English · Türkçe
Privacy Policy
This Privacy Policy explains how SelfPatch collects, uses, and protects personal information when you use our website and app. It is written to match what the app actually does, and it is kept in step with the Data safety section of our Google Play listing.
1. Information We Collect
- Account data. Your email address, name, and authentication provider identifier, received from Google when you sign in. Signing in with Google is the only way to create an account; we never see or store a password.
- Health and fitness data that you enter. SelfPatch is a self-improvement app, and its nutrition and fitness modules let you record information such as body weight, body measurements, calorie and protein targets, meal-plan choices, and workout or activity entries attached to your daily tasks. This data is optional: it exists only if you type it in, it is used only to personalise your tasks and show your own progress, and it is never shared with third parties or used for advertising.
- Other content you create. Your answers to the onboarding and intake questionnaires, notes you attach to tasks, and your chosen nickname. If you voluntarily use the in-app feedback form, we also process the subject and message you write together with your account email address so that we can receive and reply to your request.
- App usage data. Tasks, progress metrics, completion timestamps, streaks, and preferences such as language. We also record product analytics events (for example "onboarding step completed") together with a random session identifier, the platform, and the app version. These events contain no free text, no email address, and no IP address, and they are stored in our own database — not sent to an analytics vendor.
- Crash and diagnostic data. Builds of the app that we configure with crash reporting send a crash report when the app crashes: the error and stack trace, device model, operating system, and app version, identified only by your account's random user ID. Your email address is never attached, and screenshots and screen contents are disabled.
- Technical and security data. IP-derived metadata, device/browser details, and service logs generated by our hosting and authentication providers, used to keep the platform secure and reliable.
2. Information We Do Not Collect
SelfPatch does not request or access your location, camera, microphone, contacts, or calendar, and does not read device identifiers such as an advertising ID, IMEI, or serial number. The app contains no advertising and no third-party advertising or attribution SDKs. We do not collect payment information, and we do not sell personal data.
3. How We Use Information
- To provide and operate SelfPatch features.
- To personalise your daily tasks, targets, and progress views — including adapting task difficulty to what you have recorded.
- To understand how features are used, so we can improve them.
- To receive, investigate, and reply to feedback you choose to send.
- To detect, prevent, and investigate abuse or security issues.
- To comply with legal and regulatory obligations.
4. Google OAuth and Authentication
When you sign in with Google, we request only the scopes needed for authentication and account setup (your basic profile and email address). We do not sell your Google account data and we do not request access to any other Google service.
4b. Android Early Access and the Home Page
The home page lets you leave the Google account address you use on Google Play so that we can add it to the Android internal-testing list. We store that address, the language you were reading in, and the date. Nothing else: no name, no IP address, no browser fingerprint. It is used only to send the tester invitation, it is never shared, and it is deleted 180 days after the invitation goes out or when the testing programme ends, whichever comes first. Write to [email protected] to be removed sooner.
The home page also counts how it is used: page views, which language was shown, which of the two colour modes, a coarse screen-size bucket, the hostname of the site you arrived from, and whether the call to action was pressed. There is no cookie and no stored identifier; visits are grouped by a random value that exists only in the browser tab and is gone when it closes. No IP address or browser user-agent is recorded, and these counts are kept for 90 days.
5. Notifications and On-Device Data
Reminders are generated and scheduled entirely on your device. There is no push server: no notification token is created and no reminder content is sent anywhere. Reminders are off by default, and Android asks for notification permission only at the moment you turn them on. If you deny it, the rest of the app keeps working. Your reminder preferences, reminder history, and the offline cache of your task list stay on the device and are removed when you sign out.
6. Data Sharing and Processors
We do not sell personal data and we do not share it for advertising. Apart from mentorship, which you choose and control and which is described in 6.1 below, we share data only with the service providers that operate SelfPatch, and only under contractual safeguards:
- Supabase — database, authentication, and API hosting for your account and app data.
- Google — sign-in (Google OAuth), app distribution through Google Play, and the support mailbox that receives feedback.
- Sentry — crash reporting, for builds configured with it, receiving the crash data described in section 1.
- Cloudflare — hosting and delivery of this website.
- Resend — transactional email delivery when a signed-in user voluntarily submits the in-app feedback form. Resend receives the message and account email only to deliver it to our support inbox.
6.1 Mentorship — sharing with another person
Mentorship is the one place where SelfPatch shows your data to another person rather than to a service provider. It only happens if you buy a mentorship, and it is limited by choices you make and can reverse at any time.
- You choose the mentor and you choose what they see. Every category of existing data — your display name, your real name, your onboarding answers, your module intake answers, your body measurements, your task history before the mentorship, and the answers you give to the mentor's own questions — is a separate permission that is off by default. A mentorship can be bought and run with none of them granted. A mentor can ask you to turn one on; the request is a notification, not access.
- One thing is not a permission: the status of the tasks the mentor themself assigned to you. A mentor can always see whether the work they set was done, because otherwise the service they sold you cannot function.
- You can withdraw any permission at any time from Settings → Mentorship → My mentorships. Withdrawal takes effect immediately for anything the mentor has not already seen.
- You can see what was actually read. The same screen shows an access log: which categories your mentor's panel returned, and when.
- Your identity stays a pseudonym unless you say otherwise. Mentors see the handle you chose. Your real name is a separate permission of its own.
- Mentors are not anonymous to you. A mentor is approved by us and their profile carries a real name, a photo, and reviewed credentials. Their identity documents are never shown to you; only the verified category is.
- Messages are short and are not kept. You and your mentor can exchange messages of up to 200 characters inside the mentorship. Our servers delete every message twenty-four hours after it was sent; the copy your own device stores is the only one that remains, and it is yours to keep or delete. A message somebody reports is the evidence for that report, so it is kept as long as the report is. Exchanging phone numbers, e-mail addresses or payment details is against our terms, and text that looks like contact information is flagged for review.
- You can report or block a mentor from your mentorship card. Blocking takes effect immediately: the mentor can no longer assign you tasks or read your data.
- Mentorship is 18+. Buying or offering mentorship requires you to confirm you are an adult.
Mentorship data is kept on a shorter clock than the rest of your account: see section 7.
7. Data Retention
We retain account and app data while your account is active. Product analytics events are automatically deleted after 90 days. A summary record of which app surfaces you saw (first and last time seen) is deleted 90 days after it was last seen. Feedback delivery metadata (which never contains the subject or message) is also deleted after 90 days. Feedback content in our support inbox is kept for up to 12 months, unless it is needed longer to resolve an active request or meet a legal obligation. When you delete your account, your account record and the app data linked to it are deleted; limited support or legal records may remain only for those stated periods and purposes.
Mentorship data is on its own schedule, and different parts of it are kept for different lengths of time for different reasons:
- Mentorship messages — 24 hours after they are sent, counted from the message and not from the end of the mentorship. After that the only copy is the one on your own device. A reported message is kept with its report, for the two years we keep reports.
- Daily check-ins, your answers to a mentor's questions and your task notes — 90 days after the mentorship ends.
- A mentor's raw identity or credential document — 30 days after we review it. Only the verified category survives, so the badge on their profile stays but the document behind it does not.
- The mentor access log — 365 days. It is the record of what was shown to whom, so it outlives the mentorship itself.
- Proof that you gave or withdrew a permission — 3 years. It exists to answer a later dispute about what you actually agreed to.
- Reports and moderation decisions — 2 years, as evidence.
- Coin transactions are not deleted. They are financial records. After 10 years the personal fields on them are erased and only the amount, the reason and the date remain.
8. Security
Data is encrypted in transit (HTTPS/TLS). Every table holding user data is protected by row-level security, so your account can only read its own rows. On Android, your sign-in session is stored in the operating system's hardware-backed keystore rather than in plain text, cleartext HTTP is disabled at the platform level, and device backups of app data are turned off.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or export your information.
- Delete your account and data yourself, in the app: Settings → Delete Account. This removes your account record and the app data linked to it.
- Health and fitness data is optional — you can simply not enter it, and you can edit or clear entries you have made.
- Notifications are optional and can be turned off at any time in Settings or in your device settings.
- For access, correction, or export requests, contact us using the details below.
10. Children
SelfPatch is not directed to children. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be published on this page with an updated date.
12. Contact
For privacy questions or requests: [email protected]