1. General provisions
This policy explains the processing of information when using the vesometr.ru website and the Vesometr Android application. It applies to processes that WEB DEVELOPMENT SYSTEM RUS Limited Liability Company actually controls, and does not automatically apply to email services, instant messengers, cloud storage, application stores or other systems independently selected by the user.
The operator follows the principles of legality, specificity of purposes, minimization of data, limited storage periods, accuracy, confidentiality and the adoption of proportionate protective measures. The site is not designed to create a medical record and does not ask you to upload documents or backup copies.
2. Operator and application area
Operator: WEB DEVELOPMENT SYSTEM RUS Limited Liability Company, INN 5043091883, checkpoint 504301001, OGRN 1255000092995. Email address for requests from personal data subjects: info@vesometr.ru.
The policy covers visiting public pages, security server logs, submitting contact forms, and processing requests for access, correction, withdrawal of consent, or deletion. The local Android log is described separately, since its contents are not transmitted to the operator according to the standard architecture.
3. Local application data
The user can manually save weight and goal, pressure, pulse, nutrition, smoking and expenses, well-being, notes, home medicine cabinet information, medication schedule and profile for reporting. Such records may contain health information and require special care on the part of the device owner.
The working database is stored locally. Version 1.2.1 does not have a user account, server synchronization, advertising SDKs, remote analytics and Android INTERNET permission. The operator does not receive log content, PIN code, biometric templates, notification schedule, PDF or JSON file automatically.
The PIN is verified locally; biometric verification is performed using Android tools, and the application does not receive a biometric template. PDF and JSON copy are created only after user action. The files should be kept confidential and may contain selected entries and profiles.
4. Site data categories
When viewing pages, the server technically processes the IP address, date and time of the request, URL, referral source when transmitted by the browser, response code, User-Agent and secure connection parameters. Yandex Metrica and Google Analytics are connected to measure traffic: they may receive technical browser and device parameters, the visited URL, referral source, navigation events, IP address and their own identifiers in cookies or local storage. The data is used for aggregate statistics, structure improvements and error monitoring; Google advertising personalization is disabled in the site code.
The contact form accepts name, if voluntarily provided, email, subject, message body, consent mark, date, technical ID, and data required for anti-spam protection. Attachments are not accepted. Do not send diagnoses, medical documents, passwords, PINs, APKs, PDF logs, or JSON copies.
The form is secured using a signed one-time parameter embedded in the page and limited in time. It does not create a user profile and is not used for advertising. The contents of form fields and submitted messages are not intended for transfer to analytics platforms. Website counters cannot access the Android application's local database, PDF files or JSON backups.
The selected website language is stored only in the browser's local storage under the vesometr-language key. It contains only ru or en, is not sent to the operator as a separate profile and can be removed by clearing this site's browser data.
5. Objectives and legal basis
These forms are needed to register a request, respond, clarify the question, prevent spam and abuse, confirm the fact of sending and fulfill the user’s request. The basis is separate consent before shipment; site security and protection of rights may also be ensured on other grounds provided by law.
Technical logs are used for operability and information security. The data is not used for medical conclusions, scoring, advertising, distribution without a separate basis or automated decision-making that creates legal consequences.
6. Operations, place and periods of storage
With regard to the form, it is possible to collect, record, systematize, accumulate, store, clarify, retrieve, use for response, restrict access, block and delete. The main storage of requests is located on a server in the Russian Federation outside the public directory of the site.
A work request is kept for no more than 90 days, unless a longer period is required to fulfill an ongoing request, confirm an action, or protect a right or legal obligation. Technical logs are stored for a limited time, necessary for security and incident resolution, and then deleted or overwritten.
Local Android data is retained until the entry is deleted, the app is completely wiped, or the user uninstalls the app. The operator does not set a deadline for content that it does not receive and technically does not control.
7. Recipients and external services
The operator does not sell data, does not transfer it to advertising networks and does not use analytical platforms. Access to requests may only be granted to authorized persons and infrastructure providers to the extent necessary for hosting, securing and delivering email, subject to proper grounds and obligations of confidentiality.
If the user himself opens a QR or RuStore link, sends PDF/JSON through a third-party application, or writes directly from an email service, the corresponding service owner processes the data according to his own policies. Until this action is selected, the application does not transmit the log to an external recipient.
8. Safeguards and incidents
The site uses HTTPS, access control, placement of requests outside the web directory, limited file rights, CSRF protection, hidden anti-spam field, minimum fill time, limiting request frequency, checking length and format, and neutralizing control characters of mail headers. Access to the server is provided to a limited number of authorized persons.
No system can guarantee absolute security. In the event of a confirmed incident, the operator limits the consequences, retains the necessary technical information, eliminates the cause and carries out actions and notifications required by law.
9. User rights and request procedure
The subject has the right to request information about processing, access to his data, clarification, blocking or deletion, object to processing in specified cases and withdraw consent. The request is sent to info@vesometr.ru. To search for a message, enter the sender's address and the reference number, if saved.
The operator may request minimal information sufficient to confirm the applicant's connection with a specific request. Do not send a passport, medical documents or backup copy unless the operator has explicitly explained the legal need and secure method of transmission. A revocation does not affect the lawfulness of the processing carried out prior to its receipt.
10. Data of children and third parties
The form is not intended for minors to self-submit. If a user includes information from another person in a message, he must have a legal basis and limit the text to the necessary minimum. For a question about the operation of an application, an impersonal description of the interface and Android version is usually sufficient.
11. Changes and contacts
If the functions of the site, form, APK or processing structure change, a new edition with a date is published. Material changes do not apply retroactively to previously given consent without a statutory basis.
Operator contact: WEB DEVELOPMENT SYSTEM RUS Limited Liability Company, info@vesometr.ru, vesometr.ru. The procedure for self-cleaning is described on the page "Deleting data".
Federal Law No. 152-FZ · Federal Law No. 156-FZ of June 24, 2025 · Federal Law No. 149-FZ. The public text of the policy does not replace the internal organizational documents and mandatory actions of the operator when required by law.