Privacy Policy — SacredWidget

Last updated: 2026-07-25

This Privacy Policy (the "Policy") describes how an individual developer (the "developer", "we") processes the data of users of the SacredWidget app (the "App").

The developer is a natural person (Individual Apple Developer) and acts as an independent data controller within the meaning of the GDPR with respect to the processing described in this Policy.

This Policy applies solely to the SacredWidget App and does not govern data processing by other applications, websites or services, including services of Apple Inc. and other third parties.

By using the SacredWidget App, you confirm that you have read this Policy and understand the data-processing practices described in it. If you do not agree with this Policy, please stop using the App.

The App is provided "as is". This Policy describes data processing and is not a warranty of continuous, error-free or uninterrupted operation of the App, nor of the accuracy or completeness of any content or information displayed in the App. This does not affect any statutory rights that cannot be excluded under applicable law.

Your use of the App is governed by the SacredWidget Terms of Use and, unless a separate license agreement is provided, by Apple's standard Licensed Application End User License Agreement (EULA). Those documents contain warranty disclaimers and limitations of liability that apply in addition to the terms of this Policy; this Policy governs data processing.

Information We Collect

Data-collection minimization. The SacredWidget App is designed on a data-minimization principle. By default, the data you create or enter in the App is stored locally on your device (in the App's internal storage) and is not transmitted to the developer.

Data processed locally. The content you create in the App (records, settings, user input) is processed and stored on the device. The developer has no technical access to this data and receives no copies of it, except in the cases expressly described in the applicable sections of this Policy.

Data that may leave the device. Data is transmitted outside the device only to the extent and in the cases expressly described in the relevant sections of this Policy, in particular: when using analytics services (if enabled), when processing subscriptions and purchases — and in other cases expressly described in this Policy.

No sale of data. The developer does not sell personal data and does not share it with third parties for behavioral-advertising purposes.

Content and Information

Informational purposes only. The content and information displayed in the SacredWidget App are provided for general informational purposes only. The developer does not warrant the accuracy, completeness or timeliness of any content, nor its fitness for any particular purpose; content may contain errors or become outdated.

Not professional advice. The content does not constitute professional advice (medical, legal, financial, religious or otherwise). You use the content at your own risk; to the maximum extent permitted by applicable law, the developer is not liable for any decisions, actions or consequences based on the content of the App. Nothing in this section limits any non-waivable rights you may have as a consumer under applicable law.

Reporting errors. If you believe any content in the App is incorrect, you can report it to the developer (see the "Contact" section). The developer reviews such reports but does not guarantee a correction within any particular time.

Liturgical-Calendar Content

The SacredWidget App presents human-curated reference information about the Catholic liturgical calendar (such as feast days, liturgical colors, ranks of celebrations and name days), compiled from publicly available sources. Liturgical practice varies: national and local calendars, particular parishes, dioceses and religious communities may legitimately differ from the general calendar presented in the App, and the App may not reflect local observances, transfers of feasts or particular-law variations.

The App is an independent work. It is not an official publication and is not affiliated with, endorsed or approved by the Catholic Church, the Holy See, any diocese, parish or other religious organization. The content is not religious, spiritual or pastoral advice. For authoritative liturgical information, consult your parish, your diocese or the official liturgical books and calendars.

Third-Party Services

Third-party analytics services. If the corresponding feature is enabled, the SacredWidget App uses the third-party analytics and crash-diagnostics services listed below. These services collect a limited set of data for the purposes of usage analytics and App stability. With respect to such processing, the providers act as processors on behalf of the developer, who acts as the controller.

The developer transmits data only to providers that, under their data-processing terms (DPA), are obligated to ensure a level of data protection equivalent to this Policy and to Apple's requirements. The developer relies on these providers' standard data-processing terms and does not control their internal practices beyond those terms.

The services listed below may begin collecting data at the App's first launch. Where applicable law (in particular, GDPR/ePrivacy) requires consent for such processing, you may object to it or request deletion of analytics data by contacting the developer (see the section on your rights), and you may also limit collection using iOS controls.

Firebase — Analytics, Crashlytics & Performance Monitoring (Google)

The App uses Firebase Analytics and Firebase Crashlytics, and — where the corresponding SDK is included — Firebase Performance Monitoring, provided by Google. These services may collect: device and installation identifiers (in particular, the Firebase Installation ID / installation UUID, IDFV), a pseudonymous user identifier assigned by the developer (User ID, which does not contain your name or contact details), the device model and OS version, the App version, and usage events. In addition: Firebase Analytics processes the IP address and derives an approximate country/region from it; Firebase Crashlytics, in the event of a crash, collects stack traces, diagnostic device information and the installation UUID (per Firebase documentation, with a retention period of about 90 days); Firebase Performance Monitoring collects network-request traces, App-launch metrics and device attributes. These SDKs begin collecting data by default at the App's first launch. Google processes this data as a processor; data may be transferred to the United States and other countries. Firebase/Google privacy policy: https://firebase.google.com/support/privacy and https://policies.google.com/privacy.

Mixpanel

The App uses Mixpanel for product analytics. Mixpanel may collect: a user/device identifier (distinct_id), the IP address and an approximate geolocation derived from it (city/region/country), technical device attributes, and usage events and their properties. Mixpanel acts as a data processor; data may be transferred to and stored in the United States (Mixpanel is certified under the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses for cross-border transfers). By default, Mixpanel automatically deletes event data after 2 years from the event date (for projects created before 1 September 2025 the initial retention period is 5 years, but it is reduced to 2 years upon a change of pricing plan or a switch to Mixpanel's free plan). Mixpanel privacy policy: https://mixpanel.com/legal/privacy-policy/.

Responsibility. IP addresses and device identifiers may constitute personal data under the GDPR and identifiers under CCPA/CPRA. The developer discloses the use of these services and relies on these providers' standard data-processing terms (in particular, the Google Data Processing and Security Terms; Mixpanel's DPA and Standard Contractual Clauses); the developer is not responsible for the providers' independent actions beyond those terms.

Subscriptions & Purchases

SacredWidget offers optional in-app purchases and/or subscriptions. All payments and receipt validation are handled by the Apple App Store under Apple's Privacy Policy; we never receive or store your payment details (such as card numbers). The app only learns whether you currently have an active purchase, so it can unlock the corresponding features.

You can manage or cancel a subscription at any time in your device Settings (your name → Subscriptions) or in the App Store app.

Auto-renewal. Subscriptions renew automatically until canceled. Cancellation takes effect at the end of the current billing period; canceling does not, by itself, refund the current or past billing periods, except where Apple's refund policy or a statutory right provides otherwise.

Refunds. All purchases are made through Apple's App Store; billing, renewal and refunds are handled by Apple, not the developer. The developer does not process payments and is not able to issue refunds for App Store purchases. To request a refund — including under a statutory right of withdrawal, where applicable — use Apple's process at reportaproblem.apple.com; refund decisions are made by Apple under Apple's terms. Paid features provide access to the corresponding functionality; the developer does not promise any particular output, level of quality, or outcome, and, to the extent permitted by applicable law, dissatisfaction with generated or displayed results does not, by itself, constitute a defect of the App.

How We Use Information

Purposes of data processing. The developer processes data for the following purposes:

No sale and no behavioral advertising. The developer does not use your data for behavioral advertising and does not sell personal data.

Change of purposes. The developer does not use data for purposes incompatible with those stated above without obtaining consent, where required by applicable law.

Data Retention

Local data. Data stored locally on your device is retained until you delete it in the App or delete the SacredWidget App itself. Deleting the App deletes the local data stored in the App's container on the device.

Backups and data loss. The App is not a backup service. The developer has no access to data stored locally on your device and cannot recover or restore it if it is lost or deleted — including through deletion of the App, loss, damage or reset of the device, or a software error. You are responsible for backing up your device (for example, via iCloud Backup or a computer backup) if you wish to preserve your data.

Analytics data. Data collected by third-party analytics services is retained in accordance with the retention periods set by the respective providers. The developer does not control these providers' internal retention periods; you can review the periods in the respective providers' privacy policies (see the section on third-party services).

Purchase data. Subscription-status data is retained for as long as necessary to provide access to paid features and to comply with applicable requirements.

Your Rights and Choices

Your rights. Depending on your jurisdiction, you have rights regarding your personal data.

Exercising rights through the device. Since the SacredWidget App's data is stored locally by default, you can exercise most rights yourself: access the data in the App, change or delete it, and delete all local data by deleting the App.

Rights under the GDPR (European Economic Area, United Kingdom). You have the right to: access to data; rectification; erasure ("the right to be forgotten"); restriction of processing; data portability; objection to processing; withdrawal of previously given consent; and the right to lodge a complaint with a data-protection supervisory authority. In accordance with Article 12(3) of the GDPR, the developer provides information on the action taken on your request without undue delay and in any event within one month of receiving the request; this period may be extended by a further two months where necessary, taking into account the complexity and number of the requests.

Rights under CCPA/CPRA (California). To the extent CCPA/CPRA applies to the developer, you have the right to: know what personal information is collected and how it is used; request deletion; correct inaccurate information; opt out of the "sale" or "sharing" of personal information; and limit the use of sensitive personal information. For verified requests (to delete, correct, and provide information), the developer responds within 45 calendar days of receiving the request; this period may be extended once by a further 45 days with notice. The developer does not sell personal information and does not share it for behavioral-advertising purposes. The developer does not discriminate against users for exercising their rights.

How to exercise your rights through the developer. For requests that cannot be fulfilled by deleting the App (for example, requests regarding analytics data), contact the developer using the details in the "Contact" section below. The developer may request information to verify your identity before fulfilling a request.

Security

Security measures. The developer applies reasonable technical and organizational measures to protect data, commensurate with the nature of the data processed, including a preference for local, on-device storage and reliance on the iOS platform's protection mechanisms.

No guarantee of absolute security. No method of transmitting or storing data is absolutely secure. Despite the measures applied, the developer cannot guarantee the absolute security of data. To the maximum extent permitted by applicable law, the developer is not liable for unauthorized access to, loss of, or disclosure of data, including incidents on the side of third parties or the platform infrastructure. Nothing in this Policy excludes or limits liability that cannot be excluded under applicable law, including liability for intentional misconduct or gross negligence and rights of data subjects under the GDPR that cannot be waived.

Incident notification. In the cases provided for by applicable law (in particular, Articles 33-34 of the GDPR), the developer notifies the supervisory authority and/or the affected users of security incidents affecting personal data.

User responsibility. The security of your data also depends on the security of your device and your Apple account. We recommend using an up-to-date version of iOS, a passcode, and two-factor authentication.

Children's Privacy

Age restriction. The SacredWidget App is not intended for and is not directed to children under 13 years of age (and, in the European Economic Area, under the applicable age of digital consent, which ranges from 13 to 16 depending on the country).

No knowing collection. The developer does not knowingly collect the personal data of children under the specified age. The App contains no features designed to attract children as a primary audience.

Actions for parents. If you are a parent or legal guardian and believe that a child has provided personal data, contact the developer using the details in the "Contact" section below. Upon receiving verified information that data was collected from a child under the applicable age without appropriate consent, the developer will delete such data.

Platform age mechanisms. Where applicable law requires age restrictions or age verification, the App relies on the App Store's (Apple's) age-rating mechanisms and age signals; the developer does not request or store users' dates of birth.

Changes to This Policy

The developer may amend this Policy at any time, for example due to changes in the SacredWidget App's functionality, platform requirements, or applicable law.

Notice. The current version of the Policy is indicated by the last-updated date at the top of the page. Changes are communicated by updating this date and/or posting the updated Policy. We recommend that you periodically review the current version of the Policy; the last-updated date lets you determine whether it has changed since you last reviewed it.

Continued use. By continuing to use the App after the updated Policy is posted, you accept the updated Policy to the maximum extent permitted by applicable law. If the changes require your consent under applicable law, such consent will be requested separately.

Contact

For questions related to this Privacy Policy, and to exercise your rights regarding personal data, you can contact the developer:

Requests related to the exercise of rights regarding personal data are handled within the periods established by applicable law (one month under the GDPR; 45 days under CCPA/CPRA, where applicable). For other inquiries, the developer strives to respond within a reasonable time. When you contact us through third-party channels (for example, Telegram), the processing of your correspondence is governed by the terms of the respective service.