HeroicMe
Privacy

What HeroicMe knows about you and where it lives

HeroicMe is a free habit tracker for Android, built as a role-playing game. This page says plainly what stays on your phone, what goes to the server and to OpenAI, how long it is kept and how to delete it all.

Version of 8 October 2026 · Версия на русском

1Who is responsible for your data

HeroicMe is made by one person, the author of the project, who is also responsible for heroes' data and its protection: Andrew Khvan, postal address: 117 Makatayev Street, Almaty, Kazakhstan.

The app is free. There is no paid access, no subscription and no in-app purchases, so data is not needed for ads or for sale. It is needed only to make the game work.

2What stays on the phone

HeroicMe is built so that a day can be closed offline and the week ahead is already on the phone. That is why a lot lives only on the device.

  • Health Connect records. Steps, sleep and exercise are read at the moment the daily total is computed and are not stored anywhere, not even in the app's own database. Only the total leaves the phone, see section 4.
  • Device token. Kept in Android's protected storage (Keystore), not in ordinary app files.
  • Morning and evening times and notifications. Reminders are scheduled by the phone itself, without push services. These times are not sent to the server.
  • The working copy of your hero. State, the week ahead, chapters, questions and Library articles are kept in the app's database on the phone so everything works offline.

3What goes to the server and why

The server keeps a copy of your hero outside the phone and recalculates experience with the same engine as the phone. At night it prepares the week plan, chapters and questions. This is everything it receives and stores for that:

DataWhyKept for
Game log Day events with times: day opened, quest done, day closed, relapse, craving resisted, article read. The server computes experience from them and prepares the plan and the chapter. Kept: while the hero exists
Hero and device Hero name (any name you choose), game master tone, language, time zone, day boundary, platform and system language. Needed for the hero's calendar and for texts in your language. Kept: while the hero exists
Daily health totals Minutes of sleep for the night, steps for the day, your step goal, minutes of exercise. After short sleep the day becomes a recovery day with a lighter plan; steps and exercise give rewards. Kept: while the hero exists
Evening answers The option you chose or your own words. The game master learns about you from them and picks the next questions. Kept: until “Delete dossier” or “Delete everything”
Onboarding result Values, a letter to your future self, habits with anchors, a boss and an “if craving, then” plan. Onboarding chat messages go to the server so the model can reply, but the conversation itself is not stored, only its result. Kept: values, letter and result until “Delete dossier”, the rest while the hero exists
Dossier Personality axes (a short Big Five questionnaire, player type, chronotype, achievement or avoidance focus), confidence, evidence and the game master's summary. All of it is visible on the dossier screen and can be corrected with “that's not me”. Kept: until “Delete dossier”
Relapse debrief Three short answers after a relapse. They grow the “if craving, then” plan on the SOS screen. Kept: while the hero exists
SOS dialogue Your words and the game master's replies in a short online conversation during a craving. Offline, SOS works without the server. Kept: 30 days, then the texts are erased
“Ask” A question to the game master from the journal and its answer, up to three a day. Kept: while the hero exists
Chapters, mornings, plans, portraits What the server prepares itself: day chapters, morning messages, week plans, generated hero portraits. Kept: while the hero exists
Recovery code and token Hashes only: the server does not have the code or the token itself and cannot show the code again. Kept: the code until used or reissued
IP address and request time Limits on recovery code attempts and protection against brute force. The web server writes the address, time and path of requests to its log. Kept: web server log 90 days
Error reports When something breaks in the app, it sends a technical report: time, app version, phone model and Android version, system language, place in the code, error type, its message and stack trace. This lets the author find and fix failures he does not see on his own phone. Before sending, the app cuts out tokens, the recovery code and database query parameters; the report contains none of your answers, words, onboarding or SOS messages, and no health data. Reports go only to the HeroicMe server, never to third-party services. Kept: 90 days

4Health Connect

HeroicMe reads Health Connect data only with your permission and only for the game: a recovery day after poor sleep, rewards for steps and exercise. The app writes nothing to Health Connect.

Which permissions and why

  • Steps. Total steps from one game-day boundary to the next, compared with the step goal from settings.
  • Sleep. Total minutes asleep in the night that ended on the morning of that day, without awake time. Short sleep turns the day into a recovery day.
  • Exercise. Total minutes of exercise in the day.
  • Distance and calories burned. The library the app uses to read Health Connect returns exercise sessions only together with these, so the permission is requested. The app does not compute, store or send them.
  • Background reading. Once an hour an Android background task computes the daily total, so morning and evening work without opening the app.

What happens to this data

  • Individual records (each walk, sleep stage, workout) never leave the phone and are not stored even there.
  • Four numbers a day go to the server: minutes of sleep, steps, step goal, minutes of exercise.
  • For chapters and plans the server gives the game master even less: “sleep was short, normal or good”, “step goal reached or not”, “there was a workout or not”. The model's input contains no numbers.
  • Health data is not used for advertising, not sold, not shared with data brokers, insurers or lenders, and not used for anything other than game features.

You can revoke the permissions in Health Connect settings at any time. The game works without them: you just get no rewards for steps and exercise and no sleep-based recovery day.

5AI and OpenAI

The game master writes texts with language models. The model only suggests: experience, levels, boss damage and rewards are computed by a deterministic engine with open rules. The phone never talks to models directly; every request is made by the server.

Model on the author's server

The open Gemma model on the server's GPU. Texts do not leave the server.

  • week plan
  • day chapters
  • evening questions
  • dossier updates from answers
  • answers to “Ask”

OpenAI

External service, USA. Receives only the request text.

  • Hero portrait: an English prompt built from your habits' identities and leading stats. No name, values, letter, chat messages and no photo. Before drawing, the prompt goes through OpenAI moderation.
  • Onboarding chat: currently run by an OpenAI model, so your messages in this chat go to OpenAI.

The short SOS dialogue is answered by the fastest available model, which can be either the model on the author's server or OpenAI. The author can switch any request type to another model or set OpenAI as a fallback for when the server's model is unavailable. Texts of that type then go to OpenAI in the same form.

A model request contains only what that text needs: habits and the day's events, your answers and words, your values and letter to your future self when the game master quotes them, and the sleep and activity categories from section 4. It contains no device token, hero ID or IP address: the server, not your phone, talks to the model. OpenAI processes what it receives under its API terms.

Every model text is checked before it is shown by a safety layer: code on the server that blocks medical advice, diets, clinical labels and shaming. When no model is available, the game master uses prepared templates and the game goes on.

Heroes' data is not used to train models. If that ever changes, this page will change first.

6Crisis log

When your words reach the server (onboarding, evening answers, relapse debrief, SOS), the server checks them against a list of phrases for signs of self-harm or distress. The check is done by code on the server itself, with no external services.

If there are such signs, the server writes an entry to an internal log: which rule matched and a fragment of the text. Only the author sees the entry, reviewing it manually and not in real time. The app does not call anyone, does not report anything and does not pass data to anyone; the game goes on as usual.

Log entries are kept while the hero exists and are deleted by “Delete everything”. When SOS words are erased after 30 days, the log entry remains.

HeroicMe is not a help service and not a medical tool. The log does not mean that someone reads messages and will come to help.

7No sign-up

There are no accounts: no email, no phone number, no password, no Google sign-in. On first launch the server gives the phone a random token and recognises the hero by it.

So that the hero is not lost with the phone, the app can give you a recovery code of ten characters. The server keeps only its hash, so you need to save the code yourself. Entering the code on a new phone moves the hero there; the old phone stops syncing, and the data on it stays until you delete it.

8Retention and backups

  • Hero data on the server is kept while the hero exists, that is, until “Delete everything”.
  • SOS dialogue words and replies are erased after 30 days by the server's nightly run.
  • Error reports are deleted after 90 days by the server's nightly run.
  • The recovery code is valid until it is used or a new one is issued.
  • An empty hero created on a new phone that never played is deleted when a hero is moved to that phone with a code.
  • Data on the phone is kept while the app is installed or until “Delete everything”.

The server database is copied every night: 14 daily and 8 weekly copies are kept on the same server and never leave it. The copies exist to restore heroes after a failure. Deleted data disappears from the copies as they are replaced, within eight weeks at the latest.

9How to delete

“Delete dossier” in settings

Erases the dossier axes with their evidence, the game master's summary, your values, the letter to your future self, the onboarding result and your answers to evening questions together with your own words. The game master starts getting to know you again. Experience and rewards for answers stay. “Don't talk about this” marks also stay: they are your request for protection, and a sensitive topic should not come back after deletion.

“Delete everything” in settings

Erases the hero on the phone immediately, and on the server together with the whole log, plans, chapters, dossier, answers and portraits. Offline, the phone is cleared at once and the deletion request is sent to the server when the network is back. Error reports stay until they expire, but their link to the hero is erased.

Uninstalling the app erases only the data on the phone. To erase the hero on the server too, tap “Delete everything” before uninstalling. If you no longer have the phone, write a letter to 117 Makatayev Street, Almaty, Kazakhstan.

10Where the server is and how it is protected

  • The server and database run on the author's own computer in an office (Kazakhstan), not at a cloud provider.
  • Internet access goes through a small rented server: it accepts the HTTPS connection and forwards the request to the office through an encrypted WireGuard tunnel. It holds no hero data, only this website, the app file and a request log.
  • The connection is always encrypted: the app does not send data over HTTP without TLS.
  • OpenAI keys exist only on the server and are stored there encrypted. The author's panel is protected by a login and password.
  • The token and recovery code are stored on the server only as hashes.

11What HeroicMe does not have

  • ads, advertising ID or ad SDKs;
  • analytics, trackers or third-party crash reporting: error reports go only to the HeroicMe server;
  • selling data or sharing it for advertising;
  • access to contacts, location, camera or photos: the portrait is drawn from text, no selfie;
  • email, phone numbers or passwords;
  • cookies or third-party requests on this website: fonts and styles are served from here.

12Adults only, 18+

HeroicMe is made for adults aged 18 and over. Children's data is not knowingly collected. If a hero was created by someone under 18, please tap “Delete everything” or write a letter to 117 Makatayev Street, Almaty, Kazakhstan.

13Changes and contact

If anything about data processing changes, a new version of this page appears here with a new date. The current version is of 8 October 2026.

Questions about your data, requests and complaints:

117 Makatayev Street, Almaty, Kazakhstan