Privacy Policy of ISweepMate
Data Controller & Contact Information
Data Controller: Balazs Kiraly (individual)
Email: office@isweepmate.app
Under GDPR Article 13, we must identify who is responsible for your data and provide contact details for privacy inquiries. App Store Connect also requires a publicly accessible Privacy Policy URL and contact information in metadata.
Information We Do Not Collect
- We do not collect or store any personal identifiers (name, email, phone, location, payment data) within the app itself.
- Local metrics such as swipe counts remain on your device and are never transmitted to us or any server.
Third-Party Data Collection
Firebase Analytics
- Collected Data: Anonymous usage events (feature access frequency, country, ).
- Storage Location: Transmitted and stored on Google’s Firebase servers; we have no custom control over its physical location.
- Retention Period: Configured for 2 months of user- and event-level data, after which data is automatically deleted.
AdMob
- Collected Data: Advertising identifiers (IDFA on iOS) and contextual metadata for ad delivery.
- Operation: Continues to serve ads whether or not you grant ATT consent; npa=0 (personalized) or npa=1 (non-personalized) is sent accordingly.
- Security: All transmissions use HTTPS/TLS, and data at rest is encrypted with AES-256 on Google’s infrastructure.
Legal Basis & Consent
- Under iOS 14.5+ AppTrackingTransparency, we request your permission before accessing your advertising identifier. You may withdraw at any time via Settings → Privacy → Tracking.
- Continued use of the app implies consent to anonymous Firebase Analytics; you can disable analytics under Settings → Send Anonymous Reports.
Your Rights
Under GDPR, CCPA, UK DPA, and the Australia Privacy Act, you have the right to:
- Access & Portability: Request a copy of your data.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your data. We will process deletion requests via Firebase’s User Deletion API or directly on receipt of your request within 30 days.
- Consent Withdrawal: Withdraw ATT or analytics consent at any time via app settings or device settings.
- California Specific (CCPA): Right to know, delete, and opt out of sale of personal information (AD sale includes IDFA sharing) with a “Do Not Sell My Personal Information” link if needed.
Data Security
We rely on Google’s default security measures for Firebase and AdMob:
- In Transit: HTTPS/TLS for all network communication.
- At Rest: AES-256 encryption on Google Cloud servers.
- For advanced control, Firebase Cloud Firestore supports Customer-Managed Encryption Keys (CMEK) via Google Cloud KMS.
Children’s Privacy
We do not knowingly collect data from children under 13. If you believe data has been collected without parental consent, contact us to request deletion.
Updates to This Policy
We may update this policy at any time; the latest version is always accessible at https://www.isweepmate.app/privacy. Material changes will be communicated via the app or email.
Jurisdiction-Specific Summaries
GDPR (EU)
- Legal bases: consent, legitimate interest.
- Rights: access, rectification, erasure, restriction, portability, objection.
CCPA (CA, USA)
- Rights: know, delete, opt-out of sale.
- “Sale” includes sharing IDFA with AdMob.
CalOPPA (CA, USA)
- Pulicy must be conspicuous and accessible in app and web.
- Provide contact address and effective date in policy.
- Obtain meaningful consent, explain purposes.
- Limit collection to necessary data and retain only as long as needed.
UK DPA (UK)
- Similar to GDPR with ICO oversight.
- Rights and lawful bases align with GDPR.
Australia Privacy Act (APPs)
- 13 Australian Privacy Principles covering open management, anonymity, security, access, and correction.
- Notify of data breaches when serious harm risk exists.
Last Updated: May 23, 2025
Contact: Balazs Kiraly, office@isweepmate.app
This policy complies with Apple’s App Store Connect requirements and international privacy regulations.