PRIVACY / EU + EEA

EU/EEA Privacy Notice

AI Limits Tracker · Effective August 31, 2026

1. Data Controller

The Data Controller is JoCoding, Inc., a Delaware corporation. Registered address: 1111B S Governors Ave, STE 80543, Dover, DE 19904, United States. Email: mu07010@jocoding.net. Telephone: +1 (231) 450-5622. JoCoding has not appointed a Data Protection Officer because its present processing does not involve large-scale monitoring or special-category data.

2. EU representative

JoCoding has not appointed an Article 27 EU representative for this release. The app is designed not to transmit credentials or usage data to JoCoding, and JoCoding’s direct personal-data processing is limited to ordinary support communications and public-site request operations. Contact the Controller directly at the email above. We will revisit representation if EU-directed processing expands or the Article 27 exemption no longer applies.

3. What is processed and where

Provider credentials, account identifiers and aliases, normalized usage snapshots, preferences, alert rules, widget snapshots, and redacted diagnostics are processed by the app. On Apple devices, credentials and the account name the provider returned at sign-in may sync through the user’s own iCloud Keychain. Provider/account identifiers, local aliases, internal account IDs, and the latest normalized usage snapshot may sync through CloudKit private DB on the user’s iCloud account to that user’s other devices running this app. Provider email addresses are not synced through CloudKit. JoCoding does not receive or have access to the contents of the user’s iCloud Keychain or private CloudKit database through the app, an app account, analytics SDK, advertising SDK, crash SDK, or required relay. When the user explicitly chooses an available provider connection, the device sends authentication and usage requests directly to that provider.

JoCoding may process ordinary support email information (email address, message, and attachments the user chooses to send) and public-site request metadata processed through Cloudflare. Do not send credentials, tokens, cookies, OAuth codes, or raw provider responses to support.

4. Purposes and Legal basis (Article 6)

PurposeDataLegal basis
Provide requested support and answer privacy requestsContact details and message supplied by the userContract or steps at the user’s request; legal obligation for rights requests
Protect the public site and serviceLimited network/request metadataLegitimate interests in security, abuse prevention, and service availability
Direct provider connection selected by the userData transmitted by the device to the provider, not received by JoCodingPerformance of the user-requested app function; the provider is responsible for its own processing
Product analyticsApp events, an anonymous analytics identifier, app and OS version, device model, and a coarse region derived from the IP addressLegitimate interests in improving the app and diagnosing failures (Article 6(1)(f)). You can turn this off in Settings, or object through the contact in the rights section
Install attributionInstall and session signals, device vendor identifier (IDFV), IP addressLegitimate interests in measuring marketing performance (Article 6(1)(f)). You can turn this off in Settings. The advertising identifier is not collected

5. Recipients, processors, and international transfers

PostHog processes app usage events and an anonymous analytics identifier as a processor for product analytics on servers in the United States. AppsFlyer processes install and session signals as a processor to attribute installs to marketing campaigns; the Strict SDK variant does not collect the advertising identifier. Cloudflare serves the static website and may process network/request metadata as a processor or independent provider under its terms. Apple distributes the app and supplies operating-system services under Apple’s terms. RevenueCat processes purchase receipts, subscription status, and an anonymous app user identifier as a processor for purchase validation and subscription analytics. Provider credentials and usage values are not sent to RevenueCat. Support email infrastructure processes messages sent to the published mailbox. These services may process data outside the EEA using adequacy decisions or contractual safeguards described in their policies. South Korea has an EU adequacy decision for covered transfers; the United States may require an applicable Data Privacy Framework certification or Standard Contractual Clauses. A selected AI provider receives data directly from the device under its own privacy notice and transfer mechanism.

6. Retention

On-device app data is retained and deleted as described in the Global Privacy Policy. Support communications are retained only as long as needed to answer, document, and defend the request, normally up to 24 months unless law or an active dispute requires longer. Cloudflare and email-provider logs follow the provider’s documented retention and account settings.

7. Your GDPR rights

You have the Right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object, and right to withdraw consent where consent is used. You also have rights relating to automated decision-making. The app does not make solely automated decisions with legal or similarly significant effects.

Email the Controller to exercise a right. We normally respond within one month and may extend by two months for a complex request after notifying you. Because most app data never reaches JoCoding, the in-app deletion controls may be the direct way to act on on-device data, and the selected provider must handle provider-side requests.

8. Complaints and provision of data

You may lodge a complaint with the supervisory authority in your country of residence, work, or alleged infringement. The EDPB member list links national authorities. Support data is voluntary but we may be unable to answer without enough information to understand and verify the request. Provider credentials and usage are not contractually required by JoCoding; a provider connection cannot work without the data required by that provider.

9. Security and breach notification

JoCoding uses the safeguards described in the Global Privacy Policy. If a personal-data breach involving data controlled by JoCoding is likely to risk individuals, JoCoding will notify the competent supervisory authority within 72 hours of becoming aware where required and notify affected people without undue delay when the risk is high.

10. Children, special categories, cookies, and changes

The service is intended for users aged 16 and older. JoCoding does not intentionally collect special-category data through the app. The public site has no analytics or advertising script and sets only the browser-local language preference; Cloudflare may use strictly necessary security mechanisms. Material notice changes are posted here with a new effective date.

GDPR contact
JoCoding, Inc. · mu07010@jocoding.net · +1 (231) 450-5622