Privacy Policy

Last updated: May 22, 2026

1. Introduction

Welcome to HEUREKA ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our mobile application and website.

2. Information We Collect

We may collect the following types of information:

Account Information: Email address and authentication data when you create an account using Google Sign-In, Sign in with Apple, or email.

Usage Data: Anonymous usage events, screen views, and aggregated interaction data (collected via PostHog) to help us understand how the app is used.

Diagnostic Data: Crash reports and technical diagnostics including device model, OS version, and stack traces (collected via Sentry) when the app crashes.

Device Information: Device type, operating system, and app version for troubleshooting and improving our services.

3. How We Use Your Information

We use your information to:

• Provide and maintain our service

• Personalize your experience with quotes and recommendations

• Process transactions and manage subscriptions

• Send important updates about the service

• Improve and optimize our application

4. Data Storage and Security

Your data is stored securely using industry-standard encryption and security practices. We use Supabase for authentication and data storage, which employs robust security measures including encrypted data transmission and secure data centers.

5. Third-Party Services

We use the following processors to operate the app:

Supabase (authentication and database storage) — stores your email and profile data.

Apple App Store and Google Play, via RevenueCat — processes your subscription and one-time purchases. We do not store your payment card details; these are handled by Apple or Google.

PostHog — product analytics. Collects anonymous usage events, screen views, and aggregated interaction data to help us improve the app.

Sentry — crash reporting. Collects technical diagnostic data when the app crashes (device model, OS version, stack trace). Does not include identifying user data.

Google Sign In and Sign in with Apple — authentication providers, used only when you choose to sign in with one of these.

Each of these providers is independently responsible for the data they collect under their own privacy policies, but we have selected providers that we believe offer privacy protections equivalent to those described here.

6. International Data Transfers

Some of our processors (including Supabase, PostHog, and Sentry) may store or process data in the United States or other jurisdictions outside your country of residence. If you are located in the European Economic Area or the United Kingdom, you have rights under the GDPR and UK GDPR, including the right to access, correct, delete, or restrict processing of your personal data. Contact us using the details below to exercise these rights.

7. Data Retention

We retain your personal data only for as long as necessary to provide our services and fulfill the purposes outlined in this policy. When you delete your account, we will delete or anonymize your personal data within 30 days, unless we are required to retain it for legal purposes.

8. Your Rights

You have the right to:

• Access the personal data we hold about you

• Request correction of inaccurate data

• Request deletion of your data

• Object to processing of your data

• Request data portability

9. Account Deletion

You can request deletion of your account and all associated data at any time by visiting our account deletion page. Upon deletion, all your personal data will be permanently removed from our systems within 30 days.

10. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us at: privacy@heureka.dev