Privacy Policy
Intimassy ("the App") is developed and operated by Significant Inc, a sole proprietorship based in Bonn, Germany. The App is available for Android and iOS. This Privacy Policy explains how we collect, use, store, retain, and delete your personal data, including health and sensitive data, when you use the App on either platform. An earlier Android-only release ("the legacy Android version") has been discontinued; Section 15 describes its data practices for anyone still using it.
The App asks you to review and accept this policy before you start using it. You give that consent in the App, by ticking a box on a screen that shows you this policy. You are not asked to consent by simply installing or opening the App. If you do not agree, do not accept, and the App will not process your data.
1. Health and Sensitive Data We Collect
Intimassy is an intimate activity tracker. Due to the nature of the App, we collect and process health and sensitive personal data as defined under GDPR Article 9. This data is only collected when you voluntarily enter it into the App.
The following health and sensitive data may be collected:
Sexual Activity Logs (Entries)
- Date of activity
- Duration (in minutes)
- Personal rating
- Safety status (whether protection was used)
- Initiator (who initiated: you, your partner, both, or spontaneous)
- Orgasm counts (yours and your partner's)
- Personal notes
Activity Details
- Activity types (e.g., casual, oral, anal, and other sexual activity categories)
- Places where activity occurred (e.g., bedroom, hotel, car, and other locations)
- Sexual positions used, including custom positions with intensity levels
- Partners involved in the activity
Partner Information
- Partner name
- Partner gender
- Relationship type
- Date added
- Personal notes about the partner
- Partner profile photo
Menstrual Cycle Data
Marking period days is optional. Nothing here is collected unless you use that feature. You can mark days for yourself, and you can keep a separate set of days for a partner you have added.
- Days you have marked as period days, for yourself or for a partner
- The settings and corrections you apply to the estimate. This includes, for example, a cycle length, days that should not start a new cycle, cycles left out of the estimate, and how the feature shows on your calendar.
From these days the App calculates an estimated next period and an estimated fertile window. The estimate is calculated on your device. The App does not upload the estimate. The days you mark are stored in your cloud backup like your other data, as described in Section 5. These estimates are informational only. They are not medical advice and must not be used as a contraceptive method or as a way to plan a pregnancy.
Photos
- Intimate photos attached to activity entries
- Partner profile photos
All health and sensitive data listed above is used to provide you with the core features of the App: tracking, reviewing, and analyzing your intimate activity history for your personal use.
We also derive a small number of coarse usage measures from this data and include them in our analytics, to understand how the App is used and improve it. These are counts and broad ranges only — for example whether you have logged no entries, a few, or many, and roughly how recently. The content of your data is never sent to any analytics provider. We do not send your entries, notes, photos, partner names, activity types, places, positions, ratings, orgasm counts, or protection status to Firebase Analytics or to any other third party for analytics purposes.
2. Personal Data We Collect
When you create an account, we collect:
- Email address
- Name or nickname
- Gender
- Authentication provider used (Google, Apple, or email/password)
- Firebase User ID (a unique identifier assigned to your account)
In-App Purchase Information
- Product IDs of items purchased
- Purchase tokens or receipts (for verification with Google Play or the Apple App Store)
- Order / transaction IDs
- Purchase and entitlement status (managed via RevenueCat, keyed to your account ID)
Problem Reports
If you report a problem from inside the App, we store what you wrote, your account identifier, and the time you sent it. Please do not include details in that message you would rather not have stored. We keep a report until we have dealt with it, and we delete it when you delete your account.
3. Automatically Collected Data
The following data is collected automatically when you use the App:
- Device information (manufacturer, model, operating system version)
- App version
- Timezone and language preferences
- Crash reports and error logs (via Firebase Crashlytics)
- App usage analytics (screen views, feature usage, and the coarse usage measures described in Section 1, via Firebase Analytics)
The current version of the App does not send push notifications and does not collect a push notification token. If we add reminders later, we will use Firebase Cloud Messaging, update this policy, and ask you to review it again before that starts.
4. How We Use Your Data
We use your data for the following purposes:
- Service Provision: To provide you with the core features of the App, including activity tracking, statistics, partner management, and cloud backup/sync.
- Cloud Backup and Sync: To securely back up and restore your data across devices using your account.
- Analytics: To understand how the App is used and improve our services. This analytics data is pseudonymous and is linked to an account identifier (your Firebase User ID), so that usage can be understood consistently across your devices. It consists of app usage events and coarse usage measures, never the content of your entries.
- Advertising: To display advertisements within the App (via Google AdMob). We do not ask for tracking permission and we do not use your data to personalise the ads you see; they are contextual only. We do not sell or share your personal data for cross-context behavioural advertising. You can remove ads entirely through an in-app purchase.
- Aggregated Community Statistics: To provide anonymized, aggregated statistics (e.g., average activity frequency) to all users. These are computed only from accounts that have accepted this policy. No individual data is identifiable in these statistics.
- Purchase Verification: To verify in-app purchases and manage your feature entitlements.
- Customer Support: To respond to your support requests and problem reports.
- Security: To detect and prevent fraud, abuse, and security incidents.
5. Data Storage and Security
Local Storage
Your data is stored locally on your device in a SQLite database. This data is protected by the operating system's built-in application sandboxing on both Android and iOS.
Cloud Storage
If you use the cloud backup feature, your data is stored in Firebase Realtime Database and Firebase Storage (operated by Google).
Encryption
We take the security of your sensitive data seriously:
- The contents of your backup are encrypted using strong, industry-standard encryption before being uploaded to our servers. This includes your activity entries, partner information, app settings, and profile details. We intend to encrypt new kinds of backup data the same way, and we will update this section if that changes.
- Data is encrypted in small units on your device before upload.
- Photos are encrypted before being uploaded to Firebase Storage.
- The app does not write your email address into the backup. It is held in your Firebase Authentication account. Backups and account records created by older versions of the app may still contain it; updating the app and making a new backup removes it from the backup.
- Some items are not encrypted, and we would rather say so than round the claim up. These are technical values the app generates itself — for example your account identifier, internal record identifiers, the time of a backup, a counter we use to order backups, an identifier for the device that wrote it, and how many records of each kind a backup holds. Values like these are not text you entered in the app. One exception is the name you give a custom place: it is stored unencrypted, because it is used as the storage key for that place. If you would rather a place name not be stored that way, name it something that means nothing to anyone else. Backups made with older versions of the app may also hold some of your data unencrypted, including profile details; updating the app and making a new backup encrypts or removes those values.
- Encryption keys are derived using industry-standard key derivation functions.
- All data in transit is protected by HTTPS/TLS encryption.
- This encryption protects your data at rest on our servers and in transit against unauthorized access.
What We Can Decrypt, and Why
We want to be plain about one point. We hold the key material for your backup, so we are technically able to decrypt it. This is not end-to-end encryption, and we do not claim that we cannot read your data. We decrypt it only for the purposes below:
- Aggregated community statistics. As described in Section 4, and only for accounts that have accepted this policy.
- Storage housekeeping. To find photo files that no backup refers to any more, so we can delete them.
- Data format migrations. To convert stored data to a newer format, such as the change that moved profile details into the encrypted part of the backup. Data is re-encrypted and stays in place.
We do not read your data for any other reason. If we ever add a new purpose, we will list it here and ask you to review this policy again before it starts.
Data Location
Your cloud data is processed and stored on Google Cloud infrastructure (Firebase), which may include servers located in the United States and other countries. See Section 11 for information about international data transfers.
6. Data Retention
Active Accounts
Your data is retained for as long as your account remains active. You can access, modify, or delete your data at any time.
Inactive Accounts
We may remove the stored data of accounts that have been inactive for an extended period. This may include accounts that have an active in-app purchase. How long an account must be inactive before it qualifies, and when the cleanup runs, are decided by us and may change at any time. The cleanup removes:
- Your user profile, cloud backups and preferences in Firebase Realtime Database
- Your photos in Firebase Storage
The cleanup does not remove your Firebase Authentication account, your purchase records, or problem reports you sent us. You can still sign in afterwards. You can delete your account in full at any time, as described in Section 7. An active in-app purchase does not by itself prevent this cleanup.
Before the cleanup removes your data, we keep a copy of it for one month, so that we can restore it if the cleanup needs to be reverted. That copy is protected in the same way as the data described in Section 5. After one month, the copy is deleted permanently.
Local Data
Local data stored on your device is deleted when you uninstall the App. Cloud data is not affected by uninstalling the App and will remain until you delete your account or the inactive account cleanup occurs.
Cloud Backups
Cloud backups are retained until you delete your account, manually clear your data, or your data is removed through the inactive account cleanup process.
Purchase Records
Purchase verification records (order IDs, purchase tokens, product IDs) are retained for as long as your account exists to prevent duplicate charges and to verify your entitlements.
Crash Reports and Analytics
Crash reports and analytics data are retained according to Firebase's standard retention policies (typically 90 days for crash data, 14 months for analytics data).
7. Data Deletion
In-App Account Deletion
You can delete your account and all associated data directly within the App using the account deletion option on the settings page. This permanently and irreversibly deletes:
- All local data (the database on your device)
- All app settings stored on your device, including your app-lock PIN, your theme, your analytics choice, and your record of accepting this policy
- All data in Firebase Realtime Database (your user profile, all cloud backups, all preferences)
- Any problem reports you sent us from inside the App
- All files in Firebase Storage (all uploaded photos)
- Your Firebase Authentication account
We also instruct RevenueCat to delete the customer record held for your account. If RevenueCat cannot be reached at that moment, the rest of your deletion still completes, and you can contact us to have that record removed. Google Play and the Apple App Store keep their own record of any purchase you made; we cannot delete those, and they are governed by the policies of those stores.
Deletion by Email Request
You may also request deletion of your account and data by emailing us at:
We will process your request within 30 days.
What Happens After Deletion
- Deletion is permanent and cannot be undone. We cannot recover your data after deletion.
- Aggregated, anonymized statistical data that was derived from your activity (and that cannot be used to identify you) may be retained.
What Happens When You Uninstall
- Uninstalling the App deletes all local data stored on your device.
- Cloud data (backups, photos, account) is NOT deleted by uninstalling. To delete cloud data, you must use the in-app account deletion option or contact us by email before uninstalling.
- If you uninstall without deleting your account, your cloud data may be removed by the inactive account cleanup described in Section 6.
8. Third-Party Services
We use the following third-party services. Each service may collect and process data according to its own privacy policy:
Firebase Authentication (Google)
- Data shared: Email address, display name, authentication credentials, sign-in metadata
- Purpose: User account management and authentication
- Privacy Policy: firebase.google.com/support/privacy
Firebase Realtime Database (Google)
- Data shared: Encrypted user data, encrypted backups
- Purpose: Cloud storage and backup of user data
- Privacy Policy: firebase.google.com/support/privacy
Firebase Storage (Google)
- Data shared: Encrypted photos
- Purpose: Cloud storage of user-uploaded photos
- Privacy Policy: firebase.google.com/support/privacy
Firebase Analytics (Google)
- Data shared: App usage events, device information, user properties (coarse usage measures, never entry content), Firebase User ID
- Purpose: Understanding App usage patterns to improve our services
- Privacy Policy: firebase.google.com/support/privacy
Firebase Crashlytics (Google)
- Data shared: Crash reports, stack traces, device information, app version
- Purpose: Identifying and fixing bugs and crashes
- Privacy Policy: firebase.google.com/support/privacy
Sign in with Apple (Apple)
- Data shared: Apple ID credential, email address (or Apple's private relay address), name
- Purpose: User account sign-in on iOS
- Privacy Policy: apple.com/legal/privacy
Google AdMob (Google)
- Data shared: Device information, ad interaction data, IP address
- Purpose: Displaying contextual advertisements within the App
- Note: Every ad request the App makes is marked as non-personalised, so your data is not used to select the ads you see.
- Note: No advertising identifier is available to us on either platform. On Android the App removes the advertising ID permission from the build. On iOS we do not show the App Tracking Transparency prompt, so there is no IDFA.
- Note: You can remove all advertising by purchasing the "Remove Ads" feature within the App
- Privacy Policy: policies.google.com/privacy
Google Play Billing (Google) and Apple App Store (Apple)
- Data shared: Purchase tokens/receipts, order and transaction IDs, product IDs
- Purpose: Processing in-app purchases on Android (Google Play) and iOS (App Store)
- Privacy Policies: policies.google.com/privacy, apple.com/legal/privacy
RevenueCat (RevenueCat, Inc.)
- Data shared: Purchase tokens/receipts, product IDs, an app user ID derived from your account, device and app metadata
- Purpose: Verifying in-app purchases and managing your feature entitlements across devices and platforms
- Note: We instruct RevenueCat to delete your customer record when you delete your account.
- Privacy Policy: revenuecat.com/privacy
9. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds under GDPR Article 6:
Explicit Consent (Article 6(1)(a) and Article 9(2)(a))
For processing health and sensitive data (sexual activity logs, partner information, menstrual cycle data, intimate photos), we rely on your explicit consent, which you provide when you create an account and begin using the App. You may withdraw your consent at any time by deleting your account.
This also covers the coarse usage measures described in Section 1 that are derived from your entries (for example whether you have logged no entries, a few, or many). Because they are derived from health and sensitive data, we rely on your explicit consent for them as well, and not on legitimate interest.
Analytics is not needed to run the App, so it is not part of the consent you give to use it. You can turn usage analytics off at any time under Settings, without losing access to any feature. Turning it off stops further collection and clears the usage measures we hold about your account.
Performance of Contract (Article 6(1)(b))
For processing data necessary to provide the App's services to you, including account management, cloud backup, and purchase verification.
Legitimate Interest (Article 6(1)(f))
For processing data for general app analytics that is not derived from your entries (screen views, feature usage, device and app information, purchase events), security (to detect and prevent abuse), and crash reporting (to maintain App stability). We have assessed that these interests do not override your rights and freedoms.
10. Your Rights Under GDPR
If you are in the European Economic Area (EEA) or in a jurisdiction with similar data protection laws, you have the following rights:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate personal data. You can also update your data directly within the App.
- Right to Erasure: You may request deletion of your personal data. You can do this directly in the App (via the account deletion option on the settings page) or by contacting us.
- Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to Restriction of Processing: You may request that we restrict the processing of your personal data under certain circumstances.
- Right to Object: You may object to the processing of your personal data where we rely on legitimate interest, as set out in Section 9. Where we rely on your explicit consent instead, the Right to Withdraw Consent below applies.
- Right to Withdraw Consent: You may withdraw your consent at any time. For analytics, use the usage analytics switch in Settings; you keep full use of the App. For the health and sensitive data the App exists to store, withdrawing consent means deleting your account, because that data is the service. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
- Right to Lodge a Complaint: You may file a complaint with a supervisory authority. In Germany, this is the Federal Commissioner for Data Protection and Freedom of Information (BfDI) or your relevant State Data Protection Authority. If you are elsewhere in the EU, you may contact your local Data Protection Authority (DPA).
To exercise any of these rights, contact us at info@centertable.club or centertableinc@gmail.com. We will respond within 30 days.
11. International Data Transfers
Your data may be transferred to and processed in countries outside of the European Economic Area (EEA), including the United States, as our cloud infrastructure is provided by Google (Firebase), which operates servers globally.
These transfers are safeguarded by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Google's compliance with applicable data protection frameworks
- Encryption of your data before transfer
These safeguards, not your consent, are what makes the transfer lawful. Standard Contractual Clauses are the mechanism we rely on under Chapter V of the GDPR.
12. Children's Privacy
Intimassy is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a person under 18, we will take steps to delete that data promptly.
If you believe that a child under 18 has provided us with personal data, please contact us at info@centertable.club.
13. In-App Purchases
The App offers one-time in-app purchases (for example: Platinum Pack, Lock Feature (PIN/biometric app lock), Limitless Image Gallery, Limitless Partners, and Remove Ads) and auto-renewing subscriptions (for example: monthly, multi-month, and annual premium packages). Subscription billing, renewal, and cancellation are handled by Google Play or the Apple App Store.
When you make an in-app purchase:
- The transaction is processed by Google Play (on Android) or the Apple App Store (on iOS). We do not collect or store your payment method details (credit card numbers, bank account information).
- Purchase tokens/receipts, transaction IDs, and product IDs are processed by RevenueCat to verify your entitlements and prevent duplicate charges. Entitlements are keyed to your account, so purchases follow your account across devices and platforms.
- Purchase records are retained for as long as your account exists. Google Play and the Apple App Store keep their own transaction records under their own policies, and those are not ours to delete.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this policy.
For significant changes, we will notify you via email (if we have your email address) and/or through an in-app notice.
When a new version of this policy changes how we process your health and sensitive data, the App asks you to review and accept it again before you continue using it. Your earlier consent is not carried over.
We encourage you to review this Privacy Policy periodically.
15. The Legacy Android Version (Discontinued)
An earlier Android-only version of Intimassy is no longer distributed and no longer receives updates. If you still have it installed, its data practices differ from everything described above, and this section applies to you instead. We recommend updating to the current version.
In the legacy Android version:
- All your activity data stays on your device. There is no account, no sign-in, and no cloud backup, so we never receive your entries, partners, positions, or photos.
- Because there is no account, there is no in-app account deletion. Uninstalling the App removes all of its local data. There is a "clear data" option in its settings that erases your entries, partners, positions, and places.
- Any backup you create is a file on your device that you choose to share. Where it goes after that is up to you.
- It contains an anonymous identifier used to check purchases with RevenueCat, and to group analytics events.
- It sends usage events to Firebase Analytics and to Meta (Facebook app events), and crash reports to Firebase Crashlytics. It has no analytics opt-out switch.
- It uses OneSignal to deliver push notifications, and Storyly to display story content. Both collect device identifiers of their own.
- It shows no advertisements.
Third-party policies: facebook.com/privacy/policy, onesignal.com/privacy_policy, appsamurai.com/privacy-policy (Storyly), firebase.google.com/support/privacy, revenuecat.com/privacy.
To ask about data held for the legacy version, contact us at info@centertable.club.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: info@centertable.club
- Email: centertableinc@gmail.com
- Significant Inc, Germany