AdmonTracker

Privacy Policy

Last updated: 17 September 2026

AdmonTracker is operated for research by Prof. Roee Admon’s Stress & Psychopathology Lab, School of Psychological Sciences, University of Haifa. Questions and requests concerning privacy, participation, withdrawal, or deletion can be sent to radmon@psy.haifa.ac.il. Participants should identify their study and pseudonymous study code and should not email access tokens or health measurements.

1. Who and what this policy covers

This policy covers invited adult research participants, authorized University research personnel, and visitors to the synthetic guest demonstration. Participation in research is voluntary. Study-specific approved participant documents apply together with this policy.

2. Google user data and other information accessed

AdmonTracker accesses or processes the following categories when they are relevant to an authorized user or approved study:

Google Health data is accessed only after participant authorization. AdmonTracker requests the read-only scopes displayed on Google’s authorization screen and does not request permission to modify Google Health data.

3. How information is used

Information is used only to authenticate authorized staff, apply project permissions, connect participant accounts, collect measurements authorized for the approved research, assess data completeness and device status, notify the study team about operational problems, support participants, secure and audit the service, and produce research outputs permitted by the approved protocol.

AdmonTracker does not sell Google user or participant data; use it for advertising, retargeting, data brokerage, unrelated marketing, or credit, insurance, employment, or lending decisions; or use it to develop, improve, or train general-purpose AI or machine-learning models.

4. Google API Limited Use

AdmonTracker’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Use of information received from Google Health APIs also adheres to the Google Health API Developer and User Data Policy and the Google Health API User Data and Health Research Policy.

5. Storage and protection

The research application runs at app.admontracker.online on Heroku. Operational and research metadata is stored in access-controlled Google Sheets. Raw wearable archives are stored in a restricted University Google Workspace Shared Drive. OAuth client secrets and participant access and refresh tokens are stored in Google Secret Manager. Temporary processing files on Heroku are removed after archive upload.

Protections include HTTPS in transit, encryption provided by the hosting and cloud services, role- and project-based access control, least-privilege service accounts, restricted Shared Drive membership, managed secrets, OAuth state expiry and replay prevention, audit records, and separation of fictional guest data from research data.

6. Sharing and disclosure

Information is available only to the relevant study team, authorized University personnel, approved processors, and research collaborators whose access is permitted by the participant documents, ethics approval, contract, platform policy, and applicable law. Service providers can include Heroku, Google Sign-In, Google Cloud, Google Workspace, Google Health, Fitbit, Qualtrics, AppSheet, and approved email infrastructure when required for the study.

AdmonTracker does not transfer Google user data to third parties for advertising, resale, data brokerage, credit decisions, or unrelated AI/ML training. Information may be disclosed when required by law or when necessary to investigate and address a security incident.

7. Retention, withdrawal, and deletion

Research data is retained for the period and handled after collection as described in the current approved participant documents for the applicable study. Operational security and audit records are retained only as needed for research integrity, security, legal, and University requirements.

Participants may stop future collection without penalty by using the private connection-management link provided after authorization or by contacting radmon@psy.haifa.ac.il. Disconnecting revokes provider access and removes active tokens from AdmonTracker. Access may also be revoked through the participant’s Google or Fitbit account. Requests to delete already collected data are handled according to the applicable approved participant documents, ethics requirements, scientific-integrity obligations, and law.

8. Guest demonstration

The public guest demonstration contains fictional examples only. It does not access production Google Sheets, participant records, watches, Google Health, Fitbit, email, or other research services.

9. Changes

This policy is updated when the service, approved protocol, providers, or applicable requirements change. Material changes affecting research participation are handled through the applicable ethics and participant-notification process.


AdmonTracker

מדיניות פרטיות

עודכן לאחרונה: 17 בספטמבר 2026

AdmonTracker מופעלת לצורכי מחקר על-ידי המעבדה ללחץ ופסיכופתולוגיה של פרופ׳ רועי אדמון, בית הספר למדעי הפסיכולוגיה, אוניברסיטת חיפה. לפניות בנושא פרטיות, השתתפות, פרישה או מחיקה: radmon@psy.haifa.ac.il.

מידע שנאסף והשימוש בו

לצורך כניסת אנשי צוות, המערכת מעבדת מזהה חשבון Google, שם, כתובת דוא״ל, מצב אימות, תפקיד ופרויקט. לאחר הרשאת משתתף, ובהתאם למחקר המאושר, המערכת עשויה לקרוא נתוני פעילות וכושר, מדדי בריאות ושינה מ-Google Health, לרבות צעדים, פעילות, קלוריות, דופק, שונות קצב לב, טמפרטורת עור, קצב נשימה, שינה וחותמות זמן. הגישה היא לקריאה בלבד.

המידע משמש לאימות משתמשים מורשים, ניהול הרשאות, חיבור חשבונות, איסוף מדדים שאושרו למחקר, בקרת שלמות הנתונים, תמיכה במשתתפים, אבטחת השירות והפקת תוצרי מחקר מותרים.

אחסון, אבטחה ושיתוף

מטא-נתונים נשמרים ב-Google Sheets מוגנים, ארכיוני מדדים ב-Shared Drive אוניברסיטאי מוגבל, ואסימוני OAuth ב-Google Secret Manager. השירות משתמש ב-HTTPS, הצפנת ספקי הענן, בקרת גישה לפי תפקיד ופרויקט, חשבונות שירות בהרשאה מזערית, מניעת שימוש חוזר במצב OAuth ורישומי ביקורת.

הגישה ניתנת רק לצוות המחקר הרלוונטי, גורמי אוניברסיטה מורשים, ספקים מאושרים ושותפי מחקר שהגישה אליהם מותרת. המידע אינו נמכר, אינו משמש לפרסום, להחלטות אשראי או לאימון מודלי AI/ML כלליים.

שמירה, פרישה ומחיקה

המידע נשמר ומטופל בהתאם למסמכי המשתתף המאושרים של המחקר הרלוונטי. ניתן להפסיק איסוף עתידי באמצעות קישור ניהול החיבור או בפנייה לחוקר הראשי. ניתוק מבטל את גישת הספק ומסיר אסימונים פעילים. בקשות למחיקת מידע שכבר נאסף מטופלות לפי מסמכי המשתתף, דרישות האתיקה, חובות השלמות המדעית והדין.

כללי Google

השימוש והעברת המידע שהתקבל מ-Google APIs עומדים במדיניות נתוני המשתמש של Google API Services, לרבות דרישות Limited Use, וכן במדיניות Google Health הרלוונטית.