Legal
Privacy Policy
Piplu · Last updated 17 August 2026
This Privacy Policy explains what personal data the Piplu mobile app (the "app") processes and how we handle it.
Data controller
Controller: Advia d.o.o.
Privacy contact: hello@piplu.app
Summary
- The app works mainly on your device. Without an account we do not upload personal data such as your name, email or alarms. We do collect anonymous usage statistics (see below) to improve the app.
- The camera is used mainly on your device for missions, and we do not save your photos or videos. One exception: in the Object Hunt mission, if the on-device recognition cannot confirm the object, the single photo you just took is sent through our server to an AI vision provider (Google) only to check whether the requested object is in the picture. We receive only a yes/no result, not the picture.
- If you sign in (Google or Apple), we store your progress in the cloud so you don't lose it when changing phones.
- We do not sell your data and do not use it for advertising.
- For the augmented-reality hunt mission we read motion sensors and your step count on-device only to detect that you actually got up and moved. We do not store or transmit this data.
What we process and why
- On-device data (no account): your alarms, statistics (streaks, response time, exercise reps) and settings are stored locally on your device. Some of your onboarding answers are also sent as anonymous analytics (see "Anonymous usage analytics" below); they are tied to a random device identifier, not to your identity.
- Account data (only if you sign in via Google or Apple): your email, name and a unique account identifier from the sign-in provider. Purpose: creating your account and storing progress in the cloud.
- Cloud progress (signed-in users only): your alarm list, game statistics and onboarding profile are stored in our cloud database (Supabase) so your progress survives reinstalls and device changes.
- Anonymous usage analytics: to understand how the app is used and improve it, we collect anonymous events (for example: which alarm sound you pick, whether a mission was solved or skipped, onboarding steps, and interactions with the subscription screen). This also includes some of your onboarding answers, such as your age range (a range like 18 to 24, never an exact birth date) and how you found the app. We deliberately do not send more sensitive answers, such as how you feel at night. These events are tied to a random device identifier that is not linked to your name, email or account, and resets if you reinstall the app. We also record the device type, app version, country and time zone. The country and time zone come from your device settings, not from your location: the app has no location permission and never asks for one. We do not record the content of your alarms, your photos, or any names or text you type. These events are processed by our cloud database (Supabase) and our analytics tool (PostHog, EU servers). We also record the device platform (iOS or Android) and app version. This never includes your photos, video, name, email, or the content of your alarms. This data is stored in our Supabase database. Legal basis: our legitimate interest in improving the app.
- Camera: used on your device for missions (object scanner, augmented-reality hunt, a camera gesture game, squat and push-up counting via body-pose detection). We do not save images or video. In the Object Hunt mission only, if the on-device model cannot recognize the target object, the one photo you took is sent through our server to an AI vision provider (Google) to check whether that object is present. Only the object name and the photo are sent, and we get back only the result. The photo is never stored or logged by us, exists only in memory during the request, and is deleted from your device immediately afterwards. The AI provider (Google) does not use these photos to train or improve its models; the photo may be processed only briefly to answer the check and for abuse prevention, then discarded.
- App blocking and focus (optional): with your permission, Piplu can block or limit other apps during a mission or a short focus period, so you actually get up. On iOS this uses Apple Screen Time (Family Controls): you grant a one-time Screen Time permission and choose which apps to block through Apple's own system screen. This stays on your device and we do not receive your list of apps. On Android this uses the Usage Access permission (to detect which app is in the foreground) and reads the list of installed apps on your device so you can pick which ones to block. That list is read on-device only to show you the picker and is not uploaded; we only record the number of apps you chose (an anonymous statistic), never their names.
- Subscriptions (Piplu Plus): if you buy a subscription, the purchase is handled by the Apple App Store or Google Play. We use RevenueCat to check whether your subscription is active. We receive purchase and subscription status and an anonymous purchase identifier. We never receive your card or payment details.
- Diagnostics and crash reports (Sentry): to fix bugs we collect technical data on crashes (device type, OS and app version, error details). Servers are in the EU.
- Notifications and alarms: for reliable ringing the app uses notification and alarm permissions. We do not use this for advertising.
- Motion and physical activity (sensors): for the augmented-reality hunt mission the app reads the device's motion sensors (accelerometer and motion detection) and step counter to detect that you actually got up and moved. We process this on-device only and do not store or transmit it anywhere. On Android this uses the "Physical activity" permission.
Legal basis (GDPR)
- Account and sync: performance of the service you requested, and your consent at sign-in.
- Diagnostics and crashes: our legitimate interest in a stable app.
- Usage analytics: our legitimate interest in understanding where the app fails and improving it. The data is tied to a random installation identifier, not to your identity.
- Subscriptions: performance of a contract, providing the paid service you purchased.
Who we share data with (processors)
We do not sell data. We use trusted providers who process data on our behalf:
- Supabase — cloud database (account, progress, and anonymous analytics events)
- Google / Apple — sign-in (authentication)
- Google (Gemini / Google AI) — checks a single Object Hunt photo to confirm the object, when the on-device model cannot. The photo is not stored and is not used to train Google's models.
- RevenueCat — subscription and purchase processing (US servers).
- Apple App Store / Google Play — process subscription payments and distribute the app
- Sentry — crash reports (EU servers)
- PostHog — product usage analytics (EU servers).
- Expo (EAS) — delivering app updates
Retention
We keep account data and progress while you have an account. If you delete your account, we delete them. Diagnostic data is kept for a limited time.
Deleting your account and data
You can permanently delete your account and all associated data at any time, in two ways:
- From the app (fastest): open Piplu, go to Settings, tap your account, then Delete account. This immediately and permanently removes your account and all data (profile, stats and streak, alarms, progress) from our servers and your device.
- Without the app: email us at hello@piplu.app from the address linked to your account, or include the name you signed up with. We verify your identity and complete the deletion within 30 days.
What we may keep briefly: anonymous crash diagnostics (Sentry) with no link to your account, kept only as long as needed for app stability.
Your rights
You may access, correct and delete your data, and object to processing. To delete your account, see "Deleting your account and data" above; for any other request, email the address above. We will handle it within a reasonable time (at most 30 days).
Children
The app is not intended for children under 13, or the age threshold applicable in your country.
International transfers
Some providers may process data outside the EU; where they do, appropriate safeguards apply (for example standard contractual clauses). Specifically: RevenueCat (subscription processing) has servers in the United States, and the Object Hunt photo check is performed by Google's AI service. Supabase, Sentry and PostHog process data in the EU.
Changes
We may update this policy; material changes will be posted here with a new date.
Contact
Advia d.o.o. · hello@piplu.app