WaterNudge Privacy Policy
Effective date: August 2, 2026
This policy explains how WaterNudge, an Android hydration logging and reminder app published by Stackquiln, handles information. It applies to the WaterNudge app and support requests about it. The app is intended only for adults aged 18 or older.
The short version is that hydration entries and most preferences stay on your device. WaterNudge does not require an account and Stackquiln does not operate a server copy of your hydration history. Analytics is off until you grant the Analytics choice in Google's first-run consent message. Crash reporting is on by default to help identify stability problems, and you can turn it off at any time in Settings.
For privacy questions or requests, email stackquiln@gmail.com.
Information handling at a glance
The exact services available depend on the release configuration and your choices.
| Category | Purpose and legal basis where applicable | Recipient | Retention | Your control |
|---|---|---|---|---|
| Hydration entries, goals, weight-based estimate input, reminders, units, theme, sound, achievements, and preferences | Provide the features you request; performance of the service you request | Stored only on your device | Until Reset data, app-storage clearing, or uninstall | Edit entries, use Reset data, clear storage, or uninstall |
| Consent choices, ad pacing, and purchase entitlement | Remember your choices, apply feature access, and meet legal or security obligations | Primarily on-device; relevant status may also be processed by the provider named below | On-device until reset or uninstall; provider records under its policy | Change available privacy controls; manage purchases in Google Play |
| Coarse app interactions and Analytics identifiers, only after Analytics opt-in | Understand broad app use and improve reliability; consent | Google Analytics for Firebase | User- and event-level data follows the project's configured standard-property retention of 2 or 14 months; aggregated reporting data may remain longer | Use Advertising & analytics privacy in Settings to review or withdraw the Analytics choice; withdrawal stops collection and requests an identifier/data reset |
| Crash traces, installation identifiers, app version, device model, operating-system version, and technical diagnostics | Diagnose crashes and improve reliability; legitimate interests where applicable, subject to your right to object and opt out | Firebase Crashlytics | Unsent reports are deleted when collection is disabled; submitted Crashlytics data is generally retained by Firebase for 90 days before deletion begins | Reporting is on by default; turn Crash reporting off in Settings at any time |
| Consent, device/app, network, fraud-prevention, and ad-interaction information | Obtain required choices, deliver permitted native and interstitial ads, measure them, and prevent abuse; consent, legitimate interests, or legal obligation as applicable | Google User Messaging Platform and Google Mobile Ads | Under Google's retention controls and legal obligations | Use Privacy choices where available |
| IP address and routine HTTP metadata for public configuration requests, only if a Cloudflare URL is configured | Deliver a non-sensitive configuration file and secure the service; provision of the requested service and legitimate interests in security | Cloudflare | Under Cloudflare's logging and retention practices | No WaterNudge identifier or hydration data is added; safe bundled defaults are used when no URL is configured |
| Product and purchase status, only if premium products are offered | Display products, process purchases, restore entitlement, prevent fraud, and perform the purchase contract | Google Play Billing | Under Google Play's retention and legal obligations | Manage purchases, renewals, and cancellations in Google Play |
| Support email address, message, and related correspondence | Respond to your request, protect legal rights, and meet legal duties; steps at your request, legitimate interests, consent, or legal obligation depending on the message | Stackquiln and the email service used to receive the message | Until the request is resolved, then only as reasonably needed for records, security, disputes, or law | Ask for deletion; do not send hydration logs or sensitive health information |
Data stored on your device
WaterNudge stores local app data in its private Android storage. The hydration database uses SQLCipher encryption with a key protected by Android Keystore. Android cloud backup and device-to-device transfer are disabled for WaterNudge app data.
No WaterNudge account or Stackquiln backend is required. The app does not transmit your exact hydration entries, weight entry, reminder schedule, or goal to Stackquiln. Other apps or people with access to an unlocked or compromised device may still be able to see information displayed by WaterNudge.
Optional Analytics
Firebase Analytics is disabled until you grant the separate Analytics purpose in Google's consent message shown during first run. The message is configured for WaterNudge users in all regions and keeps advertising and Analytics purposes granular. You can later review or withdraw the available choices through Advertising & analytics privacy in Settings. If enabled, WaterNudge may send coarse events, such as an amount range instead of an exact hydration amount, screen or interaction categories, and ad lifecycle events. WaterNudge is designed not to send names, contact details, precise location, raw user-entered text, exact hydration logs, or payment-card details to Analytics.
When you withdraw consent, the app disables Analytics collection and requests a reset of its Analytics identifier and local Analytics data. Withdrawal does not make prior lawful processing unlawful, and aggregated statistics may no longer identify an app installation.
For a standard Google Analytics 4 property, Google currently provides a 2- or 14-month user- and event-level retention setting. Aggregated reporting data may remain beyond that setting. Because WaterNudge has no account and does not set a WaterNudge user ID, Stackquiln may be unable to associate an already uploaded event with a particular person.
Crash reporting
Firebase Crashlytics is a separate control that is enabled by default to help Stackquiln detect crashes and improve app stability. It may process crash traces, timestamps, installation or session identifiers, app/package version, device model and state, operating-system version, and exception-related technical diagnostics. WaterNudge does not intentionally attach hydration entries, exact hydration amounts, goals, reminder schedules, names, contact details, or support-message content to crash reports.
You can turn crash reporting off at any time in Settings. The preference persists across subsequent launches. Turning it off disables future collection and requests deletion of reports that have not been sent. Using Reset data, clearing app storage, or reinstalling restores app defaults, including default-on crash reporting. Reports submitted before you opted out may remain under Firebase's retention rules; Firebase states that submitted Crashlytics stack traces and associated identifiers are generally kept for 90 days before deletion from live and backup systems begins.
Ads and consent
The free production release uses Google Mobile Ads native in-feed and paced interstitial placements. Native placements are visibly labeled “Ad” and use Google-provided ad assets and click handling; WaterNudge does not disguise paid content as hydration content. Google Mobile Ads and Google's User Messaging Platform may process consent choices, IP address, device and app information, fraud-prevention signals, and ad interactions under Google's terms. WaterNudge waits until the consent service says ad requests may begin.
WaterNudge removes the Android Advertising ID permission and Android Privacy Sandbox advertising permissions. This reduces identifier access but does not prevent Google from processing other permitted connection, device, consent, fraud-prevention, or ad-delivery information. Available privacy choices can be revisited from Settings. WaterNudge does not offer a paid ad-removal product in the current release.
WaterNudge does not sell personal information and does not share it for cross-context behavioural advertising through an Advertising ID.
Public remote feature configuration
WaterNudge may request a public JSON file hosted on Cloudflare to obtain non-sensitive flags such as whether an app placement is shown and ad pacing. The HTTPS request does not add a WaterNudge user identifier, app-instance identifier, advertising identifier, hydration data, or query parameters. Like any web host, Cloudflare may process an IP address, timestamps, security signals, and routine HTTP metadata.
When no Cloudflare URL is configured, or when the response is invalid or unavailable, WaterNudge uses its last valid configuration or safe bundled defaults. WaterNudge does not use Firebase Remote Config.
Purchases
Premium features are disabled in the bundled release defaults. If premium is offered, Google Play Billing provides localized product information, processes payment, and reports purchase state. Stackquiln does not receive or store payment-card details. Google may process Google-account, transaction, device, and fraud-prevention information under Google Play's terms.
Notifications
If you enable reminders, WaterNudge asks for notification permission and schedules local notifications. The schedule remains on your device. Android scheduling, battery, and permission controls may delay or prevent notifications.
Service providers
Depending on the release and your choices, information may be processed by:
- Google Analytics for Firebase and Firebase Crashlytics, under the applicable Firebase data-processing terms.
- Google Mobile Ads and User Messaging Platform, if ads are enabled.
- Google Play, if you obtain the app or a product through Google Play.
- Cloudflare, if a public remote-configuration URL is configured.
- The email provider used to receive a message you send to the published contact address.
These providers process information for the described services and may also process service, security, or compliance information under their own notices and terms.
International transfers
Providers may process information in the United States and other countries where they or their subprocessors operate. Privacy protections may differ from those in your country. Where transfer restrictions apply, providers may rely on an adequacy decision, the EU-U.S. Data Privacy Framework and its UK or Swiss extensions where valid and applicable, Standard Contractual Clauses, or another lawful mechanism described in their terms. The provider links above contain current location and transfer information.
Legal bases
Where the GDPR, UK GDPR, or similar law applies:
- local storage and core functions are used to provide the service you request;
- Analytics relies on your consent;
- Crashlytics crash reporting relies on Stackquiln's legitimate interests in diagnosing failures and maintaining app reliability where that basis is available, balanced against data minimisation and your persistent Settings opt-out;
- support is handled to take steps at your request and, depending on the message, through consent, legitimate interests, or legal obligations;
- limited security, fraud prevention, public configuration delivery, and legal compliance may rely on legitimate interests, performance of a service, or legal obligations; and
- purchase processing is necessary to perform the transaction you request and meet related legal duties.
You can withdraw Analytics consent through Advertising & analytics privacy, and object to or disable Crashlytics processing in Settings, without affecting processing that was lawful before the change.
Your privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability; withdraw consent; and complain to a data-protection authority.
Most WaterNudge information is stored only on your device and can be viewed or erased directly. For other requests, email stackquiln@gmail.com with “WaterNudge privacy request” in the subject. Describe the feature or provider involved and the approximate date. Do not send hydration logs, government identification, or other sensitive information unless we specifically explain why limited verification is necessary.
We may ask for information reasonably necessary to verify and locate a request, respond without disclosing information to the wrong person, or preserve a legally required record. Requests are generally free, although the law may permit a reasonable fee or refusal for manifestly unfounded, excessive, or repetitive requests.
Where GDPR response periods apply, we normally respond within one month and may lawfully extend that period for a complex or numerous request after giving notice. If a request is denied or limited, we will explain the reason and available complaint rights where required.
EEA and United Kingdom
You may complain to the data-protection authority where you live, work, or believe an infringement occurred. You may contact us first so we can try to resolve the concern, but doing so does not remove your right to contact an authority.
California
If the California Consumer Privacy Act applies to Stackquiln and your information, you may have rights to know, access, correct, or delete covered personal information; receive information about categories, sources, purposes, and recipients; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing after exercising a right.
Depending on which optional features you used in the previous 12 months, the categories disclosed may include identifiers, internet or electronic-network activity, commercial information, and support correspondence. WaterNudge does not sell personal information, does not share it for cross-context behavioural advertising through an Advertising ID, and does not use sensitive personal information to infer characteristics. An authorised agent may submit a request, but we may require proof of authority and verification as permitted by law. We will respond within the time required by California law and explain any permitted extension.
Retention and deletion
Local data lasts until you reset it, clear app storage, or uninstall. Stackquiln does not operate a server copy of hydration logs. Provider-controlled records follow the provider retention described above or linked policies. Support correspondence is retained only as reasonably necessary to respond, maintain records, protect rights, prevent abuse, resolve disputes, or comply with law, after which it is deleted or de-identified where feasible.
See the Data and Deletion Guide for step-by-step controls. Deleting WaterNudge does not cancel a Google Play subscription; subscriptions must be cancelled through Google Play.
Security and incident response
WaterNudge uses private Android storage, an encrypted hydration database, Android Keystore key protection, HTTPS for configured remote requests, disabled Android backup/transfer, and data-minimising defaults. Access to provider consoles and support systems should be limited to people who need it.
No storage or transmission method is completely secure. Device compromise, operating-system vulnerabilities, provider incidents, or user actions may defeat safeguards. If Stackquiln becomes aware of a personal-data breach for which notice is legally required, affected people and authorities will be notified in the manner and time required by applicable law.
Eligibility and children
WaterNudge is intended only for adults aged 18 or older and is not directed to children. Stackquiln does not knowingly collect a child's personal information through WaterNudge. If you believe a child has provided information through an enabled third-party service or support message, contact us so the issue can be assessed and eligible information deleted.
Changes, language, and versions
We may update this policy when app behaviour, providers, or legal requirements change. Material changes will be reflected by a new effective date and, where required, an in-app notice or renewed consent. The English version controls unless mandatory local law requires otherwise.
| Date | Summary |
|---|---|
| August 2, 2026 | Moved the separate Analytics opt-in into Google's first-run consent message for all regions and retained a Settings entry point for review and withdrawal. |
| August 1, 2026 | Updated advertising disclosures for native in-feed and paced interstitial ads; confirmed premium purchases remain disabled. |
| July 30, 2026 | Changed Crashlytics to default-on crash diagnostics with a persistent Settings opt-out; Analytics remains off until opt-in. |
| July 29, 2026 | Updated product references and legal URLs for WaterNudge. |
| July 27, 2026 | Aligned the policy with independently persisted Analytics and Crashlytics opt-ins, reachable Settings controls, explicit Advertising ID and AdServices permission removal, and synchronized in-app legal links. |
| July 26, 2026 | Added structured disclosures, detailed provider retention and transfers, regional rights procedures, deletion guidance, security limitations, and version history. |
| July 25, 2026 | Initial policy. |
Contact
Publisher/controller: Stackquiln
Email: stackquiln@gmail.com