1. Data Controller
Main Character App ("we", "us", "our") is the data controller responsible for your personal data. If you have questions about this policy or your data, contact us at contact@example.com.
2. Data We Collect
We collect the following categories of personal data:
Account Data
- Email address (used for authentication)
Usage Data
- Task completions, journal entries, streak data, and goal progress
- Active path and day progress
- App preferences and settings
Purchase Data
- Subscription status and entitlements (processed via RevenueCat; we do not store payment card details)
3. How We Use Your Data
We use your data to:
- Provide and personalize the app experience
- Track your progress across paths, tasks, and goals
- Manage your subscription and premium entitlements
- Send notifications you have opted into (e.g. journal reminders)
- Improve the app based on aggregated, anonymized usage patterns
4. Legal Basis for Processing (GDPR Art. 6)
- Contract: Processing necessary to provide the service you signed up for
- Consent: Where you have given explicit consent (e.g. push notifications)
- Legitimate interest: Improving our service, preventing fraud
5. Third-Party Services
We use the following third-party services that may process your data:
- Supabase — Database and authentication (stores account and usage data)
- Firebase (Google) — Push notifications
- RevenueCat — Subscription management and purchase validation
- Apple App Store / Google Play — Payment processing for subscriptions
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
6. Data Storage & Security
- Your data is stored in Supabase-managed infrastructure, with EU-based hosting where available
- All data is encrypted in transit (TLS) and at rest
- Access to production data is restricted to authorized personnel only
7. Your Rights (GDPR Art. 13–22)
If you are located in the European Economic Area (EEA), you have the following rights:
- Right of access — Request a copy of the personal data we hold about you
- Right to rectification — Request correction of inaccurate data
- Right to erasure — Request deletion of your personal data
- Right to data portability — Receive your data in a structured, machine-readable format
- Right to restrict processing — Request that we limit how we use your data
- Right to object — Object to processing based on legitimate interest
- Right to withdraw consent — Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at contact@example.com. We will respond within 30 days.
8. Data Retention
- Account and usage data is retained for as long as your account is active
- When you request account deletion, all personal data is permanently deleted within 30 days
- Anonymized, aggregated data may be retained for analytics purposes
9. Children's Privacy
Main Character is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Your continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at: