SelfPatch logo SelfPatch

English · Türkçe

Privacy Policy

Last updated: September 24, 2026

This Privacy Policy explains how SelfPatch collects, uses, and protects personal information when you use our website and app. It is written to match what the app actually does, and it is kept in step with the Data safety section of our Google Play listing.

1. Information We Collect

2. Information We Do Not Collect

SelfPatch does not request or access your location, camera, microphone, contacts, or calendar, and does not read device identifiers such as an advertising ID, IMEI, or serial number. The app contains no advertising and no third-party advertising or attribution SDKs. We do not collect payment information, and we do not sell personal data.

3. How We Use Information

4. Google OAuth and Authentication

When you sign in with Google, we request only the scopes needed for authentication and account setup (your basic profile and email address). We do not sell your Google account data and we do not request access to any other Google service.

4b. Android Early Access and the Home Page

The home page lets you leave the Google account address you use on Google Play so that we can add it to the Android internal-testing list. We store that address, the language you were reading in, and the date. Nothing else: no name, no IP address, no browser fingerprint. It is used only to send the tester invitation, it is never shared, and it is deleted 180 days after the invitation goes out or when the testing programme ends, whichever comes first. Write to [email protected] to be removed sooner.

The home page also counts how it is used: page views, which language was shown, which of the two colour modes, a coarse screen-size bucket, the hostname of the site you arrived from, and whether the call to action was pressed. There is no cookie and no stored identifier; visits are grouped by a random value that exists only in the browser tab and is gone when it closes. No IP address or browser user-agent is recorded, and these counts are kept for 90 days.

5. Notifications and On-Device Data

Reminders are generated and scheduled entirely on your device. There is no push server: no notification token is created and no reminder content is sent anywhere. Reminders are off by default, and Android asks for notification permission only at the moment you turn them on. If you deny it, the rest of the app keeps working. Your reminder preferences, reminder history, and the offline cache of your task list stay on the device and are removed when you sign out.

6. Data Sharing and Processors

We do not sell personal data and we do not share it for advertising. Apart from mentorship, which you choose and control and which is described in 6.1 below, we share data only with the service providers that operate SelfPatch, and only under contractual safeguards:

6.1 Mentorship — sharing with another person

Mentorship is the one place where SelfPatch shows your data to another person rather than to a service provider. It only happens if you buy a mentorship, and it is limited by choices you make and can reverse at any time.

Mentorship data is kept on a shorter clock than the rest of your account: see section 7.

7. Data Retention

We retain account and app data while your account is active. Product analytics events are automatically deleted after 90 days. A summary record of which app surfaces you saw (first and last time seen) is deleted 90 days after it was last seen. Feedback delivery metadata (which never contains the subject or message) is also deleted after 90 days. Feedback content in our support inbox is kept for up to 12 months, unless it is needed longer to resolve an active request or meet a legal obligation. When you delete your account, your account record and the app data linked to it are deleted; limited support or legal records may remain only for those stated periods and purposes.

Mentorship data is on its own schedule, and different parts of it are kept for different lengths of time for different reasons:

8. Security

Data is encrypted in transit (HTTPS/TLS). Every table holding user data is protected by row-level security, so your account can only read its own rows. On Android, your sign-in session is stored in the operating system's hardware-backed keystore rather than in plain text, cleartext HTTP is disabled at the platform level, and device backups of app data are turned off.

9. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or export your information.

10. Children

SelfPatch is not directed to children. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be published on this page with an updated date.

12. Contact

For privacy questions or requests: [email protected]