1. Who processes your data
Prioritizer (iOS and Android) is developed and maintained by Alexandre Martins Montebelo, the controller of the personal data described here, under Brazil's Law 13.709/2018 (LGPD).
Data protection contact: alexandremontebelo@gmail.com
This policy also addresses the EU General Data Protection Regulation (GDPR) for users in the European Economic Area, the United Kingdom and Switzerland.
2. The short version, in four sentences
- Your lists and items stay on your device. There is no server of ours, no sign-up, and we cannot see what you write.
- If you turn on backup, your data goes to your own Google Drive, in a private app folder we cannot access.
- What leaves your device for us are event names ("a list was created", "a prioritization finished"), crash reports, and a recording of your taps on screen with all text masked - never the text you type.
- Ads and purchases are operated by Google and Apple, under their own terms.
3. What we do not collect
Stated explicitly, because it is the most important part of this policy:
- no sign-up - there is no Prioritizer account, login or password;
- no name, email, phone number or address collected for our own use;
- no location, contacts, camera, microphone, photos or calendar - the app requests none of these permissions;
- no push notifications;
- no identifier is associated with you: the app never sets a user identifier in the analytics or crash-reporting tools;
- the content of your lists and items is never sent to us, by any path - not in analytics, not in crash reports, not in support.
4. What stays on your device only
| Data | What it is |
|---|---|
| Lists, items, colors, checkmarks and the tree | The app's content |
| Deletion records | Keep the name of what was deleted, so deletions propagate across your devices |
| Prio wallet | Balance, debt and the date of the last daily drop |
| Last sync summary | Includes the names of lists and items that arrived, so the app can tell you what changed |
Technical log (collection.txt) | Internal events, for diagnostics. Capped at 1 MB |
| Theme preference | Light or dark |
All of it lives in the app's private storage, inaccessible to other apps on the device. We have no access to anything on this list.
One important caveat: if your system's automatic backup is on (Google Backup on Android, iCloud on iOS), this data is copied to your account's cloud, along with other apps' data. That is a service of your operating system vendor, not ours, and you control it in your device settings.
5. Backup to your Google Drive
This is optional and only works after you connect a Google account.
- What is uploaded: the app's complete database - lists, items, deletion records and the wallet;
- Where: the
appDataFolderof your Google Drive, a hidden area reserved for this app; - Who can access it: only you and the app installed on your devices. We have no access to that file, and the permission the app requests cannot read any other file in your Drive;
- Which permission is requested:
drive.appdata(the app's private folder) andemail(only so the screen can show which account is connected). No profile data - name, photo - is read or stored; - Where the credential lives: the system Keychain (iOS) or under Google Play Services' custody (Android). The app never stores your password, which you type directly into Google's screen.
To disconnect: tap "Sign out" on the Backup screen. The app revokes the authorization in your Google account, in addition to forgetting the session. Disconnecting does not delete your data - neither on the device nor in Drive.
6. What we send off the device
6.1 Usage data (Google Analytics for Firebase)
Purpose: understanding aggregate use - which screens people visit, whether
prioritizations finish or are abandoned, whether ads load.
Legal basis: legitimate interests (LGPD Art. 7(IX); GDPR Art. 6(1)(f)).
What is sent is a closed vocabulary, written into the app's source. Specifically:
- a screen name - from a fixed list of 16;
- an action name - from a fixed list of 29, such as
lista_criada,item_criado,priorizacao_concluida,sync_executado,anuncio_falhou; - numbers and closed-set labels: a count, a size band (
1,2-3,4-10,11-25,26+), an outcome (mesclado,falhou…), a reason (sem_rede,sem_preenchimento…), and whether the person is a subscriber (yes/no); - when something goes wrong, an event carrying only the
severity (
WARNorERROR).
Google Analytics collects, on its own and under its own policy, a random app instance identifier, the device model, OS version, country, and the advertising identifier.
6.2 Crash reports (Firebase Crashlytics)
Purpose: finding and fixing crashes.
Legal basis: legitimate interests.
When the app crashes, the technical report is sent: the point in the code, the device model, the OS and app versions, and the last lines of the internal technical log. No identifier of yours is attached to the report. Lines that could carry personal data - such as the connected account's email - are marked in the code not to be included in that transmission.
6.3 Screen usage analytics (Microsoft Clarity)
Purpose: understanding where people get stuck or give up - something an
event count cannot show. Knowing that half of all prioritizations are abandoned is useful; knowing at
which point in the sequence that happens is what makes it fixable.
Legal basis: legitimate interests (LGPD Art. 7(IX); GDPR Art. 6(1)(f)).
The app uses Microsoft Clarity, which records your interaction with the screen: where you tapped, how far you scrolled, how long you spent on each screen, and where you left.
All text is masked before it leaves your device. The app is configured in the most restrictive mode Clarity offers: the names of your lists and items are not transmitted - they are replaced with unreadable placeholders. What reaches us is the skeleton of the screen: positions, sizes and your taps. Not even we can read your list contents in those recordings.
Alongside it go your country, device model, OS version and a random identifier generated by Clarity, under its own policy.
If you are in the European Economic Area or the United Kingdom, your answer to the consent notice shown on first launch applies to this analytics as well, not only to ads.
6.4 Advertising (Google Ad Manager)
Purpose: sustaining the free version.
Legal basis: legitimate interests, and consent where local law requires it.
If you are not a subscriber, the app displays ads served by Google Ad Manager. Google collects, on its own, the device's advertising identifier, the IP address (which indicates your approximate region), and ad interaction. We send nothing of yours to the ad system - no identifier, no list content, no targeting.
On iOS, the app does not request tracking permission (ATT) and does not access the IDFA, because we do not track across apps. Ads there are contextual.
If you are in the European Economic Area, the United Kingdom or Switzerland, the app shows a consent form on first launch, where you choose whether your data may be used for personalised advertising. You can change your mind at any time: About → Privacy options. Outside those regions the form does not appear, because the legal basis there is legitimate interests - and you keep the control described in section 10.
Declining consent does not disable the app or the ads: they simply become non-personalised.
Google's privacy policy: policies.google.com/privacy
Subscribing to remove ads eliminates this entire section: with no ads, there is no ad SDK asking for anything.
6.5 Purchases (App Store and Google Play)
Purchases are processed entirely by Apple or Google. The app never sees your payment details and stores no purchase or account identifier. No server of ours is involved: subscription validity is verified on the device itself.
6.6 Support
Tapping "Support" opens your email app with a blank message addressed to us. No file is attached automatically, and no data is sent unless you write and send the message. Whatever you write to us is used only to reply.
7. Processors and international transfers
The data described in section 6 is processed by:
| Processor | Service | Policy |
|---|---|---|
| Google Ireland Limited / Google LLC | Analytics, Crashlytics, Ad Manager, Drive | policies.google.com/privacy |
| Apple Inc. | App Store, purchases (iOS) | apple.com/legal/privacy |
| Microsoft Corporation | Clarity (screen usage analytics) | privacy.microsoft.com/privacystatement |
This data is processed outside Brazil, on servers in the United States and other countries. The transfer takes place under Art. 33 of the LGPD, relying on the contractual clauses and protection commitments made by those processors.
8. How long we keep it
- On your device: until you delete the data, the app, or the app's data;
- In your Drive: until you delete the file or disconnect the app from your Google account;
- Analytics: per the retention configured in Firebase (default: 2 months for user-level data; aggregate reports are kept indefinitely);
- Crash reports: 90 days, per Crashlytics' default.
9. Your rights
The LGPD (Art. 18) and the GDPR grant you:
| Right | How to exercise it |
|---|---|
| Know whether we process, and access | Your data is all visible inside the app; nothing is held by us beyond what section 6 describes |
| Rectify | Edit and rename freely, on any screen |
| Portability | The share button on each list exports its content as text. It is one list at a time; for the whole set at once, write to us |
| Erase | Delete lists and items in the app. To erase everything at once, see section 10 - it does not depend on us, because no account of ours is involved |
| Withdraw consent | "Sign out" on the Backup screen revokes the Drive authorization. For advertising in the EEA/UK: About → Privacy options |
| Know whom we share with | Section 7 |
| Object to processing | Write to us |
How to ask: alexandremontebelo@gmail.com. We respond within 15 days.
You may also complain to Brazil's ANPD (gov.br/anpd) or, in the EEA/UK, to your country's data protection authority.
10. How to delete everything
There is no Prioritizer account to delete - which is why erasing your data does not depend on us. You directly control all three places it can live:
1. On the device. Uninstall the app. On Android you can also use "Clear data" in the system settings without uninstalling. Either one erases the database, the preferences and the technical log - nothing is left behind.
2. In your Google Drive. Go to myaccount.google.com/permissions, find Prioritizer and remove access. Google deletes the app's private folder along with the authorization, and the backup file goes with it. You do not need to ask us or wait for us.
3. In advertising and analytics. That data is aggregate and not associated with you - there is no identifier of ours linking it to you as a person, which makes it technically impossible to locate "yours". The control that does exist is your operating system's, and it applies to every app at once:
- Android: Settings → Privacy → Ads → Delete advertising ID;
- iOS: Settings → Privacy & Security → Apple Advertising, and Tracking.
If you still want us to stop any processing concerning you, write to us.
11. Children
Prioritizer is not directed to children under 13 and does not knowingly collect children's data. There is no kids' area, and the content is rated for general audiences. If you are a guardian and believe a child has provided us data, write to us.
12. Security
How your data is protected:
- The app's private storage. The operating system isolates each app's data: no other installed app can read Prioritizer's database;
- Device encryption. Android and iOS encrypt storage by default on modern devices with a screen lock - that is what protects your data if the device is lost or stolen;
- Your Google account credential lives in the system Keychain (iOS) or under Google Play Services' custody (Android). The app never sees or stores your password, which you type directly into Google's screen;
- All communication with Google happens over HTTPS;
- The risk surface is small by design. There is no server of ours that could leak, no Prioritizer account whose password could be stolen, and your list content never leaves the device except to your own Google Drive.
What this database does not contain
Worth stating plainly, first:
- No password. You type your Google password into Google's own screen; the app never sees it. The access token lives in the system Keychain, not in the database;
- No payment data. Card, billing and receipts belong to Apple and Google - they never pass through the app, which does not even store the purchase identifier;
- No ID document, phone number or address. The app has nowhere to ask for them;
- No sensitive data in the sense of Art. 5(II) of the LGPD and Art. 9 of the GDPR - health, biometrics, genetics, religion, political opinion, trade-union membership, sex life. There is no field for any of that in the app, and we neither collect nor infer any of it.
What the database holds is the text you wrote yourself in your lists, plus colors, checkmarks and your Prio balance. That content is yours: it stays on your device and, if you turn on backup, in your own Google Drive - it never reaches us, by any path.
No app can protect data on a compromised device (rooted or jailbroken) - if that is your case, it applies to everything installed on it, not just Prioritizer.
13. Changes to this policy
We will publish any changes on this same page, with the update date at the top. Changes that materially alter processing will be announced inside the app.