Effective date: September 2, 2026
Daily Talk Topics is operated by Phi IT, a sole proprietorship (eenmanszaak), at Bazillehof 46, 1628 XD Hoorn, the Netherlands, registered with the Dutch Chamber of Commerce under KVK 85537578 ("we", "our", "us"). Phi IT is the controller for the processing described here.
Contact us at [email protected]. This notice covers the Android app, website, support, and related backend services.
The app creates a random installation identifier and authentication token. Our server stores the identifier, a one-way token hash, creation and activity dates, streak values, selected category and date, and subscription status. We use these pseudonymous records to authenticate the app, provide and order daily content, enforce limits, maintain streaks, prevent abuse, and support deletion. No account name, login email, or phone number is required.
Google Play processes payments. RevenueCat receives the installation identifier as an App User ID and supplies entitlement status, product ID, purchase and expiry dates, aliases where applicable, and synchronization event identifiers. We do not receive card or bank details.
If you submit a topic suggestion or feedback, we store its text, the installation identifier, and a timestamp for authorized review. Support email includes information you choose to send and may include your installation identifier. Do not include sensitive or unnecessary personal information. If an approved suggestion is incorporated into the general topic library, its text may remain as unattributed app content after the source submission and identifier are deleted.
Requests expose IP address, user agent, and technical metadata to Cloudflare and our hosting infrastructure. The backend uses IP addresses temporarily for registration rate limiting. Operational and security logs may contain request metadata, event identifiers, or installation identifiers.
Conversation topics are generated with a self-hosted language model. Generation prompts contain internal category and date context, not installation records, selections, suggestions, feedback, or subscription data. Generated content does not make decisions about users that produce legal or similarly significant effects.
Our app uses the following third-party services:
Google's User Messaging Platform requests your choices before Mobile Ads is initialized where required. If permission to request ads is unavailable or consent gathering fails, the app does not show a banner. Banner requests are configured as non-personalized, but contextual advertising may still process IP address, device and advertising identifiers, interactions, consent records, diagnostics, and fraud-prevention information.
You may choose Consent, Do not consent, or Manage options. Where Google requires a privacy-options entry, it is available in Settings so you can change or withdraw your choice. Pro subscribers do not see advertisements, although consent configuration may occur while subscription status is being initialized.
We do not send selected categories, topic suggestions, or feedback to AdMob for targeting.
The installation identifier and authentication token are stored using Android secure storage. Ordinary local app storage contains cached topics, selections, revealed-topic history, streak and subscription cache, notification time, onboarding, theme, haptic, review-prompt, and deletion-lock preferences. Local storage is accessible to the app and is removed when you clear app storage or uninstall, subject to Android backup behavior.
Primary backend records are hosted on infrastructure we administer in the European Union. API communications use HTTPS and bearer-token authentication. No security measure eliminates all risk.
We do not sell personal data. We disclose data only as described here, on your instruction, or when legally required.
RevenueCat, Google, Cloudflare, and support providers may process data outside the European Economic Area, including in the United States. Depending on the recipient and transfer, safeguards include an adequacy decision such as the EU-US Data Privacy Framework where the recipient is certified, or European Commission Standard Contractual Clauses with supplementary measures. Contact us for information about safeguards relevant to your data.
Settings > Delete My Data removes the current installation record and directly linked selections, streak, suggestions, feedback, and subscription status from our primary database when the request succeeds. It also clears credentials, content, streak, and subscription state used by the app. Some non-identifying local preferences remain until you clear Android app storage or uninstall.
This action also requests deletion of the matching RevenueCat customer record. It does not cancel a recurring Google Play subscription, so cancel that separately in Google Play. It does not delete Google transaction records, logs awaiting expiry, backups awaiting rotation, or suggestion text already incorporated as unattributed content.
Alternatively, follow our data deletion instructions or email us. We normally respond to privacy-rights requests within one month, subject to lawful extensions or retention exceptions.
The service is not directed to children under 16. Users under 16 should not submit personal information without authorization from a parent or legal representative. A parent or guardian should approve purchases where required. Contact us if you believe a child has submitted personal data so we can assess and delete it where appropriate.
Subject to applicable conditions and exceptions, you may have the right to:
To exercise a right, contact us and include the installation identifier shown by the app if available. We use proportionate verification and will explain if a right does not apply. You may complain to the Autoriteit Persoonsgegevens.
Providing an installation identifier is necessary for authenticated app delivery and deletion. Suggestions, feedback, notifications, and advertising consent are optional; refusing them does not remove core access. Subscription information is necessary only for Pro access.
Our public pages use no first-party analytics, advertising pixels, or browser-storage code. Page presentation assets are served from our own origin. Cloudflare and hosting infrastructure still receive ordinary request metadata and may use strictly necessary security or delivery mechanisms. Links to external sites load those sites only when you follow them.
We may update this notice when our service or legal obligations change. We will update the effective date and provide an in-app or other prominent notice before a material change where required. A privacy notice describes processing; it does not rely on continued use as consent.