THE SMALL PRINT, IN PLAIN SIGHT

Privacy policy · Tubli

Privacy, in a few words

1. Who we are

Tubli is developed and operated by Slumpy Shrimp Studios, registered under CNPJ 32.687.778/0001-07 (“we” or “the studio”).

For privacy questions and rights requests, email [email protected]. For other studio enquiries, use [email protected].

2. On-device content and optional iCloud sync

Habits, tasks, categories, sessions, history, medals, your display name, and avatar emoji are stored locally. Tubli does not operate its own server to store that content.

If you enable sync, content is synchronized through CloudKit in your own iCloud account's private database. Sync is optional and can be turned off in the app's Settings. The studio cannot view the private content in its developer console.

Challenge sharing, described in section 5, is a separate feature. Usage analytics, diagnostics, and support messages are also separate from your private content.

iCloud is provided by Apple and is subject to Apple's terms and privacy policy.

Apple Privacy Policy

3. Screen Time and iOS permissions

Tubli uses FamilyControls, DeviceActivity, ManagedSettings, and ManagedSettingsUI with your authorization through iOS. You can manage and revoke that authorization in the system's Screen Time settings.

When selecting apps for limits and blocking, FamilyControls APIs provide opaque identifiers. These tokens do not disclose the selected apps' names or identifiers to the studio.

Detailed usage reports are rendered by Tubli's reporting extension in an environment isolated by iOS. That environment restricts network requests and the movement of sensitive content outside it. The studio does not receive this report.

Tubli locally records configured schedules, whether a limit was reached, and temporary unlocks. These records support habit tracking and weekly reviews. Protected Screen Time data is not sent to advertising services, Analytics, or Crashlytics.

Measurement is per device and starts when you activate tracking. Tubli does not retrieve earlier history or monitor someone else's device.

4. Usage analytics and crash reports

Google's Firebase Analytics helps us understand how Tubli is used: screens opened, features used, focus session duration, app version, and language. The duration of a focus session created in Tubli is an event from Tubli itself; it is not the protected report of other apps' usage.

Events are associated with installation or app-instance identifiers. The studio does not associate them with your name, email, or Apple Account. Because they can distinguish installations, we describe this information as pseudonymous technical data rather than guaranteeing absolute anonymity.

Before sending analytics events, Tubli removes user-provided text, replacing habit names and custom category names with markers. Text written in habits, tasks, and categories is not included in those events.

Firebase Crashlytics receives technical information to diagnose failures, such as device model, system and app versions, crash traces, and installation identifiers. The studio can review diagnostics in Firebase without accessing your private iCloud content.

In Settings → Usage statistics, you can turn off both Analytics and Crashlytics. Turning collection off does not, by itself, request deletion of previously sent records. The initial setting and diagnostic deletion procedures will be confirmed in the final version.

5. Challenges and competitions with friends

When you create or join a competition, your display name (nickname), avatar emoji, and progress are visible to the other participants in that competition. Tubli does not share your email with them.

Data is exchanged through CloudKit sharing between participants' iCloud accounts, without a content server operated by the studio. The internal identifier is the app's iCloud user record; it is not presented as your email or an identifier for other services.

Participation data is held in the competition creator's shared zone. Leaving a competition removes your participation. This does not make the habits, tasks, or other records in your private storage public.

6. Notifications and purchases

Tubli notifications are local and scheduled on your device. The studio does not operate a push notification server. You can control notification permissions in iOS Settings.

Purchases are processed by the App Store. The studio does not receive card details or other payment credentials. Tubli checks with the system to confirm your entitlement to paid features. Apple handles purchase information under its own policies.

7. Weekly reviews and on-device intelligence

Weekly reviews use Tubli's own rules to propose habit adjustments. When Apple Intelligence is available on a compatible device, its on-device model writes the review text through the Foundation Models framework. The feature also works without Apple Intelligence.

We do not send your content to external AI APIs or use it to train AI models. Adjustment decisions are made by the app's rules; the model helps express them in natural language.

8. Services and international processing

Apple and Google services may involve processing outside Brazil, including in the United States. Applicable contractual mechanisms and other transfer safeguards will be detailed in the final review based on the settings and agreements actually in place.

We do not display ads, sell or rent data to brokers, or track you across apps or websites. Tubli does not request ATT permission for advertising tracking.

Privacy and security in Firebase

Google Privacy Policy

9. Retention, deletion, and support

On your device, Settings → Clear all data deletes local content and removes active blocks. Deleting the app also removes its local data. These actions should not be understood as automatically deleting iCloud copies or information already sent to Firebase.

Synced data remains in your iCloud account, where you can manage it through iOS settings. Backups and shared data need to be managed separately using the options provided by Apple and the app.

Google Analytics user and event retention depends on the property's configuration. Tubli's actual retention period will be specified in the final version.

According to Firebase's documentation, Crashlytics retains crash traces and associated identifiers for 90 days before starting removal from live and backup systems.

If you email us, we receive your address and the information you choose to include so we can reply. This is separate from private app data. Support email retention and the email provider will be specified in the final review.

Google Analytics data retention

10. Your rights and grounds for processing

Depending on applicable law, you may request confirmation of processing, access, correction, deletion, portability, and information about sharing, and exercise rights to object, restrict processing, or withdraw consent. The scope of these rights depends on your jurisdiction and applicable legal conditions.

You manage local and iCloud content through the app and system settings. For requests about diagnostics or information received by the studio, email [email protected]. We do not require you to send all your private content to make a request.

We respond within the time limits required by applicable law. Under Brazil's LGPD, confirmation and access may be provided immediately in simplified form or through a complete statement within 15 days under Article 19. Other requests follow their own applicable deadlines and conditions.

Features you request may involve performance of a contract. The legal basis and consent flow for analytics and diagnostics must match the app's implementation, including the initial collection setting. The final version will specify these conditions and any legal obligations relating to support requests.

11. Children and personal use

Tubli is not directed at children under 13 and does not knowingly collect their data. This intended audience does not remove additional protections for children and teenagers under local law. If you believe a child has provided data to us, contact support.

Tubli tracks usage on the user's own device. It is not a parental control tool and cannot monitor another person's device.

12. Security

Local content benefits from iOS protections, and synchronization uses iCloud infrastructure and access controls. Technical data sent to Firebase is handled under that service's security documentation. The studio does not operate its own database of your habits and tasks.

No system offers absolute security. Protections depend on the type of data, the service used, and your device and account settings.

13. Changes and contact

We may update this policy to reflect changes in the app or data handling. We will update the date and communicate material changes in the app or release notes. Where new consent is required, we will request it; continuing to use the app is not a substitute for that consent.

Privacy and support: [email protected]. Studio contact: [email protected].

Slumpy Shrimp Studios · CNPJ 32.687.778/0001-07.

Contact & support