1. Data controller
The controller is Sergio Gómez de Aranda Salazar, Málaga, Spain. For any privacy matter, contact tirexmobiledev@gmail.com.
This policy applies to the Trufa: Sleep App Blocker Android application and this website.
2. Information processed on the device
Trufa stores your protection schedule, selected days, essential apps, permission status, preferences, aggregate sessions, night results, per-app aggregates, initial reference and local Trufa Plus status on the device.
This information activates protection, produces results and retains your history. There is no Trufa account or proprietary server receiving your night history.
3. Accessibility and Usage Access
During protection, the accessibility service processes window changes and the technical identity of the foreground app to decide whether it must be blocked. Usage Access provides interaction events, screen state, lock and unlock evidence needed to estimate when you stopped interacting with the phone.
Detailed events are processed temporarily. Trufa does not retain a detailed timeline or read accessibility nodes, messages, text, images, notifications, audio, contacts, locations, URLs or web history.
4. Optional analytics
Firebase Analytics stays disabled until you give explicit consent. If enabled, Google receives app opens, screens viewed and low-cardinality basic product events.
Analytics never includes schedules, apps used, technical identifiers of other apps, content, UsageStats or night history. Trufa disables advertising identifiers and personalisation. The target retention setting for user-level and event-level data is up to two months; Google aggregate reports may not be subject to the same period.
You can withdraw consent in Settings. Withdrawal stops future emissions.
5. Trufa Plus purchases
RevenueCat and Google Play process Trufa Plus purchases and restoration. They may receive an anonymous purchase identifier, technical device information, product, token, and transaction history or status.
They do not receive your schedule, apps used, UsageStats or night history. RevenueCat acts as a service provider to validate access and stores information on infrastructure in the United States under applicable contractual safeguards.
6. This website
The website has no forms, accounts, advertising, analytics, tracking pixels or first-party cookies. The hosting provider may process IP address, date, requested resource, browser and essential technical logs to deliver and protect the site.
Email links open your email application. We receive no information until you choose to send it.
7. Purposes and legal bases
Local processing of configuration and activity is necessary to provide the features you request. Accessibility and Usage Access are used only after your affirmative action and for the protection and result explained before granting them.
Optional analytics relies on consent. Purchases are processed to perform the contract, restore access, prevent fraud and comply with legal obligations.
8. Retention and deletion
Local data is retained until you delete history, delete all data in Settings, clear Android app data or uninstall Trufa. Detailed events are not persisted.
Purchase providers retain information as needed to validate purchases, comply with legal obligations, resolve disputes and prevent fraud. You may request deletion of information associated with an anonymous identifier using the contact above; some legal duties may prevent immediate or complete deletion.
9. Recipients and transfers
Outside the optional and purchase services described above, Trufa does not sell or share personal data. Google and RevenueCat may process information outside the European Economic Area under their terms, processing agreements and lawful transfer mechanisms.
10. Your rights
You may request access, correction, deletion, objection, restriction or portability where applicable by emailing tirexmobiledev@gmail.com. Because most information exists only on your device and is not linked to an account, we may be unable to identify it remotely.
You may also lodge a complaint with the Spanish Data Protection Agency.
11. Security, children and changes
Trufa limits information to what is necessary, uses encrypted connections for external providers and disables backup of app history. No system is completely infallible.
Trufa is intended for adults and does not knowingly seek data from children. Changes will be published here with an updated date.