Privacy Policy
Effective date: July 23, 2026
Overview
This Privacy Policy explains how Streakl processes information when you use the Streakl mobile application, visit the Streakl website, join the waitlist, send feedback, or contact us.
Streakl is operated by Philipp Romisch as an individual.
Address: Holzhausenstraße 62, 60322 Frankfurt am Main, Germany
Website: www.streakl.app
Privacy contact: philipp@streakl.app
Streakl is a personal productivity and habit-tracking application. It is not a medical device and does not provide medical advice, diagnosis, or treatment.
Information We Process
Accounts and authentication
Streakl uses Firebase Authentication. A temporary anonymous Firebase account is created when you first enter the app so that setup and app data can be associated with the correct session. Guest access is intended as an entry state, not as a durable identity. Until you link the account to Google or Apple, recovery after clearing app data, changing devices, or losing the session may be impossible.
Streakl asks you to link a supported Google or Apple sign-in method before account-bound purchase, purchase-restoration, or gift-claim flows are completed. Linking gives Streakl a durable account to which synchronized data and access status can be associated. The exact providers available depend on the platform.
Depending on the sign-in method, the processed account data may include:
- a Firebase user ID;
- whether the account is anonymous or registered;
- an email address, display name, and profile image URL supplied by the sign-in provider;
- the authentication provider; and
- account creation and last-sign-in information.
Google and Apple also process authentication information under their own terms. Streakl does not receive your Google or Apple password.
Habits, notes, progress, and settings
Streakl stores and synchronizes information you enter or generate in the app through Cloud Firestore, including:
- habit names and optional descriptions;
- icons, colors, goals, schedules, pause/archive state, and reminder settings;
- completion, history, timer, and session events;
- streaks, progress totals, habit statistics, and app statistics;
- optional notes;
- onboarding choices and app settings; and
- device and reminder records used for enabled push notifications.
Habit content is private to the account and is not published to other Streakl users. Habit names, descriptions, and notes are free-text fields. They can reveal health, fitness, medication, religion, addiction, mental wellbeing, or other sensitive information depending on what you choose to enter. Please do not enter information that you do not want Streakl and its service providers to process.
Usage analytics — only with consent
Firebase Analytics is off by default. A new installation or an upgrade without a documented choice does not enable Analytics automatically. Analytics is enabled only after you select Allow analytics.
You can grant or withdraw this consent at any time under Settings → Data controls → Usage analytics. Selecting Not now does not limit any app function. Withdrawal stops app-defined Analytics events immediately, denies Analytics storage, and resets the Analytics data held locally by the SDK, including its app-instance identity. Data already aggregated or de-identified by the provider may not be reversible.
When consent is active, app-defined events may include:
- onboarding starts, technical step identifiers, broad action categories, completion, duration buckets, and count buckets;
- paywall views, plan-category selections, store-checkout starts, and broad purchase-result categories;
- restore, gift-view, gift-claim, and account-link starts and broad result categories;
- subscription-settings actions such as opening store management, viewing plans, or requesting restore; and
- habit creation, completion, and undo events using broad habit/frequency categories and whether a timer is present.
These events use a fixed event dictionary and allow-listed categories. Where a checkout is actually handed to the native store, Analytics may receive the displayed product category, currency, and value needed for the checkout event. Streakl does not add separate app-defined purchase revenue to a completed-purchase event, because the platform may report in-app purchases automatically.
Firebase Analytics may also automatically process technical usage information such as first open, session start, engagement, screen views, app version, operating system, device model, language, time zone, an Analytics app-instance or installation identifier, and approximate geography derived from technical connection information such as the IP address.
Streakl does not set the Firebase Authentication user ID as an Analytics user ID. App-defined events do not contain habit names, descriptions, notes, email addresses, feedback text, notification tokens, account IDs, or other free user input.
Advertising ID access is removed from the Android app. Advertising storage, advertising user data, advertising personalization, Google Signals, cross-app tracking, and ad-personalization signals are not used by Streakl and remain denied. Only Analytics storage can be granted through the in-app choice.
Crash reports and diagnostics
Firebase Crashlytics is enabled separately in Release builds for stability and security diagnostics. It is not controlled by the Usage analytics switch.
Crashlytics may process crash and ANR stack traces, exception class and message, relevant app state, device and operating-system information, app version and build, memory/disk information, Firebase and Crashlytics installation identifiers, session identifiers, and coarse developer-defined diagnostic categories. Streakl may attach an internal feedback report ID and feature category to connect a report to a later crash, but it does not attach the feedback body.
Streakl clears the Crashlytics user identifier and does not assign the Firebase Authentication user ID. Habit names, descriptions, notes, email addresses, and feedback bodies are not intentionally added. Exception messages supplied by operating systems or libraries can nevertheless contain unexpected diagnostic content, so access to crash data is restricted and new reporting calls are reviewed.
Firebase Installations, App Check, and Remote Config
Active Firebase SDKs can use a Firebase Installation ID, installation authentication tokens, app identifiers, SDK and platform versions, and network metadata to address an installation and deliver the configured services.
Firebase App Check uses Play Integrity on Android Release builds and App Attest with DeviceCheck fallback on Apple Release builds. It processes app/device attestation material and short-lived App Check tokens to reduce abuse and verify that requests come from a genuine app instance.
Firebase Remote Config uses the Firebase Installation ID and technical request information to return app configuration. Streakl uses Remote Config for operational configuration, guardrails, in-app banners, and release announcements. It does not activate an AI feature in the current release.
Notifications
Local reminders are scheduled on the device. If you enable remote notifications, Firebase Cloud Messaging and Streakl's backend process a notification token, a Firebase Installation ID, an account association, app version, platform, time zone, notification settings, next-reminder metadata, and delivery records.
Notification permission and reminder settings are voluntary. You can disable them in Streakl and in the device settings. Disabling notifications does not delete the rest of the account.
Feedback and support
Sending feedback is a separate voluntary action. Streakl may process the feedback or support text, category, app version/build, platform, operating-system version, locale, network status, time zone, feature context, and limited interaction breadcrumbs. Bug reports can additionally contain device model/manufacturer, expected and actual behavior, reproduction steps, frequency, and your choice about follow-up contact.
Feedback is stored as a separate support record in the Firestore database in eur3. The callable submitFeedback function receives the submission in us-central1. The notification functions notifyNewFeedback and syncFeedbackNotificationDelivery, together with the ext-firestore-send-email-processqueue extension function, process the feedback notification in us-central1. The extension sends the resulting operator email through Brevo's SMTP relay. Feedback is not automatically deleted merely because the app account is deleted. A broader privacy deletion request can include identifiable feedback and support records, subject to verification and legitimate retention duties.
Smart Coach and AI
Smart Coach and AI processing are disabled in the current release. Streakl does not send habit, account, or usage data to an AI provider. Any future activation requires a separate product, provider, age, privacy, and consent review and an updated notice before processing begins.
Purchases, subscriptions, restore, and gifts
Streakl supports Monthly and Yearly automatically renewing subscriptions and a Lifetime one-time purchase. A free trial or introductory offer is available only when the applicable store presents it and confirms that the store account is eligible. Final products, price, currency, tax, billing period, eligibility, renewal terms, and any offer are shown by Google Play or Apple before you confirm a purchase; Streakl does not set a universal price in this Policy.
Google Play or Apple processes the payment under the store account and store terms. Streakl does not receive or store your full payment-card number. Streakl uses RevenueCat to retrieve store offerings, validate purchase records, restore purchases, and determine whether the linked account has the relevant access entitlement.
Depending on the store and transaction, purchase processing can include:
- a pseudonymous Streakl/RevenueCat customer identifier associated with the linked account;
- store, platform, product, package, and offering identifiers;
- transaction or original-transaction identifiers and store receipt or purchase-token data;
- purchase, renewal, expiration, cancellation, billing-issue, trial, introductory-offer, and entitlement status; and
- limited technical request, device, app-version, country/region, and diagnostic information supplied by the store or SDK.
Streakl may also process a gift campaign or offer identifier, eligibility and claim status, claim time, duration or expiry, linked-account identifier, and limited security/rate-limit information. A gift does not require Streakl to receive payment-card data. Gift access and purchase access are both resolved into the app's entitlement state; a pending or unverified result does not grant access until verification succeeds.
Local storage and export
Streakl stores local preferences and caches to keep the app responsive. These can include cached habits, timer/session state, statistics, onboarding state, language and theme preferences, notification settings, profile-image URLs, and the Analytics choice.
The data export feature creates a JSON export or printable PDF locally and opens the device share sheet. Streakl does not upload that export to a separate Streakl export server. The destination you choose in the share sheet applies its own terms.
Deleting an account in the app clears Streakl's user-scoped local data on that device. Uninstalling the app or clearing its storage also removes app-local data, subject to operating-system backup behavior.
Website and waitlist
When you join the waitlist or contact us through the website, we may process your email address, message, request details, and related delivery information.
Vercel hosts the website and necessarily processes connection and security information such as IP address, browser/device information, requested pages, timestamps, and request logs. GitHub hosts the website source and supports the deployment connection to Vercel. Loops processes waitlist addresses and related email-delivery information. The current website includes no client-side analytics; Vercel Web Analytics, Vercel Speed Insights, TelemetryDeck, and Plausible are not part of its runtime or dependencies.
Purposes and Legal Bases
We process account, habit, synchronization, timer, statistics, export, user-enabled reminder, purchase, restore, entitlement, and eligible gift-claim data to provide Streakl and take steps requested by you, based on Art. 6(1)(b) GDPR.
We process Usage analytics only after consent under Art. 6(1)(a) GDPR. The same choice also addresses access to or storage of Analytics information on the device where consent is required under Section 25 TDDDG. You may withdraw consent at any time without affecting processing that took place before withdrawal.
We process Crashlytics diagnostics, App Check data, security logs, rate-limit records, and necessary website security logs based on our legitimate interests under Art. 6(1)(f) GDPR in keeping Streakl secure, reliable, and protected against abuse. The separate legal assessment and balancing of interests remain subject to applicable law.
We process purchase and transaction records where necessary to administer access, restore purchases, prevent duplicate or abusive claims, handle disputes, and comply with tax, accounting, consumer-protection, or other legal duties. Depending on the purpose, the legal basis is Art. 6(1)(b), Art. 6(1)(c), or Art. 6(1)(f) GDPR.
We process push-notification data to provide reminders you enable, based on Art. 6(1)(b) GDPR and, where required, consent under Art. 6(1)(a) GDPR and device permission.
We process feedback and support correspondence to respond to your request based on Art. 6(1)(b) or Art. 6(1)(f) GDPR. Waitlist registration is based on consent under Art. 6(1)(a) GDPR.
We may retain minimal request or compliance records to meet legal obligations under Art. 6(1)(c) GDPR or to establish, exercise, or defend legal claims under Art. 6(1)(f) GDPR.
If free-text habit content reveals special-category data, Art. 9 GDPR may apply. Streakl does not require such content; the appropriate legal basis and safeguards for the intended use should be reviewed before entering particularly sensitive information.
Recipients, Service Locations, and International Transfers
We do not sell personal information and do not use Streakl for third-party advertising or cross-app tracking.
Relevant recipients and service providers are:
- Google Firebase and Google Cloud for Authentication, Firestore, Cloud Functions, App Check, Installations, Remote Config, Analytics after consent, Crashlytics, and Cloud Messaging;
- RevenueCat for store offering retrieval, purchase validation, entitlement management, and purchase restoration;
- Google Sign-In and Google Play for provider authentication, Android distribution, store billing, and subscription management;
- Apple for Sign in with Apple, Apple-platform distribution, store billing, and subscription management;
- Vercel for website hosting;
- GitHub for source-code hosting and the website deployment connection;
- Loops for waitlist and related email delivery; and
- Brevo as the SMTP delivery provider for feedback notification and support correspondence.
The primary Cloud Firestore database is located in the European multi-region eur3. The deployed feedback and mail functions notifyNewFeedback, syncFeedbackNotificationDelivery, submitFeedback, and ext-firestore-send-email-processqueue run in us-central1. This means that feedback notification and email-processing data is transferred from the Firestore database in eur3 to functions in the United States. Firebase, RevenueCat, the stores, and the other providers may also process purchase, operational, support, security, and service data in the United States and other countries.
Where GDPR transfer rules apply, transfers rely on the safeguard available for the recipient and service, such as an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses in the applicable provider data-processing terms. Mandatory consumer and data-protection rights remain unaffected.
Retention
We retain information only for as long as needed for the described purpose:
- active account, habit, progress, setting, and synchronization data is kept while the account is active and is deleted or scheduled for deletion after a valid request;
- protected backup copies expire according to the applicable provider backup and recovery lifecycle and are not used to continue a deleted account;
- Firebase Crashlytics, App Check, Firebase Installation, FCM, and Remote Config records are kept only as needed for their diagnostic, security, installation, notification, and configuration purposes and follow the applicable provider lifecycle;
- Analytics is not collected without consent. When consent is active, the Google Analytics property is configured to retain event data for 2 months and user data for up to 14 months. Aggregated or de-identified reporting may remain after those periods;
- purchase, subscription, restore, entitlement, and gift-claim records are kept while needed to provide and verify access, handle store lifecycle events, prevent duplicate claims, meet accounting or legal duties, or resolve disputes. Google Play, Apple, and RevenueCat retain their own transaction and service records under their applicable policies and legal duties;
- feedback, delivery status, and support correspondence are kept while needed to deliver and resolve the request, provide follow-up, maintain service security, or handle legal claims. Identifiable records are deleted or anonymized when those purposes no longer apply;
- a minimal deletion-request record is kept only as long as reasonably necessary to demonstrate proper handling or comply with legal duties;
- website and repository security/request logs follow the configured Vercel and GitHub service lifecycles and may be kept longer where a security incident or legal duty requires it; and
- waitlist information is retained until the waitlist closes, you unsubscribe, or you request deletion.
When longer retention is required by law or for legal claims, the information is restricted to that purpose and is not used to continue a deleted account.
Account and Data Deletion
To delete your Streakl account in the app:
- Open Settings.
- Open Data controls.
- Select Delete account.
- Complete any required recent sign-in and confirm deletion.
You can also use the Streakl account deletion page or email philipp@streakl.app if you no longer have access to the app.
Account deletion removes or schedules deletion of the Firebase Authentication account and user-owned Streakl cloud data, including habits, completion/history/session events, habit and app statistics, settings, registered notification devices/tokens, and reminder-send records. In-app deletion also clears user-scoped Streakl data on that device.
Deleting a Streakl account does not cancel a Google Play or Apple subscription, issue a refund, or erase the store's purchase history. Cancel an active subscription in the applicable store before deleting the account if you do not want it to renew. Store transaction records, RevenueCat records needed for purchase validation or legal compliance, limited entitlement/gift anti-abuse records, separately stored feedback/support records, provider security records, protected backups, and aggregated or de-identified Analytics or diagnostic data may remain as described above. A broader privacy request can ask us to identify and delete separately stored Streakl or processor records where legally and technically possible; it cannot require Streakl to erase records controlled by a store when the store must or may retain them.
Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, receive portable data, or withdraw consent.
You can:
- change Usage analytics under Settings → Data controls;
- control notifications in Streakl and the device settings;
- manage or cancel an active subscription in Google Play or Apple;
- export your habit data;
- delete your account in the app;
- unsubscribe from waitlist email; and
- contact us to exercise a privacy right or object to processing based on legitimate interests.
We may need to verify your identity before fulfilling a request. We will not ask you to send your password or an authentication code.
Right to complain
You may lodge a complaint with a data-protection supervisory authority, especially in the EU Member State of your residence, place of work, or the alleged infringement. For the controller address above, the competent authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
Website: datenschutz.hessen.de
Security
Streakl uses HTTPS or equivalent transport encryption for the identified network paths, Firebase Authentication, App Check, Firestore security rules, access controls, and data-minimizing telemetry design. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
Children
Streakl is not designed for children and is intended for users aged 16 and older. We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
AI processing is not active in the current release.
Changes to This Policy
We may update this Privacy Policy as Streakl, its providers, or legal requirements change. We will update the effective date and provide additional notice where appropriate.
Contact
For privacy questions, rights requests, or account-deletion requests:
Philipp Romisch
Holzhausenstraße 62
60322 Frankfurt am Main
Germany
Email: philipp@streakl.app
Website: www.streakl.app