App · Privacy · GDPR
SevenGrid App Privacy Policy
Last updated: June 13, 2026 · GDPR Art. 13
This policy covers the SevenGrid mobile app (Android, distributed via Google Play). The privacy policy for the marketing website sevengrid.app is separate and only concerns visiting the website: → Website privacy policy.
Local-first: the core
SevenGrid is a local-first app. All habit data, weekly reflections, settings, and note content are stored exclusively in an SQLite database on your device. There is no account, no login, no cloud sync, and no central user database. The vast majority of your data is therefore never processed by us. It does not leave your device.
Data categories processed
- Habit data: habit names, colors, icons, weekly goals, goal direction, check-ins, notes, amounts and duration, skipped days. Stay on your device.
- Weekly reflections: three free-text fields plus a mood value. Stay on your device.
- App settings: theme, language, reminder time, quiet hours. Stay on your device.
- Crash reports: via Sentry, EU data region (Frankfurt). Anonymized (no IP logging, no user tags,
sendDefaultPii: false). Can be turned off in the app (Settings → Data). Purpose: improve stability. - Pro purchase validation: via RevenueCat. An anonymized app-user ID, no profile data. Purpose: validate the lifetime one-time SevenGrid Pro upgrade.
- Google Play: app distribution and processing of the in-app purchase. Data processing according to the Google Privacy Policy.
- Android backup: your habit database is not part of Android's automatic backup to your Google account, it stays on your device. To move to a new phone, use the optional local CSV backup below.
- Optional local CSV backup: if you enable the automatic backup in the app, SevenGrid writes your data once a day as CSV files into a folder you choose on your device (Storage Access Framework). The files stay local, are never uploaded by the app, and survive an uninstall. You can turn this off at any time; files already written remain under your control.
What there is definitely NOT
- No behavioural tracking, no targeting, no advertising IDs.
- No analytics (no Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude).
- No newsletter signup, no mailing list, no push marketing notifications.
- No sharing of habit or reflection content with third parties. Ever.
- No AI model, no LLM, no cloud service ever sees your reflection texts.
Independently verified
An independent scan with Exodus Privacy finds exactly one service that Exodus labels a "tracker": Sentry, the crash reporter described above. No analytics, advertising, or profiling trackers. Sentry is anonymized (no IP logging, no usage or session tracking, EU region Frankfurt) and can be turned off in the app.
Legal bases
The app's features are provided in the context of contract performance (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in a functional, stable app (Art. 6(1)(f) GDPR). The anonymized crash reports rely on legitimate interest (stability and debugging); you can disable them in the app at any time. Validating the Pro purchase is technically necessary for performing the contract (Art. 6(1)(b) GDPR). Processing of the purchase and billing is carried out by Google Play under its own terms.
Recipients / processors
Personal data is transmitted only to the following parties, and only where necessary for the stated purposes:
- Functional Software, Inc. (Sentry): crash and error reports, EU data region (Frankfurt). Acting as a processor under Art. 28 GDPR.
- RevenueCat, Inc.: validation of the in-app purchase, USA, certified under the EU-US Data Privacy Framework. Processes an anonymous app-user ID, no content or profile data.
- Google Ireland Limited / Google LLC (Google Play): app distribution and the processing and billing of the in-app purchase. Google acts as an independent controller for payment processing.
No further disclosure of the content stored on your device takes place.
Transfers to third countries
Crash reports are processed in Sentry's EU data region (Frankfurt). Purchase validation via RevenueCat and parts of the Google Play processing may involve processing in the USA. These transfers are safeguarded by the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR).
Retention
- Local app data: stays on your device until you delete it in the app or uninstall the app. There is no server-side copy held by us.
- Crash reports (Sentry): automatically deleted after the retention period configured in Sentry (90 days by default).
- Pro purchase validation (RevenueCat): for as long as your Pro entitlement exists (lifetime one-time purchase), so that restores and refunds can be reflected.
Your rights
Under the GDPR you have, free of charge and at any time, the following rights:
- Access (Art. 15): because the app runs locally, your content resides entirely on your device and is viewable there at any time. We provide access to the technical data processed by Sentry and RevenueCat on request.
- Rectification (Art. 16) and erasure (Art. 17): content can be edited or deleted directly in the app. Uninstalling removes the local database entirely. To erase server-side technical data, use the Request data deletion page.
- Restriction of processing (Art. 18).
- Data portability (Art. 20): you can export your data yourself at any time via the app's CSV export, in a common, machine-readable format.
- Objection (Art. 21) to processing based on legitimate interest. You can also object to the crash reports directly in the app (toggle under Settings → Data).
Right to complain to the supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged breach. The supervisory authority responsible for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
No automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22(1) and (4) GDPR, takes place.
Controller
Full provider identification in the Imprint. A data protection officer is not legally required.
Contact & data deletion
We answer questions about data processing personally at hello@sevengrid.app, usually within 48 hours. You can also submit deletion requests for server-side technical data directly via the Request data deletion page.