Privacy Policy

Last updated: 15 August 2026

This Privacy Policy explains how SlothUp processes information in the SlothUp mobile app and on slothup.app.

1. About this policy

This policy applies to SlothUp and slothup.app. The controller for the processing described here is Georg Reinthaler.

2. No account and local app data

SlothUp works without registration or a user account. Your detailed movement history, goals, progress, settings, local reminder schedules, and Screen Time selections are stored locally on your device and are not sent to us. You can delete this information by removing the app and its local data.

Apple-protected Family Controls tokens for selected apps and categories are processed only in local app-group storage to operate App Shield. The names and identities of selected apps or categories, those tokens, your per-app Screen Time, and your app-usage or browsing history are not sent to SlothUp, PostHog, Sentry, or RevenueCat. SlothUp does not receive a readable history of how you use other apps.

3. Product analytics

In production, SlothUp uses PostHog's EU Cloud to process pseudonymous product events. Each event may include a random, persistent analytics identifier, app version, build number, device type, operating system, and operating-system version.

Product events relate to onboarding, use of SlothUp features, the paywall and purchase flow, guided movement sessions, and App Shield setup. Session analytics is limited to the type and configuration of a session, its completion status, and planned or credited duration. Credited movement duration is reported only in broad ranges.

Screen Time analytics is limited to permission and setup status, aggregate counts of selected apps and categories, and whether App Shield is enabled. It does not contain Screen Time duration, app names, category names, Family Controls tokens, your app-usage or browsing history, or content you view in other apps. Detailed movement history and exact credited movement duration are also not sent. We use these events only to understand whether SlothUp's own features work and are useful.

Geo-IP processing, session replay, automatic error capture, person profiles, surveys, remote feature flags, and advertising tracking are disabled in our configuration. Processing is based on our legitimate interest in improving SlothUp under Article 6(1)(f) GDPR. Analytics events are deleted or anonymised after no more than 12 months. See the PostHog Privacy Policy.

4. Error reporting

SlothUp uses Sentry to receive technical reports when unexpected errors occur. A report may include crash data, a stack trace, app version, operating system, device model, affected feature, and other diagnostic information needed to understand the failure. Default personal information, screenshots, view hierarchies, automatic performance tracing, native-frame tracking, breadcrumbs, and profiling are disabled in our configuration.

Processing is based on our legitimate interest in reliability and security under Article 6(1)(f) GDPR. Error reports are deleted after no more than 90 days. See the Sentry Privacy Policy.

5. Purchases and SlothUp Plus

Subscriptions are processed through Apple's App Store. Apple handles payment and Apple Account data under its own responsibility. We do not receive full payment details.

RevenueCat is used to provide and restore SlothUp Plus. It may process a randomly generated anonymous App User ID, product identifier, purchase and subscription history and status, transaction times, app and device information, and technical connection data. SlothUp does not provide RevenueCat with a name, email address, advertising identifier, or SlothUp account identifier. This processing is necessary to perform the contract under Article 6(1)(b) GDPR and for reliable purchase management under Article 6(1)(f) GDPR. We also use RevenueCat's aggregate subscription reporting to understand subscription performance under Article 6(1)(f) GDPR.

Purchase information is retained for the subscription term and then only as long as required for restoration, fraud prevention, and legal record-keeping. See the RevenueCat Privacy Policy and Apple Privacy Policy.

6. Notifications and Screen Time

If you allow notifications, SlothUp schedules reminders locally. No push token is sent to us. You can revoke permission in iOS Settings.

App Shield uses Apple's FamilyControls, ManagedSettings, and DeviceActivity frameworks. Permission is optional and can be revoked in iOS Settings. The limited status and count analytics described in section 3 are sent to PostHog, but the private Screen Time information described in section 2 remains on your device. Apple may process information under its own responsibility as part of these operating-system features.

7. No advertising tracking

SlothUp does not use collected information for third-party advertising, advertising measurement, data-broker sharing, or tracking you across apps or websites owned by other companies. It does not access the iOS advertising identifier.

8. Support requests

If you email us, we and the email service providers involved in delivering the message process your email address, message, and any technical details you provide to respond to your request. When you open support from the app, a pseudonymous PostHog Support ID is prefilled in the email subject so we can identify relevant diagnostic records. You may remove this ID before sending the email. Processing is based on Article 6(1)(b) or (f) GDPR. Support data is generally deleted within 12 months after the request is resolved unless law or a legitimate need requires longer retention.

9. Website

This website uses no analytics or advertising cookies and contains no contact form. To deliver and secure the site, the hosting provider may temporarily process IP address, time, requested URL, browser identifier, and error status in server logs under Article 6(1)(f) GDPR. Access logs, if generated, are retained only for the limited period made available by the hosting plan unless they are needed to investigate a security incident.

10. Recipients and international transfers

Only the providers identified above receive information to the extent needed for their purpose. We require service providers to protect data at least as described in this policy. Where information is processed outside the European Economic Area, transfers rely on an adequacy decision or safeguards such as the EU Standard Contractual Clauses.

11. Your rights and deletion

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent for the future. You can make a request using the contact details below. For pseudonymous service data, we may need the Support ID described in section 8 to identify a record. Apple transaction data may need to be managed through Apple.

You may also complain to a data protection authority, in particular the Austrian Data Protection Authority.

12. Changes

We update this policy when features, providers, or legal requirements change. The current version is available at slothup.app/privacy.

13. Contact

Georg Reinthaler: support@slothup.app