Privacy Policy — Cleanzly
Effective date: July 28, 2026 Last updated: July 28, 2026
This Privacy Policy explains how Cleanzly ("Cleanzly," "the App," "we," "us," or "our") handles information when you use our iOS application. It is written to comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and to broadly align with other major privacy frameworks, including Japan's Act on the Protection of Personal Information ("APPI") and South Korea's Personal Information Protection Act ("PIPA").
Cleanzly is developed and operated by an independent individual developer:
Shahboz Ghaniev
Tajikistan
Contact: support@cleanzly.app
For the purposes of GDPR and similar laws, this individual is the data controller for the limited data described below.
1. Plain-language summary
Read this section first — the rest of the Policy explains it in full legal detail.
- Cleanzly is a device-cleanup and storage-optimization utility. Its core features — scanning your photos and videos, the encrypted Vault, contact cleanup, and calendar cleanup — run entirely on your device. Your media, Vault contents, contacts, and calendar events are never uploaded to us. We do not operate any server that receives or stores this content, and we have no ability to access it.
- The App uses Google Firebase (Crashlytics and Analytics) to help us fix crashes and understand aggregate feature usage. Firebase collects limited diagnostic and usage data (e.g., crash logs, device model, app events) and sends it to Google. This is separate from, and never linked to, your personal media, contacts, calendar, or Vault content.
- Purchases are handled entirely by Apple's App Store (StoreKit). We never see or store your payment card details.
- We do not show ads, do not use advertising SDKs or advertising identifiers, do not sell or share your personal information, and do not track you across other companies' apps or websites.
| Data | Where it goes |
|---|---|
| Photos, videos, screenshots | Processed on-device only. Never leaves your device except through your own Apple iCloud, which we cannot access. |
| Vault contents (encrypted files) | Stored on-device, encrypted with a key derived from your PIN and kept in the iOS Keychain. If enabled, optionally synced only to your own private iCloud/CloudKit container. We cannot decrypt or access it. |
| Contacts | Processed on-device only. Never uploaded to us. |
| Calendar events | Processed on-device only. Never uploaded to us. |
| Purchase/subscription status | Handled by Apple via StoreKit. We receive only the transaction/entitlement status needed to unlock features — never card details. |
| Crash reports, device model, OS version, app state | Sent to Google Firebase Crashlytics for stability diagnostics. |
| App usage/interaction events, session data, coarse device info, app-instance identifier | Sent to Google Firebase Analytics for aggregate product analytics. |
2. Scope
This Policy applies to the Cleanzly iOS application distributed exclusively through the Apple App Store. It does not apply to any third-party service you separately choose to use (such as Apple iCloud), which is governed by that provider's own privacy policy.
3. Information we access and why
3.1 Media (Photos & Videos) — processed locally
Cleanzly uses Apple's PhotoKit framework, with your permission, to scan your photo library for duplicates, similar images, screenshots, and other cleanup opportunities. All scanning, comparison, and processing happens on your device, using on-device computation. We do not transmit your photos or videos to any server we operate, and we cannot view them.
If you use Apple's own iCloud Photos service, your media may already be synced to your personal iCloud account — that is a function of Apple's service, governed by Apple's privacy policy, and entirely outside our access.
Legal basis (GDPR Art. 6(1)(b)): performance of the contract with you (providing the cleanup functionality you requested) and, where applicable, our legitimate interest in providing the App's core functionality (Art. 6(1)(f)).
3.2 Vault (encrypted on-device storage) — processed locally
The Vault lets you move selected media into an encrypted, PIN-protected area of the App.
- Encryption uses AES-GCM via Apple's CryptoKit framework.
- Your encryption key is derived from your PIN using HKDF and stored in the iOS Keychain, protected by the device's secure hardware.
- Your PIN and derived keys are never transmitted to us or to any third party — we have no technical ability to decrypt your Vault.
- If you enable optional Vault sync, it uses your own private iCloud/CloudKit container. This data is encrypted before it leaves your device, and only you (via your own Apple ID) can access it. We cannot read its contents.
Because we never hold your PIN or key, if you forget your PIN, Vault contents may be permanently unrecoverable. See the Terms of Use for details.
Legal basis: performance of the contract with you (Art. 6(1)(b)).
3.3 Contacts — processed locally
With your permission, Cleanzly reads your device's Contacts (via Apple's Contacts framework) on-device to detect duplicates and help you clean up your address book. Contact data is processed locally and is never uploaded to us.
Legal basis: performance of the contract with you (Art. 6(1)(b)), based on the permission you grant via the iOS system prompt.
3.4 Calendar events — processed locally
With your permission, Cleanzly reads your device's Calendar (via Apple's EventKit framework) on-device to help you review and clean up old or duplicate events. Calendar data is processed locally and is never uploaded to us.
Legal basis: performance of the contract with you (Art. 6(1)(b)), based on the permission you grant via the iOS system prompt.
3.5 OS-level permissions
Access to Photos, Contacts, and Calendar is governed by iOS system permission prompts. You control these permissions and can review or revoke them at any time in iOS Settings → Privacy & Security, or in Settings → Cleanzly. Revoking a permission disables the related feature but does not affect data already processed on your device.
3.6 Purchases (Apple StoreKit / In-App Purchase)
Subscriptions and any one-time purchases are processed entirely through Apple's App Store and StoreKit. We do not receive, see, or store your payment card, billing address, or other payment credentials — that information stays with Apple.
We receive only the purchase/transaction and subscription-status information Apple provides to the App, which we use solely to unlock the features you've paid for.
Legal basis: performance of the contract with you (Art. 6(1)(b)).
3.7 Diagnostics & Analytics — Google Firebase
Cleanzly uses two Google Firebase SDKs to help us keep the App stable and understand how its features are used in aggregate:
Firebase Crashlytics collects, when the App crashes or encounters an error:
- Crash logs and stack traces
- Device model and operating system version
- App state and version information at the time of the crash
Firebase Analytics collects:
- App usage and interaction events (e.g., which screens/features are opened)
- Session data (e.g., session length, frequency of use)
- Approximate/coarse device and usage information
- A Google-assigned app-instance identifier used to aggregate analytics events (not the same as an advertising identifier)
This diagnostic and usage data is transmitted to and processed by Google LLC as our data processor/service provider. It is not linked to your photos, videos, Vault contents, contacts, or calendar data, and it does not identify you by name, email, or similarly direct means. For details on how Google handles this data, see Google's Privacy Policy and Firebase's data processing terms.
- Data retention: Firebase data is retained according to our project's configured retention setting — [INSERT retention setting, e.g. "14 months for Analytics data; Crashlytics reports are retained per Google's default Crashlytics retention policy"] — and Google's own terms.
- Legal basis (EU/UK users): Crashlytics is used on the basis of our legitimate interest (Art. 6(1)(f)) in maintaining a stable, working App. Firebase Analytics is used on the basis of your consent, which we request via an in-app prompt where required by applicable law (e.g., EU/UK/EEA users, and other jurisdictions requiring opt-in consent for analytics). You may withdraw consent at any time — see Section 9.
- No tracking: Cleanzly does not use advertising identifiers (IDFA) and does not link Firebase data with data from other companies' apps or websites for cross-app/cross-site tracking purposes. Cleanzly does not track you within the meaning of Apple's App Tracking Transparency framework, and no ATT prompt is shown.
3.8 Information we do NOT collect
To be explicit, Cleanzly does not:
- Show advertising or use any advertising SDK
- Collect or use advertising identifiers (IDFA) or engage in cross-app/cross-site tracking
- Integrate with Gmail or any email account
- Sell or share your personal information with third parties for their own marketing purposes
- Operate any server that stores your media, contacts, calendar, or Vault content
4. Third-party services
| Service | Purpose | What it may receive | Provider's privacy policy |
|---|---|---|---|
| Apple App Store / StoreKit | Purchases, subscription management, app distribution | Purchase/transaction data (handled entirely by Apple) | apple.com/legal/privacy |
| Apple iCloud / CloudKit (optional, user-initiated) | Optional Vault sync, Photos sync, if you enable these Apple features | Your encrypted data, within your own private iCloud account | apple.com/legal/privacy |
| Google Firebase (Crashlytics, Analytics) | Crash diagnostics, aggregate usage analytics | Crash logs, device/OS info, usage events, app-instance identifier | policies.google.com/privacy |
We do not use any other third-party analytics, advertising, or data-sharing services.
5. International data transfers
Because Google Firebase operates global infrastructure, diagnostic and analytics data may be processed in countries outside your own, including the United States, which may have data protection laws different from those in your jurisdiction. Where required, such transfers are safeguarded through mechanisms including the EU Standard Contractual Clauses (SCCs) and Google's own compliance commitments (see Google's Data Processing Terms). Your media, contacts, calendar, and Vault data are not part of this transfer, as they never leave your device (except via your own Apple iCloud account, at your direction).
6. Data retention
- On-device content (photos, videos, contacts, calendar entries, Vault items): retained on your device for as long as you keep it there. It is removed when you delete it within the App, delete it via iOS, or uninstall the App (subject to normal iOS behavior and any backups you separately maintain, such as iCloud or a computer backup, which are outside our control).
- Firebase diagnostic/analytics data: retained according to our configured Firebase retention settings — [INSERT retention period] — after which it is deleted or aggregated by Google per their standard practices.
- Purchase records: retained by Apple per Apple's own policies; we retain only the minimal entitlement status needed to keep your purchased features unlocked.
7. Business transfers
If we (the individual developer operating Cleanzly) are involved in a merger, acquisition, reorganization, sale of assets, or transfer of the App to another operator, the limited data described in this Policy — the Firebase diagnostic/analytics data described in Section 3.7, and any purchase/entitlement records described in Section 3.6 — may be transferred to the successor as part of that transaction. Your media, contacts, calendar, and Vault data are not part of any such transfer, as they are never held by us in the first place. Any successor would remain bound by the commitments in this Policy with respect to data transferred to them, and we will provide notice (e.g., within the App or on this page) before your data becomes subject to a different privacy policy.
8. Data security
We rely on Apple's platform security (sandboxing, Keychain, Secure Enclave where available) and on-device encryption (AES-GCM via CryptoKit) to protect Vault contents. Diagnostic data sent to Firebase is transmitted over encrypted connections consistent with Google's security practices. No method of transmission or storage is 100% secure, but because your content stays on your device by design, the App's architecture is intended to minimize the data actually at risk.
9. Your rights and choices
Depending on your location, you may have some or all of the following rights regarding the limited data described in Section 3.7:
- Access — request a copy of the data we (via Firebase) hold about your app usage.
- Rectification — request correction of inaccurate data.
- Erasure ("right to be forgotten") — request deletion of Firebase diagnostic/analytics data associated with your device.
- Restriction / objection — object to or request restriction of processing based on legitimate interest.
- Portability — request your data in a portable format, where technically feasible.
- Withdraw consent — where Firebase Analytics is used on the basis of consent, withdraw that consent at any time. [INSERT: describe the in-app toggle if one exists, e.g. "Go to Settings → Privacy → Analytics and disable 'Share usage data.'" If no in-app toggle currently exists, insert instructions for the developer's chosen consent-management approach, e.g. a first-launch consent prompt with an in-app change option.]
- Lodge a complaint — EU/UK users may lodge a complaint with their local data protection supervisory authority.
Because your media, contacts, calendar, and Vault data are stored only on your device, you exercise full control over that data directly within the App and iOS itself — deleting an item in the App or revoking a permission in iOS Settings is immediate and complete on our end, since we never held a copy.
To exercise any of the above rights regarding Firebase-collected diagnostic/usage data, contact us at support@cleanzly.app. We will respond within the timeframe required by applicable law (e.g., one month under GDPR, extendable as permitted).
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, this section supplements the rest of this Policy.
Categories of personal information we collect (as defined by the CCPA/CPRA), limited to the Firebase diagnostics/analytics described in Section 3.7:
- Identifiers (e.g., a Google-assigned app-instance identifier)
- Internet or other electronic network activity information (app usage/interaction events)
- Device information (device model, OS version)
We do not collect sensitive personal information, and we do not use or disclose personal information for any purpose incompatible with providing and improving the App.
We do not sell or share (as those terms are defined under the CCPA/CPRA) your personal information, and we have not done so in the preceding 12 months.
Your rights under the CCPA/CPRA include the right to know what personal information is collected, the right to delete it, the right to correct it, and the right to opt out of sale/sharing (not applicable here, as we do not sell or share data) and of certain automated decision-making (not applicable here, as we do not perform automated decision-making that produces legal or similarly significant effects). To exercise these rights, contact us at support@cleanzly.app. We will not discriminate against you for exercising any of these rights.
11. Other regional frameworks
Japan (APPI): We handle diagnostic/usage data as a "handler of personal information" would under APPI — collecting only what is necessary for a specified purpose (app stability and analytics), disclosing the purpose in this Policy, and not providing data to third parties beyond our processor (Google) without a proper legal basis.
South Korea (PIPA): Consistent with PIPA principles, we collect only the minimum diagnostic/usage information necessary, disclose our processor (Google Firebase) and purpose of use in this Policy, and do not retain data longer than necessary for that purpose.
If you are located in a jurisdiction with data protection requirements not otherwise addressed above, we intend, as a matter of policy, to apply the protections described in this document as our general standard of practice.
12. Children's privacy
Cleanzly is not directed to children under the age of 13 (or under 16 in the EU/UK, where applicable), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information through Firebase diagnostics, contact us at support@cleanzly.app and we will take appropriate steps to delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in the App, our practices, or legal requirements. We will update the "Last updated" date above, and where changes are material, we will provide notice within the App (e.g., an in-app notice or an updated consent prompt). Your continued use of the App after an update constitutes acceptance of the revised Policy.
14. Contact us
For any questions about this Privacy Policy or to exercise your data rights:
Shahboz Ghaniev
Tajikistan