Privacy Policy

How HAPT handles your data — spoiler: mostly it doesn't.

Last updated: May 2026

HAPT is designed to run entirely on your device. Your inventory data — items, photos, locations — never leaves your phone unless you explicitly export a backup. No account is required. No cloud sync happens. A minimal anonymous usage ping (item counts by category, hashed device pseudonym) is sent on each launch for product analytics — no personal data, no inventory content.

1. Overview

This Privacy Policy applies to the HAPT Android application ("the App") published by BrainyUniverse on Google Play, and the associated website at hapt.app. It describes what information the App accesses, why, and how it is handled.

HAPT is an emergency preparedness stock manager. Its core purpose is to work fully offline. As a result, the App processes personal data only to the extent strictly required for the features you choose to use.

2. Data Stored on Your Device

All data you enter into HAPT is stored locally on your Android device using a SQLite database. This includes:

  • Item names, categories, quantities, expiry dates, and notes
  • Photos you attach to items or locations
  • Location names and descriptions
  • App settings and preferences
  • QR Codes that you save after generating them on the app

This data is never transmitted to BrainyUniverse servers, and is not accessible to any third party except as described below.

Backups

When you use the Backup & Restore feature, HAPT creates a ZIP archive on your device's storage. You control where this file goes — sharing it via email, cloud storage, or any other means is your choice. HAPT does not initiate any automatic upload of backup data.

3. Permissions the App Requests

Camera

Used for two features:

  • Barcode scanning — to read product barcodes and look up food information.
  • Item and location photos — to take reference photos you attach to entries.

Camera access is only active when you explicitly open a scanner or photo capture screen. No images are sent to any server.

Storage (Read/Write)

Required to save item photos, QR code labels and to read/write backup ZIP archives. Photos, QR labels and backups remain on your device.

Internet

Used for three features: barcode product lookup, Google Play Integrity license verification, and anonymous startup statistics (described below).

4. Third-Party Services

Barcode Lookup (HAPT API)

When you scan a barcode, the App sends the barcode number to the HAPT backend server, which queries a self-hosted version of the OpenFoodFacts open food database to retrieve product information (name, brand, nutrition data). The request includes only the barcode number and your device's anonymous Bearer token (see Device Authentication below). No personal information, item names, or inventory data are transmitted.

A product snapshot is stored locally so subsequent views of the same product work offline without re-querying. The information can be refreshed upon request.

Device Authentication

HAPT uses Android Key Attestation to register your device with the HAPT backend. During first launch, the app generates a hardware-backed cryptographic keypair on your device, and the server issues a Bearer token — a random UUID stored on your device. This token authenticates all subsequent API calls (barcode lookups, license checks, usage pings). The token is not linked to your identity, Google account, or any personal information. It is necessary for stability, security and avoid abuse.

Google Play Integrity (License Verification)

On every cold start, HAPT verifies it was legitimately purchased from the Play Store using the Google Play Integrity API. The process:

  • Your device generates a signed integrity token on-device via Google Play Services
  • HAPT sends this token to its own backend server
  • The server decrypts the token using a Google API key and checks appRecognitionVerdict
  • The verdict (licensed / not licensed) is cached on your device for up to 30 days
  • No inventory data, photos, or personal information are included in this check

Google's handling of integrity data is governed by the Google Privacy Policy.

Billing & License Status

HAPT tracks trial and purchase status server-side. This involves the following data:

  • Your Android device ID — a hardware identifier provided by the Android OS, not linked to your Google account or personal identity — is used as a pseudonymous key to record trial start date and license state on the HAPT backend.
  • When you complete a purchase, the purchase token issued by Google Play is sent to the HAPT server. A one-way SHA-256 hash of that token is stored to confirm your device holds a valid purchase. The raw token is never retained.
  • Your trial status, days remaining, and license state are cached locally in the app's private storage (SharedPreferences) on your device.

No payment card details, Google account information, or purchase amounts are transmitted to or stored by BrainyUniverse. All payment processing is handled exclusively by Google Play.

Anonymous Usage Statistics

On every cold start, HAPT sends a silent background ping to the HAPT server. This ping includes:

  • A hashed device identifier — derived from the Bearer token using SHA-256. This is a pseudonym that allows aggregating data per device. It cannot be reversed to identify you or your device, and is not linked to your Google account or any personal information.
  • Your total item count and a count per category (e.g. "food: 30, water: 5, medicine: 4"). No item names, expiry dates, locations, barcodes, or any content is transmitted. The information is collected for statistical purposes.
  • A server-side timestamp.

This data is used solely for understanding how HAPT is used (inventory size, which categories are most used). It is automatically deleted after 90 days. It is not sold or shared with any third party.

The ping is fire-and-forget: it runs in the background, never blocks the app, and silently discards all errors including network failures.

5. Data We Do NOT Collect

  • No advertising SDKs are included in the App
  • No crash reporting or diagnostic frameworks
  • No behavioural tracking, session recording, or user profiling
  • No account registration or profile data
  • No location (GPS) data
  • No item names, descriptions, barcodes, expiry dates, photos, or any inventory content

6. Data Retention

All data is retained solely on your device for as long as the App is installed, or until you delete individual items or perform a factory reset. Uninstalling HAPT removes all associated databases from your device. Backup files you have exported to external storage are not deleted by uninstallation.

7. Children's Privacy

HAPT is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal information through HAPT, please contact us using the address below. In any case it is important to assert, no type of information provided would reach HAPT.

8. Changes to This Policy

If this policy changes materially, the updated version will be published on this page with a revised date. Continued use of the App after changes constitutes acceptance of the updated policy.

9. Contact

Questions about this policy: