Privacy Policy
Effective Date: April 12, 2026 · Last Updated: July 26, 2026
This Privacy Policy applies to the Dam It! mobile application and website ("Application"), operated by Cornelius Pflüger Digital Solutions ("Service Provider", "we", "us", or "our"), located in Germany.
This policy is designed to comply with:
- EU General Data Protection Regulation (GDPR / DSGVO)
- German Telecommunications-Digital Services Data Protection Act (TDDDG)
- German Digital Services Act (DDG)
- Applicable U.S. privacy laws (CCPA/CPRA, COPPA)
- Google Play User Data & Accessibility API Policies
1. Accessibility Service - Prominent Disclosure
Dam It! uses the Android Accessibility Service. This permission is required for the app's core functionality and is subject to special disclosure requirements under Google Play policy.
What the Accessibility Service is used for:
- Detecting swipe gestures within short-video applications (currently YouTube Shorts, Instagram Reels, TikTok and TikTok Lite)
- Interrupting or blocking continuous scrolling behavior in real time
- Supporting users in reducing impulsive content consumption
What the Accessibility Service does NOT do:
- No personal data is collected via the Accessibility Service
- No screen content is recorded, stored, or transmitted to us or any third party
- No keystrokes, passwords, or sensitive input fields are monitored
- No data from the Accessibility Service is shared with third parties under any circumstances
- All gesture detection and blocking logic runs exclusively on-device, in real time
User Control & Consent:
- The Accessibility Service is disabled by default
- Activation requires explicit user consent via Android system settings
- Users can revoke this permission at any time via Settings → Accessibility
- Revoking the permission stops the core blocking functionality but does not affect other app features
This disclosure satisfies the Google Play Accessibility API policy requirement for a "prominent disclosure" separate from the general Privacy Policy.
2. Information We Collect
We collect only the minimum data required to operate the Application (data minimisation principle, Art. 5(1)(c) GDPR).
a) Automatically Collected Technical Data
- IP address (for network communication and security)
- Device type, operating system version
- App version and basic diagnostics (crash logs, performance data)
- General region / country (derived from IP, not stored as precise geolocation)
b) In-App Analytics (Firebase Analytics)
We use Firebase Analytics to understand which features are used, in aggregate and anonymised form. Typical events are which onboarding screen was reached and whether a purchase was started or completed.
- No advertising identifier is collected. The AD_ID permission is removed from the app manifest and ad-personalisation signals are disabled
- Events are aggregate and anonymised; they are never used to build an advertising profile or to target ads to you
- No name, email address, or content from your device is included
c) Crash Diagnostics (Firebase Crashlytics)
If the Application crashes, anonymous diagnostic information is sent automatically to Firebase Crashlytics so that we can fix the fault.
- Stack traces, device model, operating system version, and app version
- No name, email address, or content from your device is included
d) Subscription & Purchase Data (handled by RevenueCat / Google Play)
- Subscription status (active / inactive)
- Transaction identifiers issued by Google Play
- Pseudonymous device identifiers required for entitlement validation
We do not receive, store, or process full payment card details. All payment processing is handled exclusively by Google Play Billing.
e) Referral & Promo Attribution
- Google Play Install Referrer: if you reach Google Play through a dam-it.io/promo link, Google passes the referrer string to the Application on first launch. It contains only the promo or referral code - no personal data - and is used solely to apply the correct offer
- Referral records (Cloud Firestore): when a referral link is used, we store a pseudonymous, randomly generated subscription identifier issued by RevenueCat, the referral code used, whether a purchase followed, and a timestamp. This is not your name, email address, or device ID, and it cannot be traced back to you
- Promo codes are resolved entirely on-device; no promo-code redemption data is transmitted
- App Check / Play Integrity: used to confirm that requests to our database come from a genuine, unmodified install of Dam It!, as anti-abuse protection for referral rewards. It does not identify you personally
f) Website Hosting Data
The dam-it.io website is hosted by Hostinger International Ltd. (Cyprus / Lithuania). When you visit the website, Hostinger's servers automatically log standard web access data (IP address, browser type, pages visited, timestamps). This constitutes a separate processing activity under Hostinger's own privacy policy, available at https://www.hostinger.com/privacy-policy.
3. Legal Basis for Processing (GDPR Art. 6)
All personal data we process is based on one of the following legal grounds:
- Art. 6(1)(a) GDPR - Consent: Activation of the Accessibility Service; any optional data collection you explicitly agree to
- Art. 6(1)(b) GDPR - Performance of a Contract: Processing necessary to provide the app functionality, manage your subscription (e.g., verifying entitlements via RevenueCat), and apply referral or promotional offers you have chosen to redeem
- Art. 6(1)(c) GDPR - Legal Obligation: Retention of transaction data as required under German commercial and tax law (§ 257 HGB, § 147 AO)
- Art. 6(1)(f) GDPR - Legitimate Interests: Security monitoring, crash reporting, anonymised product analytics, referral-reward abuse prevention (App Check / Play Integrity), fraud prevention, and server log analysis. Our legitimate interest is the secure and stable operation of the Application. These interests are not overridden by your interests or fundamental rights given the minimal nature of data processed.
4. Cookies & Tracking Technologies
We use no advertising cookies, no tracking pixels, and no cross-site or cross-app tracking. Analytics on the website and analytics in the mobile app are two separate systems, described below.
a) Website (dam-it.io) - Umami Cloud
- Umami Cloud is a privacy-focused, cookie-less analytics service used to measure traffic on this website only
- It sets no cookies and stores or reads no information on your device beyond what is strictly necessary to deliver the page
- No personal data, persistent device identifiers, or cross-site activity is collected; all event triggers are aggregated and anonymised
- Because no non-essential information is stored on or read from your device, no consent banner is required under § 25(2) TDDDG
b) Mobile Application - Firebase Analytics
- Firebase Analytics is not cookie-based; it uses an app-instance identifier generated on your device
- The advertising ID is not collected - the AD_ID permission is removed from the app manifest and ad-personalisation signals are disabled
- Events are aggregate and anonymised and are never used for advertising, ad profiling, or behavioural targeting
- No analytics cookies and no cross-app trackers (e.g., IDFA or AAID) are used in the Application
No consent management banner (Cookie-Banner) is required or displayed on this website, as no non-essential cookies are set and no non-essential information is stored on or read from your terminal equipment (§ 25(2) TDDDG). Any technically necessary session or preference data used by the web server is covered by the legitimate interest basis (Art. 6(1)(f) GDPR) and the TDDDG exemption for essential storage operations.
5. Third-Party Service Providers
We engage the following processors / independent controllers. Each operates under its own data protection documentation:
Google Play Services & Google LLC
Role: App distribution, billing infrastructure, device integrity checks
Privacy Policy: https://policies.google.com/privacy
RevenueCat, Inc.
Role: Subscription entitlement management and receipt validation
Data processed: pseudonymous device ID, subscription status, transaction receipts
Privacy Policy: https://www.revenuecat.com/privacy
Hostinger International Ltd.
Role: Web hosting for dam-it.io
Data processed: server access logs (IP address, browser data)
Privacy Policy: https://www.hostinger.com/privacy-policy
Google Ireland Ltd. / Google LLC (Firebase)
Role: App analytics (Firebase Analytics), crash diagnostics (Crashlytics), referral-reward storage (Cloud Firestore), and integrity verification (App Check / Play Integrity)
Data processed: anonymised event counts, crash diagnostics (stack trace, device model, OS and app version), pseudonymous subscription identifier and referral code
Privacy Policy: https://firebase.google.com/support/privacy and https://policies.google.com/privacy
Umami Software, Inc.
Role: Privacy-focused usage analytics for the dam-it.io website
Data processed: Anonymized usage statistics, page views, and custom event triggers (no personal identifiers or cookies used)
Privacy Policy: https://umami.is/privacy
6. International Data Transfers
Some of our service providers (Google, RevenueCat, Hostinger) are based in or process data in the United States or other countries outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we ensure an adequate level of protection through one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914)
- EU–U.S. Data Privacy Framework (where applicable and the recipient is certified)
- Adequacy decisions issued by the European Commission
You may request a copy of the applicable transfer mechanism by contacting us at the address in Section 14.
7. Data Retention
- Subscription & transaction data: retained for the duration of the active subscription plus the statutory retention period under German tax law (10 years, § 147 AO)
- Technical logs: retained for a maximum of 90 days for debugging and security purposes, then deleted or anonymised
- Crash reports (Firebase Crashlytics): retained for 90 days (Google's default retention period), then deleted
- App analytics (Firebase Analytics): retained in aggregate form for the shortest period offered by Google, currently 14 months
- Website analytics (Umami): statistically aggregated usage data stored without personal identifiers and kept for product optimisation purposes
- Referral records (Cloud Firestore): kept until the corresponding reward has been granted and for a further 12 months for abuse and chargeback prevention, then deleted
- Accessibility Service data: not retained - all processing is transient and on-device only
You may request deletion of your personal data at any time (see Section 8).
8. Your Rights (EU / EEA Users - GDPR)
Under the GDPR, you have the following rights, exercisable free of charge by contacting us:
- Right of access (Art. 15 GDPR) - obtain confirmation and a copy of data we hold about you
- Right to rectification (Art. 16 GDPR) - correct inaccurate data
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) - including to processing based on legitimate interests
- Right to withdraw consent at any time without affecting prior processing (Art. 7(3) GDPR)
No user account - how to identify your data: Because Dam It! has no user account, we cannot look you up. To exercise a deletion request covering referral records, email contact@dam-it.io with the referral link or code you used, and we will delete the associated record.
You also have the right to lodge a complaint with a supervisory authority. In Germany, the competent authority is the data protection supervisory authority (Datenschutzaufsichtsbehörde) of your federal state, or the Federal Commissioner for Data Protection and Freedom of Information (BfDI): https://www.bfdi.bund.de.
9. Your Rights (California Residents - CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA:
- Right to know what personal information is collected, used, shared, or sold
- Right to request deletion of personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information
- Right to non-discrimination for exercising these rights
We do not sell or share personal information as defined under the CCPA/CPRA. To exercise any of these rights, contact us at contact@dam-it.io. We will respond within 45 days as required by law.
10. Children's Privacy (COPPA & GDPR)
The Application is not intended for children under the age of 13 (or under 16 where applicable under GDPR Art. 8). We do not knowingly collect personal data from children.
In compliance with the U.S. Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506), we do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent.
If you believe we have inadvertently collected personal data from a child, please contact us immediately at contact@dam-it.io and we will delete the data promptly.
11. Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encrypted data transmission (TLS/HTTPS)
- Access controls limiting data access to authorised personnel only
- Data minimisation - we collect only what is necessary
No system can guarantee absolute security. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Art. 33 GDPR.
12. No Sale or Advertising Use of Data
We explicitly confirm:
- We do not sell personal data to any third party
- We do not use personal data for advertising, profiling, or behavioural tracking
- We do not track users across unrelated apps or services
- Data collected via the Accessibility Service is never used for any purpose beyond on-device gesture blocking
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Application, legal requirements, or our data practices. Material changes will be communicated within the Application and/or on this website with an updated "Last Updated" date. Continued use of the Application after the effective date of changes constitutes acknowledgement of the updated policy.
14. Contact & Data Controller
Data Controller (Verantwortlicher i.S.d. DSGVO):
Cornelius Pflüger Digital Solutions
Inhaber: Cornelius Pflüger
Germany
Email: contact@dam-it.io
For the full legal notice (Impressum) including postal address, please see the Legal Notice page.
15. German Legal Note
The required Legal Notice (Impressum) pursuant to § 5 DDG and § 18 Abs. 2 MStV is provided at dam-it.io/legal-notice and is reachable from every page of this website via the footer link within one click.