Legal
Privacy policy.
This policy covers the Streakletics mobile app. The streakletics.com website is covered by its own privacy policy.
This Privacy Policy explains how Point Zero GmbH processes personal data when you use the Streakletics mobile app (the “App”). It applies only to the App. The Streakletics website is covered by a separate Website Privacy Policy.
1. Controller and contact details
The controller responsible for processing your personal data is:
Point Zero GmbH
Speditionstr. 15A
40221 Düsseldorf
Germany
Phone: +49 162 7555786
Privacy and general enquiries: info@pointzero.tech
App support: support@pointzero.tech
Further company information is available in our Legal Notice.
We have not appointed a data protection officer.
2. How we obtain and use personal data
We obtain personal data:
- directly from you, for example when you enter profile information, record a training session, send feedback or contact us;
- automatically from the App and your device, for example an internal user identifier, technical diagnostics and product-usage events;
- from service providers you choose to use, such as Google Sign-In, an app store or a payment platform; and
- by deriving limited status information from your activity, such as streaks, records, badges or Pro entitlement status.
We process personal data only for the purposes described below. Depending on the processing operation, the legal basis is:
- Article 6(1)(b) GDPR, where processing is necessary to provide the App or perform a contract with you;
- Article 6(1)(a) GDPR, where we ask for your consent, for example for push notifications or certain advertising-related processing;
- Article 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation; or
- Article 6(1)(f) GDPR, where processing is necessary for our legitimate interests, particularly App security, abuse prevention, troubleshooting, product improvement and the establishment, exercise or defence of legal claims, provided that your interests and fundamental rights do not override those interests.
3. Guest use, anonymous accounts and registration
You can begin using the App without completing a conventional registration form. This guest mode is not technically accountless: when you continue through the initial onboarding, Firebase Authentication creates an anonymous account and assigns a persistent internal user identifier (UID). A corresponding user record is created so that the App can save your progress and provide its functions.
You may later register or upgrade the same account using an email address and password. This links the login credentials to the existing account so that your saved progress can be retained. We process the UID, authentication status, email address and authentication information required for this purpose. Passwords are handled by Firebase Authentication; we do not store a readable copy of your password.
You may also choose Google Sign-In. In that case, Google authenticates you and may provide us with information associated with your Google account, such as an account identifier, email address, display name and profile image, depending on your Google account and the permissions shown during sign-in. Google processes data for its own authentication service under the Google Privacy Policy.
The legal basis for anonymous account creation, registration, login and account linking is Article 6(1)(b) GDPR. Security and abuse-prevention measures are additionally based on Article 6(1)(f) GDPR.
4. Training data, progress and local App settings
To provide the core Streakletics functions, we process information such as:
- completed training sessions, including date and time;
- exercise type, training level or day, repetitions, sets, rest periods and duration;
- totals, personal records, streaks, streak freezes, badges and progress;
- selected training, coach, display and language preferences; and
- account and entitlement status, such as guest status and whether Pro features are available.
This information is used to run training sessions, save and display your progress, calculate statistics and achievements, synchronise data and restore your account. The legal basis is Article 6(1)(b) GDPR. Processing required to detect errors, manipulation or misuse is based on Article 6(1)(f) GDPR.
Some settings and cached App state are stored locally on your device, for example the selected language, training preferences, guest status and a locally cached Pro status. This local storage is used to provide the functions and settings you request and to avoid unnecessary server requests. To the extent Section 25 TDDDG applies, this storage is used for functions expressly requested by you and is based on Section 25(2) no. 2 TDDDG.
The App does not request access to Apple Health, HealthKit, Google Fit or comparable health databases. It does not ask you to provide diagnoses or medical records. Training and performance information is not used to diagnose medical conditions.
5. Profile and leaderboard visibility
The App creates a community profile record linked to your UID. Depending on the information available and the functions you use, this record may contain:
- display name;
- profile image;
- motto;
- training totals, streaks and personal records;
- badges; and
- Pro status.
These fields may be displayed in leaderboards and profile views to other authenticated Streakletics users. “Authenticated users” includes users with a registered account and users who are signed in through the App with an anonymous Firebase account. The profile records are not available through Firestore to persons without an authenticated Streakletics session, but they are visible within the Streakletics community and should not be treated as private information.
A community profile is currently created as part of onboarding and the App does not currently provide a separate profile-visibility switch. Do not enter a display name, motto or upload an image that you do not want other Streakletics users to see.
Processing required to provide community profiles and leaderboards is based on Article 6(1)(b) GDPR. Measures used to maintain leaderboard integrity, prevent abuse and enforce our rules are based on Article 6(1)(f) GDPR.
6. Profile images, sharing, reviews and device permissions
If you choose a profile image, the App requests access to the photo you select from your device’s photo library. The selected image and related file metadata, such as file size and upload time, are uploaded to Firebase Storage. The legal basis is Article 6(1)(b) GDPR. You can replace or remove the image in the App.
The current App does not request camera or microphone permission. It may request photo-library access when you select a profile image or choose an available action to save App-generated content. It requests notification permission only if notifications are offered or enabled.
If you use the sharing feature, the App creates shareable content and opens the operating system’s share sheet. Data is sent to another service only after you select that service. The selected recipient or platform processes the shared content under its own terms and privacy policy.
If you choose to rate the App, you are redirected to the relevant app-store review interface. Any rating or review is processed by the app-store operator under its own privacy terms.
7. Feedback, reports and blocking
If you submit in-App feedback, we process the content of your message, your UID, the time of submission and technical or account context needed to understand and respond to it. Please do not include unnecessary sensitive personal data in free-text fields.
If you report or block another user, we process the identifiers of the users involved, the report category or reason, any information you submit, timestamps and moderation status. We use this information to review reports, protect users, prevent abuse and enforce our Terms of Service.
Feedback connected to the provision of or support for the App is processed under Article 6(1)(b) GDPR. General product feedback and moderation, reporting and blocking are processed under Article 6(1)(f) GDPR, based on our legitimate interests in improving the App, maintaining a safe community and defending against abuse or legal claims.
8. Firebase and Google Cloud services
We use Firebase and Google Cloud services supplied under our business account by Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA, and other Google affiliates and subprocessors may also process data when providing these services.
We have entered into Google’s applicable data processing terms. Further information is available in Google’s Firebase Privacy and Security information, Cloud Data Processing Addendum and Privacy Policy.
8.1 Firebase Authentication, Cloud Firestore and Firebase Storage
Firebase Authentication manages anonymous accounts, registered accounts and sign-in. Cloud Firestore stores account, profile, training, progress, feedback and moderation-related data. Firebase Storage stores uploaded profile images. These services process the relevant content together with technical identifiers, timestamps, request metadata and connection information needed to provide and secure the services.
Our primary Cloud Firestore database is located in europe-west3 (Frankfurt, Germany). Other Firebase components may use different locations as described below or in Google’s service documentation.
The legal basis for providing these functions is Article 6(1)(b) GDPR. Security, fraud prevention and service integrity are based on Article 6(1)(f) GDPR.
8.2 Cloud Functions
We use Google Cloud Functions to perform backend operations, including push-notification handling and account-deletion processes. The custom first-generation functions currently use Google’s default us-central1 region in the United States. The Firebase account-deletion extension is configured in europe-west3.
The functions process only the information required for the relevant operation, such as UIDs, push tokens, device type and records that must be located or deleted. The legal bases correspond to the underlying function: Article 6(1)(b) GDPR for providing requested App functions and Article 6(1)(f) GDPR for secure and reliable operation.
8.3 Firebase Crashlytics
In production releases, we use Firebase Crashlytics to detect, analyse and fix crashes. Crashlytics may process:
- crash reports and stack traces;
- the time and technical circumstances of a crash;
- App version;
- device model, operating-system version, locale and orientation;
- Firebase and Crashlytics installation identifiers; and
- your UID, where available in a production session.
We do not intentionally include your name, email address or raw content from free-text fields in Crashlytics reports. Crash reporting is not enabled for our debug, profile or test builds. Google states that Crashlytics retains crash stack traces and associated identifiers for 90 days before beginning removal from live and backup systems.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is maintaining a secure, stable and reliable App and identifying errors that would otherwise be difficult to reproduce.
8.4 Firebase Cloud Messaging
If you enable push notifications, we use Firebase Cloud Messaging (FCM) to deliver notifications such as training reminders. For this purpose, we process a device-specific push token, device type and technical delivery information. Notification content is transmitted as necessary for delivery.
The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw consent at any time by disabling notifications in the App, where available, or in your device settings. Disabling notifications does not affect the lawfulness of processing before withdrawal.
8.5 Firebase App Check
Firebase App Check helps protect our backend against unauthorised clients, automated access and manipulation. The production App uses Google Play Integrity on Android and Apple App Attest on iOS. These services process app, installation, device-integrity and security-token information needed to assess whether requests originate from a genuine App installation. The checks are not used by us to determine your creditworthiness or make decisions with legal or similarly significant effects.
Processing is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in securing the App, user accounts and backend systems.
8.6 Technical logs
Google Cloud and Firebase generate technical logs when the App communicates with the backend. Depending on the service and request, these logs may include IP address, time, requested resource, response or error information, device or client information, security signals and a UID or other technical identifier.
We use these logs for security, troubleshooting, abuse prevention and reliable operation under Article 6(1)(f) GDPR. Our Google Cloud Logging configuration retains ordinary _Default log-bucket data for 30 days. The _Required bucket, which primarily contains mandatory audit logs, is retained for 400 days. Individual Firebase services may have their own documented retention periods.
8.7 Services not used
The App version covered by this Privacy Policy does not use Google Analytics for Firebase or Firebase Performance Monitoring.
9. Mixpanel product analytics
We use Mixpanel in production releases to understand how the App’s functions are used, identify failed or confusing flows, assess feature adoption and prioritise product improvements. The service is provided by Mixpanel, Inc., Pier 1, Bay 2, The Embarcadero, San Francisco, California 94111, USA.
Mixpanel starts automatically when the production App is used. Depending on your activity, the following information is processed:
- a Mixpanel-generated pseudonymous identifier and, after account identification, your Firebase UID as the Mixpanel
distinct_id; - whether the account is a guest account and whether Pro features are active;
- selected language;
- product-usage events relating to training flows, streaks, paywalls, prompts, sharing and moderation functions;
- limited contextual values such as the current streak;
- structured technical result, error-code or error-category information; and
- SDK and connection information that may include timestamps, App version, operating system, device type, time zone, IP address and coarse location derived from the network connection.
The UID is a persistent pseudonymous identifier, not anonymous data. We do not send your display name, email address, phone number, profile-image URL, separate RevenueCat identifiers or raw error messages to Mixpanel. We do not use Mixpanel Session Replay, advertising profiling or heatmaps, and Mixpanel data is not shared with AdMob for advertising purposes. Mixpanel is disabled in debug, profile and test builds.
The Mixpanel SDK may store technical information on your device to maintain its identifier, settings and a local event queue before transmission. For the processing of personal data through Mixpanel under the GDPR, we rely on Article 6(1)(f) GDPR rather than consent. Our legitimate interests are understanding whether core product flows work as intended, improving usability, detecting recurring technical failures and directing development resources toward features that users actually use. In balancing these interests, we take into account the pseudonymous identifier, the exclusion of direct contact and profile information, the restriction to production builds, the use of an EU data region and the absence of advertising use or session recording.
You have the right to object to this processing on grounds relating to your particular situation under Article 21 GDPR. You may submit an objection to info@pointzero.tech. We will assess and handle it in accordance with Article 21 GDPR.
Our Mixpanel project uses the EU data-residency endpoint, and project data is stored in Mixpanel’s Netherlands data centre. Our configured retention period for event data is two years. Mixpanel user-profile data may be retained for the duration of the active Mixpanel subscription unless it is deleted earlier. Mixpanel data is not yet automatically erased when a Streakletics account is deleted; you may request its deletion from us using the contact details above.
We have entered into a data processing agreement with Mixpanel. Further information is available in Mixpanel’s Privacy Policy, GDPR information and Data Processing Addendum.
10. Advertising through Google AdMob
The free version of the App may display advertisements through Google AdMob. AdMob is provided by Google and may process:
- IP address and network-derived approximate location;
- device and App information, including operating system, App version and language;
- a mobile advertising identifier or comparable identifier where available and permitted;
- ad impressions, interactions and technical delivery information; and
- information required for frequency control, aggregated reporting, security and fraud prevention.
The Android release includes the advertising-ID permission required by the AdMob SDK. Apple’s SKAdNetwork may provide aggregated advertising-attribution information.
AdMob is configured to serve only non-personalised ads to all users. The App does not request App Tracking Transparency permission and does not access the advertising identifier (IDFA); Google’s Publisher First-Party ID is disabled. Non-personalised ads may still use a device-local identifier for frequency capping and aggregated reporting, but are not used for cross-app or cross-site tracking. Google’s User Messaging Platform (UMP) continues to provide the required advertising disclosures and privacy choices.
You can revisit available advertising privacy choices through the App’s privacy or ad-consent settings. Device-level advertising controls may also be available in your operating-system settings.
Where processing or access to device information requires consent, the legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. Processing strictly necessary for secure, restricted ad delivery and fraud prevention may be based on Article 6(1)(f) GDPR and, where applicable, Section 25(2) TDDDG. Our legitimate interests are financing the free version of the App and protecting advertising systems against misuse, subject to your rights and the restrictions described above.
Further information is available in Google’s information about privacy and messaging for AdMob and the Google Privacy Policy.
11. Subscriptions, app stores and RevenueCat
Paid Pro subscriptions and in-app purchases are processed by the app store through which you obtained the App. The store operator processes payment credentials and payment transactions under its own terms. We do not receive your complete credit-card or bank-account details.
We use RevenueCat to manage products, purchases, subscriptions and entitlements. RevenueCat is provided by RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, Florida 33511, USA. RevenueCat may process:
- your Firebase UID as the RevenueCat App User ID;
- product, offering and entitlement identifiers;
- subscription and purchase status, purchase dates, renewals, cancellations and expiration;
- app-store receipt or purchase-token information;
- platform, device type, operating system and App version; and
- technical status and error information required to validate and restore entitlements.
Processing is necessary to perform the subscription contract and provide Pro features under Article 6(1)(b) GDPR. Fraud prevention, entitlement troubleshooting and reconciliation are based on Article 6(1)(f) GDPR.
RevenueCat stores customer data using Amazon Web Services in the United States. We have entered into a data processing agreement with RevenueCat. Further information is available in RevenueCat’s Privacy Policy and Data Processing Addendum.
Deleting your Streakletics account does not automatically cancel an active subscription. You must cancel it separately through the relevant app-store subscription settings. RevenueCat records are not yet automatically deleted when you delete your Streakletics account and may remain where required to administer purchases, restore entitlements, prevent fraud or comply with legal retention obligations. You may ask us to assess deletion or restriction using the contact details in Section 1; deletion may be limited where records remain necessary for an active subscription or a legal obligation.
For further information about the app stores, see the Google Privacy Policy and Apple Privacy Policy.
12. Contact by email and Google Workspace
If you contact us by email, we process your email address, message, attachments and related communication metadata to handle your request and any follow-up questions. Support requests connected to your use of the App are processed under Article 6(1)(b) GDPR. General enquiries are processed under Article 6(1)(f) GDPR, based on our legitimate interest in responding to communications. Legal or compliance correspondence may also be processed under Article 6(1)(c) GDPR.
We use Google Workspace as our email provider. Google Cloud EMEA Limited and affiliated Google entities process email data on our behalf under Google’s applicable data processing terms. Emails are retained for as long as necessary to resolve the matter and afterwards only where required for documentation, legal claims or statutory retention obligations.
13. Recipients and international data transfers
Depending on the functions you use, personal data may be disclosed to:
- Google Cloud EMEA Limited, Google LLC and Google subprocessors for Firebase, Google Cloud, Google Workspace, Google Sign-In and AdMob;
- Mixpanel, Inc. for product analytics;
- RevenueCat, Inc. for subscription and entitlement management;
- Apple, Google and the relevant app-store or payment platform for distribution, purchases, reviews and platform services;
- recipients or services you deliberately select through the operating-system share sheet; and
- professional advisers, authorities, courts or other parties where disclosure is required by law or necessary for the establishment, exercise or defence of legal claims.
Within Point Zero GmbH, access is limited to persons who need the data for the purposes described in this Privacy Policy.
Some providers process data outside the European Economic Area, particularly in the United States. This applies in particular to our custom Google Cloud Functions, RevenueCat and possible access by US-based provider entities or subprocessors. Where required, transfers are protected by an applicable adequacy decision, including the EU-US Data Privacy Framework for participating recipients, and/or the European Commission’s Standard Contractual Clauses together with supplementary safeguards. Data-processing agreements under Article 28 GDPR are in place where the provider acts as our processor.
The selection of an EU region for Firestore or Mixpanel reduces international storage transfers for those services but does not necessarily exclude all remote access, support processing or processing by subprocessors outside the EEA.
14. Retention and account deletion
We retain personal data only for as long as necessary for the stated purpose, unless legal obligations or legitimate legal interests require a longer period. The principal periods and criteria are:
| Data category | General retention rule |
|---|---|
| Account, profile, training and progress data in Firebase | For the duration of the account and normally deleted through the account-deletion process, subject to the exceptions below |
| Profile images | Until replaced, removed or deleted with the account |
| Feedback | Normally deleted with the account where it can be linked through the configured deletion process; otherwise until the feedback has been evaluated and is no longer needed |
| User reports and moderation records | May be retained after account deletion where necessary for user safety, abuse prevention or legal claims |
| FCM tokens | Until notifications are disabled, the token is replaced, the account is deleted or the token is otherwise no longer needed |
| Crashlytics reports | Google states that relevant crash data and identifiers are retained for 90 days before removal begins |
Google Cloud _Default / _Required logs | 30 days / 400 days under our current configuration |
| Mixpanel events | Two years under our current project configuration |
| Mixpanel user profile | Until deleted or the applicable provider/service retention period ends; not automatically deleted with the Streakletics account |
| RevenueCat and app-store records | For as long as required for subscriptions, entitlement restoration, fraud prevention, disputes and applicable legal obligations; not automatically deleted with the Streakletics account |
| Emails | Until the request is resolved and subsequently for documentation, claims or statutory retention where necessary |
Commercial and tax records may have to be retained for six, eight or ten years, depending on the document and the applicable statutory rule. Data required for legal claims may be retained until the relevant limitation period has expired.
You can delete your account in the App under Settings > Account settings > Delete Account. If you cannot access the App, you can use our account-deletion page or contact us.
The automated Firebase deletion process is configured to remove the authentication account, the main user record and its subcollections, training sessions covered by the recursive user-path deletion, the associated community profile, stored profile images and linked feedback records. Deletion may take a reasonable period to propagate through live systems and provider backups.
Account deletion does not automatically remove the separate Mixpanel and RevenueCat records described above, app-store transaction records or moderation reports that must be retained. Contact us if you want your request to include data held through these providers. We will assess the request under Article 17 GDPR and coordinate deletion or restriction where legally and technically applicable.
Uninstalling the App does not by itself delete your server-side account or cancel a subscription.
15. Your data-protection rights
Subject to the statutory requirements, you have the right to:
- obtain access to your personal data under Article 15 GDPR;
- request correction of inaccurate data under Article 16 GDPR;
- request erasure under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- receive data you provided in a portable format under Article 20 GDPR; and
- lodge a complaint with a data-protection supervisory authority under Article 77 GDPR.
Where processing is based on consent, you may withdraw that consent at any time with effect for the future under Article 7(3) GDPR. Withdrawal does not affect processing that took place lawfully before withdrawal.
Right to object under Article 21 GDPR
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
To exercise your rights, contact info@pointzero.tech. We may need information reasonably necessary to verify your identity and locate your records, such as the email address connected to a registered account or your App UID.
You may complain to any competent supervisory authority. The authority responsible for Point Zero GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2–4
40213 Düsseldorf
Germany
16. Required and optional data
There is generally no statutory obligation to provide personal data to use the App. However, the anonymous UID and the training and technical data required for the requested functions are necessary to provide the App. If this processing is not possible, some or all core functions cannot be provided.
Registration, Google Sign-In, profile text, a profile image, push notifications, feedback, sharing and a paid subscription are optional. Choosing not to provide the relevant data means only that the corresponding optional function may not be available.
17. Automated decisions and personalisation
The App may use training progress, streak status, feature interactions and entitlement status to determine when to display contextual prompts, achievements or subscription offers. This does not produce legal effects or similarly significantly affect you. We do not carry out solely automated decision-making within the meaning of Article 22 GDPR.
Mixpanel product analytics and RevenueCat entitlement information are not used by us to determine creditworthiness, insurance eligibility, employment eligibility or comparable matters.
18. Children
Streakletics is a general fitness and habit-building App and is not specifically directed at children under 13. We do not ask for a date of birth and do not operate age verification, so we may not know a user’s age. Advertising requests are currently subject to the restrictive configuration described in Section 10.
If you are a parent or guardian and believe that a minor has provided personal data unlawfully or that data should be deleted, please contact us using the details in Section 1.
19. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental loss, unlawful use and unauthorised access. These include access controls, encrypted transmission, authenticated database access, App Check, data minimisation and restricted internal access. No method of electronic transmission or storage can guarantee absolute security.
20. Changes to this Privacy Policy
We may update this Privacy Policy when the App, service providers, legal requirements or processing activities change. The current version will be made available in the App or on the Streakletics website. If a change requires your consent, we will request it separately rather than treating continued use of the App as consent.
Please also review our Terms of Service.