Privacy Policy for Ricodia

Privacy information about the Ricodia app, its local data, voluntary feedback and external services.

Ricodia is an offline-first app for daily morning impulses, weather context, sayings, local notifications, widgets and voluntary challenges. Many data points remain only on your device.

Controller

Patrick Benkö e.U. Contact: office@ricodia.app Support: support@ricodia.app

Summary

Ricodia stores everyday progress and preferences locally. The voluntary trial lasts exactly 168 hours from the final onboarding action; it starts no subscription. The app includes a Bad Coach recommendation and limited technical startup diagnostics, described below.

An account is optional and independent of backup. Sign-in uses Apple, Google or an email link through Supabase Auth, which processes the user ID, provider and supplied email address. For Google sign-in, Supabase Auth also receives the profile name and profile picture URL (picture/avatar_url) supplied by Google, if present, and stores them as profile metadata. Ricodia stores the complete sign-in session, including credentials and user/profile metadata, locally so that sign-in can be restored after a restart.

Backup requires a valid paid Sync entitlement, purchased separately or in a bundle; additional Pro access is not required. Deliberate account connection, device approval and explicit backup activation are also required. Optional sign-in alone neither activates backup nor transfers progress.

Technical startup diagnostics

When local startup fails, Ricodia automatically attempts to send a limited technical report to Supabase to help resolve startup problems. It contains the event and server receipt times, startup phase, error type, sanitized technical reason, available SQLite/operating-system error codes and package source locations from the stack trace, app/build/OS/runtime versions, language, startup duration, retry number, an allowed destination screen and hydration intent.

No account or purchase tokens, keys, preference values, SQL statements or parameters, private file paths or permanent device/installation identifiers are sent. Random event/process identifiers apply only within one app process and are not linked to an account. The provider may process connection data such as IP addresses; the diagnostics table stores no IP address.

Each error gets one time-limited background attempt, for at most two distinct error phases per startup attempt. There is no local queue or later delivery: offline and transmission failures discard the report without blocking startup or retry. A new failed startup attempt may create a new report. Daily cleanup removes entries received by the server more than 90 days earlier. Reports support app functionality, not advertising, tracking or general usage analytics.

Data processed

Local app data: Settings, language, theme, location mode, manual places, archive, daily impulses, weather, air quality and pollen values, challenge state, widget data, notification scheduling and local unlock information.

Health and activity data: With your permission, Ricodia reads today’s step count from Apple Health through HealthKit or from Android Health Connect and stores daily aggregated step counts for your progress. Water amounts and daily water goals come from your entries in Ricodia. When you deliberately activate backup, the daily step totals actually stored, including values obtained from HealthKit, and drinking progress can be transferred to Supabase and stored with your connected account. The backup includes the daily step total and its already recorded basic source type, such as Apple Health or Health Connect. Raw HealthKit/Health Connect records are not backed up. Ricodia does not write data to HealthKit or Health Connect and does not use health data for advertising.

You can explicitly save or load a backup. Automatic saving runs at the local change of day or the first use afterwards, not on every progress event. Eight groups are backed up: daily impulses, drinking entries, daily water goals, daily step counts and step challenges, completed rest sessions, daily rest goals, achievement evidence and achievement unlocks. Preferences, weather snapshots, precise coordinates, raw HealthKit/Health Connect records, detailed provenance and individual health sample data, account and purchase credentials and running timers are not progress backup content. Account, device and purchase entitlement records are processed separately to authorize backup.

Content ratings send the choice, content type, original text, language, entry screen and an independent random submission identifier to Supabase. They do not send an impulse date, weather code or location. Feedback sends the title, message, category, form language and entry screen only after submission. The server records receipt and may use technical request data and fingerprints for deduplication, rate limits and abuse prevention. Account, purchase, trial, device and health data are not attached to these submissions.

Purchases, subscriptions and restoration are handled by Apple App Store or Google Play. Ricodia processes product, transaction, purchase chain and entitlement information locally and through Supabase to verify access, expiry, refunds and revocations. Ricodia does not receive full payment card data. Purchase restoration remains separate from the optional Ricodia account. Payment and refund requests follow the relevant store process.

Comparison percentages are calculated from existing backups. Each account that is neither deleted nor pending deletion and has at least one current backup fact counts once, including accounts without unlocked achievements. Subscription expiry, disconnection and local progress reset do not remove saved participation. The app receives only rounded percentages for the 76 achievements and whether data is available, without other members’ individual values or identifiers. Reading requires currently valid paid Sync access and a verified account and device connection; opening details does not enable backups.

External services

Weather, air quality, pollen and location searches go through Supabase to Google services; the app does not contact Google weather APIs directly. The requested location and necessary request context are processed to provide these features. Optional daily and drinking reminders are scheduled locally on the device with the chosen time, text and time zone. Delivery depends on system permissions and settings.

Supabase receives coordinates or search text, language and an installation identifier. A purchase access credential or random trial-weather marker may be included for server weather authorization. Marker registration processes the marker and local trial start and stores a marker hash with a time-limited grant; IP and marker rate limits prevent abuse. This controls server weather only: the local trial starts and works independently, including offline.

Free weather uses a separate random weather quota identifier stored securely on the device and preserved by progress reset. Supabase processes its separate hash, a durable request identifier, location, language and device time zone. The server allows three new successful requests per identifier and calendar date using its clock and a valid time zone. Lost responses resume automatically with the same request identifier for at most 24 hours. Request records are cleaned up 48 hours after start or completion; active reservations are protected. Response bodies last only until the original one-hour Current expiry. Daily counters are limited to still reachable dates. A deliberate refresh is needed afterwards.

The ricodia.app website is hosted by Vercel. When you visit a page, Vercel processes technical connection and request data such as IP address, requested page, and browser and system information to deliver and securely operate the website. Vercel’s own retention rules apply to this processing.

Advertising and privacy choices

When using Free with ads, Google AdMob and UMP provide ads and privacy choices. Choosing Free does not mean consenting to personalized ads. Refusing personalization or ad errors does not block Free. Ads are requested only during actual Free access with valid SDK permission; Plus, Pro and the Pro trial are ad-free. UMP provides the applicable privacy options and changes to your choices. Your privacy choice does not grant blanket tracking permission. The ads the SDK may serve depend on your choices, platform permissions and valid SDK permission.

Ricodia adds no account, purchase, trial, weather quota, location, step or health data to ad requests and disables the same-app key. This does not mean anonymous or data-free SDK use: depending on platform, permissions and choices, Google may process IP addresses, device and advertising identifiers, diagnostics, performance and ad interactions for advertising, analytics and fraud prevention. UMP processes the necessary technical context and privacy choices. Google’s own retention rules apply.

Rights and deletion

Local data normally remains until removed through available app or system functions or by uninstalling. Server feedback and ratings are subject to regular cleanup with a planned maximum retention of 24 months, unless longer retention is required for legal claims, security or abuse investigations. Startup diagnostics have the separate period described above. Rights to access, correction, deletion, restriction, portability, objection and withdrawal may apply under applicable law. For privacy or deletion requests about accounts, backup, ratings or feedback, contact support@ricodia.app with identifying details such as the account email, feedback title or approximate date. Delete account: Your Ricodia account and server backup will be deleted. All connected devices will lose their connection. Disconnecting or removing a device does not delete the account or its backup. External services have their own retention rules. No fixed automatic deletion period is currently implemented for backup data.

Local progress, settings, your current rest break, trial and purchases remain. Your progress will not be linked to a new account automatically. Store subscriptions continue. You can manage them in the store.

The app stores a resumable deletion request and required credentials until completion. The server then retains only minimal request and blocking information for safe retries; private backup content is not archived. Proven purchase chains are unlinked from the deleted account; purchases and restoration remain. Independent anonymous ratings and feedback are unaffected.

If no safely usable Apple authorization is available for automatic revocation, account deletion completes and Apple’s instructions for removing the connection are offered. Technical revocation errors leave deletion unfinished and it can be retried.

Reset progress: After your final confirmation, the app removes all local usage progress and ends any running or paused rest break. Settings, the trial start, purchases and restoration, account, sign-in, device connection, system permissions and health data held by the operating system are preserved. Ratings and their submission identities are preserved. The cloud backup remains unchanged. Automatic local backup is disabled; you can then deliberately enable and load the existing backup. New usage is stored as a new local dataset.

Children

Ricodia is not aimed specifically at children. If minors use the app, this should happen within applicable legal requirements and, where needed, with guardian consent.

Changes

This privacy policy may be updated when app features, data processing, external services or legal requirements change.