Privacy Policy
This Privacy Policy explains how BETTR OFF processes your personal data when you use the BETTR OFF mobile application (the “Service”). We take the protection of your data seriously, especially because using BETTR OFF can reveal sensitive information about your gambling behaviour and wellbeing.
1. Controller
The controller responsible for processing your personal data is PL Core GmbH. Full contact details are set out in the Imprint. Privacy enquiries: hello@bettroff.app
2. Data We Process
Depending on how you use the Service, we process:
- Account data: email address and authentication credentials (passwords are stored only in hashed form), and a user identifier.
- Recovery and progress data: your self-assessment answers and resulting score, daily pledges, gamble-free streak, journal entries, logged triggers, and milestones. Because this data concerns your gambling behaviour and wellbeing, parts of it may qualify as special-category (health-related) data.
- Trusted person data: any name or contact detail you choose to enter for an accountability partner.
- Subscription data: your subscription and trial status. Purchases are processed by Apple; we receive transaction and entitlement status, not your payment-card details.
- Support data: the content of messages you send us, e.g. by email.
- Technical data: information needed to operate the Service securely, such as app version, device type, and server log data (including IP address).
We follow the principle of data minimisation and only process what we need. Where data is required to provide the Service (for example, account and subscription data), not providing it may mean you cannot use the relevant features. Providing your recovery and progress data is always voluntary.
3. Purposes and Legal Bases (Art. 6 & 9 GDPR)
- Providing the Service, your account, and subscription — Art. 6(1)(b) GDPR (performance of a contract).
- Processing your recovery and progress data, including health-related information — your explicit consent, Art. 6(1)(a) and Art. 9(2)(a) GDPR, obtained in the app before you provide this data. You can withdraw this consent at any time with effect for the future, without affecting prior processing.
- Security, abuse prevention, and improving stability — Art. 6(1)(f) GDPR (our legitimate interest in a safe, reliable Service).
- Complying with legal obligations, e.g. retention of billing-related records — Art. 6(1)(c) GDPR.
4. Recipients and Processors
We use carefully selected service providers who process data only on our behalf and under a data processing agreement:
- Supabase — application hosting, database, and authentication.
- Email service provider — sending transactional and support emails.
- Apple — processing in-app purchases and subscriptions, as an independent controller under Apple’s own privacy policy.
We do not sell your personal data and do not use it for advertising.
5. International Transfers
Where a provider processes data outside the European Economic Area, we ensure an adequate level of protection through appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep your data for as long as your account exists and the Service is provided. If you delete your account, we delete or anonymise your personal data, unless we are legally required to retain certain records (for example, billing-related data under tax law).
7. Your Rights
Under the GDPR you have the right to access, rectification, erasure, restriction, and data portability, the right to object to processing based on legitimate interests, and the right to withdraw consent at any time with effect for the future. To exercise these rights, contact hello@bettroff.app. You also have the right to lodge a complaint with a supervisory authority, in particular in your country of residence or at the controller’s place of business.
8. Data Security
We use appropriate technical and organisational measures, including encryption in transit and access controls, to protect your data against unauthorised access, loss, or misuse.
9. No Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Your self-assessment score is shown to you as feedback and is not used to make any automated decision about you.
10. Children
BETTR OFF is intended only for adults aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has provided us data, please contact us so we can delete it.
11. Changes to This Policy
We may update this Policy to reflect changes to the Service or legal requirements. The current version is always available here, with the date of the last update shown above.
12. Contact
Privacy questions: hello@bettroff.app