Back to Privacy Hub

WristBridge: Wear OS Data Privacy Policy

Last Updated: August 25, 2026

Quick Summary

A local-first Android + Wear OS data-to-complication utility in development. Source definitions and cached values are stored on the user devices, REST acquisition happens on the phone, and WristBridge does not require a developer-operated cloud backend for its current V1 architecture.

App-Specific Details

Specific data handling practices for WristBridge: Wear OS Data.

  • Stores source definitions, bounded source snapshots/status, presentation configuration, watch bindings, sync state, and limited local activation/billing state on the user devices.
  • The Android phone can make user-configured HTTPS REST/JSON GET requests; the Wear app does not perform remote acquisition during complication rendering.
  • REST credentials are protected on the phone with Android Keystore-backed encrypted storage and are not synchronized to the watch.
  • Phone-to-watch source state is synchronized through Google Play services Wear Data Layer; the watch renders complications from its local Room replica.
  • The current baseline contains no WristBridge account, developer-operated cloud backend, advertising SDK, third-party analytics SDK, or third-party crash-reporting SDK.
  • Google Play Billing is present in the phone application for the planned one-time Pro entitlement and Google may process purchase/technical information under its own policies.
  • Clearing app storage or uninstalling WristBridge removes local app-owned data on that device; data already sent to a user-configured REST endpoint is controlled by that endpoint operator.

Detailed Official Policy

Full technical and legal disclosure for WristBridge: Wear OS Data.

# WristBridge: Wear OS Data Privacy Policy Last updated: August 25, 2026 ## Overview WristBridge is an Android and Wear OS utility that turns user-controlled values into native Wear OS complications. This policy describes the current V1 implementation and release architecture while the app is still in production qualification. WristBridge is designed to work without a WristBridge account or developer-operated cloud backend. The current baseline does not include advertising, a third-party analytics SDK, or a third-party crash-reporting SDK. ## Data stored on your devices WristBridge may store the following app data locally on the Android phone: - source definitions and source type; - manual or Tasker-provided values; - the latest valid source snapshot and bounded source-health/error category; - presentation and freshness configuration; - limited local onboarding/activation counters and preferences; - cached Google Play entitlement category and verification time; - encrypted REST endpoint credentials or authentication material when a configured source requires them. The Wear OS application stores a bounded local replica of source state needed for watch UI and complication rendering, plus watch-local complication bindings and freshness state. WristBridge uses Room and other app-private Android storage for these functions. Android backup is disabled in the current phone and Wear manifests. ## REST/JSON sources The Android phone application declares Internet access so the user can configure supported REST/JSON sources. The current V1 REST path is read-only and uses HTTPS GET requests. It applies bounded timeouts, redirects, response sizes, JSON discovery/extraction, and scalar sizes. Cleartext HTTP is not supported in the current production path. REST requests go directly from the user's Android phone to the endpoint the user configures. WristBridge does not proxy source requests through Quazmoz infrastructure. The Wear OS application does not perform REST acquisition. A complication request reads only the watch-local persisted replica. ## REST credentials and secrets REST authentication secrets are stored only on the phone through Android Keystore-backed encrypted storage. They are not synchronized to the watch. The current security design keeps secret material out of normal sync payloads and sanitized diagnostics. Raw credentials, authorization headers, purchase tokens, source values, and JSON bodies are not intended to appear in the privacy-safe support diagnostics. ## Tasker integration WristBridge includes a Tasker/Locale setting plug-in surface so a user can send a value to a configured source. The exported Tasker ingress is authenticated with an app-generated per-source capability before source mutation. Tasker-provided values are stored locally as source state and can be synchronized to the paired watch for complication display. WristBridge does not send Tasker values to a WristBridge-operated server. ## Phone and Wear OS synchronization WristBridge uses Google Play services Wear Data Layer to synchronize bounded, versioned source state between the Android phone and paired Wear OS device. The synchronized payload can include source identity, presentation-safe source data, status, revision metadata, and the latest valid snapshot needed on the watch. REST credentials are deliberately excluded. The watch keeps a local Room replica so a supported complication can continue to show truthful cached state during a temporary phone or network disconnect. A failed acquisition preserves the last valid snapshot rather than replacing it with fabricated current data. Google and the Android/Wear OS platform may process technical information when providing Play services, app distribution, updates, pairing, synchronization, and complication functionality under their own policies. ## Google Play Billing The Android phone application includes Google Play Billing support for the planned one-time WristBridge Pro entitlement. Google Play handles purchase UI and payment processing. WristBridge may receive purchase state and entitlement-related information from Google Play as needed to verify and acknowledge the purchase. The current app design stores only a bounded entitlement category and verification timestamp locally rather than persisting raw purchase tokens or order/account identifiers in normal app state. WristBridge does not receive payment-card or bank-account details. ## Analytics, advertising, and diagnostics The current V1 baseline contains no third-party analytics SDK, advertising SDK, or third-party crash-reporting SDK. Product-quality evidence is intended to come from Google Play Android Vitals, privacy-safe local counters, sanitized user-triggered diagnostics, and beta/support feedback unless a later release explicitly changes this posture. WristBridge's diagnostic contract intentionally excludes raw source values, REST URLs, credentials, authorization headers, JSON responses, Tasker values, purchase tokens, and order/account identifiers. ## Data sharing WristBridge does not sell user data and does not send source values to a WristBridge-operated backend. Data can leave the user's devices in these cases: - the Android phone sends a request to a REST/JSON endpoint the user configured; - Google Play and Google Play services process information required for app distribution, billing, pairing, synchronization, and other platform functions; - the user intentionally exports or shares a sanitized support diagnostic. The operator of a user-configured REST endpoint controls what happens to data after it reaches that endpoint. ## Permissions The current Android phone source manifest explicitly requests Internet access for REST/JSON acquisition. Google Play Billing and other libraries may contribute additional normal platform manifest entries when the final package is merged. The current Wear source manifest declares no runtime permission. The Wear app uses native complication APIs, local Room state, the Wear Data Layer, and a non-exact local freshness mechanism. The current source does not request location, microphone, camera, contacts, storage/media, health/body-sensor, AccessibilityService, exact-alarm, or background-location permissions for WristBridge. ## Retention and deletion Source configuration and cached source state remain local until the user deletes the source, clears app storage, or uninstalls the application, subject to the app's sync/tombstone correctness rules while paired devices reconcile state. Clearing Android app storage or uninstalling WristBridge removes the app-owned local data on that device. Because WristBridge has no developer-operated account database in the current V1 design, there is no WristBridge server-side account dataset to request deletion of. Deleting local WristBridge data does not delete information that was already processed or retained by a REST endpoint the user chose; that endpoint must be managed under its own controls and privacy policy. ## Children WristBridge is a general-purpose customization/utility product and is not directed to children. The current architecture does not operate a hosted user-profile service for children. ## Changes to this policy This policy will be updated before shipping functionality that materially changes data collection, sharing, analytics, advertising, cloud processing, authentication, permissions, or external provider behavior. ## Contact For privacy questions, contact Quazmoz@vivaldi.net.

General Privacy Terms

These terms apply across all our applications.

Questions or privacy requests? Contact us at Quazmoz@vivaldi.net