Home/Apps Privacy Policy
Privacy Policy for Anemoia Apps
This is the privacy policy for the mobile apps Anemoia publishes. It explains what those apps collect, why we collect it, who else touches it, and what you can do about any of it.
It is written to be read rather than skimmed past. If a section is unclear, email us and we will fix the wording.
Questions, corrections, or a deletion request go to contact@anemoia.dev.
1. Which apps this covers
This policy applies to every mobile app published under the Anemoia developer accounts on Google Play and the Apple App Store, and to the pages on anemoia.dev that those apps link to. One document covers all of them because the apps are built from shared templates and rely on the same short list of third-party services.
If an app handles something this document does not describe, that app ships its own policy and links to it from its store listing. Where the two disagree, the app-specific policy wins.
Every listing also carries a Data safety summary on Google Play, or a privacy label on the App Store, naming exactly what that app collects. Read the listing for the per-app answer and this page for the detail behind it.
2. Who we are
Anemoia builds and publishes the apps described here. For everything in this policy we act as the data controller under the UK and EU GDPR, and as a business under the California Consumer Privacy Act.
Email reaches us fastest. Postal addresses are at the bottom of this page.
Privacy inquiries: contact@anemoia.dev
3. What our apps collect
Most of our apps work without an account and without a login. What follows is the full set of data any of them may touch; a given app touches a subset of it.
- Content you create in the app
- Notes, lists, photos, imported files, saved settings, game progress. This sits in the app's own storage on your device. We do not receive it and we cannot read it, and it goes away when you clear the app's data or uninstall it. If your device backs itself up to Google Drive or iCloud, that copy is governed by Google's or Apple's terms rather than ours.
- Device and app information
- Device model, operating system version, app version, language, time zone, screen size, and the country your connection comes from. Analytics and crash tools collect this automatically, which is how we tell a genuine bug apart from a quirk on one manufacturer's firmware.
- How you use the app
- Which screens open, which features get used, how long a session runs, whether a flow such as onboarding was finished. These events attach to a random identifier the analytics SDK generates for your installation of the app. They are not attached to your name.
- Crash and performance diagnostics
- When an app crashes or freezes we receive a stack trace and the device state at that moment: free memory, orientation, app version, and the sequence of events leading up to the failure. A crash report can occasionally contain a fragment of whatever was in memory when the app stopped.
- Advertising identifier
- Apps that show ads read the advertising identifier your device provides: the Google Advertising ID on Android, the Identifier for Advertisers on iOS. It is a resettable number rather than a name, and you can reset or delete it from system settings whenever you like.
- Approximate location
- Worked out from your IP address and accurate to roughly city or region level. It decides which ads are legal to show you and which currency to display. None of our apps read precise GPS location unless the app is built around a map, weather, or nearby-search feature, in which case it asks for the location permission first and uses it only while that feature is open.
- Messages you send us
- If you email support or use an in-app feedback form, we get your email address, whatever you wrote, and anything you attached. We keep the thread so that whoever picks it up next has the history.
- Account details
- Only apps that need an account ask for one. The usual set is an email address and a password, or a Sign in with Google or Apple token if you pick that route. Your Google or Apple password never reaches us.
- Purchases and subscriptions
- Google Play and the App Store take the payment. They tell us a purchase happened, what it was for, and whether a subscription is still active. Card numbers, billing addresses, and bank details do not reach our systems, and we have no way to charge you directly.
We do not collect your contacts, your call or SMS logs, your browsing activity outside the app, your health data, or anything else a store policy classifies as sensitive personal information.
4. Device permissions
Android and iOS both make an app ask before it reaches the camera, your photo library, your location, or your notifications. Our apps ask at the moment a feature needs the permission rather than all at once on first launch, and the prompt names the feature.
- —Camera or photo library, in apps that let you import, scan, or save an image. The image stays in the app's storage.
- —Files and media, in apps that import or export documents. Limited to the files you pick.
- —Location, in apps with a map, weather, or nearby-search feature.
- —Notifications, for reminders and alerts you set up yourself.
- —Internet and network state, which every app needs to load content, fetch ads, and send crash reports.
Decline any prompt and the app still runs; the feature behind that prompt does not. You can change an answer later under Settings, Apps, the app name, then Permissions on Android, or Settings and the app name on iOS.
5. Why we use this data
The UK and EU GDPR require a lawful basis for each purpose. This table is the mapping.
| What we do | Why | Lawful basis |
|---|---|---|
| Run the app and the features you ask for | The app cannot work otherwise | Performance of a contract |
| Fix crashes and slow screens | A broken release gets uninstalled and reviewed badly | Legitimate interests |
| Count which features get used | So the work goes into the parts people open and away from the parts they ignore | Legitimate interests, or consent where local law requires it |
| Show ads | Ads pay for the apps that are free | Consent in the EEA, UK and Switzerland; legitimate interests elsewhere, subject to local law |
| Measure whether an ad worked | Advertisers pay on results | Consent where required, otherwise legitimate interests |
| Reply to your support email | You wrote to us | Legitimate interests |
| Process a purchase or subscription | You bought something | Performance of a contract |
| Detect fraud, abuse, and invalid ad traffic | It protects the apps and our ad account | Legitimate interests, and legal obligation where one applies |
| Keep tax and accounting records | The law says so | Legal obligation |
Where the basis is legitimate interests, we have weighed ours against your privacy and judged the processing narrow enough to be fair. Ask about a specific case and we will walk you through the reasoning.
6. Who else handles your data
We do not sell data and we do not pass it to data brokers. A short list of providers processes data on our behalf, each under its own published policy. The Data safety section of a given listing tells you which of these that app actually uses.
Google AdMob
Serves the ads in our free apps and pays out the revenue.
Data it receives: Advertising identifier, approximate location from IP address, device and app information, ad interactions.
Their privacy terms →Google Analytics for Firebase
Counts feature usage and retention so we know what to build next.
Data it receives: App instance identifier, device and app information, in-app events, approximate location from IP address.
Their privacy terms →Firebase Crashlytics
Collects crash and stability reports.
Data it receives: Stack traces, app instance identifier, device state at the moment of the crash.
Their privacy terms →Google Play services and Google Play Billing
Distributes the Android apps and processes purchases.
Data it receives: Google account identifiers, purchase records, device information.
Their privacy terms →Apple App Store and StoreKit
Distributes the iOS apps and processes purchases.
Data it receives: Apple account identifiers, purchase records, device information.
Their privacy terms →Our email provider
Carries and stores the support mail you send to our contact address.
Data it receives: Your email address, your message, and anything you attach to it.
Beyond that list, we hand over data only when a court order, a regulator, or a law enforcement request with legal force requires it, and only as far as the request reaches. If an app changes hands, we will say so on its store listing before the transfer takes effect.
7. Advertising and your choices
Most of our apps are free and carry ads through Google AdMob. A personalized ad is chosen partly from your advertising identifier and the interests associated with it. A non-personalized ad is chosen from the app you are in and your rough location, nothing else.
In the European Economic Area, the United Kingdom, and Switzerland, the app shows a consent form on first launch. Nothing goes toward personalized advertising unless you agree there. You can reopen that form from the app's settings screen at any point and change your answer, including withdrawing consent outright.
Three controls sit outside our apps and work regardless of what you told us:
- —Android: Settings, then Privacy, then Ads, lets you reset the advertising ID or delete it. Delete it and apps stop receiving an ID at all, which forces ads to be non-personalized.
- —iOS: Settings, then Privacy and Security, then Tracking, controls whether apps may even ask for the Identifier for Advertisers. If you never allowed it, our apps never had it.
- —Google account holders: myadcenter.google.com controls the personalization Google applies across its own products and its ad network.
Switching personalization off does not remove the ads. It changes how they get chosen, and it usually makes them less relevant.
8. Children
Our apps are built for a general audience. We do not direct them at children under 13, or under whatever age your country sets for digital consent, and we do not knowingly collect personal data from anyone in that group.
Where an app is listed in the Google Play Families program or carries a child-directed rating, it runs under tighter rules: no personalized ads, no use of the advertising identifier for ad targeting, and ad content filtered to the app's age rating.
If you are a parent or guardian and believe your child gave us personal data, email us with enough detail to locate the record. We will delete it and confirm once it is gone.
Report a child's data: contact@anemoia.dev
9. How long we keep it
| Data | How long |
|---|---|
| Anything stored on your device | Until you clear the app's data or uninstall it. We hold no copy. |
| Crash and stability reports | Up to 90 days in Crashlytics, then deleted automatically. |
| Analytics events | Up to 14 months, the longest user-level retention Google Analytics for Firebase offers. Aggregate counts with no identifier attached may outlive that. |
| Advertising identifiers held by ad partners | On Google's own retention schedule, set out in its advertising policies. |
| Support email threads | 24 months after the conversation ends, unless it concerns an unresolved legal or safety matter. |
| Account records, in apps that have accounts | While the account is open, then 30 days after you ask us to delete it. Backup copies age out within a further 90 days. |
| Purchase and subscription records | As long as tax and accounting law requires, which across the countries we operate in usually means seven years. |
10. Deleting your data
Four of these you can do yourself, right now, without asking us:
- —Remove everything the app stored locally: uninstall it, or use Settings, Apps, the app name, Storage, then Clear data on Android. Nothing survives that.
- —Cut the link to your analytics history: clearing the app's data or reinstalling generates a fresh app instance identifier, and the earlier events no longer connect to anything you use.
- —Remove your advertising identifier: Settings, Privacy, Ads, then Delete advertising ID on Android, or leave tracking off on iOS.
- —Close an account: apps with accounts carry a Delete account option in their settings. It removes the account and the data attached to it rather than only suspending access.
For anything else, email us from the address you used to contact us, or tell us the app name, roughly when you used it, and the device you used. We answer within 30 days. If a request turns out to be complicated we will say so and give you a date rather than go quiet.
Send a deletion request to: contact@anemoia.dev
Two categories we cannot delete on request: purchase receipts we are required to keep for tax, and records we need to defend a legal claim. Where one of those applies we will tell you which, rather than let the request lapse.
11. Security
Traffic between our apps and any server we run travels over TLS. The consoles holding analytics, crash, and account data sit behind accounts with two-factor authentication, and access is limited to the people whose work needs it. Card numbers are stored nowhere on our side, because payment never touches our systems in the first place.
None of that makes a breach impossible, and we are not going to claim otherwise. If one happens and it puts you at risk, we will notify you and the relevant regulator inside the deadlines the law sets, which under the GDPR means 72 hours from the point we become aware.
12. Where your data is processed
Our team works from the United States, the United Kingdom, and Pakistan, and the providers listed above process data mainly in the United States. If you use one of our apps from the EEA or the UK, your data leaves that region.
Those transfers rest on the European Commission's standard contractual clauses and the UK addendum to them, which our providers build into their terms. Ask and we will point you at the clauses a particular provider relies on.
13. Your rights
Wherever you live, you can email and ask what we hold, ask for a copy, ask us to correct it, or ask us to delete it. There is no charge and you do not need an account for us to honor the request.
If the UK or EU GDPR applies to you, the full set is access, rectification, erasure, restriction of processing, portability, objection to processing we base on legitimate interests, objection to direct marketing at any time, and withdrawal of consent without that affecting anything done while the consent stood. You can also complain to your supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk.
We answer inside one month, extendable by two further months for genuinely complicated requests, and we will tell you if we take the extension. Expect a question or two to confirm you are who you say you are, particularly where the request would delete something.
Make a request at: contact@anemoia.dev
14. California residents
If you live in California you have the right to know what we collect and why, to receive a copy, to correct it, to delete it, and to opt out of its sale or sharing. Using any of those rights does not get you a worse version of the app.
We do not sell personal information for money. Passing an advertising identifier to Google for personalized advertising may still count as a sale, or as sharing for cross-context behavioral advertising, under California law. You can stop it by turning personalized ads off in the app, by deleting your advertising ID in Android settings, or by declining the tracking prompt on iOS. Each of those is a valid opt-out. On this website we also honor the Global Privacy Control signal.
15. Changes to this policy
We update this page whenever the apps change what they collect, and the date at the top tells you when it last moved.
If a change widens what we collect in a way that matters to you, we will flag it in the app or on the store listing before it takes effect. Where the law requires consent for the new processing, we will ask again rather than treat your earlier answer as covering it.
16. Contact us
Email is the fastest route. Put the app name in the subject line and the message reaches the right person sooner.
Email: contact@anemoia.dev
Post works too, though it takes considerably longer:
United States
131 Continental Drive, Suite 305, Newark, DE 19713
United Kingdom
9 Marlborough Road, Southall, UB2 5LW
Pakistan
Anemoia Plaza, Opal Square, Wah Cantt