in the App, or uninstall the App to remove locally stored entries. Remote push registrations follow the separate removal and retention rules below. Android's automatic cloud backup is turned off for WaterChamp, so no copy of your data exists in your Google account backup — uninstalling removes it completely. Anything already written to Health Connect is managed separately, in Health Connect.

Notifications on Android. The App asks for the Android notification permission before sending hydration reminders. You can turn reminders off in the App's settings, or block them entirely in Android Settings > Apps > WaterChamp > Notifications.

Notifications

The App requests the system notification permission. Hydration and caffeine reminders remain local notifications scheduled on your device.

Push registration. When you allow notifications, the App also registers for remote notification delivery through Expo. Expo receives the native push token and app registration details. Our server, hosted on Cloudflare Workers and D1, stores the Expo push token, a random registration ID, your RevenueCat App User ID, platform, app version, app release channel, and registration/update times. If you change the offers switch, we also store your choice, the time of the change, the version of the consent wording, and whether you made the choice in Settings or onboarding. This links the notification destination to a subscription customer without requiring login or collecting an advertising identifier. Registration requests also use a device-held secret; the server stores only its hash.

Expo and Cloudflare receive your IP address when serving network requests. Our registration database does not store it. We do not send hydration entries, health data, name, email, IDFV, or IDFA in registration requests. If remote notifications are sent, Expo and Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android) process the destination token and notification content to deliver them.

Offers. Allowing the system notification permission does not opt you into promotional messages. Offers remain disabled until you accept them. In onboarding, the offers switch starts on as an unsaved choice. After allowing notifications, selecting Allow offers and continue gives consent to occasional push notifications about WaterChamp offers and discounts. Allowing the system permission alone does not give this consent. You can turn the offers switch off before continuing. You can also accept offers later with the Offers and discounts switch in Settings. You can turn it off at any time, independently of hydration reminders. Your choice applies to this app installation and is not copied through backup and restore. The App shows when your choice is waiting to reach our server; keep the App online to complete the change. We have not yet enabled promotional sending.

Removing a registration. Disable notifications in your device settings, then open WaterChamp while online. The App asks our server to remove the push token and RevenueCat link. If the request fails, it retries when you reopen the App or reconnect. The server retains only registration credentials and ordering information to prevent an older request from restoring the deleted token. Registrations and these deletion records expire after 180 days without an update. Uninstalling alone does not immediately notify our registration server.

The WaterChamp Website

The website at waterchamp.app (including this page) uses the Google tag (gtag.js) to measure whether Google ads lead to visits and app downloads. For visitors in the EEA, the UK, and Switzerland, ad consent defaults to denied: the tag sets no cookies and stores nothing on your device. For visitors elsewhere, Google may set first-party cookies to attribute a visit to an ad click. This data is used solely for measuring our ad campaigns. Google's privacy policy: policies.google.com/privacy

The website also uses DataFast to count page visits: which pages are viewed and which site or search engine the visitor came from. DataFast sets no cookies and stores nothing on your device. Like every web request, the script request carries your IP address to DataFast's servers. DataFast's privacy policy: datafa.st/privacy-policy

The landing page also uses data.dad to count page visits and clicks on the App Store and Google Play links. We use its default cookieless mode. The script sends the page path, referring site, campaign parameters, and store-click goal names to data.dad. Like every web request, these requests carry your IP address to its servers.

Beyond these services, the website uses no analytics or other third-party trackers.

Data We Do Not Collect

Legal Basis for Processing (GDPR)

For users in the EEA and UK, we rely on the following legal bases (GDPR Article 6, and Article 9 for health data):

International Data Transfers

Superwall, RevenueCat, Sentry, Expo, AppsFlyer, and GoMarketMe are based in the United States, so the limited technical data described above is transferred to the US. These transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. Cloudflare processes requests through its global network; its data processing addendum provides safeguards for international transfers. DataFast (JustShipIt Pte. Ltd.) is based in Singapore and hosts most of its infrastructure outside the EU, including in the United States; the transfer of the analytics data described above relies on Standard Contractual Clauses under DataFast's data processing agreement. Your hydration entries, health data, and on-device profile are never transferred — they stay on your device.

Data Retention

Your Rights

Everyone can:

If you are in the EEA or UK, you also have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with your local data protection supervisory authority. Because we hold no account and cannot identify you from the anonymous analytics, our ability to act on some requests about that specific data may be limited; the data on your device is always fully under your control in the App. To exercise a right, email support@waterchamp.app.

Children's Privacy

The App is not directed to children. We do not knowingly collect data from children under 16 (or the minimum digital-consent age in your country, which may be as low as 13). If you believe a child has provided data through the App, please contact us.

Changes to This Policy

We may update this policy from time to time. Changes will be reflected in the “Last updated” date above.

Contact

If you have questions about this privacy policy or your data, contact us at support@waterchamp.app.