Introduction

Welcome to TaDone! Your privacy is important to us. This privacy policy explains how we collect, use, and protect your personal information in compliance with the GDPR.

By using TaDone, you agree to the terms of this privacy policy. If you do not agree with these terms, please do not use TaDone.

1. Data Controller

Bruno Silva support@tadone.app

If you have any questions about this privacy policy, please contact us.

2. Information Collected

We collect and process the following categories of data:

Personal Data

  • Authentication Data — Name, email address, and profile photo URL (if shared).
  • Profile Data — Information you add to your profile such as preferences, routines, actions, rewards, and other data derived from using the app.

Usage Data

  • App Interaction Data — Information about how you interact with the app, such as actions taken, time spent, errors encountered, and other usage metrics.

Technical Data

  • Device Information — Device model, operating system, browser type, and app version.
  • IP Address — For security and fraud prevention purposes.

3. How We Use Your Data

We use your data for the following purposes:

  1. Authentication: to verify your identity and protect your data using Firebase Auth.
  2. Fraud Prevention: to protect against unauthorized access to our infrastructure, ensuring a stable service via Firebase App Check.
  3. Service Delivery: using Firebase Firestore and Firebase Functions to manage data.
  4. Personalization: to provide a personalized experience based on your settings and preferences.
  5. Compliance: to comply with our obligations under applicable regulations and legislation.

We process your data under the following legal bases:

  • Consent: when you give explicit consent for us to process your data (e.g., when creating an account).
  • Performance of a Contract: to provide you with TaDone services.
  • Legitimate Interest: to protect the security and integrity of the application and its users, as well as to improve our services.
  • Legal Obligation: to comply with legal and regulatory obligations.

5. Data Sharing

We do not share your personal data with third parties, except in the following cases:

  • Service Providers: using Firebase, a service provided by Google LLC, for secure authentication, storage, and data processing. Google’s Firebase services comply with GDPR standards. For more information, please see Firebase Privacy and Security.

  • Use of reCAPTCHA for Fraud Prevention: To protect your account and our services from fraud and abuse, we use Google reCAPTCHA as part of Firebase App Check. reCAPTCHA helps determine whether interactions with our app are initiated by a human user or an automated system (bot).

    What data is collected by reCAPTCHA?

    When reCAPTCHA is active, it may collect the following information:

    • IP address
    • Browser and device information (e.g., device model, operating system, and browser version)
    • User behavior, such as mouse movements and interactions with the app

    This information is processed by Google and used solely for the purpose of distinguishing between human and automated access.

    We process this data based on our legitimate interest in protecting the security and integrity of our services (Article 6(1)(f) GDPR).

  • Legal Requirements: to comply with legal and regulatory obligations.

  • Healthcare Providers: to share information when you choose to add providers to your family.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected under this privacy policy or to comply with legal obligations. When you delete your account, we will:

  1. Remove your data from our database.
  2. Keep data necessary to comply with legal obligations.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  1. Access: to request a copy of the personal data we hold about you.
  2. Rectification: to request correction of your personal data.
  3. Erasure: to request deletion of your personal data.
  4. Restriction of Processing: to request the restriction of processing of your personal data.
  5. Portability: to request a copy of your data in a structured format.
  6. Objection: to object to the processing of your personal data based on legitimate interests.
  7. Withdrawal of Consent: to withdraw your consent for the processing of your personal data.

To exercise your rights, please contact us by email.

8. Data Security

We implement technical and organizational measures to protect your personal data against loss, alteration, unauthorized access, and disclosure, including:

  • Encryption: data is encrypted in transit and at rest.
  • Restricted Access: data access is restricted to authorized personnel.
  • Fraud Prevention: using Firebase App Check to prevent unauthorized access.

9. Data Transfer Outside the EU

Your personal data may be processed by Firebase on servers outside the EU. Google ensures GDPR compliance through mechanisms such as the EU-US Data Privacy Framework and Standard Contractual Clauses. For more details, see Google’s Data Transfer FAQs.

10. Changes to This Policy

We reserve the right to change this privacy policy at any time. The most recent version will always be available at tadone.app/privacy-policy. The date of the latest revision will always appear at the top of the page.

11. Complaints

If you have any complaints about how we handle your personal data, please contact us. If you are not satisfied with our response, you may file a complaint with your country’s data protection authority.


By using TaDone, you acknowledge that you have read and understood this privacy policy.