1Organization Information
Handback ("the app") is published by the organization named below, which is the data controller for the purposes of this policy.
- Publisher
- [DEVELOPER_NAME]
- Contact email
- [DEVELOPER_EMAIL]
- Application ID
- com.handback.handback
- Account type
- Organization / company account
2Data Collection
Handback collects no personal data whatsoever. There is no analytics SDK, no crash reporting, no advertising identifier and no telemetry of any kind.
Everything you type into the app — item names, the names of the people you type in, dates, tags, condition notes and free-text notes — is written only to storage on your own device. It is never transmitted anywhere, and the publisher has no ability to read it.
3Data Usage
Your entries are used solely to render the app's own features on your device: the ledger, the Today/Upcoming agenda, search and filtering, the insights charts, and streaks and badges. Every one of those figures is computed locally, on demand, from your own data.
4Data Sharing
Handback shares no data with anyone — not with the publisher, not with advertisers, not with analytics providers, and not with any other third party. No data is sold, rented or disclosed.
The only time information leaves the app is when you explicitly trigger an export and choose a destination in the Android share sheet. You control that action and its destination entirely.
5Data Security
Ledger entries are stored in a local Hive database encrypted with AES-256. The encryption
key is generated on your device at first launch and held in flutter_secure_storage,
which is backed by the Android Keystore.
Because no data ever leaves the device, there is no server, no database and no backup of your information anywhere that could be breached, subpoenaed or leaked.
6Data Retention
Your data is retained on your device for exactly as long as you want it. It is removed when you delete an individual entry, when you use Settings → Clear all data, or when you uninstall the app. There is no copy held elsewhere to delete.
7No User Accounts
Handback has no sign-up, no sign-in, no password and no user profile. It never asks for an email address, a phone number or any other identifier, and it cannot associate your use of the app with any identity.
8Children's Privacy (COPPA)
Handback does not knowingly collect personal information from anyone, including children under 13. Because the app collects no data from any user of any age, it cannot collect data from a child. The app is not directed at children and is not enrolled in Google Play's Designed for Families programme.
9User Rights
You have complete and direct control over your information at all times:
- Access & portability — export everything as JSON or CSV from Settings.
- Rectification — edit or delete any entry at any time.
- Erasure — use Settings → Clear all data, or uninstall the app.
No request to the publisher is necessary to exercise any of these rights, because the publisher holds none of your data.
10No Third-Party Services
Handback integrates no third-party services, SDKs, advertising networks, analytics platforms, social logins or cloud backends. Its functionality is entirely self-contained.
11Permissions
Handback requests exactly one Android permission:
- INTERNET — used solely so the in-app privacy-policy screen can load this page. No other feature of the app uses the network.
12Google Play Data Safety
The app's Data Safety declaration in the Google Play Console states "No data collected" and "No data shared". This policy and that declaration are consistent, and both accurately describe the app's behaviour.
13Policy Dates
- Effective date
- 21 July 2026
- Last updated
- 21 July 2026
If this policy changes materially, the updated version will be published at this address with a new "last updated" date.
14Contact
Questions about this policy or about privacy in Handback can be sent to [DEVELOPER_EMAIL]. We aim to respond within 30 days.
15Legal
Handback is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and Google Play's Developer Programme Policies including the User Data and Data Safety requirements.
Under GDPR, no lawful basis for processing is required because no personal data is processed by the publisher. Under CCPA, no personal information is collected, sold or shared. This policy is issued by the organization identified in section 1.