Legal
Privacy Policy
Last updated 20 September 2026
Draft — pending review
This document has not yet been verified against the shipped app or reviewed by a lawyer. Confirm every data claim below, then set legalDraft = false in lib/company.ts to remove this notice sitewide.
This policy explains how Applation OÜ (“Applation”, “we”, “us”) handles personal data across this website and our mobile applications. Each app also has its own policy setting out exactly what that app collects:
1. Who is responsible for your data
The data controller is:
Applation OÜ
Narva mnt 5, 10117 Tallinn, Estonia
Registry code 17599165
support@applation.org
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the address above and are handled by the company’s management.
2. Our approach
We collect the minimum personal data needed to make a feature work. We do not sell personal data. We do not use personal data for advertising profiling, and we do not share it with data brokers.
3. What we collect on this website
- Server logs. Our hosting provider records the IP address, user agent, requested URL and timestamp of each request in order to serve the site and protect it from abuse. These logs are kept for a short period and then deleted.
- Messages you send us. If you email us, we process your address and the content of your message in order to reply.
This website does not set advertising or tracking cookies, and does not embed third-party analytics that profile you across sites.
4. What our apps collect
This varies by app and is described in each app’s own policy, in its App Store Privacy Nutrition Label, and in its Google Play Data safety section. Broadly, our apps may process:
- Account data — such as an email address, display name and authentication identifiers, so you can sign in and keep your data across devices.
- Content you create — the entries, settings and progress you record in the app.
- Device and diagnostic data — crash reports and basic technical information, used to find and fix faults.
- Push notification tokens — if you enable notifications, so we can deliver them.
5. Legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the app and your account | Performance of a contract — Art. 6(1)(b) |
| Security, abuse prevention, fault diagnosis | Legitimate interests — Art. 6(1)(f) |
| Push notifications and optional features | Consent — Art. 6(1)(a) |
| Health-related information you choose to record | Explicit consent — Art. 9(2)(a) |
| Keeping accounting and tax records | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you can withdraw it at any time — in your device settings, in the app, or by writing to us. Withdrawal does not affect processing carried out before you withdrew.
6. Who we share data with
We use a small number of processors to run our Services. Each is bound by a data processing agreement under Article 28 GDPR and may only act on our instructions:
- cloud hosting, database and authentication providers;
- push notification delivery services operated by Apple and Google;
- crash and error reporting;
- email delivery for transactional messages.
Apple and Google also process purchase and subscription data as independent controllers under their own privacy policies. We never receive your full payment card details.
We may disclose data where we are legally required to do so, or to establish, exercise or defend legal claims.
7. International transfers
We prefer processors that host data inside the European Economic Area. Where data is transferred outside the EEA, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses, together with additional safeguards where needed.
8. How long we keep data
- Account and app content — for as long as your account exists. When you delete your account, we delete or irreversibly anonymise it within 30 days, except where the law requires us to keep a record.
- Backups — deleted data can persist in encrypted backups for up to 90 days before rotating out.
- Support correspondence — up to 24 months.
- Accounting records — 7 years, as required by the Estonian Accounting Act.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority where you live.
To exercise any of these, email support@applation.org or use our account deletion page. We respond within one month. We may ask you to verify your identity before acting on a request.
10. Children
Our Services are not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with data, contact us and we will delete it.
11. Security
Data is encrypted in transit with TLS and at rest by our hosting providers. Access to production systems is restricted, authenticated and logged. No system is perfectly secure, but if a breach occurs that is likely to put your rights at risk we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
12. Changes
We will post any update here and change the date above. Material changes are announced in the app or by email before they take effect.
13. Contact
Applation OÜ, Narva mnt 5, 10117 Tallinn, Estonia — support@applation.org
