Privacy Policy

Last updated: September 2026

Overview

Camilleri Creations ("we", "us", "our") builds and operates mobile applications. This privacy policy explains how we collect, use, and protect information across all of our apps.

We believe in privacy by design. Our apps collect the minimum data necessary to function, store data locally on your device wherever possible, and never sell your personal information to third parties.

How to read this policy: the sections below describe our apps in general, and individual apps differ in what they collect. Where an app-specific section (for example, ADHD Morning Routine or FamilyHub) conflicts with the general text, the app-specific section applies for that app.

What We Collect

Data stored locally on your device

Most of our apps store data primarily on your device. This includes:

Data stored in the cloud (Firebase)

Some apps use Google Firebase to enable features like family sharing, multi-device sync, or coach/team management. When cloud storage is used, we may store:

Data we never collect

Our apps do not access your device location. FamilyHub offers optional email scanning for calendar events; this is off until you turn it on, and is fully described in the FamilyHub — Email & Wellness Data section below.

App-Specific Data Handling

App Storage Account Required Special Permissions
ADHD Morning Routine (details) Local by default; Firebase only if a Family Group is used No account (anonymous). iOS-only optional email backup Notifications
LionTrack (details) Firebase (team data) Yes (coach account) Camera & photos (optional), Microphone (optional, safeguarding), Notifications
StudyTrack Local + Firebase (selective sync: sessions, scores, schedules, settings) Yes Notifications, AI (Gemini default; BYOK multi-provider)
FamilyHub Firebase (family data) Yes Calendar, Notifications, Email scanning (optional, read-only)
Odyssey Local + Firebase Yes HealthKit (distance, vitals)
FirstSolo Firebase (progress & squadron) Yes Notifications
Provenance Firebase + on-device processing Yes Notifications
Fancy That Firebase (couple sync) Yes Photos (optional), Notifications

ADHD Morning Routine — What We Collect

ADHD Morning Routine is a guided morning-routine app designed for children (and adults) with ADHD. It is built to work with as little data leaving your device as possible, and this section describes exactly what it does — which overrides the more general descriptions above where they differ.

Stored only on your device

By default, everything the app creates stays on the device and is never uploaded:

No account, no sign-in details (Android)

On Android, the app does not ask for an email address, password, or any sign-in details, and there is no account to create. To make family sharing work, the app uses an anonymous Firebase identifier that is generated automatically on the device — it is not linked to your name, email, or any personal profile.

On iOS only, an optional "Link Email" feature lets a parent add an email and password so a child's stats can be backed up and recovered. This is entirely optional and is the only place an email is ever collected; it is not present on Android.

What is shared when you use a Family Group

Family sharing (the "Family Race") is optional. It only sends data to the cloud (Google Firebase) if you choose to create or join a family group. When you do, the following is stored in Firebase and made visible to the other members of your family group only:

This information is only visible to members of the same family group. It is never public, never sold, and never used for advertising. Names are entered by whoever sets up the profiles (normally a parent or guardian), and you can use non-identifying labels if you prefer.

Crash reporting is off by default

Because this app is intended for children, crash and diagnostics reporting (Firebase Crashlytics) is turned off by default. Nothing is sent unless an adult explicitly turns on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device.

What ADHD Morning Routine never collects

Children's data and deleting it

The names and routine progress described above may relate to children. They are entered under the control of a parent or guardian, are only shared within your own family group, and can be removed at any time. You can delete everything — all profiles on the device, your family-group data in the cloud, and the anonymous identifier — from Settings → Delete All My Data, or by contacting us to request deletion.

Third-Party Services

Our apps may use the following third-party services:

Crash Reporting & Diagnostics

To keep our apps stable and fix problems quickly, we use Firebase Crashlytics (a Google service) for crash and error reporting. When an app crashes or records a handled error, Crashlytics sends us a diagnostic report.

What crash reports contain

What crash reports do not contain

How we use it

Which apps use it

Crash reporting via Crashlytics is used across our Firebase-backed apps, including FamilyHub, StudyTrack, LionTrack, Odyssey, FirstSolo, ADHD Morning Routine, and Fancy That. Apps that store all data on-device and do not use Firebase do not include crash reporting.

In our apps that are used by children — FamilyHub, LionTrack, StudyTrack, and ADHD Morning Routine — crash reporting is opt-in and off by default: nothing is collected unless you turn on "Share crash reports" in Settings → Privacy.

StudyTrack — AI Data Processing

StudyTrack uses AI (Google Gemini by default) to provide revision suggestions based on your academic performance. This section explains exactly what data is involved and how it flows.

What data is sent to the AI provider

When AI features generate a revision suggestion, the app sends an anonymised performance context containing only:

Not sent: your name, email address, study notes, free-text content, or any personally identifiable information. The data models are explicitly designed as anonymised structures to enforce this boundary.

Cross-device sync

StudyTrack offers selective cloud sync for premium users via Firebase Firestore. Exactly four collections are synced:

Data is stored under your user account and propagated across devices via real-time listeners. Conflict resolution uses a last-modified-wins strategy.

Not synced: BYOK API keys, local caches, AI call history, rate limit counters, or device-specific notification tokens.

BYOK (Bring Your Own Key)

StudyTrack supports a "Bring Your Own Key" mode that lets you connect your own AI provider. Supported providers include Google Gemini, Claude, ChatGPT, and Copilot.

Third-party data sharing

The following table summarises what data is shared with each third-party service:

No behavioural analytics SDK is used in StudyTrack. There is no Firebase Analytics or any advertising/behavioural profiling. StudyTrack can use Firebase Crashlytics for crash and stability diagnostics, but this is opt-in and off by default — nothing is collected unless you turn on "Share crash reports" in Settings → Privacy. When enabled it collects technical crash data only (never your study content or personal data), and it is always disabled in development builds.

Data retention (AI)

AI-generated revision suggestions are cached locally on your device. If you are a premium user with sync enabled, suggestions may be included as part of your synced data. Deleting your account removes all cloud-stored data. Local data is removed when you uninstall the app.

Crash reporting is off by default

Crash and diagnostics reporting (Firebase Crashlytics) in StudyTrack is opt-in and turned off by default. Nothing is sent unless you turn on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain your name, email, study data, or the content you create — see the Crash Reporting & Diagnostics section above.

Account, deletion, and your data

You can export your StudyTrack data or delete your account at any time from Settings → Privacy & Account. Account deletion removes your cloud-stored data within 30 days; data exports are provided in a machine-readable (JSON) format. Third-party data sharing is off unless you enable it.

FamilyHub — Email & Wellness Data

FamilyHub is an ADHD-friendly family organiser. In addition to the data described in the general sections above, it offers an optional email-scanning feature for calendar events. It is turned off by default, requires your explicit in-app consent before access is requested, and can be disabled at any time. This section discloses exactly how FamilyHub accesses, collects, uses, and shares this data.

Location (place labels only — no device location)

FamilyHub does not access, collect, track, or monitor your device's location on any platform. It requests no location permissions and includes no GPS, geofencing, or background-location features.

When you attach a place to a task, event, or reminder, you type a place name and pick a matching result from a text search. FamilyHub stores that place only as a descriptive label (a name and coordinates you selected) so it can show a static map preview or open the address in your maps app. This is reference information you enter — it is never derived from where your device actually is.

Email scanning (optional)

If you enable email scanning, FamilyHub reads your inbox in read-only mode to detect event invitations and ICS calendar attachments, then suggests matching events for your calendar.

Health & wellness data

FamilyHub includes wellness features: mood check-ins, symptom logging (such as brain fog, hot flushes, and sleep quality), guided breathing exercises, and focus timers. You can export your symptom data as CSV or PDF to share with a healthcare provider. This data is created by you, used for your own personal tracking, stored with your family data in Firebase, and is never sold or shared with third parties for advertising.

Crash reporting is off by default

Because FamilyHub is a family app that may be used by children, crash and diagnostics reporting (Firebase Crashlytics) is opt-in and turned off by default. Nothing is sent unless you turn on "Share Crash & Diagnostics Reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain your name, account details, or the content you create — see the Crash Reporting & Diagnostics section below.

What FamilyHub shares with third parties

FamilyHub contains no advertising SDKs, does not use your device location, and does not sell personal data. You can delete all your FamilyHub data at any time from Settings → Privacy → Delete All My Data.

LionTrack — What We Collect

LionTrack is a grassroots youth-football management app for coaches, parents, and players. Because players are children, we deliberately keep the data we collect to the minimum needed to run a team. This section describes exactly what LionTrack does and overrides the more general descriptions above where they differ.

Account and identity

A coach account is required to use LionTrack. When you create or sign in to an account we collect:

Team and player data

Coaches create players and record football activity. This is stored in Firebase (Firestore/Storage) and is only visible to authorised members of that team:

We do not collect a player's date of birth or age, and we do not store medical notes about players.

Safeguarding reports

LionTrack includes an FA-aligned safeguarding feature that lets an authorised coach record a welfare concern (a category, free-text notes, and an optional voice recording). Because this can be sensitive information about a child, it is stored securely in Firebase and is restricted to authorised safeguarding roles. It is only created when a coach chooses to report a concern.

Microphone: recording a voice note requires microphone permission. LionTrack only requests microphone access at the point you choose to attach a recording to a safeguarding concern, and the microphone is used for nothing else in the app. You can decline or revoke this permission in your device settings; doing so simply means you cannot attach a voice note.

Retention and deletion of safeguarding data: because safeguarding records (including any voice recording, category, and notes) are special-category data about a child, they are retained only for as long as needed for the welfare purpose for which they were created and are then deleted. Authorised safeguarding roles can delete a concern and its recording from within the app, and you can also request deletion by contacting us. When a concern is deleted, its voice recording is removed from Firebase Storage.

Notifications and subscriptions

Crash reporting is off by default

Because LionTrack is used by children, crash and diagnostics reporting (Firebase Crashlytics) is turned off by default and is opt-in. Nothing is sent unless a user turns on "Share crash reports" in Settings → Privacy. When it is off, no crash or diagnostic data leaves the device. Crash reports never contain names, team content, or the photos and recordings you create — see the Crash Reporting section below.

Location

LionTrack does not request location permissions and does not collect, store, or transmit GPS coordinates. Match venues are entered manually as text, and match weather is chosen manually by the coach.

What LionTrack never collects

Deleting your data

You can delete your account and its associated data from within the app (Settings → Account) or by contacting us. Deletion removes your account and profile data; team media and records are removed in line with the retention and deletion process described below.

Children's Privacy

Several of our apps are designed for use by children (ADHD Morning Routine, LionTrack, FirstSolo, StudyTrack). We take extra care with data involving minors:

Data Security

We take the security of your data seriously:

Your Rights

You have the right to:

To exercise any of these rights, contact us at camillericreations@icloud.com. We will respond within 30 days.

Data Retention

We retain your data only for as long as your account is active or as needed to provide our services. If you delete your account:

GDPR Compliance (EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your data under the following legal bases:

Data is processed within the EEA/UK where possible. Where data is transferred to the US (via Firebase/Google Cloud), it is protected under Google's Standard Contractual Clauses.

Changes to This Policy

We may update this privacy policy from time to time. When we make significant changes, we will notify users via an in-app notification or update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically.

Contact

If you have any questions about this privacy policy or our data practices, please contact us:

Camilleri Creations
Email: camillericreations@icloud.com