← MundaneApps

Privacy Policy

Version 20260819-151337 · Effective 19 August 2026, 15:13 UTC

The plain-English version: we try to be a good houseguest. Without an account, your cadences, notes, tags, profile, and settings stay on your device unless you deliberately export or share them. HeadsUp uses RevenueCat to verify purchases without requiring an account. Analytics and crash reporting are off by default; you opt in, and can opt out anytime. We never sell your data, and you can leave with it whenever you want. The legal detail is below.

This policy describes how MundaneApps ("we", "us") handles your data. It covers both the HeadsUp app ("the app") and the mundaneapps.com website, including the optional email lists you can join there (section 7). It is written to be truthful and specific about what we actually do. Client-side claims are reviewed against the app's source code before release; hosting, processor, email, and deletion claims are also checked against the relevant production systems.

1. The short version

2. Data collected, by mode

No-account mode

HeadsUp stores user content and operational state on your device. This includes cadences, notes, custom tags, profile fields, preferences and customization, consent and onboarding state, subscription-entitlement cache, device/sync state, queued deletion identifiers, backup status, and tour progress. If you sign in, your login tokens are also stored on the device, in the operating system's secure keystore (iOS Keychain, Android encrypted preferences) rather than with ordinary app data. If you use reminders, the operating system's local notification scheduler stores one daily reminder for each of the next thirty days on the same device. Each one contains only a count of how many cadences need your attention that day — no cadence titles, and no identifiers that point back to a cadence. Nothing in this content is uploaded by HeadsUp unless you sign in to an eligible cloud plan or deliberately export, share, email, or send it to an external service.

Two more kinds of local storage are worth naming explicitly, because they are easy to overlook:

HeadsUp supports purchases without requiring an account. To determine whether Pro or Pro+ features are available, the app uses RevenueCat, which may process a randomly generated purchaser identifier, device and operating-system information, and purchase or subscription information. If you separately opt in to analytics and crash reporting, the information described in section 3 is also sent without requiring you to sign in.

During onboarding, the optional "region" field may be pre-filled from the region code in your device's locale. HeadsUp does not inspect SIM or carrier information. The field is editable free-form text, no location permission is requested, and the value only leaves your device if you sign in and save it as part of your profile.

Signed-in mode (optional)

Signing in is optional. It currently uses Google; Sign in with Apple is not offered. When you sign in, we additionally process:

DataPurpose
Account email address from your sign-in providerAccount identification; transactional email (see section 6)
Sign-in tokens and provider account details. Google returns an identity token, which we hand to Supabase; Supabase then holds the resulting session and the account details Google supplies with it, including your Google display name. The app reads that name to pre-fill your profile.Keeping you signed in, and refreshing your session
Optional profile: name, gender, occupation, free-form region, and an editable profile/contact email that may differ from the account emailSaved to your account profile and shown back to you in the app
Cadence data. This is more than a list of titles. Each uploaded cadence carries its title, type, category, tags and notes, its schedule and recurrence rules, its due and end dates, how much advance warning you asked for, its priority, whether it is pinned, paused or stopped, when it was created and last changed, and its full history: every completion, every skip, and every pause, resume, stop and reactivation, each with a timestamp.Not uploaded on Free; single-device cloud backup on Pro; automatic cross-device sync on Pro+
Purchase and subscription state: your plan tier, whether it is active, the store and product involved, renewal or expiry dates, when a plan lapsed, and the identifier RevenueCat uses for youDetermining your plan tier (Free / Pro / Pro+) and the 30-day window after a plan lapses
A per-install device identifier and a label derived from the device model, plus a record of each time your backup moves to a different deviceEnforcing the Pro plan's single-device backup slot, and detecting when you've switched devices
A record of each time your account is restored or your backup is pulled to a deviceAn activity log we can look at if you report that something went wrong. Nothing is enforced or limited using it.
Which version of this policy you accepted, and whenKeeping a record of what you agreed to

We do not collect your birth date, phone number, or precise location. We do not collect age or any data intended to identify whether you are a minor. See section 9.

3. Analytics & crash reporting (optional, consent-based)

With your explicit opt-in consent, HeadsUp uses two services to understand how the app is used and to fix crashes:

Both are disabled by default. We ask once, during onboarding, and you can change your choice at any time in Settings → Privacy → "Share usage & crash data." When off, nothing is sent. On an installation that has never opted in, neither library is started at all. If you opt in and later opt out, collection stops immediately and the crash reporter is shut down; the analytics library stays loaded but silenced until you next restart the app.

Sentry is configured for crash and error reports only. Its performance monitoring — which samples timings from sessions where nothing has gone wrong — is switched off.

We configure these services not to intentionally receive your name, email address, precise location, or cadence contents. When signed out, analytics may use a randomly generated installation identifier. When signed in, analytics and crash reports are associated with your Supabase account UUID. This UUID is pseudonymous—not anonymous—because we can connect it to your account, although it is not your email address. We do not use these tools for advertising or cross-app tracking, and we do not build an advertising profile of you.

4. Where your data is hosted

Account, cadence, and profile data stored through Supabase is hosted in the European Union (Frankfurt region). Analytics and crash information is sent to the EU services described in section 3. Transactional email is sent through Resend from its European Union region (Ireland). RevenueCat processes purchaser, technical, and transaction information using infrastructure in the United States to validate purchases and determine subscription access.

Sending personal data outside the EU needs a legal safeguard, not just a disclosure. For RevenueCat we rely on the European Commission's Standard Contractual Clauses, in their UK and Swiss forms where those apply. These form part of RevenueCat's Data Processing Addendum, which RevenueCat publishes at revenuecat.com/dpa.

Separately, when you buy a subscription, Apple or Google handles the payment itself and processes that purchase under their own terms and their own transfer safeguards, not ours. That is the case whichever tools we use.

5. Who we share data with (sub-processors)

We use a small number of service providers for authentication, cloud features, purchases, email, optional analytics, and optional crash reporting. None of them receive more data than needed for the purposes described here, and none may use your data for their own purposes.

Sub-processorWhat they receivePurpose
SupabaseEverything in the "Signed-in mode" table aboveDatabase hosting, authentication
GoogleYour Google account info (if you sign in with Google), and your app-store purchase data (Play Store)Sign-in; subscription billing
RevenueCatA randomly generated purchaser id when signed out, your account id when signed in, device/OS technical information, and purchase/subscription transaction informationPurchase validation and subscription management across stores; an account is not required
ResendYour email address and the name shown in the greeting, for the transactional emails listed in section 6 and the website confirmation emails in section 7Sending those emails
PostHog (EU Cloud)Usage events, intro answers, selected settings, and an opaque installation or account id, only if you opt inProduct analytics to improve the app
Sentry (EU region)Crash/error diagnostics (stack trace, device/OS metadata, opaque user id), only if you opt inCrash reporting and stability

We do not sell any of this data, and we do not share it with anyone for advertising purposes.

6. Transactional email

If you sign in, we send you email only for account events you triggered or that affect your account directly:

These five are transactional, not marketing: signing in to the app does not add you to any mailing list, and we do not send app users newsletters or promotional email. The optional website lists described in the next section are entirely separate, and you are only on one if you asked to be.

7. Website sign-up lists (optional)

The mundaneapps.com website offers two lists you can join by entering your email address. Neither has anything to do with the app: you can use HeadsUp without joining, and joining does not create an app account.

For each list we store the email address you gave us, where the sign-up came from, your current status, whether you want updates, when we last emailed you, and a unique unsubscribe token. We also keep a log of the emails we send to these lists, containing the recipient address, which kind of email it was, and the delivery outcome.

Joining a list opts you in to occasional update emails as well as the immediate confirmation email. Every one of them carries an unsubscribe link, and unsubscribing stops all further email to that address. You can also email us to be removed entirely.

To stop the sign-up form being abused, the website briefly stores a one-way hash derived from the request — not your email address, and not something we can reverse — together with a count of recent attempts.

8. Retention: how long we keep your data

What happenedCloud contentDeletion markerYour device
You sign outUntouchedNoneYour cadences, profile and settings stay. Your login tokens are deleted, you are signed out of Google, your analytics identity is reset, and your cached paid status is cleared until you sign back in.
You delete one cadenceContent erased as soon as the deletion is sent, which is shortly after the undo option disappearsKept until you delete your accountRemoved immediately
Clear my data → This device onlyUntouched (re-downloads next sync)NoneCadences, profile, saved tags, this install's analytics identifier, the last-sync record, the widget snapshot and any leftover export file are all removed. Your sign-in and your app settings — appearance, reminders, text size, app icon, onboarding and tour state, and your analytics choice — are kept.
Clear my data → EverywhereErased immediatelyKept until you delete your accountSame as above
Subscription lapsesErased 30 days after lapsingKeptUntouched
You delete your accountEverything permanently deleted 30 days after you delete, unless you restore firstDeleted with the accountSame as signing out: content stays, login and paid status are cleared

In plain terms: content you delete is erased from our servers straight away, not on a delay. Deleting a single cadence is held back only for the few seconds the undo option is on screen, so that undo can still work; after that the content is gone and cannot be brought back, by you or by us.

What remains is a deletion marker: the cadence's identifier, a "this was deleted" flag, and the times involved. It exists so a device that comes back online later cannot resurrect something you deleted, and it is erased when your account is deleted. These markers are not anonymous — each one is stored against your account, so it shows that your account deleted something and when. Calling them anonymous, as an earlier version of this policy did, was wrong.

The two activity logs in section 2 — the record of your backup moving between devices, and the record of restores and syncs — are deleted after 90 days by a daily job. They used to be kept for as long as the account existed, which meant a long-running account built up a permanent history of both. Ninety days is long enough for us to look into a problem you report, and long enough for the device-switch limit described in section 2, which only counts the last 30 days.

How long our service providers keep data

The table above covers our own database. The providers in section 5 keep their own copies for their own periods:

ProviderRetention
Supabase (account, profile, cadences)Deleted 30 days after you delete your account. Deleting the account removes the login record and everything attached to it — cadences, devices, entitlements, restore history and sessions.
PostHog (analytics, only if you opt in)Configured to retain events for 12 months.
Sentry (crash reports, only if you opt in)As configured by the provider under our current plan.
RevenueCat (purchases)As configured by the provider. Purchase records may outlive your HeadsUp account, because they also exist to satisfy the app stores' own billing requirements.
Resend (email delivery)As configured by the provider.
Website sign-up lists (section 7)Kept until you unsubscribe or ask us to remove you.

Where a row says "as configured by the provider", we have not stated a number because we would not be able to stand behind it here. Deleting your HeadsUp account removes your data from our database on the schedule above; telemetry and delivery records already sent to those providers expire on their own schedules.

9. Children

HeadsUp is not directed at children and is intended for users 18 and older (see our Terms of Service). We do not knowingly collect data from children, and we do not collect age or birth-date information from anyone, at any age.

10. Your rights

Regardless of where you live, you can:

If you are in the EU/EEA or UK, these rights are provided under the GDPR / UK GDPR. If you are in India, they are provided under the DPDP Act. We extend the same rights to users everywhere, regardless of location.

11. Contact

Questions, requests, or concerns about this policy: info@mundaneapps.com.

12. Changes to this policy

We may update this policy as the app changes. Material changes receive a new visible version and effective date on this page, and HeadsUp always links to the current published policy from Settings, so the version you reach from the app is the current one. The app does not currently show an in-app notice when the policy changes, or ask you to accept a new version; if we add processing that requires your renewed consent, we will build that before the processing starts.