Privacy Policy
1. Introduction
DeleteIt ("we", "us", the "App") is an Android app that helps you ("you") clean photo and video galleries by swiping. This Privacy Policy explains what data we collect, how we use it, and your rights.
By using DeleteIt, you agree to this Policy. If you do not agree, do not use the App.
2. Data We Collect
2.1 Data that never leaves your device
DeleteIt is media-first and privacy-first. Your gallery photos and videos:
- Are never uploaded to our servers or any third-party server.
- Are never content-scanned (no AI/ML content analysis, face recognition, etc.).
- Are processed 100% on-device for swipe, grouping, and keep/delete decisions.
- “Truly freed” storage history is stored locally only and is not cloud-synced.
2.2 Firebase account (anonymous by default + optional Google Sign-In)
When the App is online, we automatically create a Firebase Anonymous Authentication session so weekly quota can be synchronized and subscription status can be verified. This is not a Google login—you can use core features without linking Google. Google Sign-In is required when purchasing or restoring a subscription so the purchase can be securely associated with your account.
| Data | Purpose |
|---|---|
| Unique Firebase UID | Key for Firestore account data (weekly quota, ad grants, subscription entitlement) |
| Email (only if you link Google Sign-In) | Shown in Settings; ties quota/subscription across devices |
| Session auth tokens | Secure Auth sessions |
Note: Google display name and profile photo are not shown in this App version (even if Firebase Auth receives them). Google Sign-In is optional for core features, but is required to purchase/restore a subscription and for cross-device account continuity.
Without Google link, cloud data stays bound to that device’s anonymous UID. Changing devices or clearing app data without Google link usually will not carry over cloud quota/subscription.
2.3 Firestore data
Under users/{uid} we may store deletes this week, ad quota grants, week start, and last sync time. Backend-only collections store subscription entitlement (status, plan, expiry, and token hash) and the Google Play purchase token bound to the UID. This is needed for server verification, entitlement restoration, token-reuse prevention, and Play status-change notifications. Gallery media never goes to Firestore.
2.4 Payments / subscriptions
Payments are processed entirely by Google Play Billing. DeleteIt never stores or sees card/payment methods. We receive purchase status from Play. The backend stores the purchase token and required entitlement metadata (such as product, status, and expiry), but not card or payment method data.
2.5 100% Ad-Free
DeleteIt is 100% ad-free. The app contains no advertising SDKs, does not request or use the Advertising ID (AD_ID), and displays no ads whatsoever.
2.6 Analytics, crash, Remote Config & App Check
- Firebase Analytics & Crashlytics (after consent where required): feature events (e.g. app open, session start/complete, swipe, delete confirmed, paywall, subscribe, account deleted)—no photo/video content or filenames. Plus device model, Android version, install ID, crash stacks.
- Firebase Remote Config: product parameters so we can tune without always shipping a Play Store update. A weekly-quota Remote Config key exists, but this version still uses the in-app default (100/week).
- Firebase App Check (Play Integrity on release builds): helps protect backends from abuse.
2.7 Android permissions
| Permission | Purpose | Required? |
|---|---|---|
| Photos & videos access | Core gallery features | Yes |
| Partial media access (Android 14+) | If you allow selected photos only | Alternative |
| Internet / network state | Firebase, Play Billing | Yes (system) |
We do not request GPS/location, contacts, camera, microphone, SMS, or Advertising ID (AD_ID).
3. Legal bases & how we use data
We use data to:
- Run core on-device gallery features.
- Manage quota and account mirrors (including anonymous sessions).
- Sync subscription across devices (after Google Sign-In).
- Process Play Billing entitlement.
- Aggregate analytics and crash fixing.
- Secure the service (App Check / Play Integrity).
Legal bases (for users in GDPR-like regions):** contract/service delivery, consent (analytics where required), and legitimate interests in service security.
We do not sell your personal data and do not track you for advertising.
4. Sharing with third parties
| Service | Role | Policy |
|---|---|---|
| Google Firebase (Auth, Firestore, Analytics, Crashlytics, Remote Config, App Check) | Accounts, mirrors, analytics, config, security | Firebase Privacy |
| Google Play Billing | Subscriptions | Google Privacy |
We do not share beyond this list except as required by law or to protect rights, property, or safety.
These legal web pages load fonts from Google Fonts (network request to Google). There are no first-party analytics cookies on our static legal pages.
5. Storage & retention
- Local: preferences, swipe staging, “truly freed” history—removed on uninstall/clear data.
- Firestore: while the UID is active; in-app account deletion removes quota, entitlement, and purchase-token bindings associated with the UID.
- Analytics/crash/Play: per Google retention. Google-managed Play transaction history is not removed by deleting a DeleteIt account.
6. Your rights & account deletion
You may:
- Request access / correction / restriction / objection regarding account data (email us; no automatic in-app export yet).
- Delete your account & related data via Settings → Hapus Akun & Data (Delete Account & Data), the Account deletion page, or email kodingindonesia@gmail.com with subject “Hapus Akun DeleteIt” / “Delete DeleteIt Account”.
- Withdraw consent for ads/analytics via UMP (when shown).
- Revoke media permission in Android Settings (core features will stop).
- Where applicable, lodge a complaint with your local data protection authority.
In-app deletion is immediate. Email requests: after identity verification, within 30 days. After in-app deletion, the App may create a new anonymous session so you can keep using it (quota resets to the current week’s default). Deleting your DeleteIt account does not cancel a Google Play subscription; cancel it separately through Play Store → Payments & subscriptions → Subscriptions.
7. Security
We use HTTPS/TLS to Firebase and rely on Google Cloud/Firebase security. No method is 100% secure.
8. Children
Not intended for children under 13 (in the EEA, national digital consent age may be higher). Not “Designed for Families.” Contact us to delete a child’s data if needed.
9. International transfers
Firebase/Google data may be processed outside Indonesia (often including the US). Google provides mechanisms such as Standard Contractual Clauses.
10. Changes
Material changes will be noted by updating the “Last updated” date above and/or via an App update when relevant. Ad grant/cap parameters may also change via Remote Config.
11. Contact
Email: kodingindonesia@gmail.com