Privacy

Privacy Policy

Developer: Koding Indonesia
Effective: 21 July 2026
Last updated: 12 August 2026
Contact: kodingindonesia@gmail.com

1. Introduction

DeleteIt ("we", "us", the "App") is an Android app that helps you ("you") clean photo and video galleries by swiping. This Privacy Policy explains what data we collect, how we use it, and your rights.

By using DeleteIt, you agree to this Policy. If you do not agree, do not use the App.

2. Data We Collect

2.1 Data that never leaves your device

DeleteIt is media-first and privacy-first. Your gallery photos and videos:

2.2 Firebase account (anonymous by default + optional Google Sign-In)

When the App is online, we automatically create a Firebase Anonymous Authentication session so weekly quota can be synchronized and subscription status can be verified. This is not a Google login—you can use core features without linking Google. Google Sign-In is required when purchasing or restoring a subscription so the purchase can be securely associated with your account.

DataPurpose
Unique Firebase UIDKey for Firestore account data (weekly quota, ad grants, subscription entitlement)
Email (only if you link Google Sign-In)Shown in Settings; ties quota/subscription across devices
Session auth tokensSecure Auth sessions

Note: Google display name and profile photo are not shown in this App version (even if Firebase Auth receives them). Google Sign-In is optional for core features, but is required to purchase/restore a subscription and for cross-device account continuity.

Without Google link, cloud data stays bound to that device’s anonymous UID. Changing devices or clearing app data without Google link usually will not carry over cloud quota/subscription.

2.3 Firestore data

Under users/{uid} we may store deletes this week, ad quota grants, week start, and last sync time. Backend-only collections store subscription entitlement (status, plan, expiry, and token hash) and the Google Play purchase token bound to the UID. This is needed for server verification, entitlement restoration, token-reuse prevention, and Play status-change notifications. Gallery media never goes to Firestore.

2.4 Payments / subscriptions

Payments are processed entirely by Google Play Billing. DeleteIt never stores or sees card/payment methods. We receive purchase status from Play. The backend stores the purchase token and required entitlement metadata (such as product, status, and expiry), but not card or payment method data.

2.5 100% Ad-Free

DeleteIt is 100% ad-free. The app contains no advertising SDKs, does not request or use the Advertising ID (AD_ID), and displays no ads whatsoever.

2.6 Analytics, crash, Remote Config & App Check

2.7 Android permissions

PermissionPurposeRequired?
Photos & videos accessCore gallery featuresYes
Partial media access (Android 14+)If you allow selected photos onlyAlternative
Internet / network stateFirebase, Play BillingYes (system)

We do not request GPS/location, contacts, camera, microphone, SMS, or Advertising ID (AD_ID).

We use data to:

  1. Run core on-device gallery features.
  2. Manage quota and account mirrors (including anonymous sessions).
  3. Sync subscription across devices (after Google Sign-In).
  4. Process Play Billing entitlement.
  5. Aggregate analytics and crash fixing.
  6. Secure the service (App Check / Play Integrity).

Legal bases (for users in GDPR-like regions):** contract/service delivery, consent (analytics where required), and legitimate interests in service security.

We do not sell your personal data and do not track you for advertising.

4. Sharing with third parties

ServiceRolePolicy
Google Firebase (Auth, Firestore, Analytics, Crashlytics, Remote Config, App Check)Accounts, mirrors, analytics, config, securityFirebase Privacy
Google Play BillingSubscriptionsGoogle Privacy

We do not share beyond this list except as required by law or to protect rights, property, or safety.

These legal web pages load fonts from Google Fonts (network request to Google). There are no first-party analytics cookies on our static legal pages.

5. Storage & retention

6. Your rights & account deletion

You may:

In-app deletion is immediate. Email requests: after identity verification, within 30 days. After in-app deletion, the App may create a new anonymous session so you can keep using it (quota resets to the current week’s default). Deleting your DeleteIt account does not cancel a Google Play subscription; cancel it separately through Play Store → Payments & subscriptions → Subscriptions.

7. Security

We use HTTPS/TLS to Firebase and rely on Google Cloud/Firebase security. No method is 100% secure.

8. Children

Not intended for children under 13 (in the EEA, national digital consent age may be higher). Not “Designed for Families.” Contact us to delete a child’s data if needed.

9. International transfers

Firebase/Google data may be processed outside Indonesia (often including the US). Google provides mechanisms such as Standard Contractual Clauses.

10. Changes

Material changes will be noted by updating the “Last updated” date above and/or via an App update when relevant. Ad grant/cap parameters may also change via Remote Config.

11. Contact