PRIVACY POLICY
Sharper Daily ("we," "the app") respects your privacy. This policy explains what information we collect, how we use it, and the choices you have.
What we collect
- Account info: your email address and either a hashed password OR a sign-in token from your chosen authentication provider (Google if you use "Continue with Google," Apple if you use "Continue with Apple" — Apple may provide a private-relay email that hides your real address). Stored by our authentication provider, Supabase.
- Your activity in the app: which quotes you liked, which you saved (and when you saved them), any private notes you write on saved quotes, your reading streak and streak freezes, your daily reading goal, your mood check-ins, your category filter, your daily screen-time goal and the accumulated screen time itself, your progress through guided Paths and practices, and your audio preferences (voice gender per language, playback speed, and auto-read on/off). All of this is stored locally on your device, scoped to your account.
- Settings: your chosen language, theme, accent color, card style, text size, story-writing speed, your daily-reminder time and how many reminders per day, and your chosen background sound. Stored locally on your device, scoped to your account.
- Subscription status: if you subscribe to Sharper+, whether your subscription is active. See "Google Play Billing and RevenueCat" below.
- We do not collect your name, phone number, contact list, location, or any other personal information. If we ever add a new category of data collection, we will update this policy first and notify you in-app on your next sign-in.
How we use it
- Your account info lets you sign in across devices.
- Your likes drive the personalization algorithm (categories you like appear more often).
- Mood check-ins tailor which quotes appear next and let you see your own mood history; this stays on your device.
- Notifications are local-only: if you turn on reminders, the app schedules your daily reminders, a streak-save reminder, and a gentle "come back" nudge entirely on your device. We use no push servers and collect no push tokens — these notifications never leave your phone.
- Sharing: when you share a quote, the image (with a link to that quote) is created on your device and handed to your system share sheet. We don't receive or store what you share or who you share it with.
- We do not sell or rent your data. We share specific data with the third parties listed below only as necessary to provide the service. We never share your personal data for marketing or advertising.
- We do not run advertising. We use one privacy-respecting analytics service (Aptabase) to understand how the app is used; it records only anonymous, aggregated usage events (such as "opened the app" or "completed onboarding") tied to a random identifier — never your name, email, or the quotes you read — and never tracks you across other apps.
Cookies and tracking technologies
Sharper Daily is a native mobile app and does not use HTTP cookies, browser local storage, web beacons, device fingerprinting, or any other web-based tracking technologies. We do not track you across other apps, websites, or services, and we use no advertising or attribution SDKs.
Third parties
- Supabase (supabase.com): handles sign-up, sign-in, password reset, account deletion, and stores your email + hashed password. Privacy policy
- Resend (resend.com): delivers our transactional emails — verification codes for sign-up and password reset. Receives your email address only when we send these emails. We do not use Resend for marketing. Privacy
- Cloudflare (cloudflare.com): hosts this website and the DNS for our email domain (sharperdaily.app). Receives standard web-server and DNS lookup metadata only. Privacy
- Google Cloud Text-to-Speech: when you tap the speaker icon to hear a quote read aloud, the quote text is sent to Google's TTS service to generate audio (audio is then cached so the same quote is not re-synthesized). The text consists of public-domain quotes from real historical authors — no personal information is sent. Privacy
- HaveIBeenPwned (haveibeenpwned.com): when you create or change a password, your password is SHA-1 hashed locally on your device and only the first 5 characters of the hash are sent to check whether the password has appeared in known data breaches. Your full password and full hash never leave the device. Privacy
- Google: only contacted if you tap "Continue with Google" during sign-in. Google's privacy policy
- Apple: only contacted if you tap "Continue with Apple" during sign-in. Apple's privacy policy
- Google Play Billing and RevenueCat (revenuecat.com): if you subscribe to Sharper+, the purchase itself is handled by Google Play (or the App Store), which processes your payment details — we never see your card. RevenueCat receives the purchase receipt, an anonymous app-user identifier tied to your account, and your device platform, so the app can check whether your subscription is active and restore it on a new phone. Privacy
Your rights
- You can log out at any time from Settings → Account → Log Out.
- You can reset your likes from Settings → Wander → Reset Likes.
- You can delete individual saved quotes from Your Book.
- To permanently delete your account and all associated data, go to Settings → Delete Account at the bottom of the Settings page. Your authentication record and any server-side data are removed immediately. Backup copies are purged within 30 days.
- Under GDPR (EU/EEA), CCPA (California), and similar laws, you have rights of access, rectification, erasure, and portability. You can export your data from Settings → Download my data. For requests we can't fulfill through in-app controls, email [email protected].
- If you are in the EU/EEA and believe we have not handled your data properly, you have the right to lodge a complaint with your national data protection authority. The full list is at edpb.europa.eu.
For California residents
The California Consumer Privacy Act (CCPA) gives California residents specific rights regarding their personal information:
- Right to know: the categories of personal information we collect are described in the "What we collect" section above.
- Right to delete: you can delete your account and associated data in-app at Settings → Delete Account, or email [email protected].
- Right to opt out of the sale or sharing of personal information: we do not sell personal information as that term is defined under the CCPA, and we have not done so in the past 12 months. We also do not share personal information for cross-context behavioral advertising. There is therefore nothing to opt out of.
- Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA rights.
International data transfers
Some of the third parties we use may process your data outside your country of residence:
- Supabase processes data on servers that may be located outside the European Economic Area (EEA).
- Resend's email-sending infrastructure for our domain is hosted in Ireland (within the EEA).
- Google Cloud Text-to-Speech, RevenueCat and HaveIBeenPwned may process requests in regions outside the EEA.
Where data leaves the EEA, transfers are protected by the Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards as required by GDPR Article 46.
Data security
We take reasonable technical measures to protect your data:
- All communication between the app and our servers uses HTTPS encryption.
- Passwords are hashed using bcrypt by Supabase. Your plain-text password is never stored or seen by us.
- When you create or change a password, it's checked against the HaveIBeenPwned breach database using k-anonymity: only the first 5 characters of your password's SHA-1 hash leave your device.
- Your sign-in session is stored encrypted on your device, with the encryption key held in the device's secure hardware keystore.
- Each user's local data is scoped to their account so multiple users on the same device cannot see each other's saved quotes, likes, or preferences.
- You can permanently delete your account and associated data at any time from Settings → Delete Account.
No system is perfectly secure. If we ever discover a data breach that affects your personal information, we will notify you and the relevant regulators within the timeframes required by applicable law (within 72 hours under GDPR).
Data retention
- While your account is active, we retain your data for as long as needed to provide the service.
- If you delete your account (Settings → Delete Account), your authentication record and server-side data are removed immediately. Backup copies are purged within 30 days.
- We reserve the right to delete accounts that have been inactive (no sign-in) for an extended period (typically 3 years), together with associated data. Where practical, we will email you at the account address at least 30 days before deletion.
Children
Sharper Daily is intended for users 13 years and older. We do not knowingly collect personal data from children under 13.
For users in the European Union / European Economic Area: the minimum age for digital consent under GDPR varies between 13 and 16 depending on your country. If you are under the minimum age in your country, please obtain consent from a parent or legal guardian before using the app.
If you believe a child below the applicable minimum age has provided us with personal data, please contact us at [email protected] and we will delete the account and associated data promptly.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our service, or applicable law.
- For material changes (new categories of data collected, new third parties, or changes affecting your rights), we will make reasonable efforts to notify you in-app on your next sign-in.
- Minor edits (typo fixes or clarifications that do not change meaning) may be made without notice.
- In all cases we update the "Last updated" date at the top. We encourage you to review this policy periodically.
Contact
Questions or requests: [email protected]