← Back to apps
Privacy Policy
Last updated: August 10, 2026
This privacy policy covers all iOS applications published under the developer name Tabish Hassan on the Apple App Store. It applies collectively to every app in the portfolio unless a specific app ships its own supplemental policy inside the app.
Two kinds of apps. Most of our apps are offline-first and keep the content
you create on your device. A few apps are cloud-connected and require an account to work —
for example Project Hub, a 1:1 chat with the developer. Cloud-connected apps are covered in
the “Cloud-Connected Apps” section below, which governs them where it differs from the general terms.
Summary
- For offline-first apps, the content you create (notes, habits, moods, budgets, logs, etc.) is stored locally on your device using Apple's SwiftData framework, and no account is required.
- Cloud-connected apps (e.g. Project Hub) require sign-in and store your account and messages on Google Firebase servers — see the dedicated section below.
- Some offline-first apps use a small number of network services for crash reporting and an optional invite/referral feature. These never receive the content you create in the app. See “Services Used by Offline-First Apps”.
- We do not sell your personal content, and we do not track you across other apps or websites.
- Some offline-first apps display third-party ads (InMobi) in the free tier. Premium subscribers see no ads. Cloud-connected apps like Project Hub contain no ads.
Data We Access (Offline-First Apps)
Depending on the specific app and the features you use, the following data may be accessed locally on your device:
- Content you create in the app (notes, habits, moods, flashcards, budgets, books, etc.)
- App preferences (theme, language, notification schedule)
- Health data (only for apps that explicitly request HealthKit permission — you control this in iOS Settings)
- Photos and camera (only for apps that request picker permission on demand)
- Purchase receipts (processed by Apple StoreKit)
The content you create is never uploaded to us. It stays on your device (and in your own
iCloud backup, if you have that enabled) and is not transmitted to any server we operate. The limited
network services described in the next section receive only diagnostic and account-free identifiers —
never your notes, entries, photos, health data, or other app content.
Services Used by Offline-First Apps
Even though your content stays on your device, some offline-first apps use these services:
- Firebase Crashlytics (Google) — collects anonymous crash reports and diagnostic data
(device model, iOS version, stack traces, and the sequence of events leading to a crash) so we can fix
bugs. Crash data is not linked to your identity, is not used for advertising, and never contains the
content you create in the app.
- Invite / referral feature (Firebase) — only in apps that offer it, and only if you use it.
When you open the invite screen, the app creates an anonymous Firebase account. This is not a
login: it has no name, no email, and no password, and it exists solely to attach an invite code to a device.
We store the invite code, how many invites have been redeemed, and whether a reward has been granted.
No personal information and no app content is stored.
- InMobi — advertising in ad-supported apps. See “Advertising” below.
- Open Library API — ReadingLog sends book search queries to openlibrary.org over HTTPS. No personal identifiers are transmitted.
Cloud-Connected Apps (e.g. Project Hub)
Some apps need an account and a server to work. Project Hub is a one-to-one consultation
chat that connects you directly with the developer. These apps use Google Firebase and
collect and store the following on Firebase servers:
- Account information — your name and email address when you sign up with Email, Google, or Sign in with Apple. If you continue as a Guest, you may optionally provide a name and contact email so we can reply.
- Messages & content — the text (and, where supported, images, documents, and voice messages) you send in your conversation.
- Identifiers — a unique account identifier (Firebase user ID) and, if you enable notifications, a device push token used to deliver message alerts.
- Project details you choose to share — e.g. a project category, budget, timeline, or company name.
This data is used solely to operate the service: to create and secure your account, deliver your
messages to the developer (and replies back to you) in real time, and send you reply notifications if
you enable them. These apps contain no advertising, do no behavioral
tracking, and do not collect the advertising identifier (IDFA), location, or health data.
You can permanently delete your account, profile, and entire conversation at any time
from Settings → Delete Account inside the app. Conversations include safety tools: you can report
content, and the developer can block users and remove content that violates the app's Terms of Use.
Third-Party Services
- InMobi — in apps that display ads, the InMobi SDK may access the Advertising
Identifier (IDFA), coarse device and connection information, and ad-interaction events in order to serve
and measure advertising. On iOS, the IDFA is only accessed if you grant permission through Apple's
App Tracking Transparency prompt; if you decline, ads are still shown but are non-personalised. You can
change this at any time in iOS Settings → Privacy & Security → Tracking. See
InMobi's privacy policy.
- Google Firebase (Crashlytics, Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging) —
used for crash reporting and the optional invite feature in offline-first apps, and to store your account,
messages, and attachments in cloud-connected apps such as Project Hub. Firebase processes this data on
Google's servers on our behalf. See Firebase's privacy information
and Google's Privacy Policy.
- Sign in with Apple & Google Sign-In — used only to authenticate you in cloud-connected apps. If you use Apple's “Hide My Email,” we receive a private relay address.
- Apple StoreKit — processes in-app purchases and subscriptions. Governed by Apple's privacy policy.
- Apple iCloud — if you enable iCloud sync, your data syncs via your Apple ID. Managed by Apple; we have no access.
- Apple HealthKit — for apps that use it, reads the specific data types you authorize. We never write, upload, or share HealthKit data.
- Open Library API — ReadingLog sends book search queries to openlibrary.org over HTTPS. No personal identifiers are transmitted.
Advertising (Ad-Supported Apps Only)
Apps marked "Free with In-App Purchases" may show banner, interstitial, and rewarded advertisements from
InMobi. Purchasing the premium subscription removes all ads immediately. Ads are never shown in:
- Any app listed in the Apple App Store Kids category.
- Any app targeted at children under 13.
- Any cloud-connected app such as Project Hub (these contain no ads).
In apps that handle sensitive personal records, ads are additionally kept out of the screens where you
create, review, or export that content — they appear only in peripheral areas of the app.
Where required by law (for example in the EU/UK), a consent dialog is presented before any advertising
SDK is initialised, and your choice is respected on every subsequent launch.
Children's Privacy
We do not knowingly collect personal information from children under 13, and we comply with the Children's
Online Privacy Protection Act (COPPA).
Most of our family apps are tools for parents — baby and feeding logs, vaccination records,
allowance trackers, chore charts and screen-time journals are used by the adult, not the child. These are not
directed at children.
For the small number of apps a child uses directly, advertising runs in
age-restricted mode: ads are contextual and non-personalised, the advertising identifier (IDFA)
is not used, and there is no behavioral tracking, profiling, or sharing of data with advertisers for that
audience. Premium removes ads entirely.
In every case, the content created in the app — a child's name, routine, word list, progress or records —
stays on the device and is never uploaded to us or shared with any advertiser. Where a children's app offers a
feature that needs a network connection, that connection is limited to what the feature itself requires. We do
not ask children for personal details in order to use an app, and cloud-connected apps such as Project Hub are
not directed to children under 13.
Data Retention & Deletion
For offline-first apps, the content you create is stored locally on your device — you can delete everything
at any time by deleting the app or clearing data from the in-app Settings screen. Crash reports are retained by
Firebase Crashlytics for a limited period under Google's retention policy. If you used an app's invite feature,
you can delete the associated anonymous record from Settings → Delete Account in that app.
For cloud-connected apps (e.g. Project Hub), we retain your account and messages while your account exists. You can permanently delete your account and all associated data at any time from Settings → Delete Account in the app, which removes it from our Firebase database and authentication system.
Your Rights (GDPR, CCPA)
If you are located in the EU, UK, or California you have rights including access, rectification, erasure, and objection regarding personal data. For offline-first apps you exercise these directly on your device. For cloud-connected apps you can delete your data in-app, or contact us for any other request at the email below.
Changes to This Policy
If we update this policy, the revised version will be posted at this URL with an updated "Last updated" date. Material changes will be communicated through an in-app notice where feasible.
Contact
Questions about this policy? Reach out to tabishhassan01998@gmail.com.
© 2026 Tabish Hassan. All rights reserved.