Privacy Policy

We take your privacy seriously. This policy explains what data we collect, why, and your rights under GDPR.

1. Who we are

Data controller within the meaning of GDPR Art. 4(7):

Philip Youn Wai Leong, trading as Picky Alarm (“we”, “us”, “our”)
Goldpeppingstr. 28
60435 Frankfurt am Main
Germany

For data protection enquiries, write to hello@pickyalarm.com or use the contact form. Full details are in the imprint.

2. Data we collect

We collect the following categories of personal data:

  • Account data - email address, display name, and a hashed password when you register.
  • Calendar data - event titles, dates, times, and locations, accessed through Google OAuth when you choose to link your calendar. This data is processed only to schedule your alarms.
  • App preferences - volume levels, notification preferences, and display settings stored locally on your device and, if you are signed in, associated with your account on our servers.
  • Alarm backup data (optional, opt-in required). If you enable Auto-sync alarms to cloud in the app Settings, your alarm configurations (name, time, recurrence schedule and ringtone preference) are stored on our servers and linked to your account. This allows your alarms to be restored if you reinstall the app. Cloud backup is disabled by default and can be turned off at any time; disabling it does not delete already-synced alarms from our servers, but deleting your account removes all alarm data permanently.
  • Contact form data - name, email address, and message content you provide when you contact us through this website.
  • Records of changes to your data - when an account is edited, deactivated or deleted, we keep a dated record that it happened, who did it, and which fields changed. A record of a deletion holds no values from the account, only a one-way hash of the username, so it can confirm an account was erased without keeping the account. This record deliberately outlives the account it describes; see section 7.
  • Technical data - request timestamps, the page requested, and your browser’s user agent, in server logs, kept for security and operational purposes. The access log records no IP address, ours or yours. The separate error log records the requesting address on the lines it writes when a request fails, because the web server writes that field itself and offers no way to leave it out. Those lines are written only when something goes wrong, and they are covered by the same retention and the same processors as everything else in this section.
  • Crash reports (optional, consent required). If you enable “Share crash reports” in the app Settings, anonymised crash data (device model, OS version, app version and a stack trace) is sent to Firebase Crashlytics. No account data or personally identifiable information is included.
  • Usage data (optional, consent required). If you enable “Share anonymous usage data” in the app Settings, basic session events (e.g. app open) are sent to Firebase Analytics. No account data or personally identifiable information is included.

3. How we use your data

  • Providing the service (legal basis: contract) - account management, authentication, and delivering alarm functionality based on your calendar.
  • Responding to enquiries (legal basis: legitimate interest) - replying to messages submitted via our contact form.
  • Security and fraud prevention (legal basis: legitimate interest) - detecting and investigating abuse or unauthorised access.
  • Legal compliance (legal basis: legal obligation) - retaining records where required by applicable law.

4. Data sharing

We do not sell your personal data. We share data only in the following circumstances:

  • Google LLC - calendar data is fetched via Google’s APIs under the OAuth 2.0 authorisation you grant explicitly in the app. Governed by Google’s Privacy Policy.
  • Firebase (Google LLC) - used for the following purposes, all governed by Firebase’s Privacy Policy:
    • Firebase Cloud Messaging. If you link a Google Calendar, your device token is shared to deliver push notifications about calendar changes.
    • Firebase Crashlytics (consent-based). If you opt in, anonymised crash reports are transmitted to Google’s servers, which may be located outside the EEA. Google LLC participates in the EU–US Data Privacy Framework and provides Standard Contractual Clauses.
    • Firebase Analytics (consent-based). If you opt in, anonymised usage events are transmitted under the same transfer safeguards as above.
    You can withdraw consent at any time in the app Settings under Privacy.
  • IONOS SE - our hosting provider, based in Germany (EU), processes data on our behalf as a data processor under a Data Processing Agreement. Your data is stored and processed within the European Economic Area.
  • Grafana Labs - our monitoring provider, processing server logs and performance measurements on our behalf as a data processor under a Data Processing Agreement. We use a Grafana Cloud instance hosted in Germany, so this data is stored and processed within the European Economic Area. It exists so we can tell when the service is broken or slow. It carries no account data: we do not label a measurement with a user id, an email address or any other identifier.
  • Legal authorities - where required by law or valid legal process.

5. Third-party services on this website

  • hCaptcha (Intuition Machines, Inc., United States) - our contact form uses hCaptcha to tell people from bots. The legal basis is our legitimate interest in preventing automated abuse of a form that sends us mail.
    • When it loads. Nothing is requested from hCaptcha when you open the page. The script is fetched only when you put the cursor in the contact form, so simply reading this site contacts them not at all.
    • Transfer. Loading the widget transmits your IP address and interaction data to Intuition Machines, Inc. in the United States. The transfer rests on the EU–US Data Privacy Framework, and on the EU and UK Standard Contractual Clauses in hCaptcha’s data processing agreement underneath it, which is the same pair of safeguards described for Google in section 4.
    • Processing is governed by hCaptcha’s Privacy Policy.
  • Cloudflare Web Analytics (Cloudflare, Inc., United States) - counts page views for this website. The legal basis is our legitimate interest in knowing whether anyone reads the site.
    • What it stores on your device. Nothing. It sets no cookie, writes nothing to local storage, and does not fingerprint your browser, so it needs no consent under § 25(2) TDDDG. There is no identifier that follows you between visits or between sites, and no profile is built.
    • What it sends. The address of the page, the address you arrived from, your browser and operating system version, your country, and the loading timings the browser has already measured.
    • Transfer. Cloudflare, Inc. is in the United States. Cloudflare already serves every byte of this site, so your IP address reaches them on every request whether or not this counter exists. The transfer rests on the EU–US Data Privacy Framework and on the Standard Contractual Clauses in Cloudflare’s data processing addendum, which is the same pair of safeguards described for Google in section 4.
    • Processing is governed by Cloudflare’s Privacy Policy.

6. Cookies and analytics

This website sets no cookies of its own. It is static files served from disk, with no session and no login. We use no advertising cookies and no tracking pixels.

Page views are counted by Cloudflare Web Analytics, described in section 5. It sets no cookie and stores nothing on your device, which is why this site shows no consent banner. Google Analytics is not used here, and neither is a tag manager.

Our CDN, Cloudflare, sets a single strictly necessary cookie, __cf_bm, to tell human visitors from bots. It carries no advertising or profiling purpose and requires no consent under § 25(2) TDDDG.

The mobile app may collect anonymised usage and crash data via Firebase Analytics and Firebase Crashlytics only if you explicitly opt in through the app Settings. No analytics are collected by default.

hCaptcha sets one cookie, and only once you have put the cursor in the contact form: __cf_bm, under hcaptcha.com. It is Cloudflare’s bot-management cookie, the same kind and the same name as the one described above, it carries no advertising or profiling purpose, and it requires no consent under § 25(2) TDDDG. Measured on 4 September 2026 against this page: no cookie of any kind is set before that first click. Apart from the counter named in section 5, no other third party is contacted by this website.

7. Data retention

  • Account data - retained until you delete your account. Deletion removes your profile and associated data within 30 days.
  • Calendar data - event details are fetched on demand and not stored. For an event you have linked to an alarm we keep its title and start time, so the app can tell you what changed; that record is deleted as soon as you delete the alarm it belongs to, and with your account.
  • Alarm backup data - retained for as long as your account is active, and deleted with the account. Deleting a single alarm in the app marks it deleted at once, so it stops syncing to your other devices, and the record is erased within 30 days. The delay is what lets a device that has been offline learn the alarm is gone rather than restore it.
  • Contact form data - your message is sent to us as email and is not stored in the app’s database. We keep the correspondence for up to 12 months and then delete it.
  • Records of changes to your data - an edit is kept for 12 months. A deletion is kept for 6 years, which matches the period in which a claim that we mishandled a request could still be brought. The deletion record contains no personal data beyond the hash described in section 2.
  • Server logs - two copies, with two limits. On our own server they are capped in size and rotated daily, keeping 14 days. A copy is sent to Grafana Cloud in Germany, described in section 4, and is deleted there after 14 days. The access log contains no IP address; see the note on the error log in section 2.

You can delete your account from the app, or ask us to delete it without installing the app. Both routes, and what each figure above means in practice, are set out on deleting your account.

8. Your rights (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the following rights:

  • Right of access (Art. 15) - request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) - ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17) - request deletion of your personal data where there is no overriding legal basis for retention. Your account and its contents are removed. A dated record that the deletion happened is kept, without your name or any account contents, because Art. 5(2) requires us to be able to demonstrate that we handled the request properly.
  • Right to restriction (Art. 18) - request that we limit how we process your data in certain circumstances.
  • Right to data portability (Art. 20) - receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) - object to processing based on legitimate interests.
  • Right to withdraw consent - where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, write to hello@pickyalarm.com or use the contact form (indicate “Data Request” in your message). We will respond within 30 days as required by GDPR Art. 12.

You also have the right to lodge a complaint with a supervisory authority. Ours is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany. You may instead complain to the authority for the country where you live or work.

9. Children’s privacy

Picky Alarm is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the app or by email. Continued use of the service after changes constitutes acceptance of the revised policy.

Effective date: 6 September 2026  |  Version: 1.10