Privacy Policy
Privacy Policy
This Privacy Policy explains what the Quotify Android app
(package com.kovhan.quotify, published on Google Play by LumaDay)
collects, why, where it is stored, who else processes it, and how you can see it
removed. It covers the app itself and this website.
Developer: LumaDay
Contact: lumadaystudio@gmail.com
Effective: August 18, 2026
Last updated: August 18, 2026
1. Who is responsible for your data
Quotify is developed and published under the name LumaDay by an
independent individual developer. LumaDay is the data controller for the personal
data described here.
Contact for any privacy question, access request or deletion request:
lumadaystudio@gmail.com. There is no
separately appointed data protection officer; the developer answers these requests
personally.
2. Short summary
- Your quotes, folders, tags, authors, books and playlists are stored on your device first and, when you are signed in, mirrored to your own private area in Google Firestore.
- Nobody else can read your library: Firestore rules bind every document to your account identifier.
- We do not sell your data, we do not run advertising, and advertising identifiers are explicitly switched off in the app.
- Photos you scan and audio you dictate are processed to produce text; we do not store the photo or the audio.
- You can delete individual items yourself at any time, or delete the whole account from Profile - Edit profile - Delete account.
3. What we collect and process
3.1 Account data
- Firebase user ID (UID) - created for every user, including guests.
- Email address and the sign-in method, if you register with email and password or with Google Sign-In. Google Sign-In returns your email, display name and profile picture URL from your Google account.
- Whether the email address is verified, and whether the session is a guest (anonymous) session.
- Display name and username you enter yourself.
- Password: handled entirely by Firebase Authentication. The app never stores your password and the developer never sees it.
- Profile photo, if you upload one. See section 8 for where it is hosted.
3.2 Content you create
- Quote text, and the author, book, folder, tags, favorite flag, colors and icons you attach to it.
- Widget playlists you assemble from your own quotes.
- Creation and modification timestamps used for syncing.
Quote text is free-form. If you type personal or sensitive information into a quote, it
is stored the same way as any other quote - please keep that in mind.
3.3 Settings stored on the device
- Theme, app language, whether onboarding was completed.
- Whether the quote of the day is shown, and the reminder time you pick.
- Widget settings: quote source, style, refresh interval, whether the daily quote joins the rotation.
- Small flags that stop the app from repeating itself - whether a tooltip was dismissed, whether a review or feedback prompt was already shown, when a paywall or special offer was last displayed.
- A cached copy of your profile (UID, email, name, username, photo URL, guest flag) so the app can open instantly and work offline.
3.4 Subscription data
- Purchase token and product identifier issued by Google Play when you subscribe, your Firebase UID, and the resulting subscription state (active, canceled, in grace period, on hold, paused, expired) with its start and expiry dates.
- These are exchanged with our purchase-verification service (see section 8) so that Premium can be unlocked for your account and not for someone else's.
- We never receive your card number, bank details or billing address. Payment is handled entirely by Google Play.
3.5 AI usage counters
To enforce the daily and monthly AI limits, the app stores a per-month counter of AI
requests against your account. It records how many requests were made, not what they
contained.
3.6 Feedback you send
If you answer an in-app feedback prompt, we store your rating, your optional comment,
which screen the prompt came from, the timestamp and your Firebase UID.
3.7 Diagnostics
- Crash reports and non-fatal errors through Firebase Crashlytics: stack traces, app version, device model, OS version, and application log breadcrumbs.
- Basic app-usage and device information collected automatically by Google Analytics for Firebase, such as app opens and approximate region.
- Device-integrity signals through Firebase App Check with Google Play Integrity, used to block requests from tampered or automated clients.
4. What we do not collect
- No advertising identifier. Collection of the Android Advertising ID is removed from the app manifest and ad personalization signals are disabled.
- No advertising networks, no ad SDKs, no data brokers.
- No precise or coarse location, no contacts, no calendar, no SMS or call data.
- No access to your photo library beyond the single image you pick through the Android photo picker.
- We never sell or rent personal data, and we do not share it for other companies' marketing.
5. Why we process it, and on what legal basis
Where the EU/UK GDPR or comparable law applies, our legal bases are as follows.
6. Device permissions
Quotify asks for a permission only at the moment the related feature is used, and the
app keeps working if you decline.
- Camera - to show the viewfinder when you scan a printed page. No photo is saved to your gallery and no video is recorded.
- Microphone - to dictate a quote by voice. Recording stops as soon as you stop dictation.
- Notifications - declared for the quote reminders being introduced in the app. Android asks for it only if you enable reminders; declining it does not affect any other feature, and we never use notifications for advertising.
- Internet and network state - to sync, verify purchases and run AI features, and to tell whether you are offline.
- Run at startup - so the home-screen widget keeps rotating quotes after the device restarts.
- Billing - required by Google Play to offer in-app subscriptions.
Choosing an image from your device uses the Android photo picker, which hands the app
the one file you select without granting access to the rest of your gallery.
7. AI, camera and voice in detail
7.1 Scanning a page
When you scan, the captured image is sent over an encrypted connection to a Google
Gemini model through Firebase AI Logic. The model returns the transcribed text, which
the app shows you for editing before anything is saved. LumaDay does not store the
image; it is discarded after the request. Google processes the request as our
sub-processor under the Google APIs Terms of Service and the Gemini API terms.
7.2 Tag suggestions
Tag suggestions send the quote text you are editing to the same Gemini model and return
a list of proposed tags. Nothing is applied until you accept it.
7.3 Voice input
Dictation uses the speech recognition service built into Android. Depending on your
device and settings, the audio is processed on the device or by the Google speech
service configured on it. Quotify receives only the recognized text and never keeps
an audio file.
7.4 Accuracy
AI output can be wrong or incomplete. Always check the recognized text before saving.
Do not scan documents you are not allowed to reproduce.
8. Service providers and third parties
We use the following providers. Each processes data on our instructions or, where they
act as an independent controller, under their own policy.
A note about profile photos: an uploaded photo is stored by Cloudinary and referenced by
a public URL. Anyone who has that URL can open the image, so please do not upload a
picture you would not want reachable by link. Deleting the photo in the app, or deleting
your account, removes it from Cloudinary.
Firebase Cloud Messaging is bundled with the Firebase SDK and may register a device
token. We do not use it for marketing messages.
Beyond these providers, we disclose data only if we are legally required to, or where it
is necessary to establish or defend a legal claim.
9. International transfers
Our providers operate globally, so your data may be processed outside your country,
including in the United States and the European Union. Google and Cloudflare rely on
the European Commission's Standard Contractual Clauses and equivalent safeguards for
such transfers; those safeguards form part of the agreements we accepted when using
their platforms.
10. Where data is stored and for how long
- On your device - the full library in a local database, plus settings and the cached profile. Removed when you delete your account, sign out, clear the app storage, or uninstall the app.
- In Firestore - your library under a private path tied to your Firebase UID, kept for as long as your account exists.
- Diagnostics - retained by Firebase according to Google's own retention windows (crash data for a limited period, analytics for the retention window set for the project).
- Subscription records - kept while the subscription is active and afterwards for as long as accounting, tax and dispute-handling rules require.
- Feedback - kept while it is useful for improving the app. Ask us and we will delete yours.
11. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate - most of it you can edit directly in the app;
- delete your data, in the app or by asking us;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable, machine-readable form;
- withdraw consent at any time, without affecting processing that already happened;
- complain to your local data protection authority.
Write to lumadaystudio@gmail.com from the
email address linked to your account. We answer within 30 days. If we cannot safely
confirm that the request comes from the account holder, we may ask for more detail
before acting.
12. Deleting your data
- Individual items - delete a quote, folder, tag, author, book, playlist or profile photo directly in the app. See the Delete specific data page.
- The whole account - in the app go to Profile - Edit profile - Delete account and confirm. Details and the email route are on the Account and data deletion page.
- Local copy only - signing out clears the library cached on the device while your cloud data stays intact.
Deleting the account does not cancel a Google Play subscription. Cancel it in Google
Play first - see the Subscription Policy.
13. Children
Quotify is not directed at children. You must be at least 13 years old to use it, and at
least 16 in countries where that is the minimum age for consenting to online services
without a parent. We do not knowingly collect data from children below that age; if you
believe a child has created an account, contact us and we will delete it.
14. Changes to this policy
When the app changes, this policy changes with it. The date at the top always reflects
the current version. For material changes we will show a notice in the app or on this
page. Continuing to use Quotify after a change means you accept the updated policy.
Privacy questions, access requests and deletion requests:
lumadaystudio@gmail.com.