← Back to product
PAUSEVOIn development

Privacy policy

Privacy notice for the local PAUSEVO 1.0.0 release candidate. PAUSEVO keeps nicotine, urge, plan, SOS, goal and money records in encrypted local storage and does not add or send those records to advertising services. PAUSEVO has no account, developer backend, cloud sync, developer-operated analytics, FCM or remote AI. Google consent, advertising and Play Billing SDK data practices are disclosed separately and still require reconciliation with the signed production AAB and Google Play Data Safety form.

Last updated
27 July 2026
Version
1.0.0
Package name
ee.blacksunset.pausevo
Platform
Android

This page explains the current data practices of

PAUSEVO

01

Controller and scope

The publisher and controller for developer-managed processing is Blacksunset OÜ, Estonian registry code 16513658. Contact: info@blacksunset.ee.

Hariduse põik 1, Kõrveküla alevik, Tartu vald, Tartu maakond, 60512, Estonia.

If you email support, the studio processes your email address and message only to answer the request and meet applicable legal obligations.

02

Data handled by the app

  • Local nicotine and plan data can include source type and user-given name, unit and strength details, plan role, chosen path, baseline, schedule, targets, use-event time and quantity, context or note, lapse classification and explicit day confirmations.
  • Local urge and support data can include urge ratings, triggers, support windows, if-then plans, SOS actions and outcomes, reminder preferences, session status and timing values needed to pause and resume a coping exercise.
  • Local goal and money data can include goal text and an optional goal photo, user-entered prices and usage assumptions, savings estimates, actual-transfer records and hypothetical growth parameters. PAUSEVO does not connect to a bank, broker or investment account.
  • Local app state also includes onboarding and accessibility choices, language, appearance and palette preferences, notification settings, content exposure state and the cached ad-removal entitlement needed to decide whether a banner may be shown.
  • Google Mobile Ads may automatically collect and share an IP address that can be used to estimate approximate location, app and advertising interactions, diagnostic or performance information, and device or account identifiers for advertising, analytics and fraud prevention. These SDK-handled categories remain in the Google Play Data Safety disclosure.
  • PAUSEVO never adds nicotine or use records, urge ratings, plan details, goals, notes, money records or SOS details to an ad request and never uses them for custom advertising targeting.
03

Permissions

  • Notification permission is optional and supports only reminders the user enables. Notification scheduling and content stay local, and denying the permission does not block the core app.
  • A goal photo and user-chosen backup or export destination use Android system pickers. PAUSEVO does not request broad photo, media or shared-storage access.
  • Google SDK dependencies contribute INTERNET, ACCESS_NETWORK_STATE, READ_BASIC_PHONE_STATE, advertising-ID and Privacy Sandbox AdServices access, while Play Billing contributes its billing declaration to the current staging merged manifest. WorkManager contributes WAKE_LOCK and FOREGROUND_SERVICE; PAUSEVO does not directly call telephony APIs or run a persistent custom foreground service. PAUSEVO does not request precise device-location, microphone, contacts, Health Connect, accessibility-service, exact-alarm or broad-storage permission. The exact final AAB permission set and the Google Mobile Ads phone-state declaration remain release-audit gates.
04

Storage and security

  • PAUSEVO stores its Room working database locally with SQLCipher Android 4.17.0. A random 32-byte database key is wrapped with AES-GCM by a non-exportable Android Keystore key; the app fails closed if the required key material cannot be opened.
  • Goal photos copied into PAUSEVO storage are encrypted separately with AES-256-GCM and profile-specific Keystore-protected key material. App preferences remain in app-private local storage.
  • A portable backup is created and restored only at the user’s request. It is password-encrypted and authenticated; restore validates the backup and switches to the replacement encrypted local profile only after validation succeeds. PAUSEVO cannot recover a forgotten backup password.
  • User-initiated readable exports are available as JSON, CSV or PDF. They are not encrypted, may contain sensitive PAUSEVO records, require an explicit warning acknowledgement, and are written only to the destination selected through Android’s system document picker.
  • Android automatic cloud backup and device-to-device app-data transfer are disabled, and the backup rules exclude every app-data domain. User-created backup and export files remain under the user’s chosen storage provider and must be managed separately.
05

Third-party services

  • PAUSEVO has no account service, PAUSEVO or Blacksunset backend, cloud database or sync, separate PAUSEVO- or Blacksunset-operated analytics or crash-reporting service, Firebase Cloud Messaging, remote configuration, session replay, attribution SDK or remote AI service.
  • The candidate uses Google Mobile Ads Next-Gen 1.3.0 for the allowlisted Today banner and Google User Messaging Platform 4.0.0 to update and manage applicable advertising privacy choices before an ad request is permitted.
  • PAUSEVO manually disables the Google Mobile Ads 1.3.0 SDK crash-reporting handler. That opt-out does not remove Google SDK diagnostics and performance categories from the Data Safety disclosure; the final signed AAB and runtime traffic must still be reconciled with Google’s documentation and Play forms.
  • Google Play Billing 9.1.0 queries the candidate remove_ads_lifetime product and temporarily handles ProductDetails, the Play-supplied localized price, purchase state and purchase token needed to grant, acknowledge and restore ad removal. PAUSEVO persists only the cached entitlement and the latest successful reconciliation time, not the token, price or ProductDetails. Google Play, not PAUSEVO, processes payment-card and bank information.
  • If the user chooses to write to a support person from SOS, PAUSEVO passes only the editable message text to Android’s share chooser. PAUSEVO does not choose a recipient or send the message automatically; the app and provider selected by the user then process that message under their own terms.
  • Learning cards can open user-selected WHO, Cochrane, PubMed or national health-authority sources in an external browser. PAUSEVO opens the listed HTTPS source without appending profile or health records; the browser and destination site receive ordinary web-request data and process it under their own policies.
06

Advertising and purchases

  • The active ad-supported V1 runtime has one small 320 × 50 banner placement on the passive Today view after consent and entitlement are resolved. No banner is placed in SOS, urge timing, logging, Settings, purchase, consent, privacy, backup, export, deletion or other sensitive and critical flows.
  • remove_ads_lifetime is the only purchase candidate. It is a restorable one-time non-consumable, not a subscription, Pro plan, donation or feature bundle. It removes only advertising; every PAUSEVO feature remains free.
  • Development and staging use Google test ad identifiers. No public Play product, live localized price or production AdMob identifier is claimed: those values, UMP settings, purchase behavior and licence testing remain release-audit gates.
  • PAUSEVO does not add nicotine, urge, plan, goal, money or SOS records to advertising requests, does not derive custom ad targeting from those records and does not sell personal data.
07

Retention and deletion

  • After explicit confirmation, the in-app delete-all action removes the local PAUSEVO health and profile records, encrypted database, encrypted goal photos, settings, notification schedules and app-language choice, then creates a fresh empty encrypted local profile. It deliberately preserves the install-scoped cached ad-removal entitlement and its last successful Play reconciliation time so a paid user does not receive a banner while ownership refreshes. Clearing app storage in Android settings or uninstalling removes that cache and the remaining app-private local data; the permanent purchase stays with the purchasing Google Play account and can be restored.
  • A backup, readable export or support message saved or shared outside PAUSEVO must be managed and deleted separately in the destination chosen by the user. Once local data is deleted without a usable backup, PAUSEVO cannot restore it from a server because no PAUSEVO server copy exists.
  • PAUSEVO has no developer-managed account or cloud profile to delete. If a user contacts support, the email providers and Blacksunset receive the sender address, message and attachments; deletion of that correspondence can be requested at info@blacksunset.ee subject to applicable legal retention duties. Google retains consent, advertising and purchase information under its own policies.
08

Your rights and contact

Where data-protection law applies, you may request access, correction, deletion, restriction or portability of personal data controlled by the publisher, and object to processing. Most product data described here is held only on your device and can be managed there.

You may also lodge a complaint with the Estonian Data Protection Inspectorate.

This policy may be updated when the app or legal requirements change. The revision date above shows the current version.