Privacy Policy – Stronger Days
Effective: September 25, 2026 · Version: 1.0
Applies to: the Android app "Stronger Days" (package ID com.strongerdays.tree)
This policy applies to everyone whose app language is not German. German-language users see the German version ("Datenschutzerklärung").
1. Summary
- Your streak, journal, mood, notes, relapses, partner name and settings stay on your device only. We do not receive them and cannot access them.
- The app sends no data on its own to us or to third parties. Data is only sent to Google (Firebase) when you use an optional feature (leaderboard, feedback/wish, report) or agree to crash reports and usage data.
- No ads, no sale of data, no cross-app tracking, no advertising ID, no profiling, no automated decisions.
- All optional features are off by default and can be withdrawn at any time. In Settings, "Delete all data" removes everything.
- No account, email address or real name is required.
- The app is for people aged 18 and over only.
2. Controller
Sven Saborowski, trading as Studio Auralis (toiminimi, Finland) Y-tunnus (Finnish business ID): 3577773-3 Graniittilinnankatu 1, 20100 Turku, Finland Email: fi.studio.auralis@gmail.com
This address is also the contact point for all privacy requests (Sections 11 to 13).
3. Why this app is particularly sensitive
Information in this app (for example streak, relapses, journal, mood) can reveal things about your health and your sex life. Such data receives special protection: as "special categories of personal data" under Art. 9 GDPR, as "sensitive information" under the Australian Privacy Act, and as "sensitive personal information" or "consumer health data" under the laws of several US states.
That is why everything stays local. Only if you expressly consent is a small part (display name, streak days, level) sent to the leaderboard.
4. Age limit (18+)
The app is intended only for people aged 18 and over. On first launch you confirm your age by making a selection. We do not ask for a date of birth and only store, locally on your device, that you confirmed (age_confirmed_18). Anyone who states they are younger is pointed to the age limit and may not use the app. We do not knowingly collect data from people under 18. If we learn that we have, we delete it.
5. Data that stays on your device only
The app stores this data in a database in your device's protected app storage:
| Data | Content |
|---|---|
| Streak and history | check-ins ("watering"), relapses, timestamps, tree status, tree rescue |
| Journal | mood, triggers (tags), notes you write, timestamps |
| Badges and level | badges and levels you have earned |
| Settings | app language, reminders (on/off, time), app lock (on/off), consent status for usage data, age confirmation, leaderboard participation (on/off) and display name, name of your accountability partner |
Important:
- This data does not leave your device, unless you share something yourself (Section 7.4). We do not receive it and cannot view it.
- The database is not additionally encrypted. It sits in app storage that other apps cannot access. Protect your device with a screen lock and use the app lock if needed.
- Android cloud backup is disabled for the app. Your data is not backed up to Google Drive. It is lost when you uninstall the app, clear its data or switch devices. There is currently no export function.
- You delete local data via "Settings → Delete all data", by clearing the app's data, or by uninstalling.
6. Data sent to servers
Data is only sent in cases 6.1 to 6.4. The anonymous sign-in (6.5) is the technical prerequisite for them. All recipients are described in Section 9.
6.1 Leaderboard (optional, only with your express consent)
- When: only once you choose "Join leaderboard".
- Data: the display name you chose, your current streak days, your level, the time of the last update and a random user ID (see 6.5; it is also the key of your entry). Technically, your IP address and device and app details are also processed by Firebase on every connection.
- Updates: when you join, when you "water" the tree and when you relapse. On a relapse the streak is set to 0. Relapses themselves, journal, mood and notes are not sent.
- Visibility: the entry is visible to other users in the leaderboard and publicly viewable. It is pseudonymous but not anonymous: if you choose a name that identifies you, others can recognize you. Therefore do not use your real name. You can use the dice to get a suggested name.
- Name check and moderation: display names are checked on your device against a word list for profanity. Other users can report entries (6.3). We can delete entries.
- Storage location: Google Cloud Firestore, region
europe-north1(Finland, EU). - Legal basis: your express consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), which you give by joining.
- Withdrawal and deletion: "Leave leaderboard" deletes your entry immediately. "Delete all data" also removes the anonymous user (6.5). If you uninstall the app without leaving the leaderboard, your entry remains. Please leave the leaderboard first. Otherwise write to us (Section 17) with your display name and we will delete the entry. We reserve the right to delete entries that have not been updated for a long time.
6.2 Feedback and wishes (optional)
- When: only when you send a message from Settings.
- Data: your text (up to 2,000 characters), the type ("feedback" or "wish"), the app language and a timestamp. We store no user ID, no streak or app data, and no contact details unless you write them in the message. Sending technically triggers an anonymous sign-in (6.5).
- Please do not write personal or sensitive details in the message. If you do, we only process them to handle your request.
- Purpose: improving the app, answering requests.
- Legal basis: your consent by voluntarily sending it (Art. 6(1)(a) GDPR), alternatively our legitimate interest in developing the app (Art. 6(1)(f) GDPR). If you include sensitive details, the basis is also your explicit consent (Art. 9(2)(a) GDPR).
- Retention: until handled, at most 12 months. Because the message is not linked to you, we can only find it if you tell us its content and approximate time (Art. 11 GDPR).
6.3 Reports in the leaderboard (optional)
- When: only when you report an entry in the leaderboard.
- Data: the user ID of the reported entry, the reason ("Inappropriate name" or "Another reason") and a timestamp. We do not store who reported. Sending technically triggers an anonymous sign-in (6.5).
- Purpose: protecting the leaderboard from abuse and inappropriate content.
- Legal basis: our legitimate interest in a safe leaderboard (Art. 6(1)(f) GDPR).
- Retention: until handled, at most 12 months.
6.4 Crash reports and usage data (optional, only with consent)
On first launch the app asks whether crash reports and coarse usage data may be collected. Both options are equally prominent. Without your consent, collection is technically switched off. You can withdraw at any time in Settings ("Crash reports & usage data").
- Services: Firebase Crashlytics and Google Analytics for Firebase (Google).
- Crash reports (Crashlytics): the error log (stack trace) and device state at the time of the crash (e.g. device model, manufacturer, Android version, free memory, time, app version), and a random installation ID. The app attaches no custom data, user IDs or logs.
- Usage data (Analytics): a few coarse events that we trigger ourselves:
panic_started(SOS opened) andreminder_enabled(reminder turned on). In addition, Google Analytics automatically records standard events (e.g. first launch, sessions, app updates, engagement time), the Firebase installation ID, device and app details (model, Android version, language, time zone, app version), the install source and an approximate location (country/region/city). According to Google, Google Analytics 4 does not log or store the IP address itself (Google: IP addresses in Analytics). - Never collected: streak, relapses, journal, mood, notes, partner name or display name. The advertising ID is not collected. Collection is disabled, as are ad personalization and ad storage.
- Further information from the providers: Firebase: Privacy and Security · Google Analytics: Data retention · Google Privacy Policy
- Purpose: improve the app's stability, find bugs, roughly understand which features are used.
- Legal basis: your consent (Art. 6(1)(a) GDPR and, where information on your device is accessed, Section 25(1) of the German TDDDG or the corresponding national implementation of Art. 5(3) of the ePrivacy Directive, in Finland the Act on Electronic Communications Services, Laki sähköisen viestinnän palveluista). You can decline without giving a reason, and using the app does not depend on it.
- Withdrawal: in Settings. On withdrawal, collection is switched off and the Analytics instance ID is deleted (
resetAnalyticsData). Data already collected stays with Google until the retention period ends (Section 10).
6.5 Anonymous sign-in (Firebase Authentication)
- When: only once you join the leaderboard, send feedback or report an entry. There is no sign-in before that.
- Purpose: technical prerequisite so that only you can change or delete your leaderboard entry and to limit abuse (database security rules).
- Data: a random user ID and the times of creation and sign-in. On every connection Google also technically processes the IP address and device details. There is no name, email address or phone number.
- Legal basis: same as the respective feature (6.1 to 6.3).
- Processing location: According to Google, Firebase Authentication runs exclusively in data centers in the United States. Your anonymous user ID and the related technical data are therefore transferred to the United States (Section 9).
- Duration: the anonymous user remains until you run "Delete all data". "Leave leaderboard" does not delete it.
6.6 Contact by email (outside the app)
- When: If you write to us, e.g. with a privacy request, a deletion request or a support question.
- Data: your email address, the content of your message, the time and technical headers. Please do not send us sensitive details you do not want to share.
- Purpose: answering your request and handling data subject requests.
- Legal basis: our legitimate interest in handling requests (Art. 6(1)(f) GDPR). For requests about your rights, also compliance with a legal obligation (Art. 6(1)(c), Art. 12 et seq. GDPR).
- Recipients: Our mailbox is operated via Google (Gmail) (provider and addresses: see Section 9).
- Retention: until the matter is finally handled. We then delete the correspondence, unless statutory retention obligations or limitation periods require otherwise.
6.7 Purposes of data processing and legal bases at a glance
| Purpose | Data | Legal basis | Section |
|---|---|---|---|
| Features of the app on your device (streak, journal, reminders, app lock, widget, SOS) | local data | no processing by us: the data stays on your device | 5, 7 |
| Providing the leaderboard | display name, streak days, level, user ID, timestamp | consent (Art. 6(1)(a), Art. 9(2)(a) GDPR) | 6.1 |
| Handling feedback and wishes | message, type, language, timestamp | consent (point (a)), alternatively legitimate interest (point (f)) | 6.2 |
| Protecting the leaderboard from abuse | reported user ID, reason, timestamp | legitimate interest (point (f)) | 6.3 |
| Improving stability, coarse usage statistics | crash data, events, device and app details | consent (point (a); Section 25(1) TDDDG or national implementation) | 6.4 |
| Technical safeguards (anonymous sign-in, security rules) | user ID, IP address, device details | same as the respective feature | 6.5 |
| Answering requests, meeting data subject rights | email address, message | legitimate interest (point (f)), for data subject requests legal obligation (point (c)) | 6.6 |
We do not process your data for advertising, profiling or sale to third parties.
7. Features that do not send data to us
7.1 App lock
Uses Android's authentication (fingerprint, face, PIN, pattern, password). The app only receives the result "successful" or "not successful". Biometric data and PINs are neither stored nor transmitted. Only whether the lock is active is stored locally. If no device security is set up anymore, the app opens without a lock so you are not locked out. While the lock is active, the preview in the app switcher is hidden.
7.2 Reminders
Local notifications that your device shows at the time you choose. No server, no push service, no data transfer. Android only asks for the "Notifications" permission when you turn on reminders. The texts are neutral and do not reveal the topic of the app. After a restart, the app schedules the reminder again.
7.3 Home screen widget
If you add the widget, it shows the tree and streak number openly on your home screen. Others who see your device can see it. Image and number are in the app's own storage and are not transmitted. You can remove the widget at any time.
7.4 Sharing and accountability partner
Your partner's name is stored locally only. Messages (possibly with streak days or a note about a setback) and the "share tree" image (tree, day count, app name) are only passed to an app of your choice via the Android share menu after you tap. The app itself transmits nothing. From the handover, the privacy policy of the chosen app applies. The temporary image file is deleted afterwards.
7.5 Rate the app
Opens Google Play's in-app review. Google processes data under the Google Privacy Policy. We do not learn whether or how you rate, and receive no personal data from you through it.
7.6 SOS features
The breathing exercise and focus task run entirely on your device.
7.7 Google Play
The Google Play Terms of Service and the Google Privacy Policy apply when you download and update the app. In the Google Play Console we only see aggregated statistics (e.g. installs, crash rates from users who share diagnostics with Google), not personal data.
8. App permissions
| Permission | Purpose |
|---|---|
INTERNET, ACCESS_NETWORK_STATE |
connection to Firebase (only for the features in Section 6) |
USE_BIOMETRIC, USE_FINGERPRINT |
app lock |
POST_NOTIFICATIONS |
reminders (only requested when you turn them on) |
RECEIVE_BOOT_COMPLETED |
reschedule the reminder after a restart |
VIBRATE, WAKE_LOCK, FOREGROUND_SERVICE |
required by libraries for notifications and background tasks (e.g. widget) |
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE |
Google Play Install Referrer: Google Analytics can use it to record the install source (only with your consent, 6.4) |
com.google.android.providers.gsf.permission.READ_GSERVICES |
access by Google libraries to the Google Play services configuration |
The app does not request access to location, contacts, camera, microphone, photos or files. The permissions for the advertising ID have been removed from the app. The app does not read or use the advertising ID.
9. Recipients, processors and international transfers
Recipients of the data in Section 6:
Google (Firebase Authentication, Cloud Firestore, Crashlytics, Google Analytics for Firebase) as processor. Depending on the contracting location, one of the following companies acts (see the definition of "Google" in the Firebase terms):
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy information: Google Privacy Policy · Firebase: Privacy and Security · Firebase Data Processing and Security Terms · Firebase Terms of Service
Google Play (7.5, 7.7): the provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Under the Google Privacy Policy, the company responsible for processing your data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland for users in the EEA and Switzerland, and Google LLC for everyone else. See the Google Play Terms of Service and the Google Privacy Policy.
Google (email): Our mailbox is operated via Google (Gmail) (6.6). Provider and addresses as above, see the Google Privacy Policy.
Other leaderboard users and visitors: display name, streak days and level of your leaderboard entry (6.1).
The app you choose in the share menu: only what you share there (7.4).
Authorities and courts only if we are legally obliged to.
There are no other recipients. We do not sell data and do not pass it on for advertising.
International transfers:
- Google stores leaderboard entries in Finland (EU, region
europe-north1). - According to Google, Firebase Authentication processes data exclusively in the United States. Analytics and Crashlytics may process data in the United States and in other countries where Google or its sub-processors operate data centers.
- For transfers to the USA we rely on the EU-US Data Privacy Framework (according to Google, Google LLC is certified; see dataprivacyframework.gov) and on the standard contractual clauses in the Firebase Data Processing and Security Terms (Art. 44 et seq. GDPR). For Switzerland, Google states that it complies with the Swiss-U.S. Data Privacy Framework. For the United Kingdom we rely on the transfer mechanisms provided for in the data processing terms.
- For users in Australia, see Section 13.
10. Data retention
| Data | Duration |
|---|---|
| Local data on your device | until you delete it (Delete all data, clear app data, uninstall) |
| Leaderboard entry | until you leave the leaderboard or use "Delete all data"; remains if you only uninstall; we delete it on request |
| Anonymous user (Firebase Authentication) | until "Delete all data" |
| Feedback and wishes | until handled, at most 12 months |
| Reports | until handled, at most 12 months |
| Email correspondence | until the matter is finally handled, then deletion unless statutory retention obligations or limitation periods require otherwise |
| Usage data (Analytics) | 2 or 14 months, depending on the setting in the Analytics account (Google: Data retention) |
| Crash reports (Crashlytics) | 90 days according to Google (Firebase: Privacy and Security) |
Statutory retention obligations remain unaffected. Even after deletion, copies may remain at Google in backup systems for a limited time.
11. Your rights under the GDPR (EU, EEA, United Kingdom, Switzerland)
Under the GDPR (or the UK GDPR and the Swiss Data Protection Act) you have the right to:
- access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21),
- withdraw consent at any time with effect for the future (Art. 7(3)). The lawfulness of processing before withdrawal is not affected.
- lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the place where you live, work or where the alleged infringement occurred. The authority responsible for us is the Finnish supervisory authority:
- Finland: Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman), P.O. Box 800, 00531 Helsinki, Finland, tietosuoja.fi
- Other authorities in the EEA: list of authorities at the European Data Protection Board
- United Kingdom: Information Commissioner's Office, ico.org.uk
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, edoeb.admin.ch
How to exercise your rights:
- In the app: "Leave leaderboard", switch off "Crash reports & usage data", "Delete all data".
- By email to the address in Section 2. We respond within one month (Art. 12(3) GDPR).
- Because we have no access to your local data and server data is pseudonymous, we can only handle requests if you give us details that let us find your data (e.g. display name, content of a message). Otherwise Art. 11 GDPR applies.
No obligation to provide data: all data transfers are voluntary. Without them you can keep using the app, just without the leaderboard, feedback function and reports. No automated decision-making, no profiling within the meaning of Art. 22 GDPR.
12. Notes for users in the United States
There is no single federal privacy law in the United States. We voluntarily apply the following rights to all users in the US, even where a law would not apply to us because of its thresholds.
12.1 Categories we collect (Notice at Collection, including under the California Consumer Privacy Act (CCPA/CPRA))
In the past 12 months we have collected the following categories (each only if you use the respective feature):
| Category | Examples | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers | random user ID (Firebase), Firebase installation ID, IP address | leaderboard, feedback, reports, security, crash and usage statistics | Google (service provider) |
| Internet or network activity | app events (panic_started, reminder_enabled), sessions, crashes |
stability, coarse usage statistics (only with consent) | Google (service provider) |
| Device data | model, Android version, language, app version | error analysis, statistics (only with consent) | Google (service provider) |
| Coarse location | country, region or city (no precise location) | statistics (only with consent) | Google (service provider) |
| Sensitive personal information / health data | streak days and level in the leaderboard (behavior and health may be inferred) | solely display in the leaderboard (only with express consent) | Google (service provider); other users (visible) |
| Message content | text in feedback/wish | handling the request | Google (service provider) |
Not collected: purchase/payment data, precise location, biometric data (Android handles recognition), audio, images, employment or education data, inferences about you.
Sources: solely you or your device. Retention: see Section 10. No sale, no "sharing": We do not sell personal information and do not share it for cross-context behavioral advertising ("sell"/"share" within the meaning of the CCPA). We use sensitive data only to provide the feature you requested. A right to limit the use of sensitive data is therefore not needed. We offer no financial incentives for data.
12.2 Your rights (California and other states, e.g. Virginia, Colorado, Connecticut, Texas)
You have the right to know (which data and categories, sources, purposes, recipients), access a copy, delete, correct, and non-discrimination for exercising your rights. The rights to opt out of sale, targeted advertising and profiling are moot because we do none of these.
- How: in the app ("Leave leaderboard", "Delete all data") or by email (Section 2). We confirm receipt and generally respond within 45 days (extendable once by another 45 days, with an explanation).
- Verification: because we do not know you by name, we verify requests using details only you know (e.g. display name, content of a message).
- Authorized agents: you may appoint an authorized agent. We require proof of authorization.
- Appeal: if we deny a request, you may appeal by replying to our denial by email. If that is unsuccessful, you may contact the Attorney General of your state.
- California Shine the Light: we do not disclose personal information to third parties for their direct marketing purposes.
12.3 Consumer health data (including the Washington My Health My Data Act, Nevada SB 370, Connecticut)
Because your streak may reveal something about your health status, we treat it as "consumer health data". These notes are our Consumer Health Data Privacy Policy.
- Categories collected: streak days (period without a relapse) and level, linked to a random user ID, only if you join the leaderboard. All other health data (relapses, journal, mood, notes) stays on your device.
- Purposes: solely display in the leaderboard you chose.
- Sources: only you.
- Sharing: display to other leaderboard users, which you expressly release by joining. Processing by Google as a service provider on our behalf. We do not otherwise share or sell consumer health data.
- Consent: collection and release happen only with your consent when you join, which you can withdraw at any time via "Leave leaderboard". Your entry is then deleted immediately.
- Your rights: confirmation of whether we collect such data; access, including a list of the third parties with whom we share it; withdrawal of consent; deletion. Requests by email (Section 2). We respond within 45 days. If we deny a request, you may appeal and then contact your state's Attorney General (in Washington, the Attorney General).
- We use no location data and no geofencing around health care facilities.
12.4 Children (COPPA)
The app is not directed at children under 13 and is intended solely for people aged 18 and over. We do not knowingly collect data from anyone under 18.
12.5 "Do Not Track"
We do not track users across third-party apps or websites. A response to "Do Not Track" or "Global Privacy Control" signals is therefore not required. Third parties (other than Google as our service provider, see Section 6.4) do not collect data through the app about your behavior across multiple websites or services.
13. Notes for users in Australia
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), even where our size would not oblige us to in every case.
- Kinds of data and purposes: see Sections 5 to 7. The streak in the leaderboard counts as "sensitive information" (health or behavioral details). We collect it only with your express consent (APP 3) and only for the stated purpose (APP 6).
- Anonymity and pseudonymity (APP 2): you can use the app without an account or real name.
- Storage and security (APP 11): see Section 14.
- Overseas (APP 8): data in Section 6 is processed by Google in Finland (leaderboard entries) and in the United States (Firebase Authentication exclusively there) and other countries where Google or its sub-processors operate data centers. We have agreed Google's data processing terms for Firebase. By consenting to the respective feature, you agree to the overseas transfer.
- Direct marketing (APP 7): we do not engage in direct marketing.
- Access and correction (APPs 12, 13): requests by email (Section 2). We generally respond within 30 days. You can delete leaderboard data yourself in the app.
- Complaints: write to us first (Section 2). We confirm receipt and generally respond within 30 days. If you are not satisfied with the response, you can contact the Office of the Australian Information Commissioner (OAIC): GPO Box 5288, Sydney NSW 2001, Australia, phone 1300 363 992, oaic.gov.au.
- Data breaches: if a data breach is likely to cause you serious harm, we will notify you and the OAIC under the Notifiable Data Breaches scheme.
- Children: only from age 18.
14. Security
- Transfers to Firebase are encrypted (HTTPS/TLS).
- Server-side security rules only allow you to change or delete your leaderboard entry. The app can only write feedback and reports, not read them.
- Local data is in protected app storage. It is not additionally encrypted. Use a screen lock and, if needed, the app lock.
- If a data breach occurs despite all care, we will inform those affected and authorities as required by law (including Arts. 33 and 34 GDPR, US state laws, the Notifiable Data Breaches scheme).
15. Links to other websites; no advertising, no tracking
Links to other websites: This policy contains links to third-party websites, e.g. to Google, Firebase and data protection authorities. The respective operators alone are responsible for their content and privacy practices, over which we have no influence. When you open a link you leave our service. The privacy terms of that site then apply, and the operator receives technical data such as your IP address. The app itself only opens a website when you tap: this privacy policy or our legal notice on our website studio-auralis.fi, in your device's browser. The web server (Google's Firebase App Hosting, region europe-west4) then receives technical data such as your IP address and browser details; the privacy policy of that website applies to this. The app itself transmits nothing in the process. The "Rate the app" function opens the review or store page of Google Play, and via the share menu (7.4) you leave the app if you choose another app.
No advertising, no tracking: The app contains no advertising, no advertising or attribution SDKs from ad networks (e.g. AppsFlyer, Adjust) and no payment service. We do not sell data. There are no behavioral profiles. Fonts are bundled locally in the app (no connection to Google Fonts or other font services).
16. Changes to this privacy policy
If we change the app or legal requirements change, we will update this policy. The date and version at the top show the current status. You can find the current version at https://www.studio-auralis.fi/en/strongerdays/privacy. We introduce material changes involving additional data transfers only with your renewed consent.
17. Contact
Sven Saborowski, trading as Studio Auralis (toiminimi, Finland) Y-tunnus: 3577773-3 Graniittilinnankatu 1, 20100 Turku, Finland Email: fi.studio.auralis@gmail.com