Privacy
For PosiVibes 2.0, including prerelease testing. Effective September 20, 2026.
PosiVibes is provided by Salty Panda LLC. Contact support@saltypanda.com for privacy questions or requests. This policy covers version 2.0 and these support pages; it does not replace the policy linked from an older app version.
Reading, saving and reflection
The app stores reading preferences, saved entries, collections, routine progress and private reflection text on your device. It includes an offline catalog and checks our hosted catalog for updates. Those requests expose normal connection information, such as your IP address, to our hosting provider.
Private reflection text is excluded from the app’s cloud synchronization data format. Your device backup may contain local app data. Copies that you choose to export or share are handled by the destination you select. Deleting a record in PosiVibes does not remove those separate copies or your device backups.
Optional accounts and cloud features
Reading and saving do not require an account. When you use an available sign-in option, Firebase Authentication processes an account identifier and the email, name and sign-in information supplied by you or your sign-in provider. We use this information to recognize your account and keep its records separate from other accounts and guest data.
Where cloud saving is available and used, it stores saved readings, collection names and membership, revisions and synchronization history. It does not include private reflections. Removing a saved entry can leave an earlier revision in synchronization history until account cleanup.
An explicit purchase or remote-reminder setup can establish a guest service identity when you are not signed in. This identity supports that feature without requiring an email account. Feature availability can differ between prerelease builds.
Reminders and system features
Device-only reminders are scheduled on your device. Remote reminders use Apple Push Notification service and Firebase Messaging. Remote setup processes an installation identifier, notification delivery token, language, time zone, chosen times, enabled state and records used to confirm delivery ownership. Private reflections are not included.
You control notification permission in iOS Settings and reminder scheduling in PosiVibes. Turning reminders off cancels future scheduling; a notification already sent may still arrive. Widgets use a shared local reading snapshot. Optional Spotlight search indexes saved readings on the device, excluding private reflections. Apple’s system services and your device backup settings govern their own processing.
Purchases
Apple handles subscription payments. We do not receive your card details. PosiVibes uses StoreKit purchase information and, when linking purchases to service features, signed transaction identifiers, product and subscription status, an account-binding identifier and verification history. These records support access, restoration, refunds and protection against duplicate or unauthorized claims.
Version 2.0 does not use RevenueCat. Data associated with an older app version may remain with its service providers until handled under their retention and deletion processes.
Reliability and security
Firebase Crashlytics is enabled by default to help diagnose crashes. It can process crash traces, installation identifiers, device and operating-system details and app-version information. A previously saved diagnostic preference may affect collection. Firebase Analytics collection is deactivated in version 2.0.
App Attest and Firebase App Check help confirm that service requests come from the app. Our providers also process IP addresses, request information and security logs to operate services and prevent abuse. We do not use this information for advertising tracking or sell it.
Providers and international processing
We use Apple for purchases, sign-in when selected, notifications and system features; Google Firebase for authentication, hosting, cloud records, messaging, app verification and crash diagnostics; and your email provider and ours when you contact support. Information may be processed outside your country, including in the United States, under the providers’ applicable data-processing arrangements.
We use information to deliver features you request, maintain security and reliability, answer support requests and meet legal obligations. Where required, optional processing relies on your consent; you can withdraw permission through the relevant app or device controls. Other processing supports providing the service and our legitimate interest in keeping it secure and functional.
Retention
Local records remain until you remove them or remove the app, subject to backups you maintain. Cloud account records remain while needed for the account and requested features. Account cleanup removes ordinary account records but may retain restricted identifiers and purchase-binding history needed to prevent reuse of deleted accounts or fraudulent claims. These safety records do not have a fixed expiry.
Our reminder delivery records are eligible for automatic expiry after seven days; short-lived rate and setup records after one day; and purchase-notification deduplication records after 35 days. Expiry processing is asynchronous. Project operational logs are normally retained for 30 days, and required audit logs for 400 days.
Provider retention is separate. Google describes 90 days for Crashlytics data before removal begins, up to 180 days for removal of authentication data and messaging installation identifiers after the applicable deletion request, authentication IP logs lasting a few weeks, and hosting IP records lasting a few months. See Firebase’s privacy and retention information. App deletion alone does not initiate every provider’s deletion process.
Your choices and requests
You can read without an account, choose whether to share, control notifications and remove local content. Contact support@saltypanda.com to request access, correction, export or deletion of account information, or help with an older version’s data. Please do not send passwords or private reflection text. We may need to verify that the request concerns your account.
Depending on where you live, you may also have rights to restrict processing, object, withdraw consent or complain to your local data-protection authority. Deleting app data or an account does not cancel an Apple subscription; manage subscriptions through Apple.
These pages and updates
These support pages contain no advertising, analytics scripts, sign-in, cookies or submission forms. Hosting receives ordinary web requests. An email link opens your email app and sends nothing until you choose to send. If we change this policy, we will update the effective date and provide additional notice when required.