Privacy Policy - Ava Habit Tracker

Last updated: 4 June 2026

You can delete your data or your entire account at any time — directly in the app under Settings, or via the data & account deletion page. Deletion takes effect immediately. Questions? Email me@maxkeppeler.com.

This Privacy Policy explains how the Ava Habit Tracker mobile app (package com.mk.ava, the “app”) collects, uses, stores, shares, and protects your personal data, and the rights you have over it. The app is available worldwide; this policy is written to help you understand how your data is handled and your rights under the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), the Washington My Health My Data Act (MHMDA), and other applicable privacy laws.

At a glance

  • An account is required — sign in with Google or continue anonymously as a guest.
  • Your habits and content are stored in the cloud (Google Firebase) so they sync across devices.
  • You decide what to log. Health-related entries are entirely optional and entered manually by you — covered by a separate Consumer Health Data Privacy Policy.
  • Usage analytics are off by default — you choose whether to turn them on.
  • The app shows no ads today. If a free-tier ad option is added later, a Premium subscription will remove it. I do not sell your data for money, and I would never use your health-related entries to target ads.
  • You can export your data, and delete your data or account at any time with immediate effect.

Who is responsible (Data Controller)

The data controller responsible for your personal data is Maximilian Keppeler, an individual developer based in Germany. You can reach me at me@maxkeppeler.com. As I am established in the EU, no Article 27 representative is required. I have not appointed a Data Protection Officer because I am not legally required to do so; you can contact me directly about any privacy matter using the email above.

What data I collect, why, and the legal basis

Under the GDPR I must have a lawful basis for processing your personal data. The table below summarizes what is processed, why, and the legal basis for each purpose.

DataWhyLegal basis (GDPR Art. 6 / 9)
Account identity: email, display name, profile photo (Google Sign-In)Create and secure your account, sync your dataPerformance of a contract (Art. 6(1)(b))
Anonymous user ID (guest mode)Let you use the app without a Google accountPerformance of a contract (Art. 6(1)(b))
Habit content: titles, descriptions, values, reminders, tags, filter lists, free-text journal notes, and photo attachmentsProvide the core habit-tracking servicePerformance of a contract (Art. 6(1)(b))
Optional health-related entries you choose to log (e.g. fitness, weight, calories, steps, water intake, quitting smoking or alcohol, related notes)Track the habits you decide to trackYour explicit consent (Art. 9(2)(a)) — see below
Subscription / purchase status (handled by RevenueCat, keyed to your account ID)Manage Premium access and restore purchasesPerformance of a contract (Art. 6(1)(b))
Usage analytics (Firebase Analytics)Understand feature usage to improve the appConsent (Art. 6(1)(a)) — off by default
Advertising data, if ads are introduced in the free version (a device advertising identifier and limited ad-interaction data, via Google AdMob)Show ads that keep the free version freeConsent (Art. 6(1)(a)) in the EEA/UK for personalized ads; otherwise your opt-out choice
Crash & performance diagnostics (Firebase Crashlytics)Detect and fix crashes, keep the app stable and secureLegitimate interests (Art. 6(1)(f))
Device & log data: IP address, device model, operating system, app configuration, and service identifiers (including, where present, an advertising identifier used by the SDKs below)Operate, secure, and troubleshoot the serviceLegitimate interests (Art. 6(1)(f))

The app does not use push messaging — reminders are scheduled locally on your device. Crash and performance diagnostics (Crashlytics) run from app start to keep the app stable; usage analytics are separate and stay off until you opt in. The app does not currently show ads — if advertising is introduced in the free version later (see the Advertising section below), the ad SDK may access a device advertising identifier, and a paid Premium subscription would remove ads.

Where your data is stored and international transfers

Your data is stored using Google Firebase / Google Cloud. A local copy is also cached on your device so the app works offline; changes sync to the cloud when you are back online. Google may process and store data on servers located in the United States and other countries. Where data is transferred outside the EU/EEA or the UK, it is protected by appropriate safeguards: Google LLC is certified under the EU-US Data Privacy Framework (and its UK Extension and the Swiss-US DPF) and relies on it for EEA/UK data sent to the United States, backed by the European Commission’s Standard Contractual Clauses as an additional safeguard; RevenueCat relies on the Standard Contractual Clauses. See Google’s and RevenueCat’s privacy documentation for details.

Health-related and other sensitive data

Ava Habit Tracker is not a medical app and does not provide medical advice. The app does not automatically collect health data and does not infer your health status. If you choose to track health-related habits — for example fitness activity, body weight, calories, steps, water intake, or quitting smoking or alcohol — or write notes about them, that information may qualify as “special category” data under GDPR Article 9 and as “consumer health data” under laws such as the Washington My Health My Data Act. Because you enter this data manually and voluntarily, your deliberate choice to log it constitutes your explicit consent (Art. 9(2)(a)) for me to store and process it solely to provide the service to you. You can stop at any time, edit or delete individual entries, export everything, or delete all of your data — and withdrawing consent is as simple as deleting the data.

Third-party service providers

I use a small number of trusted service providers who process data on my behalf as “processors” under their respective Data Processing Addenda, and only for the purposes described in this policy:

  • Google Firebase — Authentication, Cloud Firestore (data storage), Cloud Storage (photos), Analytics, Crashlytics, and Remote Config. Firebase privacy / Google Privacy Policy
  • Google Play services — billing, in-app review and in-app updates. Google Privacy Policy
  • RevenueCat — manages Premium subscriptions; receives your account ID and purchase information. RevenueCat privacy
  • Google AdMob — if and when ads are introduced in the free version, Google AdMob serves them and may receive a device advertising identifier and ad-interaction data (see the Advertising section). For personalized ads, Google acts as an independent controller rather than only my processor. How Google uses data

These providers — other than Google AdMob in connection with personalized advertising — are contractually obliged to protect your data, process it only on my instructions, and not use it for their own purposes. For personalized ads, Google acts as an independent controller and uses certain data for its own advertising purposes (see Advertising and Selling and sharing below).

Advertising

The app does not currently show advertising. I may introduce ads in the free version in future, provided by Google AdMob (a Google service), in which case a paid Premium subscription would remove them and this policy will be updated before ads go live. If that happens, Google may use a device advertising identifier and limited data about your device and your interaction with the ads, and the following will apply:

  • In the EEA, UK, and Switzerland, personalized ads would be shown only with your prior consent, requested through a Google-certified consent management platform; if you decline you would see only non-personalized (contextual) ads, and you could change or withdraw your choice at any time.
  • Elsewhere, you would be able to opt out of personalized advertising in the app and/or through your device settings (you can reset or delete your advertising ID, or enable “opt out of Ads Personalization”).
  • I would never use your habit content, health-related entries, journal notes, or other sensitive information to target ads, and such data would not be shared with the ad network for advertising purposes.

You can learn more about how Google uses data and your ad choices via Google’s advertising information.

Selling and sharing your data

I do not sell your personal data for money, and the app does not currently show ads. If personalized advertising is introduced in future, it can involve “sharing” personal data for cross-context behavioral advertising as those terms are defined under certain U.S. state laws; you would be able to opt out at any time — see Advertising above and Your California privacy rights below. Your habit content and any sensitive or health-related data you enter are never sold or shared for advertising.

Data retention and deletion

Your data is kept only while your account is active. At any time you can, directly in the app under Settings, either delete all of your data (which keeps your sign-in) or delete your entire account. Both in-app actions take effect immediately — there is no waiting period or temporary “freeze” — and remove your habits and everything logged against them (entries, journal notes, daily and period summaries, and attached photos) together with your filter lists; deleting your account also removes the account itself. If you no longer have the app installed, you can request deletion via the data & account deletion page, and such requests are completed within 30 days. Analytics data is retained according to Firebase’s default retention settings, and crash reports are typically retained for around 90 days. I keep the minimum data required by law (for example, for tax or fraud-prevention purposes relating to a paid subscription).

Security and data breaches

Your data is encrypted in transit and at rest by Firebase, access is restricted by security rules, and metadata (EXIF) is stripped from photos before upload. No method of transmission or storage is 100% secure, so I cannot guarantee absolute security. In the event of a personal-data breach that is likely to affect you, I will notify the relevant supervisory authority and, where legally required, affected users (GDPR Articles 33–34).

Your rights (EU/EEA and UK)

If you are in the EU/EEA or the UK, you have the right to:

  • be informed about how your data is used (this policy);
  • access a copy of your personal data;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability — the app’s built-in JSON and XLSX export lets you download your data in a structured, machine-readable format;
  • withdraw consent at any time — for analytics, through the controls available in the app and on your device; for health-related data, by editing or deleting it.

You can exercise most of these rights directly in the app, or by emailing me@maxkeppeler.com. You also have the right to lodge a complaint with a supervisory authority — in Germany, your competent State Data Protection Authority, or otherwise the authority in your country of residence. I do not carry out automated decision-making that produces legal or similarly significant effects (GDPR Art. 22); statistics, streaks, phase insights, and the dependency graph are descriptive features, not automated decisions about you.

Data you import and export

The app lets you import data (from Ava’s own backup format or from certain other apps) and export your data as JSON or XLSX. Imported content is processed under this Privacy Policy just like data you enter directly. You are responsible for ensuring you have the right to import any data you bring in, particularly if it relates to other people. Files you export leave my control and become your responsibility.

Your California privacy rights (CCPA/CPRA)

If you are a California resident, this section serves as your notice at collection. The categories of personal information collected are: identifiers (email, name, account/device IDs), internet/app activity (usage and diagnostics), commercial information (subscription status), visual information (photos you upload), and any sensitive or health-related information you choose to enter. The sources are you and your Google account; the recipients are the service providers listed above; the purposes are to provide, secure, and improve the app (and, if ads are introduced in the free version, to show ads). I retain each category only as long as needed for those purposes, as described in “Data retention and deletion” above. I do not sell your personal information for money, and the app does not currently “share” it for cross-context behavioral advertising. If personalized advertising is introduced, you will be able to opt out (“Do Not Sell or Share My Personal Information”) through the in-app ad choices and your device’s ad settings. To the extent any opt-out preference signal (such as Global Privacy Control) is technically applicable to the app, I will treat it as a valid opt-out request. You also have the right to limit the use of sensitive personal information — and in any case I do not use your sensitive or health-related data for advertising. You have the right to know, access, delete, and correct your information; you can use an authorized agent. I will not discriminate against you for exercising these rights and will respond to verifiable requests within 45 days (extendable once by a further 45 days).

Consumer health data (Washington MHMDA, Nevada & similar laws)

If you choose to log health-related habits, that information may be “consumer health data” under laws such as the Washington My Health My Data Act or Nevada SB370. How it is collected, used, and shared, and how you can access, delete, or withdraw consent for it, is set out in full in the separate Consumer Health Data Privacy Policy. In short: you enter it voluntarily, it is used only to provide the tracking service, it is never sold and never shared with third parties for their own purposes, and you can delete it at any time.

Other U.S. state privacy rights

If you live in a U.S. state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Texas, Oregon, and others), you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. If the free version shows personalized ads, that is “targeted advertising” you can opt out of at any time (see Advertising above); I do not sell personal data for money, and I do not carry out profiling that produces legal or similarly significant effects. You also have the right to appeal a decision on your request: I will respond within 45 days, and if I deny an appeal you may contact your state Attorney General. Some states (for example Maryland) further restrict the sale of sensitive data and require data minimization; I do not sell sensitive or health-related data and collect only what you choose to provide.

Children’s privacy

The app is not directed to children. I do not knowingly collect personal data from children under 16 in the EU/EEA, or under 13 in the United States. If I learn that such data has been collected without appropriate consent, I will delete it. Any advertising is treated as non-child-directed, and I do not knowingly serve personalized ads to children. If you are a parent or guardian and believe your child has provided personal data, please contact me at me@maxkeppeler.com.

Changes to this policy

I may update this Privacy Policy from time to time. Material changes will be reflected by an updated “Last updated” date at the top of this page, and I encourage you to review it periodically.

Contact

If you have any questions about this Privacy Policy or your data, contact me at me@maxkeppeler.com.

This Privacy Policy is effective as of 4 June 2026.