Privacy Policy — Orthodox Rhythm
Note: This file is hosted at
https://studio.kzlab.dev/orthodox-rhythm/privacy/(see the portfolio repo’sstudio-kzlab-dev/_build/generate.py) — it is not rendered inside the Orthodox Rhythm app itself, which has its own static in-app screens atapp/legal/privacy.tsx/terms.tsx. Keep both versions in sync if either changes.
Version: 1.0.0 · Last updated: 2026-07-25
1. Data Controller
The data controller for personal data collected in connection with the Orthodox Rhythm mobile app is:
LogicLoom Kamil Zwarycz Sole proprietorship (JDG), Poland NIP: 5871749235 · REGON: 540001576 ul. Kalinowa 6L lok. 3, 81-198 Kosakowo, Poland
Contact for data protection matters: contact@kzlab.dev
Given the scale of this service (no large-scale processing of special categories of data, no systematic large-scale monitoring), a formal Data Protection Officer is not required under GDPR Art. 37. The contact above serves as the data protection point of contact.
2. What data we collect, why, and on what legal basis
Orthodox Rhythm is designed to work fully offline with no user account. The table below reflects the actual, narrow scope of data this app processes:
| Data category | Examples | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Subscription/purchase data | Device/app identifier, purchase receipt, subscription status (processed via RevenueCat) | Validate and manage your Orthodox Rhythm Pro subscription, restore purchases across devices | Art. 6(1)(b) (performance of a contract) |
| Notification permission status | Whether you granted local-notification permission | Enable the optional daily fasting-rule reminder | Art. 6(1)(a) (consent) |
We do not operate a server or database of our own for this app. All of the following stay entirely on your device and are never transmitted to us or any third party: your reading history, your prayer/fasting checklist state, your Old Calendar/New Calendar preference, any names you add to the in-app Diptychs/Commemorations feature (for your own private prayer use), and any other in-app setting.
The app reads your device’s motion sensors (magnetometer/gyroscope) only while the optional Liturgical Compass or a Great Feast icon background is actively on screen, solely to render that on-screen effect. This sensor data is processed transiently, on-device, is never stored, and is never transmitted anywhere.
We do not store payment card details — payments are handled exclusively by Apple App Store or Google Play, via RevenueCat (see §5).
3. What we do NOT collect
- Location/geolocation data.
- Microphone or camera data.
- Contacts/address book data from your device.
- Behavioral data outside the app.
- Special categories of data (GDPR Art. 9 — health, ethnicity, religious beliefs, etc.) — even though this is a religious app, we do not collect or infer anything about your personal religious practice; your fasting checklist and reading history never leave your device.
- Data for advertising or third-party behavioral profiling. We do not show ads, and we do not sell or share personal data for marketing purposes.
- No account registration exists, so we do not collect an email address, password, or name for using the app.
4. Automated processing
The app computes the Orthodox liturgical calendar (Pascha, fasting rules, feast days) using a deterministic, purely mathematical algorithm running entirely on your device. This is not automated decision-making producing legal effects under GDPR Art. 22 — it is offline calendar arithmetic, not a decision made about you as a person.
5. Data recipients (processors)
We share data only with the following trusted processors, only to the extent necessary to provide the service:
| Processor | Purpose | Location |
|---|---|---|
| RevenueCat | Subscription and entitlement management | US (Data Privacy Framework) |
| Apple App Store / Google Play | Payment processing, app distribution | US |
| Expo (EAS) | Building and distributing the mobile app | US (Data Privacy Framework) |
We do not currently use any analytics, advertising, or crash-reporting SDK in this app.
6. International data transfers
Some of the processors listed in §5 (RevenueCat, Apple/Google, Expo) may process data outside the European Economic Area. Where this occurs, transfer relies on mechanisms recognized under GDPR — in particular the EU-US Data Privacy Framework (DPF) for certified US entities, or Standard Contractual Clauses (SCCs) where DPF does not apply. Current certification status can be verified at https://www.dataprivacyframework.gov/.
7. Data retention
| Category | Retention period |
|---|---|
| Subscription/purchase data (held by RevenueCat/Apple/Google) | For as long as your subscription is active, plus their standard retention period thereafter — governed by their own privacy policies |
| Local app data (reading history, checklist, settings, Diptych/Commemoration names) | Stays on your device until you delete the app, clear its data, or remove an entry yourself; never transmitted to us |
8. Your rights
Under GDPR, you have the right to:
- Access your data — since we hold no server-side account data about you beyond what RevenueCat processes for subscription management, contact us and we will help you request your subscription/purchase data from RevenueCat or the relevant app store.
- Rectification — local app settings can be changed directly in the app at any time.
- Erasure (“right to be forgotten”) — uninstalling the app removes all local data immediately. To request deletion of any subscription-related data held by RevenueCat, contact us at contact@kzlab.dev.
- Restriction and objection to processing based on legitimate interest — contact contact@kzlab.dev.
- Data portability — not generally applicable, since we hold no server-side personal profile data for this app.
- Lodge a complaint with a supervisory authority — you may contact the data protection authority in your country of residence.
We respond to rights requests without undue delay, and no later than one month after receiving the request (GDPR Art. 12(3)).
9. Children’s data
Orthodox Rhythm is a general-audience devotional app not specifically directed at children. We do not knowingly collect personal data from children. Since the app requires no account and stores no personal data on our servers, there is minimal risk of processing children’s personal data; however, if you become aware that a child has provided us with personal information through the app’s purchase flow, please contact us at contact@kzlab.dev so we can address it.
10. Cookies
The mobile app itself does not use cookies. If this policy is hosted on a companion website, that website’s own cookie usage (if any) should be disclosed here — update this section to reflect the actual site it is deployed on.
11. Data security
- Local app data is stored using standard on-device secure storage (MMKV/SQLite), which stays sandboxed to the app by the operating system.
- Subscription data is transmitted over TLS to RevenueCat and the relevant app store.
- We do not store payment card numbers.
- We keep dependencies updated and monitor for known vulnerabilities.
12. Changes to this policy
We will provide at least 30 days’ notice of material changes to this policy via an in-app notice and/or the website hosting this document. The “last updated” date at the top of this document reflects the most recent revision.
13. Contact
- Data protection: contact@kzlab.dev
- Support: contact@kzlab.dev
- Mailing address: LogicLoom Kamil Zwarycz, ul. Kalinowa 6L lok. 3, 81-198 Kosakowo, Poland