← Back to Home

Privacy Policy

Effective Date: January 25, 2026

1. Introduction

This Privacy Policy applies to the theGoodspace mobile application (“Application”), created and operated by Shreyas Krishnamurthy (“Service Provider”) as a commercial service based in India. The Application is provided on an “AS IS” basis. This policy explains how information is collected, used, stored, and protected when you use the Application.

2. Health Data (Apple HealthKit)

The Application integrates with Apple HealthKit to access and analyze health-related data such as sleep, heart rate, heart rate variability (HRV), and activity levels to provide energy predictions and insights.

Prohibited Use

HealthKit data is never used for advertising, marketing, or data mining purposes and is never sold to third parties.

Purpose Limitation

Health data is processed transiently to generate insights and is not retained beyond what is required to provide ongoing features such as energy trends.

3. Information Collection and Use

We collect information necessary to operate and improve the Application, including:

  • Email address (via Google/Firebase authentication)
  • Device and operating system information
  • Approximate location (derived from IP)
  • Application usage diagnostics

4. Artificial Intelligence

The Application uses third-party AI services, including OpenAI and Google Gemini, to generate user-requested insights and task suggestions.

AI services process only user-provided content and application context. Google User Data obtained via OAuth is not sent to or used by AI providers and is never used to train global models.

5. Third-Party Services

The Application relies on the following trusted services:

Google FirebaseRevenueCat

6. Google User Data Policy

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Data Sharing and Disclosure

Google User Data is shared only with Google Firebase for authentication and secure account management. Google User Data is never shared with advertisers, data brokers, or used for marketing, profiling, or personalization.

7. Data Protection Mechanisms

The following safeguards apply to all sensitive personal data, including Google User Data obtained via OAuth authentication:

  • Encryption in Transit: HTTPS / TLS
  • Encryption at Rest: AES-256
  • Access Control: Restricted to authorized personnel
  • Data Minimization: Only the minimum Google User Data required for authentication and essential functionality is accessed or stored.

8. Account and Data Deletion

You may permanently delete your account and associated data through the Application settings or by contacting support.

12. Contact and Grievance Officer

Email: support@brainsugar.studio

Grievance Officer: Shreyas Krishnamurthy