Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains how Lexiam BV ("Sisa," "we," "us") collects, uses, and shares information when you use the Sisa mobile application (the "App"). By using the App you agree to this Policy.
Sisa is a digital‑detox and accountability app. A core design principle is that the details of how you use your phone stay on your device. The sections below explain exactly what does and does not leave your phone.
Privacy at a glance
- On‑device. Your app usage, blocking schedules, and screen‑time data stay on your phone. We never see them.
- Cloud sync. We only sync your account details, achievements, and the social messages you send.
- No selling. We do not sell your personal data.
- Your control. You can delete your account and all associated data at any time from within the App.
This summary is for convenience only; the full policy below governs.
1. Who we are
The data controller for the App is Lexiam BV (company number 1024.430.856), contact support@sisa-app.com, Kroonstraat 43, 3018 Wijgmaal, Belgium.
We use third‑party service providers (Data Processors) to assist in operating the App - specifically for hosting, authentication, analytics, and notifications. These providers process data on our behalf and under our instructions.
2. Information we collect
a) Account information
You sign in with Sign in with Apple or Google Sign‑In. When you create an account we collect:
- A sign‑in identifier from your provider (a stable user ID; we never receive your Apple/Google password).
- Your email address, which your sign‑in provider supplies to our authentication service (Firebase Authentication) - Google provides your Google account email; Apple provides your email or a private "Hide My Email" relay address, depending on your choice. We use it to identify your account; it is not shown to other users.
- A username and display name you choose.
- An optional avatar you configure (a letter or emoji, a color, and - where earned - a background style).
b) Screen Time & device‑activity information - processed on your device
Sisa uses Apple's Screen Time / Family Controls, Device Activity, and Managed Settings frameworks to let you block apps and track your own usage against limits you set. Critically:
- The specific apps and categories you choose to block or monitor, and your usage of them, are represented by opaque tokens that remain on your device (in a private, app‑local storage group). We never transmit your app selections or your raw screen‑time/usage data to our servers or any third party, and we cannot see which apps you use.
- Schedules, daily limits, and bypass ("give me X more minutes") activity are likewise stored and evaluated locally on your device.
The only information derived from this that may leave your device are aggregate, non‑identifying counters used to award achievements - for example a count of "days under your limit" or "bypass‑free days," and referral/message counts. These are numbers only; they never include the identities of the apps you use.
c) Social & content information
If you use Sisa's social features, we store:
- Circles you create or join (name, description, public/private setting, optional topic category, emoji/color, member list, owner, and a "last active" timestamp).
- Messages you send to others - private 1:1 nudges ("interventions") and, if you are a circle's coach, broadcast messages to circle members. These contain the text you write and identifiers of sender/recipients.
- Achievements you unlock.
- Referrals: if you enter another user's username when you join, we record that you were referred by them (and credit the referrer). If you refer others, we count how many joined via you.
- Lightweight activity‑feed events within a circle (e.g., "X unlocked an achievement").
d) Device & technical information
- A push notification token (Apple Push Notification service / Firebase Cloud Messaging) so we can deliver notifications.
- App attestation data via Apple's DeviceCheck/App Attest (through Firebase App Check) to verify requests come from a genuine, untampered app instance and to prevent abuse.
- Usage and diagnostic analytics via Firebase Analytics. We log in‑app events to understand, in aggregate, how the App is used and where it can be improved, for example onboarding progress, permission grants, subscription and paywall steps, and feature usage such as creating a schedule, joining a circle, sending a nudge, or reacting to a coach message. These events are recorded together with the standard device/app information those SDKs collect (such as app version, device model, OS version, and a pseudonymous installation identifier). This analytics is first‑party and aggregate: we do not use advertising identifiers (such as the IDFA) and do not track you across other apps or websites.
- Crash and diagnostic reports via Firebase Crashlytics. If the App crashes, we collect an anonymous crash report (the type of crash, a stack trace, and basic device/app information such as app version, device model, and OS version) so we can diagnose and fix stability problems. These reports are not linked to your account identity.
- IP address and connection logs. When the App communicates with our providers (e.g., Firebase, App Check), they process your device's IP address and basic connection/log data to operate and deliver the service and to protect against abuse. We do not use your IP address to build a profile of you.
e) Subscription & purchase information
- When you subscribe, we and our subscription‑management provider (RevenueCat) and Apple process your purchase and entitlement status - for example, which product you bought, whether a subscription or free trial is active, and its renewal/expiry - so we can unlock paid access and restore it across your devices. This is linked to your account identifier.
- We do not receive or store your payment card or bank details. Payment is handled entirely by Apple under your Apple ID.
f) Ad attribution (Apple Ads)
- If you installed Sisa after tapping one of our ads on the App Store, Apple gives us a campaign‑level attribution token indicating which campaign, ad group, or keyword led to the install. We pass this token to RevenueCat, acting on our behalf, so we can understand which campaigns lead to subscriptions and spend our advertising budget sensibly.
- Apple's token is campaign‑level and does not identify you or your device. We use Apple's standard attribution only. We do not use the advertising identifier (IDFA), we do not ask for App Tracking Transparency permission, and we do not track you across other apps or websites.
We do not collect your contacts, your location, your photos, or your phone number.
3. How we use information
We use the information above to:
- Provide and operate the App (authentication, blocking, scheduling, circles, messaging, achievements, referrals).
- Deliver notifications you've enabled.
- Manage your subscription - unlock paid access, start or track a free trial, restore purchases, and prevent access after a subscription ends.
- Maintain aggregate statistics that power achievements and circle features.
- Keep the service secure and prevent fraud/abuse (App Check, security rules, rate limiting).
- Diagnose problems and understand, in aggregate, how features are used so we can improve the App.
4. How information is shared
- With other users. Your username, display name, and avatar are visible to other users (e.g., in circles you join and - if you make a circle public - in the public discovery list). Messages you send are visible to their recipients. Public circles you create are discoverable by other signed‑in users.
- With service providers. We use Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, and App Check) and Google Sign‑In, provided by Google LLC; Apple services (Sign in with Apple, Apple Push Notification service, and the App Store); and RevenueCat (subscription management - see §11). These providers process data on our behalf to run the App.
- For legal reasons. We may disclose information if required by law or to protect the rights, safety, and security of our users, the public, or Sisa.
- We do not sell your personal information.
5. Notifications
With your permission, we send push notifications such as accountability nudges from circle‑mates, coach messages, and (where applicable) a notice that you've become a circle's daily coach. Some notifications are "silent" and used only to refresh on‑device content. You can disable notifications at any time in your device Settings.
These notifications are service‑related - they help the App function and support your accountability. We do not send marketing or promotional push notifications, and we do not send marketing emails.
6. Data retention
Generally, we retain your information only for as long as is necessary to provide the services you have requested, comply with our legal obligations, resolve disputes, and enforce our agreements. More specifically:
- We keep your account and profile data while your account exists.
- Private nudges and circle invites are automatically deleted after they expire or are no longer needed (via automatic time‑to‑live policies).
- Coach broadcasts automatically expire and are deleted approximately 24 hours after they're sent; their "seen" receipts shortly after.
- Circle activity‑feed events are automatically deleted after roughly 30 days.
- On‑device data (your app selections, usage, schedules) is removed when you delete the App.
7. Security
We protect information using Apple's on‑device frameworks for screen‑time data, Firebase security rules that restrict who can read and write each record, App Check attestation, and server‑side validation in Cloud Functions. No method of transmission or storage is 100% secure, but we work to protect your information.
8. Your rights and choices
- Access / correction. You can view and edit your profile, avatar, username, circles, and schedules in the App.
- Deletion. You can delete your account from within the App's Settings. This removes your profile and associated data and revokes the Sign in with Apple token. Deleting the App also removes all on‑device data.
- Notifications. Manage or disable in device Settings.
- Analytics. We use Firebase Analytics for aggregate, in‑app usage insights (see §2d). You may limit the collection of usage data by adjusting your device's privacy settings (for example, limiting ad tracking under iOS Settings → Privacy & Security), or by contacting us at support@sisa-app.com.
- EEA/UK (GDPR). You have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw any consent at any time (this does not affect processing already carried out). To exercise these rights, contact us at support@sisa-app.com. You also have the right to lodge a complaint with a supervisory authority - in Belgium, the Belgian Data Protection Authority (Gegevensbeschermings‑ autoriteit / Autorité de protection des données, gegevensbeschermingsautoriteit.be)
- or the supervisory authority in your country of residence.
- Our legal bases (GDPR Art. 6). We rely on: performance of a contract (to provide the App and maintain your account); legitimate interests (to operate, secure, and improve the App and prevent abuse - for example aggregate analytics and crash reporting); consent (for example push notifications, which you can withdraw at any time in device Settings); and compliance with a legal obligation (where the law requires us to keep or disclose data).
- California residents (CCPA/CPRA). You may have the right to request access to or deletion of the personal information we hold about you, and not to be discriminated against for exercising these rights. To make a request, contact us at support@sisa-app.com with “California Privacy Request” in the subject line. We do not sell your personal information.
9. Children
The App is not directed to children under 13, and we do not knowingly collect personal information from them. Where local law sets a higher minimum age for consent to data processing (up to 16 in parts of the EEA/UK), users below that age should not use the App without verifiable parental or guardian consent. If you believe a child has provided us information, contact us and we will delete it.
10. International data transfers
We use Google Firebase, Apple, and RevenueCat services, which may process and store information on servers located in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
11. Subscriptions and payments
Sisa is a paid app offered as an auto‑renewable subscription (with a free trial) and a one‑time lifetime purchase. Payments are processed by Apple's App Store under your Apple ID, and our subscription‑management provider RevenueCat manages your entitlement across devices.
- What Apple handles. All payment processing is done by Apple. We do not receive or store your payment card, bank details, or full Apple ID.
- What we and RevenueCat receive. Your purchase and entitlement status - such as which product you purchased, whether a subscription or free trial is active, and its start, renewal, and expiry - linked to your account identifier so we can unlock and restore paid access. RevenueCat also processes a pseudonymous app/user identifier and standard device information to provide the service. See RevenueCat's Privacy Policy.
- Managing your subscription. You can manage, cancel, or turn off auto‑renew anytime in your Apple ID account settings, and restore purchases from the paywall or the App's Settings. Billing terms are set out in our Terms of Service.
12. Third‑party services
- Google Firebase (Google LLC) - Authentication, Firestore, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, App Check. See Google's Privacy Policy.
- Google Sign‑In (Google LLC) - an optional sign‑in method. See Google's Privacy Policy.
- Apple (Apple Inc.) - Sign in with Apple, Family Controls / Device Activity (on‑device), Apple Push Notification service, App Store, Apple Ads campaign attribution. See Apple's Privacy Policy.
- RevenueCat (RevenueCat, Inc.) - subscription management, entitlement status, and Apple Ads campaign attribution reporting. See RevenueCat's Privacy Policy.
13. Cookies and the website
Our website (sisa-app.com) is a simple, static site. It does not use analytics, advertising, or tracking cookies, and it does not track you across sites. Our hosting provider may set a strictly necessary cookie for security and load balancing; these are essential to serve the site and do not require your consent. The Sisa app itself does not use web cookies. If we add website analytics in the future, we will update this Policy and, where required, ask for your consent first.
14. Changes to this Policy
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide notice in the App. Continued use after changes means you accept the updated Policy.
15. Contact
Questions or requests: support@sisa-app.com. Postal address: Kroonstraat 43, 3018 Wijgmaal, Belgium.
