Sadhana

Privacy Policy

Last updated 16 August 2026 · Effective 16 August 2026

This policy describes how the Sadhana mobile application (com.zenski.japa, “Sadhana”, “the app”) handles your information. It is written to be read, not to be survived.

The short version. Your practice is stored on your device. Nothing leaves it unless you turn on cloud sync or backup. Analytics and crash reporting are off until you switch them on. Your mantras, Sankalpa intentions, practice notes, profile names and group content are never used for advertising or analytics, and are never sold or shared with anyone.

1. Who is responsible

Sadhana is published by Zenski, an independent developer, who is the data controller for the purposes of the UK and EU General Data Protection Regulation. You can reach us at info.zenski@gmail.com.

2. What stays on your device

By default, everything. The app stores the following in a database on your device, and — unless you enable an optional feature described in section 3 — it never transmits any of it anywhere:

There is no age, date of birth, phone number or contact detail anywhere in the app, because there is nowhere in it to store one.

3. What leaves your device, and only if you ask

3.1 Signing in (optional)

You may sign in with Google or Apple. There is no email-and-password option, so Sadhana never receives, stores or transmits a password. Signing in creates an account identifier (a “uid”) held by Firebase Authentication; within Sadhana’s own records that uid is the only thing kept about your identity — no email address, no display name.

Signing in on its own uploads no practice data. It only makes cloud sync, cloud backup and group features possible.

3.2 Cloud sync and cloud backup (optional, off by default)

If you enable either, a second copy of your practice data is stored in Google Cloud Firestore under your account. It is readable only by that account: there is no public path, no share link and no signed URL anywhere in the design. Turning the feature off stops future uploads; it does not by itself delete what is already there, which you can remove at any time (section 8).

3.3 Group Sankalpa (optional)

If you create or join a group, the practice figures you contribute to that group are visible to its other members, along with the profile name you chose. Groups are invite-only: there is no feed, no directory and no way to search for people or be found by them.

3.4 Notifications (optional)

Reminders are scheduled on your device and involve no server. If you enable group notifications, Firebase Cloud Messaging issues a delivery token for your device. Sadhana stores only a truncated one-way hash of that token, and the token is discarded when you sign out or turn notifications off.

3.5 Analytics (optional, off by default)

If you turn on Help improve Sadhana, the app sends anonymous usage events through Firebase Analytics: which screens are opened and which features are used. What it sends is deliberately constrained:

3.6 Crash diagnostics (optional, off by default)

If you turn on Share crash diagnostics, Firebase Crashlytics receives technical details when something goes wrong — what failed and where in the app. No account identifier, no device identifier and none of your practice content is attached. This is a separate switch from analytics; agreeing to one is not agreeing to the other.

3.7 Advertising (free tier only)

The free tier may show adverts supplied by Google AdMob on browsing screens. They never appear during Japa, meditation or any practice surface, and never for a Premium subscriber.

3.8 Purchases

Premium is sold by Apple and Google, not by us. Payment is handled entirely in their systems: Sadhana never sees or stores a card number, a billing address or a payment credential. The app receives only whether an entitlement is active, and keeps that locally.

3.9 App integrity and configuration

Sadhana uses Firebase App Check to confirm that requests come from a genuine, unmodified copy of the app, and Firebase Remote Config to adjust feature settings without a release. Both involve a request to Google containing device attestation and technical data; neither carries your practice content or your identity.

4. What is never collected

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. Why we process what we do

Data Purpose Legal basis (UK/EU GDPR)
Practice data on your device To provide the app itself Contract — you asked for the app to work
Account uid To identify your cloud copy and your groups Contract
Cloud sync / backup copy To keep your practice safe and in step across devices Contract, at your request
Group contributions To show a shared commitment to its members Contract, at your request
Notification token hash To deliver group notifications you enabled Consent
Analytics events To understand which features are worth building Consent — off until you switch it on
Crash diagnostics To find and fix defects Consent — off until you switch it on
Advert requests To fund the free tier Legitimate interests, and consent where required
App Check attestation To keep the backend from being abused Legitimate interests — protecting the service

6. Who else is involved

Sadhana uses a small number of processors. We do not sell data to anyone, and there are no advertising or data brokers beyond the advert network named below.

Service Used for Only when
Firebase Authentication (Google) Sign in with Google or Apple You sign in
Cloud Firestore (Google) Cloud sync, backup, groups You enable them
Firebase Cloud Messaging (Google) Group notifications You enable them
Firebase Analytics (Google) Anonymous usage events You opt in
Firebase Crashlytics (Google) Crash diagnostics You opt in
Firebase App Check & Remote Config (Google) Integrity and configuration Always
Google AdMob Non-personalised adverts Free tier, browsing screens
Apple App Store / Google Play Purchases and subscriptions You buy Premium

These services are operated by Google LLC and Apple Inc. and may process data on servers outside your country, including in the United States. Transfers rely on the transfer mechanisms those providers maintain, including the European Commission’s standard contractual clauses. See the Firebase privacy documentation and the Google Privacy Policy.

7. How long it is kept

8. Your choices, inside the app

These are controls, not requests you have to make of us. All of them are under Profile → Account & Privacy:

9. Your rights

Depending on where you live, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time without affecting what was done before. For most of these the fastest route is section 8, which does it immediately and without asking anyone.

For anything the app cannot do for you, write to info.zenski@gmail.com. We will respond within 30 days. If you are in the UK or the EEA you may also complain to your data protection authority — in the UK, the Information Commissioner’s Office.

If you are a California resident, you have the rights to know, delete, correct and to opt out of sale or sharing. As stated in section 4, we do not sell or share personal information, so there is nothing to opt out of; you will never be discriminated against for exercising a right.

10. Children

Sadhana is not directed to children under 13 (or the equivalent minimum age where you live), and we do not knowingly collect personal data from them. The app asks for no age and infers none. If you believe a child has provided personal data, write to us and it will be deleted.

11. Security

Data in transit is encrypted with HTTPS/TLS. Cloud data is protected by security rules that make each account’s data readable only by that account, and by Firebase App Check, which rejects requests that do not come from a genuine copy of the app. Data on your device is protected by your device’s own encryption and lock. No system is perfect, and we do not claim otherwise.

12. Changes to this policy

If this policy changes, the date at the top changes with it, and a material change will be signalled in the app before it takes effect. The current version always lives at this address.

13. Contact

Zenski · info.zenski@gmail.com