Privacy

Who is responsible and which data yesumi moves. The list follows the actual state of development.

Controller

Controller
candybytes GmbH, Sophiengutstraße 20, 4020 Linz, Österreich
Contact for privacy questions
support@reloop.cards
Data protection officer
None on record.

This website

This website sets no cookies, uses no analytics and loads no fonts or scripts from third parties. Which server logs a future hosting provider keeps will be added at publication.

Data in the app

Each entry names a service or component of the app. Consents are separate; the default is off unless stated otherwise.

Firebase Analytics
Optional analytics, separate from the account.
Firebase Crashlytics
Crash reports require their own consent.
Firebase Remote Config
Technical configuration may load while analytics is off.
Firebase Installations / transport
Technical installation identifiers are separate data.
Firebase Auth / Google sign-in
The personal account is separate from the push identity.
Firebase anonymous technical identity
Inbox and push may use their own technical identity; since PRIV-02 their data can be exported and deleted on the server.
FCM / APNs / native notification adapters
Permission and category are separate choices.
yesumi account/sync API
Favorites sync requires separate opt-in.
Daily-card artwork/text cache
A last daily snapshot is not a full offline catalogue.
Guest favorites / local preferences
Guest cards and local choices stay device-scoped.
StoreKit / Google Play Billing
Real checkout stays locked by the server; verification and restore go through the server.
yesumi commerce verification/events
Local store fixtures do not prove a real purchase.
Application subject and replay fences, provider-identity outbox
Pseudonymous erasure fences remain. The plaintext UID waits in an outbox for Firebase deletion retries. Since PRIV-02 the worker never gives up silently: after 14 days from the first failed attempt the row stays, is retried daily and raises an operator alert; an optional reconciliation deletes Firebase records that survived. Without provider configuration the UID can remain there indefinitely. PRIV-05: An append-only erasure journal (HMAC fence, deletion time, kind only) lives on its own volume outside the database backup; after a restore a step erases accounts that came back.
Google Mobile Ads
Ad SDKs are included; test ads are separate.
Google User Messaging Platform
Ad privacy choices are separate from analytics consent.
Resolved iOS / Android transitive SDKs
Resolved does not mean linked or active.
Native update / iTunes lookup
Version checks use a separate service route.
Native app review
A review prompt does not prove a submitted review.
Native share / chosen recipient
You choose where to share card text.
Local API request logs / Firebase Admin
Technical API logs are separate from app analytics.
Media/download manifests
An offline media contract is not a native download.
Voice recording boundary
No native recording feature in the inspected baseline.
Collection library (snapshots, thumbnails, saved times)
The collection stores card text and small images on the device.
Daily reminder schedule and permission state
Time, weekdays, pause and system permission are sent to the server.
Native purchase handoff and local commerce memory
Purchase proofs go to the server for checking only with your account.
Local operational backups (OPS-01)
Local backups are encrypted and expire after a fixed retention.
Personalization: topics, card feedback, hidden cards, personal daily card
Topics, feedback and hidden cards are stored with the account; guests hide cards on this device only.
Browser account deletion / Auth-only Firebase
Delete without the app using the same Google identity; unknown sign-in creates no application account.

Your rights

You can request access, rectification, erasure, restriction, portability and object to processing, and lodge a complaint with the supervisory authority. How to delete your account

Supervisory authority
Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb.gv.at