Skip to content

Privacy Policy

§ 1

Controller

  1. The controller of personal data processed in connection with the Headset Timer application (the “App”) is MEMORY2 spółka z ograniczoną odpowiedzialnością (“Memory2” or “Provider”), with its registered office in Kraków at Jana Zamoyskiego 63, 30-519 Kraków, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division of the National Court Register, under KRS number: 0000983529, NIP: 6762622200, share capital of PLN 5 000, e-mail: hello@headsettimer.com, telephone: +48 668 106 279.
  2. Matters concerning personal data may be raised using the contact details specified in §12.

§ 2

Scope

  1. This Policy describes the processing of personal data within the App. It does not cover the website headsettimer.com, which, if it processes personal data, will be addressed in a separate policy.
  2. The App may be used without providing directly identifying details, such as a name or e-mail address. Some data is nevertheless processed automatically. This Policy distinguishes between data processed without such details and data processed where the User voluntarily provides a name and e-mail address.
  3. This Policy is made available in the App and on the App Store listing in a manner allowing it to be stored and reproduced.

§ 4

Recipients and processors

  1. The Provider may share personal data with the following categories of recipients: a provider of e-mail and push messaging services, an analytics or attribution provider, a hosting or backend provider, and Apple in connection with distribution and payments.
  2. Data is shared only to the extent necessary and, where a processor acts on the Provider’s behalf, on the basis of a data processing agreement meeting the requirements of Article 28 GDPR.
  3. Where the Provider shares personal data with a third party, it requires that the third party provide a level of protection of personal data at least equivalent to that described in this Policy.
  4. Apple processes certain data in connection with distribution through the App Store and with payments as an independent controller, under Apple’s own privacy policy.

§ 5

Transfers outside the EEA

  1. The Provider may use processors established outside the European Economic Area, in particular in the United States. In that case, the Provider transfers personal data only where an appropriate basis under Chapter V GDPR applies, namely a European Commission adequacy decision, the Standard Contractual Clauses referred to in Article 46 GDPR, or the EU-U.S. Data Privacy Framework. A copy of the safeguards, or information on where they have been made available, may be obtained by contacting the Provider.

§ 6

Retention

  1. Personal data is retained for the following periods or according to the following criteria, after which it is deleted or anonymised.
    1. 1) App usage and event data - for 12 months from collection;
    2. 2) technical and security logs - for 12 months from collection;
    3. 3) a name and e-mail address provided for the account - for as long as the User maintains the account, but no longer than 5 years from the User’s last activity, and up to 3 years afterwards where necessary to establish, pursue or defend claims;
    4. 4) data processed for marketing - until the User withdraws consent or objects, after which the marketing profile is deleted within 30 days; the Provider may keep a limited suppression record (the contact identifier and the withdrawal or objection) to demonstrate compliance and to ensure that no further marketing is sent, for the period necessary to establish, pursue or defend claims;
    5. 5) transaction and entitlement data - for the duration of access and up to 6 years, for accounting purposes and to establish, pursue or defend claims.

§ 7

Rights of the data subject

  1. The User has the following rights under the GDPR.
    1. 1) The right of access to their personal data and to obtain a copy of it (Article 15 GDPR).
    2. 2) The right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR).
    3. 3) The right to erasure, in particular where the data is no longer necessary, consent has been withdrawn and there is no other basis, or the User has effectively objected to the processing (Article 17 GDPR).
    4. 4) The right to restriction of processing in the cases set out in the GDPR, for example while the accuracy of the data is being verified (Article 18 GDPR).
    5. 5) The right to data portability in respect of data processed on the basis of consent or of the contract by automated means (Article 20 GDPR).
    6. 6) The right to object to processing based on the Provider’s legitimate interest, and to object at any time to processing for direct marketing (Article 21 GDPR).
    7. 7) The right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR).
    8. 8) The right to lodge a complaint with a supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.
  2. To exercise these rights, the User may contact the Provider.
  3. The Provider responds to a request concerning these rights without undue delay and within one month of receipt. That period may be extended by up to two further months for complex or numerous requests, in accordance with Article 12(3) GDPR.
  4. The User may request deletion of their personal data, including a name and e-mail address provided for the Trial or for marketing, by contacting the Provider. The Provider then deletes the data unless it is required to retain it under applicable law.
  5. Providing personal data is voluntary. The App, including the Free Version and Black Belt Pro, can be used without providing a name or e-mail address. However, without providing and confirming an e-mail address the extended Trial cannot be granted, and without marketing consent the Provider cannot send marketing messages.
  6. The App is intended for users aged 16 or over and is not directed to persons below that age. The App Store age rating does not determine the age of valid consent to the processing of personal data.

§ 8

Security

  1. The Provider applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or destruction, adequate to the risks and the categories of data protected.

§ 9

Automated decision-making

  1. The Provider does not take decisions concerning the User based solely on automated processing, including profiling, that produce legal effects for the User or similarly significantly affect the User. Tap recognition is a technical function and is not used to evaluate the User.

§ 10

Device storage

  1. The App and its third-party components may store information on, or access information already stored on, the User’s device. Storing or accessing such information for purposes that are not strictly necessary to provide a service requested by the User requires the User’s prior consent under Article 399 of the Polish Electronic Communications Law. Storage or access that is strictly necessary to provide the App does not require consent.
  2. The technologies that store or read information on the User’s device are set out in the table below, which the Provider completes with the actual technologies. Consent, where required, may be withdrawn at any time in app settings.
Name / providerPurposeInformation stored or readRetentionConsent required (yes/no)
Secure storage (iOS Keychain)Authentication and account sessionAuthentication tokens and basic account detailsUntil logout, account deletion, or session invalidation. Keychain entries can survive app uninstall (iOS system behaviour)no
Local database (SQLite)Core app data, offline-first with server syncApp settings and timer historyUntil app uninstall, logout, or account deletionno
Local app storage (AsyncStorage)Crash recovery of the running session; scheduling in-app prompts; deferred-deeplink and identifier-sync stateTechnical state of the running session; scheduling data for in-app prompts; a technical marker containing identifiers used for analytics and attributionSession snapshot cleared when the session ends; remaining keys until app uninstall (paywall intent and identifier-sync marker survive logout)no
App preferences (UserDefaults)Gesture-feature configurationGesture and recognition-model configuration (no personal data)Until app uninstallno
App filesOnboarding state; gesture-model delivery; local diagnosticsOnboarding status; downloaded gesture-recognition models (no personal data); local diagnostic logs, never transmitted automaticallyOnboarding flag and models until uninstall or replacement; diagnostic logs rotated on device, 30 most recent files keptno
Installation identifier (IDFV)Identifying the app installation to the Provider's backend when issuing and refreshing sessionsDevice installation identifier (Apple identifier for vendor), sent to the Provider's backend with API requestsServer-side until account deletion; the identifier itself is managed by iOSno
In-app purchases (StoreKit 2)Processing subscription and lifetime purchases; verifying entitlementPurchase and transaction data managed by iOSManaged by Apple, tied to the Apple ID; survives app uninstallno
  1. Where the App tracks the User across apps or websites owned by other companies for advertising or measurement, it requests the User’s permission through Apple’s App Tracking Transparency prompt beforehand. App Tracking Transparency operates in addition to, and does not replace, the consent required under the electronic communications law.

§ 11

Amendments

  1. The Provider may update this Policy, in particular where the functionality of the App or the applicable law changes. Users are informed of material changes in an appropriate manner.

§ 12

Contact

  1. Matters concerning personal data may be raised with the Provider by e-mail to hello@headsettimer.com or by post to the registered office indicated in § 1.
  2. This Policy is effective as of 01.08.2026.

Published