Aika Works – Privacy Policy

Effective date: 1 August 2024

Last updated: 5 October 2026

1. Who we are

Constlet Oy ("we", "our", "us") is the data controller for the Aika Works mobile app and the aika.works website. Learn more about Constlet Oy at constlet.com.

2. What data we collect and why

Aika Works can be used without signing in. We collect installation-specific usage and error data to operate and improve the app. These records use a separate installation identifier (guid), not your account email or user ID. A persistent identifier may still be personal data under the GDPR. If you choose to sign in, we also process the account and work data described below.

Field Example Purpose
application Aika Works Identifies the Aika Works app.
element home button Identifies which UI element was used.
description User pressed home button on Settings page Human‑readable action description.
guid ios-1754388…f89021 Distinguishes one installation from another.
screen settings page Identifies which page the action occurred.
action click / navigate Interaction type.
type button press Identifies element action type.
error code NullReferenceException Code that identifies the fault; no user content.
error message Null reference at Main:42 Helps locate the fault; personal data removed.
timestamp 2025‑08‑04 T09:21:33 Z Orders events in time.

Legal basis for usage and error data: Our legitimate interest in operating, securing and improving Aika Works (GDPR Article 6(1)(f)).

Optional sign-in and cloud sync

You may choose to sign in with Apple or Google. We receive the email address made available by your chosen provider and a name or username if the provider shares one. Apple may provide a private relay email address instead of your personal email address. We do not receive your Apple or Google password. Firebase Authentication creates a user ID so that your account can be recognised securely.

For a signed-in account, we store the user ID, provider-supplied email and available name, together with your work records, their sessions and related information you add to Aika Works, in an EU-located Cloud Firestore database. This lets you save and restore your work across devices. Work photos that you attach may be stored separately in Firebase Cloud Storage. If you do not sign in, your work is not synced to an account in Firestore.

We do not put your account email or user ID into our installation-based usage analytics records, and we do not use the guid to join those records to your account. The account data is used to provide the optional sign-in and cloud sync you request, not to profile your work for advertising.

Legal basis for optional account data: Processing necessary to provide the account and cloud sync service you choose to use (GDPR Article 6(1)(b)).

3. How we use the data

  • Measure feature usage and guide product decisions.
  • Diagnose crashes and technical issues.
  • Manage in‑app purchases and subscriptions (pseudonymous purchase data itself is handled separately by RevenueCat; see Section 5).

We do not sell your account record or synced work content. Our installation-based usage analytics is kept separate from account records as described in Section 2.

4. Retention and aggregation

Stage Retention period What happens
Raw analytics logs 90 days Used for debugging and feature analysis.
Anonymous aggregated metrics Undetermined All identifiers removed; only daily totals retained. The resulting dataset is anonymous.
Optional account and synced work data While your account is active Used to provide sign-in and cloud sync. You can delete the account and its associated cloud data with the in-app Delete Account action, subject to any retention required by law.
Deletion Automatic Usage logs are deleted after the period above. Aggregated data is treated as anonymous only after identifiers and any reasonable means of linking it back to a person have been removed.

5. RevenueCat (in‑app purchases)

We use RevenueCat Inc. (United States) to validate App Store / Google Play purchase receipts and manage subscription status. These receipts are pseudonymous and sent directly from the store servers to RevenueCat; they are not stored in our analytics logs. For details on what RevenueCat collects and how long it keeps that data, please see the RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

6. Where the data is processed

Service Location Role Safeguard
Firebase Cloud Function European Union Receives pseudonymous usage events No onward transfer outside the EU (events from all regions are sent directly to EU location).
Cloud Firestore (usage logs) European Union Stores pseudonymous analytics and error logs The database is located in the EU.
Apple Sign in Apple-operated services Verifies your Apple account and provides the email address and name you choose to share Apple may provide a private relay email. See Apple's privacy policy.
Google Sign-In Google-operated services Verifies your Google account and provides the email address and name available to Aika Works See Google's privacy policy.
Firebase Authentication United States Maintains the optional sign-in account and its authentication identifiers Firebase Authentication processes account data in the US. See Firebase privacy information.
Cloud Firestore (signed-in accounts) European Union Stores account details and synced work records, including sessions Account data is kept in an EU-located database with account-based access controls.
Firebase Cloud Storage Configured storage bucket; separate from Firestore Stores work photos you choose to attach when cloud sync is enabled Its storage location is configured separately from the Firestore database.
RevenueCat Inc. United States Processes purchase receipts & subscription status Standard contractual clauses with pseudonymous data.

Our own usage-analytics events are sent to an EU-hosted endpoint using a separate installation identifier. The EU Firestore location for account data does not cover every sign-in provider: Firebase Authentication processes authentication data in the United States, and Apple and Google process sign-in data under their own policies. RevenueCat also processes purchase-related data in the United States. Firebase Cloud Storage has a separately configured location for attached work photos.

7. Security

  • Encryption in transit and at rest.
  • Role‑based access controls.
  • Automated log deletion.
  • Continuous monitoring.

8. Your GDPR rights

If you sign in, we can locate your account data using your account details. You may ask to access, correct, export or delete that data, subject to applicable law. To delete the account you created by signing in and the cloud data associated with it, open the account settings in Aika Works and tap Delete Account. You can also contact us at the address below. For installation-based usage logs, we may need your guid to find the relevant records; we do not link that guid to your account email or user ID. You may also lodge a complaint with a data protection authority.

If you would like a fresh guid, uninstalling and reinstalling the app creates a new installation record. Uninstalling or no longer using the app also stops further app analytics collection. It does not by itself delete a signed-in account or its cloud data.

9. Children

The Aika Works app is not directed to children under 13 years of age.

10. Changes to this policy

We may update this notice from time to time. The "Last updated" date shows the current revision.

11. Legal basis and your choices

Using Aika Works does not by itself constitute consent to every type of processing. You can use the app without an account. If you choose to sign in, the account data described in Section 2 is processed to provide the optional account and cloud sync service. The separate legal basis for usage and error data is also set out in Section 2.

12. Contact

If you have any further questions about this privacy policy or our data practices, please email mail@constlet.com.