Privacy Policy
Relatably is a daily one-question app. We try to collect as little as possible while still running the daily drop, the wordcloud, the leaderboard, and push notifications. This page explains exactly what data we touch and why.
1. What we collect
- Anonymous device ID — a random ID generated on first launch and stored locally on your device (Expo SecureStore). The server only ever sees a SHA-256 hash of this ID. It is used to deduplicate submissions and gate the daily reveal.
- Your free-text answer — what you type into today's question. We aggregate it into the wordcloud and store it in our database (Firestore).
- Submission timestamp + dwell time — when you submitted and how long you spent before tapping submit. Used for anti-cheat scoring.
- IP address (hashed) — used only to rate-limit submissions per IP. We never store your raw IP.
- Push token (FCM) — if you grant notification permission, we store the token so the daily drop can ping you. You can revoke this in iOS settings at any time.
- Apple ID (only if you sign in) — if you tap "Sign in with Apple" we receive a stable user identifier from Apple and an opaque email (Apple may relay it). We use this to score the leaderboard and link the friend graph. You can use Relatably entirely without signing in.
- Friend graph (only if you sign in) — the user IDs of accounts you friend, plus pending friend requests.
2. What we do NOT collect
- No name, address, phone number, or birthday.
- No location.
- No contacts.
- No camera, microphone, or photo-library access.
- No third-party analytics SDK on the iOS client (no PostHog, no Mixpanel, no Firebase Analytics).
3. Third parties that process your data
- Google Firebase (Firestore, Auth, Cloud Messaging, Remote Config) — stores submissions, the wordcloud, the friend graph, and routes push notifications. Subprocessor agreement: firebase.google.com/support/privacy.
- Vercel — hosts our backend; receives request metadata (URL, hashed IP, anonymous device ID hash). vercel.com/legal/privacy-policy.
- Sentry (server-side only) — receives stack traces from our backend if it crashes. No PII attached. sentry.io/privacy.
- Google Perspective API — your submitted answer text is sent to Google for toxicity scoring. Google's policy: policies.google.com/privacy.
- Google AdMob — when ads are enabled, AdMob shows display ads using Apple's SKAdNetwork (privacy-preserving attribution). We do not pass user identifiers. policies.google.com/technologies/ads.
- Branch.io — used for install attribution when you tap a referral link. Branch may collect anonymous device fingerprints. branch.io/policies.
4. Data retention
Submissions, hashed device IDs, and aggregated wordclouds are retained indefinitely so that the public archive of past questions stays readable. If you delete your account (see §6) we delete your signed-in identity and friend graph; we do not retroactively scrub your anonymized historical answers from the wordcloud, because they are already aggregated and not tied to you in any retrievable way.
5. Children
Relatably is rated 12+. We do not knowingly collect data from children under 13. Parents who believe their child has used Relatably can email the address above and we will delete any associated identifier.
6. Your rights (GDPR / CCPA)
You can request access to, rectification of, or erasure of your personal data by emailing levin.schwab@gmx.de. Account deletion: if you signed in with Apple, you can revoke Relatably in Settings → Apple ID → Sign in with Apple on your iPhone, OR email us. We will permanently delete your signed-in identity, friend graph, and leaderboard entries within 30 days.
7. Changes to this policy
We will post any changes to this URL. Material changes will be announced in-app at next launch.
8. Contact
Levin Schwab
levin.schwab@gmx.de
Germany