Oscillator

Privacy Policy

1. Controller and scope

This Privacy Policy explains how personal data is processed in connection with the Hourglass mobile application for Android and iOS (the "App"). The controller of the personal data processed through the App is Michał Daniel Dobrzański, Poland ("we", "us"). You can reach us at dobrzanskioscillator@gmail.com.

2. Data stored on your device

The App requires no account and no registration. The App stores base functionality data on your device storage. It is deleted when you uninstall the App. On Android it may be included in your device's backup, which is controlled by your device settings.

3. Advertising

3.1 Provider

The App displays one banner advertisement at the bottom of the timer screen. Ads are served by AppLovin MAX, a service of AppLovin Corporation, 1100 Page Mill Road, Palo Alto, CA 94304, USA ("AppLovin"), through the AppLovin software development kit (SDK) embedded in the App. No ad is requested for users who own the ad-free unlock described in section 5.

The App also embeds the SDK of Meta Audience Network, a service of Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA (for users in the EEA, the United Kingdom and Switzerland: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland) ("Meta"). Through AppLovin MAX, Meta can bid for the banner placement and serve the ad. When it does, the Meta SDK communicates with Meta directly.

3.2 Data processed

When an ad is requested, the SDKs transmit to AppLovin and, where Meta takes part in the request, to Meta, information that includes:

3.3 Purposes and recipients

AppLovin processes this data to select and deliver ads, to limit how often an ad is shown, to measure and report ad performance, to detect fraud and invalid traffic and, where permitted, to personalize advertising. AppLovin acts as an independent controller for this processing. Through the MAX mediation platform and the AppLovin Exchange, ad requests may be shared with AppLovin's advertising partners, which bid for the ad placement. AppLovin's processing and its partners are described in the AppLovin Privacy Policy.

Meta processes the data it receives to take part in the auction, to deliver, measure and report on the ads it serves, and to detect fraud and invalid traffic. Meta acts as an independent controller for this processing, as described in the Meta Privacy Policy and the Audience Network policies.

We receive from AppLovin only aggregated reporting, such as the number of impressions and the revenue earned per country. We do not receive your advertising identifier, we cannot identify you from these reports, we do not sell personal data, and we use no attribution or tracking service of our own.

3.4 Legal basis and your choices

Advertising funds the free version of the App. If you are in the European Economic Area, the United Kingdom or Switzerland, the App asks for your consent before it requests its first ad. The consent message is provided by Google's consent management platform, which follows the IAB Europe Transparency and Consent Framework. It explains each purpose, lists the advertising partners, including AppLovin, and lets you consent or, under Manage options, decide per purpose and per partner, including refusing all of them. To show the message, Google receives your IP address, which it uses to determine your region, and basic information about your device and the App.

Your choices are saved on your device and sent with each ad request, so that AppLovin and its partners can follow them. Meta does not read these choices directly: where you refuse Meta in the message, the App tells the Meta SDK to apply Meta's Limited Data Use option. Where you consent, storing and accessing information on your device and personalized advertising are based on your consent (Article 6(1)(a) GDPR). Some purposes, such as measuring ads and detecting fraud and invalid traffic, may rely on legitimate interest (Article 6(1)(f) GDPR). The message shows which ones, and section 10 describes your right to object. If you refuse, your data is not used for personalized ads, and fewer ads or none may be shown. You can review or change your choices at any time under Settings, Privacy options, Ad preferences, which shows the message again.

Outside these regions, the delivery of ads, frequency capping, measurement, and the detection of fraud and invalid traffic are based on our interest in funding and protecting a free application, and ads may be personalized on the basis of your advertising identifier in accordance with applicable law. In every region your device lets you limit personalization at any time: on Android you can reset or delete the advertising ID under Settings, Privacy, Ads; on iOS you can deny tracking as described below. You may object to this processing as described in section 10, and the ad-free unlock (section 5) ends it entirely for your device.

On iOS, the operating system additionally asks, through Apple's App Tracking Transparency prompt, whether the App may track you across other companies' apps and websites. Before that prompt, the App may show a short explanation of why it asks. If you decline, the IDFA is not available to the SDK and you receive non-personalized ads. You can revisit this choice under iOS Settings, Privacy & Security, Tracking.

Where a law such as the California Consumer Privacy Act grants an opt-out from the sale or sharing of personal information, the device controls above apply, and you can contact us as set out in section 10. We do not sell personal data and we do not discriminate against users who exercise their privacy rights.

4. Usage analytics

The App uses Google Firebase Analytics, a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (for users in the EEA, the United Kingdom and Switzerland: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), to understand how the App is used. Firebase Analytics collects:

We use this data for two purposes only: to understand which features are used, so we can improve the App, and to understand how much revenue the ad produces, so we can keep the App free. We do not collect your name, email address, contacts or precise location, we do not use analytics to build advertising profiles, and we do not sell or share this data. Google processes the data on our behalf as our processor under the Firebase Data Processing and Security Terms; see also Privacy and Security in Firebase.

The App also uses Firebase Crashlytics, from the same provider, to receive a report when the App crashes: the stack trace, device model, operating system version, App version, free memory and disk space at the time, and a randomly generated identifier for this installation of the App. We use these reports only to find and fix crashes. Google processes them on our behalf under the same terms.

The legal basis is our legitimate interest in maintaining and improving the App (Article 6(1)(f) GDPR). The Anonymous usage statistics switch under Settings, Privacy options turns collection off or on at any time, for crash reports as well.

5. The ad-free unlock

The App offers one optional, one-time in-app purchase that permanently removes the banner ad and unlocks all sand colors. Payment is handled entirely by Google Play or the Apple App Store under their own terms and privacy policies. We never receive your payment details.

To determine whether you own the unlock, the App uses RevenueCat, a service of RevenueCat, Inc., San Francisco, CA, USA. RevenueCat validates the store receipt and stores, for this App, a pseudonymous identifier generated by the App on your device, together with the associated purchase records (product, purchase date and store transaction reference), the platform and the App version. RevenueCat acts as our processor; see the RevenueCat Privacy Policy. This processing is necessary to perform our contract with you, namely to provide the unlock you purchased and to restore it on your other devices (Article 6(1)(b) GDPR). The unlock is tied to your store account and can be restored on any device signed in to that account through Restore purchases in the App's settings.

6. Permissions and system features

Permission or feature Why the App uses it
Notifications (Android POST_NOTIFICATIONS; iOS notification authorization) To alert you when the timer finishes while the App is in the background. Optional: the timer works without it, but the alert is then shown only inside the App.
Exact alarms (Android USE_EXACT_ALARM) So that the finished-timer alert fires at the exact moment the countdown ends, also in battery-saving modes. This permission is reserved for alarm and timer apps.
Run at boot (Android RECEIVE_BOOT_COMPLETED) To re-arm a running timer's alarm if your device restarts before the timer ends. The App does not otherwise run at startup.
Vibration (Android VIBRATE; iOS haptics) For the vibration alert when the timer finishes. Can be turned off in settings.
Advertising ID (Android com.google.android.gms.permission.AD_ID); App Tracking Transparency (iOS) Used only by the advertising SDKs, as described in section 3. Not used for users who own the ad-free unlock.
Internet access To load ads, to verify the ad-free unlock and to send the analytics events and crash reports described in section 4. The timer itself works offline.
Time-sensitive notifications and Live Activities (iOS) So that the finished-timer alert can be delivered during Focus modes, and so that the running countdown can be shown on the Lock Screen and in the Dynamic Island.

The App does not request access to your location, camera, microphone, contacts, photos, files or any other sensitive permission.

7. Data retention

8. International transfers

AppLovin, Google, Meta and RevenueCat are headquartered in the United States and may process data there and in other countries. Where data of users in the EEA, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, these providers rely on the EU-U.S. Data Privacy Framework, including its UK Extension and the Swiss-U.S. Data Privacy Framework, where they are certified under it, or on the European Commission's Standard Contractual Clauses and equivalent UK and Swiss instruments. Details are available in each provider's privacy policy.

9. Children

The App is not designed for or directed to children under 13 years of age, or under the higher age of digital consent that applies in your country (up to 16 in parts of the EEA). We do not knowingly collect personal data from children, and the advertising SDKs are configured for a general audience, not for a child-directed service. If you are a parent or guardian and believe that a child has provided personal data through the App, please contact us and we will take appropriate steps.

10. Your rights

Depending on where you live, you have the right to access the personal data held about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work. Our lead authority is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych) in Poland.

Because the App has no accounts and we hold no data that identifies you, the most direct controls are on your device and in the App: Privacy options in Settings, your device's advertising settings, or uninstalling the App, which removes all data stored on the device. Rights concerning data held by AppLovin or Meta as independent controllers can be exercised directly with them, as described in their privacy policies; we will assist you where we can.

Residents of California and other United States states with comparable laws have the right to know what personal information is collected and how it is used and shared, to request its deletion or correction, to opt out of the sale or sharing of personal information for cross-context behavioral advertising, and not to be discriminated against for exercising these rights. Your device's advertising settings and the ad-free unlock are the opt-out controls for such sharing.

To exercise any right, contact us at the address in section 13. We will respond within the time limits required by applicable law.

11. Security

Data stored on your device is protected by your device's own security measures. Data exchanged between the SDKs embedded in the App and their providers is encrypted in transit. We hold no copies of your data and therefore cannot be a source of its disclosure.

12. This website

This Policy and the Terms of Service are hosted on GitHub Pages, a service of GitHub, Inc. When you open these pages, in a browser or inside the App, GitHub may process your IP address and technical request data as described in the GitHub General Privacy Statement. These pages set no cookies and use no analytics.

13. Changes to this Policy

If a future version of the App changes what data it processes, we will update this Policy before releasing that version and indicate the change with a new effective date at the top of this page. Where a change materially affects you, we will also draw your attention to it in the App where feasible.

14. Contact

Michał Daniel Dobrzański
dobrzanskioscillator@gmail.com