Mission

Privacy Policy

Last updated: July 26, 2026

🇬🇧
PrivacyTermsLiabilityImprintSupport

This Privacy Policy explains how Mission processes personal data when you use the Mission iPhone app, dailymission.app, invitation and quote-sharing links, subscriptions, or the support channels.

Personal data means any information relating to an identified or identifiable person. Mission processes personal data only for the purposes and on the legal bases described below.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

David Novakovic

Spielmanngasse 4/16/3
1200 Wien
Ă–sterreich

Privacy and data-subject requests: office@dailymission.app. Product support: support@dailymission.app. Website: dailymission.app.

2. Scope and categories of personal data

Website and server request data

  • IP address, date and time, requested URL, HTTP status, referrer, user-agent and comparable technical request and security data processed when a page or preview image is retrieved.
  • URL parameters can contain an invitation code or quote text, author, language and visual settings. These parameters can therefore appear in hosting and security logs.
  • Supabase can process provider-side Auth, API and Edge Function logs, including IP address, date and time, requested endpoint or function, request and response status, user-agent, country derived from the IP address, account or session identifiers and comparable request and security metadata.

Authentication, account and profile data

  • Email address, internal user ID, authentication provider, session and token metadata, and login security data.
  • When Google or Sign in with Apple is selected: the identifiers, email address and name information released by that provider.
  • First and last name, initials, profile photo including the selected image data, language, theme and other profile preferences.

Synchronized app snapshot, tasks, history and notification plan

  • The app snapshot used for local storage and current synchronization: profile, daily and favorite quotes, streak and activity values, goals, missions and their tasks, task-completion history, friends, challenges and challenge invitations.
  • Completion records, check-ins, streaks, weekly and monthly activity, completion rates, statistics and derived progress values.
  • Notification preferences and the generated notification plan, including notification type, title, content, scheduled time and related mission, task, challenge or invitation identifier.

Friends, invitations and challenges

  • Friend relationships, invitation codes, inviter and invitee identifiers, display name, profile-image reference, invitation status, acceptance and expiry data.
  • Challenge titles, descriptions, colors, emojis, duration, creator, members, check-ins, weekly activity and member progress.

Quotes and public share links

  • Saved and favorite quotes, author, language, background and typography settings, and generated share identifiers.
  • For a quote share, the quote text, author and visual settings are included in the share URL and preview-image URL. Anyone with the link, as well as messaging, social-network and search preview bots, can retrieve that content.

Issue reports and support

  • Category, message, internal user ID, app version and build, device and system context, language, theme, access status, number of tasks completed and planned for the day, and creation time.
  • Emails, attachments, screenshots and any additional information that you voluntarily submit to support.

Purchases and entitlements

  • The Mission app processes the selected RevenueCat offering or package, the RevenueCat app-user ID and active-entitlement information required to offer, purchase and restore paid access.
  • Apple and RevenueCat process product, transaction, receipt, trial, subscription, renewal, cancellation and refund information within their respective services. Mission does not receive full payment-card details from Apple.
  • RevenueCat can also process app, SDK, device and operating-system information, first- and last-seen timestamps and a country derived from the IP address for subscription operation, security and fraud prevention.

Account-deletion receipts and write guards

  • While deletion is being processed, the receipt record contains one-way hashes of the deletion receipt and account reference, the direct internal Supabase user ID, the processing status, and creation, completion and expiry timestamps. When the Supabase Auth user is deleted, that user ID is set to null; only the hashes, status and timestamps remain until physical cleanup. The plain receipt and deleted account contents are not stored in this record.
  • The account-deletion write guard contains the direct internal Supabase user ID, an active or processing status and the deletion_started_at timestamp. It is used to quiesce and block account-owned Storage writes while deletion runs. The guard is deleted by cascade when the Supabase Auth user is deleted.

Local device data and permissions

  • Locally stored app snapshot and preferences, pending synchronization operations, pending issue reports, custom quote backgrounds, and widget configuration and data stored in the app's shared App Group container. Widget data and custom quote backgrounds are not part of the currently synchronized dashboard snapshot.
  • Notification, photo-library and camera permissions and the content selected through those permissions. Mission receives only the content you select or create for an app feature.

3. Purposes and legal bases

  • Website delivery, technical stability and protection against abuse: legitimate interests in providing a secure and reliable website (Article 6(1)(f) GDPR).
  • Registration, authentication, account administration and profile functions: performance of the user agreement and steps requested before entering into it (Article 6(1)(b) GDPR). Security checks are additionally based on the legitimate interest in protecting accounts and services (Article 6(1)(f) GDPR).
  • Local storage of operational app and widget data and synchronization of the supported snapshot fields and notification plan: performance of the user agreement (Article 6(1)(b) GDPR).
  • Where enabled in the released service, synchronization and account-to-account display of friend relationships and activity, challenge memberships, invitations, check-ins and member progress: performance of the user agreement (Article 6(1)(b) GDPR) and legitimate interests in correctly assigning invitations, enforcing access boundaries and preventing abuse (Article 6(1)(f) GDPR).
  • Quote and invitation share links: performance of the sharing function expressly requested by you (Article 6(1)(b) GDPR). Public retrieval occurs at your instruction when you create and send the link.
  • Issue reports and support: performance of the user agreement and handling your request (Article 6(1)(b) GDPR), and legitimate interests in diagnosing errors, preventing abuse and improving service security and reliability (Article 6(1)(f) GDPR).
  • Purchases, trials and entitlements: performance of the subscription agreement (Article 6(1)(b) GDPR), compliance with tax, accounting and consumer-law duties (Article 6(1)(c) GDPR), and legitimate interests in preventing purchase fraud (Article 6(1)(f) GDPR).
  • Reconciliation and documentation of account-deletion status: performance of the deletion requested by you (Article 6(1)(b) GDPR), compliance with applicable erasure and accountability duties (Article 6(1)(c) GDPR), and legitimate interests in preventing receipt misuse and resolving interrupted or lost responses (Article 6(1)(f) GDPR).
  • Write quiescing during account deletion: performance of the deletion requested by you (Article 6(1)(b) GDPR) and legitimate interests in blocking new account-owned Storage writes while the deletion process removes existing files safely and reliably (Article 6(1)(f) GDPR).
  • Supabase Auth, API and Edge Function logs and RevenueCat technical, device and usage metadata: operation of account and subscription functions (Article 6(1)(b) GDPR) and legitimate interests in service security, error analysis, availability, abuse and fraud prevention (Article 6(1)(f) GDPR).
  • Optional notifications, profile photos, camera or photo-library access: your voluntary activation or selection (Article 6(1)(a) GDPR where consent is the applicable basis) and provision of the feature you requested (Article 6(1)(b) GDPR). Consent can be withdrawn at any time without affecting prior lawful processing.
  • Establishment, exercise or defence of legal claims and compliance with authorities: legitimate interests (Article 6(1)(f) GDPR) or a legal obligation (Article 6(1)(c) GDPR).

4. Required and voluntary information

Technical website request data is transmitted automatically and is required to deliver the requested page securely. An email address or provider identifier and the corresponding authentication data are required to create and use an account. Without them, account login, synchronization, social functions and account-linked entitlements cannot be provided.

Profile photos, optional profile details, notifications, camera and photo-library access, Google OAuth, social functions, quote sharing, purchases and support reports are voluntary. If you do not provide the data required for one of these optional functions, only that function remains unavailable. Email authentication and Sign in with Apple remain alternatives to Google OAuth where displayed in the app.

Mission does not request special categories of personal data such as health information, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric identification data, sex-life or sexual-orientation data. Do not enter such data in synchronized free-text fields or images, support messages or public share links. If Mission nevertheless becomes aware of such data unintentionally, it is processed only insofar as necessary to handle or erase the submission, protect legal claims or comply with a statutory duty; no separate product use is made of it.

5. Shared and publicly accessible content

Where the corresponding production migrations and functions are deployed, Mission is designed to synchronize friend relationships and activity as well as challenge memberships, invitations, check-ins and member progress between the accounts involved in those functions. The source configuration uses Supabase row-level security and authenticated server-side functions intended to limit access, as applicable, to the account owner, the relevant friend, the challenge owner, the invited person or accepted challenge members. Actual production enforcement remains subject to a live multi-account verification, including an unrelated account, and these records are not intended to be publicly browsable. Mission does not sell personal data.

Quote and invitation links are accessible to anyone who receives or otherwise obtains the link. Quote text, author and design parameters can also be retrieved by preview bots and can remain in messages, browser history, server logs or third-party previews after the link is no longer actively shared. Do not include confidential, special-category or third-party personal data in public share links.

6. Recipients and processors

  • Apple: App Store distribution and purchases, StoreKit transactions, subscription management, iOS device permissions, local notification delivery, and Sign in with Apple when selected.
  • Supabase: authentication, account and session administration, Postgres database services, Edge Functions, synchronization, invitation processing and storage of issue reports.
  • RevenueCat: provision of App Store offerings and packages and return of active-entitlement information linked to the Mission app-user ID. Apple and RevenueCat process the underlying transaction and subscription information within their respective services.
  • Vercel: hosting and delivery of dailymission.app, server request logs, security and technical performance.
  • Google: identity and authentication data only when you choose Google OAuth.
  • Email and mailbox providers: delivery, storage and protection of messages sent to office@dailymission.app or support@dailymission.app and related replies.
  • Authorities, courts, professional advisers and other recipients where disclosure is required by law or necessary for the establishment, exercise or defence of legal claims.

Processors act under contractual data-protection obligations. Apple, Google and other providers also process certain data as independent controllers for their own account, purchase, security and legal obligations; their linked privacy information applies to those processing activities.

7. International data transfers

Some providers and group companies process data in the United States or other countries outside the European Economic Area. Transfers are based on an adequacy decision under Article 45 GDPR, including the EU-U.S. Data Privacy Framework for certified recipients, or on the European Commission's Standard Contractual Clauses under Article 46 GDPR together with supplementary safeguards where required. Information about the applicable safeguard or a copy of it can be requested from office@dailymission.app.

8. Cookies, trackers and device permissions

The public Mission website currently uses no optional analytics, advertising or marketing cookies and contains no third-party advertising tracker. After you dismiss the informational cookie notice, the first-party cookie mission_cookie_notice stores only the value seen for 180 days so that the notice is not shown again. It contains no user identifier and is not used to measure or track browsing. If optional tracking is introduced, it will remain disabled until the required consent has been obtained and this Policy has been updated.

The app stores operational data locally and uses iOS permissions only after the relevant system prompt or your explicit selection. Notification permissions can be changed in iOS Settings. Selected profile or quote images can be removed or replaced in the app. Deleting the app normally removes local app data, but does not delete synchronized account data or cancel an App Store subscription.

9. Retention and deletion

  • The retention period for account data, synchronized snapshots, issue reports, support correspondence and other records is determined by the purpose of the processing, account activity, applicable statutory retention duties, the establishment, exercise or defence of legal claims, security and abuse-prevention requirements, and the contractual or operational retention periods of the relevant provider. If no fixed statutory period applies, necessity is assessed according to those criteria.
  • Invitation links can no longer be accepted 14 days after creation. Records relating to expired or accepted invitations may remain stored where and for as long as this is necessary under the preceding criteria; the 14-day validity period does not itself represent a deletion period.
  • During processing, an account-deletion receipt also contains the direct internal Supabase user ID. Deletion of the Supabase Auth user sets that ID to null, and the related write guard is deleted by cascade. The remaining receipt hashes, status and timestamps are retained only as necessary to reconcile and document the request, prevent misuse, resolve interrupted responses and protect or defend legal claims, and must then be physically removed. The concrete maximum period and lifecycle of both receipt and guard must be set in an approved retention schedule and enforced and verified in production. An expiry timestamp can stop receipt retrieval but does not by itself prove physical deletion.
  • Apple, RevenueCat, Supabase, Vercel and email providers retain data processed within their respective services in accordance with their applicable legal duties, contractual settings, security requirements and published policies. This includes Supabase Auth, API and Edge Function logs and RevenueCat transaction, device, operating-system, first- and last-seen and IP-derived country metadata.
  • Local files containing pending synchronization operations or pending issue reports are removed after successful transmission. Other local operational data can normally be removed by deleting the app or its data from the device.

Where the installed Mission version displays “Delete Account”, the authenticated in-app flow initiates permanent deletion of the Mission account and the supported local and synchronized account data. Completion depends on the required server-side deletion service being correctly configured and deployed and is not confirmed until that service reports completion. Provider-side steps, including deletion of the linked RevenueCat customer record where configured, can remain pending temporarily if a provider is unavailable; the app can therefore continue to show a pending status. If the function is unavailable or completion is not confirmed, send the deletion request to office@dailymission.app. Data subject to a statutory retention duty or required for legal claims may remain stored for the applicable period. Account deletion does not cancel an App Store subscription; subscriptions must be managed or cancelled separately through the Apple account.

10. Your rights and response period

Subject to the statutory conditions, you have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. You can withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.

Submit a request to office@dailymission.app. Mission responds without undue delay and within one month of receipt. For complex or numerous requests, this period can be extended by up to two further months; you will be informed of the extension and reasons within the first month. Requests are free of charge unless they are manifestly unfounded or excessive. Identity verification is requested only to the extent necessary to protect the account and the rights of others.

11. Austrian Data Protection Authority

You can lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria, email dsb@dsb.gv.at. Further information is available at dsb.gv.at.

12. Sources of data

Mission receives data directly from you and from the app or device when you use a function. Authentication data is received from Supabase and, depending on your selection, Apple or Google. Offering, package and active-entitlement information is received through RevenueCat; Apple and RevenueCat process the underlying transaction and subscription information. Invitation information, friend activity and challenge membership, check-in or progress information can also be received from another Mission user involved in the relevant friendship, invitation or challenge. Statistics, streaks and notification plans are generated from your app activity. Website request data is generated when your device or a preview bot connects to Vercel-hosted pages. This information also fulfils the transparency requirements for data not obtained directly from you under Article 14 GDPR.

13. No automated decisions under Article 22 GDPR

Mission automatically evaluates personal app activity to calculate and display individual progress values, streaks, statistics and reminders. This simple automated evaluation may constitute profiling within the broad meaning of Article 4(4) GDPR. It is not used as the sole basis for a decision that produces legal effects or similarly significantly affects you; Mission therefore does not carry out solely automated decision-making within the meaning of Article 22 GDPR.

14. Children

Mission is not directed at children under 14 years of age. A child under 14 must not independently create an account or consent to optional processing. A parent or legal guardian who believes that a child under 14 has provided personal data without the required authorisation can contact office@dailymission.app. Mission verifies and processes the request manually under the statutory requirements and confirms the outcome; data subject to a legal retention duty may remain stored for the applicable period.

15. Security

Mission uses encrypted transmission (TLS), separates publishable client keys from server secrets, keeps server secrets in server-side environments, limits the data transmitted for each function and relies on the security measures made available by its processors. No internet service can guarantee absolute security. Report suspected security incidents promptly to support@dailymission.app without sending passwords, one-time codes or authentication links.

16. Changes to this Policy

This Privacy Policy is updated when processing activities, providers or legal requirements change. The current version and its revision date are published at dailymission.app. Material changes are announced in the app, on the website or by email before they take effect where this is required by law.