Menu

Privacy Policy

Effective date: 8 September 2026.

Controller: Benoit Rivaux, self-employed sole trader, trading as Relaxing App, Malta. Email: info@relaxingapp.com.

Data, purpose and legal basis

  • Account: name, surname, email, password hash, selected country, account UUID, verification/deletion tokens and dates, to create, secure and administer the service contract.
  • Registration choices: Terms/Privacy acceptance, newsletter choice and business-interest choice, with version, time and source metadata, to evidence those choices and send marketing only when requested.
  • Optional wellbeing preference: Bedtime Music, Masking Sounds or Deep Focus plus consent version/time/source and withdrawal time, used for personalisation only with explicit consent and erased on withdrawal.
  • Service activity: playlists, favourites, listening events, game scores, rewards, avatars, support messages and notification preferences, used to provide requested features and protect integrity.
  • Technical data: app-generated device UUID, IP address, platform, request/security logs and diagnostics, used for authentication, abuse prevention, troubleshooting and reliability.
  • Notifications: FCM Android token or PWA web-push token, platform and delivery metadata, used only when device notifications are enabled.
  • Google sign-in: Google identifier, verified email and name supplied by Google, used to authenticate and link the account.
  • Advertising/business: company identity and website, campaigns, creatives, targeting country, orders, invoices, payments, impressions and clicks, used to review, contract, deliver, measure and account for advertising.

Recipients and transfers

Hosting/database providers process service data; the configured transactional SMTP provider processes account-email and delivery metadata; Brevo processes optional newsletter addresses and delivery metadata; Google processes sign-in data and Firebase Cloud Messaging tokens/payloads; Stripe processes advertiser payment/billing data; self-hosted Matomo receives privacy-minimised events only after consent. We do not use Firebase Analytics or Android Advertising ID. Transfers outside the EEA require an applicable adequacy decision or safeguards such as European Commission Standard Contractual Clauses.

Location distinction

The optional Coordinate Beacon processes device/browser coordinates only on the device and does not transmit them to our server. Your selected country and the IP address necessarily visible to the server leave the device for content/advertising selection and security. GPS coordinates are not used for advertising.

Retention

  • Active consumer account and service fields: while the account remains open; removed after valid deletion confirmation.
  • Wellbeing preference: while consent remains active; erased from the active database on withdrawal or confirmed deletion.
  • Push tokens: until disabled, replaced, logout cleanup or confirmed deletion.
  • Deletion token: 24 hours; email-verification token: one hour, unless used sooner.
  • Encrypted backups: up to 30 days after deletion, unavailable for normal use.
  • Application request/security logs: up to 90 days unless a documented incident or legal hold requires longer.
  • Retained advertiser/accounting fields: pseudonymous user ID and replacement identity, Terms/Privacy acceptance versions and dates, registration/approval dates, business role, business-interest record, Stripe customer/payment-method references; company name, website, category, description, postal address, country, VAT number and impression balance; order package, payment-intent reference, amount/VAT, invoice URL, impressions and frequency; campaign name/status/order and impression balance; ad creative path, destination, status, impressions/clicks; target countries; impression/click country and referrer; daily totals, rejection reasons, subscription/item references and normal record timestamps. These are restricted for nine years after closure only for Maltese income-tax/accounting and VAT duties, fraud prevention or legal claims; a documented legal hold may require longer. Login credentials, original name/email/phone, consumer data and push identifiers are erased; a daily process permanently purges expired database rows and force-deleted ad creatives.
  • Matomo raw visits: up to 180 days; aggregate reports: up to 12 months.

Your rights

You may request access, correction, portability, restriction, objection or erasure and withdraw consent. Use My Account or email info@relaxingapp.com. You may complain to Malta's Information and Data Protection Commissioner.

Optional audience measurement

Our self-hosted Matomo setup is cookieless and does not receive your account ID, email, wellbeing preference, or listening history. You can grant or withdraw consent on this browser at any time.