Privacy Policy

Chainfy Mobile Application

Last Updated: January 2026

1. Introduction

This Privacy Policy describes how Chainfy ("we," "us," or "our") collects, uses, and protects your personal information when you use our mobile application ("App"). We are committed to protecting your privacy and being transparent about our data practices.

Data Controller: Mustafa Yılmaz

Contact Email: codermuss@gmail.com

By using the App, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

Account Information:

  • Email address (if you register with email)
  • Name
  • Authentication credentials (stored securely, never in plain text.)

Habit Tracking Data:

  • Habit chains you create
  • Daily progress and completion records
  • Notes and annotations
  • Reminder schedules and preferences
  • Statistics and analytics data

2.2 Information Collected Automatically

Device Information:

  • Device type and model
  • Operating system version
  • App version
  • Unique device identifiers
  • IP address (for server communication)

Usage Information:

  • App features you use
  • Time spent in the App
  • Crash reports and error logs
  • Performance metrics

3. How We Use Your Information

We use the information we collect to:

  • Provide and Improve the Service: Create and maintain your account, store and sync your habit tracking data across devices, deliver push notifications and reminders, process subscription transactions, provide customer support
  • Cloud Synchronization Service: Sync your data across multiple devices in real-time, maintain secure backups of your data, ensure data consistency and availability
  • Push Notification Service: Send reminder notifications at your specified times, deliver achievement and milestone notifications, provide important service updates
  • Analytics and Improvement: Understand how users interact with the App, identify and fix bugs and performance issues, improve App features and user experience, analyze subscription conversion and retention
  • Legal Compliance: Comply with applicable laws and regulations, respond to legal requests and court orders, protect our rights and prevent fraud

4. Data Storage and Security

4.1 Data Storage

  • Your data is stored on secure cloud servers
  • Data is encrypted in transit using HTTPS/TLS
  • Data is encrypted at rest using industry-standard encryption
  • We use PostgreSQL databases with proper access controls

4.2 Data Retention

  • We retain your data for as long as your account is active
  • If you delete your account, we delete your data immediately upon your request
  • Some anonymized analytics data may be retained for longer periods
  • Legal obligations may require us to retain certain data

4.3 Security Measures

  • Secure authentication and authorization
  • Regular security audits and updates
  • Access controls and monitoring
  • Data backup and disaster recovery procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

5. Third-Party Services

We use the following third-party services that may collect information:

  • Firebase (Google): Analytics, crash reporting, push notifications - Privacy Policy
  • RevenueCat: Subscription management and analytics - Privacy Policy
  • Apple App Store / Google Play Store: Payment processing and subscription management
  • OAuth Providers (Google, Apple): User authentication

7. Your Rights and Choices

7.1 Access and Portability

  • You can access your data through the App
  • Pro subscribers can export their data in CSV or JSON formats
  • You can request a copy of your data by contacting us

7.2 Correction and Deletion

  • You can update your account information in the App settings
  • You can delete your account and all associated data at any time
  • Account deletion is immediate and permanent - it cannot be undone
  • Once deleted, your data cannot be recovered

7.6 European Economic Area (EEA) Rights

If you are located in the EEA, you have additional rights under GDPR:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to certain types of data processing
  • Right to Withdraw Consent: Withdraw consent for data processing

To exercise these rights, contact us at codermuss@gmail.com.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email:

codermuss@gmail.com

Data Protection Contact: codermuss@gmail.com

Response Time: We aim to respond to all inquiries within 30 days.