Back to Barometer

Privacy policy

Service: Barometer

Updated 26 September 2026

Barometer helps you record mood and chosen conditions, review personal outlooks, and optionally learn from your records. This page explains where each kind of information goes and what the available controls do. For service and privacy questions, use the contact address below.

Records on your device

Your mood ratings, chosen conditions, notes, actions, weather cache, and record books are stored on your device by default. The app's local Hive storage is not separately encrypted by Barometer; device and operating-system protections are distinct. Other people with access to your unlocked device or browser profile may be able to access local data. You can delete local records in Settings. That action keeps your account, cloud backups, privacy choices, and app preferences.

Sign-in and account

Google sign-in is optional. When you sign in, our server stores your Google provider identifier and, when supplied, email address, name, and profile-picture URL, as well as account sessions and privacy-jurisdiction selections. These are used to identify your account and provide backup and account controls. Deleting the account removes its account record and sessions from the application database.

Optional encrypted cloud backups

If you choose Backup now, the app encrypts a backup on your device with your backup password before upload. The server stores the encrypted payload and account-linked metadata such as creation time, device identifier, size, and checksum; it cannot verify your password or read the backup contents through the backup service. Backups are accessible for seven days after upload. An hourly maintenance job removes expired rows, so physical removal may happen later than the access cutoff. If you lose the password, that encrypted backup cannot be restored. Local records may still be available on your device. A separately exported JSON file may be unencrypted if you choose not to set a password; copies you download remain your responsibility.

Optional app analytics

The Flutter app asks you to choose in Settings before optional Firebase app-usage events are sent. Declining or leaving the choice unset keeps optional analytics off. If enabled, events can include screens, actions, and technical context with a pseudonymous identifier; recorded mood values, record dates, and free-text notes are excluded. You can turn this off in Settings. This stops new optional events but does not itself delete events already sent to Firebase. This choice is separate from the landing-page choice and from model-comparison sharing. Firebase may process enabled analytics data under its own service terms.

Optional landing-page analytics and hosting

This website has its own analytics choice. Firebase landing-page events are sent only after you select Allow analytics here; declining or not choosing leaves them off. The app's analytics choice does not apply to this website. Cloudflare hosts the website and may process necessary request and network metadata. The separate Cloudflare Web Analytics beacon is disabled in the site's deployment settings.

Optional model-comparison summaries

A separate Share model comparison results switch is off by default and requires sign-in. After an encrypted backup succeeds, it can send bounded numeric summaries from the current record book to our server. The summaries exclude raw mood, weather, dates, notes, and personal model files, but are linked to your account and readable by the server; they are not part of the encrypted backup or Firebase analytics. A summary remains eligible for up to seven days with its source backup. Turning sharing off deletes its server summary; if offline, the app stops new uploads and retries deletion on a later connection.

Optional external learning runner

If you separately enable a personal-computer or server learning runner, it receives data scoped to the selected record book, including numeric observations and dates or times; free-text notes are excluded. Runner jobs may be retained for up to 24 hours. A separately approved fixed model may be retained for up to 30 days. Cancelling a job may leave resumable job data until its retention limit. Deletion requests made while offline or while the runner is unavailable remain pending and are retried when it reconnects.

Optional weather and location

Weather is optional. Weather requests can send coordinates or city search terms to Open-Meteo. Reverse geocoding can send coordinates to BigDataCloud. These requests serve weather and place lookup and are separate from model-summary or analytics sharing.

Page resources and fonts

The site and app may load Google Fonts for display. Those technical font requests can reveal network metadata to Google, but they do not include your mood entries or notes. Basic hosting requests are separate from optional analytics consent.

Deletion choices

Deleting local records leaves your account and cloud backups. Deleting cloud backups removes the account's backups and shared model-comparison summary, turns that sharing off, and invalidates account sessions, while local records and the account remain. Deleting the account removes the account, backups, summaries, and sessions, while records on this device remain. Turning off model-summary sharing deletes that summary but keeps backups. These application actions do not automatically erase analytics already sent to third-party services or earlier hosting telemetry. Downloaded exports cannot be recalled by the app or server. For a request about previously sent information, use the contact address below; handling depends on the processor's settings and policies.

Contact and requests

For privacy questions or a request about your information, contact support@bonayo.app

Google operates sign-in and Firebase. See the Google Privacy Policy and Firebase privacy information for provider practices. For current analytics settings or a request concerning previously sent data, contact Barometer above.