Privacy Policy
Daily Panda ("the app", "we", "us") is developed by Suhas Shelar, an individual developer. This policy explains what data the app collects, why, and what choices you have.
1. Data that stays entirely on your device
Habit titles, completion history, reflections, your display name, and app preferences are stored in a local database on your device. We do not have access to this data, and it is never transmitted to us in the ordinary course of using the app.
2. Cloud Backup (optional, off by default)
If you enable Cloud Backup, the app uploads an encrypted-in-transit snapshot of your habit data
to your own Google Drive, using Google's drive.file permission
scope. This scope only lets the app see files it created itself — it cannot browse, read, or
modify any other file in your Drive. We never receive a copy of this backup; it is stored in
your Google account, under your control, and you can delete it at any time from Google Drive.
3. Analytics (opt-in, off by default)
The app can optionally send anonymous usage analytics via Firebase Analytics (Google) to help us understand how features are used. This is off until you say yes — the app asks for consent, and you can turn it on or off at any time in Settings → Privacy. Where GDPR applies, the legal basis for this processing is your consent (Art. 6(1)(a)) — withdrawing it at any time, with no effect on processing that already happened, is exactly what the Settings switch does.
When enabled, analytics may include:
- Device model, operating system version, app version, and general country/region
- Feature usage events (e.g. a screen was viewed, a button was tapped) — as category/counter data, never as free text
We never send anything you typed — habit titles, notes, reflections, or your display name are never included in analytics events, under any circumstance.
4. Crash reporting (on by default)
The app uses Firebase Crashlytics to automatically report crashes and technical errors, so we can fix bugs. This is on by default under our legitimate interest in keeping the app stable and working (GDPR Art. 6(1)(f)), but you can turn it off at any time in Settings → Privacy. Crash reports may include device information, app version, and technical logs (stack traces) — never your habit content. Because this rests on legitimate interest rather than consent, you also have a standing right to object to it for reasons relating to your particular situation (Art. 21) — in practice, that objection is the Settings switch: turning it off stops the processing immediately.
5. Purchases and subscriptions
Daily Panda Premium is sold as a subscription through the Apple App Store or Google Play. We never see or store your payment card details — that is handled entirely by Apple or Google. We use RevenueCat to confirm your subscription status (i.e. whether you're entitled to premium features) via your store account; RevenueCat does not receive your payment information either.
6. Notifications
Reminder times you set are scheduled as local, on-device notifications. They are not sent through any third-party push notification service, and no reminder content leaves your device.
7. What we don't do
- No advertising, and no advertising SDKs of any kind
- No advertising identifiers (IDFA / Android Advertising ID) are collected
- We do not sell your data, and we do not share it with data brokers
- We do not track you across other apps or websites
8. Who we share data with
| Service | Purpose | What it may see |
|---|---|---|
| Google Firebase (Analytics & Crashlytics) | Opt-in usage analytics; crash reporting | Device/app metadata, anonymized events — never your habit content |
| RevenueCat | Subscription/entitlement verification | Purchase/subscription status from your app store account — not payment details |
| Google Drive | Optional cloud backup, if you turn it on | Your own backup file, in your own Google account |
| Apple App Store / Google Play | Payment processing | Handled entirely by Apple/Google under their own privacy policies |
9. Your choices and rights
In the app, right now, with no need to contact anyone:
- Turn analytics on/off any time in Settings → Privacy
- Turn crash reporting off any time in Settings → Privacy
- Delete your local data by deleting habits in-app, or by uninstalling the app
- Delete a Drive backup directly from your own Google Drive
If the GDPR, UK GDPR, or a similar law applies to you, you additionally have the right to:
- Access (Art. 15) — ask what data we hold about you
- Rectification (Art. 16) — ask us to correct inaccurate data
- Erasure (Art. 17) — ask us to delete data we hold about you
- Restriction (Art. 18) — ask us to limit how we use your data while a dispute is resolved
- Data portability (Art. 20) — receive the data you gave us in a common, machine-readable format
- Object (Art. 21) — object to processing based on our legitimate interest (this covers crash reporting; see §4)
- Withdraw consent (Art. 7(3)) — at any time, for anything based on consent (this covers analytics; see §3), without affecting processing already done
- Lodge a complaint (Art. 77) — with your local data protection supervisory authority, if you believe we've mishandled your data
If the CCPA/CPRA applies to you (California residents), you have a parallel right to know what we've collected and to request its deletion. We don't sell personal information and never have, so there's no "opt out of sale" to exercise. Contact us (§12) for any of the above.
10. Children's privacy
Daily Panda is not directed at children under 13, and we do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. Changes will be posted at this URL with a revised effective date above.
12. Contact
Questions about this policy, or a data access/deletion request, can be sent to privacy@dailypanda.app. For general support questions about the app, use support@dailypanda.app instead.