Privacy Policy
Last updated: September 2026
Overview
Camilleri Creations ("we", "us", "our") builds and operates mobile applications. This privacy policy explains how we collect, use, and protect information across all of our apps.
We believe in privacy by design. Our apps collect the minimum data necessary to function, store data locally on your device wherever possible, and never sell your personal information to third parties.
How to read this policy: the sections below describe our apps in general, and individual apps differ in what they collect. Where an app-specific section (for example, ADHD Morning Routine or FamilyHub) conflicts with the general text, the app-specific section applies for that app.
What We Collect
Data stored locally on your device
Most of our apps store data primarily on your device. This includes:
- Routine configurations, task lists, and preferences
- Progress data (scores, streaks, XP, badges)
- Calendar events and reminders
- Health and fitness data (read from Apple HealthKit with your permission — never uploaded to our servers)
Data stored in the cloud (Firebase)
Some apps use Google Firebase to enable features like family sharing, multi-device sync, or coach/team management. When cloud storage is used, we may store:
- Account information (email address or Apple ID identifier for authentication)
- User-generated content (team rosters, match stats, study records, family events)
- Subscription status (managed by Apple/Google, we only see entitlement status)
Data we never collect
- We do not access your contacts
- We do not use advertising SDKs or sell data to advertisers
- We do not create behavioural profiles for marketing
Our apps do not access your device location. FamilyHub offers optional email scanning for calendar events; this is off until you turn it on, and is fully described in the FamilyHub — Email & Wellness Data section below.
App-Specific Data Handling
| App | Storage | Account Required | Special Permissions |
|---|---|---|---|
| ADHD Morning Routine (details) | Local by default; Firebase only if a Family Group is used | No account (anonymous). iOS-only optional email backup | Notifications |
| LionTrack (details) | Firebase (team data) | Yes (coach account) | Camera & photos (optional), Microphone (optional, safeguarding), Notifications |
| StudyTrack | Local + Firebase (selective sync: sessions, scores, schedules, settings) | Yes | Notifications, AI (Gemini default; BYOK multi-provider) |
| FamilyHub | Firebase (family data) | Yes | Calendar, Notifications, Email scanning (optional, read-only) |
| Odyssey | Local + Firebase | Yes | HealthKit (distance, vitals) |
| FirstSolo | Firebase (progress & squadron) | Yes | Notifications |
| Provenance | Firebase + on-device processing | Yes | Notifications |
| Fancy That | Firebase (couple sync) | Yes | Photos (optional), Notifications |
ADHD Morning Routine — What We Collect
ADHD Morning Routine is a guided morning-routine app designed for children (and adults) with ADHD. It is built to work with as little data leaving your device as possible, and this section describes exactly what it does — which overrides the more general descriptions above where they differ.
Stored only on your device
By default, everything the app creates stays on the device and is never uploaded:
- Profiles (the name label and avatar you choose for each family member)
- Routines, tasks, timers, and schedules
- Progress, streaks, points, badges, and unlocked avatars
- App preferences and alarm settings
No account, no sign-in details (Android)
On Android, the app does not ask for an email address, password, or any sign-in details, and there is no account to create. To make family sharing work, the app uses an anonymous Firebase identifier that is generated automatically on the device — it is not linked to your name, email, or any personal profile.
On iOS only, an optional "Link Email" feature lets a parent add an email and password so a child's stats can be backed up and recovered. This is entirely optional and is the only place an email is ever collected; it is not present on Android.
What is shared when you use a Family Group
Family sharing (the "Family Race") is optional. It only sends data to the cloud (Google Firebase) if you choose to create or join a family group. When you do, the following is stored in Firebase and made visible to the other members of your family group only:
- The profile name label you entered (this can be a first name, a nickname, or any label you like — you choose what to type)
- The chosen avatar (a built-in character, never a photo)
- Routine progress for the race (how many tasks are done, and whether a routine is active or finished)
- Optionally, a routine you choose to share with the group (its name, tasks, and schedule)
This information is only visible to members of the same family group. It is never public, never sold, and never used for advertising. Names are entered by whoever sets up the profiles (normally a parent or guardian), and you can use non-identifying labels if you prefer.
Crash reporting is off by default
Because this app is intended for children, crash and diagnostics reporting (Firebase Crashlytics) is turned off by default. Nothing is sent unless an adult explicitly turns on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device.
What ADHD Morning Routine never collects
- No location, contacts, photos, microphone, or phone number
- No advertising identifiers and no ad SDKs
- No behavioural analytics (Firebase Analytics is disabled)
- No purchases or subscription data
- No date of birth or age (the app performs no age screening)
Children's data and deleting it
The names and routine progress described above may relate to children. They are entered under the control of a parent or guardian, are only shared within your own family group, and can be removed at any time. You can delete everything — all profiles on the device, your family-group data in the cloud, and the anonymous identifier — from Settings → Delete All My Data, or by contacting us to request deletion.
Third-Party Services
Our apps may use the following third-party services:
- Firebase (Google) — Authentication, database, cloud functions, and analytics. Firebase Privacy Policy
- Firebase Crashlytics (Google) — Crash and stability reporting. Collects diagnostic data (stack traces, device model, OS version, and an anonymous installation identifier) when the app crashes or logs a non-fatal error, so we can find and fix bugs. It does not collect the content you create or your personal profile data. See the Crash Reporting section below. Firebase Privacy Policy
- Apple HealthKit — Read-only access to health data. Data is never uploaded to external servers. Apple Privacy Policy
- RevenueCat — Subscription management. Processes purchase receipts only. RevenueCat Privacy Policy
- AI APIs (Claude, ChatGPT, Gemini) — Used in Fancy That for content generation. Couple profile data is sent to generate personalised content. No conversation data is stored by us beyond delivery.
- Google Gemini API — Used in StudyTrack for AI-powered revision suggestions. Only anonymised performance data (subject IDs, topic IDs, scores, timestamps) is sent — no PII. When using BYOK mode, requests route directly to the user's chosen provider (Gemini, Claude, ChatGPT, or Copilot) via their personal API key. See the StudyTrack AI section below for full details.
Crash Reporting & Diagnostics
To keep our apps stable and fix problems quickly, we use Firebase Crashlytics (a Google service) for crash and error reporting. When an app crashes or records a handled error, Crashlytics sends us a diagnostic report.
What crash reports contain
- The stack trace and error type that caused the crash
- Device model, operating system version, and app version
- Whether the device was rooted/jailbroken, available memory, and orientation at the time
- An anonymous, Crashlytics-generated installation identifier (not linked to your name or email)
What crash reports do not contain
- Your name, email address, or account credentials
- The content you create (tasks, routines, study notes, journal/couple content, team data, etc.)
- Location, contacts, messages, or photos
How we use it
- Crash and diagnostic data is used solely to diagnose and fix bugs and improve app stability.
- Collection is disabled in development/debug builds so testing does not pollute production data.
- We do not use crash data for advertising or to build marketing profiles.
Which apps use it
Crash reporting via Crashlytics is used across our Firebase-backed apps, including FamilyHub, StudyTrack, LionTrack, Odyssey, FirstSolo, ADHD Morning Routine, and Fancy That. Apps that store all data on-device and do not use Firebase do not include crash reporting.
In our apps that are used by children — FamilyHub, LionTrack, StudyTrack, and ADHD Morning Routine — crash reporting is opt-in and off by default: nothing is collected unless you turn on "Share crash reports" in Settings → Privacy.
StudyTrack — AI Data Processing
StudyTrack uses AI (Google Gemini by default) to provide revision suggestions based on your academic performance. This section explains exactly what data is involved and how it flows.
What data is sent to the AI provider
When AI features generate a revision suggestion, the app sends an anonymised performance context containing only:
- Subject identifiers (opaque IDs such as "maths" — not display names you have set)
- Topic identifiers (internal IDs, not human-readable titles)
- Recent scores: topic ID, percentage, and UTC date
- A fixed system prompt requesting a focused revision suggestion
Not sent: your name, email address, study notes, free-text content, or any personally identifiable information. The data models are explicitly designed as anonymised structures to enforce this boundary.
Cross-device sync
StudyTrack offers selective cloud sync for premium users via Firebase Firestore. Exactly four collections are synced:
- Study sessions
- Scores
- Revision schedules
- Settings
Data is stored under your user account and propagated across devices via real-time listeners. Conflict resolution uses a last-modified-wins strategy.
Not synced: BYOK API keys, local caches, AI call history, rate limit counters, or device-specific notification tokens.
BYOK (Bring Your Own Key)
StudyTrack supports a "Bring Your Own Key" mode that lets you connect your own AI provider. Supported providers include Google Gemini, Claude, ChatGPT, and Copilot.
- Your API key is stored in encrypted platform secure storage (Android Keystore / iOS Keychain) — device-only, never synced to the cloud
- Only provider metadata (name, validity flag, timestamp) is stored locally for fast lookups — never the key itself
- When BYOK is configured, all AI requests route exclusively to your chosen provider — there is no silent fallback to our default key
- BYOK users bypass the standard rate limit (5 requests/day for premium users)
- Deleting a BYOK key clears both secure storage and metadata, reverting you to your tier's default behaviour (premium = rate-limited Gemini, free = no AI access)
Third-party data sharing
The following table summarises what data is shared with each third-party service:
- Gemini (default, premium users) — Anonymised scores, topic IDs, and timestamps only. No PII.
- BYOK provider (Claude/ChatGPT/Gemini/Copilot) — The same anonymised data, routed directly to your chosen provider using your personal API key
- Firebase Firestore — Study sessions, scores, revision schedules, and settings (premium sync only)
- Firebase Auth — Authentication credentials and email address
- RevenueCat — Purchase/entitlement state and an anonymous user ID (no study data)
- Firebase Messaging — Push notification device tokens
- Firebase Crashlytics — Crash and error diagnostics only, and only if you opt in (off by default; see the Crash Reporting section below). No behavioural analytics.
No behavioural analytics SDK is used in StudyTrack. There is no Firebase Analytics or any advertising/behavioural profiling. StudyTrack can use Firebase Crashlytics for crash and stability diagnostics, but this is opt-in and off by default — nothing is collected unless you turn on "Share crash reports" in Settings → Privacy. When enabled it collects technical crash data only (never your study content or personal data), and it is always disabled in development builds.
Data retention (AI)
AI-generated revision suggestions are cached locally on your device. If you are a premium user with sync enabled, suggestions may be included as part of your synced data. Deleting your account removes all cloud-stored data. Local data is removed when you uninstall the app.
Crash reporting is off by default
Crash and diagnostics reporting (Firebase Crashlytics) in StudyTrack is opt-in and turned off by default. Nothing is sent unless you turn on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain your name, email, study data, or the content you create — see the Crash Reporting & Diagnostics section above.
Account, deletion, and your data
You can export your StudyTrack data or delete your account at any time from Settings → Privacy & Account. Account deletion removes your cloud-stored data within 30 days; data exports are provided in a machine-readable (JSON) format. Third-party data sharing is off unless you enable it.
FamilyHub — Email & Wellness Data
FamilyHub is an ADHD-friendly family organiser. In addition to the data described in the general sections above, it offers an optional email-scanning feature for calendar events. It is turned off by default, requires your explicit in-app consent before access is requested, and can be disabled at any time. This section discloses exactly how FamilyHub accesses, collects, uses, and shares this data.
Location (place labels only — no device location)
FamilyHub does not access, collect, track, or monitor your device's location on any platform. It requests no location permissions and includes no GPS, geofencing, or background-location features.
When you attach a place to a task, event, or reminder, you type a place name and pick a matching result from a text search. FamilyHub stores that place only as a descriptive label (a name and coordinates you selected) so it can show a static map preview or open the address in your maps app. This is reference information you enter — it is never derived from where your device actually is.
Email scanning (optional)
If you enable email scanning, FamilyHub reads your inbox in read-only mode to detect event invitations and ICS calendar attachments, then suggests matching events for your calendar.
- Access uses the Gmail API or Microsoft Graph API in read-only scope, and requires your explicit consent.
- We extract only event details (title, date, time, and location) needed to suggest an event.
- Email content is processed in memory and is never stored on our servers.
- You can disable email scanning and revoke access at any time in the app settings or your Google/Microsoft account.
Health & wellness data
FamilyHub includes wellness features: mood check-ins, symptom logging (such as brain fog, hot flushes, and sleep quality), guided breathing exercises, and focus timers. You can export your symptom data as CSV or PDF to share with a healthcare provider. This data is created by you, used for your own personal tracking, stored with your family data in Firebase, and is never sold or shared with third parties for advertising.
Crash reporting is off by default
Because FamilyHub is a family app that may be used by children, crash and diagnostics reporting (Firebase Crashlytics) is opt-in and turned off by default. Nothing is sent unless you turn on "Share Crash & Diagnostics Reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain your name, account details, or the content you create — see the Crash Reporting & Diagnostics section below.
What FamilyHub shares with third parties
- Firebase (Firestore, Auth, Cloud Messaging): Account, family, task, calendar, meal, and wellness data (including any place labels you enter) for sync and notifications.
- Google Calendar API / Microsoft Graph API: Read-only calendar sync and, if enabled, email scanning.
- Firebase Crashlytics: Crash and diagnostics data — only if you opt in (off by default).
FamilyHub contains no advertising SDKs, does not use your device location, and does not sell personal data. You can delete all your FamilyHub data at any time from Settings → Privacy → Delete All My Data.
LionTrack — What We Collect
LionTrack is a grassroots youth-football management app for coaches, parents, and players. Because players are children, we deliberately keep the data we collect to the minimum needed to run a team. This section describes exactly what LionTrack does and overrides the more general descriptions above where they differ.
Account and identity
A coach account is required to use LionTrack. When you create or sign in to an account we collect:
- Your email address and a display name, via Firebase Authentication (email/password, Sign in with Apple, or Google Sign-In)
- An account user ID used to store and secure your team's data
Team and player data
Coaches create players and record football activity. This is stored in Firebase (Firestore/Storage) and is only visible to authorised members of that team:
- Player name label and shirt number (the name is entered by the coach and can be a first name or nickname)
- Playing positions, match and training statistics, attendance, badges, and awards
- Optional player and team photos uploaded by the coach (camera or photo library)
- Optional match weather — the coach taps a weather icon (sunny, cloudy, rain, etc.) when starting a match. This is entered manually and stored with the match; LionTrack does not use your device location or GPS to determine weather
We do not collect a player's date of birth or age, and we do not store medical notes about players.
Safeguarding reports
LionTrack includes an FA-aligned safeguarding feature that lets an authorised coach record a welfare concern (a category, free-text notes, and an optional voice recording). Because this can be sensitive information about a child, it is stored securely in Firebase and is restricted to authorised safeguarding roles. It is only created when a coach chooses to report a concern.
Microphone: recording a voice note requires microphone permission. LionTrack only requests microphone access at the point you choose to attach a recording to a safeguarding concern, and the microphone is used for nothing else in the app. You can decline or revoke this permission in your device settings; doing so simply means you cannot attach a voice note.
Retention and deletion of safeguarding data: because safeguarding records (including any voice recording, category, and notes) are special-category data about a child, they are retained only for as long as needed for the welfare purpose for which they were created and are then deleted. Authorised safeguarding roles can delete a concern and its recording from within the app, and you can also request deletion by contacting us. When a concern is deleted, its voice recording is removed from Firebase Storage.
Notifications and subscriptions
- Push notifications: LionTrack registers a Firebase Cloud Messaging (FCM) device token so it can send match and team notifications. The token identifies the device install, not you personally, and no message content is collected from you.
- Subscriptions: Paid plans are handled by RevenueCat and the App Store / Google Play. LionTrack only sees your entitlement status (which plan is active), never your card details.
Crash reporting is off by default
Because LionTrack is used by children, crash and diagnostics reporting (Firebase Crashlytics) is turned off by default and is opt-in. Nothing is sent unless a user turns on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain names, team content, or the photos and recordings you create — see the Crash Reporting section below.
Location
LionTrack does not request location permissions and does not collect, store, or transmit GPS coordinates. Match venues are entered manually as text, and match weather is chosen manually by the coach.
What LionTrack never collects
- No device location or GPS
- No player date of birth, age, or medical notes
- No advertising identifiers and no ad SDKs
- No behavioural analytics (Firebase Analytics is not used)
- No in-app messaging between adults and children
Deleting your data
You can delete your account and its associated data from within the app (Settings → Account) or by contacting us. Deletion removes your account and profile data; team media and records are removed in line with the retention and deletion process described below.
Children's Privacy
Several of our apps are designed for use by children (ADHD Morning Routine, LionTrack, FirstSolo, StudyTrack). We take extra care with data involving minors:
- Our apps are set up and controlled by a parent or guardian, who creates the profiles and decides whether to enable any sharing feature
- We minimise what we collect from children: profiles, routines, and progress are stored on the device by default, and only a name label, avatar, and routine progress are shared — and only within your own family unit — when a parent chooses to use family sharing
- The name used for a profile is free text chosen by the parent/guardian, who may use a non-identifying label
- Child profiles and data are never public and are never shared outside the family/team unit, and are never used for advertising or behavioural profiling
- Photos of minors (in LionTrack) are stored in Firebase Storage with per-coach quotas and are only visible to authorised team members
- A parent or guardian can delete all of a child's data at any time (in ADHD Morning Routine via Settings → Delete All My Data) or by contacting us
- We aim to comply with COPPA (Children's Online Privacy Protection Act) and the UK AADC (Age Appropriate Design Code). For questions or to exercise any rights over a child's data, contact us at the address below
Data Security
We take the security of your data seriously:
- All data transmitted between your device and Firebase is encrypted in transit (TLS/SSL)
- Data at rest in Firebase is encrypted using Google's standard encryption
- Authentication uses Firebase Auth with support for Sign in with Apple and Google Sign-In
- Firestore Security Rules enforce per-user data access — users can only read/write their own data
- Sensitive features (Fancy That, Provenance) support device-level biometric authentication (Face ID / Touch ID)
Your Rights
You have the right to:
- Access — Request a copy of the data we hold about you
- Correction — Ask us to correct inaccurate data
- Deletion — Request full deletion of your account and associated data
- Portability — Request your data in a machine-readable format
- Withdraw consent — Revoke permissions (e.g., HealthKit) at any time via device settings
To exercise any of these rights, contact us at camillericreations@icloud.com. We will respond within 30 days.
Data Retention
We retain your data only for as long as your account is active or as needed to provide our services. If you delete your account:
- Account data is deleted from Firebase within 30 days
- Locally stored data is removed when you uninstall the app
- Anonymised, aggregated analytics data may be retained (it cannot identify you)
GDPR Compliance (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your data under the following legal bases:
- Consent — For optional features like HealthKit access, push notifications, and opt-in crash reporting
- Contract — To provide the service you signed up for (e.g., storing your team data in LionTrack)
- Legitimate interest — For crash and stability diagnostics, only where you have opted in. We do not use behavioural analytics.
- Substantial public interest / safeguarding — For LionTrack safeguarding records (a special category of data concerning a child's welfare), we rely on the safeguarding condition for processing special-category data under UK GDPR Article 9(2)(g) and the Data Protection Act 2018 (protecting an individual from neglect or physical, mental, or emotional harm). This data is restricted to authorised safeguarding roles.
Data is processed within the EEA/UK where possible. Where data is transferred to the US (via Firebase/Google Cloud), it is protected under Google's Standard Contractual Clauses.
Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will notify users via an in-app notification or update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically.
Contact
If you have any questions about this privacy policy or our data practices, please contact us:
Camilleri Creations
Email: camillericreations@icloud.com