Privacy Policy
1. Who is responsible for your data
The controller of the data described below is Dravoss LLC («ԴՐԱՎՈՍՍ» ՍՊԸ), a company registered in the Republic of Armenia. Registration number 999.110.1603874, taxpayer number (TIN) 08331738, registered address: N. Zaryan St. 22A, Arabkir, Yerevan 0051, Armenia.
Contact: support@witto.tech
Representative in the EU and the UK (Article 27 GDPR): [name, address, contact — to be filled in once appointed]
2. The short version
Witto is built to work on your device. Your answers, your exercise results and your scores are written to local storage on the device.
Two things do go to our server, under two different conditions:
- Usage events — which screens you opened, which exercises you started, whether a purchase went through. These are sent once you have accepted this policy, whether or not you have an account.
- Your progress — copied to the server only if you sign in, so a replacement device can pick it up.
There is no third-party analytics, no crash reporter, no advertising and no ad tracking in the app.
3. What is stored on your device
In the app's local database:
- Onboarding profile — the name you typed (optional), your age range and the age it implies, your self-reported screen-time band, your two self-ratings for focus and forgetfulness, the skill you picked as a priority, how you heard about the app, the checklist items you ticked, and the date you finished onboarding.
- Exercise results — for every round: which exercise it was, which skill it belongs to, its measured metrics, the completion time, and whether it was part of a test.
- Scores — your brain-age value with the date it was computed, and per-skill values with their statistical measures.
- Test snapshots — the date of each test with the lower and upper bound of your brain-age range and the per-skill values behind it.
- Daily training totals — per day: experience points, number of sessions, accuracy totals and minutes.
- Training state — difficulty per skill, recent exercise types, rolling accuracy per type, play counts, personal bests, last-played dates and your library levels.
- Progress — modules completed, streak, experience and level, and awards.
- Unfinished sessions — lessons you started but did not complete.
In the app's settings: chosen theme, chosen language, game sound on or off, favourite exercises, chosen avatar, which tutorials and awards you have already seen, whether a one-time offer has been shown, subscription status, your consent flag for usage events, the installation identifier, internal sync bookkeeping, and markers for scheduled reminders.
In the device's secure storage: the name and email address received at sign-in, your account identifier at the sign-in provider, and your session token.
In app files: a queue of usage events not yet sent, and up to two backups of the local database, no older than 30 days.
4. What is sent to our server, and when
Both categories land in the same Supabase project — a hosted PostgreSQL service.
4.1. Usage events — sent without an account
Once you have accepted this policy in the app, Witto sends usage events to the analytics_events table. No account is needed for this. Events are queued on the device and uploaded in batches; the upload is gated on your acceptance, not on having an account.
Every event carries:
| Field | What it is |
|---|---|
| Event identifier | a random identifier the app assigns to each event so that the same event is not recorded twice if a batch is sent again |
| Installation identifier | a random identifier created on first launch and kept in the app's settings. It is not your app store identifier, not your device identifier and not an advertising identifier — but it does persist across launches and lets events from this installation be grouped together. |
| Account identifier | present only if you are signed in, absent otherwise |
| Session identifier | identifies one run of the app |
| Event name | what happened: app opened, lesson started, subscription screen shown, purchase completed |
| Parameters | a small set of structured values: which screen, which exercise variant, which plan, how many games were done. Free text is not permitted here. |
| Time of the event | when it happened |
| App version and build | which version it happened in |
| Platform and language | the operating system, and the interface language |
What is deliberately kept out: your name, your email address, your age, your screen-time answer and your self-ratings. For the onboarding questions the app records that a question was answered, never the answer itself. A filter in the app enforces this — it accepts only a fixed list of parameter keys, rejects keys such as name, email, age and answer outright, and rejects values that look like free text or contain an "@".
The app can only insert rows into this table. It cannot read, update or delete them. Events are deleted automatically 180 days after they occurred.
4.2. Your progress — only if you sign in
If you sign in, the app keeps a copy of your progress so a replacement device can pick it up. Six tables are synced, each row tied to your account:
| Table | What it holds |
|---|---|
| Profile | display name, subscription status and its expiry |
| Progress | experience, level, streak, modules, awards |
| Training state | difficulty, accuracy, play counts, personal bests, library choices |
| Scores | brain-age value, when it was computed, per-skill breakdown |
| Test snapshots | test date, brain-age range, per-skill values |
| Daily totals | experience, sessions, accuracy totals and minutes per day |
Your individual exercise results never leave the device. The per-round records are deliberately excluded from sync and have no table on the server.
Every row is tied to your account identifier, and the database enforces row-level security: a request can only read or write rows whose owner matches the signed-in user. Without a session, no rows are returned at all.
5. Where the data physically sits
Our Supabase project runs in the eu-north-1 region (Stockholm, Sweden) on Amazon Web Services infrastructure. This is inside the European Economic Area, so no transfer outside the EEA takes place over this channel.
Supabase acts as our data processor under its data processing agreement.
6. How long we keep it
- Usage events — 180 days, after which they are deleted automatically on a schedule.
- The copy of your progress (the six tables above) — there is no automatic deletion. Rows are kept until you ask us to delete them, as described in section 9.
- Data on your device — until you delete your account inside the app, or delete the app itself.
- Payment and subscription records — to the extent we receive them from the app store, they are kept for the period required by applicable accounting and tax law: 5 years from the end of the reporting year in which the transaction took place. These records are stored separately and are not used to restore your profile or your training history.
7. Legal bases for processing
| What we process | Basis |
|---|---|
| Local data and running the app | performance of our contract with you — Article 6(1)(b) GDPR |
| The copy of your progress on the server when signed in | performance of our contract with you — Article 6(1)(b) GDPR |
| Usage events | your consent — Article 6(1)(a) GDPR |
| Website server logs, abuse prevention | our legitimate interest in the security of the service — Article 6(1)(f) GDPR |
| Payment and subscription records | compliance with a legal obligation — Article 6(1)(c) GDPR |
| Handling support requests | performance of our contract and our legitimate interest |
8. Signing in
Signing in is optional; the app is fully usable without an account. When you sign in with Apple, Witto asks for exactly two things: your name and your email address. Nothing else. If you choose Apple's private relay address, that relay address is what we receive, not your real one. The app also periodically checks whether the sign-in is still valid, so it can tell you if access was revoked.
9. Account and data deletion
This section explains how to delete your Witto account and how to request deletion of the data associated with it.
How to request deletion
There are two ways. The second does not require the app to be installed.
- In the app. Open the app, go to the profile section and press "Delete account". The button erases all data on your device and signs you out.
- By email. Send a request to support@witto.tech from the address associated with your account, stating that you want your account and data deleted. If you signed in with Apple and chose to hide your email address, send the request from the relay address issued to you by Apple, or include information that lets us identify your account.
We delete the account and the associated data on the server within 10 business days of receiving the request. Before we proceed, we may write to your registered address to confirm that the request came from the account owner.
Important. The button in the app erases the data on your device, but the copy of your progress on the server remains. To have that and the account itself deleted, send the request by email as described above. We say this directly rather than promising more than the button does.
Before you delete your account: active subscriptions
Deleting your Witto account does not cancel a paid subscription and does not by itself result in a refund. Subscriptions are billed by the app store you bought them from, and only you can cancel them:
- App Store — open Settings on your device, tap your name, go to Subscriptions, select Witto and cancel it.
- Google Play — open the Google Play app, go to Payments and subscriptions, select Witto and cancel it.
Please cancel your subscription before requesting deletion of your account. If you have already deleted your account and are unsure whether your subscription is still active, write to support@witto.tech and we will help you check its status and direct your refund request to the appropriate store.
What is deleted
When your account is deleted, we permanently delete from our systems:
- your account and the credentials associated with it, including your name and email address;
- the copy of your progress on the server: profile, progress, training state, scores, test snapshots and daily totals;
- the usage events sent from your installation, if you ask for that in the same message.
The button in the app additionally erases on the device: onboarding profile, exercise results, scores, test snapshots, daily totals, progress and training state, unfinished sessions, settings and preferences, backups, and the stored name, email and sign-in link.
Deletion is irreversible. Once done, the data cannot be restored, and you lose access to the history of your results.
Deleting the app without deleting your account removes the local database along with the app, but leaves the server copy untouched.
What is retained and for how long
After your account is deleted we retain, in the minimum volume necessary:
- payment and subscription records — for the period required by applicable accounting and tax law: 5 years from the end of the reporting year in which the transaction took place. These records are stored separately and are not used to restore your profile or your result history;
- data whose retention is required by law — for the period established by that law, and disclosed to a public authority only under a legally established procedure.
Changing your data
At any time you can view, change or delete individual details in your account — directly in the app, or by writing to support@witto.tech.
10. Your rights
If you are in the EEA or the UK, you have the following rights:
- Access — obtain a copy of the data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, as described in section 9.
- Restriction — have processing temporarily suspended.
- Objection — object to processing based on legitimate interest.
- Portability — receive your data in a machine-readable form.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing before the withdrawal.
To exercise any of these, write to support@witto.tech from the address associated with your account. Deletion requests are completed within 10 business days; other requests within one month at the latest.
How to withdraw consent for usage events
There are currently two ways:
- Delete the app. Reinstalling clears the consent flag together with the queue of unsent events, and collection stops.
- Write to support@witto.tech. We will delete the events already collected from your installation and stop accepting further ones.
We state plainly that there is no separate toggle inside the app yet.
Complaints
If you believe we are processing your data unlawfully, you have the right to complain to the data protection supervisory authority in your country of residence. The list of EEA authorities is published by the European Data Protection Board. In the UK, it is the Information Commissioner's Office.
11. Data security
We take organisational and technical measures to protect your data against unlawful or accidental access, destruction, alteration, blocking, copying and disclosure:
- traffic between the app and the server travels only over an encrypted connection;
- the database enforces row-level security: without a valid session a request returns no rows at all, and with one it returns only the rows belonging to that user;
- the app may only insert rows into the usage-events table and cannot read, alter or delete them;
- your name, email address and session token are held in the operating system's secure storage rather than in ordinary app settings;
- access to the production database is limited to a small number of people and granted only where it is needed for the work;
- the content of usage events is restricted to a fixed list of fields, and a filter in the app rejects attempts to place personal details into them.
No system is perfectly secure, and we cannot guarantee absolute safety for data transmitted over the internet.
12. What Witto does not do
- No third-party analytics. The usage events described above go to our own server and nowhere else. There is no Firebase, Amplitude, Mixpanel, AppsFlyer, Adjust or PostHog in the app, and no data broker receives anything.
- No crash reporting. No Crashlytics, no Sentry. If the app fails, we learn about it only if you tell us.
- No advertising and no tracking. The app never asks for permission to track, does not touch the advertising identifier, is not connected to SKAdNetwork, and shows no ads.
- Two external dependencies, neither of them a tracker. The Supabase client, which performs the network calls described above, and Lottie, an animation player that renders artwork inside the app and makes no network requests of its own.
- We do not sell or share personal data with third parties.
13. Payments
Subscriptions are sold and billed by the app store you installed Witto from — the Apple App Store or Google Play. Witto never sees or handles your card details, and they never reach our servers. The app stores only a flag saying whether a subscription is active and when it expires.
14. Age
Witto is intended for people aged 16 and over. We deliberately do not collect data from children below that age. If you believe a child under 16 is using the app with an account, write to support@witto.tech and we will delete that account and the data associated with it.
The age-range question in onboarding includes an "under 18" option — it is used only to interpret the result, and it neither grants nor restricts access to anything.
15. For California residents
We do not sell personal information and do not share it for targeted advertising — neither for money nor on any other terms. The categories of information collected and the purposes are described above. You have the right to request details of the information collected, to request its deletion and correction, and we will not discriminate against you for exercising those rights. Requests: support@witto.tech.
16. This website
witto.tech is a set of static pages. It sets no cookies, embeds no fonts, scripts or images from other domains, and runs no analytics. Requests are handled by our hosting provider Beget, which keeps standard server logs including IP addresses. The provider does not publicly disclose how long those logs are retained.
17. Changes
If this policy changes materially, we update the revision number and the date at the top of this page and tell you about significant changes in the app. The current version is always available at witto.tech/privacy.html
18. Contact
Privacy questions: support@witto.tech