Effective Date: August 24, 2026
Last Updated: September 26, 2026 (added Fitbit data section and clarified the full list of Health Connect data types)
Welcome to Tabs. We take your privacy seriously. This Privacy Policy explains how Tabs ("we," "us," or "our") collects, uses, stores, processes, and shares information when you use our mobile application ("App") and associated backend services.
When you create an account, we collect your email address and password (securely hashed) to authenticate your access, secure your data, and sync it across your devices.
If you explicitly grant permissions, Tabs accesses wellness and health data from Google Health Connect. Depending on the permissions you approve, this can include: steps, heart rate, resting heart rate, heart rate variability (HRV), sleep sessions, calories burned, basal metabolic rate (BMR), weight, height, respiratory rate, blood oxygen saturation (SpO2), blood pressure, power, and historical health data access. This health data is synchronized and stored on our backend servers to enable cross-device sync and power our AI-driven wellness insights. We do not sell this data to third parties, nor do we use it for advertising.
If you connect your Fitbit account, Tabs uses Fitbit OAuth to access your Fitbit data with your explicit consent. The Fitbit scopes we request are: activity, heart rate, sleep, profile (basic profile information), weight, oxygen saturation, and respiratory rate. Fitbit data is synchronized and stored on our backend servers alongside your Health Connect data to provide heart-rate spike detection, trend analysis, and AI-driven wellness insights. You can revoke Fitbit access at any time from within the App (Settings > Connected Apps) or from your Fitbit account settings at fitbit.com, which stops future data syncs. We do not sell Fitbit data to third parties, nor do we use it for advertising.
We collect the logs, categories, and custom notes you write within the App to provide the core logging and notepad functions.
If you upload PDFs, text files, or other documents to the "Knowledge Base," these files are transmitted to and stored on our servers to extract context for your personal AI model.
The App requests access to specific device features to enable core functions:
We use your information, including health metrics and uploaded documents, to provide personal health summaries and AI-driven insights. Specifically, your data (including health details and document text) is transmitted to the Google Gemini API for processing to generate summaries of your logs and notes. This processing is subject to Google's Gemini API Terms of Service. Under paid API configurations, Google does not use your content to train Google models; however, free-tier API usage may allow Google to use inputs for model improvement. You should review Google's Gemini API privacy documentation for details on your active deployment's data usage.
We share data only with trusted service providers necessary to operate the App:
We retain your personal information, user-generated logs, and documents as long as your account remains active. You can delete your account and all associated data at any time, which will initiate the deletion of your records from our active databases.
You have full control over your data. You can:
We implement security measures to protect your data, including encrypting data in transit using Transport Layer Security (TLS) and utilizing secure server configurations. Locally, Android key storage is secured using the Android Keystore System.
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at support@notel.com.