Privacy Policy

Last updated: 2026-10-01

This Privacy Policy explains how We Are So Back Ltd (“we”, “us”), a company registered in the Republic of Cyprus, handles information when you use Daily Design Challenge (the “App”).

TL;DR

Who we are

We Are So Back Ltd, Cyprus. Contact: wearesobackltd@gmail.com.

We are the data controller for any personal data processed via the App. We have not appointed a Data Protection Officer because we do not meet the thresholds in GDPR Article 37.

Information we collect today

Stored only on your device (we never see it):

Sent off-device when you use the App:

That is the full list. The App contains no sign-in, no profiles, no ad networks, and no cross-app or cross-site tracking technologies. The only third-party SDKs are RevenueCat (subscriptions) and PostHog (analytics and crash reports); neither is used for tracking as defined by Apple, and no advertising identifier is ever read.

Information we may collect in the future

We may, in the future, introduce additional or third-party privacy-respecting diagnostic or analytics tools (for example, Apple’s MetricKit, anonymous crash reporting, or a privacy-preserving analytics provider) to help us improve stability and usability. If we do:

  1. We will update this Policy with the provider name, the data they receive, and the legal basis.
  2. We will post the update at least 30 days before it takes effect.
  3. Where consent is required by law (GDPR / UK GDPR / similar), we will request your consent in-app before enabling any non-essential collection.

This forward-looking statement is here so you know what to expect. Today’s Policy still describes today’s behaviour.

How we use information

Legal bases under the GDPR

Where the GDPR applies, we rely on:

Third-party services and subprocessors

ServiceWhy we use itWhat they receive
Apple App Store / StoreKitProcess subscription purchasesApple ID, payment info, transaction details
RevenueCatVerify subscription receipts and entitlementsAnonymous App User ID, subscription status, device identifiers from Apple
PostHogProduct analytics and crash reporting, hosted in the EU (PostHog EU Cloud)The usage events, device context, crash reports, and IP address described above, under the random per-install identifier
CloudflareHost our backend API and content databaseIP address from requests
YouTube CDN (img.youtube.com)Video thumbnailsIP address and standard request data when a thumbnail loads
Apple iTunes Search APIFetch artwork for referenced appsIP address and standard request data
unavatar.ioAvatar images for referenced X / Twitter profilesIP address and standard request data

International transfers

Some service providers are located outside the EEA, including in the United States (Apple, RevenueCat, Cloudflare). Transfers of personal data outside the EEA are made under the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework where the provider is certified.

Data retention

We do not maintain user accounts. We hold no user data on our own infrastructure; the usage analytics and crash reports described above are stored by PostHog on our behalf.

Uninstalling the App deletes all device-side data, including the random identifier, and stops all collection. Reinstalling generates a new identifier. Because the identifier is random and never leaves your device except inside these events, we cannot look up which rows belong to you; they are deleted on the schedule above. Settings > Erase App Data in the App discards the identifier immediately, so nothing recorded afterwards can be linked to what came before.

Your rights under the GDPR (EU / EEA / UK / Switzerland)

You have the right to:

To exercise any right, email wearesobackltd@gmail.com. We respond within 30 days. Note that we cannot link analytics records to a person (see Data retention), so for those records we may be unable to identify which ones are yours (GDPR Art. 11). Uninstalling the App stops all further collection immediately.

Your rights under California law (CCPA / CPRA)

If you are a California resident:

Children’s privacy

The App is rated 4+ and is not directed at children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Security

All network requests use HTTPS. The analytics data described above contains no names, emails, or other direct identifiers. Our service providers maintain their own security programmes and certifications (PostHog is SOC 2 Type II certified and hosts our project in the EU).

Changes to this Policy

We may update this Policy. For material changes, we will give you at least 30 days’ notice in the App and update the “Last updated” date at the top. Material changes include new categories of data, new service providers, or new purposes of use. Non-material changes (clarifications, typo fixes) take effect when posted.

Contact

We Are So Back Ltd Cyprus wearesobackltd@gmail.com