Legal
Privacy Policy
ShimmerPool ("we," "us," or "our") is an offline-first pool water chemistry tracker built by a solo developer. Privacy is not an afterthought — it is built into the architecture. Your pool data lives on your device by default, and the choices you make determine how much, if anything, leaves it.
This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. By using ShimmerPool, you agree to the practices described below.
1. Information We Collect
Anonymous / Guest Users
When you use ShimmerPool without creating an account, no personal identifying information is collected or transmitted.All water chemistry records, chemical calculations, pool configurations, and history are stored exclusively on your physical device in a secure local SQLite database (expo-sqlite). We have no access to this data.
Registered Users (Cloud Sync)
If you choose to register or sign in — via Google Sign-In or email/password — we collect and securely store the following in our cloud database to enable multi-device sync:
- Email address — used as your account identifier.
- Active session tokens — short-lived tokens used to authenticate requests. These are never shared with third parties.
- Pool data you enter — readings, configurations, and treatment history that you explicitly sync to the cloud.
Diagnostic & Usage Information (All Users)
We automatically collect anonymous, non-identifying technical information to improve app stability and features:
- Crash reports — anonymous device info and stack traces to diagnose bugs (via Sentry).
- Feature interaction statistics — which screens and features are used, without any personal identifiers (via PostHog).
2. Data Storage & Syncing
Local storage — Guest and registered users alike keep a primary copy of their data on-device in an expo-sqlite database. This data is sandboxed to the app and is not accessible to other apps.
Cloud storage (registered users only) — Synced data is stored in Supabase, a secure cloud database platform hosted on Amazon Web Services (AWS). All data is encrypted in transit using SSL/TLS and encrypted at rest. Supabase complies with SOC 2 Type II and GDPR.
3. Third-Party Services
We use the following trusted third-party services. Each processes only the minimum data required for their function:
Supabase Auth
Authentication and cloud database hosting. Processes your email address and session tokens to manage your account and sync your data. Supabase Privacy Policy ↗
Sentry
Crash logging and stability diagnostics. Receives anonymous device information and crash stack traces when the app encounters an error. No personal data is included. Sentry Privacy Policy ↗
PostHog
Anonymous feature interaction analytics used to guide product decisions and UI improvements. Events contain no personal identifiers. PostHog Privacy Policy ↗
4. How We Use Your Information
- Provide, operate, and personalize the ShimmerPool Service.
- Sync your pool data securely across your devices (registered users).
- Diagnose crashes, fix bugs, and improve app stability.
- Understand feature usage patterns to guide product improvements.
- Comply with applicable laws and legal obligations.
We do not sell your personal information. We do not use your data for advertising.
5. Your Rights & Data Deletion
You have the right to access, correct, or permanently delete your account and all associated cloud data at any time. Deletion is available through two methods:
- In the app: Settings → Preferences → Account → Delete Account
- Web portal: shimmerpool.com/delete-account
Cloud account deletion permanently and irreversibly removes your profile, email address, session data, and all synced pool logs from our Supabase databases. Local data on your device is unaffected by a cloud deletion request; to delete local data, clear the app cache or uninstall ShimmerPool.
For California residents (CCPA) and EU/EEA residents (GDPR), you also have the right to know what data we hold, request a portable copy, and object to processing. Submit these requests to [email protected].
6. Data Retention
We retain cloud account data for as long as your account is active. When you delete your account, cloud data is purged within 48–72 hours. Anonymous diagnostic data (crash logs, usage events) may be retained in aggregated, non-identifiable form for up to 12 months to support trend analysis.
7. Security
We use commercially reasonable technical and organizational measures to protect your information, including SSL/TLS encryption in transit and encryption at rest in Supabase. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. Children's Privacy
ShimmerPool is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently done so, contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy at any time. When we do, we will revise the date at the top of this page. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
10. Contact
Questions, access requests, or concerns? Reach us at [email protected]. We aim to respond to all privacy-related inquiries within 5 business days.