This Privacy Policy describes how EssGeeDev Inc. (“we,” “us,” or “our”) collects, uses, and discloses your information in connection with your use of the G.R.A.P.E.S A Day mobile application (the “App”).
We are committed to protecting your privacy and handling your personal data in a transparent and secure manner.
We collect information directly from you when you use our App, and we ensure that sensitive user content is encrypted on your device before it leaves your device.
Information you provide to us:
Account Information (Identifiers & Contact Info):When you create an account, we collect your User ID (assigned by our backend service, Supabase) and your Email Address (if you use email/password sign-up). This information is used for account management and authentication.
User Content:
Tasks:Any tasks, notes, or descriptions you create within the App. This data is encrypted on your device before being stored.
Profile Pictures (Photos or Videos):If you choose to upload a profile picture, the image data is encrypted on your device before being stored.
Password:Your password is used to derive an encryption key (see Section 4) but is never stored in plaintext on our servers.
Information collected indirectly (from your device/App usage):
Location Data (Precise Location & Coarse Location):If you choose to upload a profile picture using the device’s camera or photo library via the @capacitor/camera plugin, the photo file may contain EXIF metadata, including GPS location data. If present in the photo, this location data will be implicitly collected as part of the photo file. We do not otherwise explicitly request or collect your device’s location.
Device Identifiers:When you use the App, a unique User ID is assigned by our backend (Supabase) to identify your account. This is used for app functionality and account management.
We do not collect:
Financial Information (e.g., payment details)
Health and Fitness data
Contacts
Sensitive Information (e.g., racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, data concerning health or sex life)
Browse History (e.g., from using the @capacitor/browser plugin)
Search History
Other specific data types not explicitly mentioned above, unless you choose to provide them within user content fields.
3. How We Use Your Information
We use the information we collect for the following purposes:
App Functionality:To provide, operate, and maintain the core features of the App, including storing and retrieving your encrypted tasks and profile picture, and managing your user account.
Account Management:To manage your user account, authenticate your login, and enable cross-device synchronization of your encrypted data.
Product Personalization:To personalize your experience within the App by displaying your tasks and profile picture.
We do not use your information for tracking purposes (e.g., linking your data with data collected from other companies’ apps or websites for advertising or marketing). We do not sell your data.
4. How We Protect Your Information (Encryption Details)
We employ robust security measures, including strong encryption, to protect your data.
Client-Side Encryption:Your sensitive data, including tasks and profile pictures, are encrypted on your device using industry-standard cryptographic algorithms before they are transmitted to our servers.
We use AES-256 in GCM (Galois/Counter Mode) for symmetric encryption of your data.
Your master encryption key is derived from your password using PBKDF2 (Password-Based Key Derivation Function 2) with SHA256, ensuring your password itself is never stored in plaintext.
This encryption is performed using native device cryptography (Apple’s CryptoKit and CommonCrypto frameworks via our custom Capacitor plugin), leveraging the secure hardware capabilities of your device.
Secure Key Storage:Your master encryption key, derived from your password, is stored securely on your device using the iOS Keychain (accessed via the capacitor-secure-storage-plugin). This ensures the key is protected by the operating system’s security features.
Encrypted Key Backup:For cross-device synchronization and account recovery, your master encryption key is itself encrypted using your password (via AES-256 GCM) and then securely backed up to our Supabase backend. It is never stored in plaintext on our servers.
Secure Randomness:Random values (like nonces and salts) crucial for encryption are generated using cryptographically secure random number generators provided by your device’s operating system (SecRandomCopyBytesvia Web Crypto API or native Swift functions).
5. How We Share Your Information
We share your information only as described below:
With Third-Party Service Providers:
Supabase:We use Supabase as our backend service for user authentication and to store your encrypted tasks, encrypted profile pictures, and your encrypted master encryption key backup. Supabase processes this data on our behalf.
Legal Requirements:We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency request).
Protection of Rights:We may disclose your information when we believe it is necessary to protect our rights, property, or safety, or the rights, property, or safety of our users or others.
We do not share your plaintext encrypted content with any third parties other than for storage on our secure backend.
6. Data Retention
We retain your collected information (User ID, Email, encrypted tasks, encrypted profile pictures, encrypted master key backup) for as long as your account is active or as needed to provide you with services. If you delete your account, we will delete your associated data from our systems within a reasonable timeframe, unless retention is required by law.
7. Your Choices and Rights
You have certain rights regarding your personal data:
Access:You can access your data within the App.
Correction/Update:You can update your profile picture and tasks within the App. For other corrections, please contact us.
Deletion:You can delete your account and associated data through the App or by contacting us. Note that deleting your account will result in the permanent loss of access to your encrypted data.
Opt-Out:You can choose not to provide certain information, but this may limit your ability to use certain features of the App (e.g., you cannot use the App without creating an account).
8. Children’s Privacy
Our App is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently received personal information from a child under 13, we will delete such information from our records.
9. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. We encourage you to review this Privacy Policy periodically for any changes.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: