Privacy Policy

Learn how the Good Wishes App collects, uses, and protects your personal data with complete security and transparency.

Last Updated: May 2026

1. Introduction

Welcome to Good Wishes App. We deeply value your privacy and are firmly committed to ensuring security and transparency when processing our users' personal information.

This Privacy Policy describes how we collect, process, store, and protect your information when you use the Good Wishes App mobile application (available for Android and iOS) and our related services.

By downloading, installing, or using the application, you agree to the practices described in this document in compliance with applicable data protection laws, including the Brazilian General Data Protection Law (LGPD), GDPR, and the guidelines set forth by the Apple App Store and Google Play Store.

2. Data Collection

We collect only the necessary information to provide our core services of engagement and experience sharing within the community. We categorize this information as follows:

a) Registration and Account Information

  • Personal Data: Full name, email address, and secure authentication details provided during account pre-provisioning by system administrators or when logging in.
  • User Profile: Profile picture (if you choose to upload one), biography, or display details that you customize within the community.
  • Third-Party Credentials: Secure access tokens provided when you choose to use the fast sign-in features of Google Sign-In or Sign In with Apple.

b) User-Generated Content

  • Posts, comments, reactions, shares ("sharings"), announcements, and shared activities within the community groups that you choose to join.

c) Technical and Diagnostic Data

  • Device Information: Device model, operating system version (iOS or Android), and unique device identifiers.
  • Crash Logs and Diagnostics: Technical statistics collected through tools such as Firebase Crashlytics to identify and resolve app malfunction or unexpected bugs.
  • Usage Data: Anonymous interaction statistics collected via Firebase Analytics to help us understand how the app is being used and continuously improve the overall experience.

3. How We Use Data

We utilize the collected data securely for the following legitimate business purposes:

  • Service Provision: To validate your login, manage your profile, allow you to create, join, and manage groups, and share experiences across the network.
  • Communication and Alerts: To send important updates regarding the app or group activities via native push notifications on your mobile device.
  • Safety and Fraud Prevention: To ensure the platform's integrity and prevent the creation of abusive accounts or content.
  • Continuous Improvement: To analyze system crashes technically and quantify user engagement with new features.

4. Data Sharing

We never sell, rent, or trade your personal data with third parties. Your data is securely processed and stored using high-trust infrastructure partners:

  • Supabase: Used as our secure relational database and cloud storage provider to host user profiles, posts, and community group details.
  • Firebase (Google LLC): Used for critical app infrastructure, including authentication, mobile push notifications (FCM), engagement analytics (Firebase Analytics), and stability monitoring (Firebase Crashlytics).

These service providers have strict security policies in place and process your data solely under our instructions and in full compliance with global privacy regulations.

5. Required Permissions

To enable the full interactive features of the Good Wishes App, the application may request the following permissions on your mobile device:

  • Photo Library and Camera: Required if you choose to upload or change your profile picture or attach images to your posts and shared experiences.
  • Push Notifications: Requested to alert you in real-time when other users comment, react, or interact within your groups of interest.

You can revoke or adjust any of these permissions at any time directly through the privacy settings of your mobile device's operating system (iOS/Android).

6. Your Rights and Data Deletion

You hold full control over your personal information in compliance with international regulations (including LGPD and GDPR). Your rights include access to your personal data, correction of inaccurate data, and complete deletion of your account.

How to Request Account & Data Deletion

Users of the Good Wishes App, developed by the Good Wishes App Development Team (managed by developer Rodrigo Ambros), have the absolute right to delete their accounts and all associated data at any time. You can request deletion through one of the two clear methods below:

Method 1: In-App Deletion (Instant)

  1. Open the Good Wishes App on your device and sign in.
  2. Navigate to your Profile tab.
  3. Tap on Settings (gear icon).
  4. Select Delete Account and confirm. Your account will be closed and all active personal data purged immediately.

Method 2: Request via Email

  1. Send an email to rodrigo.ambros@callofthetime.org with the subject "Account Deletion Request".
  2. Clearly state the registered email address and name of the account you wish to delete.
  3. Our support team will process your request and completely purge your account data within 15 days.

Types of Data Deleted vs. Retained

Upon an account deletion request, the following actions are executed:

  • Permanently Deleted: Your personal credentials (name, email), profile photograph, user-generated posts/experiences ("sharings"), group memberships, notifications logs, and personal settings are permanently wiped from our active databases.
  • Retained Data: No personal details are retained. In extremely rare circumstances, anonymized telemetry or system logs (which contain no personally identifiable information) may be kept solely for security diagnostic purposes.
  • Storage & Backup Retention Period: Personal data is purged from active production servers immediately. Secure backup snapshots containing database states are encrypted and kept for a maximum rotation period of 30 days, after which they are automatically and permanently overwritten and deleted.
✉ Request Data Deletion by Email

7. Data Security

We adopt strict technical, administrative, and physical protection measures designed to safeguard data confidentiality and security against loss, unauthorized access, alterations, or unwanted disclosures.

We employ data-in-transit encryption (HTTPS and SSL/TLS protocols) and robust access controls on database nodes managed on Supabase and Firebase.

8. Contact and Support

If you have any questions concerning this Privacy Policy or wish to exercise any of your legal privacy rights, please feel free to contact our Data Protection Officer (DPO) through the following channels: