Privacy Policy

Privacy Policy

Last updated: 7 August 2026

richardorchard.com is Richard Orchard's personal website. This policy explains what data the site collects, and in particular how it uses Google user data through the Google Health API integration that powers the "Currently" health panel.

Who operates this site

Richard Orchard, Perth, Western Australia. Contact: me@richardorchard.com.

Google Health data

The site includes a small "Currently" panel showing recent activity and recovery stats — steps, active zone minutes, resting heart rate, and sleep duration/efficiency. This data is read from the Google Health API for one account only: the site owner's own account (richardorchard1975@gmail.com). No other person's Google account is ever connected to this integration, and the site does not offer this feature to visitors.

The integration requests the following read-only scopes:

  • googlehealth.activity_and_fitness.readonly
  • googlehealth.sleep.readonly
  • googlehealth.health_metrics_and_measurements.readonly

How the data is used

A scheduled, non-interactive process authenticates as the site owner, fetches recent activity, heart rate, and sleep data from the Google Health API, and computes a small set of rounded, aggregate display values (for example, "8,342 steps today" or "7h 12m sleep, 91% efficiency"). Only these rounded values are written to storage and served to the public website. This is the sole purpose of accessing the data: displaying a personal, at-a-glance wellbeing snapshot on the site's homepage.

The site does not store or publish, from Google Health data:

  • Raw or intraday samples
  • Sleep stage start/end timestamps or interval detail
  • Google or Fitbit account/device identifiers
  • Email addresses, OAuth scopes, or token metadata
  • Any data belonging to an account other than the site owner's own

Data storage and retention

Only the latest computed snapshot is retained, in a private Azure Blob Storage container that is not publicly listable or writable. Each scheduled run overwrites the previous snapshot; there is no historical archive of raw Google Health data. The OAuth client credentials and refresh token used to access the API are stored in Bitwarden Secrets Manager, an access-controlled secrets vault, and are never included in the website's source code, logs, or public output.

Data sharing

Google user data obtained through this integration is not sold, rented, or shared with any third party. It is not used for advertising or any purpose unrelated to displaying the sanitized panel described above, and it is not used to train generalized AI or machine learning models. Access to the underlying Google Health data is limited to the site owner.

Revoking access

The connected Google account owner can revoke this integration's access at any time via Google Account → Security → Third-party access. Revoking access stops future updates to the panel; previously published rounded values may remain visible until the next scheduled run fails and the panel is removed.

Other data collected by this site

The site uses privacy-focused, aggregate analytics (Google Analytics) to understand overall traffic. It does not use tracking for advertising, does not sell visitor data, and does not knowingly collect data from children.

Changes to this policy

This policy may be updated as the site's features change. Material changes affecting how Google user data is handled will be reflected here with an updated "Last updated" date.

Contact

Questions about this policy or the data described above can be sent to me@richardorchard.com.

Back to the main page