Privacy Policy
Effective: 25 June 2026 · Version 1.1
This Privacy Policy describes how Gua (“Gua”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal data when you use the Gua mobile applications, browser extension, and the website at feelragua.com (together, the “Services”). It explains your rights under the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and Israel’s Protection of Privacy Law, 5741‑1981, as amended by Amendment 13 (in force 14 August 2025).
By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.
- 1. Who is responsible for your data
- 2. Personal data we collect
- 3. Purposes and legal bases
- 4. The consequences of not providing data
- 5. Recipients and processors
- 6. International data transfers
- 7. How long we keep data
- 8. Your rights
- 9. U.S. / California disclosures
- 10. Israel-specific disclosures
- 11. Automated decisions
- 12. Children
- 13. Security & breach notification
- 14. Changes
- 15. How to contact us
1. Who is responsible for your data
Gua is the data controller (and, for CCPA/CPRA, the “business”) that determines how and why your personal data is processed. Gua is operated from Israel. You can reach our privacy contact at privacy@feelragua.com for any question or to exercise your rights.
2. Personal data we collect
We collect only what we need to run the Services:
- Account & identity data — your email address and display name, created when you sign up by email, Apple, or Google. Apple/Google sign-in returns a unique identifier and the email you authorize.
- Commitment data — the schedules, time windows, and limits you create. The specific apps you block are represented on your device as opaque Screen Time tokens provided by Apple; these are not human-readable, and we cannot see which apps they correspond to. Typed website domains you block are stored to operate the block.
- Accountability data — buddy relationships you create or accept, and the approve/decline requests exchanged between you and a buddy.
- Creativity content — notes, audio recordings, and photos you capture in the creativity feature are stored locally on your device by default. If you choose to share a creation with your accountability buddy, that specific photo, audio, and/or text is uploaded to our cloud storage so your buddy can view it, and is automatically deleted after 7 days (or sooner if you cancel, your buddy declines, or the content is reported). We do not analyze your creations with AI.
- Feedback you submit — if you use the in-app feedback / bug-report feature, we receive your message and, only if you choose to attach them, a screenshot and an anonymous diagnostic log (a technical record of recent in-app blocking events; it contains no messages, contacts, or other personal content).
- Aggregate product analytics — we compute aggregate, non-identifying statistics from the data above (for example, the percentage of users who enable a given line of defense) to understand and improve the Services. These metrics are first-party and are never shared with advertising networks or data brokers; we do not track you across other apps or websites.
- Device & technical data — push-notification tokens, app version, device model/OS, language, and limited diagnostic data.
- Website data — server logs (IP address, timestamp, user agent), and the cookie/consent preference you set. See our Cookie Policy.
We do not intentionally collect special-category/sensitive data and ask that you not submit it through free-text fields.
3. Purposes and legal bases
Under the GDPR and similar laws, we rely on the following legal bases:
- To provide the Services (authentication, schedules, blocking, accountability, payments) — performance of a contract with you.
- To prevent circumvention/abuse — our legitimate interests in protecting the integrity of the Services.
- To send notifications you request (e.g., a buddy request) — performance of a contract; promotional messages, if any, rely on consent.
- To secure, maintain, debug, and improve the Services, including computing aggregate, non-identifying product statistics — legitimate interests, balanced against your rights.
- To share a creation with your accountability buddy, at your choice — performance of a contract / your consent when you tap “Share.”
- Optional website analytics — consent, which you may withdraw at any time.
- To comply with legal obligations (tax, accounting, responding to lawful requests) — legal obligation.
4. The consequences of not providing data
You are not legally required to give us personal data, but some data is necessary to use the Services: without an email and display name we cannot create your account; without commitment data we cannot block anything. Declining optional items (such as analytics) does not affect your ability to use the core Services. (This notice is provided to meet Section 11 of Israel’s Protection of Privacy Law.)
5. Recipients and processors
We do not sell your personal data and do not “share” it for cross-context behavioral advertising. We disclose data only to service providers (processors) who act on our documented instructions under data-processing agreements:
- Google Firebase / Google Cloud — authentication, database (Firestore), cloud functions, hosting, and push notifications.
- Apple — Screen Time functionality on iOS.
- Any analytics provider we later add will be named here and loaded only after you opt in.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or Gua. If Gua is involved in a merger, acquisition, or asset sale, personal data may be transferred subject to this Policy.
6. International data transfers
Our providers may process data in the United States and other countries that may not provide the same level of protection as your home jurisdiction. Where we transfer personal data out of the EEA, the UK, or Israel, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), reliance on adequacy decisions where applicable, and our providers’ certified transfer mechanisms. You may request a copy of the relevant safeguards from us.
7. How long we keep data
We keep personal data only as long as necessary for the purposes above:
- Account, commitment, and accountability data — for the life of your account, then deleted or anonymized within a reasonable period after account closure.
- Server logs — retained for a short period for security and diagnostics, then deleted or aggregated.
- Creativity content — remains on your device under your control. A creation you choose to share with a buddy is held in our cloud storage and automatically deleted after 7 days (or sooner if cancelled, declined, or reported).
- Feedback — messages, screenshots, and any attached diagnostic log are retained while we work on the feedback and for a reasonable period thereafter for product and support purposes.
- Aggregate analytics — non-identifying statistics may be retained indefinitely because they are not linked to any individual.
8. Your rights
Everyone may access, correct, or delete account data, and contact us with any privacy concern. You can delete your account in the app or by emailing us.
EEA / UK (GDPR). You have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing based on legitimate interests, plus the right to withdraw consent at any time without affecting prior processing. We respond within one month (extendable by two further months for complex requests, with notice). You may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). See Section 9. We respond to verifiable consumer requests within 45 days (extendable by another 45 days with notice).
Israel (Protection of Privacy Law). You have the right to review the personal data we hold about you, to request correction of inaccurate data, and to request deletion. We will respond within the timeframes set by law.
To exercise any right, email privacy@feelragua.com. We will take reasonable steps to verify your identity and will not charge a fee unless your request is manifestly unfounded or excessive. You may use an authorized agent where the law permits.
9. U.S. / California disclosures
In the prior 12 months we collected the categories described in Section 2 (identifiers, customer records, internet/network activity, and content you create) for the business purposes in Section 3. We disclosed certain categories to the processors in Section 5 for those purposes. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes beyond those permitted. California residents have the rights to know, access, delete, correct, and opt out of sale/sharing, and to limit the use of sensitive personal information; we honor these and will not discriminate against you for exercising them. Because we do not sell or share, no “Do Not Sell or Share My Personal Information” mechanism is required, but you may still contact us with any request.
10. Israel-specific disclosures
This Policy serves as the notice required under Section 11 of the Protection of Privacy Law: it states the purposes for which data is collected, to whom the data may be transferred and for what purposes, and the consequences of not providing data (Section 4). We maintain appropriate organizational and technical safeguards consistent with the Protection of Privacy Regulations (Data Security), 5777‑2017, and the requirements introduced by Amendment 13. Under the law, individuals may bring claims, including in certain cases without proof of damage, for statutory compensation; we aim to resolve any concern directly first — please contact us.
11. Automated decisions
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing or profiling.
12. Children
The Services are not directed to children under 16 (or the higher minimum age set by your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Security & breach notification
We use industry-standard safeguards including encryption in transit (TLS), access controls, least-privilege practices, and reputable infrastructure providers. No method of transmission or storage is perfectly secure, but we work to protect your data and continually improve our defenses. In the event of a personal-data breach that poses a risk to your rights, we will notify the relevant supervisory authority and affected users as required by applicable law.
14. Changes
We may update this Policy to reflect changes in our practices or the law. We will post the new effective date above and, for material changes, provide additional notice in-app or by email. Your continued use after an update means you accept the revised Policy.
15. How to contact us
Privacy contact: privacy@feelragua.com · General: hello@feelragua.com.
Supervisory authorities. EEA users may complain to their national data protection authority; UK users to the Information Commissioner’s Office (ICO); California residents may contact the California Privacy Protection Agency or the California Attorney General; Israeli users may contact the Privacy Protection Authority (the Israeli regulator).