Privacy Policy
Privacy Policy
# Privacy Policy
**Last updated: February 2026**
## 1. Introduction
Widgetopia ("we", "us", or "our") operates the Widgetopia mobile application, which allows users to share photos on friends' home screen widgets, track moods and sleep, create customizable widgets, and connect with friends (our "Services").
We are committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and safeguard your personal data when you use our Services. It also describes your rights and choices regarding your data.
## 2. Personal Data We Collect
### Information You Provide
- **Account information.** When you create an account, we collect your full name and email address through Apple Sign-In or Google Sign-In. You may also provide a username, profile picture, and birthday.
- **Photos.** When you send a photo to a friend's widget, we collect the photo and associated metadata, including the file type, size, captions, and the time the photo was taken.
- **Status updates.** When you create a status widget, we collect the content you provide, including emoji, text, background colors, and optional custom photos.
- **Mood entries.** When you log your mood, we collect the mood emoji, timestamp, and any optional notes you provide.
- **Sleep data.** If you use the sleep tracking feature, we collect bedtime, wake time, sleep duration, and sleep quality data. This data may come from your manual input, HealthKit (step count and sleep analysis data from Apple Watch), or phone interaction patterns (tappigraphy).
- **Friend connections.** When you add friends, we collect friend request and friendship data, including sender and receiver information.
- **Contact information.** With your permission, we may access your device contacts to help you find friends who use Widgetopia. We do not store your full contact list on our servers.
- **Widget configurations.** When you create and customize widgets (countdown timers, status displays, mood bubbles, miss-you widgets, sleep widgets), we store your configuration preferences.
- **Correspondence.** When you contact us for support, we collect the content of your communications.
### Information Collected Automatically
- **Device data.** We collect information about your device, including operating system version, device model, and unique device identifiers.
- **Usage data.** We collect information about how you interact with our Services, including features used, screens viewed, and timestamps of activity.
- **Location data.** With your permission, we access your device location solely to provide weather and location-based photo captions. Location data is processed locally on your device and is not stored on our servers. Location data may be included in photo captions you choose to share.
- **Push notification tokens.** We collect Apple Push Notification service (APNs) device tokens to deliver notifications about new photos, friend requests, and other activity.
### Information from Third Parties
- **Authentication providers.** When you sign in with Apple or Google, we receive your name, email address, and authentication tokens from the respective provider.
## 3. How We Use Your Personal Data
We use your personal data for the following purposes:
- **To provide the Services.** We use your account information, photos, statuses, mood entries, sleep data, and widget configurations to operate and deliver the core features of Widgetopia.
- **To enable social features.** We use friend connections and contact information to allow you to connect with friends and share content on their widgets.
- **To send notifications.** We use push notification tokens to inform you about new photos received, friend requests, and other relevant activity.
- **To provide health-related features.** With your permission, we access HealthKit data (step count and sleep analysis) to detect sleep patterns and display sleep data in widgets. HealthKit data is never used for advertising or shared with third parties.
- **To provide weather and location captions.** With your permission, we use your location to fetch weather data via Apple WeatherKit and to generate location-based photo captions.
- **To display advertisements.** We use Google AdMob to display ads within the app. AdMob may collect device information, advertising identifiers, and usage data to serve relevant ads. See Section 4 for more details.
- **To improve our Services.** We use usage data and aggregated analytics to understand how our Services are used and to make improvements.
- **To ensure safety and security.** We use personal data to detect, prevent, and address fraud, abuse, security risks, and technical issues.
- **To comply with legal obligations.** We may process your data as required by applicable laws and regulations.
## 4. How We Share Your Personal Data
We do not sell your personal data. We share personal data only in the following circumstances:
- **With your friends.** Photos, statuses, mood entries, and other content you share are visible to the friends you choose to share them with.
- **Service providers.** We use third-party services to operate our backend infrastructure:
- **Supabase** for database hosting, user authentication, file storage, and serverless functions.
- **Apple** for authentication (Sign in with Apple), push notifications (APNs), weather data (WeatherKit), and health data (HealthKit).
- **Google** for authentication (Google Sign-In).
- **Advertising partners.** We use Google AdMob to display advertisements. AdMob may collect and use device information, advertising identifiers, and app usage data to serve personalized or non-personalized ads, in accordance with [Google's Privacy Policy](https://policies.google.com/privacy). You can manage your ad preferences through your device settings.
- **Legal requirements.** We may disclose your data to law enforcement or regulatory authorities if required by law, legal process, or to protect the rights, property, or safety of Widgetopia, our users, or the public.
- **Business transfers.** If Widgetopia is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction.
## 5. HealthKit Data
We take the privacy of your health data seriously:
- **Purpose.** HealthKit data (step count and sleep analysis) is used solely to detect sleep patterns and provide sleep tracking features within the app.
- **No advertising use.** HealthKit data is never used for advertising, marketing, or shared with advertising partners.
- **No third-party sharing.** HealthKit data is not shared with any third parties.
- **Local processing.** Sleep detection algorithms run locally on your device. Only user-confirmed sleep records are stored on our servers to enable widget display and friend sharing features.
- **User control.** You can revoke HealthKit access at any time through your device's Health app settings.
## 6. Data Storage and Security
- **Storage.** Your personal data is stored on Supabase servers. Photos are stored in Supabase Storage. Widget configurations and cached data are stored locally on your device.
- **Security.** We use industry-standard security measures including encryption in transit (HTTPS/TLS) and secure authentication to protect your data. However, no method of transmission or storage is 100% secure.
- **Local caching.** Photos and widget data may be cached locally on your device and in shared app group storage to enable widget functionality.
## 7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Services. Specifically:
- **Account data** is retained until you delete your account.
- **Photos** are retained until deleted by you or the sender.
- **Sleep, mood, and status data** is retained as long as your account is active.
- **Cached data** on your device is managed automatically and can be cleared through the app settings.
When you delete your account, we will delete or anonymize your personal data within a reasonable timeframe, except where we are required to retain it for legal or legitimate business purposes.
## 8. Your Rights and Choices
Depending on your location, you may have the following rights:
- **Access.** Request a copy of the personal data we hold about you.
- **Correction.** Request correction of inaccurate or incomplete data.
- **Deletion.** Request deletion of your account and personal data. You can delete your account through the app settings.
- **Withdraw consent.** Revoke permissions for camera, location, contacts, HealthKit, or notifications through your device settings at any time.
- **Opt out of personalized ads.** You can limit ad tracking through your device settings (Settings > Privacy & Security > Tracking on iOS).
- **Data portability.** Request your data in a portable format.
To exercise these rights, contact us at the email provided in Section 12.
## 9. Children's Privacy
Our Services are not directed to children under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete such data.
## 10. International Data Transfers
Your personal data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.
## 11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app or by other appropriate means. Your continued use of the Services after such changes constitutes your acceptance of the updated policy.
## 12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
**Email:** justflowapp@gmail.com
---