Legal

Privacy Policy

What personal data we collect when you use My Daily Challenge, why we use it, who we share it with, how long we keep it and what rights you have.

This Privacy Policy applies to the My Daily Challenge app for iOS and Android (listed in the stores as “My Daily Challenge: Streaks”, “the app”) and to the website mydailychallenge.dedaldev.com (“the website”), together “the Service”. It is written to meet the EU General Data Protection Regulation (GDPR) and the Serbian Law on Personal Data Protection.

1. Who we are

The controller of your personal data is Dedaldev D.O.O., Vojvođanska 42, 11070 Belgrade, Serbia, registration number 21438995, tax ID 111190461 (“we”, “us”, “our”). For any question or request about your data, write to info@dedaldev.com.

2. Data we collect

2.1 Account data

You sign in with Google, with Apple, or with an email address and password. Sign in is handled by Google Firebase Authentication. We receive your email address, a random account identifier created by Firebase and the sign in method you used. If you use Sign in with Apple and choose to hide your email, we only receive the private relay address Apple creates for you. We never receive your Google or Apple password. If you sign in with email and password, Firebase Authentication stores the password in hashed form, and it never reaches our server.

2.2 Profile answers (optional)

To choose challenges that fit you, the app asks a few questions. Every question can be skipped or answered with “Prefer not to say”, and you can change your answers in Profile at any time.

  • Basic questions: name, date of birth, gender, relationship status, number of children, occupation and interests.
  • Premium questions: work environment, pets at home, personality type, time you can dedicate each day, preferred challenge types and preferred days.
  • Focus areas you select.

2.3 Challenge activity

The challenges assigned to you and when, whether and when you complete them, your self rating from 1 to 5 of how far you got, and the optional reflection note you write. We also keep the local date and time of your device, so that your daily challenge follows your own day.

2.4 Device and notification data

Device platform (iOS or Android), app version, language setting, an install identifier created by the app, and, if you allow notifications, a push token from Firebase Cloud Messaging. The daily reminder is scheduled on your device; the push token lets us deliver notifications you have allowed.

2.5 Subscription data

If you buy Premium, Apple or Google processes the payment. We never see your card or bank details. RevenueCat tells our server the status of your subscription: product, store, purchase, renewal and expiry dates, whether it is a trial, price and currency, and events such as renewal, cancellation or billing issues. This is linked to your account identifier.

2.6 Usage and analytics data

  • Our own event log. The app sends usage events to our server, for example app opened, screen viewed, challenge shown, challenge completed or Premium screen shown, together with the install identifier, your account identifier when you are signed in, platform, app version and time. Our server adds events such as account created, challenge assigned or account deleted. We use this log to understand how the app is used, to find problems and to improve it. It is never sold and never used for advertising.
  • Google Analytics for Firebase. App usage events, device model, operating system version, an app instance identifier, approximate location at country or region level derived from your IP address, and your account identifier.
  • Smartlook session replay. Smartlook records how you move through the app (screens, taps and scrolling) so we can find usability problems and bugs. A recording can show what was on the screen at that moment, which may include profile answers you typed. Recordings are linked to your account identifier, not to your name or email address.

2.7 Advertising attribution

  • Meta SDK. The app sends events such as install, app open and purchase to Meta, together with your account identifier, so we can measure and improve our ads on Facebook and Instagram. Purchase events may also be sent to Meta by RevenueCat. On iOS, the device advertising identifier (IDFA) is shared only if you allow tracking in the App Tracking Transparency prompt. On Android, the Meta SDK may use the Android advertising ID, which you can reset or delete in your device settings.
  • Apple Search Ads attribution. On iOS, the app can request an attribution token from Apple's AdServices framework, which tells us, directly or through RevenueCat, whether the install came from an Apple Search Ads campaign. This does not use the advertising identifier.

2.8 Support messages

If you email us, we receive your email address and everything you write to us.

2.9 Website

The website does not set cookies, does not use analytics or advertising trackers and does not load content from other companies. Like any web server, ours records technical logs (IP address, time, requested address and browser type) for security and troubleshooting.

2.10 What we do not collect

The app does not ask for access to your contacts, camera, microphone or precise location, and it does not read data from Apple Health or Google Fit.

3. How we use data and why

For each purpose below we name the legal basis under Article 6 of the GDPR.

  • Providing the Service: creating and securing your account, choosing and showing your daily challenges, saving your progress, ratings and reflections and keeping them in sync across your devices. Basis: performance of our contract with you (Art. 6(1)(b)).
  • Premium: checking your subscription status and unlocking Premium features. Basis: contract (Art. 6(1)(b)).
  • Notifications: the daily reminder and other notifications you allow. Basis: your consent, given through the notification permission on your device (Art. 6(1)(a)). You can withdraw it at any time in your device settings.
  • Understanding and improving the app: our event log, Google Analytics for Firebase and Smartlook. Basis: our legitimate interest in knowing how the app is used and in fixing problems (Art. 6(1)(f)). You can object at any time, see section 7.
  • Measuring our advertising: Meta SDK and Apple Search Ads attribution. Basis: our legitimate interest in knowing which campaigns bring new users (Art. 6(1)(f)). On iOS, tracking across apps of other companies happens only with your consent in the App Tracking Transparency prompt (Art. 6(1)(a)).
  • Support: answering your messages. Basis: contract and our legitimate interest in helping you (Art. 6(1)(b) and (f)).
  • Security and abuse prevention: verifying sign in tokens, rate limiting and technical logs. Basis: legitimate interest (Art. 6(1)(f)).
  • Legal obligations: accounting and tax rules and lawful requests from authorities. Basis: legal obligation (Art. 6(1)(c)).

We do not sell your personal data and we do not use your profile answers, challenge activity or reflections for advertising. Challenges are chosen automatically from your focus and answers, but this never produces legal or similarly significant effects for you.

4. Who we share data with

We use the following service providers. They process data on our behalf and under our instructions, unless stated otherwise.

  • Google (Firebase Authentication, Firebase Cloud Messaging, Google Analytics for Firebase): sign in, delivery of push notifications and app analytics. Google Ireland Limited and Google LLC, USA.
  • RevenueCat, Inc., USA: subscription status and purchase history.
  • Smartlook.com, s.r.o., Czech Republic: session replay.
  • Meta Platforms Ireland Limited and Meta Platforms, Inc., USA: measurement of our ads. Meta also uses this data for its own purposes as described in Meta's privacy policy.
  • DigitalOcean, LLC: hosting of our server and database in a data center in Frankfurt, Germany.
  • Slack Technologies, LLC: internal notifications for our team, for example that a new account was created. They contain only the random account identifier, never your email address or profile answers.
  • Apple and Google as app stores: they handle downloads, payments, subscriptions and refunds as independent controllers under their own privacy policies.

We may also disclose data when the law requires it, for example to a court or authority, or to protect our rights and the safety of our users. If Dedaldev D.O.O. or the app is ever sold or merged, your data would pass to the new owner under this policy and we would tell you beforehand.

5. Where data is processed

Our own server and database run in Frankfurt, Germany, in the European Union. Google, RevenueCat, Meta and Slack may process data in the United States and other countries outside the EU and Serbia. For these transfers we rely on the Standard Contractual Clauses approved by the European Commission and, for providers certified under it, the Data Privacy Framework between the EU and the United States. You can ask us for a copy of the safeguards that apply.

6. How long we keep data

  • Account, profile answers and challenge activity: as long as you keep your account. They are deleted when you delete your account, see Delete your account.
  • Push tokens: until the token stops being valid or you delete your account.
  • Our event log: at most 400 days, after which events are deleted automatically. Events linked to a deleted account are deleted or made anonymous when the account is deleted.
  • Subscription and purchase records: as long as needed for accounting, tax and the handling of disputes, and no longer than the law requires.
  • Google Analytics for Firebase, Smartlook and Meta: deleted automatically under the retention settings of each service; for Google Analytics for Firebase this is at most 14 months.
  • Server logs: at most 30 days.
  • Support emails: as long as needed to answer you, and at most 2 years after our last message.
  • Backups: encrypted backups of our database are overwritten within 30 days.

7. Your rights

Under the GDPR and the Serbian Law on Personal Data Protection you have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate data (most of it you can edit yourself in Profile);
  • delete your data (you can delete your account in the app at any time);
  • restrict processing in certain cases;
  • receive your data in a structured, machine readable format (portability);
  • object to processing based on our legitimate interests, including analytics and session replay;
  • withdraw your consent at any time, without affecting processing that happened before.

To use any of these rights, email info@dedaldev.com from the address linked to your account. We answer within one month. We may ask you to confirm your identity before we act on a request.

You can also lodge a complaint with a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), and in the EU, the data protection authority of the country where you live or work.

8. Your choices in the app

  • Profile answers: skip any question, or change and clear answers in Profile.
  • Notifications: turn them off in your device settings.
  • Tracking on iOS: change your choice in Settings, Privacy and Security, Tracking.
  • Advertising ID on Android: reset or delete it in your device settings under Privacy and Ads.
  • Analytics and session replay: email us and we will exclude your account.
  • Account: delete it in Profile, Account, Delete account.

9. Children

The Service is not meant for anyone under 16 and we do not knowingly collect data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.

10. Security

Data travels over encrypted connections (TLS). Every request from the app that reads or changes your account is checked against a signed Firebase sign in token, access to the server and database is limited to the people who run the Service, and we never store passwords. No method of transmission or storage is completely secure, but we work to protect your data and will inform you and the authorities of a breach as the law requires.

11. Changes to this policy

We may update this policy when the Service or the law changes. The date at the top shows the latest version. We will tell you about material changes in the app or by email at least 14 days before they take effect.

12. Contact

Dedaldev D.O.O.
Vojvođanska 42, 11070 Belgrade, Serbia
Registration number 21438995, tax ID 111190461
Email: info@dedaldev.com