Legal
Privacy policy - Hybbit
For the website arnoldschreiner.de, the site privacy policy applies. The following section applies to the Hybbit iOS app.
Last updated: August 20, 2026
Quick Overview
- No account, no cloud sync – your habits, notes, history and settings stay on your device.
- The only data that leaves your device is your subscription status – processed by RevenueCat on our behalf (section 5.1).
- Features: habits, reminders (local), statistics, categories, journal, widget, export/import (JSON), Pro subscription via the App Store.
- Notifications: local notifications only (iOS consent), no remote pushes.
- No tracking, no IDFA, no advertising, no usage analytics.
- No third-party crash reporting – crash diagnostics stay on the device and are only transmitted if you share them yourself.
(Apple requires App Privacy declarations; possibly Privacy Manifest/Required Reason APIs in the app. These developer obligations concern publication, not your rights.)
1. Data Controller
Arnold Schreiner
Wümmering 28
21629 Neu Wulmstorf
Germany
Phone: +49 40 60682201
Email: hello@arnoldschreiner.de
Contact form: https://arnoldschreiner.de/contact
No data protection officer is appointed as it is not legally required.
Legal basis of the information obligations: Art. 13 GDPR. For your right to lodge a complaint with a supervisory authority, see section 14.
2. Scope
This declaration applies to the iOS app "Hybbit" (App Store ID: 6749539405) including its widget extension. The website has its own privacy policy at: https://arnoldschreiner.de/datenschutz.
3. Processing in Detail
3.1 App Operation (without account)
Purpose: providing the app's functions locally.
Data types: habits (title, description, category), goals and frequencies, reminder schedules, history and completions, streaks, journal entries, sorting and display settings, language and appearance.
Storage location: on your device, in the shared app container of the app and its widget (SwiftData database, UserDefaults, files). The widget reads the same data – nothing is transmitted externally.
Recipients: none.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.2 Local Notifications
Purpose: reminding you of your habits.
Data types: schedules, title and body of local notifications, app badge.
Recipients: no external recipients – delivery is handled locally by iOS.
Legal basis: Art. 6(1)(a) GDPR (consent via the iOS prompt; revocable at any time in iOS Settings).
3.3 In-App Purchases and Subscription Management
Purpose: processing the purchase and verifying whether a Pro subscription is active.
Data types: product identifiers, transaction status, receipts and entitlements (system-side), purchase and expiry dates, App Store account country, and a randomly generated identifier assigned by RevenueCat.
Recipients and role: Apple as independent controller (payment processing) and RevenueCat, Inc. as processor (subscription status verification, restoring purchases across devices). Details in section 5.1.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.4 On-Device Usage Values (Review Timing)
Purpose: choosing an appropriate moment to ask for an App Store review.
Data types: purely local counters (app launches, completed habits, streaks, successful days).
Recipients: none.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a non-intrusive prompt; the values never leave the device).
3.5 Data Export and Import
Purpose: portability and backup at your request.
Data types: JSON file containing habits, categories, reminders, history, journal and settings.
Recipients: controlled solely by you via the iOS share sheet; there is no automatic upload.
Legal basis: Art. 6(1)(b) GDPR.
4. Device Access (TDDDG § 25)
We only use the local storage and identifiers required for core functions; no tracking, no IDFA, no fingerprinting. Non-essential access would require consent – no such access takes place. (Since May 14, 2024, the TDDDG with § 25 applies in Germany; in 2025 the Consent Services Regulation also came into force.)
5. Recipients and Service Providers (SDKs)
5.1 RevenueCat (Subscription Management)
We use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA to manage Pro subscriptions. The service verifies whether a subscription is active and ensures that a purchase remains available across your devices and after reinstalling the app.
- Data processed: purchase and transaction data received from the App Store (product identifier, purchase date, expiry and renewal dates, subscription status, App Store country) and a random identifier generated by the RevenueCat SDK (prefix
$RCAnonymousID:). - Explicitly not transmitted: your habits, notes, progress history, journal entries and settings. These never leave your device. We also transmit no name, email address, phone number or location data.
- No account, no personal identifier: the identifier RevenueCat assigns is not linked to your name, email address or Apple ID.
- Legal basis: Art. 6(1)(b) GDPR – processing is necessary to perform the subscription contract.
- Processor: RevenueCat acts as a processor on our behalf under Art. 28 GDPR, governed by their Data Processing Addendum (https://www.revenuecat.com/dpa).
- Third-country transfer: processing also takes place in the United States; for the transfer mechanism see section 7.
- RevenueCat privacy policy: https://www.revenuecat.com/privacy
5.2 Apple (StoreKit, UserNotifications) – Independent Controller
Payment processing, receipts and the delivery of local notifications are handled system-side by Apple. Apple may provide crash reports in App Store Connect if you have consented to sharing with developers at the system level; that decision is one you make towards Apple, not towards us.
Apart from RevenueCat, no third-party SDKs that transmit data to external service providers are integrated. There is no analytics, no advertising and no tracking.
6. No Tracking and No Usage Analytics
Hybbit demonstrably does not use:
- analytics or statistics services (such as Google Analytics, Firebase Analytics, Mixpanel)
- third-party crash reporting services (such as Crashlytics, Sentry, Bugsnag)
- advertising networks or advertising identifiers (IDFA)
- social media plug-ins or pixels
- fingerprinting or cross-device recognition
- third-party push notification services
The app explicitly declares in its Apple Privacy Manifest file (PrivacyInfo.xcprivacy): NSPrivacyTracking = false.
Distinction from crash diagnostics: iOS produces technical diagnostics for crashes and hangs via the MetricKit framework. These stay on your device. They are only transmitted if you export them yourself via "Share diagnostics" – and you decide where they go. No automatic transmission to us takes place.
7. Transfer to Third Countries
A transfer takes place solely in the context of subscription management: data processed by RevenueCat, Inc. on our behalf is also processed in the United States.
The basis is the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), which RevenueCat incorporates in its Data Processing Addendum under Module Two (controller to processor). All other processing described in this policy takes place exclusively on your device.
8. Retention Periods and Deletion
| Data | Storage location | Retention period |
|---|---|---|
| Habits, goals, history, journal, categories | Your device (shared app container) | Until deletion in the app ("Delete all data") or uninstallation |
| Reminder schedules | Your device (iOS notification system) | Until the reminder is disabled or the app is uninstalled |
| Widget data (mirror of today's values) | Your device (shared app container) | Overwritten on every app launch; removed on uninstallation |
| Review timing counters | Your device | Until uninstallation |
| Export files (JSON) | Your device (temporary directory), then wherever you share them | Controlled by you |
| Subscription status and purchase history | RevenueCat servers (USA) | Per RevenueCat Privacy Policy |
| Receipts and transactions | Apple | Per Apple's Privacy Policy |
9. Obligation to Provide
There is no legal obligation to provide data. Without certain local data (for example the definition of a habit), individual functions cannot be used. Consent – for example to notifications – is voluntary.
10. Your Rights (GDPR)
Under the GDPR you have the following rights:
- Right of access (Art. 15 GDPR): you may request information about the personal data we process.
- Right to rectification (Art. 16 GDPR): you may request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): you may request the deletion of your data. Locally stored content can be removed by you at any time via "Delete all data" or by uninstalling the app.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR): the app's export function hands you your data as JSON in a structured, commonly used and machine-readable format at any time.
- Right to object (Art. 21 GDPR): you may object to processing based on Art. 6(1)(f) GDPR. We will then stop the processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent – for example for notifications – you may withdraw it at any time with effect for the future.
To exercise your rights, contact hello@arnoldschreiner.de. We respond within one month (Art. 12(3) GDPR).
11. Rights for Users in the United Kingdom (UK GDPR)
Users in the United Kingdom have comparable rights under the UK GDPR (Data Protection Act 2018 in conjunction with the UK General Data Protection Regulation). The competent supervisory authority is the Information Commissioner's Office (ICO): https://ico.org.uk.
12. Rights for Users in California (CCPA/CPRA)
Although Hybbit, as a solo developer app, is unlikely to meet the thresholds of the California Consumer Privacy Act, we provide the following information in the interest of transparency:
- No sale or sharing of data: we do not sell or share personal information of California users within the meaning of the CCPA/CPRA.
- No targeted advertising: we do not use data for behavioral advertising.
- Categories of data collected: purchase history only (product identifier, purchase date, subscription status) and a random identifier assigned by RevenueCat. We do not collect names, email addresses, location data or other directly personal data.
- Right to know and delete: California users may request information about the data processed or request its deletion at hello@arnoldschreiner.de.
13. Notice for Users in Other Jurisdictions
Hybbit is available worldwide in the Apple App Store. We respect the privacy rights of all users regardless of where they live. Should more extensive rights apply in your country, we will endeavour to meet your requests within the framework of applicable law. Write to us at hello@arnoldschreiner.de.
14. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover, Germany
Website: https://www.lfd.niedersachsen.de
Alternatively, you may contact the supervisory authority of your country of residence (Art. 77 GDPR).
15. Data Security
We apply appropriate technical and organizational measures in accordance with Art. 32 GDPR:
- Encrypted transmission via HTTPS/TLS for the subscription check – the only network connection the app itself establishes
- Storage exclusively in your device's app container, protected by iOS device encryption
- No cloud synchronization, no user account and no password – there is no login that could be taken over
- No server of our own and no database of user data
- Data integrity: if a database migration fails after an update, the existing data is not deleted but set aside untouched. Likewise, a backup is written to the app container before any legacy data from a previous version is removed.
- Regular updates and security patches
- Incident management including the 72-hour notification obligation under Art. 33 GDPR
16. Children's Privacy
Hybbit is not specifically directed at children under 16. We do not knowingly collect personal data from children under 16 (or under 13 in the United States under COPPA). Should we become aware that a child's data has been collected, we will delete it promptly.
17. Automated Decisions and Profiling
No automated decisions with legal effect take place. Review timing is based on purely local counters without any personal reference.
18. Changes to This Privacy Policy
We update this policy when functions, the legal situation or the services we use change. The current version is always available:
- In the app: Settings → Privacy Policy
- Online: https://arnoldschreiner.de/hybbit/privacy
We announce material changes inside the app. The date of the last update is shown at the top of this document.
19. Contact
For privacy questions you can reach us at:
Arnold Schreiner
Wümmering 28, 21629 Neu Wulmstorf, Germany
Phone: +49 40 60682201
Email: hello@arnoldschreiner.de
Contact form: https://arnoldschreiner.de/contact