Privacy
Who is responsible and which data yesumi moves. The list follows the actual state of development.
Controller
- candybytes GmbH, Sophiengutstraße 20, 4020 Linz, Österreich
- None on record.
This website
This website sets no cookies, uses no analytics and loads no fonts or scripts from third parties. Which server logs a future hosting provider keeps will be added at publication.
Data in the app
Each entry names a service or component of the app. Consents are separate; the default is off unless stated otherwise.
- Firebase Analytics
- Optional analytics, separate from the account.
- Firebase Crashlytics
- Crash reports require their own consent.
- Firebase Remote Config
- Technical configuration may load while analytics is off.
- Firebase Installations / transport
- Technical installation identifiers are separate data.
- Firebase Auth / Google sign-in
- The personal account is separate from the push identity.
- Firebase anonymous technical identity
- Inbox and push may use their own technical identity; since PRIV-02 their data can be exported and deleted on the server.
- FCM / APNs / native notification adapters
- Permission and category are separate choices.
- yesumi account/sync API
- Favorites sync requires separate opt-in.
- Daily-card artwork/text cache
- A last daily snapshot is not a full offline catalogue.
- Guest favorites / local preferences
- Guest cards and local choices stay device-scoped.
- StoreKit / Google Play Billing
- Real checkout stays locked by the server; verification and restore go through the server.
- yesumi commerce verification/events
- Local store fixtures do not prove a real purchase.
- Application subject and replay fences, provider-identity outbox
- Pseudonymous erasure fences remain. The plaintext UID waits in an outbox for Firebase deletion retries. Since PRIV-02 the worker never gives up silently: after 14 days from the first failed attempt the row stays, is retried daily and raises an operator alert; an optional reconciliation deletes Firebase records that survived. Without provider configuration the UID can remain there indefinitely. PRIV-05: An append-only erasure journal (HMAC fence, deletion time, kind only) lives on its own volume outside the database backup; after a restore a step erases accounts that came back.
- Google Mobile Ads
- Ad SDKs are included; test ads are separate.
- Google User Messaging Platform
- Ad privacy choices are separate from analytics consent.
- Resolved iOS / Android transitive SDKs
- Resolved does not mean linked or active.
- Native update / iTunes lookup
- Version checks use a separate service route.
- Native app review
- A review prompt does not prove a submitted review.
- Local API request logs / Firebase Admin
- Technical API logs are separate from app analytics.
- Media/download manifests
- An offline media contract is not a native download.
- Voice recording boundary
- No native recording feature in the inspected baseline.
- Collection library (snapshots, thumbnails, saved times)
- The collection stores card text and small images on the device.
- Daily reminder schedule and permission state
- Time, weekdays, pause and system permission are sent to the server.
- Native purchase handoff and local commerce memory
- Purchase proofs go to the server for checking only with your account.
- Local operational backups (OPS-01)
- Local backups are encrypted and expire after a fixed retention.
- Personalization: topics, card feedback, hidden cards, personal daily card
- Topics, feedback and hidden cards are stored with the account; guests hide cards on this device only.
- Browser account deletion / Auth-only Firebase
- Delete without the app using the same Google identity; unknown sign-in creates no application account.
Your rights
You can request access, rectification, erasure, restriction, portability and object to processing, and lodge a complaint with the supervisory authority. How to delete your account
- Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb.gv.at