Sibaq

Privacy policy

Effective 3 September 2026. Applies to the Sibaq mobile app and its server, operated by Modern Digital Optimization SPC. Sibaq is in a closed beta; this policy describes what the software does today and will be updated when that changes.

The short version

What Sibaq reads

Sibaq connects to one health source per person, with your explicit consent, and reads only the metrics needed for the challenges you join:

MetricWhat is readWhat is kept
StepsDaily step totals for exact challenge-timezone daysOne integer per day, or a gap when the source had no data
Runs and ridesCompleted sessions: sport, start and end, active duration, distance when attached, indoor or outdoor, whether it was recorded automatically or entered by handThose fields as integers, with an opaque record identity so corrections replace rather than duplicate
SleepSleep sessions and the intervals within them marked as asleepAsleep duration per night and whether the night met the challenge target; sleep-stage streams are discarded

Sibaq does not read or keep GPS routes, heart-rate series, calories, blood oxygen, weight, body battery, or any raw provider payload. Those values do not enter the server, the app's logs, or its analytics.

Sources

Today Sibaq reads from Android Health Connect on the device you install it on. Support for Apple HealthKit and for Garmin Connect through Garmin's own cloud program is planned and is not available yet. A source appears in the app only after the server has been configured to accept it. When more than one source is connected, you choose which one counts for each challenge. Sibaq never adds two sources together.

What other participants see

A challenge is private. Only people who joined it through its invite can see it. Within a challenge, other members see your display name, your derived daily values for the challenge metric, your total, your rank, and whether your data is fresh, stale, or missing for a day. Sharing requires a separate, versioned consent step inside the app; if the disclosure changes, you are asked again before anything new is shared.

Other members never see your source records, timestamps within a day, the app or device that produced a number, your provider account identifier, or anything about metrics the challenge does not use.

Account data

To run your account Sibaq keeps an authenticated subject identifier, a display name, the challenges you belong to and their rules, invite codes in hashed form, and the record of which sharing disclosure you accepted and when. Invite secrets are never stored in plain text after they are shown to you once.

Sync and operational data

To sync safely and to explain gaps, the server keeps sync attempt identities, per-metric permission state, the time windows a source was actually accessible for, and opaque provider cursors. These are used to retry correctly and to label a day as covered, stale, or missing. They are never shown to other participants.

Operational logs hold request identifiers, route templates, status codes, latency, and error categories for at most 30 days. They are written through an allow-list that excludes health values, record identifiers, timestamps of health events, and provider labels. Statement logging is disabled on databases that hold real data.

On your device

The app keeps a small encrypted journal of sync state, protected by a hardware-backed key that never leaves the device and excluded from backups. It contains cursors and the exact pending upload, so a sync that was interrupted can be retried without reading your health source again. Disconnecting a source or deleting your account destroys that key.

Retention and deletion

Who else receives data

Sibaq uses no analytics SDK, no advertising SDK, and no third-party trackers, in the app or on this website. This website loads nothing from other hosts. It is served by Firebase Hosting, a Google service, which keeps ordinary web-server logs such as the requesting IP address and the page requested; Sibaq does not read those logs for tracking. If a hosting or database provider is engaged for the app's server in production, it will be named here before real user data reaches it.

Children

Sibaq is not intended for anyone under 18 and does not knowingly hold data about them.

Changes

The effective date at the top changes whenever this text changes. If a change affects what other participants can see, the app asks for your consent again before sharing anything new.

Contact

Questions or requests about your data: nasserbusaidi@gmail.com.