Privacy Policy
1. Introduction
LEAPR ("we", "us", "our"), operated by Dawid Ratajczak, operates the LEAPR mobile application and the website at leapr.app (together, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have.
LEAPR is a gamified self-improvement application that presents voluntary daily challenges designed to build social confidence. We take your privacy seriously. This policy is written to be read, not to intimidate.
We are registered in Poland and this policy is designed to comply with the EU General Data Protection Regulation (GDPR), the Polish Act on the Protection of Personal Data (10 May 2018), and the Polish Act on the Provision of Electronic Services.
By using the Service, you confirm that you have read and understood this Privacy Policy.
2. Who is responsible for your data
LEAPR is the data controller responsible for your personal data.
LEAPR Team
Operated by: Dawid Ratajczak
Email: [email protected]
For all data-related questions, requests, and complaints, contact us at [email protected].
3. A note on the nature of the Service
LEAPR is a self-improvement and educational tool, not a medical or therapeutic service. Wellbeing and psychological data you provide is used solely to personalize your in-app experience and is not used for any clinical, diagnostic, or research purpose. For more information on what LEAPR is and is not, please read our Terms of Service alongside this Policy.
4. Minimum age
You must be at least 16 years old to use LEAPR. We do not knowingly collect personal data from anyone under 16. If we learn that we have done so, we will delete the data promptly. Parents or guardians who believe their child has created an account should contact [email protected] and we will act immediately.
5. What personal data we collect
5.1 Data you provide directly
- Account data: email address, username, and password; or authentication tokens if you sign in via Google or Apple.
- Psychological assessment responses: your answers to the onboarding questionnaire, which includes questions about your comfort level in social situations and how you experience social anxiety. These responses are used solely to calibrate your starting challenge level and difficulty.
- Post-challenge reflections: your ratings of challenge difficulty submitted after completing a challenge. These are stored on our servers and used only by the recommendation algorithm to adapt your challenge deck over time. They are not reviewed by staff.
- Communications: any information you send to our support team.
5.2 Data we collect automatically
- Activity and progress data: challenges started and completed, XP earned, levels reached, streaks, in-app engagement events, and feature usage.
- Device and technical data: device type and model, operating system and version, app version, language settings, time zone, and approximate location inferred from device or network settings.
- Diagnostics: crash reports and performance logs used to identify and fix technical issues.
- Push notification tokens: device identifiers used to deliver push notifications via Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM).
5.3 Data from third parties
- Subscription and payment data: when you purchase a subscription, our payment processors (Apple, Google, RevenueCat) provide us with confirmation of purchase, subscription status, and limited transaction metadata. We do not receive or store your full payment card details.
5.4 Psychological and wellbeing data (special category)
Your answers to the onboarding questionnaire, and potentially your post-challenge difficulty ratings, may constitute special-category data relating to mental health or psychological condition under Article 9 GDPR.
We process this data only on the basis of your explicit consent, which you will be asked to give separately and specifically before you complete the questionnaire. You may withdraw this consent at any time by contacting [email protected] or through your in-app account settings; doing so may limit features that depend on this data.
This data is:
- Never shared with other users.
- Never sold or transferred for advertising purposes.
- Used solely to personalize your challenge experience.
- Subject to additional access restrictions within our systems.
6. How we use your data and our legal bases
Under GDPR, we must have a lawful basis for each processing activity. The table below explains what we do and why.
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Account management; challenge delivery; XP, streak, and level tracking | Art. 6(1)(b) — performance of contract |
| Personalize your experience | Calibrating challenge difficulty; adapting recommendations based on your responses | Art. 9(2)(a) — explicit consent (psychological data); Art. 6(1)(b) for other data |
| Send push notifications | Streak reminders; re-engagement nudges | Art. 6(1)(f) — legitimate interests |
| Send marketing emails | Challenge tips; product updates (opt-in only) | Art. 6(1)(a) — consent |
| Process payments | Subscription management; billing | Art. 6(1)(b) — performance of contract |
| Improve and secure the Service | Analytics; crash diagnostics; fraud and abuse prevention | Art. 6(1)(f) — legitimate interests |
| Respond to support requests | Customer service | Art. 6(1)(b); Art. 6(1)(f) |
| Comply with legal obligations | Tax records; responses to lawful regulatory requests | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to processing carried out on this basis (see Section 11).
7. Who we share your data with
We do not sell your personal data. We do not share your psychological assessment responses, post-challenge reflections, or any other personal data with other users of the App.
We share data only with the following processors under written data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase (Auth, Firestore, Analytics, Crashlytics, FCM) | Authentication, database, app analytics, crash reporting, push messaging | United States (Standard Contractual Clauses in place) |
| Railway (Amsterdam, Netherlands region) | Backend hosting and database infrastructure | Data stored in the Netherlands (EU); Railway Corporation is a US-based company — Standard Contractual Clauses in place |
| RevenueCat | Subscription and purchase management | United States (Standard Contractual Clauses in place) |
| Apple (APNs / App Store) | Push notification delivery; App Store purchases | Subject to Apple's own privacy policies |
| Google (Google Play / Play Billing) | Google Play purchases | Subject to Google's own privacy policies |
We may also share data:
- With professional advisers (lawyers, auditors, accountants) bound by confidentiality obligations.
- In connection with a merger, acquisition, or sale of assets, where the recipient will be required to honor this Policy or you will be notified.
- With public authorities, regulators, or courts where required by law or to protect our legal rights.
A list of sub-processors is available on request at [email protected].
8. International data transfers
We are based in Poland (EU/EEA). Our backend hosting provider, Railway, stores your data in its Amsterdam, Netherlands data center. However, Railway Corporation, the company that operates this infrastructure, is based in the United States, and its own data processing terms confirm that some processing operations may take place there. For this reason, we treat Railway the same as our other non-EU processors for transfer purposes.
Google Firebase, RevenueCat, and Railway are all operated by US-based companies, even though certain data may be physically stored in the EU. We transfer data to them under the European Commission's Standard Contractual Clauses (SCCs), which provide appropriate safeguards for your personal data. Signed Data Processing Agreements incorporating SCCs are in place with each of these processors.
You can request a copy of the applicable safeguards at [email protected].
9. How we protect your data
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption of data in transit (TLS) and at rest.
- Access controls and the principle of least privilege — staff do not have routine access to individual psychological responses.
- Additional access restrictions for special-category (psychological and wellbeing) data.
- Regular security reviews of our own systems and our processors' practices.
No system is perfectly secure. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify the President of the Polish Personal Data Protection Office (UODO) within 72 hours and notify affected users as required by law.
10. How long we keep your data
| Data type | Retention period |
|---|---|
| Account data (email, username) | Duration of active account + 30 days following account deletion |
| Psychological assessment responses | Deleted when you delete your account |
| Post-challenge reflections | Deleted when you delete your account |
| Activity and progress data | Duration of active account + 30 days following account deletion |
| Diagnostic and analytics data | 12 months in individually identifiable form |
| Payment and subscription records | 5 years from the transaction date (Polish accounting law) |
| Email marketing list | Until you unsubscribe |
| Push notification tokens | Until account deletion or withdrawal of notification consent |
When data is no longer needed for the purpose for which it was collected, we delete or irreversibly anonymize it.
11. Your rights
11.1 Rights under GDPR / Polish law (EU/EEA users)
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — have your data deleted in certain circumstances.
- Restriction — limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent — withdraw consent (including for psychological/wellbeing data) at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint — complain to the supervisory authority.
Lead supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland. Website: www.uodo.gov.pl. You may also contact the data protection authority in your country of residence.
11.2 How to exercise your rights
Email [email protected] or use the account controls available in the App. We will respond within one month of receipt (extendable by a further two months for complex requests). We may need to verify your identity before acting on your request. Most requests are handled free of charge; we may charge a reasonable fee for requests that are manifestly unfounded or excessive.
12. Automated decision-making
We use your activity data and psychological assessment responses to generate personalized challenge recommendations. This recommendation process does not produce legal effects or similarly significant effects on you and does not constitute automated decision-making within the meaning of Article 22 GDPR. You remain entirely free to skip or ignore any recommendation.
13. Third-party platforms
The App is distributed through the Apple App Store and Google Play. Your use of those platforms is governed by their respective privacy policies, which we do not control. Subscriptions and purchases made through those stores are subject to Apple's and Google's terms.
14. Changes to this Privacy Policy
We may update this Policy from time to time. If we make material changes, we will notify you within the App or by email before the changes take effect, and we will update the "Last updated" date. Changes that require new consent (for example, new uses of psychological data) will require your active re-consent.
15. Contact us
LEAPR Team — operated by Dawid Ratajczak
Email: [email protected]