Back to home

Privacy Policy — monoink

Version 1.0

monoink is operated by an individual developer based in the Sultanate of Oman ("we", "us"), and provides the monoink mobile app and monoink.app (the "Service"). Contact: privacy@monoink.app.

1. The short version. monoink is designed to be private. Your drawings and saved images stay on your device — they are never uploaded to us. You can use the app without an account. If you create an account, we store your email, a securely hashed password (or your Apple/Google sign-in identity), and which features you have unlocked — that's essentially it. We run no analytics, no crash trackers, no ads, and no tracking, and we do not sell personal data.

2. What we collect

Only if you create an account: email address; password (stored hashed by our auth provider — we never see the plain text) or your Apple/Google sign-in identity (basic profile: email); an optional newsletter opt-in choice; a user ID (random identifier); and which features you have unlocked (your purchases).

If you purchase: the app stores (Apple/Google) process payment; our purchases provider (RevenueCat) receives your user ID and store receipt data to unlock and restore your purchase across devices. We never receive card details.

On your device only (never transmitted to us): your drawings, your saved gallery images, app settings, and motion-sensor data used for shake-to-erase (processed locally, instantly discarded).

Not collected at all: location, contacts, camera, photos (beyond images you explicitly export via your device's own share sheet), microphone, advertising identifiers, analytics events, crash logs.

3. Why we process it

DataPurposeLegal basis (where GDPR applies)
Email, password/OAuth identity, user IDAccount sign-in, syncing your unlocks across devicesContract
Purchases / unlocks, receipts (via RevenueCat)Deliver and restore purchases, prevent fraudContract / legal obligation
Newsletter opt-in + emailSending our newsletter — only if you opted inConsent (withdraw anytime)
Transactional email (confirmation, password reset, deletion confirmation)Account service messagesContract

4. Who processes data for us

Supabase (authentication and database hosting); RevenueCat (purchase management); Apple App Store and Google Play (sign-in and payments under their own terms); our email delivery provider (service emails). Each receives only what its function requires, under contract. We disclose data beyond this only if required by law or to protect users and the Service. If the app is acquired, data transfers under this policy's protections.

5. Where

Our database is hosted by Supabase. RevenueCat and the app stores may process data in other countries, including the US and EU, under appropriate safeguards (e.g. standard contractual clauses where GDPR applies).

6. Retention

Account data: kept while the account exists; deleted within 30 days of account deletion (encrypted backups fully cycle out within 90 days). Purchase/transaction records: retained by RevenueCat and the stores as required for tax, accounting, and fraud-prevention law. Newsletter list entries: removed on unsubscribe or account deletion. Your on-device artwork is yours — uninstalling the app deletes it with the app (we never had a copy).

7. Your rights

Depending on your jurisdiction (Oman PDPL, GDPR/UK GDPR, US state laws), you may have rights to access, correct, delete, export, restrict, or object, and to withdraw consent (e.g. newsletter). Use in-app Settings (account deletion, newsletter toggle) or email privacy@monoink.app; we respond within 30 days. You may lodge a complaint with your local supervisory authority.

8. Account deletion

In the app: Profile → Delete account → confirm. Or see our account deletion page (including a no-app email path). Deletion removes your account, profile, and purchase-unlock records per §6. Purchases are one-time and processed by Apple/Google; refunds, if any, are handled by the store under its policy.

9. Children

The Service is not directed at children under 13 (or the higher applicable digital-consent age), and account creation is not intended for them. A child can draw in the app without an account, in which case we collect nothing at all. If you believe a child has created an account, contact privacy@monoink.app and we will delete it.

10. Security

TLS in transit; passwords hashed by our auth provider; access to production is restricted and credentialed; and the most effective control of all — we simply don't collect most data in the first place. Report vulnerabilities to support@monoink.app.

11. Changes

Updates appear here with a new version note; material changes are announced in-app. If we ever add analytics, crash reporting, or any new data collection, this policy will be updated before that version ships. Changelog: v1.0 — initial policy.