Privacy Policy
Effective date: October 10, 2026 (revised)
Also available: 한국어 · EN · 日本語 · 中文 · ES
This policy covers both the Jjan iOS app and the Jjan Android app. Where the two differ, the text is marked iPhone or Android.
1. Information You Enter and Store
The information below is stored on your device (in the app's private storage) and is never sent to the developer's servers (the developer does not operate any servers).
- Your baseline (sex, age, height, weight, usual intake, flush response) — used to personalize the light calculation
- Drink logs (drink type, serving, time), water logs, session context (e.g. work dinner, drinking alone), record notes, plans, and morning-condition and in-session check-in answers
- Your name (optional) and profile photo (optional — a photo you choose, cropped and saved. On Android the system photo picker is used, so only the one photo you pick is passed to the app)
- Voice files you record for the Quiet Exit (Escape) feature, and Escape settings (caller name, message text, etc.)
- Learning data for personalizing your estimates (per-session summaries and condition answers) — used only for on-device calculation
2. Account and Backup
iPhone — Sign in with Apple · iCloud
- Using the Service requires a Sign in with Apple account. The app receives an anonymous user identifier issued by Apple, a name (entered by you or provided by Apple), and the email address Apple provides (you can choose a private relay address — used only for display on the account screen). We do not collect any other information, such as your contacts.
- Your records, profile, plans, and profile photo are backed up to your own iCloud private database (CloudKit). This space is operated by Apple and belongs to your Apple account, and the developer cannot access it. Apple's handling is governed by apple.com/legal/privacy.
- Depending on your device's iCloud Backup settings, data may be included in your personal iCloud device backup.
Android — Sign in with Google · Google Drive app-data folder
- Using the Service requires Sign in with Google. The app receives your Google account's unique identifier, your name, and your email address. These are stored only on your device (in the app's private storage), used to tell accounts apart and to show on the account screen, and are never sent to the developer.
- For backup, the app accesses only the app-data folder of your Google Drive (drive.appdata scope). With this scope it can read and write only a hidden folder created by Jjan — it cannot see any of your other Drive files. The folder belongs to your Google account (it uses your Drive storage), and the developer cannot access it.
- The single backup file contains: session, drink and water records; your baseline; plans; quick-glass buttons; some app settings (sound, haptics, first day of the week, lock-screen quick log, two plan notifications); your profile photo; personalization learning data; and the number of sessions started. Your name, email address, and voice recordings are not included.
- Android Auto Backup (device backup and device-to-device transfer) is turned off. The only backup path for your records is the Drive app-data folder above.
- Google's handling is governed by the Google Privacy Policy.
Both platforms
- Signing out stops the backup; the records on your device remain as they are.
- Deleting your account (in the app: Profile > Account > Delete account) permanently erases the iCloud or Google Drive backup and the records, profile, photo, and recordings on your device. This cannot be undone. What is deleted, what is kept, and how to delete without the app are explained on the account deletion page.
3. How Data Is Processed and Kept
- All calculations (intoxication estimates, report generation, personalization) happen on your device. Estimates are for reference only and are never sent anywhere.
- Data is kept in the app's private storage under iOS or Android device protection (encryption). Backups and all network traffic use encrypted connections (HTTPS).
- Data is kept until you delete it or delete your account. Uninstalling the app removes the data on your device, but the cloud backup remains until you delete your account.
4. Notifications and Device Permissions
Water reminders, pacing alerts, morning reports, plan and rhythm reminders, and Escape (simulated call or text) are all local notifications scheduled on your device. No push servers are used.
iPhone: the app asks for notification permission, and for microphone permission only when you record a voice for Escape.
Android uses these permissions:
- Notifications (POST_NOTIFICATIONS) — to show the local notifications above. You can still use the app if you decline.
- Exact alarms (SCHEDULE_EXACT_ALARM) — used for on-time reminders and simulated calls only if you allow it; otherwise inexact alarms are used.
- Run at startup (RECEIVE_BOOT_COMPLETED) — to re-schedule reminders after a reboot
- Vibration and full-screen notifications (USE_FULL_SCREEN_INTENT) — for Escape's simulated incoming-call screen. No real calls are made.
- Microphone (RECORD_AUDIO) — requested only when you record your own voice for Escape. Recordings are stored only on your device, are never uploaded, and are not part of the Drive backup.
- Internet and network state — for backup, billing, ads, anonymous statistics, and downloading Insights articles
- Billing (Google Play Billing), and the advertising ID (AD_ID) and Android ad-services API permissions included by the Google ads SDK (see section 6)
- Background work (WAKE_LOCK, FOREGROUND_SERVICE) — used by Android's WorkManager to retry backups
Jjan does not use location, contacts, camera, or call-log permissions. The home-screen widget is drawn only from data on your device.
5. Payments
- iPhone: Premium subscriptions and purchases are processed by Apple App Store billing. The app only checks the transaction status Apple provides (whether a subscription is active).
- Android: Premium subscriptions and purchases are processed by Google Play Billing. The app checks the purchase information Google Play provides (product, purchase state, purchase token, auto-renew status) on your device to unlock Premium and acknowledge the purchase, and keeps the subscription status on your device. Google's handling is governed by the Google Privacy Policy.
- On either platform, the developer never receives payment details such as card numbers.
6. Advertising
If you are not a Premium user, a rewarded ad from Google AdMob may be shown when you start a session (except your first) and when you open record or report details. Jjan sends every ad request as non-personalized (personalized ads off). Premium subscribers see no ads.
- iPhone: Jjan does not track you for ad targeting and makes no App Tracking Transparency request.
- Android: even for non-personalized ads, the Google ads SDK may process your device's advertising ID and limited data such as IP address and device information for frequency capping, fraud prevention, and ad measurement. You can reset or delete your advertising ID in Android Settings > Privacy > Ads.
- For how Google processes data to serve ads, see How Google uses information from sites or apps that use its services and the Google Privacy Policy. Your drinking records and account details are never passed to the ads SDK.
7. Anonymous Usage Statistics
To improve the app, we send anonymous usage statistics with the privacy-first analytics tool Aptabase (on both iPhone and Android).
- What is sent: the name and time of app-usage events (for example, onboarding started or completed, sign-up completed, session started or ended, drink logged, morning report viewed, Insights article opened, paywall shown or closed, purchase completed, ad watched), simple attributes on some events (such as which article, product, or screen it came from), plus app version, OS version, device model, language setting, and a random session number that changes after an hour of inactivity.
- What is not sent: account identifiers, name, email, advertising IDs (IDFA or Android advertising ID), or the contents of your drinking records (drink type, number of drinks, times, session context, condition answers, etc.). Events like "drink logged" carry only the fact that it happened.
- Android: while offline, up to 500 unsent events wait in a queue file on your device (in storage excluded from device backup), are sent when you're back online, and are removed from the queue once sent.
- Statistics are not used for cross-app tracking. Aptabase's handling is governed by aptabase.com/legal/privacy.
8. Other Network Requests
- Insights articles: the app downloads the latest article list and images from jjan.io. These requests contain no personal information or records, but like any web request, the site's host (GitHub Pages) may process connection data such as your IP address.
- Review prompts: the rating prompt is shown and handled by the App Store (iPhone) or Google Play In-App Review (Android).
9. Sharing with Third Parties
Jjan does not sell personal information or share it with third parties. The services named above (Apple; Google Sign-In, Drive, Play Billing, AdMob and In-App Review; Aptabase; GitHub Pages) process data under their own policies while providing their features. If this ever changes, we will update this policy and give notice in the app.
10. Children's Privacy
Jjan is an app for users at or above the legal drinking age. We do not knowingly collect personal information from children.
11. Contact
Privacy questions: support@fizzlabs.ai · Account and data deletion: jjan.io/delete-account