Privacy policy
Draft for review. This is not an effective published legal notice.
1. Who we are and what this policy covers
LastTime is operated by Blue Sparrow, an independent solo developer based in India. In this policy, "we", "us" and "our" mean the developer operating under that name. We are responsible for the purposes and means of personal-data processing that we control, including as controller or Data Fiduciary where those roles apply.
This policy covers LastTime, its public product pages, support, and connected services. The app provides personal activity history, optional reminders, calendar and usage targets, readings, photos and scan shortcuts. Guest use is available without an account. Optional sign-in, cloud sync, recovery, subscriptions and operational messages involve the providers described below.
- Privacy, data requests and grievances: privacy@bluesparrow.dev.
- General support: info@bluesparrow.dev.
- Website: https://bluesparrow.dev.
The developer monitors the privacy email and is the contact for privacy questions. This policy applies globally to our practices; particular rights and obligations depend on your location, the processing involved and the applicable law.
2. Our data boundary
Your personal app records and calculations are stored locally in encrypted storage. They are not uploaded to our operational API or stored as a readable personal history in Netcup.
If you enable sync, your device encrypts personal records before placing them in your Google Drive app-data folder. Our Netcup service handles limited identity, device, recovery-key, subscription and delivery information. Passwordless recovery is not operator-zero-knowledge: our service can access the recovery key during enrollment and recovery, although it does not receive your Drive archives or Drive authorization tokens.
If you voluntarily email us personal content, the information in that message is handled as support correspondence. Please avoid sending personal-record exports, sensitive screenshots, passwords or recovery material.
3. Information handled and where it comes from
| Category | Information and source | Main purpose and location |
|---|---|---|
| Personal app content | Item names, categories and optional place/thing labels, completion dates and time precision, notes, selected photos and thumbnails, independent numeric readings and counter epochs, baseline links, calendar/seasonal/usage targets, pauses, reminder rules, shortcut aliases, settings and edit/conflict history. Provided by you or calculated locally. | App features on your device; encrypted copies in your Drive only after opt-in. |
| Account identity | Selected Google account identifier, Firebase UID, verified email and verification/authentication state from Google/Firebase. Provider tokens remain protected; display information may appear in the account chooser. | Optional account authentication and authorized service access. Netcup derives identity from verified tokens. |
| Device and service state | Random app/device identifiers, app/OS version, locale, consent preferences, device enrollment, dataset generation, last-seen and sync coordination status. | Secure device continuity, compatibility and operational administration. No personal record text is included. |
| Recovery material | Random portable recovery key, encrypted server-held key envelope, key/version/generation identifiers; generated by the app. | Passwordless recovery. Local database keys remain separate. |
| Push and email delivery | Verified email, FCM registration token, permission/preferences, generic template identifier, delivery status, provider reference, retries and expiry. | Account/security/subscription/service notices and content-free sync hints through Netcup and delivery providers. |
| Purchase information | Store/customer/purchase identifiers, product and entitlement, renewal/expiry/refund status, and necessary store country/currency metadata from Play/RevenueCat. | Verify and manage subscriptions. We do not receive full payment-card or bank credentials. |
| Support and privacy requests | Sender address, message, voluntarily attached files, verification information and response history. | Respond to the request; communications are processed outside the app's encrypted local record store. |
| Website and security requests | IP address, user agent, requested route, time and response/security status. | Deliver and protect our website and services; minimize and redact logs. |
We do not buy personal data from brokers, sell or rent it, share it for cross-context behavioral advertising, or use it to train general-purpose AI models. The app has no ads, advertising identifier collection, default usage analytics or automatic personal-content crash uploads. A necessary provider SDK can still process technical metadata to perform its disclosed function.
4. Sensitive information and permissions
Your notes, item names, photos or routines may reveal health, relationships or other sensitive information. LastTime does not require a medical profile and does not infer a diagnosis. Suggestions describe your recorded intervals. Please include another person's information only when you have an appropriate basis to do so; there is no public feed or household sharing.
Notifications are optional. Camera access is requested only for a photo you take or an in-app QR scan; system photo selection gives access to chosen images rather than your whole library. Retained photos have location/EXIF metadata removed. Local NFC read/write needs compatible hardware and an explicit action; scanning opens an item and never records completion. NFC/QR payloads contain an opaque alias, not names, history or keys, unless you separately print a visible label. We do not upload scan activity or use a server resolver. We do not request microphone, contacts or precise location. Biometrics remain with the operating system; widgets respect your visibility and lock choices.
Google sign-in and Drive permission are separate choices. Drive access is limited to this app's hidden app-data area, not your ordinary Drive files. Refusing optional permissions leaves the local core available, although the corresponding optional feature will not work.
Sensitive-data processing or unexpected background access is explained in context before the relevant choice. Where explicit consent is required, it is requested separately; accepting terms or purchasing Premium does not provide that consent.
5. Purposes and legal bases
We use data only to deliver the features you request, secure and maintain the service, respond to support, manage purchases, and meet applicable obligations.
Where EU/EEA or UK rules apply, our bases are:
- Contract: processing necessary for optional account services, requested sync/recovery, paid access and relevant service support.
- Consent: optional uploads, optional communications or nonessential processing requiring a choice. Where health or other special-category data requires an additional basis, we obtain explicit consent for that processing.
- Legitimate interests: proportionate service security, abuse prevention and necessary operational troubleshooting, after considering your rights. This does not authorize advertising profiles or unrestricted use of private content.
- Legal obligation: required billing/accounting records, valid data requests and incident notifications.
In India and other regions, consent and any other permitted basis are used only as allowed by the rules applicable there. Information is optional unless needed for the feature you choose or a mandatory obligation. Without account verification we cannot release a recovery key; without purchase verification we cannot confirm paid access.
You can withdraw consent through the relevant setting, Google permission controls or the privacy email. Withdrawal affects future processing and does not invalidate earlier lawful processing. Turning off sync stops new transfers but does not itself erase existing copies; deletion controls are separate.
6. Drive sync, backups, keys and exports
Automatic sync reconciles encrypted changes between your own devices using the same selected Google account. It is not cross-account sharing and may pause because of connectivity, Drive quota, permissions, operating-system limits or service outages. The app distinguishes local saves, pending sync, conflicts and verified backups.
Backups are separate verified recovery checkpoints. They may include older versions, deleted-record markers and unresolved conflicts needed for recovery. A new device needs the matching Google identity, Drive permission, a valid recovery key and compatible encrypted data.
We protect the random recovery key inside an encrypted envelope on Netcup. It is transmitted over TLS and available transiently to our authenticated service during registration/release. This enables recovery without a user-held passphrase. Someone who compromises your account could obtain both archive and key; encryption does not eliminate that risk. No service backup contains the personal Drive archive, and our API has no server-held Drive access token.
Exports are initiated by you and saved or shared to a destination you choose. Readable exports and separately exported photos are not protected by the app's encryption once outside it. The recipient, chosen app or storage provider controls those copies.
7. Providers and disclosures
We limit information to what each provider needs for its role:
- Google/Firebase: sign-in, authentication, Drive storage, FCM push, Play distribution and payments. Google controls the physical storage of your Drive data and provider metadata.
- Netcup and Blue Sparrow operational services: hosted API, database, protected key envelopes, device/account coordination, delivery and subscription processing, public website and infrastructure backups.
- RevenueCat: purchase/customer identification, offerings and verified entitlement events. Our subscription gateway forwards only operational billing information.
- Email and support providers: delivery addresses, generic operational messages and correspondence you choose to send.
- Your selected export destination: only the records or files you choose to export/share.
Shared Blue Sparrow infrastructure does not combine private records across our apps for profiling. Personal reminder schedules and reports stay on device. Cloud messages contain generic operational wording, never item names, readings, notes or health summaries.
Providers may act as our processors or as independently responsible providers for their own functions. Their notices explain their separate practices: Google, Firebase, RevenueCat, and Netcup.
Limited disclosure may also be necessary to meet a valid legal requirement, prevent serious harm or address fraud/security incidents. Any business transfer involving personal data must preserve applicable protections and provide required notice or choices. We do not authorize a new recipient to repurpose private content merely because ownership changes.
8. Website, cookies and communications
Our product pages use necessary technical storage only where needed for security or a choice you make. We do not use advertising cookies, cross-site tracking, marketing pixels or a default analytics feed. Links to stores or other providers take you to services with their own practices.
Personal reminders run locally. Operational push registration is contextual and permission-controlled. You can change channel preferences, unsubscribe from optional emails, disable notifications or disconnect your account. Necessary security, purchase or request-response messages may still be sent when required to provide the service or meet an obligation. Marketing is not enabled by default.
9. Storage locations and international processing
Blue Sparrow is operated from India, and support or service administration can involve access from India. Netcup operational hosting is planned in the European Union; Google, Firebase, Drive, Play, RevenueCat and email providers may process their limited data in other countries. We do not promise that every copy remains in your country or in the EU.
For transfers requiring protection, we use an applicable lawful mechanism, such as an adequacy decision or approved contractual safeguards with supplementary measures where needed. Ordinary consent is not treated as a blanket substitute for safeguards for ongoing international services. Contact the privacy email for information or a copy of applicable safeguards, subject to necessary redactions.
10. Retention and deletion
We keep personal data for its stated purpose and any applicable mandatory retention, rather than indefinitely by default.
| Information | Retention approach |
|---|---|
| Local app records | Until you remove them or clear the local dataset. Archived items, recovery state and conflict revisions remain until their scope is removed. |
| Encrypted Drive material | Latest two verified checkpoints plus a rolling 30-day recovery window. Earlier encrypted sync revisions may remain longer until safely covered and acknowledged by active devices; retiring an inactive device enables cleanup. |
| Account, device and recovery-key state | While the connected feature is active, then removed through account/cloud deletion except narrowly necessary deletion or retention records. |
| Routine security/access/delivery logs | Target of up to 14 days; restricted security evidence or records subject to a longer mandatory period are handled separately. Logs exclude personal record contents. |
| Infrastructure backups | Target rotation within 30 days, except an applicable mandatory preservation requirement. Deletion markers are reapplied after restoration to prevent reactivation. |
| Support and rights correspondence | While needed to resolve and document the request; review after closure and remove unnecessary attachments promptly. Any longer retention is limited to a documented support, security or mandatory purpose. |
| Billing and mandatory records | Only fields needed for accounting, subscription reconciliation, fraud prevention or an applicable retention period. Store/provider retention can differ from ours. |
The routine targets above do not override mandatory retention requirements, including Indian requirements when applicable and in force. For an exception we limit access, use and retained fields, document the reason and duration, and erase or anonymize when the requirement ends. We explain the relevant exception in a deletion response where permitted.
Deleting a synced record propagates after reconciliation; an older checkpoint or offline device may still hold a copy. Cloud deletion removes sync objects and checkpoints through your authorized client. Disconnecting, signing out or uninstalling alone does not delete cloud or provider records.
Account deletion is available in the app and through the externally published deletion instructions linked from our website/store listing. You may also email the privacy address with "LastTime deletion" in the subject. Verification is proportionate; we never ask for a Google password or encryption key by email.
Without Drive authorization, we cannot delete Drive files from the server. We explain reconnection for cleanup or verified account/key deletion leaving encrypted files behind, which may no longer be recoverable. Failures are reported so you can retry. Local deletion is separate; inaccessible offline devices and copies you exported remain outside remote deletion control. Deleting an account does not cancel a Google Play subscription.
11. Security and incidents
Safeguards include encrypted local storage, protected device keys, client-side authenticated encryption for Drive, encrypted server-held recovery material and contact tokens, TLS, access controls, recent authentication for sensitive actions, minimized logs and restricted operational payloads. Personal databases and keys are excluded from unintended operating-system backup.
No method guarantees complete security or recovery. Protect your device and Google account, keep software updated, and secure exported files. Report suspected exposure to the privacy email. We investigate and notify affected people and authorities when required, using the applicable content and timing requirements.
12. Your choices and privacy rights
Depending on applicable law, you may request access or confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, information about recipients, or limits on sensitive-data use. We do not discriminate against people for exercising applicable rights.
Use app controls for local records, export, permissions and cloud choices. Email privacy@bluesparrow.dev for operational data or assistance; include the app name, requested action and relevant account email if applicable. We verify only what is necessary. Authorized agents or guardians may contact us with appropriate authority. We do not require a personal-record upload to process a request.
We respond within applicable deadlines and explain permitted extensions, refusals and available review options. Requests are normally free; any exceptional fee or refusal must be permitted and explained. We cannot retrieve local-only records from your device through an email request.
13. Regional rights
- EU/EEA and UK: GDPR/UK GDPR rights include those above; consent may be withdrawn and legitimate-interest processing may be challenged. Responses are generally due within one month, with permitted extensions explained. You may contact your local supervisory authority, including the UK ICO where relevant.
- Switzerland: applicable rights under the Federal Act on Data Protection include information, access and correction, with concerns addressed to the FDPIC where appropriate.
- United States: where state privacy laws apply, including California's CCPA as amended, you may have rights to know categories and specific information, correct/delete, receive a portable copy, limit qualifying sensitive-data use, and opt out of sale, sharing for targeted advertising or qualifying profiling. We perform none of those advertising/sale activities or significant-decision profiling, including when a Global Privacy Control signal is present. Agents may submit applicable requests. Where an appeal right applies, email the privacy address with "Privacy appeal"; we explain the outcome and available regulator contact. Many US requests have a 45-day response period, subject to the applicable law and permitted extensions.
- US consumer health data: additional consent, access, recipient-information and deletion rights may apply, including under Washington and Nevada requirements. The separate consumer-health notice below describes the relevant categories and purposes. Personal wellness records are not automatically protected by HIPAA simply because they are health-related.
- India: applicable DPDP rights include information about processing, correction/completion/updating, erasure, grievance redressal and nomination, subject to the Act and Rules being in force for that processing. Contact the developer at the privacy email. Our grievance target is 30 days, and no later than a shorter applicable deadline or the statutory maximum where relevant. You may use the Data Protection Board channel when available and applicable after the prescribed grievance process. Consent withdrawal is available without purchasing a plan.
- Brazil, Canada, Australia and New Zealand: applicable LGPD, federal/provincial and national privacy rules may provide access, correction, deletion, consent/objection, portability or complaint rights with local conditions. Contact us or the relevant privacy authority, such as ANPD, the Canadian federal/provincial commissioner, OAIC or the New Zealand Privacy Commissioner.
- Japan, South Korea, Singapore, South Africa and other regions: applicable APPI, PIPA, PDPA, POPIA or other local rules may provide additional access, correction, deletion, consent, objection and cross-border protections. We apply required local protections and response periods; this policy does not limit a mandatory right because your country is not individually listed.
14. Children and automated insights
LastTime is intended for adults aged 18 or older, or a higher age where needed to enter the relevant agreement. We do not knowingly offer child accounts or invite children's personal data. If a child has provided information, contact us so we can review and remove data we control where appropriate. An age statement alone does not eliminate obligations when we become aware of a child's data.
Interval suggestions and target calculations use your records locally. Suggestions require your acceptance and do not silently alter schedules. They are not used to make decisions with legal or similarly significant effects.
15. Changes and contact
We update this policy when practices or requirements change, revise its date, and provide meaningful notice of material changes. New uses requiring consent need a new choice before processing; continued use alone does not supply that consent.
Privacy and data requests: privacy@bluesparrow.dev. General support: info@bluesparrow.dev. Website: https://bluesparrow.dev.