Privacy Policy
Privacy Policy
Effective Date: 12 July 2026
Effective Date: 12 July 2026
Rush (“Rush”, “we”, “us”) is a wake-up alarm app that makes you complete a task to switch the alarm off. This policy explains what data we collect, why, and your choices.
1. What we collect and why
Rush (“Rush”, “we”, “us”) is a wake-up alarm app that makes you complete a task to switch the alarm off. This policy explains what data we collect, why, and your choices.
1. What we collect and why
Data
Why
Where it goes
Account: user ID, and email + name from your Apple/Google sign-in
Create and secure your account
Firebase; sign-in tokens stay on your device
Your first name (onboarding)
Personalize the app
Device + your account in our cloud
Alarms and wake-up history (times, objective, sound, repeats, when you woke, response time, streak)
Run alarms; show progress
Device + your account in our cloud
Target wake-up time
Onboarding plan
Device + your account in our cloud
Commitment signature (drawn image)
The commitment feature
Device + your private cloud storage
Objective photos / exercise video
Verify you completed the objective
Sent to a third-party AI provider to check; not stored by us
Usage events + device model, OS, app version, a device identifier
Improve the app
Firebase Analytics
Advertising / attribution identifier
Measure which ad brought you in
Google Analytics — only if you allow tracking
Subscription status
Unlock paid access
Verified through Apple
Account — User ID, email, and name from Apple/Google sign-in. Used to create and secure your account. Stored in Firebase; sign-in tokens stay on your device.
First name — Used to personalize the app. Stored on your device and in your cloud account.
Alarms and wake-up history — Used to run alarms and show progress. Stored on your device and in your cloud account.
Target wake-up time — Used for the onboarding plan. Stored on your device and in your cloud account.
Commitment signature — Used for the commitment feature. Stored on your device and in private cloud storage.
Objective photos / exercise video — Sent to a third-party AI provider for verification and not stored by us.
Usage and device details — Used to improve the app. Sent to Firebase Analytics.
Advertising / attribution identifier — Used to measure which ad brought you in, only if you allow tracking.
Subscription status — Used to unlock paid access and verified through Apple.
Stays only on your device: your “current wake-up time” answer and your snooze/vibration settings. We do not collect location or health data, and we show no third-party ads inside the app.
Permissions we use: camera & microphone (for objectives), notifications, alarms, and, optionally, tracking. iOS asks you before each.
2. Legal bases (GDPR / UK GDPR)
Contract: to provide accounts, alarms, sync, and objective checks.
Consent: for tracking (ATT) and camera/microphone/photo access - withdraw anytime in iOS Settings.
Legitimate interests: to keep the app secure and understand usage.
3. Who we share with
We share data only with the providers that make the app work:
Firebase (accounts, storage, server processing, analytics);
Anthropic (checks your objective photos/videos); and
Apple (Sign in with Apple, App Store purchases).
Each gets only what its function needs. We may also disclose data if required by law or to protect people’s safety.
4. Selling and sharing (California)
We do not sell your personal information. We only “share” it for cross-context behavioral advertising - ad-attribution identifiers with our ad-measurement provider - if you allow tracking in the App Tracking Transparency prompt. Turn tracking off in iOS Settings to opt out anytime.
5. International transfers
Our providers may process your data in the United States and other countries under approved safeguards (such as the EU Standard Contractual Clauses).
6. Retention
We keep account and synced data while your account exists. Delete your account in the app to remove your cloud data, stored signature, and sign-in record. Objective photos/videos are not stored. Analytics are kept per our provider’s retention setting.
7. Your rights
EEA / UK (GDPR): access, correct, delete, restrict or object to processing, data portability, and withdraw consent - plus the right to complain to your data protection authority.
California (CCPA / CPRA): know, access, delete, and correct your data, and opt out of “sharing” for cross-context advertising. We won’t discriminate for exercising these rights.
India (DPDP Act 2023): access a summary of your data and how it’s processed, correct/complete/update it, erase it, seek grievance redressal, and nominate another person to exercise your rights on your behalf.
How to exercise: delete your account in Settings → Account → Delete Account, or email johnvbissell@gmail.com. We respond within the time the law requires.
8. App Tracking Transparency
Your ATT choice controls whether advertising/attribution data is collected and shared. Product analytics run either way to operate and improve the app, and don’t use cross-app tracking unless you allow it.
9. Children
Rush is not intended for children under 13, and we don’t knowingly collect their data. If you believe a child gave us data, email us and we’ll delete it.
10. Security
Access to your data is locked to your authenticated account by server-side rules, and sign-in tokens are stored in your device’s secure keychain. No system is perfectly secure, but we take thorough measures to protect your data.
11. Changes
We may update this policy. For material changes we’ll update the “Last Updated” date and, where appropriate, notify you in the app.
12. Contact
Stays only on your device: your “current wake-up time” answer and your snooze/vibration settings. We do not collect location or health data, and we show no third-party ads inside the app.
Permissions we use: camera & microphone (for objectives), notifications, alarms, and, optionally, tracking. iOS asks you before each.
2. Legal bases (GDPR / UK GDPR)
Contract: to provide accounts, alarms, sync, and objective checks.
Consent: for tracking (ATT) and camera/microphone/photo access - withdraw anytime in iOS Settings.
Legitimate interests: to keep the app secure and understand usage.
3. Who we share with
We share data only with the providers that make the app work:
Firebase (accounts, storage, server processing, analytics);
Anthropic (checks your objective photos/videos); and
Apple (Sign in with Apple, App Store purchases).
Each gets only what its function needs. We may also disclose data if required by law or to protect people’s safety.
4. Selling and sharing (California)
We do not sell your personal information. We only “share” it for cross-context behavioral advertising - ad-attribution identifiers with our ad-measurement provider - if you allow tracking in the App Tracking Transparency prompt. Turn tracking off in iOS Settings to opt out anytime.
5. International transfers
Our providers may process your data in the United States and other countries under approved safeguards (such as the EU Standard Contractual Clauses).
6. Retention
We keep account and synced data while your account exists. Delete your account in the app to remove your cloud data, stored signature, and sign-in record. Objective photos/videos are not stored. Analytics are kept per our provider’s retention setting.
7. Your rights
EEA / UK (GDPR): access, correct, delete, restrict or object to processing, data portability, and withdraw consent - plus the right to complain to your data protection authority.
California (CCPA / CPRA): know, access, delete, and correct your data, and opt out of “sharing” for cross-context advertising. We won’t discriminate for exercising these rights.
India (DPDP Act 2023): access a summary of your data and how it’s processed, correct/complete/update it, erase it, seek grievance redressal, and nominate another person to exercise your rights on your behalf.
How to exercise: delete your account in Settings → Account → Delete Account, or email johnvbissell@gmail.com. We respond within the time the law requires.
8. App Tracking Transparency
Your ATT choice controls whether advertising/attribution data is collected and shared. Product analytics run either way to operate and improve the app, and don’t use cross-app tracking unless you allow it.
9. Children
Rush is not intended for children under 13, and we don’t knowingly collect their data. If you believe a child gave us data, email us and we’ll delete it.
10. Security
Access to your data is locked to your authenticated account by server-side rules, and sign-in tokens are stored in your device’s secure keychain. No system is perfectly secure, but we take thorough measures to protect your data.
11. Changes
We may update this policy. For material changes we’ll update the “Last Updated” date and, where appropriate, notify you in the app.