Privacy Policy
Last updated: 2026-10-01
This Privacy Policy explains how We Are So Back Ltd (“we”, “us”), a company registered in the Republic of Cyprus, handles information when you use Daily Design Challenge (the “App”).
TL;DR
- We use PostHog (EU-hosted product analytics) to understand how the App is used: which screens you open, which onboarding options you pick, which challenges you open, complete, and share, and whether the App crashed, tied to a random identifier generated on your device, not to you.
- We do not run advertising or cross-app tracking SDKs.
- Your challenge progress and preferences stay on your device.
- Subscription billing is handled by Apple. RevenueCat helps us verify it. Neither receives your name or email from us.
Who we are
We Are So Back Ltd, Cyprus. Contact: wearesobackltd@gmail.com.
We are the data controller for any personal data processed via the App. We have not appointed a Data Protection Officer because we do not meet the thresholds in GDPR Article 37.
Information we collect today
Stored only on your device (we never see it):
- Your challenge progress and preferences (via
SwiftData). - A local copy of your onboarding answers (in iOS
UserDefaults), used to personalise your daily challenge.
Sent off-device when you use the App:
Usage analytics (PostHog). As you use the App, it sends a stream of usage events to PostHog, a product analytics service we use as a processor, hosted in the European Union (PostHog EU Cloud, Frankfurt). Each event carries:
- a random identifier generated on your device when the App is first installed (a UUID stored in
UserDefaults). It is not derived from your Apple ID, your device hardware, or anything else that identifies you, and we have no way to map it back to you; - a random identifier for the current session;
- the event name and its details: the screen you opened; onboarding steps viewed and the options you chose, and the full set of your onboarding answers on completion; the paywall being shown and whether a purchase was started, completed, cancelled, or failed (never payment details); which challenges you opened, completed, and how long you spent on them; whether you shared a completed challenge and which app you shared it to (never the photos or text you shared); which videos, app links, inspiration posts, and community profiles you opened; search terms you typed inside the App; Settings actions such as restoring purchases;
- the App version and build, iOS version, device model, screen size, language and region setting, network type (Wi-Fi or cellular), whether a subscription or free trial is active, and the date of first launch;
- your IP address, which PostHog receives as part of any network request and uses to derive an approximate (city-level) location for the event. We do not use this for advertising or to track you, and it is never combined with any identity.
- Crash reports. If the App crashes, the PostHog SDK records the crash (signal or exception type, the App and OS version, and the call stack of the crashing thread) and sends it on the next launch under the same random identifier. It contains no content you created and nothing that identifies you.
The onboarding questions ask about your design focus, experience level, and goals. They do not ask for anything sensitive. We use this data only to understand how the App is used: where people drop off during onboarding, which challenges get completed and shared, and what to improve. It is not used for advertising, and it is not used to track you across other apps or websites.
- a random identifier generated on your device when the App is first installed (a UUID stored in
Subscription data. When you subscribe, restore, or open the App with an active subscription, Apple receives your Apple ID and payment information (we do not), and RevenueCat receives a randomly generated anonymous App User ID, your subscription status, and basic device identifiers provided by Apple’s servers. RevenueCat also forwards subscription events (trial started, renewal, cancellation, expiration, refund, the product and price, the store country) to PostHog under the same random identifier the App uses, so we can see how subscriptions relate to how the App is used. None of this contains your name, email, or Apple ID.
Server request data. When the App fetches content (challenges, videos, profiles, thumbnails, app icons), our backend and the third-party CDNs listed below receive standard request data including your IP address.
That is the full list. The App contains no sign-in, no profiles, no ad networks, and no cross-app or cross-site tracking technologies. The only third-party SDKs are RevenueCat (subscriptions) and PostHog (analytics and crash reports); neither is used for tracking as defined by Apple, and no advertising identifier is ever read.
Information we may collect in the future
We may, in the future, introduce additional or third-party privacy-respecting diagnostic or analytics tools (for example, Apple’s MetricKit, anonymous crash reporting, or a privacy-preserving analytics provider) to help us improve stability and usability. If we do:
- We will update this Policy with the provider name, the data they receive, and the legal basis.
- We will post the update at least 30 days before it takes effect.
- Where consent is required by law (GDPR / UK GDPR / similar), we will request your consent in-app before enabling any non-essential collection.
This forward-looking statement is here so you know what to expect. Today’s Policy still describes today’s behaviour.
How we use information
- To provide the App: verify your subscription, deliver content, restore purchases.
- To improve the App: understand onboarding drop-off, answer distribution, challenge completion, sharing, subscription behaviour, and crashes from the usage analytics and crash reports described above.
- To protect the App: prevent fraud and abuse (e.g. rate-limit our backend).
- To comply with our legal obligations (tax records for subscription transactions).
Legal bases under the GDPR
Where the GDPR applies, we rely on:
- Contractual necessity (Art. 6(1)(b)) for subscription management, content delivery, and restore purchases.
- Legitimate interests (Art. 6(1)(f)) for fraud prevention, security, operating our backend, and product analytics (improving the App). You may object to this processing at any time.
- Consent (Art. 6(1)(a)) for any non-essential third-party analytics or tracking we add in the future.
Third-party services and subprocessors
| Service | Why we use it | What they receive |
|---|---|---|
| Apple App Store / StoreKit | Process subscription purchases | Apple ID, payment info, transaction details |
| RevenueCat | Verify subscription receipts and entitlements | Anonymous App User ID, subscription status, device identifiers from Apple |
| PostHog | Product analytics and crash reporting, hosted in the EU (PostHog EU Cloud) | The usage events, device context, crash reports, and IP address described above, under the random per-install identifier |
| Cloudflare | Host our backend API and content database | IP address from requests |
YouTube CDN (img.youtube.com) | Video thumbnails | IP address and standard request data when a thumbnail loads |
| Apple iTunes Search API | Fetch artwork for referenced apps | IP address and standard request data |
| unavatar.io | Avatar images for referenced X / Twitter profiles | IP address and standard request data |
International transfers
Some service providers are located outside the EEA, including in the United States (Apple, RevenueCat, Cloudflare). Transfers of personal data outside the EEA are made under the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework where the provider is certified.
Data retention
We do not maintain user accounts. We hold no user data on our own infrastructure; the usage analytics and crash reports described above are stored by PostHog on our behalf.
- Usage analytics and crash reports (PostHog). Raw events are retained for up to 24 months from collection, then deleted. We may keep aggregate statistics derived from them (for example, the share of users who picked a given option) indefinitely; these contain no identifiers.
- Subscriptions. Apple and RevenueCat keep subscription and transaction records for the lifetime of your subscription plus the period required by accounting and tax law (typically seven years under Cypriot / EU law).
Uninstalling the App deletes all device-side data, including the random identifier, and stops all collection. Reinstalling generates a new identifier. Because the identifier is random and never leaves your device except inside these events, we cannot look up which rows belong to you; they are deleted on the schedule above. Settings > Erase App Data in the App discards the identifier immediately, so nothing recorded afterwards can be linked to what came before.
Your rights under the GDPR (EU / EEA / UK / Switzerland)
You have the right to:
- access the personal data we hold about you;
- have it rectified or erased;
- restrict or object to processing;
- portability;
- withdraw consent at any time, where consent was the legal basis;
- lodge a complaint with your supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection.
To exercise any right, email wearesobackltd@gmail.com. We respond within 30 days. Note that we cannot link analytics records to a person (see Data retention), so for those records we may be unable to identify which ones are yours (GDPR Art. 11). Uninstalling the App stops all further collection immediately.
Your rights under California law (CCPA / CPRA)
If you are a California resident:
- Categories of personal information collected in the last 12 months: identifiers (the anonymous App User ID used to verify your subscription, and the random per-install identifier used for analytics), commercial information (your subscription status), internet or other electronic network activity information (in-App interaction events), and approximate location derived from IP address by our analytics provider.
- Categories sold or shared: None. We do not sell or share personal information as defined under the CCPA, and we have not done so in the preceding 12 months. We do not engage in cross-context behavioural advertising.
- Your rights: to know, delete, correct, and non-discrimination. To exercise, email wearesobackltd@gmail.com.
Children’s privacy
The App is rated 4+ and is not directed at children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Security
All network requests use HTTPS. The analytics data described above contains no names, emails, or other direct identifiers. Our service providers maintain their own security programmes and certifications (PostHog is SOC 2 Type II certified and hosts our project in the EU).
Changes to this Policy
We may update this Policy. For material changes, we will give you at least 30 days’ notice in the App and update the “Last updated” date at the top. Material changes include new categories of data, new service providers, or new purposes of use. Non-material changes (clarifications, typo fixes) take effect when posted.
Contact
We Are So Back Ltd Cyprus wearesobackltd@gmail.com