PAPTrack — Privacy Policy

Effective August 31, 2026

PAPTrack is built to work entirely in your browser. This page explains exactly what data exists, where it goes, and who can see it. It covers the web app at eagleadams86.github.io/paptrack; the iOS app has its own policy.

What PAPTrack Stores

The only data the app holds is what you enter about your CPAP supplies: the item names you choose, their cleaning and replacement cycles in days, the dates you last cleaned or replaced each one, how many spares you have and the level at which you want to reorder, anything you type in a supply's notes, and — all optional — a supplier name, a reorder link and what the item costs. Since 22 August 2026 each supply also keeps a short history of what you marked and when: the dates you pressed Mark cleaned, Mark replaced or Mark ordered, up to sixty entries per supply, oldest dropped. It is a record of your own taps, kept on the same terms as everything else here, and it goes wherever the rest of your supply list goes — nowhere at all unless you sign in. Plus your preferences (theme).

Since 22 August 2026 the app can hold more than one list — a profile for each person in a household — and each profile has a short name you choose for it, up to 24 characters. That name stays on this device. It is never sent to sync: a synced list is identified by a random internal id, not by whose list it is, so the names you pick are not part of what leaves the browser. A name does appear in a backup file, because a backup is a copy of what is on the device — and that file goes only where you send it.

There is no account and no usage tracking required to use the app, and nothing about your therapy, your machine's data or your health records is collected: PAPTrack never reads a CPAP device or an adherence report.

Where That Data Lives

In your browser (always). Everything is stored in your browser's local storage on your own device. This is the only copy that exists if you never sign in. Clearing the site's browser data deletes it.

A copy of the app itself, so it opens offline. The page, its stylesheet, this policy and the icon are kept on your device — the same public files anyone can read on GitHub, and nothing else. Your supplies are never put there, nor is anything that arrives from sync. Clearing the site's browser data removes it along with everything else.

Google sign-in / Firestore (optional, off until you choose it). If you tap "Sign In to Sync", your supply list is stored in a Firebase/Firestore database operated by the developer so the same list can appear on your other devices, and Firebase Authentication records your Google account's email address and display name. If you keep more than one profile, each one's list is stored as its own record under your account, labelled with a random id rather than with the name you gave that profile. Access rules restrict every account to its own data — other signed-in users cannot read yours. This only happens if you sign in; the app never does it on its own.

Backups and reminders stay on your device. A backup file downloads straight to your device and is never uploaded anywhere. A calendar reminder is built in the page and handed to your own calendar app — no server is involved in either.

What PAPTrack Does Not Do

When Google’s Code Loads

Only when you ask for it. Nothing of Google’s is fetched on an ordinary visit: open PAPTrack, use it, close it, and your browser never speaks to Google at all. The Firebase and sign-in scripts are downloaded from www.gstatic.com and accounts.google.com the moment you reach for the “Sign in to sync” button — when your pointer arrives on it, when you tab to it, or when you press it — and not before.

There is one exception, and it is the only way this can work: if you are already signed in on this device, the app has to load Firebase as the page opens, because asking Firebase whether your session is still good is the only way to find out. It knows to do that from a note it keeps in your own browser, written every time your sign-in state changes — so signing out stops the requests too, not just the syncing. A browser that has signed in at some point but has no such note yet gets one page load that asks, once, and then settles.

When those requests do happen they tell Google your IP address, your browser’s user-agent and which page asked — the ordinary information any request to any server carries. None of your supplies goes with them, and nothing is stored or synced until you sign in. Until August 22, 2026 this code loaded on every visit; the page said otherwise, which was wrong, and the app was changed rather than the sentence softened.

Your Choices

You can edit or delete anything in the app at any time — "Start again", inside the Back up dialog, removes everything at once. Signing out stops all syncing and leaves the local copy in charge. To have your synced copy deleted from the developer's Firestore database, email eagleadams86@gmail.com and it will be removed.

Changes to This Policy

If this policy changes, the updated version will be posted here with a new effective date.

Contact

eagleadams86@gmail.com