Legal
Privacy Policy
Everyday A Painting helps you discover one painting each day, save your progress, receive optional reminders, and manage your account. This policy explains what data the app processes and why.
Data We Process
- Account data, including email/password authentication; the name and email address supplied through Sign in with Apple or Google sign-in; and a Google profile image if Google supplies one.
- Product-interaction data linked to your account, including saved paintings, daily views and claims, streak state, local-reminder preferences.
- Daily-calendar and local-reminder settings, including the current time zone used to unlock paintings at local midnight, whether reminders are enabled, and the chosen reminder time. Changing time zones never removes paintings that have already become available. Reminders are scheduled on your device; the app does not store a push token or use remote push delivery.
- Purchase data, including RevenueCat subscription entitlement status, product status, restore state, and related store transaction signals.
- Support data, including the email address and message content you send to our support address.
- Other Diagnostic Data linked to your account, including content or image error categories, the affected painting and app surface, a hashed remote-image URL, and diagnostic details needed to keep the service reliable.
- Optional app-analytics data. Only after you turn on Share usage data, the app sends PostHog the screens and feature actions listed below, a randomized PostHog device ID, and app/device metadata such as app version, operating system, device model, locale, and time zone.
- Anonymous app diagnostics. Share anonymous diagnostics is on by default and can be disabled in Profile, Legal. It sends only categorized sync dead letters, hydration retry transitions, and account-session race transitions through a closed allowlist. It does not send your account ID, raw error text, artwork or Story text, or a screen recording.
- EAS Update checks send Expo the device operating system, the Expo project ID, and a randomized app-install token. Expo uses this unlinked identifier only to deliver and measure app updates; it is not used for tracking.
For Apple's App Privacy label, Name, Email Address, Photos or Videos, and Other Diagnostic Data are linked to your account and used for App Functionality. User ID, Purchase History, and Product Interaction are linked and used for App Functionality and Analytics. Device ID is unlinked and used for App Functionality and Analytics. No category is used for tracking.
Device ID covers the randomized EAS Update app-install token and the randomized PostHog identifier. Neither is associated with your app account. PostHog receives a fresh random identifier when the signed-in account or product-analytics consent changes.
How We Use Data
- To create and secure your account through Supabase.
- To keep your saved paintings, daily view and claim history, streak, reminder preferences.
- To schedule local reminders on your device only when you choose to enable them.
- To provide subscriptions, restore purchases, and sync entitlement status through RevenueCat.
- To answer support requests and investigate operational issues.
- To comply with legal, fraud-prevention, platform, and store-review obligations.
Service Providers
Everyday A Painting uses Supabase for authentication, database, storage, and Edge Functions; RevenueCat for in-app purchase and subscription entitlement handling; Expo Notifications only to schedule local reminders on your device; Apple and Google for provider sign-in when you choose those flows; and Cloudflare Pages to host this website.
Expo also processes the limited, unlinked EAS Update request data described above as a service provider so the app can receive software updates.
PostHog processes enabled anonymous diagnostics and optional product analytics in its European Union cloud region. The app never sends PostHog your Supabase user ID, email address, or RevenueCat identifier. RevenueCat remains separate and does not send subscription lifecycle events to PostHog. These providers act on our instructions and are not used for advertising.
Website Analytics
This website uses Cloudflare Web Analytics to understand aggregate page views, referrers, browser information, and page-performance measurements. Cloudflare Web Analytics does not use cookies, local storage, or fingerprinting, and we do not use it to collect personal data or for advertising. We use this aggregate data to improve the website.
App Diagnostics And Optional Analytics
Anonymous diagnostics is on by default and limited to the three reliability event families described above. Product analytics is off by default. If you enable Share usage data, we also collect screen views and product actions such as onboarding steps, paywall and checkout outcomes, daily reveals, Story starts and completions, collections, share-sheet outcomes, and review-request opportunities. We do not send account details, support messages, artwork or Story text, raw error messages, advertising identifiers, precise location, touch autocapture, or screen recordings. PostHog retains these events for up to 12 months. You can disable either setting independently; disabling product analytics rotates the random identifier before anonymous diagnostics continue.
Advertising And Tracking
The app does not sell personal data, track you across other companies’ apps or websites, or include third-party advertising SDKs. If that changes, this policy and the App Store privacy disclosures will be updated before release.
Retention And Deletion
Account, app-activity, and entitlement data are kept while your account is active. Linked diagnostic data is deleted after 90 days. You can delete your account in the app from Profile, Account, Delete account. The server marks the account for deletion, scrubs app-owned user data, revokes sessions where possible, and schedules hard deletion after 30 days. If you cannot access the app, contact support.
Your Choices
- You can choose whether to use Apple, Google, or email/password sign-in where available.
- You can disable local reminders in the app.
- You can independently disable anonymous diagnostics or enable and disable product analytics at any time in Profile, Legal.
- You can restore or manage purchases through the store and in-app subscription controls.
- You can request help, correction, or deletion by emailing our support address.
Children
Everyday A Painting is not directed to children under 13. If you believe a child has provided personal data, contact support so we can review and delete it where appropriate.
Changes
We may update this Privacy Policy as the app, store requirements, or service providers change. The current version is always available on this page.