What the lock protects against
The documented app lock adds a deliberate authentication step. Whether it covers each ordinary exposure moment depends on the current build and device, so treat these as acceptance tests.
- Open BaeMax from an already-unlocked phone
- Switch away and inspect the recent-apps preview
- Return after the screen locks and after a reboot
- Check whether a sensitive screen flashes before authentication
What it does not cover
A biometric app lock is not a full privacy plan by itself. Check the places where cycle details can leave the app or appear outside the locked screen.
- Notification previews on the lock screen
- Exports or reports you save or send
- Cloud backups and shared device backups
- Anyone who already knows your phone passcode
How Android handles biometrics
BaeMax uses the device credential flow. That means the phone handles fingerprint, face, or passcode checks rather than BaeMax storing biometric data.
- Fingerprint data stays with Android
- Face data stays with Android
- Device passcode can act as fallback when supported
- BaeMax receives only the auth result
Limits
An app lock does not make a compromised phone safe. It reduces ordinary exposure, but it does not replace device security or safe backup habits.
- Not protection against someone who knows your passcode
- Not a guarantee screenshots never exist
- Device behavior can vary by Android version
- Confirm that the app is available for your phone before choosing it
Run a lock and fallback drill
Test the boundary before entering sensitive history. Open BaeMax, send it to the background, switch through recent apps, lock the phone, and restart the device. Confirm that returning to the tracker requires the expected check and that the recent-apps preview does not reveal more than you accept. Then fail the biometric prompt on purpose and test the device-credential fallback. Repeat after adding or removing a fingerprint, changing the phone passcode, or restoring the app on another device. A failed fingerprint should not be confused with lost health data, but a passcode known by another person is not a private boundary. Notifications, screenshots, exports, and backups still need their own review.
- Test launch, background return, recent apps, and reboot
- Check failed-biometric and device-credential fallback
- Repeat after changing Android biometrics or passcode
- Use a private device credential if the app lock must be private
Plan for shared-device edge cases
Biometrics can be convenient on a personal phone but confusing on a device where another person's fingerprint or face is enrolled. Android authentication may accept any biometric registered for that device, depending on the app's requested authentication class and system configuration. Review the enrolled biometrics and device passcode before treating the app lock as private. Also check accessibility, work-profile, and parental-control software that may capture screens or notifications. If the device itself is not under your control, keep especially sensitive notes elsewhere or avoid entering them.
- Remove old or shared biometric enrollments you no longer authorize.
- Use a strong personal device credential rather than a widely known household PIN.
- Confirm backup and export locations do not bypass the lock.
- Know how to regain access if biometrics stop working without weakening the phone's security.
