Effective: August 3, 2026
Privacy Policy
This policy explains what Arun Alarm processes, why it is needed, where it is handled, and the choices available to you.
Scope
This policy covers the Arun Alarm iPhone app and arunalarm.com. Arun Alarm does not require an account at launch.
Data that stays on your device
- Alarm times, repeat days, labels, sounds, routines, local history, progress, and saved object choices are stored on your device.
- Camera frames for Photo, QR, Object Hunt, and Push-up missions are analyzed in memory. Arun Alarm does not save those frames as photos or videos.
- Motion and Fitness input is reduced to mission progress. Raw Motion data is not retained.
- Body-pose processing uses a bundled MediaPipe model on device. Camera frames and landmark streams are not persisted or transmitted.
- QR checkpoints use random Arun Alarm identifiers. Raw QR content is not sent to analytics.
Data processed by service providers
Arun Alarm uses a limited set of service providers for purchases, product operation, diagnostics, install attribution, subscription campaign measurement, and website analytics. We require providers to handle data consistently with applicable law and their published privacy terms.
- Apple StoreKit and RevenueCat process subscription offers, purchase status, restore status, entitlement state, and related purchase history needed to provide Arun Pro. The app sends RevenueCat the pseudonymous app-instance AppsFlyer UID so RevenueCat can forward subscription lifecycle and revenue events associated with that identifier to AppsFlyer server-side for campaign measurement.
- Firebase Analytics receives a small, sanitized paywall funnel such as paywall viewed, offer loaded, purchase started, cancellation, failure code, restore state, and active entitlement state.
- Firebase Crashlytics may process crash diagnostics, device details, and app state needed to investigate failures.
- AppsFlyer Strict processes install and session attribution with a pseudonymous app-instance identifier. This release does not collect IDFA, does not show an ATT prompt, and does not send alarm, mission, questionnaire, purchase, or revenue event payloads from the app client. Subscription lifecycle and revenue events are forwarded by RevenueCat server-side as described above; the client does not send duplicate revenue events.
- Google Analytics measures website visits, page views, and interactions. It may process page URLs, referrers, browser and device details, approximate location derived from IP address, and first-party analytics identifiers or cookies.
What app analytics never includes
- Alarm labels or alarm times
- Typed mission phrases
- Images, videos, or body-pose frames
- Raw QR payloads
- Raw Motion or other sensor values
Tracking and advertising
The app does not collect IDFA or request App Tracking Transparency permission in this release. AppsFlyer Strict uses a pseudonymous app-instance identifier for install and session attribution and for the RevenueCat server-side subscription measurement described above.
The website uses Google Analytics for audience and usage measurement. Where an analytics choice is presented, Google Analytics stays off until you allow it. You can later change that choice using the Analytics settings control. A hosting provider may also process ordinary request logs for security and delivery.
Permissions and your choices
- Alarm or notification access is requested when it is needed to schedule an alarm on your iOS version.
- Camera access is requested only for a selected camera-based mission.
- Motion and Fitness access is requested only for a selected movement mission.
- You can revoke these permissions at any time in iOS Settings. A permission-dependent mission may stop working after access is revoked.
Retention and deletion
Local app data remains on your device until you clear an available in-app record or delete the app. Apple and our service providers retain purchase, attribution, analytics, and diagnostic records according to their operational, security, legal, and published retention requirements. We keep service-side data only as long as needed for those purposes.
You may contact us to request access, correction, or deletion. Because some telemetry is anonymous or pseudonymous, include the app-instance identifier when available; we will explain if a record cannot reasonably be linked back to you.
International processing and legal rights
Service providers may process data in countries other than your own. Applicable contractual and legal safeguards continue to apply. Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing.
Changes to this policy
We may update this policy when the app, its providers, or legal requirements change. The effective date above will be updated, and material changes will be communicated where required.