REDLANE Guide Privacy Notice
Effective date: 6 October 2026. This notice covers the REDLANE Guide Android utility and its account, purchase, support and rights services. It does not replace the separate redlane.xyz website/waitlist notice or describe future REDLANE AI or memory products.
Controller and contact
Calvin Promotions Sàrl, Chemin des Ceps 34, 1217 Meyrin, Geneva, Switzerland is the operator and controller. Contact support@redlane.xyz for support, privacy requests, correction, deletion, objections or complaints. Where available, you may complain to the Swiss FDPIC or your competent local supervisory authority.
Data used to operate Guide
Google or email-link sign-in supplies an email address, Firebase user/provider identifiers, verification and authentication records; Google may supply profile name/photo. These support account management and secure sign-in. We do not receive your Google password.
Account data includes Terms acceptance, trial and access state. Google Play purchase data includes product, purchase token, transaction references, verification, acknowledgement and ownership history. It supports purchase verification, Restore, recovery and fraud prevention. We do not receive full payment-card details; Google Play processes payments under its own arrangements.
Firebase Auth, App Check/Play Integrity and the backend process connection/security information such as IP address, app/device metadata, attestation tokens, request time and result. Web account actions additionally use reCAPTCHA Enterprise. These are security and functionality processing, not optional product analytics.
Support and account-rights requests can contain your email address and the message/details you provide. Avoid sending passwords, raw purchase tokens, payment-card details or sensitive reading material. We use these messages to answer your request and verify ownership where necessary.
Guide preferences and detailed reading-rhythm counters are stored on your device, not automatically synced. Counters measure Guide use, not comprehension or reading content. Guide does not read text in other apps, capture reading screenshots, record browsing URLs, or request contacts, precise location, camera, microphone or Accessibility Service access.
Optional services
Optional Analytics collection and marketing are off in this edition, even if an older preference was saved. Crashlytics is absent from the commercial release. Feedback and bug reports are optional, user-initiated support messages. When you submit the form, the Guide backend sends the category, subject/message, optional reply email and disclosed app version to support@redlane.xyz through the existing Infomaniak-hosted support mailbox. Authentication and native App Check protect this route. The backend does not automatically add your Firebase UID, purchase receipt or reading content to the outgoing message. Web3Forms is not used for this delivery or current account sign-in links. No advertising or sale of personal data is part of Guide.
Purposes and rights
Necessary account, trial, purchase and requested support processing supports the service you request. Proportionate security and abuse prevention protect users and the service; relevant transaction records may also be needed for applicable accounting duties and legal claims. Where GDPR applies, these purposes rely as appropriate on contract/pre-contract steps, legitimate interests and legal obligations; optional future processing requiring consent will not be bundled into Terms acceptance. Applicable local privacy and consumer rights remain intact. Automated purchase checks can be reviewed by a person through support.
Guide is offered only to people aged 18 and over. Google Play is configured to restrict users it determines to be minors; this may not identify every minor. The app checks available Play age and approval signals before account onboarding, Terms acceptance, live Guide activation and new purchases. When age sharing is unavailable outside mandatory-verification regions, the app relies on the explicit 18+ declaration; it does not describe this as independently verified age. A known below-minimum or verification restriction cannot be cleared by declining sharing. Parent approval does not make an under-18 person eligible. Contact support if an under-18 account or an incorrect age restriction is reported. Privacy, deletion and legitimate purchase-recovery rights remain available regardless of age.
Age eligibility information
Google Play supplies an age range and related approval or verification status where available. REDLANE does not receive an exact birth date or identity document through this integration. The age range, its source and Play installation identifier are not stored or sent to the REDLANE backend. Only a confirmed eligibility restriction reason is stored in encrypted local app storage. The account stores the 18+ Terms declaration, notice version and acceptance time; this is not a verified birth date. These data are used only for eligibility and legal compliance, not advertising, analytics, profiling or marketing.
Providers and international processing
Google Firebase/Google Cloud provides authentication, Firestore, Hosting, backend operations and app security. The operational Firestore database is in europe-west6 (Zurich); this does not mean all Google processing, support or backups are confined to Switzerland. Google Play and Google sign-in also operate under Google's own terms and privacy information.
Infomaniak Network SA, Geneva, Switzerland, hosts support@redlane.xyz and processes support correspondence on our instructions under its Mail Service terms and incorporated Data Processing Agreement. Its Mail Service terms locate hosted mail data in Switzerland. Messages can also pass through the mail providers used by their senders or recipients. This does not make Google services or every email transmission Switzerland-only.
Data can also be disclosed when required by applicable law or necessary to establish/defend claims, limited to what is justified. We do not use account creation or a purchase as consent for advertising or unrelated marketing.
Retention and deletion
Account/profile, Terms and trial data remain while the account exists. A confirmed deletion request enters a retryable queue; sign-out is immediate but backend erasure is asynchronous. The workflow removes Firebase Auth and associated account, Terms/trial, rights, consent and validation bindings. Provider/mailbox checks are recorded separately; completion is not claimed while they remain pending. This workflow was validated with an unowned test account.
If purchases exist, restricted purchase evidence is retained for legitimate ownership/Restore, fraud prevention, accounting or claims. Ordinary UID linkage is cleared and a keyed deleted-owner association is retained for proof-reviewed recovery. Purchase tokens/order evidence remain personal/pseudonymous information, not anonymous data. Deletion does not automatically refund, revoke or consume a Google Play purchase. Re-registration does not by itself prove ownership; contact support for verified recovery of a legitimate purchase rather than buying it again.
Deletion-job UID and token-hash fields are cleared after account removal. Contact email is retained only until the required provider/mailbox review is completed, then cleared. A restricted deletion ledger retains the original Auth UID and deletion/job metadata to prevent erased accounts returning from older backups. It currently has no automatic expiry; it is retained pending verification that all relevant backup/export copies and replay needs have expired. The database backup lifetime is not an automatic ledger-deletion deadline. Necessary purchase/security/claims records have no blanket automatic expiry; retention is reviewed against their continuing purpose and applicable duties. Contact us for the exception applicable to a particular request.
Daily Firestore backups are configured with 35-day retention. Individual backups expire according to their schedule; deletion is not an immediate rewrite of existing backups. Restored data must be checked against the current deletion ledger before use.
The Cloud Logging _Default bucket retains logs for 30 days. The mandatory _Required audit bucket retains records for 400 days. These settings do not promise identical retention for every provider log or backup.
Rate-limit records, notification receipts and feedback deduplication receipts use their configured expiry/TTL. Notification receipt expiry is 30 days; feedback deduplication expiry is seven days; Firestore TTL removal is asynchronous. Purchase records are separate.
Ordinary closed support cases are subject to a 12-month retention policy, currently managed manually by the operator. Necessary legal/transaction/rights evidence can require longer retention for a documented purpose. Mail removed from the active support mailbox may remain in Infomaniak recovery backups for the lifecycle applicable to the Mail Service plan and service terms. Infomaniak documents daily mail backups. We do not promise immediate removal from provider backups. Recovery copies are not used to reopen a completed deletion request.
Local rhythm history is limited to approximately 400 days and pruned when the app runs the relevant activity checkpoint. Local reset removes the selected installation's statistics; other devices are not remotely wiped. Android app-data backup is disabled for this edition.
Exercise your rights
Use Account & Access → Delete account, or the web deletion flow without reinstalling. You will see a warning, confirm recent identity and explicitly confirm deletion. Keep the private status receipt to check progress after sign-out. Never post that receipt publicly. If you cannot authenticate, email support@redlane.xyz; we verify identity proportionately and do not routinely ask for identity documents. Export/correction and other rights requests are available through account controls or support. Account deletion is separate from a refund.