HushLog · Privacy

Privacy policy

How HushLog accesses and protects sleep-sound, health, and journal data in the Free V1 app.

English

Overview

Effective 2026-09-15. HushLog is provided by HushLog (“we”). HushLog is a local-first sleep-sound journal. It is not a medical device and does not diagnose, prevent, monitor, predict, treat, or cure any disease or condition.

Information HushLog accesses and stores

When you start a recording, HushLog accesses your device microphone, stores audio in app-private storage, and processes the audio on the device to identify candidate sound moments.

The app may also store session times, event labels and corrections, notes, mood, factors, custom labels, favorites, recording context, body weight, neck measurement, and one respiratory-rate value you choose to save.

Collection, sharing, and third parties

HushLog does not require an account and contains no advertising. It uses Google Analytics for Firebase to measure app launches, engagement, and feature usage, and Firebase Crashlytics to receive crash and stability reports. These services may send an app-installation identifier, app interaction events, an approximate geographic region derived from an IP address, app/version information, general device and operating-system information, crash traces, and related diagnostics to Google as our service provider.

We do not attach your name, email address, recordings, sound-event content, notes, factors, body measurements, Health Connect data, or exported files to Analytics or Crashlytics events. Advertising-ID collection and ad-personalization signals are disabled. HushLog does not automatically transmit recordings or night history to us, advertisers, or data brokers, and we do not sell personal or sensitive data.

If you deliberately export, share, or back up information, Android sends it only to the app, person, or storage destination you choose. That recipient’s privacy practices then apply.

Health Connect

Health Connect access is optional and separately initiated by you. With permission, HushLog can write only a reviewed time-in-bed interval, read a nearby weight for review, or read one respiratory-rate sample within the reviewed interval.

HushLog does not send audio, events, names, notes, mood, factors, neck measurements, or recordings to Health Connect. It performs no automatic or background Health Connect synchronization.

Storage and security

Audio is stored in app-private no-backup storage. Android automatic backup and device transfer can include only four non-history settings files: appearance, recording plan, storage retention, and time-in-bed target. Cloud backup additionally requires device encryption capability. Recordings, the event database, app-lock state, permission/disclosure state, alarms and reminders, playback state, diagnostics, and recording recovery state are not included. Manual history backups use AES-256-GCM authenticated encryption and a passphrase you choose.

An optional app lock can hide the interface, screenshots, and recent-app previews until your device screen lock is confirmed. It protects the interface; it does not mean every local file is individually encrypted. No storage method is completely secure, so protect your device and backup passphrase.

Retention and deletion

You control audio-retention and storage-limit settings. HushLog can delete eligible old, unprotected audio while retaining a non-audio summary. You can delete one night’s audio, a whole night and summary, unprotected audio in bulk, the local activity log, or all HushLog local data.

Removing the app removes its app-private data under Android’s normal behavior. Exports and backups outside HushLog must be deleted from their destination by you. Health Connect records are managed in Health Connect. Analytics and Crashlytics data is retained according to the Firebase project settings and Google’s service terms; Crashlytics states that crash traces and associated identifiers are retained for 90 days before removal begins. You may contact us about a privacy request at the address below.

Permissions

HushLog requests microphone access for user-started recording; notifications and foreground-service access for visible recording, playback, and alarm status; alarm/full-screen access for a wake alarm you configure; and optional Health Connect permissions for the actions above.

Permissions are requested in context and can be changed in Android settings. Refusing or revoking a permission can make its related feature unavailable or less reliable. Internet access is used for Analytics and Crashlytics reporting and, in a Pro build, Google Play Billing. It is never used to upload recordings or journal content automatically.

Children

HushLog is intended for people aged 18 and older. It is not directed to children below that age. The Play Console target-audience selection must match this statement.

Changes and contact

We may update this policy when HushLog’s behavior, SDKs, or applicable requirements change. The effective date above identifies the current version.

Developer
HushLog
Privacy contact
ringtone.sky@gmail.com
Policy URL
https://hushlog-privacy.rainy-dill-4301.chatgpt.site/

简体中文

概述

生效日期:2026-09-15。HushLog 由 HushLog(“我们”)提供。HushLog 是一款本地优先的睡眠声音记录工具,不是医疗设备,也不诊断、预防、监测、预测、治疗或治愈任何疾病或健康状况。

HushLog 访问和保存的信息

当你主动开始录音时,HushLog 会访问设备麦克风,把音频保存在应用私有存储中,并在设备本机处理音频以识别候选声音时刻。

应用还可能保存会话时间、事件标签和纠正、备注、感受、因素、自定义名称、收藏、录音环境、体重、颈围,以及由你选择保存的一条呼吸率数值。

收集、共享和第三方

HushLog 不要求注册账号,也不含广告。应用使用 Google Analytics for Firebase 统计启动、使用参与度与功能使用情况,并使用 Firebase Crashlytics 接收崩溃与稳定性报告。这些服务可能把应用安装标识符、应用交互事件、由 IP 地址推导的大致地理区域、应用/版本信息、通用设备与操作系统信息、崩溃堆栈及相关诊断数据发送给作为服务提供商的 Google。

我们不会在 Analytics 或 Crashlytics 事件中附加你的姓名、邮箱、录音、声音内容、备注、因素、身体测量、健康数据或导出文件。广告标识符收集和广告个性化信号已关闭。HushLog 不会自动把录音或夜间历史发送给我们、广告商或数据经纪商,我们也不出售个人或敏感数据。

只有当你明确选择导出、分享或备份时,Android 才会把信息发送到你选择的应用、人员或存储位置;之后适用该接收方的隐私做法。

健康数据共享

健康数据共享完全可选,并由你分别发起。授权后,HushLog 只能写入一段经你复核的在床时间,读取附近的一条体重供你确认,或读取复核区间内的一条呼吸率样本。

HushLog 不会把音频、声音事件、姓名、备注、感受、因素、颈围或录音发送到健康数据共享服务,也不会自动或在后台同步健康数据。

存储与安全

音频默认保存在应用私有且不参与备份的存储中。Android 自动备份和设备迁移只能包含四类非历史设置:外观、录音方案、存储保留策略和卧床时长目标;云备份还要求设备具备加密能力。录音、事件数据库、应用锁状态、权限/披露状态、闹钟与提醒、播放状态、诊断和录音恢复状态均不包含。手动历史备份采用 AES-256-GCM 认证加密和由你设置的口令。

可选应用锁能在设备锁屏凭据确认前隐藏界面、截图和最近任务预览。它保护界面,但不表示每个本地文件都单独加密。没有任何存储方式绝对安全,请保护设备和备份口令。

保留与删除

你可以控制音频保留期和存储上限。HushLog 可以删除符合条件的旧且未保护音频,同时保留不含音频的摘要。你也可以删除单晚音频、整晚及摘要、批量未保护音频、本地活动日志或全部 HushLog 本地数据。

卸载应用会按 Android 的正常机制移除应用私有数据。导出或备份到 HushLog 外部的文件需要由你在目标位置删除;健康数据共享记录需要在相应系统服务中管理。Analytics 与 Crashlytics 数据按 Firebase 项目设置及 Google 服务条款保留;Crashlytics 说明,崩溃堆栈及相关标识符会保留 90 天,之后开始移除。你可通过下方邮箱提出隐私请求。

权限

HushLog 为用户主动开始的录音申请麦克风权限;为可见的录音、播放和闹钟状态申请通知及前台服务权限;为你配置的唤醒闹钟申请闹钟和全屏显示权限;并为上述可选健康操作申请相应权限。

权限会在相关场景中申请,也可在 Android 设置中更改。拒绝或撤销权限可能使对应功能不可用或降低可靠性。互联网访问仅用于 Analytics、Crashlytics 报告,以及 Pro 版本中的 Google Play Billing;不会用于自动上传录音或日志内容。

儿童

HushLog 面向 18 岁及以上用户,不以低于该年龄的儿童为目标。Play Console 中的目标受众选择必须与本说明一致。

更新与联系

如果 HushLog 的行为、SDK 或适用要求发生变化,我们可能更新本政策。以上生效日期用于标识当前版本。

开发者
HushLog
隐私联系邮箱
ringtone.sky@gmail.com
政策网址
https://hushlog-privacy.rainy-dill-4301.chatgpt.site/