If you use sapplify Account with an app
This policy applies in addition to the Privacy Policy of each sapplify app you use. Your app's policy describes what the app does on your device. This policy describes what we do with the data your sapplify Account sends to our servers. Both apply at the same time.
1. Introduction
In short: This policy covers the data tied to your sapplify Account: your sign-in identity, your profile, and the data that flows to our servers when you turn sapplify Sync on. It layers on top of each app's own Privacy Policy.
A sapplify Account is a single identity that works across every sapplify app. sapplify Sync is included free with your account. It is off until you turn it on, and you turn it on separately in each app, so signing in does not by itself copy any of your app data to our servers.
This Privacy Policy explains what data your sapplify Account holds, who processes it on our behalf, how long we keep it, and the rights you have over it. It does not replace each app's own Privacy Policy: each app's policy continues to govern what that app does locally on your device.
By creating a sapplify Account, you confirm that you have read and understood this policy.
2. Data Controller
The data controller responsible for your personal data is:
Anthony Eli Rasch - sapplify
PO Box 004
91501 Nove Mesto nad Vahom
Slovakia
ICO: 56665032
General inquiries: contact@sapplify.com
Privacy and data protection: privacy@sapplify.com
Data Protection Officer
sapplify operates at a scale that does not require the designation of a Data Protection Officer under Article 37 GDPR. For any data protection inquiry, contact privacy@sapplify.com.
3. Definitions
- sapplify Account: the identity you create with us and use to sign in across sapplify apps.
- sapplify Sync: the free, opt-in backup and cross-device service you turn on separately in each app.
- Sub-processor: a third party that processes personal data on our behalf, under contract.
- Entitlement: our record of what your account has access to. Sync is free for every account and is no longer gated by this record.
- Personal Data: any information relating to an identified or identifiable person.
- Sensitive Personal Data: a subset of Personal Data that receives stronger protection under GDPR Article 9, such as data concerning health.
- Auth Provider: Apple, Google, or our email/password sign-in (provided by Supabase).
- Sync Data: the per-app data your account holds on our servers for an app where you have turned Sync on.
- Sync Consent: your decision to turn Sync on for a particular app, recorded on our servers with the time and the version of this policy in force at that moment.
4. What Data Your sapplify Account Collects
Your sapplify Account holds nine categories of data on our servers.
Identity and profile
- Email address (always required)
- Display name (optional)
- Auth provider identifiers (Sign in with Apple user identifier, Sign in with Google subject ID) when you use those providers
- The language your device was set to when you created your account, kept with your authentication record and used only to choose the language of account emails such as confirmation and password reset. Accounts created with Sign in with Apple or Sign in with Google do not carry one, and their account emails are sent in English.
- Account creation and last-update timestamps
Authentication and session data
- Hashed passwords (managed by Supabase Auth; we never see the plaintext)
- Active session tokens (JWTs) issued to your signed-in devices
- Sign-in event timestamps and IP addresses, retained transiently by Supabase Auth for security investigations
Cross-app sync data
If you have turned sapplify Sync on for an app while signed in, that app uploads that app's data to our servers. Each sapplify app describes the exact shape of its data in its own Privacy Policy:
- sWeight: weight entries and body measurements
- sCycle: cycle events
- sMoment: mood, journal, and breathing entries
- sLists: lists and list entries
- sTrain: training sessions and exercises
- sBudget: budget entries
- sDiary: your daily intention and reflection, the moments you record inside each day (text, photos and voice notes), and, if you invite one, the trusted reader you share with, including the email address you used to invite them
- sDoku: puzzle progress, game settings, and your solve records (difficulty, time taken, hints and mistakes used)
- Palate: the meals you log with their tags, and how you felt afterwards (energy, mood, digestion)
You only have data on our servers for an app where you turned Sync on. Signing in is not enough on its own. Apps where you have never turned Sync on, and apps you have never signed into, hold no data for your account.
Sync consent records
When you turn Sync on or off for an app, we record the decision itself, so that we can show if asked that your data was only ever synced with your agreement. For each app we store whether Sync is on, when you turned it on, the version of this policy in force at that moment, whether you chose from the sign-in prompt or from the account screen, and, if you turned Sync off, when you did so and the date that app's server copy is due for deletion. We also keep an append-only log of these changes, which includes the user-agent string sent by the app making the request. The timestamps and the policy version are set by our server rather than accepted from your device, because a value your own device supplied would not be evidence.
Purchase and entitlement records
sapplify Sync is free and is never billed. These records cover the per-app Pro purchases you make inside individual apps.
- Your entitlement status for the purchases tied to your account
- The store you bought through (Apple App Store, Google Play) and the store product identifier
- Receipt-validation metadata returned by Apple and Google, used to confirm the purchase is genuine
- Purchase lifecycle events received from Apple App Store Server Notifications and Google Real-time Developer Notifications
Error and crash reports
When a sapplify app hits an error or crashes, it sends us a report so we can fix it: the app and its version, the platform, a device identifier, a session identifier, the severity and type of the error, the error message, the stack trace, and technical context about what the app was doing at the time. While you are signed in, your account identifier is attached. Stack traces and context can incidentally contain fragments of the data the app was handling when it failed, which is why they are the parts we keep for the shortest time.
Error reports follow the same 30-day rule as usage analytics: after 30 days the report leaves our live database, and what we retain for long-term product statistics is only the classification, which app, which version, which platform, how severe, and what kind of error. The account identifier, the stack trace and the technical context are stripped out and not kept.
Usage analytics
Each app reports how it is used to our own servers in Ireland: the app and its version, the platform, a randomly generated device identifier, a session identifier, and the name of each event together with the values attached to it. While you are signed in, your account identifier is attached to those events. We use no third-party analytics SDK, nothing is sent to an advertising network, and these records are deleted when you delete your account.
After 30 days these rows are moved out of the live database into a long-term statistical archive with the account identifier stripped out, so historical usage figures cannot be traced back to your account.
Legal acceptance log
- Which version of which sapplify legal document you accepted
- Timestamp of acceptance
- The sapplify app from which you accepted
This log is append-only and is used to demonstrate, if asked, that you accepted the policies in force at the time you signed up or re-signed in.
AI feature data (conditional)
If you use AI features inside a sapplify app, the content of your prompts and the AI responses are processed by Anthropic on our behalf (see Sub-processors) and stored in your account so the AI can recall context for follow-up questions. No sapplify Sync app uses AI features at the time of writing, but the schema is part of the shared account database.
What sapplify Account does NOT collect
- We do NOT collect your real name, postal address, or government identification.
- We do NOT collect payment card details. All billing is handled by Apple or Google.
- We do NOT collect device location.
- We do NOT operate advertising, ad networks, or cross-app behavioural profiling.
- We do NOT sell or share your data with advertisers or data brokers.
5. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR) and equivalent laws, we process your personal data on the following legal bases:
Contract (Article 6(1)(b))
We need to process your account identity, authentication, profile and entitlement state to deliver the sapplify Account you have asked for. Without this processing, your account cannot work. Sync data is not processed on this basis: see Consent below.
Legitimate interest (Article 6(1)(f))
- Fraud prevention and abuse detection
- Service security (intrusion detection, secret rotation)
- Investigating bugs and incidents
- Retaining short-lived security logs
- Delivering a sharing invitation to an email address you give us, where an app offers that (sDiary's trusted reader). We use that address to send the invitation and to operate the share you set up, and for nothing else
You can object to processing based on legitimate interest. See Section 12 for how.
Consent (Article 6(1)(a))
sapplify Sync runs on your consent, and that consent is given per app. An app's data is copied to our servers only after you have turned Sync on in that app. We record that decision, with the time and the version of this policy in force, as described in Section 4. Turning Sync on in one app says nothing about any other app.
Other processing that relies on your consent: providing a display name, opting into optional notifications, and using AI features.
Withdrawing consent (Article 7(3))
You can withdraw consent at any time, and withdrawing is as easy as giving it. For Sync, turn it off on the account screen in that app: the same control that turned it on. Withdrawal does not affect the lawfulness of any processing carried out before you withdrew. When you turn Sync off for an app, the server copy of that app's data is deleted 30 days later, and the data on your device is not touched. See Section 8.
Special category data (Article 9(2)(a))
Some sapplify apps process health data (for example, sWeight weight entries, sCycle cycle events, sMoment mood entries). Turning Sync on in such an app is your explicit consent to that health data being processed on our servers for the purpose of backing it up and syncing it across your devices. Signing in alone does not give that consent, and you can withdraw it for one app without affecting any other app.
Legal obligation (Article 6(1)(c))
We may process and retain data where required by law, for example, tax records or responses to lawful requests from authorities.
Automated decision-making and profiling
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you under Article 22 GDPR. AI features in sapplify apps provide informational suggestions only; they do not take actions, change your data, or make decisions on your behalf.
6. Sub-processors
The following sub-processors process your sapplify Account data on our behalf under written contracts. Each entry links to that sub-processor's own privacy policy.
| Sub-processor | Role | Location | Privacy policy |
|---|---|---|---|
| Supabase | Authentication, primary database (Postgres), Edge Functions, encrypted backups, transactional email transport | European Union (Ireland) | supabase.com/privacy |
| Vercel | Hosting for the sapplify Account web portal (account.sapplify.com): request routing, server-side rendering, and operational logs, which include IP addresses | Functions execute in the European Union (Dublin), the same region as the database. Vercel Inc. is US-based, and the operational data it holds as our processor, such as request logs, is covered by Standard Contractual Clauses | vercel.com/legal/privacy-policy |
| Apple | Sign in with Apple; App Store billing for per-app Pro purchases; App Store Server Notifications | Global | apple.com/legal/privacy |
| Sign in with Google; Google Play Billing for per-app Pro purchases; Real-time Developer Notifications via Google Cloud Pub/Sub | Global | policies.google.com/privacy | |
| Resend | Transactional email delivery (sign-up confirmation, password reset, service notices) | United States, with Standard Contractual Clauses for EU transfers | resend.com/legal/privacy-policy |
| Anthropic | AI inference. Conditional: only invoked if you use AI features inside a sapplify app. | United States, with Standard Contractual Clauses for EU transfers | anthropic.com/legal/privacy |
We will tell you when we add or change sub-processors. Material changes (a new processor, a change in role) trigger a re-acceptance gate the next time you sign in.
7. Data Residency and International Transfers
Your primary account database, including profile, entitlements, and Sync data, lives in Supabase's European Union region (Ireland). That is where the great majority of it sits at rest.
Two other places hold data, and we would rather name them than imply a single location:
- The sapplify Account web portal is hosted by Vercel. Its server-side rendering runs in the European Union (Dublin), the same region as the database, so pages showing your account data are assembled inside the EU. Requests reach it through Vercel's global edge network, and Vercel keeps short-lived operational logs including IP addresses.
- Usage-analytics rows older than 30 days are moved to an offline statistical archive held on company equipment in Slovakia, with the account identifier stripped out before it is written (see Section 4).
Some sub-processors operate globally. When data leaves the EU to reach them, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal basis for the transfer.
- Apple and Google handle authentication and billing globally; the transfer is necessary to perform the contract you have with each store.
- Resend is headquartered in the United States; transfers covered by SCCs.
- Anthropic (only if you use AI features) is in the United States; transfers covered by SCCs in Anthropic's data processing addendum.
8. Data Retention
How long we keep your data depends on what happens to your account.
| Event | What happens to your data |
|---|---|
| Account is active | Profile, entitlement, and Sync data are kept for as long as your account exists. |
| You turn Sync off for an app | That app's server-side data is scheduled for deletion and removed 30 days after you turn Sync off. Turning Sync back on for that app inside those 30 days cancels the deletion and your data is still there. Other apps are unaffected. The data on your device is never touched. |
| Account deletion (you delete from inside any sapplify app) | Immediate hard-delete across every sapplify app schema, your profile, your entitlement record, and your authentication record. No grace period, no recovery. |
| Usage analytics | Analytics rows stay in our live database for 30 days, then they are removed. We keep a longer-term copy for product statistics with the account identifier stripped out, so it can no longer be linked to you. |
| Sync consent records and their event log | Kept for as long as your account exists, and deleted with it. We keep them deliberately: they are how we can show that your data was synced only with your agreement, and when you gave or withdrew it. |
| Legal acceptance log | Kept for as long as your account exists, and deleted with it. It records which version of which document you accepted and when. |
| Error and crash reports | Same as usage analytics: 30 days in the live database, then removed. What is kept for long-term product statistics is the classification only, without the account identifier, the stack trace or the technical context. Deleting your account removes any report still inside the 30-day window. |
| Encrypted backups | Supabase-managed encrypted backups age out within 7 days of the deletion. After 7 days, no copy of your data remains on our systems. |
| Tax and billing records | Anonymized aggregate records are kept as required by Slovak tax law (typically 10 years). They contain no personal data after account deletion. |
9. Security
We take security seriously, but no online service is risk-free. Here is what we do, and where the limits are.
What we do
- All network traffic between your devices and our servers uses TLS 1.2 or higher.
- Data at rest is encrypted using Supabase-managed AES-256.
- Row-level security policies in our database isolate each user's data so one user cannot read another user's rows.
- Service-role database keys are kept only in server-side environment variables and never bundled into sapplify apps.
- All sign-in events, purchase events, Sync consent changes, and account-deletion events are logged for security investigations.
What we do NOT claim
No end-to-end encryption
sapplify Sync is not end-to-end encrypted. Your data is encrypted in transit and at rest, but sapplify-side service-role access could in principle read the contents (we do not, except as needed to operate the service). Do not use Sync to store information that requires end-to-end encryption.
What you can do
- Choose a strong, unique password.
- Lock your device with PIN, password, or biometric authentication.
- Revoke the sapplify OAuth grant in your Apple or Google account if a device is lost.
- Sign out of devices you no longer use.
10. Data Breach Notification
If a security incident exposes personal data we hold about you, this section describes how we respond.
What could be affected
Because the primary copy of your account data lives on our servers in Supabase's EU region, a server-side incident could in principle expose:
- your email address, profile fields, and auth-provider identifiers;
- the contents of your synced data, for the sapplify apps where you turned Sync on;
- your purchase and entitlement records;
- your Sync consent records.
The following are not stored on our servers and therefore cannot be exposed by a breach on our side:
- your password (Supabase Auth holds only a hash);
- your payment card details (Apple or Google holds them);
- local-only data on devices where Sync is not active.
Notification process
If we become aware of a personal data breach on our servers or at one of our sub-processors:
- We will notify the Slovak Office for Personal Data Protection within 72 hours of becoming aware, as required by Article 33 GDPR, unless the breach is unlikely to result in a risk to your rights.
- If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, as required by Article 34 GDPR. Notification is sent to the email address on your sapplify Account.
The notification will tell you, in plain language: what happened, what data was affected, the likely consequences, what we have done about it, and what you can do to protect yourself.
What you can do
- Change your sapplify Account password if you use email/password sign-in.
- Sign out of all devices and sign back in to invalidate session tokens.
- If you are concerned, delete your sapplify Account (see Section 13).
To date, we have not experienced a personal data breach affecting sapplify Account users.
11. Sharing and Disclosure
We do not sell your data
- We do NOT sell your data to anyone.
- We do NOT share your data with advertisers, marketers, data brokers, or social-media platforms.
- We do NOT use your data to train cross-customer AI models.
- We do NOT send marketing or promotional emails through your sapplify Account. The only emails we send are transactional (sign-up confirmation, password reset, billing notices).
Who actually sees your data
Only the sub-processors listed in Section 6, and only for the roles described there. No other third party has access to your account data.
Sharing you start yourself
Some sapplify apps let you share your own content with a person you choose. sDiary's trusted reader is the current example: you enter someone's email address, we send them an invitation, and if they accept they can read the entries you chose to share.
When you do this you are asking us to process that person's email address. We use it to deliver the invitation and to run the share you set up, and for nothing else. We do not add them to any mailing list. You can revoke a share at any time in the app, and the invitation itself tells the recipient who invited them and how to contact us. Only share content with people who should see it: once someone can read an entry, we cannot un-see it for them.
Legal and law-enforcement requests
We may disclose data if required by a valid court order, statute, or law-enforcement request that meets the legal standards of Slovakia or the European Union. We will notify you when permitted to do so. As of the date of this policy, we have received no such request.
12. Your Rights
You have comprehensive rights over your account data. The exact list depends on where you live.
GDPR rights (European Union and European Economic Area)
- Right of access (Art. 15): ask us what personal data we hold about you.
- Right to rectification (Art. 16): have inaccurate data corrected.
- Right to erasure (Art. 17): have your data deleted. The fastest way is to delete your sapplify Account from inside any sapplify app.
- Right to restriction (Art. 18): limit how we process your data while a dispute is resolved.
- Right to data portability (Art. 20): receive your data in a machine-readable format. See note below.
- Right to object (Art. 21): object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7): withdraw consent at any time for processing that relies on consent.
- Right to lodge a complaint: with the Slovak Office for Personal Data Protection (see Section 17) or your local supervisory authority.
UK GDPR rights (United Kingdom)
UK users have the same rights as EU users under UK GDPR. Complaints can be lodged with the Information Commissioner's Office at ico.org.uk.
CCPA and CPRA rights (California)
- Right to know what personal information we collect and how we use it.
- Right to delete your personal information.
- Right to correct inaccurate information.
- Right to opt out of sale or sharing. (We do not sell or share for cross-context behavioral advertising.)
- Right to non-discrimination for exercising your rights.
- Right to limit the use of sensitive personal information. Our local-first architecture and the absence of secondary uses inherently satisfy this for the data we hold.
LGPD rights (Brazil)
Brazilian users have rights equivalent to GDPR's, including confirmation, access, correction, anonymization, deletion, data portability, and information about sharing. Contact us at privacy@sapplify.com to exercise them.
How to exercise your rights
Portability note
sapplify does not yet offer a single "download all my account data" button. Each sapplify app has its own data-export feature (CSV). For an account-wide portability export, email privacy@sapplify.com and we will assemble it manually.
For access, rectification, restriction, objection, or any other right, email privacy@sapplify.com. We respond within one month, as required by Article 12(3) GDPR. Where a request is complex or you have made several, we may extend by up to two further months and will tell you within the first month that we are doing so, and why. We aim to answer well inside that.
13. Deleting Your sapplify Account
You can delete your sapplify Account from inside any sapplify app (Settings > Account > Delete account). When you confirm, we immediately hard-delete:
- your account record in our authentication system,
- your profile (display name, language preference),
- all data tied to your account in every sapplify app schema, for each app where you turned Sync on (sWeight, sCycle, sMoment, sLists, sTrain, sBudget, sDiary, sDoku, Palate),
- your entitlement record and purchase event history,
- your Sync consent records and their history,
- your legal-acceptance log.
Encrypted backups of our database age out within 7 days of the deletion. After 7 days, no copy of your data remains on our systems.
Account deletion is immediate and is not affected by the 30-day window that applies when you turn Sync off for a single app (Section 8). Deleting your account removes that app's server data straight away, whether or not a deletion was already scheduled.
Two things are NOT removed by account deletion
- Local data on your devices. Each sapplify app keeps a local copy on your device. Uninstall the app, or use the app's in-app "Delete all data" option, to remove it.
- Purchases billed by the store. Deleting your sapplify Account does not cancel or refund anything billed by Apple or Google. sapplify Sync is free and is never billed. If you hold any other store subscription, cancel it separately in your store's subscription settings.
See also our public Account Deletion guide for step-by-step instructions.
14. Children's Privacy
Age requirement
sapplify Account is intended for users aged 16 and older. By creating an account, you confirm that you meet this requirement.
In jurisdictions where a higher minimum age applies to processing personal or health data, that higher age applies.
If you are a parent or guardian and believe a child under 16 has created a sapplify Account, contact us at privacy@sapplify.com and we will delete the account.
15. Cookies and Web Tracking
You can use your sapplify Account in two places, and they behave differently.
Inside a sapplify app. Sign-in happens in the app itself. No cookies are set on your device; the session is held in the app's own secure storage.
In the account web portal at account.sapplify.com. Signing in there sets strictly necessary cookies that hold your session so you stay signed in between pages. They are set by us, they are not used to profile you, and there are no advertising, analytics or cross-site tracking cookies in the portal. Signing out or deleting your account clears the session; you can also clear them in your browser at any time, which signs you out.
The sapplify marketing website (sapplify.com) has its own Privacy Policy that covers cookies and analytics on the site itself.
Global Privacy Control
Because the sapplify Account flow does not place tracking cookies or share data for cross-context behavioral advertising, there is nothing for Global Privacy Control (GPC) or Do Not Track signals to opt out of. We honor these signals by default.
16. Changes to This Policy
We may update this Privacy Policy when our practices change, when we add or remove sub-processors, or when the law requires.
Material changes
Material changes (a new sub-processor, a change in data flows, a change in retention) update the policy version. The next time you sign in to any sapplify app, you are asked to read and re-accept the updated policy before continuing. Your acceptance is recorded server-side.
Non-material changes
Typo fixes, contact-information changes, and reformatting ship silently with an updated "Last updated" date at the top of this page.
Version history
Each version is dated. Earlier versions are available on request at privacy@sapplify.com.
17. Governing Law and Supervisory Authority
This Privacy Policy is governed by the laws of the Slovak Republic, without regard to conflict of law principles.
Lead supervisory authority
We are based in Slovakia. Our lead data-protection supervisory authority is:
Urad na ochranu osobnych udajov Slovenskej republiky
(Office for Personal Data Protection of the Slovak Republic)
Hranicna 12
820 07 Bratislava 27
Slovak Republic
Website: dataprotection.gov.sk
Email: statny.dozor@pdp.gov.sk
EU and EEA users may also lodge complaints with their local supervisory authority.
18. Contact Us
For questions about this Privacy Policy or to exercise any of the rights described in Section 12:
Privacy and data protection: privacy@sapplify.com
General inquiries: contact@sapplify.com
Postal:
Anthony Eli Rasch - sapplify
PO Box 004
91501 Nove Mesto nad Vahom
Slovakia
For data-subject rights requests tied to your sapplify Account, include the email address on the account in your message so we can verify your identity. We respond within 30 days.