Privacy Policy
Privacy Policy
Last updated: June 14, 2026
1. Introduction
This Privacy Policy explains how LeelaClue ("the App", "we", "us") handles your data. Your privacy is important to us. LeelaClue is designed with a privacy-first approach — the application works without a user account, and the only identifier linked to your usage is a randomly generated, anonymous UUID stored on your device. An optional sign-in with your Apple or Google account exists solely to protect in-app purchases; it is never required and does not create a user profile (see Section 3).
2. Data Collection and Storage
LeelaClue does not collect your name, email address, phone number, postal address, contacts, location, photos, or any government identifier. The application works without registration.
- Local Data: All card spreads, reflection text, daily practices, reminder settings, and your chosen display name are stored exclusively on your device using the system's standard preferences storage (
SharedPreferences). They are removed when you uninstall the application. - Anonymous UUID: On first launch, the application generates a random UUID and stores it in the system's standard preferences storage on your device. This storage is included in your device's operating-system backup (Android Auto Backup / iCloud backup), so the UUID — and with it your Clues balance — can survive a device migration when you restore from a backup. The UUID cannot be linked to your personal identity; access to the associated server record is protected by server-side security checks, not by keeping the identifier secret.
- Server-Side Ledger: To support the in-app Clues virtual currency, the UUID is paired server-side with a Clues balance, a one-time welcome-gift flag, and (if you have opted in) an analytics-consent timestamp. If you use the optional sign-in (Section 3), the ledger record additionally stores the opaque account identifier that links your balance to your Apple or Google account. No other data is stored against the UUID.
- No Account Required: LeelaClue does not require user registration or account creation.
3. Optional Sign-In with Apple or Google
LeelaClue has no user accounts of its own. To still let you recover purchased Clues after a reinstall or on a new device, the App offers an optional sign-in with the Apple or Google account you already use for app-store purchases.
- Entirely Optional: Sign-in is offered only on the purchase (Dakshina) screen. Every feature of the App works without it. The only consequence of not signing in is that purchased Clues remain tied to the current installation and cannot be restored on another device.
- Purpose Limitation: Sign-in is used exclusively to protect purchased Clues and to restore them on a new device (one Clues balance per account). It is not used for marketing, profiling, or any other purpose.
- What We Receive: The sign-in is processed by Firebase Authentication and yields a cryptographically signed token. Our server verifies this token and stores only: an opaque account identifier (a random string issued by Firebase — not your email address), its link to your anonymous UUID, the sign-in provider (Apple or Google), the platform, the app version, and timestamps.
- What We Never Store: Your email address and your name are not stored, displayed, or transmitted to our backend — even though the Apple or Google sign-in dialog may mention them.
- Sign-Out: You can sign out at any time on the Dakshina screen. To have the server-side account link deleted, contact us (see Section 7).
4. Data You Provide
The App allows you to enter the following types of data, all stored locally on your device:
- Reflection text and notes attached to card spreads
- Daily-practice tasks and reminder settings
- A display name (optional, used only for in-app greetings)
The text of your intent and your card selection are transmitted to our Cloud Functions only when you explicitly invoke an AI feature — see Section 6.
5. Third-Party Services
LeelaClue uses the following third-party services:
- Google Firebase: Cloud Functions and Firestore (hosted in EU-Frankfurt,
europe-west3) host the Clues balance ledger and route AI requests. Google Firebase's privacy policy applies: https://policies.google.com/privacy. - Firebase Authentication (only if you use the optional sign-in): Verifies your Apple or Google sign-in and issues the opaque account identifier described in Section 3. Google's privacy policy applies: https://policies.google.com/privacy.
- Firebase App Check: Every request from the App to our backend carries a device-integrity attestation (Play Integrity on Android, App Attest on iOS). It confirms that the request comes from an unmodified app on a genuine device and is used solely to block bots and abuse. The attestation is performed by Google (and, on iOS, Apple) and contains no personal data.
- Google Gemini: AI processing for intent refinement, personalized guidance questions, generated practices, and spread summaries. See Section 6 for the specific data handling.
- Google Analytics for Firebase (optional, opt-in): When you explicitly enable analytics in Settings, anonymous usage events (screens visited, rituals completed) are sent to Firebase Analytics. No reflection text or personal content is ever transmitted. Personalized advertising is disabled (
allow_personalized_ads = false); the Android Advertising ID permission is stripped from the build. You can turn analytics off at any time in Settings. - RevenueCat: Manages in-app purchases of Clues on top of the Apple App Store and Google Play. RevenueCat receives your anonymous UUID (used as its App User ID — no name or email) and the platform receipt / transaction metadata returned by Apple or Google. RevenueCat's privacy policy: https://www.revenuecat.com/privacy.
- Apple App Store / Google Play Store: Clue purchases are processed through the respective platform. Their privacy policies apply to those transactions.
No personal data from the App is shared with these services beyond what is required for the function described.
6. AI Data Processing
Leela Guru — AI Features
LeelaClue includes optional AI features ("Leela Guru") that send specific request data to our Cloud Functions, which then call Google Gemini. The features are: intent refinement, personalized guidance questions, generated practice suggestions, and spread summaries.
- Data Minimization: We do not send any personally identifiable information (PII). The data sent per request is limited to: the intent text you typed, the names and standard questions of the cards you drew, your active reflection text (only when requesting a summary), and the active interface language (
en,de, orru). - No Data Retention: AI requests are processed in real-time. Neither LeelaClue nor Google stores these requests on external servers after the result is returned to your device.
- No Model Training: Per our Google Cloud configuration, Google does not use your input to train or improve the Gemini models.
- Local Finality: Once the AI response is returned, it is saved exclusively on your device alongside the corresponding spread.
7. Account and Data Deletion
Deletion is available inside the app and is the primary method. Open Settings → Delete Account & Data and confirm. This permanently and immediately:
- deletes the server-side ledger entry (your Clues balance, purchase history, the one-time welcome-gift flag, and any analytics-consent timestamp);
- deletes the link to your Apple/Google account and the associated authentication account (the opaque
authUid), if you used the optional sign-in; - deletes your subscriber record at RevenueCat (our purchase processor); and
- erases all on-device data (card spreads, reflections, settings) and the anonymous UUID, returning the app to first-run onboarding.
The Apple App Store / Google Play transaction receipts are retained by Apple/Google for legal and accounting reasons and cannot be removed by us or RevenueCat.
If you already removed the app: reinstall it, sign in with the same Apple/Google account, then run Settings → Delete Account & Data.
Multiple devices: if you use the same Apple/Google account on more than one device, run Delete Account & Data on each of them. After deletion on one device the others lose access — their Clues balance reads 0 and correct operation is not guaranteed until they are also reset or reinstalled.
Email fallback: you can also request deletion by emailing leelaclue@gmail.com with the subject "Data deletion". If you used the optional sign-in, name the Apple or Google account you signed in with. Note that for Apple "Hide My Email" users the address we receive is an anonymous relay, so we may be unable to match an email request to your record — in-app deletion is the reliable route.
Processing time: in-app deletion is immediate; emailed requests are processed within 30 days. No data is retained for other purposes.
8. Your Rights (GDPR)
You have the right to access, correct, delete, and obtain a copy of any personal data we process, to object to processing, and to lodge a complaint with the data-protection supervisory authority responsible for the operator (LfDI Baden-Württemberg, https://www.baden-wuerttemberg.datenschutz.de). To exercise these rights, contact us at the email below.
9. Children's Privacy
LeelaClue is not intended for use by children under 16. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected in the application with an updated "Last updated" date.
11. Contact
If you have questions about this Privacy Policy, please contact:
Irene Engelko | leelaclue@gmail.com