App · Privacy · GDPR

SevenGrid App Privacy Policy

Last updated: June 13, 2026 · GDPR Art. 13

This policy covers the SevenGrid mobile app (Android, distributed via Google Play). The privacy policy for the marketing website sevengrid.app is separate and only concerns visiting the website: → Website privacy policy.

Local-first: the core

SevenGrid is a local-first app. All habit data, weekly reflections, settings, and note content are stored exclusively in an SQLite database on your device. There is no account, no login, no cloud sync, and no central user database. The vast majority of your data is therefore never processed by us. It does not leave your device.

Data categories processed

What there is definitely NOT

Independently verified

An independent scan with Exodus Privacy finds exactly one service that Exodus labels a "tracker": Sentry, the crash reporter described above. No analytics, advertising, or profiling trackers. Sentry is anonymized (no IP logging, no usage or session tracking, EU region Frankfurt) and can be turned off in the app.

Legal bases

The app's features are provided in the context of contract performance (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in a functional, stable app (Art. 6(1)(f) GDPR). The anonymized crash reports rely on legitimate interest (stability and debugging); you can disable them in the app at any time. Validating the Pro purchase is technically necessary for performing the contract (Art. 6(1)(b) GDPR). Processing of the purchase and billing is carried out by Google Play under its own terms.

Recipients / processors

Personal data is transmitted only to the following parties, and only where necessary for the stated purposes:

No further disclosure of the content stored on your device takes place.

Transfers to third countries

Crash reports are processed in Sentry's EU data region (Frankfurt). Purchase validation via RevenueCat and parts of the Google Play processing may involve processing in the USA. These transfers are safeguarded by the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR).

Retention

Your rights

Under the GDPR you have, free of charge and at any time, the following rights:

Right to complain to the supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged breach. The supervisory authority responsible for the controller is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22(1) and (4) GDPR, takes place.

Controller

Full provider identification in the Imprint. A data protection officer is not legally required.

Contact & data deletion

We answer questions about data processing personally at hello@sevengrid.app, usually within 48 hours. You can also submit deletion requests for server-side technical data directly via the Request data deletion page.