Do not commit Google OAuth credentials, Open Wearables API keys, encryption keys, admin passwords, refresh tokens, health data, or populated state files.
Keep the importer behind HTTPS, use a unique administrator password, grant only the read-only Google scopes required, and protect the persistent volume and its backups. Rotate credentials if exposure is suspected.
Please report security issues privately to the repository owner rather than opening a public issue containing sensitive information.