Universal Privacy Policy

Effective Date: 2026-05-28 Last Updated: 2026-05-28 Version: v1

This Privacy Policy explains how RH Mobile Studio LLC, a California limited liability company (California Secretary of State File No. B20260226415, formed May 12, 2026; principal office: 2108 N St, Ste N, Sacramento, CA 95816) (“RH Mobile Studio,” “Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use any of our mobile, web, or other applications and services, including Pickr, Embr, Taskr, Trackr Food, Trackr Activity, Trackr Grocr, Savr, Speakr, Wakr, Accountr, Bookr, EmojiCreator, ChromaCascade, snapgather, and any current or future application we publish (each, an “App,” and collectively, the “Apps” or “Services”).

This Policy is incorporated by reference into our Universal Terms of Service & EULA. Capitalized terms not defined here have the meaning given in the Universal Terms.

Plain-English summary. We are a small independent studio. We try to collect the minimum data needed to make our apps work. We do not sell your personal information. Where possible, your data stays on your device. When data does leave your device (for purchases, AI features, crash reports, or sync), we use reputable processors and tell you who they are. You can ask us to delete your data at any time at privacy@rhmobilestudio.com.


1. Scope

This Policy applies to personal information we process about you when you:

  • Download, install, or use any App;
  • Interact with our websites, including https://rhmobilestudio.com and per-app marketing pages;
  • Make in-app or web purchases or manage a subscription;
  • Use AI-assisted features;
  • Contact us for support, accessibility accommodations, or legal notices;
  • Apply for a job or correspond with us about partnerships.

This Policy does not apply to third-party services we link to or integrate with (Apple, Google, Stripe, RevenueCat, Anthropic, OpenAI, Supabase, Sentry, Expo, and any other identified processors). Those parties have their own privacy policies; we list the main ones in Section 6.


2. Information We Collect

We follow a data-minimization principle: we collect only what we need, and we prefer to process data on your device when feasible.

2.1 Information you provide directly

  • Account information (only for Apps that offer accounts, e.g., snapgather, Bookr web): email address, password hash, display name.
  • User Content: anything you create or upload — food entries, alarms, activity logs, photos, audio, text prompts to AI features, event photos, bookkeeping entries, color presets, etc.
  • Purchase metadata: anonymized purchase receipts, entitlement state, promo-code usage. Payment card data is processed by Apple, Google, or Stripe and never reaches our servers.
  • Support correspondence: emails, screenshots, attachments, and device/OS info you choose to share.
  • Accessibility requests sent to accessibility@rhmobilestudio.com.

2.2 Information collected automatically

  • Device & technical data: device model, OS version, app version, locale, time zone, anonymized device identifier (e.g., RevenueCat App User ID), and crash diagnostics (stack traces, breadcrumbs).
  • Performance & error logs: scrubbed of user-entered text and personal identifiers wherever feasible.
  • In-app interaction events (only in Apps that explicitly disclose analytics, with consent where required): screen views, feature toggles, anonymized usage counts — never the content of your entries.
  • Network metadata: IP address (used for fraud prevention and approximate region, then discarded or truncated), TLS handshake metadata.

We do not use cross-app advertising identifiers (IDFA, AAID) to track you across other apps or websites, and we do not implement the AppTrackingTransparency tracking prompt unless and until an App genuinely requires it (none currently do).

2.3 Sensitive categories

Some Apps process potentially sensitive information only on your device, only when you invoke the relevant feature, and only to deliver that feature:

Category Where How it’s handled
Food / nutrition entries Trackr Food On-device storage; AI image analysis (Anthropic) only when you tap “analyze photo”
Activity / step / motion data Trackr Activity, Wakr On-device sensors; not transmitted unless you explicitly export
Photos / camera Trackr Food, snapgather, EmojiCreator Camera roll access is permission-gated; images leave the device only for explicit upload or AI analysis
Audio / microphone Speakr Captured locally; transcripts processed in-memory; no recording stored server-side without explicit opt-in
Approximate location Bookr, Trackr Grocr Used only to find nearby stores/items; not stored as a precise track
Calendar / events snapgather Used only to organize your event photos
Contacts Not collected by any current App —
Precise GPS Not collected by any current App —
Health / HealthKit Not currently integrated —
Biometrics Not collected —

We do not knowingly process information from children under the age of 13 (or under 16 in the EEA/UK). See Section 12.


3. How We Use Information

We use personal information to:

  • Provide, operate, maintain, and secure the Apps;
  • Process purchases and manage subscriptions (via Apple, Google, Stripe, RevenueCat);
  • Deliver AI-assisted features you invoke;
  • Diagnose, debug, and improve the Apps (crash reports, anonymized performance metrics);
  • Respond to your support, accessibility, privacy, or legal requests;
  • Prevent fraud, abuse, security incidents, and Terms violations;
  • Comply with legal obligations (tax, accounting, court orders, lawful requests);
  • Send transactional communications (purchase receipts, security alerts, terms updates) — not marketing, unless you opt in.

Lawful bases (GDPR/UK GDPR). Where applicable, we rely on: (i) contract to provide the Apps you requested; (ii) legitimate interests in operating, securing, and improving the Apps (balanced against your rights); (iii) consent for optional analytics, marketing, or sensitive processing where required by law; and (iv) legal obligation for compliance.


4. AI & Machine-Learning Features

When you invoke an AI feature (e.g., analyzing a food photo in Trackr Food), the input you provide may be transmitted to a third-party AI provider — currently Anthropic and/or OpenAI — under their respective terms and zero-data-retention or limited-retention APIs where available. We do not use your inputs or outputs to train our own models or third-party foundation models.

AI output is probabilistic and may be inaccurate. See Section 7 of the Universal Terms.


5. How We Share Information

We share personal information only as follows:

  • Service providers (processors) acting under contract on our behalf:

Apple App Store / Google Play — distribution & billing – Stripe — web billing – RevenueCat — subscription/entitlement management – Anthropic, OpenAI — AI feature execution (zero/limited-retention endpoints where available) – Supabase — backend storage for Apps that have accounts (snapgather, Bookr web) – Sentry / Crashlytics — crash & error reporting (scrubbed) – Expo / EAS — over-the-air updates and build delivery – Cloud hosting providers (e.g., AWS, GCP, Vercel, Netlify) supporting the above

  • Legal & safety: when required by law, lawful process, or to protect rights, safety, or property.
  • Business transfers: in a merger, acquisition, financing, or sale of assets, subject to the surviving entity honoring this Policy.
  • With your direction: when you choose to share content (e.g., export, share sheet, public link).

We do not:

  • Sell personal information for money or other valuable consideration as defined by the CCPA/CPRA;
  • Engage in “sharing” for cross-context behavioral advertising (CCPA/CPRA);
  • Use sensitive personal information to infer characteristics about you;
  • Transmit User Content to third parties for advertising or model-training purposes.

6. Third-Party Services & International Transfers

Third-party processors operate their own platforms. Their privacy practices are governed by their policies, summarized for convenience:

  • Apple: https://www.apple.com/legal/privacy/
  • Google: https://policies.google.com/privacy
  • Stripe: https://stripe.com/privacy
  • RevenueCat: https://www.revenuecat.com/privacy
  • Anthropic: https://www.anthropic.com/legal/privacy
  • OpenAI: https://openai.com/policies/privacy-policy
  • Supabase: https://supabase.com/privacy
  • Sentry: https://sentry.io/privacy/
  • Expo: https://expo.dev/privacy

We operate from the United States. If you use the Apps from outside the U.S., your information may be transferred to, stored, and processed in the U.S. and in countries where our processors operate. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework where the processor is certified, with supplementary measures as appropriate.


7. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy or required by law.

Category Typical retention
Local on-device data (AsyncStorage, SecureStore, IndexedDB) Until you delete the App or clear local data
Account records For the life of the account + up to 90 days after deletion request
Purchase / billing records 7 years (tax & audit)
Crash reports & security logs 90 days, scrubbed
Support correspondence Up to 3 years
AI feature inputs Not retained by us; processor retention per Section 4

After retention periods expire, we delete or de-identify the data using industry-standard methods.


8. Your Rights & Choices

Depending on where you live, you may have rights to:

  • Access / Know: request a copy of personal information we hold about you.
  • Correct / Rectify: request correction of inaccurate information.
  • Delete / Erase: request deletion of personal information, subject to legal retention.
  • Port: receive your data in a portable format.
  • Restrict / Object: limit or object to certain processing, including profiling.
  • Withdraw consent: where processing is based on consent.
  • Opt out of “sale”/”sharing” (CCPA/CPRA): we do not sell or share, but you can confirm your status.
  • Non-discrimination: we will not discriminate against you for exercising rights.
  • Appeal (where required, e.g., Virginia, Colorado, Connecticut): appeal a denial of a rights request.

To exercise these rights, email privacy@rhmobilestudio.com from the email associated with your account (or describe enough about your use to let us verify identity). We respond within the time required by applicable law (typically 30–45 days; we may extend once with notice). We do not charge for the first request in a 12-month period.

Authorized agents (CCPA/CPRA): you may designate an agent to submit requests; we will verify your identity and the agent’s authority before disclosing data.

Do Not Track / Global Privacy Control. Our websites recognize the Global Privacy Control (GPC) signal where required by law and treat it as an opt-out of “sale” and “sharing.”


9. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including:

  • TLS for all data in transit;
  • Encryption at rest for server-side storage where supported by the provider;
  • Use of Keychain / Keystore (expo-secure-store) on device for auth tokens and sensitive material — never plaintext AsyncStorage;
  • Least-privilege service-account permissions and Row-Level Security on multi-tenant tables;
  • Scrubbing of user-entered text, identifiers, and tokens from crash reports and logs;
  • Vendor due diligence and contractual data-protection terms;
  • Routine dependency, secret-scanning, and security review.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and regulators as required by law.


10. Privacy Claim Procedure & Notice-and-Cure

This Section applies to privacy-related claims and works alongside Section 8 of the Universal Terms.

Before initiating any lawsuit, demand letter, administrative complaint, arbitration, or regulatory complaint based on an alleged privacy violation, you agree to:

  1. Send written notice to privacy@rhmobilestudio.com identifying the App, the specific data or behavior at issue, the alleged violation, and the relief sought;
  2. Allow us at least 60 days to investigate and, where appropriate, remediate, delete, or provide an equivalent corrective measure at no cost to you; and
  3. Cooperate in good faith with our remediation.

Claims filed without completing this process are premature and are a material breach of the Universal Terms. Statutory damages claims that are duplicative of actual damages already remedied are waived to the extent permitted by law. Claims based solely on alleged technical violations causing no concrete harm to you are subject to dismissal and contractual waiver. Nothing in this Section waives non-waivable statutory rights under GDPR, CCPA/CPRA, BIPA, or similar laws.


11. Region-Specific Disclosures

11.1 California (CCPA/CPRA)

In the prior 12 months we may have collected the following categories: identifiers (device ID, email), commercial information (purchase/subscription state), internet/device activity (app/version, crash data), geolocation (approximate, when feature-gated), audio/visual (when you invoke camera or mic features — on-device unless explicitly uploaded), and inferences (entitlement tier, feature usage counts).

  • Sources: directly from you; automatically from your device; from our processors.
  • Business purposes: as described in Section 3.
  • Sale/Share: No. We have not sold or shared personal information in the prior 12 months.
    • Sources: directly from you; automatically from your device; from our processors.
    • Business purposes: as described in Section 3.

    Sensitive personal information: processed only to provide the requested feature; not used to infer characteristics.

    Retention: as in Section 7.

    Rights: access, correct, delete, opt out of sale/share (already off), limit sensitive PI, non-discrimination, appeal (where applicable).

    11.2 European Economic Area, United Kingdom, Switzerland

    Controller: RH Mobile Studio LLC, 2108 N St, Ste N, Sacramento, CA 95816, USA. EU/UK representative: to be appointed and listed here prior to material EU/UK marketing. Lawful bases: see Section 3. Transfers: Standard Contractual Clauses / UK IDTA / DPF, plus supplementary measures. Supervisory authority: you may lodge a complaint with your local DPA.

    11.3 Other U.S. States (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, etc.)

    We honor access, correction, deletion, portability, and opt-out rights as required by your state’s law, appeal process where mandated. Use privacy@rhmobilestudio.com.

    11.4 Canada (PIPEDA), Brazil (LGPD), Japan (APPI), Australia, others

    We honor analogous rights under applicable law. Contact privacy@rhmobilestudio.com.


    12. Children’s Privacy

    The Apps are not directed to children under 13 (or under 16 in the EEA/UK, or the digital-consent age in your jurisdiction), and we do not knowingly collect personal information from such children. If you believe we have inadvertently collected information from a child, contact privacy@rhmobilestudio.com and we will delete it. The Apps do not knowingly comply with COPPA verifiable-parental-consent requirements because they do not target children; we will not roll out features that would change that without first implementing COPPA-compliant controls.


    13. Cookies & Similar Technologies

    Our marketing websites may use a minimal set of strictly necessary and (where applicable, with consent) analytics cookies. We do not use advertising or cross-site tracking cookies. Mobile Apps use platform-native storage (AsyncStorage, SecureStore, localStorage in WebViews) for app function, not for tracking across other apps or sites.


    14. Changes to This Policy

    We may update this Policy from time to time. We will indicate material changes by updating the “Last Updated” date and Version above, and where required, by in-app notice, email, or prominent posting. Continued use of the Apps after the effective date constitutes acceptance.


    15. Contact

    RH Mobile Studio LLC 2108 N St, Ste N, Sacramento, CA 95816, USA Privacy requests: privacy@rhmobilestudio.com Accessibility: accessibility@rhmobilestudio.com Legal: legal@rhmobilestudio.com DMCA: dmca@rhmobilestudio.com Website: https://rhmobilestudio.com


    This document is a template prepared for internal product use and is not legal advice. Have a qualified attorney review before public release, especially for jurisdictions where you actively market.


    Published by RH Mobile Studio LLC
    A California limited liability company · California Secretary of State File No. B20260226415
    2108 N St, Ste N, Sacramento, CA 95816, USA
    Privacy: privacy@rhmobilestudio.com · Legal: legal@rhmobilestudio.com
    Website: https://rhmobilestudio.com