App · Privacy · GDPR
SevenGrid App Privacy Policy
Last updated: September 6, 2026 · GDPR Art. 13
At a glance
Accounts 0 · Cloud sync 0 · Analytics 0 · Ads 0
SevenGrid stores your habits, reflections, and settings exclusively on your device. There is no account, no login, and no central user database.
- Two services see any data at all: Sentry (anonymized crash reports, can be turned off) and RevenueCat (anonymous purchase validation)
- No content leaves the device: no habit, no note, no reflection, ever
- Reminders (and, on Android, widgets) work entirely on-device, no push server
- Backup and export stay on your device: a folder you choose on Android, the share sheet on iOS
- Independently verified: Exodus Privacy scan and Google Play Data safety, sources in § 5
Important: This policy covers the SevenGrid mobile app (Android via Google Play, iOS via the Apple App Store). The marketing website sevengrid.app has a separate privacy policy that only concerns visiting the website.
1. Local-first: the core
SevenGrid is a local-first app. All habit data, weekly reflections, settings, and note content are stored exclusively in an SQLite database on your device. There is no account, no login, no cloud sync, and no central user database. The vast majority of your data is therefore never processed by us. It does not leave your device.
The home-screen widgets, too, read only this local database: whatever a widget shows has never left your device.
2. Data categories processed
- Habit data: habit names, colors, icons, weekly goals, goal direction, check-ins, notes, amounts and duration, skipped days. Stay on your device.
- Weekly reflections: three free-text fields plus a mood value. Stay on your device.
- App settings: all settings, such as theme, language, week start, reminder times, or widget options. Stay on your device.
- Reminders: reminders you set up are scheduled as local notifications directly on the device. There is no push server and no cloud-messaging connection; no reminder leaves your device.
- Import from other apps: if you import CSV files from other habit trackers, processing happens entirely on the device. None of it is uploaded.
- Crash reports: via Sentry, EU data region (Frankfurt). Anonymized (no IP logging, no user tags,
sendDefaultPii: false). Can be turned off in the app (Settings → Data). Purpose: improve stability. - Pro purchase validation: via RevenueCat. An anonymized, randomly generated app-user ID, no profile data. Purpose: validate the lifetime one-time SevenGrid Pro upgrade.
- Google Play: app distribution and processing of the in-app purchase. Data processing according to the Google Privacy Policy.
- Apple App Store (iOS): app distribution and processing of the in-app purchase. Data processing according to the Apple Privacy Policy.
- Android backup: your habit database is not part of Android's automatic backup to your Google account, it stays on your device. To move to a new phone, use the optional local CSV backup below.
- iCloud backup (iOS): if iCloud Backup is switched on, an iPhone backs itself up to the owner's Apple account, encrypted, and the SevenGrid habit database rides along in that backup. Nothing about it involves us: Apple runs it, we have no access to it. Its upside is a new iPhone that arrives with your habits already in place; if you would rather keep the database out, switch SevenGrid off under Apple Account → iCloud → iCloud Backup → this iPhone. The CSV export listed below works on iOS too and gives you a copy in your own hands.
- Optional local CSV backup (automatic backup on Android; on iOS a manual export via the share sheet): if you enable the automatic backup in the app, SevenGrid writes your data once a day as CSV files into a folder you choose on your device (Storage Access Framework). The files stay local, are never uploaded by the app, and survive an uninstall. You can turn this off at any time; files already written remain under your control.
3. What there is definitely NOT
- No behavioural tracking, no targeting, no advertising IDs.
- No analytics (no Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude).
- No newsletter signup, no mailing list, no push marketing notifications.
- No sharing of habit or reflection content with third parties. Ever.
- No AI model, no LLM, no cloud service ever sees your reflection texts.
4. App lock & biometrics
The app includes an optional app lock (Settings → App lock) that puts SevenGrid behind your fingerprint, face unlock, or device code. The checking is done entirely by the operating system (Android or iOS): SevenGrid only receives the system's answer, "unlocked: yes or no". Biometric data is never collected, stored, or transmitted by the app; it stays in your device's secure area and never leaves it.
Optionally, the lock also blocks screenshots, screen recording and the preview in the recent-apps overview (on Android via FLAG_SECURE, on iOS via the protection the system gives secure input fields). This too is a purely local system feature with no data processing outside the device.
5. Independently verified
An independent scan with Exodus Privacy finds exactly one service that Exodus labels a "tracker": Sentry, the crash reporter described above. No analytics, advertising, or profiling trackers. Sentry is anonymized (no IP logging, no usage or session tracking, EU region Frankfurt) and can be turned off in the app.
The second independent source is Google's Data safety listing on the Play Store: no data shared with third parties, and the only data collected is optional crash logs plus "device or other IDs". The latter refers to the anonymous, randomly generated app-user ID from § 2 that RevenueCat uses to validate the Pro purchase; it is not an advertising ID.
6. Legal bases
The app's features are provided in the context of contract performance (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in a functional, stable app (Art. 6(1)(f) GDPR). The anonymized crash reports rely on legitimate interest (stability and debugging); you can disable them in the app at any time. Validating the Pro purchase is technically necessary for performing the contract (Art. 6(1)(b) GDPR). Processing of the purchase and billing is carried out by Google Play under its own terms.
7. Recipients / processors
Personal data is transmitted only to the following parties, and only where necessary for the stated purposes:
- Functional Software, Inc. (Sentry): crash and error reports, EU data region (Frankfurt). Acting as a processor under Art. 28 GDPR.
- RevenueCat, Inc.: validation of the in-app purchase, USA, certified under the EU-US Data Privacy Framework. Processes an anonymous app-user ID, no content or profile data.
- Google Ireland Limited / Google LLC (Google Play): app distribution and the processing and billing of the in-app purchase. Google acts as an independent controller for payment processing.
- Apple Distribution International Ltd. (Apple App Store, iOS): app distribution and the processing and billing of the in-app purchase; for App Store purchases Apple is the seller and an independent controller. Seat: Cork, Ireland (EU).
No further disclosure of the content stored on your device takes place.
8. Transfers to third countries
Crash reports are processed in Sentry's EU data region (Frankfurt). Purchase validation via RevenueCat and parts of the Google Play and Apple App Store processing may involve processing in the USA. These transfers are safeguarded by the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR).
9. Retention
- Local app data: stays on your device until you delete it in the app or uninstall the app. There is no server-side copy held by us. On iOS, a copy can remain inside your iCloud device backup until that backup is replaced or deleted (see § 2).
- Crash reports (Sentry): automatically deleted after the retention period configured in Sentry (90 days by default).
- Pro purchase validation (RevenueCat): for as long as your Pro entitlement exists (lifetime one-time purchase), so that restores and refunds can be reflected.
10. Your rights
Under the GDPR you have, free of charge and at any time, the following rights:
- Access (Art. 15): because the app runs locally, your content resides entirely on your device and is viewable there at any time. We provide access to the technical data processed by Sentry and RevenueCat on request.
- Rectification (Art. 16) and erasure (Art. 17): content can be edited or deleted directly in the app. Uninstalling removes the local database entirely. To erase server-side technical data, use the Request data deletion page.
- Restriction of processing (Art. 18).
- Data portability (Art. 20): you can export your data yourself at any time, as CSV files or as a full JSON export (both under Settings → Data), in common, machine-readable formats.
- Objection (Art. 21) to processing based on legitimate interest. You can also object to the crash reports directly in the app (toggle under Settings → Data).
11. Right to complain to the supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged breach. The supervisory authority responsible for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
12. No automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22(1) and (4) GDPR, takes place.
13. Controller
Full provider identification in the Imprint. A data protection officer is not legally required.
14. Contact & data deletion
We answer questions about data processing personally at hello@sevengrid.app, usually within 48 hours. You can also submit deletion requests for server-side technical data directly via the Request data deletion page.