Bloopie Privacy Policy
Who is responsible
Document version: 27 September 2026
Bloopie is operated by Szymon Kurek, ul. Śródrzeczna 13, 43-518 Ligota, Poland. I am responsible for deciding how personal data is used for Bloopie. In this policy, “we” means the operator of Bloopie.
This policy covers the Bloopie mobile app and website. For privacy questions or requests, contact [email protected] or write to the address above.
Information we handle
- Account information: email address, account identifier, authentication information and, when provided by your sign-in provider, your name. Email/password, Google and Apple sign-in use Firebase Authentication. Google and Apple also process information under their own policies when you use their sign-in services.
- Your records: habit names, descriptions, goals, schedules, completion history, notes or reasons you enter, and related preferences, progress, statistics and achievements. Information is stored on your device and, for account-backed functions, processed by our servers. Local-only use does not necessarily stop technical connections to service providers.
- Settings and delivery information: language, timezone, notification preferences, device/installation identifiers and push tokens, plus records needed to send and troubleshoot notifications.
- Support information: your contact details, message, replies, support notes and information needed to resolve your request. Please do not send passwords or unnecessary sensitive details.
- Technical and usage information: IP address, device/browser and operating-system information, app version, service interactions, error and performance information, and relevant cookie or SDK identifiers. The information depends on the service and enabled function.
Account and habit information comes from you and your use of the service; sign-in providers supply authentication and profile information, while technical information is collected through the app, website and their service providers. Account functions cannot be provided without the necessary account information. Optional information is not required to create an account. Internal event and delivery records can include account identifiers, email addresses or habit names; this operational processing is separate from advertising analytics.
Bloopie is intended for habits that do not contain special-category personal data. Our Terms of Service prohibit entering such data about yourself or others, including information revealing health, religious beliefs or sexual orientation. Do not include it in habit names, descriptions or other content. If you enter it by mistake, remove it or contact support without repeating the sensitive details. This restriction does not mean that information entered contrary to the Terms cannot reach our systems; our obligations under applicable data-protection law still apply.
Why we use information
We use account and habit data to provide the functions you request, manage your account, synchronize records where available, and respond to support requests. Where GDPR applies, the basis for processing necessary to provide the agreed service is performance of our contract with you.
We process proportionate security and operational information to prevent abuse, investigate failures and maintain reliable services. Our basis is our legitimate interest in protecting and operating Bloopie, where your rights do not override that interest. We process privacy requests to comply with our GDPR obligations. Other enquiries that are not necessary to perform a contract are handled on the basis of our legitimate interest in responding to people who contact us. We retain proportionate evidence needed to establish, exercise or defend legal claims on the basis of our legitimate interest in protecting our rights. Where such evidence contains special-category data, a separate applicable condition under Article 9 GDPR is also required.
Where we request consent for optional analytics or advertising, that consent is also the basis for the associated personal-data processing. Optional analytics and advertising have separate purposes and controls, described below. Receiving this policy or accepting the Terms does not itself constitute consent to optional tracking.
Analytics, diagnostics, cookies and advertising
The following services are covered by this policy on the app and website:
| Service | Purpose and information |
|---|---|
| Sentry | Diagnose technical errors using error reports and technical metadata. Production app and API reports are restricted to error types, release information and sanitized stack frames. Website diagnostics may also include browser, request and performance information. |
| Google Analytics, including Google Analytics for Firebase | Understand use of the app and website through interaction events, device/app/browser information and analytics identifiers. |
| AppsFlyer | Measure advertising effectiveness and support advertising and retargeting, using attribution and interaction information and identifiers permitted by your settings and applicable law. Retargeting can involve connecting interactions with advertising shown elsewhere. |
Habit content is excluded from external analytics and advertising data. We do not describe technical identifiers or reports as anonymous merely because names and email addresses are omitted.
Our website uses cookies and similar technologies. Some support necessary functions; others support analytics or advertising. On iOS, Apple also controls permission for tracking covered by App Tracking Transparency.
We request consent for optional analytics and advertising where required by applicable law and allow you to withdraw that consent. Use the privacy controls presented when consent is requested; you can also contact [email protected]. Refusing or withdrawing optional consent does not require deleting your account. Where processing relies on consent, withdrawal does not affect processing lawfully carried out beforehand.
Where consent is required, we do not start the relevant processing before you give it.
Notifications and emails
Push notifications provide habit reminders and motivational messages. Habit reminder text includes the habit name, which is processed by Google Firebase Cloud Messaging and Apple Push Notification service to deliver the notification. You can disable push delivery in your device’s notification settings. Turning off delivery does not necessarily erase existing device tokens or delivery records.
We send a welcome email, account/security communications, and support ticket updates and replies. Automated service emails are sent through FORPSI from [email protected]; FORPSI processes the recipient address and message content. You can use the unsubscribe link in an email to unsubscribe from the category of messages covered by that link. These are service messages, not a marketing mailing list. Unsubscribing from optional messages does not prevent delivery of messages necessary for account security or a support request you initiate.
Service providers and other recipients
Our provider list includes Railway for API and database hosting, FORPSI for our support mailbox and automated service emails, Google/Firebase for authentication, configuration, messaging and analytics, Sentry for diagnostics, and AppsFlyer for attribution and advertising-related functions. Our advertising partners include Meta Ads, Google Ads and TikTok Ads. Depending on the enabled integration and applicable permissions, these partners may receive attribution or interaction events and permitted identifiers for advertising measurement and retargeting. Habit content is excluded from this advertising-related sharing.
We may also disclose limited information when required by law or necessary to establish or defend legal claims. A transfer to a service provider and advertising-related sharing are not necessarily treated the same under every privacy law.
Provider information: Railway, FORPSI, Google/Firebase, Apple, Sentry, AppsFlyer, Google Ads, Meta, TikTok.
International processing
Our selected Railway API/database region is Amsterdam, Netherlands. Firebase Authentication processes data in the United States. Other provider services may also involve international processing. For transfers outside the EEA, we require an applicable adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and any necessary supplementary measures. You can request information and a copy of the relevant transfer safeguards at [email protected], with any necessary redactions to protect confidential information. The selected hosting region does not mean that all information stays in the EU. See Firebase’s processing-location information for its service-specific locations.
Retention and account deletion
| Category | Retention |
|---|---|
| Account and habit records | While needed for your account and requested functions, subject to deletion requests and applicable legal requirements. |
| Support tickets | Up to 24 months after closure. |
| Internal event log | Up to 12 months from the event. |
| Notification history | Up to 90 days from the notification record. |
| Failed-delivery records | Up to 30 days from the failure record. |
| Push tokens | Removed after 270 days without use, or earlier when invalidated or removed. |
| Hosting application logs | Kept for investigating failures, protecting the service and resolving incidents; the period depends on the incident and applicable hosting retention. We review whether continued retention is necessary. |
| Google Analytics user/event data | Retention depends on the configured property and data type. We retain identifiable data only while needed to evaluate usage and improve the service, subject to consent withdrawal and deletion rights. Google deletes expired user/event data through its monthly process. This setting does not cover standard aggregated reports or every advertising-related dataset. |
| Sentry event data | 30 days under our current Sentry Developer plan. Organization audit records are separate from end-user error events and are not covered by this period. |
| AppsFlyer end-user data | Its published services policy generally limits retention to 24 months, with exceptions for customer instructions or legal requirements/permissions. Shorter report-availability windows do not establish deletion. |
| Railway scheduled volume backups | We store recovery backups on Railway in the same region as our backend: Amsterdam, Netherlands (EU). Daily backups are retained for up to 7 days, weekly backups for up to 30 days, and monthly backups for up to 90 days. Deleted data may remain in these copies until they expire. |
| FORPSI mailbox backups | The published email-service description states two weeks. |
| Meta, Google Ads and TikTok data | Campaign and audience information is retained for the relevant advertising purpose, subject to applicable permissions, deletion rights and the partner’s own retention rules. These periods are separate from AppsFlyer’s retention. |
We may retain limited correspondence or evidence needed for a specific legal obligation or dispute until that obligation expires or the dispute and applicable limitation period end. This does not justify retaining all habit records or all activity history.
Where a maximum period is specified above, it is a limit, not a reason to keep information after it is no longer needed. A valid deletion request may require earlier removal. Standalone support correspondence is kept for resolving the request and necessary follow-up; correspondence stored with a ticket follows the ticket period.
You can initiate account deletion in the app’s account settings or request it at [email protected]. We may ask for proportionate information to verify that the account belongs to you.
Deletion requests must be handled without undue delay. Where GDPR applies, we normally respond within one month; if a permitted extension is necessary, we explain it within that period. This response deadline is not a routine waiting period for deletion. Uninstalling the app is not the same as deleting your account.
Your rights
Depending on applicable law and the processing involved, you can request access, correction, deletion, restriction and a portable copy of your data. You may withdraw consent where processing relies on it. Where local law gives you a right to opt out of targeted advertising or advertising-related sharing, you can exercise it by contacting [email protected] and through any applicable privacy controls. These rights have legal conditions and exceptions. Contact [email protected]; we do not require account deletion merely to submit a privacy request.
Your right to object: On grounds relating to your particular situation, you may object to processing based on our legitimate interests. You may object at any time to direct marketing, including related profiling; we will then stop processing your data for those purposes. Contact [email protected].
You may complain to Poland’s President of the Personal Data Protection Office (Prezes UODO), or another competent supervisory authority, including in your country where applicable.
Adults only and policy changes
Bloopie is intended for users aged 18 or older. If you believe an under-18 user has provided personal data, contact us so we can investigate and take appropriate steps, including account closure and deletion where required.
We update this policy when our practices change. The version date above identifies this text. We will provide appropriate notice of material changes and obtain fresh consent where required before using information for a new purpose.