Privacy Policy
This policy explains what personal data we collect when you use the Puff Counter app (published as “Puff Counter - Quit Vaping” on the App Store and Google Play, “the app”) and the website puffcounter.app (“the website”), why, who receives it, and what your rights are. It follows the EU General Data Protection Regulation (GDPR) and Dutch law. The app is available in many languages; this policy exists in English only and the English text prevails.
In short
- The app works without an account. Your puff data then stays on your phone and we never see it.
- If you create an account, we back up your profile, settings and puff history to Google Firebase so you can restore them on a new phone.
- We collect crash reports and basic usage statistics from all installs to keep the app working.
- Premium subscriptions are sold by Apple or Google. We never see your card details.
- We do not sell your data, and the app shows no third-party ads.
- You can delete your account and all backed-up data in the app at any time.
1. Who is responsible for your data
The data controller is:
Selanto Apps (sole proprietorship, eenmanszaak)
Nehrusingel 122, 3066 VN Rotterdam, Netherlands
Chamber of Commerce (KvK) number: 75803097
Email: support@puffcounter.app
Write to the email address above with any privacy question or request.
2. Data that stays on your phone
In short: without an account, nothing you log leaves your device.
The app stores your puff log, your settings (puff strength, puff volume, daily limits, quit plan dates), the nicotine estimate calculated from them, widget data and notification preferences in a local database on your phone. Without an account, we have no access to this data. It is removed when you delete the app, or earlier if you use “Delete only puffs” or “Delete account and data” in Settings. Your phone’s own backup (iCloud or Google) may also include this local data.
3. Data we collect if you create an account
Creating an account is optional. You can sign in with Google, with Apple, or with an email address and password. Accounts run on Firebase Authentication, a Google service, which also logs technical sign-in data such as IP address and device type for security. With an account we store:
| Category | Details | Source |
|---|---|---|
| Account details | Name, email address, sign-in method, a random user ID, account creation date, the date you accepted our terms | You, Google or Apple |
| Profile picture | Optional. Your Google profile picture or a picture you upload | You, Google |
| Onboarding answers | Optional. Vaping experience, age range, gender, where you heard about the app | You |
| App settings | Puff strength, puff volume, daily limits, quit plan dates | The app |
| Puff history | Number of puffs per hour and per day | The app |
| Email preference | Whether you ticked the box for updates and deals | You |
Your puff history and nicotine settings can reveal information about your health, namely your nicotine use. We only store this data on our servers when you create an account, and creating an account is how you give us your explicit consent to back it up. You can withdraw that consent at any time by deleting your puff data or your account in Settings.
4. Data we collect from every install
In short: technical data that keeps the app stable, plus purchase status if you buy Premium.
Crash reports. We use Firebase Crashlytics. When the app crashes it sends the crash trace, device model, operating system version, app version, free memory and storage, the time of the crash and a Crashlytics installation ID that is not linked to your name.
Usage statistics. The app includes Google Analytics for Firebase. It records standard events such as first open, screens viewed and purchases, with device model, operating system, language, the country derived from your IP address, app version and a Firebase app instance ID. On Android it may also read the advertising ID. We look at these statistics in aggregate to see which features are used, never for advertising.
Mixpanel. The app also contains the Mixpanel analytics SDK. It can send usage events and, for account holders, your name, email address, sign-in method and onboarding answers to Mixpanel, Inc. in the United States, only so we can understand how the app is used.
Purchases. Premium is sold through the App Store or Google Play. We use RevenueCat to check what you bought. RevenueCat receives a random app user ID, the store receipt, your subscription status and a device identifier. Apple or Google processes the payment; we never receive your card or bank details. If you buy Premium on a web checkout run by RevenueCat, the checkout page tells you what payment data it collects.
Push notifications. If you allow notifications, the app registers a push token with Firebase Cloud Messaging so we can send app notifications. You can turn them off in your device settings at any time.
Support. If you email us, we keep your message, your email address and any details you choose to share so we can help you.
5. Why we use your data and on what legal basis
In short: to run the app, to back up your data at your request, to keep it working, and to email you only when you asked for it.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account, show your name and picture, restore your backup on a new device | Account details, profile picture, settings, puff history | Contract (Art. 6(1)(b)); explicit consent for health-related puff data (Art. 9(2)(a)) |
| Service emails: verification, password reset, security notices, important changes | Email address, name | Contract, and legitimate interest in keeping you informed (Art. 6(1)(f)) |
| Updates and deals by email | Email address, name, onboarding answers | Consent (Art. 6(1)(a)); withdraw any time via the unsubscribe link |
| Fix crashes and keep the app stable | Crash reports | Legitimate interest in a working product |
| Understand how the app is used and improve it | Usage statistics, optional onboarding answers | Legitimate interest; you can object (section 12) |
| Unlock Premium and handle purchase issues | Purchase data | Contract |
| Keep accounting records | Purchase records from the stores | Legal obligation (Dutch tax law) |
| Answer support requests | Your message | Contract, and legitimate interest |
| Prevent abuse and defend legal claims | Any of the above, as needed | Legitimate interest |
Where we rely on legitimate interest, we have checked that our interest does not override your rights; ask us for a summary of that assessment.
6. How the app uses Google user data
If you choose “Sign in with Google”, the app requests the Google scopes openid, email and profile. Through them we receive your Google account name, email address and profile picture URL. We use this data only to create your Puff Counter account and sign you in, to show your name and picture in the app, to link your cloud backup to you and restore it on a new phone, and to send you service emails (marketing emails only if you opted in).
We do not request access to Gmail, Drive, contacts, calendar or any other Google data. We do not use Google user data for advertising, do not sell it, and do not transfer it to anyone except the processors in section 8, who act on our instructions. No person reads it except when you ask for support, when security requires it, or when the law requires it.
Puff Counter’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove Puff Counter’s access at any time at myaccount.google.com/permissions. This does not delete your Puff Counter account; use the steps in section 11 for that.
7. Sign in with Apple
If you use Sign in with Apple, we receive your name (unless you edit it) and either your real email address or a private relay address that Apple creates for you. Emails we send to a relay address are forwarded by Apple. You can manage this in your Apple Account settings.
8. Third-party services (who receives your data)
In short: a short list of service providers that work for us. We do not sell data, and there are no ad networks.
The companies below process data on our behalf under a data processing agreement and may only use it to provide their service to us.
| Provider | Service | Data | Location and transfer safeguard | Privacy policy |
|---|---|---|---|---|
| Google Ireland Limited and Google LLC (Firebase) | Authentication, Firestore backup, Storage for profile pictures, Cloud Messaging, Crashlytics, Analytics | Account data, crash reports, usage statistics, push tokens | EU and US. EU-US Data Privacy Framework (Google LLC is certified) and EU standard contractual clauses | firebase.google.com/support/privacy |
| RevenueCat, Inc. | Subscription management and web checkout | App user ID, store receipts, subscription status, device identifier | US. Data Privacy Framework and standard contractual clauses | revenuecat.com/privacy |
| Mixpanel, Inc. | Product analytics (section 4) | Usage events, account profile fields | US. Data Privacy Framework and standard contractual clauses | mixpanel.com/legal/privacy-policy |
| Vercel Inc. | Website hosting and cookie-free analytics | Page views, short-lived hashed visitor identifier, request logs | US with EU edge locations. Data Privacy Framework and standard contractual clauses | vercel.com/legal/privacy-policy |
Apple and Google (App Store and Google Play) process your purchase and, if you use their sign-in, your sign-in, as independent controllers under their own policies (apple.com/legal/privacy, policies.google.com/privacy). We may also disclose data to authorities, courts or legal advisers when the law requires it or to defend our rights, and to a buyer of the business if Puff Counter is ever sold, in which case this policy continues to apply.
9. International transfers
Where a provider processes data outside the European Economic Area, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework for certified companies, and otherwise on the EU standard contractual clauses with extra measures such as encryption. You can ask us for a copy of the relevant safeguards.
10. How long we keep your data
| Data | Retention |
|---|---|
| Account, settings, profile picture, puff history | Until you delete your account or the data in the app |
| Crash reports | 90 days |
| Usage statistics tied to a device or user | Up to 14 months, then only aggregate statistics |
| Purchase and subscription records | 7 years after the transaction, as Dutch accounting law requires |
| Support emails | Up to 2 years after our last exchange |
| Website request logs | A short period, for security and operations |
Data we no longer need is deleted or anonymized.
11. Account and data deletion
In the app: open Settings, tap “Delete account and data”, confirm. This deletes your cloud backup (profile, settings, puff history, profile picture) and your Firebase account, and clears the data on your phone. Without an account, it clears the local data. “Delete only puffs” removes your puff history but keeps your account.
By email: write to support@puffcounter.app from the address linked to your account, or include your user ID from Settings. We delete the account and its data within 30 days and confirm by email.
What remains: crash reports and usage statistics that cannot be linked back to you, purchase records held by Apple or Google, and the accounting records we must keep by law. Deleting your account does not cancel a subscription; cancel it in the App Store or Google Play. Full instructions: puffcounter.app/delete-account.
12. Your rights
Under the GDPR you can ask us to access, correct, delete or restrict the personal data we hold about you, and to give it to you in a portable format. You can object to processing based on legitimate interest, including the usage statistics. Where we rely on consent, you can withdraw it at any time; this does not affect what happened before.
Email support@puffcounter.app. We may ask you to confirm your identity, for example by writing from the account email. We answer within one month; for complex requests we may take up to two more months and will tell you.
If you are unhappy with our answer, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or to the data protection authority of the EU country where you live.
Outside the EU. If you live in the United Kingdom, Switzerland, a US state with a privacy law or elsewhere, you can exercise the rights above by email and we will apply your local law. We do not sell personal data or share it for cross-context behavioral advertising.
13. Children
Puff Counter is not directed at anyone under 18. Nicotine products are age restricted (18 or older in most countries, 21 in the United States), and the app is meant for adults who want to track and reduce their vaping. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, email us and we will delete it.
14. Security
Traffic between the app, the website and our providers is encrypted with TLS. Google encrypts stored data at rest. Sign-in tokens are kept in your phone’s secure storage. Passwords are handled by Firebase Authentication and are never visible to us. Only the owner has access to production data. If a breach affects your data, we will inform you and the authorities as the law requires.
15. Automated decisions
We make no decisions about you by automated means that have legal or similarly significant effects. The quit plan is a simple schedule calculated from the limits and dates you set.
16. Website analytics
In short: no cookies, no login, no forms.
Analytics. We use Vercel Web Analytics to count page views and clicks on the App Store and Google Play buttons (the event records the store, the page and the button position). Vercel sets no cookies. To count unique visitors it creates a salted hash of your IP address and browser details that is valid for one day and cannot be turned back into your IP address. No raw IP address is stored in the analytics data. Legal basis: legitimate interest in knowing how the site is used. Our store links contain a page name so we can see which page led to a download; they carry no personal data.
Server logs. Vercel’s servers may keep request logs with your IP address for a short period for security and to run the site.
Public reviews. Some pages quote reviews that users published on the App Store or Google Play, with the reviewer’s public display name and profile picture, linked to the original review. Legal basis: legitimate interest in showing genuine feedback that is already public. If you are quoted and want the quote removed, email us and we will remove it promptly.
Help pages in the app. The Help screen opens pages from puffcounter.app inside the app; this section applies to them too. The website links to the app stores and social networks, which have their own privacy policies.
17. Data safety summary
In short: the table we use to fill in Google Play’s Data safety form and Apple’s App Privacy labels.
“Shared” means passed to a third party for its own purposes. The providers in section 8 work on our behalf, so their processing counts as collected, not shared.
| Data type | Collected | Shared | Purpose | Optional | Encrypted in transit | Deletable by you |
|---|---|---|---|---|---|---|
| Name | With account | No | Account, personalization | Yes | Yes | Yes |
| Email address | With account | No | Account, service email, marketing with opt-in | Yes | Yes | Yes |
| User IDs | Yes | No | Account, purchases, analytics | Account ID yes; app instance ID no | Yes | Account ID yes |
| Photos (profile picture) | With account | No | Personalization | Yes | Yes | Yes |
| Other personal info (age range, gender, experience, install source) | With account | No | Personalization, product improvement | Yes | Yes | Yes |
| Health info (puff counts, nicotine settings, quit plan) | With account | No | Backup and restore | Yes | Yes | Yes |
| App interactions (usage events) | Yes | No | Analytics | No | Yes | Not linked to you |
| Crash logs and diagnostics | Yes | No | Stability | No | Yes | Not linked to you |
| Device or other IDs | Yes | No | Analytics, crash reports, purchase validation | No | Yes | Not linked to you |
| Purchase history | If you buy Premium | No | Unlock Premium | Yes | Yes | Kept by the stores and for accounting |
Not collected: location, contacts, messages, files, audio, browsing history, HealthKit or Health Connect data, payment details.
18. Changes to this policy
We update this policy when the app or the law changes. The date at the top shows the current version. For important changes we notify you in the app or by email before they take effect. Earlier versions are available on request.
19. Contact
Selanto Apps
Nehrusingel 122, 3066 VN Rotterdam, Netherlands
support@puffcounter.app