Skip to content
Water Tracker · Legal

Privacy Policy

What Drink Time collects, why, where it goes, and what control you have over it.

Last updated: August 21, 2026

This Privacy Policy explains what information the Drink Time mobile app (“Drink Time”, “the app”, “we”, “us”) collects, how it is used, where it is stored, and what choices you have.

Drink Time is a water and hydration tracking app for iOS and Android (app identifier com.zappsco.drinktime), operated by Zappsco Ltd.

If you have questions about this policy or about your data, contact us at hello@zappsco.com.

1. Summary

  • Drink Time works fully offline. By default, everything you record stays on your device.
  • If you create an account or sign in, your hydration data is also backed up to Firebase (Google Cloud) so it can be restored on another device.
  • We do not use analytics SDKs, crash-reporting SDKs, advertising SDKs, or cross-app tracking. We do not sell your data.
  • Reminders are local notifications generated on your device. We do not operate a push-notification server.
  • The optional app-blocking (Focus) feature runs entirely on your device. We never receive the list of apps you block or anything you do inside them.

2. Information We Collect

2.1 Information you provide

Onboarding and personalization data. During onboarding, and whenever you later edit it in Settings, you provide:

  • Age (the app supports ages 13–100)
  • Sex (male, female, or “prefer not to say”)
  • Body weight
  • Activity level, exercise frequency, and optionally typical workout duration
  • Typical environment (e.g. cool, hot, humid)
  • Your motivation for using the app, your estimated current intake, how often and when you tend to forget to drink, your usual drinking pattern, and your commitment level
  • Your unit preference (metric or imperial)

This information is used to calculate a recommended starting hydration goal and to personalize wording inside the app. The calculation is a fixed, deterministic formula that runs on your device. No artificial intelligence or external service is involved, and the result is a wellness recommendation — not medical advice (see Terms of Use §11).

Hydration data. Each time you log a drink, the app records the amount (in millilitres internally), the exact timestamp, the local calendar date, and which container preset you used, if any.

Containers. Names and volumes of the containers you create.

Reminders. The reminder times you choose, whether each is enabled, whether reminders are on overall, and your quiet-hours settings.

Account information (only if you create an account). If you sign in, we receive from your chosen sign-in method:

  • Your email address
  • Your display name and profile photo URL, when your provider supplies them (Google and Sign in with Apple; email/password sign-up does not)
  • A Firebase user ID that identifies your account

Your password is never stored or seen by us — email/password sign-in is handled entirely by Firebase Authentication, which stores credentials on Google’s infrastructure.

2.2 Information generated by the app

  • Streak and consistency data — current streak, best streak, and the last date you met your goal.
  • Daily, weekly, and monthly aggregates — computed on your device from the entries you logged. We never estimate or synthesize intake you did not log.
  • Subscription status — whether an entitlement is active, whether it is a free trial, and its expiry date (see §6).
  • App preferences and state — appearance mode (light/dark/system), whether onboarding is complete, whether the notification permission prompt has been shown, and whether an account has ever signed in on this device.

2.3 Information collected automatically

Drink Time does not include any analytics, attribution, advertising, or crash-reporting SDK. Firebase Analytics is not part of the app and is explicitly disabled in the app’s Firebase configuration. We do not collect an advertising identifier (IDFA/AAID), we do not present an App Tracking Transparency prompt, and we do not track you across other companies’ apps or websites.

The app reads your device time zone so reminders fire at the correct local time. This value stays on the device.

The following are collected automatically by third parties as part of providing their service, not by us directly:

  • Firebase Authentication records sign-in metadata such as account creation time, last sign-in time, and the IP address of a sign-in request.
  • RevenueCat, Apple, and Google process purchase and device information when you buy or restore a subscription (see §6).

2.4 Health and fitness data

Drink Time records hydration information you enter, along with the personal attributes listed in §2.1 that feed the goal calculation. Depending on where you live, some of this may be treated as health-related data.

Drink Time does not connect to Apple Health, Google Fit, HealthKit, or any other health platform, and does not read any data from them.

2.5 What we do not collect

We do not request or collect: location, camera or microphone access, photos, contacts, calendars, health-platform data, browsing history, or the contents of any other app on your device.

3. How We Use Information

We use the information described above only to:

  • Calculate your recommended starting hydration goal
  • Show today’s intake, progress, remaining amount, and goal completion
  • Build your history, calendar, charts, streaks, and insights
  • Schedule the reminders you configured, and word them according to your current progress
  • Run the optional app-blocking feature you enabled
  • Back up and restore your data across devices when you sign in
  • Determine whether you have an active subscription or trial
  • Provide support when you contact us

We do not use your data for advertising, profiling for third parties, or sale to anyone.

4. Where Your Data Is Stored

4.1 On your device (always)

The app stores locally:

  • Your water entries, containers, and reminders — in a local SQLite database
  • Your profile, streak, reminder settings, appearance, subscription status, and app flags — in the platform’s standard app preferences storage
  • Your blocked-apps list and app-blocking settings, including (on Android) the package name, display name, and icon of each app you selected

Local data is protected by your device’s own operating-system protections and device encryption. The app does not add a separate layer of encryption on top of the local database, and it does not lock the app behind a passcode.

Local data is removed when you uninstall the app, when you delete your account in the app, or (for account-scoped data) when you sign out.

4.2 In the cloud (only if you sign in)

If you create an account or sign in, the app mirrors data to Cloud Firestore under a document keyed to your Firebase user ID. Specifically:

Synced to the cloud:

  • Your email address and display name (as provided by your sign-in method)
  • Your full personalization profile and daily goal
  • Your streak state
  • Your reminder settings, and each reminder time
  • Every water entry (amount, timestamp, date, container link)
  • Your containers (name, volume, order)

Not synced to the cloud — these stay on the device only:

  • Your blocked-apps list and app-blocking settings
  • Appearance mode and other device-level preferences
  • Your cached subscription status

Firestore access is restricted by server-side security rules so that a signed-in user can read and write only their own documents. Firebase transmits data over encrypted connections (TLS) and Google encrypts data at rest on its infrastructure.

Synchronization runs in both directions while you are signed in: changes made on the device are pushed up, and changes present in the cloud are pulled down. When you sign in on a device that already has local data and your account also has cloud data, the app asks you whether to restore the cloud copy or keep the data on this device. Choosing “Restore” replaces the local entries, containers, and reminders with the cloud copy; choosing “Keep this device” overwrites the cloud copy with the local one.

If cloud synchronization fails — for example, you are offline — the app continues to work normally from local storage and retries later. Because the sync layer is best-effort, we cannot guarantee that every change reaches the cloud.

5. Authentication Providers

You can sign in with:

  • Email and password (Firebase Authentication)
  • Sign in with Google — the app requests your basic profile and email address from Google in order to create your account
  • Sign in with Apple — the app requests your name and email address; if you choose Apple’s “Hide My Email” option, we only ever receive the relay address Apple generates for you

Signing in is optional for using the app’s hydration features, but is required to complete a purchase, restore a purchase, or back up and sync your data.

Password resets are handled by Firebase Authentication, which sends the reset email directly to you.

6. Subscriptions and Payments

Drink Time offers paid access through RevenueCat, which sits in front of Apple’s App Store and Google Play.

  • When you sign in, we set your RevenueCat App User ID to your Firebase user ID, so that your entitlement follows your account across devices and reinstalls. RevenueCat therefore receives that identifier along with the purchase, receipt, and device information its SDK collects.
  • All payments are processed by Apple or Google. We never receive or store your card number, billing address, or any other payment credential.
  • The app stores only the resulting entitlement status locally: whether access is active, whether it is a trial, and when it expires.
  • Promotional/offer-code redemption on iOS is handled entirely inside Apple’s own redemption sheet. The app never sees, validates, or stores the code.

Your purchase records are held by RevenueCat, Apple, and Google under their privacy policies and retention schedules, which we do not control:

7. Notifications

Hydration reminders are local notifications scheduled on your device by the app. There is no push-notification server, and no reminder content is sent over the network — the message text (for example, how much you have left to reach your goal) is generated on the device from data already stored there.

You choose every reminder time. The app never invents or silently reschedules a reminder time. You can turn reminders off in the app, or revoke the notification permission in your device settings, at any time.

8. App Permissions

PermissionPlatformWhy it is used
NotificationsiOS & AndroidTo deliver the hydration reminders you schedule
Exact alarmsAndroidSo reminders and blocking windows fire at the exact minute you chose
Run at device bootAndroidTo re-register your reminders and blocking schedule after a restart
InternetiOS & AndroidSign-in, cloud sync, and subscription checks
Screen Time / Family ControlsiOSOptional app blocking — required by Apple to shield apps you select
Accessibility ServiceAndroidOptional app blocking — to detect when a blocked app comes to the foreground
Query launchable appsAndroidOptional app blocking — to show you a list of installed apps to choose from

Every permission is optional in the sense that the core hydration experience works without it. Blocking-related permissions are requested only if you open the App Blocking feature.

App blocking and your privacy

If you enable app blocking:

  • On Android, an Accessibility Service checks the package name of the app currently in the foreground against the list you selected, entirely on the device. The service is configured so that it cannot read window content. Nothing it observes is stored beyond your own selections, and nothing is transmitted anywhere.
  • On iOS, your selection is made in Apple’s own picker and stored as an opaque token that Apple does not let the app decode. The app can only ever learn how many items you selected — never which apps they are.
  • Confirmations you make on the blocking screen (“I drank water”) are recorded locally and turned into a normal water entry the next time the app opens.

We never see, receive, or transmit which apps you block, how often you open them, or anything that happens inside them.

9. Data Sharing and Third Parties

We do not sell your personal information and we do not share it for advertising. We share data only with the service providers required to run the app:

ProviderWhat it receivesPurpose
Firebase Authentication (Google)Email address, password (hashed by Firebase), provider identity, sign-in metadata including IP addressAccount creation and sign-in
Cloud Firestore (Google)Your email, display name, profile, goal, streak, reminder settings, reminders, containers, and water entriesCloud backup and multi-device sync
RevenueCatYour Firebase user ID, purchase receipts, entitlement and device data collected by its SDKSubscription management and restore
Apple / Google (App Store, Google Play)Payment and purchase dataProcessing your purchase
Sign in with Apple / Google Sign-InThe sign-in request itselfAuthenticating you

We may also disclose information if required by law, to respond to a valid legal request, or to protect the rights, safety, or property of our users or of Zappsco Ltd.

If the app or the business behind it is transferred to another owner, your data may be part of that transfer; we will make reasonable efforts to notify you beforehand.

10. Data Retention

  • Local data is kept on your device until you delete it in the app, delete your account, or uninstall the app.
  • Cloud data is kept for as long as your account exists. It is deleted when you delete your account (see §11).
  • Authentication records are kept by Firebase for as long as your account exists.
  • Purchase records are retained by RevenueCat, Apple, and Google under their own retention policies, even after you delete your Drink Time account. We cannot delete those records on your behalf.

11. Data Deletion and Account Deletion

Deleting individual data

You can delete any individual water entry from the daily timeline, and you can delete containers and reminders at any time. When you are signed in, those deletions are also propagated to the cloud copy.

Signing out

Signing out clears your account-scoped data from the device — your profile, streak, reminder settings, and cached subscription status. Your cloud data is untouched and is available again the next time you sign in.

Deleting your account

Settings → Account → Delete account performs, in this order:

  1. Stops cloud synchronization.
  2. Deletes all of your Firestore data — every water entry, container, and reminder, plus your user document containing your email, display name, profile, streak, and reminder settings.
  3. Detaches your account from RevenueCat.
  4. Deletes your Firebase Authentication account.
  5. Revokes the app’s Google OAuth grant, where Google was your sign-in method.
  6. Clears your hydration data, profile, streak, reminder settings, and subscription state from the device, and returns the app to a fresh state.

For security, Firebase may require you to re-authenticate first; the app will prompt you and then retry.

Important limitations, stated plainly:

  • If you signed in with Apple, deleting your account here stops Drink Time from using your Apple ID, but only you can remove the app from your Apple ID, in Settings → your name → Sign-In & Security → Sign in with Apple. The app explains this on the deletion screen.
  • Deleting your account does not cancel your subscription and does not produce a refund. Subscriptions must be cancelled through your App Store or Google Play account (see the Terms of Use).
  • Purchase records held by RevenueCat, Apple, and Google are not deleted by this flow.
  • Deletion of cloud data is carried out on a best-effort basis. If a network or server error interrupts it, some records may remain; contact us at hello@zappsco.com and we will complete the deletion.
  • Residual copies may persist for a limited period in our providers’ routine backups before being overwritten in the ordinary course.

You may also request deletion by writing to hello@zappsco.com.

12. Data Security

  • Traffic between the app and Firebase is encrypted in transit using TLS.
  • Firestore data is encrypted at rest on Google’s infrastructure.
  • Firestore security rules restrict every read and write so that an account can only access its own documents, and validate the shape of records that are written.
  • Passwords are handled and stored by Firebase Authentication; we never see them.
  • Sign in with Apple uses a cryptographically random, hashed nonce to protect against replay attacks.
  • On-device data relies on the operating system’s app sandbox and device encryption. The app does not separately encrypt its local database.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children's Privacy

Drink Time is not directed to children. The app’s personalization only supports ages 13 and above, and it is intended for users aged 13 or older. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact hello@zappsco.com and we will delete it.

14. International Data Transfers

Firebase (Google) and RevenueCat operate globally. If you use an account, your data may be processed and stored on servers located outside your country of residence, including in the United States, where data-protection laws may differ from those where you live. By creating an account you consent to that transfer. Where required, we rely on the transfer mechanisms offered by these providers.

15. Your Rights

Depending on where you live (for example, under the GDPR in the EEA/UK, or under the CCPA/CPRA in California), you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information
  • Port your information to another service
  • Object to or restrict certain processing
  • Withdraw consent at any time
  • Not be discriminated against for exercising these rights

Much of this you can exercise directly in the app: your hydration data, profile, goal, containers, and reminders are all viewable and editable, and account deletion is available in Settings. For anything else — including a copy of your data in a portable format — contact hello@zappsco.com. We will respond within the time frame required by applicable law.

We do not sell or share personal information as those terms are defined under California law.

16. Changes to This Privacy Policy

We may update this policy as the app changes. When we do, we will revise the “Last updated” date above and publish the new version at the same URL, which is linked from the app’s Settings screen. Material changes will be communicated in the app or by email where appropriate. Continuing to use Drink Time after an update means you accept the revised policy.

17. Contact

Zappsco Ltd

Email: hello@zappsco.com

For privacy-specific requests, please write “Privacy Request” in the subject line.