Privacy Policy
Effective from 1 December 2026
In short: we don’t send your steps, workout minutes or location to the server. They stay on your phone. The server holds only what a shared streak with a buddy and the optional backup can’t work without — nickname, colour, streak length and the status of today.
Who is responsible
The controller of your personal data is Lukas Slehofer, Kurzova 2222/16, Praha 5, company ID (IČO) 668 99 095. You can write to us at help@tadapp.eu.
An app without accounts
Tada! has no accounts. You don’t enter an email address or a password, and you never sign in anywhere. Your phone creates a random key that the app uses to identify itself to the server when needed — there is no other identity.
If you use the app without a buddy and don’t turn on backup, it sends nothing to our server that belongs to you — only anonymous counters, which can be switched off. The whole calculation of active days and your entire history stay on your phone.
Health data
The app reads two things from Apple Health or Health Connect: step count and workout minutes. It asks for nothing else — not heart rate, distance or calories.
This data is processed only on your phone. It serves a single purpose: deciding whether a day was active. It is never sent to the server, in any form.
You grant access to health data yourself in a system dialog, and you can withdraw it at any time in your phone’s settings. Without it, the app can’t count active days.
What is on the server
A record on the server is created only once you give a reason for it — your first shared streak with a buddy or in a group, or turning on backup. Until then, we know nothing about you at all.
Anonymous identity
- a random identification number (UUID) that is not derived from anything of yours
- the nickname and colour you choose
- language, time zone and phone platform
- streak length, longest streak and the status of today
- the key for sending notifications to your phone, whether you allow notifications, and the time of the evening reminder
- the date and time of your consent and of the last time the app checked in
Your buddy and the others in a group see only your nickname, your colour and whether you’ve completed today or have a day off. Never steps, minutes, time or place.
Shared streaks and groups
For a shared streak we keep who is in it, and for a group also its name and emoji. On top of that, an overview of the streak’s closed days — whether the day counted, who had a day off and who didn’t make it — and who nudged whom and when (because of the once-a-day limit). None of this contains steps, minutes or workout times.
We need the time of the evening reminder because the evening summary of a shared streak comes from the server and replaces the reminder on your phone.
Backup (optional)
If you turn on backup, we additionally store an overview of which days were completed — one character per day, with no steps, minutes or times. Without it, restoring on a new phone would bring back your streak, but the calendar would stay empty.
Backup comes with a recovery code. On the server we keep only a fingerprint of it, from which the code can’t be reconstructed. That’s why not even we can recover a lost code.
Waitlist on this website
If you leave us your email address here, we store the address, the language of the page and the time of consent. Nothing more — not even your IP address. We use it for a single message: the one about the launch. You can unsubscribe via the link in every email, and we then delete the address straight away.
Server logs
For every request, the server logs the IP address, the time, the page address and the browser type. This is a standard operational log used to detect faults and attacks. It is deleted automatically within 14 days at the latest.
Cookies and tracking
This website sets no cookies and uses no third-party tracking or analytics. That’s why you won’t find a consent banner here — there’s nothing to ask consent for. The app contains no third-party analytics SDK. It only sends anonymous counters and reports crashes.
Anonymous counters
To find out whether the app helps people, it sends anonymous counters to our server: what happened (for example, opening the app on day 30 after installation, an accepted invitation or the Plus offer being shown), in which week, on which platform and in which store country (App Store or Google Play — not your location).
A counter carries no identifier — no key, no token, nothing from your phone. From it, the server stores only a total (“in week 40, twelve people opened the app on day 30”), not a record about you, and the IP address remains only in the server log. It contains no steps, minutes, streak length, dates of days or location. The only exception is that a counter says “someone reached a 7-day or 30-day streak” — without the actual number and without who it was.
You can switch them off in the app under More → Anonymous counters. Counters not yet sent are then discarded, and switching them off survives deleting your data.
Why we are allowed to process it
- Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for the identity, the backup and the waitlist. Streak length is derived from health data, so we treat it as a special category of data. You can withdraw your consent at any time by deleting your data.
- Legitimate interest (Art. 6(1)(f) GDPR) — for server logs, for the security and reliability of the service, and for anonymous counters, so that we can tell whether the app works.
Who receives the data
We don’t sell it to anyone and don’t pass it on for advertising. It is processed only by those without whom the service wouldn’t work:
- the server provider hosting the database (European Union)
- Expo — delivering notifications to your phone. A notification carries the text you see on the screen: the nickname of your buddy or a group member, the group name and the status of the shared streak. It never contains steps, minutes or times.
- Apple and Google — delivering notifications through their systems (they see the same text as Expo) and handling payments
- RevenueCat — keeping track of Plus subscriptions
- Resend — sending the waitlist email
- Sentry — technical records of app and server crashes
Some of them are based outside the European Economic Area. In that case, the transfer relies on the European Commission’s standard contractual clauses.
Crash reports
When the app or the server crashes, a technical record is sent to Sentry: the type of error, the place in the code, the app version and the phone model. It serves a single purpose — fixing what crashed.
It contains no steps, workout minutes, nickname or screen content. We send neither a screenshot nor your IP address, and the record is not used to measure what you do in the app. We process it on the basis of our legitimate interest in keeping the app working (Art. 6(1)(f) GDPR).
How long we keep it
- identity and backup — until you delete them, or until the app hasn’t checked in for two years
- waitlist — until you unsubscribe, at the latest until the launch message is sent
- server logs — 14 days at most
- anonymous counters — totals only, not linked to anyone, so you can’t be found in them or deleted from them
- crash records — 90 days at most
- database backups — 14 days at most; deleted data therefore survives in them for two weeks at most
- payment records — for as long as tax regulations require
Deleting your data
In the app under Settings → Profile and data → Delete data. Deletion is immediate and irreversible — there is no account from which anything could be restored. Your identity, the overview of days from the backup and all shared streaks disappear; your buddy will see that the shared streak has ended, and in a group the others carry on without you. Nothing else is shown to them.
If you no longer have the app on your phone, write to us at help@tadapp.eu and include the identification number the app showed in your Profile. Without it we can’t find your record — precisely because it is anonymous.
Your rights
You have the right of access to your data, the right to have it rectified, erased and its processing restricted, the right to data portability, the right to object and the right to withdraw consent. You can exercise them by email at help@tadapp.eu.
Because the data isn’t linked to your name or email address, we need the identification number from your Profile to find it. Without it, we can’t identify you — and under Art. 11 GDPR we are then not obliged to look for the data.
You can lodge a complaint with the Czech data protection authority, the Úřad pro ochranu osobních údajů (Office for Personal Data Protection, Pplk. Sochora 27, Prague 7), or with the data protection authority in the EU country where you live.
Children
The app is not intended for children under 16. We don’t knowingly collect data from them.
Changes
If this policy changes, we will publish the new version at this address and move the effective date at the top. For a significant change, we will also ask you in the app.