Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how Streakl processes information when you use the Streakl mobile application, visit the Streakl website, join the waitlist, send feedback, or contact us.
Streakl is operated by Philipp Romisch as an individual. For data-protection purposes, Philipp Romisch is the controller for processing described in this Policy.
Address: Holzhausenstraße 62, 60322 Frankfurt am Main, Germany
Website: www.streakl.app
Privacy contact: philipp@streakl.app
Information We Process
Account and authentication data
Streakl uses Firebase Authentication. When you sign in with Google or Apple, Streakl may process:
- a Firebase user ID;
- your email address, display name, and profile image URL supplied by the sign-in provider;
- the authentication provider; and
- account creation and last-sign-in information.
Streakl does not receive your Google or Apple password. Google and Apple process authentication information under their own terms and privacy notices.
Habits, progress, settings, and synchronization
Streakl stores and synchronizes information you enter or generate in the app through Cloud Firestore, including:
- habit names and optional descriptions;
- icons, colors, goals, schedules, pause or archive state, and reminder settings;
- completion, history, timer, and session events;
- streaks, progress totals, habit statistics, and app statistics;
- optional notes;
- onboarding choices and app settings; and
- device and reminder records used for enabled push notifications.
Habit content is private to your account and is not published to other Streakl users. Free-text fields can reveal sensitive information depending on what you choose to enter. Please do not enter information that you do not want Streakl and its service providers to process.
Usage analytics
Firebase Analytics is enabled only after you choose Allow analytics. You can grant or withdraw this consent under Settings → Data controls → Usage analytics. Choosing Not now does not limit app functionality. Withdrawal stops new Analytics collection; information already aggregated or de-identified by the provider may not be reversible.
With consent, Streakl measures broad categories of onboarding, feature, habit, subscription, restore, gift, and checkout interactions. Events may include completion states, duration or count ranges, broad habit or frequency categories, and technical information such as app version, operating system, device model, language, time zone, installation identifier, and approximate geography. A store-checkout event may include the displayed product category, currency, and value.
Streakl does not use the Firebase Authentication user ID as an Analytics user ID. Analytics events do not intentionally contain habit names, descriptions, notes, email addresses, feedback text, notification tokens, account IDs, or other free user input. Streakl does not use personal information for third-party advertising or cross-app tracking.
Crash reports and diagnostics
Firebase Crashlytics is used for stability and security diagnostics. It may process crash and ANR stack traces, exception class and message, relevant app state, device and operating-system information, app version and build, memory and disk information, Firebase and Crashlytics installation identifiers, session identifiers, and diagnostic categories.
Streakl clears the Crashlytics user identifier and does not assign the Firebase Authentication user ID. Habit names, descriptions, notes, email addresses, and feedback bodies are not intentionally added. Exception messages supplied by operating systems or libraries can nevertheless contain unexpected diagnostic content, so access to crash data is restricted.
App security, configuration, and notifications
Firebase may process installation identifiers, authentication tokens, app and device-attestation signals, app, SDK, and platform versions, and network metadata to authenticate app instances, reduce abuse, and deliver operational configuration.
Local reminders are scheduled on your device. If you enable remote notifications, Firebase Cloud Messaging and Streakl's backend may process a notification token, Firebase Installation ID, account association, app version, platform, time zone, notification settings, next-reminder metadata, and delivery records. Notification permission and reminder settings are voluntary and can be changed in Streakl or your device settings.
Purchases and subscriptions
Streakl may offer optional auto-renewable subscriptions or other paid features through an applicable app store. The store shows the available product, price, currency, taxes, billing period, eligibility, renewal terms, and any trial or introductory offer before you confirm a purchase.
The applicable store processes the payment. Streakl does not receive or store your full payment-card number. Streakl uses RevenueCat for store-offering retrieval, purchase validation, entitlement management, and purchase restoration. Depending on the store and transaction, Streakl or RevenueCat may process:
- a pseudonymous customer identifier associated with your Streakl account;
- store, platform, product, package, and offering identifiers;
- transaction or original-transaction identifiers and store receipt or purchase-token data;
- purchase, renewal, expiration, cancellation, billing-issue, trial, introductory-offer, and entitlement status; and
- limited technical, device, app-version, country or region, and diagnostic information supplied by the store or SDK.
Streakl processes this information to provide and verify access, restore purchases, prevent abuse, provide support, and comply with legal obligations. Apple and Google process payment and store-account information under their own terms and privacy notices.
Local storage and export
Streakl stores local preferences and caches to keep the app responsive. These may include cached habits, timer and session state, statistics, onboarding state, language and theme preferences, notification settings, profile-image URLs, and your Analytics choice.
The export feature creates a JSON export or printable PDF locally and opens the device share sheet. Streakl does not upload that export to a separate Streakl export server. The destination you choose in the share sheet applies its own terms.
Deleting an account in the app clears Streakl's user-scoped local data on that device. Uninstalling the app or clearing its storage also removes app-local data, subject to operating-system backup behaviour.
Feedback, support, and the website
When you send feedback or contact us, we may process your email address, message, request details, app version and build, platform, operating-system version, locale, network status, time zone, feature context, and limited interaction breadcrumbs. Bug reports may also contain device details, expected and actual behaviour, reproduction steps, and your choice about follow-up contact.
Feedback is stored as a separate support record in Streakl's primary database, hosted in the EU. Receiving feedback and delivering related operator email involve limited backend processing in the United States, with Brevo acting as the SMTP delivery provider. Feedback is not automatically deleted merely because an app account is deleted.
When you join the website waitlist, we process your email address and related delivery information. Vercel hosts the website and processes connection and security information such as IP address, browser or device information, requested pages, timestamps, and request logs. We also use Vercel Web Analytics to measure aggregate website traffic using anonymized, cookie-free data such as page views, referrers, browser and operating-system information, and broad visitor location. Loops processes waitlist addresses and related email-delivery information.
How We Use Information and Legal Bases
We process account, habit, synchronization, timer, statistics, export, user-enabled reminder, purchase, restore, entitlement, and eligible promotional-access data to provide Streakl and take steps requested by you, based on Art. 6(1)(b) GDPR.
We process Usage Analytics only after consent under Art. 6(1)(a) GDPR. The same choice addresses access to or storage of Analytics information on the device where consent is required under Section 25 TDDDG. You may withdraw consent at any time without affecting processing that took place before withdrawal.
We process Crashlytics diagnostics, app-integrity data, security logs, rate-limit records, and necessary website security logs based on our legitimate interests under Art. 6(1)(f) GDPR in keeping Streakl secure, reliable, and protected against abuse.
We process purchase and transaction records where necessary to administer access, restore purchases, prevent duplicate or abusive claims, handle disputes, and comply with tax, accounting, consumer-protection, or other legal duties. Depending on the purpose, the legal basis is Art. 6(1)(b), Art. 6(1)(c), or Art. 6(1)(f) GDPR.
We process push-notification data to provide reminders you enable, based on Art. 6(1)(b) GDPR and, where required, consent under Art. 6(1)(a) GDPR and device permission.
We process feedback and support correspondence to respond to your request based on Art. 6(1)(b) or Art. 6(1)(f) GDPR. Waitlist registration is based on consent under Art. 6(1)(a) GDPR. We may retain minimal request or compliance records to meet legal obligations or establish, exercise, or defend legal claims.
If free-text habit content reveals special-category data, Art. 9 GDPR may apply. Streakl does not require such content; please consider this before entering particularly sensitive information.
Recipients and International Transfers
We do not sell personal information and do not use Streakl for third-party advertising or cross-app tracking. Relevant service providers and recipients include:
- Google Firebase and Google Cloud for accounts, data storage and synchronization, backend processing, app security and configuration, Analytics after consent, crash diagnostics, and notifications;
- RevenueCat for store-offering retrieval, purchase validation, entitlement management, and purchase restoration;
- Google Sign-In and Google Play for provider authentication, Android distribution, store billing, and subscription management;
- Apple for Sign in with Apple, Apple-platform distribution, store billing, and subscription management;
- Vercel for website hosting, security logs, and Web Analytics;
- GitHub for source-code hosting and the website deployment connection;
- Loops for waitlist and related email delivery; and
- Brevo as the SMTP delivery provider for feedback notification and support correspondence.
The primary Cloud Firestore database is located in the European Union. Some backend functions used to receive feedback and deliver feedback notifications run in the United States. Firebase, RevenueCat, the stores, and other providers may also process purchase, operational, support, security, and service data in the United States and other countries.
Where GDPR transfer rules apply, transfers rely on an available safeguard for the recipient and service, such as an adequacy decision or the European Commission's Standard Contractual Clauses in the applicable provider data-processing terms.
Retention
We retain information only for as long as needed for the described purpose:
- active account, habit, progress, setting, and synchronization data is kept while the account is active and is deleted or scheduled for deletion after a valid request;
- protected backup copies expire according to the applicable provider backup and recovery lifecycle and are not used to continue a deleted account;
- app-security, installation, notification, configuration, and crash-diagnostic records are kept only as needed for those purposes and follow the applicable provider lifecycle;
- when Analytics consent is active, the Google Analytics property is configured to retain event data for 2 months and user data for up to 14 months. Aggregated or de-identified reporting may remain after those periods;
- purchase, subscription, restore, entitlement, and promotional-access records are kept while needed to provide and verify access, handle store lifecycle events, prevent abuse, meet accounting or legal duties, or resolve disputes. Google Play, Apple, and RevenueCat retain their own transaction and service records under their applicable policies and legal duties;
- feedback, delivery status, and support correspondence are kept while needed to deliver and resolve the request, provide follow-up, maintain service security, or handle legal claims;
- a minimal deletion-request record is kept only as long as reasonably necessary to demonstrate proper handling or comply with legal duties;
- website and repository security or request logs follow the configured provider lifecycles and may be kept longer where a security incident or legal duty requires it; and
- waitlist information is retained until the waitlist closes, you unsubscribe, or you request deletion.
When longer retention is required by law or for legal claims, the information is restricted to that purpose and is not used to continue providing a deleted account.
Account and Data Deletion
To delete your Streakl account in the app:
- Open Settings.
- Open Data controls.
- Select Delete account.
- Complete any required recent sign-in and confirm deletion.
You can also use the Streakl account deletion page or email philipp@streakl.app if you no longer have access to the app.
Account deletion removes or schedules deletion of the Firebase Authentication account and user-owned Streakl cloud data, including habits, completion, history and session events, statistics, settings, registered notification devices and tokens, and reminder-send records. In-app deletion also clears user-scoped Streakl data on that device.
Deleting a Streakl account does not cancel an Apple or Google Play subscription, issue a refund, or erase the store's purchase history. Cancel an active subscription in the applicable store before deleting the account if you do not want it to renew. Store transaction records, RevenueCat records needed for purchase validation or legal compliance, limited promotional-access records, separately stored feedback or support records, provider security records, protected backups, and aggregated or de-identified Analytics or diagnostic data may remain as described above.
Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, receive portable data, or withdraw consent.
You can:
- change Usage Analytics under Settings → Data controls;
- control notifications in Streakl and your device settings;
- manage or cancel an active subscription in the applicable app store;
- export your habit data;
- delete your account in the app; and
- unsubscribe from waitlist email; and
- contact us to exercise a privacy right or object to processing based on legitimate interests.
We may need to verify your identity before fulfilling a request. We will not ask you to send your password or an authentication code.
Right to complain
You may lodge a complaint with a data-protection supervisory authority, especially in the EU Member State of your residence, place of work, or the alleged infringement. For the controller address above, the competent authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
Website: datenschutz.hessen.de
Security
Streakl uses HTTPS or equivalent transport encryption for identified network paths, Firebase Authentication, app-integrity controls, Firestore security rules, access controls, and data-minimizing telemetry design. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
Children
Streakl is not designed for children and is intended for users aged 16 and older. We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
Changes to This Policy
We may update this Privacy Policy as Streakl, its providers, or legal requirements change. We will update the last-updated date and provide additional notice where appropriate.
Contact
For privacy questions, rights requests, or account-deletion requests:
Philipp Romisch
Holzhausenstraße 62
60322 Frankfurt am Main
Germany
Email: philipp@streakl.app
Website: www.streakl.app