Privacy policy
This policy describes what the Apteda app and its server collect, why, where it is kept and how to have it deleted. It describes what the code actually sends, not what we would like it to send.
Draft. This text has not yet been accepted and may change before the app is released. Version of 6 October 2026.
Who is responsible
Apteda is developed by (to be named before the app is released). Questions about your data: support@apteda.com.
What you agree to
After the question about your year of birth, the app shows the screen “What leaves your phone”. Nothing on it is selected in advance. You can change your answer at any time in “Profile” → “Consents”, as easily as you gave it.
Sending trials to the server. If you choose “Send and continue”, your game results, the device profile, the reminder history, attempts to play beyond the daily limit and the advertising revenue records described below go to our server, and the server computes an estimate with a confidence interval from them. If you choose “Don’t send”, the games still work and every answer is saved on your phone, but none of this leaves it. Even then the app sends crash reports, which carry no identifiers, your consent records, the request for advertising settings, and what is needed for things you start yourself, such as signing in or redeeming a promo code. If you withdraw consent, the app stops sending; what our server has already received stays there until you ask for it to be deleted.
Health data. Game results can reveal something about the state of your attention and memory, so the law may regard them as health data (Article 9 of the GDPR). That is why the screen says so above the choice, and why sending them needs your explicit consent, given by a separate tap. The research tick box is explicit consent in the same way. We draw no conclusions about your health from the results, but the law looks at what data could reveal, not at what we intend to do with it.
Research (optional). A separate tick box, “Allow research use”, is unticked by default. If you tick it, your game results may be used in scientific research. They are pseudonymous, not anonymous: instead of your name or email they carry random identifiers, but the device profile, the timings and the finger paths still link them into one person’s record. Today no data is used for research and none is passed to anyone; your answer is recorded so that it can be respected when that changes. It does not affect the games or your results.
Consent records. Each consent is kept on our server as a record: what it is for, which version of the screen text you saw, when you gave it and, if you did, when you withdrew it. A withdrawal is added to the record rather than erasing it. Choosing a reminder time counts as consent to reminders and is recorded the same way; switching reminders off withdraws it. Consent records are sent even when sending trials is off, because otherwise a withdrawal would never reach us. Why: to know what you agreed to and to respect it.
What the app sends and why
Apart from Google’s advertising module (see “Other services involved”), the app sends data only to our own server. It works offline and sends what it has collected once you are back online.
Game results. For every answer in a game: the time it took, where and how you touched the screen (including the path of your finger), whether the answer was correct, interruptions such as leaving the app mid-game, the interface language, whether power saving was on and which audio output was in use (speaker, headphones, hearing aid). Why: to adapt the games to you and to compute a measurement estimate with its range. Raw answers are kept as they are, so an estimate can be recalculated later without losing information. For each game we also keep whether it was unlocked by an advertising video and which advertising settings were in effect, so that it can be checked later whether watching a video changes the answers.
Device profile. Manufacturer, model, operating system and its version, screen size and density, refresh rate, the app build and your time zone offset from UTC. Why: reaction times depend on the phone, and results from different phones can only be compared when the phone is known.
Install identifiers. On first launch the app creates random identifiers for you and for this install, and a secret that proves later requests come from the same install. The server keeps only a hash of the secret. These identifiers are not your name, email or phone number.
Year of birth (stays on the phone). The app asks for your year of birth. It is kept only on your phone and is sent neither to our server nor to the advertising module. The advertising module learns only whether family-friendly or teen-appropriate advertising is needed; while your age is unknown, no advertising is shown.
Account (optional). You can play without an account. If you sign in, we keep your email address or, with Google sign-in, the identifier Google gives us for your account. With Google sign-in the app asks Google only to confirm who you are and does not request access to any other Google data. To sign in by email we send a one-time code to your address.
Reminders (only if you turn them on). When a reminder was scheduled, shown and opened. Why: to find out whether reminders help people come back, rather than assume it.
Promo codes. Which code you redeemed and what access it gave.
Crash reports. When the app fails, it sends the error message and technical trace, the app version, the phone model and the operating system version. Crash reports carry no user or install identifier. A daily summary of crashes is emailed to the developer.
Network address. Our server sees the IP address of each connection. It is used, in memory only, to limit the number of requests from one address, and is not written to our database. The web server keeps no access log.
Country for the advertising settings. A two-letter country code, taken from your Google Play account or, if Play does not provide one, from your SIM card. The phone’s language is not used for this. Why: advertising works differently from country to country, and in some countries there is none at all. The server picks the settings by this code and does not store it with that request; the same code is stored with each advertising revenue record (below).
Advertising revenue (only with consent to send trials). When a video you started earns money, Google’s module reports the amount to the app. The app sends us that amount, its currency and how precise it is, which advertising settings and test variant were in effect, the country code and the time. No game names, answers or scores are included. Why: to know what advertising actually earns and to compare advertising settings between countries.
Attempts to play beyond the daily limit (only with consent to send trials). When the day’s free games have run out and you try to start another one, the app records the time of that attempt, your phone’s time zone and the limit that applied. It does not record which game you wanted to start. Why: to see whether the free games per day are enough, and to decide on the limit from data rather than by guesswork.
Summaries for the developer. From the same data, with no separate collection, our server computes totals: how many installs and how many active users per day and per week, how many came back after a day, a week and a month, which games are started and finished, how many games are played per day, how many promo codes were redeemed, which app versions are in use and how many crashes there were. The summaries contain no names, no email addresses and no individual people, only numbers across everyone. The developer sees them on a private page; no third-party analytics service is involved. Why: to understand what works in the app and what does not.
On what legal basis
The EU General Data Protection Regulation (GDPR) requires each purpose to rest on a legal basis. Ours, purpose by purpose:
- Explicit consent (Article 9(2)(a) and Article 6(1)(a)): game results and the estimates computed from them; their use in research, if you ticked that box.
- Consent (Article 6(1)(a)): the device profile, the reminder history, attempts to play beyond the daily limit and the advertising revenue records, which leave the phone only together with game results; the reminders themselves.
- Contract (Article 6(1)(b)): install identifiers, the account and promo codes. Without them the app cannot tell your requests from anyone else’s or give you the access you redeemed.
- Legal obligation (Article 6(1)(c)): consent records, because we must be able to show what you agreed to (Article 7(1)); the fingerprint of an erased install, because without it a deletion would not hold (Article 17).
- Legitimate interest (Article 6(1)(f)): crash reports, the network address held in memory to limit requests, the country code in the request for advertising settings, the developer summaries and the email in which you asked for deletion. Our interest is to keep the app working and protected from overload, to understand what works in it and to be able to show that we carried out your request. You can object to this at any time (see “Your rights”).
You can withdraw consent at any time in “Profile” → “Consents”. Withdrawal does not affect what was done before it.
What we don’t do
- No advertising inside games, before a measurement, or on results and score screens. The only advertising is a video you start yourself with the “one more game” button once the day’s free games are used up.
- Advertising is non-personalised: it is not chosen by your interests. No game names, answers, reaction times or scores are passed to the advertising module.
- No third-party analytics or crash-reporting services in the app.
- We do not sell or rent your data.
Other services involved
- Google, if you choose Google sign-in; and Google Play, when you install the app or tap to update it.
- Google AdMob: Google’s advertising module is built into the app. It starts only once the day’s free games are used up, and then loads a video in advance so that the “one more game” button can appear. Loading and showing a video sends Google the device’s advertising identifier and app set identifier, the IP address, technical details about the phone, the app and the connection, and how you interact with the video; Google then handles them under its own privacy policy. Your choice on the “What leaves your phone” screen does not cover this module.
- Hetzner Online (Germany) hosts our server and database.
- An email delivery service delivers sign-in codes and the daily crash summary.
Where and how long data is kept
The server and database are in Germany. Game results, device profiles, account data, consent records and advertising revenue records are kept for as long as your account or install exists: an estimate is recalculated from the raw answers, and a consent record shows what you agreed to. There is no automatic deletion yet. Crash reports carry no identifiers and are kept to fix errors.
Fingerprint of an erased install. When your data is deleted, the server keeps a fingerprint of each erased identifier: a SHA-256 hash of the random identifier of you and of your install, with no date, account or email. Why: a phone that still has the app may come online after the deletion and try to send what it still holds. The server recognises the install by the fingerprint and refuses it, and the app on that phone then erases its data, so what was deleted does not come back. The fingerprint is kept indefinitely, because such a phone can come online at any time. Only the phone that created the identifier can be recognised by it, and once that phone has erased its data, the identifier no longer exists anywhere.
Deletion request by email. If you ask for deletion by email, your email and the address it came from stay in our mailbox as proof of when you asked and when we carried it out. They are kept for three years, the general limitation period under Czech law (§ 629 of the Civil Code), and then deleted. Deletion from the app leaves no such record: our server log notes only that a deletion took place and how many entries it removed.
The database is backed up every hour. Backups are encrypted before they leave the database, a copy is kept outside the server, and each backup is kept for up to 14 days. Data deleted at your request therefore disappears from backups within 14 days.
Your rights
You can ask for a copy of your data, including in a machine-readable form that you can take elsewhere, for it to be corrected or deleted, for its use to be restricted, and object to its use: write to support@apteda.com. We answer within one month. If you live in the EU, you can also complain to your data protection authority.
Deletion at your request removes from our server the account, the link to your installs, raw game results, device profiles, the estimates computed from them, the reminder history, attempts to play beyond the daily limit, consent records and advertising revenue records. What remains is the fingerprint of the erased install and, if you asked by email, your email (see “Where and how long data is kept”). The totals in the developer summaries contain no individual people and are not recalculated.
How to delete your account and data is described on the Delete account page.
Changes
When this policy changes, the new version appears on this page with a new date.