Sumraf — Privacy Policy


Sumraf
Privacy Policy

Last Updated
May 5, 2026
General Enquiries
hello@sumraf.com
DPO Contact
dpo@sumraf.com
01

Introduction

Sumraf ("we," "our," or "us") is committed to protecting your privacy. This General Privacy Policy applies to all mobile applications ("Apps") published under the Sumraf developer account on the Apple App Store and Google Play Store, and to all related services.

By downloading, installing, or using an App, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree, please do not use our Apps.

We prioritize user privacy and rely on your explicit consent for data collection and access to device features. You have the right to withdraw or modify your consent at any time. This can be done directly through the settings within the App or by contacting us at hello@sumraf.com.

02

Data We Collect

2.1 Data You Provide Directly

Depending on the features of the specific App you use, we may collect:

2.2 Data Collected Automatically

Data TypeSourcePurpose
Device advertising identifiers (IDFA on iOS, AAID on Android)Device OSAttribution, personalised advertising (with consent), fraud prevention
Device model, OS version, app version, build numberDevice OSCrash reporting, compatibility, performance optimisation
IP addressNetworkSecurity, approximate region for localisation
Usage events (screens viewed, features used, sessions)In-app interactionAnalytics, product improvement
Crash logs and error stack tracesFirebase Crashlytics, SentryDebugging and stability monitoring
Attribution data (install source, campaign, ad interactions)Adjust, AppsFlyer, Apple Search Ads, Facebook SDK/Pixel,Revcat,TikTok,Firebase,PlaystoreMarketing attribution and campaign measurement
Subscription and purchase statusRevenueCat / App StoresEntitlement verification
Push notification token (FCM token)Firebase Cloud MessagingPush notification delivery (with permission)
Consent status and preferencesUsercentrics CMP / ATT (iOS)GDPR / CCPA / ATT compliance record-keeping
Ad interaction data (impressions, clicks)Google AdMobServing in-app advertisements (contextual without consent; personalised with consent)
Aggregated behavioural and engagement dataBi-Dash (data collection)Product intelligence and user engagement analysis

2.3 Data We Do NOT Collect

Unless user consent or app requirements:

2.4 AI and Machine-Learning Processing

Some Apps use third-party AI services to provide features such as voice-to-text, content generation, recitation feedback, or task classification. Where an App uses AI (features are intended for entertainment purposes only and may generate inaccurate or incorrect information. They should not be utilized for financial, medical, or other significant real-life decision-making.):

03

Legal Basis for Processing

Processing ActivityLegal Basis
Account management and core App functionalityPerformance of a contract — Art. 6(1)(b) GDPR
Crash reporting and security monitoringLegitimate interests — Art. 6(1)(f) GDPR
Non-personalised analytics (where consent not required by law)Legitimate interests — Art. 6(1)(f) GDPR
Personalised advertising and attribution trackingConsent — Art. 6(1)(a) GDPR
Facebook SDK / Pixel data processing for ad measurementConsent — Art. 6(1)(a) GDPR
Apple Search Ads attributionConsent — Art. 6(1)(a) GDPR
AI feature inputs sent to third-party processorsConsent — Art. 6(1)(a) GDPR
Compliance with legal obligationsLegal obligation — Art. 6(1)(c) GDPR

You may withdraw consent at any time via Settings → Privacy Settings in the App, or through your device settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

04

Consent Management

We use Usercentrics as our Consent Management Platform (CMP) to comply with GDPR, UK GDPR, ePrivacy, and CCPA/CPRA. Before any advertising, attribution, social, AI-processing, or personalised-analytics SDK is initialised:

iOS — App Tracking Transparency (ATT). On iOS we additionally request ATT permission (App Store Review Guidelines §5.1.2) before accessing your IDFA or enabling any cross-app or cross-website tracking, including probabilistic or fingerprint-based attribution methods. All tracking SDKs — including Adjust, AppsFlyer, Facebook SDK, and Apple Search Ads until ATT permission is granted.

05

How We Use Your Data

06

Third-Party Services & Data Sharing

We share data with carefully selected third-party providers strictly to operate our Apps. We do not sell your personal data. Each provider processes data under its own privacy policy and a Data Processing Agreement with us. The specific providers active in an individual App are disclosed and its iOS Privacy Label / Google Play Data Safety form.

6.1 Hosting, Backend & Core Firebase Suite

ServiceTypeData SharedPurpose
Firebase / React Native Firebase
Google LLC
EssentialUser ID, app data, in-app contentCore database storage and account management
Firebase Authentication
Google LLC
EssentialEmail address, UID, sign-in tokenSecure account authentication
Firebase Remote Config
Google LLC
FunctionalDevice info, app versionRemote feature flags and configuration
Firebase Cloud Messaging (FCM)
Google LLC
FunctionalFCM device tokenPush notification delivery (with permission)

6.2 Analytics & A/B Testing

ServiceTypeData SharedPurpose
Google Firebase Analytics
Google LLC
FunctionalPseudonymous user ID, usage events, device infoProduct analytics and user behaviour understanding
Google Analytics for Firebase
Google LLC
FunctionalSession data, screen views, conversion eventsUnified analytics reporting
Firebase A/B Testing
Google LLC
FunctionalExperiment variant assignment, device infoFeature testing and optimisation
Bi-Dash (data collection)
Bi-Dash
FunctionalAggregated engagement and behavioural eventsProduct intelligence and engagement analysis

6.3 Crash & Error Monitoring

ServiceTypeData SharedPurpose
Firebase Crashlytics
Google LLC
FunctionalCrash reports, error stack traces, device infoApp stability monitoring and bug fixing
Sentry
Functional Software, Inc.
FunctionalError logs, stack traces, breadcrumbs, device infoReal-time error tracking and performance monitoring

Sentry Privacy Policy

6.4 Attribution & Marketing Measurement

ServiceTypeData SharedPurpose
Adjust
Adjust GmbH
EssentialAdvertising ID, install events, in-app events (with consent)Mobile marketing attribution and campaign performance measurement
AppsFlyer
AppsFlyer Ltd.
EssentialAdvertising ID, install events, in-app events (with consent)Mobile marketing attribution and campaign performance measurement
Apple Search Ads
Apple Inc.
MarketingAttribution token, campaign identifiers (iOS only, with consent)Measuring installs driven by Apple Search Ads campaigns
Facebook SDK
Meta Platforms, Inc.
EssentialAdvertising ID, install events, in-app events, app usage data (with consent)Facebook/Meta campaign attribution and ad measurement
Facebook Pixel
Meta Platforms, Inc.
EssentialEvent signals, conversion data (with consent)Measuring ad campaign conversions across Meta platforms

1. Adjust Privacy Policy
2. AppsFlyer Privacy Policy
3. Meta Privacy Policy
4. TikTok Privacy Policy
5. RevnueCat Privacy Policy
6. Apple Privacy Policy
7. Google Privacy Policy
8. Admob Privacy Policy
9.Firebase Privacy Policy
10.Open AI Privacy Policy

Facebook SDK & Pixel — Consent Required The Facebook SDK and Facebook Pixel are initialised only after you grant consent in the Usercentrics CMP banner, and on iOS only after ATT permission is granted. Without consent, no data is transmitted to Meta.

6.5 Advertising

ServiceTypeData SharedPurpose
Google AdMob
Google LLC
FunctionalAdvertising ID, ad interaction data (contextual only without consent; personalised only with consent)Serving in-app advertisements on the free tier

We use Google AdMob exclusively for advertising across all Sumraf. No other ad network or mediation platform is used. Ads served in children's Apps are strictly contextual with no behavioural targeting.

6.6 AI & Machine-Learning Processing

ServiceData SharedPurpose
Generative AI / Speech-to-Text
(specific processor named in App Addendum)
Text prompts, audio recordings, image inputs (App-dependent, with consent)AI-powered features as described in §2.4

6.7 Subscription & In-App Purchase

ServiceTypeData SharedPurpose
RevenueCat
RevenueCat, Inc.
EssentialUser ID, purchase events, subscription status, transaction identifiersIn-app purchase and subscription entitlement management
Apple App Store
Apple Inc.
Purchase records (handled by Apple)iOS in-app purchase processing
Google Play Store
Google LLC
Purchase records (handled by Google)Android in-app purchase processing

6.8 Consent Management

ServiceTypeData SharedPurpose
Usercentrics CMP
Usercentrics GmbH
EssentialConsent choices (no personal data sold)GDPR / CCPA consent record-keeping

6.9 Third-Party Content APIs

Some Apps call read-only content APIs.

6.10 Legal Disclosure

We may disclose information when required by law, court order, or government authority, or where necessary to protect our rights, user safety, or the integrity of our Apps. We will notify affected users where legally permitted.

6.11 Sub-Processor List

A current list of all sub-processors used across the Sumraf portfolio is maintained. We update this page when sub-processors are added, replaced, or removed.

07

Advertising

Free-tier Apps may display advertisements served exclusively by Google AdMob.

08

Data Retention

Data TypeRetention Period
Account dataUntil account deletion or as required by law
User-generated contentUntil deletion by user or account deletion
Firebase Analytics eventsUp to 14 months (Firebase Analytics default)
Crash logs (Crashlytics)Up to 90 days
Crash logs (Sentry)Up to 90 days
Attribution data (Adjust)Up to 13 months
Attribution data (AppsFlyer)Up to 24 months
Facebook SDK / Pixel attribution dataAs per Meta data retention policy
Apple Search Ads attribution dataAs per Apple data retention policy
Bi-Dash engagement dataAs per Bi-Dash data retention policy
Subscription and purchase recordsAs required by financial, tax, and legal obligations
Voice / audio recordingsDeleted by us after processing; AI processor retention up to 30 days (§2.4)
AI prompts (text)Deleted by us after processing; AI processor retention up to 30 days (§2.4)
Consent recordsUp to 3 years (GDPR accountability obligation)

Where an App requires different retention, the App-Specific states it.

09

Data Security

We implement industry-standard security measures including:

No method of transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. If you believe your account or data has been compromised, contact us immediately at hello@sumraf.com.

10

Children's Privacy

Unless an individual App is specifically designed and rated as a children's app:

11

Your Privacy Rights

11.1 All Users

Access

Request a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your personal data (see §11.4).

Opt-Out of Personalised Ads

Through device settings or our in-app consent manager.

11.2 EEA / UK / Swiss Users (GDPR / UK GDPR)

11.3 Account & Data Deletion

In-AppSettings
Emaildpo@sumraf.com (reply within 30 days)

User-Facing DataTimeline
Removed within 7 daysUser-Facing Data
Removed within 30 daysBackend Production Data
Purged within 90 daysEncrypted Backups

Anonymised, aggregated analytics data may be retained indefinitely. To exercise any other privacy right, contact us at dpo@sumraf.com. We respond within statutory deadlines:

12

International Data Transfers

Our Apps operate globally. Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our service providers (Google, Meta, RevenueCat, Adjust, AppsFlyer, Sentry, Usercentrics, Bi-Dash) maintain infrastructure. Where data is transferred outside the EEA, UK, or Switzerland, we rely on appropriate safeguards including:

13

Push Notifications

Where an App offers push notifications, we may send reminders, learning streaks, subscription updates, or feature announcements via Firebase Cloud Messaging (FCM). Notification permission is requested in context (when first relevant), not at launch. You may enable or disable notifications at any time via your device settings or the App's settings. Disabling notifications does not affect your ability to use core features.

14

Local Data Storage

Some App data — preferences, progress, offline content, cached settings — is stored locally on your device using platform-appropriate storage mechanisms (e.g., MMKV, Redux Persist, AsyncStorage on Android; equivalent storage on iOS). Local data is not transmitted to our servers and is removed when you uninstall the App or reset App data in your device settings.

Sensitive credentials are stored in the device secure keystore (iOS Keychain / Android Keystore).

15

Tracking Technologies

Our Apps do not use browser cookies. Mobile equivalents we may use include:

16

iOS Privacy Manifest Compliance

Our iOS Apps include the PrivacyInfo.xcprivacy Privacy Manifest required by Apple, declaring required-reason API usage and the data practices of all bundled third-party SDKs — including Firebase, Facebook SDK, Sentry, RevenueCat, Adjust, AppsFlyer, and Usercentrics. We update Privacy Manifests with each SDK upgrade and verify that App Privacy Labels in App Store Connect match the manifest declarations and actual app behaviour, in line with App Store Review Guidelines §5.1.1.

17

Google Play Data Safety Compliance

Our Android Apps include a fully completed Data Safety declaration in Google Play Console reflecting the actual data collection and sharing behaviour of the App and all integrated SDKs — including Firebase, Facebook SDK, Sentry, Adjust, AppsFlyer, RevenueCat, Google AdMob, and Usercentrics. We review and update Data Safety declarations whenever we update SDK integrations or data practices, in line with Google Play's Developer Program Policy.

18

Biometric Data

If an App offers biometric features (e.g., Face ID, Touch ID, fingerprint authentication for app lock or premium content):

19

AI-Generated Content Disclosure

Where an App generates content using AI (text, audio feedback, suggestions, classifications):

20

User Reporting & Content Moderation

Where an App allows user-generated content or displays AI-generated output, an in-app reporting mechanism is provided — typically Settings → Report Content, or a long-press / "Report" option on the content itself. Reports are reviewed within 48 hours during business days. Content that violates our Community Guidelines or applicable law is removed, and accounts that repeatedly violate guidelines may be suspended or terminated.

This mechanism is also available for reporting:

21

Data Breach Notification

In the event of a personal data breach that affects your information, we will:

We maintain an incident response process, including documentation of all breaches, regardless of whether notification is legally required.

22

Data Protection Contact

For users in the EEA, UK, and Switzerland, our Data Protection point of contact is reachable at dpo@sumraf.com. Where Article 27 GDPR requires the appointment of an EU Representative, the current Representative's name.

23

Changes to This Privacy Policy

We may update this Policy periodically to reflect changes in our practices, technology, or legal requirements. For material changes, we will notify you through:

The "Last Updated" date at the top reflects the most recent revision. Continued use of our Apps after changes become effective constitutes acceptance of the updated Policy.

24

Contact Us

For questions, concerns, or privacy requests:

Sumraf

General privacy enquiries: hello@sumraf.com

Data Protection contact (EEA / UK): dpo@sumraf.com

Website: sumraf

We respond within statutory deadlines (§11.4) or, where no deadline applies, within 30 days.