Effective from 26 September 2026

Privacy policy

The app works entirely on your phone without an account. Every additional service is optional and off until you turn it on (the only exception is crash reports, see section 9), and processes only what it needs to work. This document describes which data is processed, where and why.

1. Who the controller is

The Bonpace app for Android and iPhone and the website bonpace.app (also goal-coach-21931.web.app) are operated by Solunit s.r.o., Werferova 6, 040 11 Košice, Slovakia, company ID (IČO) 54 035 635, registered in the Commercial Register of the Municipal Court Košice, section Sro, file no. 52398/V ("we"). E-mail: contact@solunit.dev. Contact details are in the Contact section.

2. Data that stays on your phone

All the content you create in the app – goals, steps, plans, outcome records, notes, feelings, photos, voice messages, the journey film, the coach's memory, reminders – is stored locally only, in the app's private storage. Unless sync is turned on, it never leaves the device. Uninstalling the app deletes it; you can save a copy manually at any time (Settings → Export and delete data).

3. Optional integrations on the phone

IntegrationWhat the app readsWhat it stores
CalendarEvents of the calendars you select (time, title for showing a conflict)Derived free slots and the title of an overlapping event for at most 21 days; events it created itself, by ID
MicrophoneThe recording during a voice record or a message to yourselfThe message to yourself locally; a voice record is discarded after transcription
Notifications, alarms–The reminder schedule locally

You turn each integration on and off in Settings; revoking the permission in the system turns it off as well. Calendar data never leaves the device – it is not synced even with sync turned on, and each device reads it on its own. The app currently does not use location or Health Connect and reads no health data.

4. AI coach (optional)

The AI features (goal breakdown, help with an obstacle, voice transcription, search terms for a photo) are off until you turn them on. You have two options:

Built-in AI: requests go through our server (a Cloud Function in the EU, Frankfurt region) to Google Gemini with our key. The server checks that you are signed in, counts requests for the daily limit (it stores only the account identifier, the day and the count) and forwards the request. The content technically passes through the server, but we neither store nor log it – unlike sync, where the content is encrypted and cannot be read. Google Gemini is used on the paid tier, where data is not used to train models; processing is governed by the Gemini API terms. Requires signing in (with a Google account, on iPhone also with Apple).

Your own key: the AI features work through an OpenAI-API-compatible gateway and your own API key (e.g. Google Gemini); requests go from the phone directly to the provider. With each request, only what the given task needs is sent to the provider you chose: the title and plan of the current goal, recent records without notes (unless you enabled them), or the recording to transcribe. Before the first use you see a preview of exactly what is sent. The key is stored only on the phone and is not part of the backup or sync. Processing at the provider is governed by its terms.

5. Finding a photo for a goal

If you use "Find a photo", only the search term (1–2 English words) is sent to Openverse. The author credit and licence are stored with the photo.

6. Account and sync between devices (optional)

After signing in (Firebase Authentication) with Google, or on iPhone also with Apple, we receive your account identifier, e-mail and name. With Sign in with Apple you can hide your e-mail – we then receive only a random relay address from Apple; Apple sends the name only on the first sign-in, if you share it. Sync stores only encrypted data in Cloud Firestore and Cloud Storage (Google, Frankfurt region, EU) (XChaCha20-Poly1305). The key is created on your device and we keep it on our server, wrapped (AES-256-GCM) with a master key in Google Secret Manager (EU), separately from the data; after you sign in, our service (a Cloud Function in Frankfurt) releases it only to your account. That is why signing in is enough on a new phone – no phrase needed.

This means the data is not end-to-end encrypted: technically it could be decrypted by someone with access to both the data and the master key (the service operator). We do not do that, and access to the project is limited to the operator. The key is also stored on the device (Android Keystore, and possibly Block Store in Google Play services; on iPhone the iOS keychain, on that device only). Signing out removes the key from the device; “Delete server data” (Settings → Account and sync) or “Delete data → Everywhere, including the server” (Settings → Export and delete data) deletes all data, the stored key and partner shares on the server; the sign-in account itself is deleted too (for an Apple account the app also revokes its access to it). Signing out also removes the data from the phone (it stays in the account).

7. Accountability partner (optional, requires an account)

If you invite a partner, the server stores in readable form only: the name you chose for the partner, the days done in the current week (7× yes/no), whether you're done today, since when the goal has been running, the number of missed days, the text of a commitment with a witness if any, your name from the account and the identifiers of both accounts. Your partner can send you a reaction (an emoji or a sentence of up to 80 characters), which is stored with us and on both phones. The content of goals, notes, feelings, the program, photos and the calendar are never shared. Either side can end the partnership; the document is then deleted.

8. Bonpace Plus subscription (optional)

Purchases are processed by Apple (App Store) or Google (Google Play); we never see your payment details. We check the subscription status through RevenueCat (RevenueCat, Inc., USA), which receives the purchase receipt from the store. RevenueCat processes the purchase identifier, product, price, currency, store country, dates (start, renewal, expiry, trial), a random app identifier and, if you are signed in, your Bonpace account identifier (not your email or name). Our server (Cloud Function, Frankfurt) stores whether Plus is active and until when (for the built-in AI daily limit), and a purchase record: store, product, transaction identifier, dates, country, currency, price and your Bonpace account identifier. The record lets us keep your subscription working if we ever change the service provider.

Transfers to the USA are covered by standard contractual clauses. When you delete your server data, we also delete the subscription record on our side and at RevenueCat; the store keeps payment records under its own rules.

9. Crash reports and anonymous usage statistics

Crash reports are on by default; usage statistics are collected only once you turn them on. You can change both at any time in Settings → AI and privacy → Diagnostics and statistics; the change takes effect immediately. The app does not use the advertising ID and shows no ads.

Crash reports (Firebase Crashlytics): if the app crashes, the stack trace, device model, Android and app version and time are sent. They contain neither the content of goals nor the account identifier.

Usage statistics (Firebase Analytics): events about which features are used and whether they help – for example "goal activated: routine, 5× a week", "outcome recorded: done, by voice", "review: shrink", "partner reaction sent: emoji" – and the screens shown. Events carry only kinds, counts and yes/no; never goal titles, notes, reaction text, names or identifiers of goals or the account. Together with them a random installation identifier, device model, system version and an approximate location derived from the IP address (country/city, per Google Analytics settings) are processed. The data is used solely to evaluate and improve the app; it is not used for advertising or sold.

10. Website

The site is hosted on Firebase Hosting (Google) and loads the Noto Sans font from Google Fonts; these services log the IP address to deliver content. The site uses no cookies and no analytics. Your language choice (Slovak / English) is kept only in your browser's local storage.

11. Legal basis and retention

Local data is processed exclusively by your device. Account, sync, partner and the Plus subscription: performance of a contract (providing the feature you turned on). Crash reports: legitimate interest in the stability of the app, with the option to object at any time by turning them off in settings. Usage statistics: your consent, which you can withdraw at any time by turning them off. Data on the server is retained as long as you have an account or a partnership; crash reports for 90 days, usage statistics for 14 months.

12. Your rights

You have the right of access, rectification, erasure and portability (JSON export directly in the app) and the right to object. You can delete everything on the server directly in the app (Settings → Account and sync → Delete server data; goal detail → Partner → End) or write to us at contact@solunit.dev. Steps, even without the app: Delete your account and data. You can lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or your local supervisory authority.

13. Children

The app is not intended for children under 16 and we do not knowingly collect data from them.

14. Changes

In the event of a material change we update the effective date and notify you in the app.

Contact

Privacy questions, data deletion requests or interest in the closed test: contact@solunit.dev.

Solunit s.r.o., Werferova 6, 040 11 Košice, Slovakia, company ID (IČO) 54 035 635, registered in the Commercial Register of the Municipal Court Košice, section Sro, file no. 52398/V.