FiuFiu

Privacy Policy

Effective date: September 7, 2026 · Last updated: September 7, 2026

Draft. This document is pending legal review and is not yet in force.

This policy explains what FiuFiu collects, why, where it goes, how long it stays, and what you can do about it. It covers the FiuFiu mobile app and the website at https://fiufiuapp.com. We have written it to match what the app actually does today; when the app changes, this page changes with it.

1. Who we are

FiuFiu is made by FiuFiu Labs. For anything about your data, write to privacy@fiufiuapp.com.

2. The website

This website is a set of static pages. It sets no cookies, runs no analytics, loads nothing from third-party servers, and has no forms. The only data involved is the standard access log our hosting provider, Vercel, keeps for each request: your IP address, browser identifier, the page requested, and the time. Vercel keeps those logs for a short period on our behalf; we do not export or analyse them.

3. The app: what we collect and why

The app works without an account. Everything below applies only once you sign in, which turns on cloud sync so your alarms and progress survive a new phone.

3.1 Your account

3.2 A device identifier

The app creates a random identifier on each phone the first time it syncs and keeps it on that phone. It tags the data that phone sends so we can tell your devices apart. It is not a hardware identifier or an advertising identifier, and it is deleted with your account.

3.3 Alarms, schedule, and wake-ups

3.4 Sleep and mood

On iPhone, with your permission, the app reads your sleep from Apple Health to show how last night went. That reading stays on your phone. We never write to Health, and Health data is never used for advertising, never sold, and never shared with anyone. The only sleep-related data that syncs to your account is the mood you tap each morning (rough, okay, or rested) and when you tapped it.

3.5 Camera, motion, and microphone

Challenges use your phone's sensors, and the processing happens on the phone:

You can withdraw any of these permissions at any time in your phone's Settings. The related challenges will stop working until you turn the permission back on.

3.6 Subscriptions and purchases

Payments are handled by Apple or Google, and subscriptions are managed through RevenueCat. We never see your card or bank details. What we receive and keep:

RevenueCat knows you by the same account identifier we use, or by an anonymous identifier before you sign in.

Refund requests. Apple sometimes asks the developer whether a purchase was used before deciding a refund. We answer only if you have switched on the optional setting in the app that allows it. If you have, we tell Apple whether you used any Stop Alarms; we send nothing else.

3.7 Optional product analytics

If you allow it, the app sends usage events to PostHog so we can see which parts of FiuFiu people use and where they get stuck. We ask once during setup, with equal Allow and Decline buttons, and you can change your answer at any time in the app's Settings. Nothing is collected or stored for analytics before you allow it, and declining changes nothing else in the app.

An event contains its name (for example an onboarding step completed, an alarm created, a challenge finished, or a subscription started), a few fixed properties from a short allowlist, the app version, the platform, and the app environment. Events never include your email, free-text answers, Health data, your exact sleep schedule, or your IP address, which is not stored (it is replaced with zeros); location lookup is switched off. Before you sign in, events carry a random identifier; after you sign in they carry your account identifier so we can count returning users. Withdrawing consent stops new events immediately. Events already sent are deleted when you delete your account. Analytics is currently available on iPhone only, and our PostHog project is hosted in the European Union.

Separately from your choice, our backend sends PostHog a small number of operational signals about itself, such as failure counts and processing health. These describe the service, not you, and carry no account identifier.

3.8 What we do not collect

The app has no crash reporting, no advertising, and no over-the-air update client. It does not access your location, contacts, or photo library, and it does not collect push notification tokens. Alarm notifications are scheduled locally on your phone.

4. Why we use this data and on what basis

We do not use your data for advertising or profiling, and we do not sell it.

5. Who processes data for us

If you are outside the United States, account and purchase data is transferred there to be processed by the providers above; analytics data stays in the European Union.

6. How long we keep data

7. Your rights and choices

You can ask us to show you the data we hold, correct it, delete it, or send you a copy. Where a law gives you further rights, such as objecting to processing or restricting it, you can exercise those too. Write to privacy@fiufiuapp.com from the email address on your account. We reply within two business days and complete requests within 30 days.

To delete your account, follow the steps on the Delete your account page. To stop the app reading Health data or using the camera, motion sensors, or microphone, change the permission in your phone's Settings. To stop syncing, sign out.

8. Children

FiuFiu is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will delete it.

9. Security

Data travels over encrypted connections and is stored with providers that encrypt it at rest. Access is limited to what is needed to run the service. No system is perfectly secure, so please use a strong, unique password.

10. Changes to this policy

When we change this policy we update the dates at the top of this page and, for changes that matter to you, we tell you in the app before they take effect.

11. Contact

privacy@fiufiuapp.com