Privacy Policy — monoink
Version 1.0
monoink is operated by an individual developer based in the Sultanate of Oman ("we", "us"), and provides the monoink mobile app and monoink.app (the "Service"). Contact: privacy@monoink.app.
2. What we collect
Only if you create an account: email address; password (stored hashed by our auth provider — we never see the plain text) or your Apple/Google sign-in identity (basic profile: email); an optional newsletter opt-in choice; a user ID (random identifier); and which features you have unlocked (your purchases).
If you purchase: the app stores (Apple/Google) process payment; our purchases provider (RevenueCat) receives your user ID and store receipt data to unlock and restore your purchase across devices. We never receive card details.
On your device only (never transmitted to us): your drawings, your saved gallery images, app settings, and motion-sensor data used for shake-to-erase (processed locally, instantly discarded).
Not collected at all: location, contacts, camera, photos (beyond images you explicitly export via your device's own share sheet), microphone, advertising identifiers, analytics events, crash logs.
3. Why we process it
| Data | Purpose | Legal basis (where GDPR applies) |
|---|---|---|
| Email, password/OAuth identity, user ID | Account sign-in, syncing your unlocks across devices | Contract |
| Purchases / unlocks, receipts (via RevenueCat) | Deliver and restore purchases, prevent fraud | Contract / legal obligation |
| Newsletter opt-in + email | Sending our newsletter — only if you opted in | Consent (withdraw anytime) |
| Transactional email (confirmation, password reset, deletion confirmation) | Account service messages | Contract |
4. Who processes data for us
Supabase (authentication and database hosting); RevenueCat (purchase management); Apple App Store and Google Play (sign-in and payments under their own terms); our email delivery provider (service emails). Each receives only what its function requires, under contract. We disclose data beyond this only if required by law or to protect users and the Service. If the app is acquired, data transfers under this policy's protections.
5. Where
Our database is hosted by Supabase. RevenueCat and the app stores may process data in other countries, including the US and EU, under appropriate safeguards (e.g. standard contractual clauses where GDPR applies).
6. Retention
Account data: kept while the account exists; deleted within 30 days of account deletion (encrypted backups fully cycle out within 90 days). Purchase/transaction records: retained by RevenueCat and the stores as required for tax, accounting, and fraud-prevention law. Newsletter list entries: removed on unsubscribe or account deletion. Your on-device artwork is yours — uninstalling the app deletes it with the app (we never had a copy).
7. Your rights
Depending on your jurisdiction (Oman PDPL, GDPR/UK GDPR, US state laws), you may have rights to access, correct, delete, export, restrict, or object, and to withdraw consent (e.g. newsletter). Use in-app Settings (account deletion, newsletter toggle) or email privacy@monoink.app; we respond within 30 days. You may lodge a complaint with your local supervisory authority.
8. Account deletion
In the app: Profile → Delete account → confirm. Or see our account deletion page (including a no-app email path). Deletion removes your account, profile, and purchase-unlock records per §6. Purchases are one-time and processed by Apple/Google; refunds, if any, are handled by the store under its policy.
9. Children
The Service is not directed at children under 13 (or the higher applicable digital-consent age), and account creation is not intended for them. A child can draw in the app without an account, in which case we collect nothing at all. If you believe a child has created an account, contact privacy@monoink.app and we will delete it.
10. Security
TLS in transit; passwords hashed by our auth provider; access to production is restricted and credentialed; and the most effective control of all — we simply don't collect most data in the first place. Report vulnerabilities to support@monoink.app.
11. Changes
Updates appear here with a new version note; material changes are announced in-app. If we ever add analytics, crash reporting, or any new data collection, this policy will be updated before that version ships. Changelog: v1.0 — initial policy.