Privacy Policy
Effective 25 July 2026 · Version 1.0
This policy explains what the Sums mobile application ("Sums", "the app", "we") collects, why it collects it, and what it never does. It is written to be read, not to be survived.
The short version. There is no account and no password. Your progress lives on your phone. We receive your daily result so we can tell you how your time compares, anonymous usage analytics, and crash reports. There are no ad networks in the app, and we do not sell your data to anyone.
1. Who is responsible
The data controller is Gleb Matsko, an individual developer based in Serbia. A postal address is available on request. For any privacy question, write to support@sums.day — a human answers.
2. There is no account
Sums does not ask for your name, email address, phone number or password. You are never asked to register. To sync a result to our servers, the app creates an anonymous identifier that is not linked to your identity and cannot be used to contact you.
3. What stays on your device
The following never leaves your phone unless you explicitly share it:
- Your answers, times and per-skill ratings
- Your streak and freeze history
- Your queue of error patterns for review
- App settings: theme, haptics, reminder, currency, session options
Uninstalling the app removes all of it. We cannot restore it, because we never had it.
4. What we receive, and why
| Data | Why | Processor |
|---|---|---|
| Daily result: date, total time, number correct, per-task fast/slow/miss marks, anonymous id, content version | To compute your percentile for that day and the day's median time | Supabase |
| Usage events: screens opened, sessions started and finished, scores and durations, paywall views, purchases, permission answers | To understand which parts of the app work and which are ignored | Google Firebase Analytics |
| Crash reports: stack traces, device model, OS version | To find and fix the crashes you hit | Google Crashlytics |
| Subscription state: which plan, when it renews, whether a trial was used | To unlock what you paid for, and restore it on a new device | RevenueCat, Apple / Google |
| Advertising identifier (IDFA) — only if you allow tracking | To measure which channels bring people who stay | Firebase, RevenueCat |
We never receive your payment card. Purchases happen inside the App Store or Google Play, and the store tells us only whether a subscription is active.
5. Tracking, and your right to say no
On iOS the app asks for permission to track (Apple's App Tracking Transparency prompt). If you allow it, your advertising identifier is shared with the processors above so we can attribute app installs to the channel they came from.
If you decline, nothing in the app changes. Every feature, every mode and every puzzle works identically. You can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
6. What we never do
- No advertising networks, no ad SDKs, no sponsored content
- No selling or renting of personal data to anyone, ever
- No reading your contacts, photos, location or microphone
- No profiling that produces legal or similarly significant effects
7. Notifications
Reminders are scheduled on your device, not sent from a server, and only if you turn them on. We do not know whether you opened one. Turn them off any time in the app's settings or in system settings.
8. Legal bases (GDPR)
- Performance of a contract — delivering the app, computing your percentile, unlocking your subscription.
- Legitimate interest — crash reporting and aggregate product analytics, to keep the app working and improving.
- Consent — advertising identifier and attribution, collected only after you accept the tracking prompt. Withdrawable at any time.
9. How long we keep it
- Daily results — retained while the app operates, to keep historical percentiles consistent. They contain no identity.
- Analytics events — up to 14 months.
- Crash reports — up to 90 days.
- Subscription records — for as long as required by tax and accounting law.
10. Where data goes
Our processors operate servers in the European Union and the United States. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses. Current processors: Supabase (database and functions), Google Firebase (analytics and crash reporting), RevenueCat (subscription state), Apple and Google (payments and app delivery).
11. Your rights
Depending on where you live, you may request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interest. Write to support@sums.day.
A practical note, honestly stated: because there is no account, we usually cannot connect a request to a specific person. To let us find your records, include the anonymous client id from the app — Settings → About → tap the client id to copy it. Without it we can still confirm what categories of data exist, but we cannot locate a specific device.
EEA residents may complain to their national data protection authority.
12. Children
Sums is not directed at children and is rated for users aged 16 and older. We do not knowingly collect data from children. If you believe a child has used the app, write to us and we will delete anything we hold.
13. Changes
If this policy changes materially, the app will tell you before the new version applies. The date at the top always reflects the current version, and previous versions are available on request.
14. Contact
support@sums.day — Gleb Matsko, individual developer, Serbia.