Privacy Policy
Last updated FILL: date · Effective FILL: date
Draft. Every highlighted value is a placeholder that must be replaced before this page is submitted to App Review. This text is a starting point, not legal advice — have it reviewed before you rely on it.
This policy explains what The Rising Drop (“the app”, “we”) collects, why, and what you can do about it. It covers the iOS app and the website at therisingdrop.com.
The app is operated by FILL: legal entity name and registered address, the data controller for the purposes of this policy.
The short version
We collect the least we can. There is no advertising, no tracking across other apps or websites, and we do not sell your data or share it with data brokers. What we keep is the account you sign in with and the record you write.
What we collect
Account
- Sign in with Apple identifier — an opaque ID from Apple that tells us which account is yours.
- Email address — whatever Apple passes us. If you chose “Hide My Email”, that is a private relay address and we never see your real one. Used to reset your PIN and, if it is ever needed, to reach you about your account.
- PIN — stored only as a one-way hash. We cannot read it, and neither can anyone who obtains the database.
- Sessions — a hashed sign-in token, the device or browser description your device sends, and when it was last used, so that you can sign out a device you no longer have.
Your record
- Daily marks, habit entries, and challenges — the dates and entries you create in the app, so they are on every device you sign in on and survive losing a phone.
This is written by you and read by you. We do not use it to profile you, and no human at FILL: entity reads it except where you ask us to for support, or where the law requires it.
Purchases
Subscriptions are sold and processed by Apple through the App Store. We never receive your card number, billing address, or Apple ID password. We receive only whether an account has an active subscription.
Diagnostics
FILL: state honestly what you actually run. If you use crash reporting or analytics (e.g. Apple's own App Analytics, Sentry, PostHog), name the provider, say what it collects and whether it is tied to your identity. If you use none, say: “The app contains no analytics or crash-reporting SDK.” Server logs that record IP address and request time for security and debugging should be disclosed here too, with how long they are kept.
What we do not collect
- No location, contacts, photos, health data, or microphone access.
- No advertising identifiers, and no tracking as the App Store defines it — we do not link your data to third-party data for advertising or measurement.
- No sale or sharing of personal information for cross-context behavioural advertising.
Why we are allowed to hold it
Where the GDPR or UK GDPR applies: we process your account data to perform the contract you enter into by using the app, and we process security data (session records, FILL: logs, if kept) under our legitimate interest in keeping accounts safe. Where we ever rely on consent, you can withdraw it at any time.
Who else touches it
We use a small number of processors, each bound to handle the data only on our instructions:
- Apple — sign-in, App Store purchases, delivery of the app.
- FILL: hosting provider — e.g. Railway — application hosting and the database, in FILL: region.
- Cloudflare — DNS and delivery of this website.
- FILL: add email sending, analytics, or support tools if you use them; delete this line if you do not.
Data may be processed in FILL: country/countries. Where data leaves the UK or EEA, transfers are covered by FILL: mechanism, e.g. Standard Contractual Clauses.
How long we keep it
- While your account is open — your account and record are kept so the app works.
- After you delete your account — the account is marked deleted immediately and everything belonging to it is erased within FILL: number days.
- Sessions — expire on their own and are cleared after FILL: period.
- FILL: logs, if kept — FILL: period.
Deleting your account
You can delete your account and everything in it from inside the app: FILL: exact path, e.g. Settings → Account → Delete account. You can also write to us at the address below and we will do it for you. Deleting the app alone does not delete the account.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, export it, object to or restrict processing, and — in the EEA/UK — complain to your data protection authority (FILL: name the lead authority if you have one). California residents have the rights to know, delete, correct, and to opt out of sale or sharing; we do not sell or share personal information, so there is nothing to opt out of. To exercise any of these, email the address below. We will respond within FILL: e.g. 30 days and will not treat you differently for asking.
Security
Traffic is encrypted in transit. PINs and session tokens are stored hashed, never in the clear. Access to production data is limited to FILL: who. No system is perfect, and we will tell affected users and any required regulator if a breach puts your data at risk.
Children
The app is not directed at children under FILL: 13, or 16 in some regions — match your App Store age rating, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes
If this policy changes in a way that matters, we will update the date at the top and — for material changes — tell you in the app before the change takes effect.
Contact
Questions, requests, or complaints: privacy@therisingdrop.com FILL: confirm this mailbox exists and is monitored; add a postal address if you need one for GDPR.