This Privacy Policy describes how PixMixy ("we," "us," or "our") collects, uses, stores, and protects your personal information when you use the PixMixy personal productivity and habit tracking application (the "Service"). By using PixMixy, you agree to the collection and use of information in accordance with this policy. We are committed to safeguarding your privacy and ensuring transparency in how your data is handled.
1. Information We Collect
We collect the following categories of information to provide and improve the Service:
Account Information
• Full name and display name
• Email address
• Account credentials (encrypted password hash or OAuth token)
• Profile picture (if provided via Google OAuth)
• Date of account creation
Usage Data & Content You Create
• Habit tracking logs (habit names, completion status, streaks, schedules)
• Fitness data (workouts, exercises, sets, reps, weights, personal records)
• Nutrition and meal entries (meal names, calorie counts, macronutrient data)
• Financial transaction records (amounts, categories, descriptions, budgets)
• Study session logs (subjects, durations, notes, exam schedules)
• Goals, milestones, and achievements
• Platform-wide progress and streaks
Device & Log Data
• IP address
• Browser type and version
• Device type and operating system
• Referring URLs and pages visited within the Service
• Date and time of access
• Session duration and interaction patterns (anonymized)
Cookies & Local Storage
• Authentication session tokens
• User interface preferences (theme, layout settings)
• We do not use third-party tracking cookies or advertising cookies
2. How We Use Your Information
Your information is used exclusively for the following purposes:
• Service Delivery: To operate, maintain, and provide the core features of PixMixy, including displaying your personal dashboard, tracking habits, logging fitness activities, managing nutrition entries, recording financial data, and organizing study sessions.
• Personalization: To customize your experience, including remembering your preferences, displaying relevant progress metrics, and tailoring the interface to your usage patterns.
• Progress Tracking: To calculate and display streaks, achievements, statistics, and progress toward your personal goals across all tracking categories.
• Analytics & Improvement: To analyze aggregated, anonymized usage patterns in order to improve the Service, fix bugs, and develop new features. We do not perform individual behavioral profiling for advertising purposes.
• Communication: To send you essential service-related notifications, including account verification, security alerts, and important policy updates. We do not send unsolicited marketing emails.
• Security: To detect and prevent fraud, unauthorized access, abuse, and other malicious activities, and to maintain the integrity and availability of the Service.
3. Legal Basis for Processing (GDPR)
For users located in the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK), we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):
• Consent (Article 6(1)(a)): Where you have given clear, affirmative consent for us to process your personal data for specific purposes, such as creating an account or enabling optional features. You may withdraw your consent at any time.
• Contractual Necessity (Article 6(1)(b)): Processing is necessary for the performance of the contract between you and PixMixy - i.e., to provide the Service you have signed up for, including storing your habit logs, fitness data, financial records, and other tracked information.
• Legitimate Interest (Article 6(1)(f)): We process certain data based on our legitimate interests, such as improving the Service, ensuring security, preventing fraud, and conducting anonymized analytics. We balance these interests against your rights and freedoms.
• Legal Obligation (Article 6(1)(c)): We may process your data where necessary to comply with a legal obligation, such as responding to lawful requests from public authorities or retaining records as required by applicable law.
4. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
• Active Accounts: Your data is retained for as long as your account remains active. All habit logs, fitness records, meal entries, financial data, study sessions, goals, and achievements are stored and accessible throughout the lifetime of your account.
• Deleted Accounts: When you delete your account, all personal data is permanently and irreversibly deleted from our primary systems within 30 days of the deletion request.
• Backup Copies: Residual copies of your data that may exist in encrypted backup systems will be purged within 90 days of account deletion.
• Anonymized Data: Aggregated, anonymized analytics data that cannot be used to identify you may be retained indefinitely for the purpose of improving the Service. This data contains no personally identifiable information.
• Legal Requirements: We may retain certain data for longer periods where required by applicable law, regulation, or legal proceedings.
5. Data Sharing & Third Parties
We are committed to keeping your data private. Here is how we handle data sharing:
• Google OAuth: When you sign in with Google, we receive only your name, email address, and profile picture from Google. We do not access your Google Drive, Gmail, contacts, calendar, or any other Google service data. Google's use of your information is governed by Google's own Privacy Policy.
• No Data Selling: We do not sell, rent, lease, or trade your personal data to any third party, under any circumstances. This is a core principle of PixMixy.
• No Advertising Networks: PixMixy does not integrate with any advertising networks, demand-side platforms, or ad exchanges. We do not serve ads and do not share your data for advertising purposes.
• Service Providers: We may engage trusted third-party service providers for hosting, infrastructure, and operational support (e.g., cloud hosting, database management). These providers are bound by strict data processing agreements (DPAs) and are contractually prohibited from using your data for any purpose other than providing their services to us.
• Legal Disclosure: We may disclose your information if required to do so by law, or if we believe in good faith that such disclosure is necessary to comply with a legal obligation, protect our rights or safety, or respond to a valid legal process (e.g., a court order or subpoena).
6. Children's Privacy & Child Safety Policy
Protecting children's privacy is especially important to us. This section outlines our comprehensive approach to child safety in compliance with applicable laws and app store requirements.
Age Restrictions
• PixMixy is not intended for, marketed to, or designed for use by children under the age of 13.
• For users located in the European Union (EU) or European Economic Area (EEA), the minimum age is 16 years, in accordance with the General Data Protection Regulation (GDPR).
• Users must confirm that they are of legal age to use the Service during the registration process. We implement age verification gates during account creation.
COPPA Compliance
• PixMixy fully complies with the Children's Online Privacy Protection Act (COPPA) of the United States.
• We do not knowingly collect, use, store, or disclose personal information from children under the age of 13.
• We do not knowingly allow children under 13 to create accounts or use the Service.
• We do not condition a child's participation in any activity on the child disclosing more personal information than is reasonably necessary.
Discovery of Underage Users
If we discover or are informed that a user is under the age of 13 (or under 16 in the EU/EEA), we will take the following immediate actions:
• Immediately suspend the account to prevent further data collection
• Permanently delete all personal data associated with the account within 48 hours
• Remove all user-generated content, including habit logs, fitness data, meal entries, financial records, study sessions, goals, and achievements
• Notify the parent or guardian if their contact information is available to us
• Document the incident in our child safety records for compliance auditing
Parental Supervision (Ages 13–17)
• Users between the ages of 13 and 17 (or 16 and 17 in the EU/EEA) may use PixMixy under the supervision and with the consent of a parent or legal guardian.
• Parents or legal guardians are responsible for monitoring their minor's use of the Service.
• Parents may contact us at
[email protected] to request access to, correction of, or deletion of their minor child's data.
No Advertising or Profiling of Minors
• PixMixy does not serve targeted advertising to any users, including minors.
• We do not perform behavioral profiling of minors for any purpose, including advertising, marketing, or analytics.
• We do not build interest-based profiles or tracking profiles of any users under the age of 18.
• We do not use minors' data for machine learning model training or algorithmic recommendation beyond the core Service functionality.
Content Safety & Platform Design
• PixMixy is a personal productivity and habit tracking tool. It does not include social or community features.
• There is no user-generated public content visible to other users.
• There is no messaging, chat, or direct communication functionality between users.
• There are no comments, forums, feeds, or any other interactive social features.
• All data entered by a user is private to that user's account and is not shared with or visible to any other user.
No Sharing of Children's Data
• We do not share, sell, rent, or disclose children's personal data to any third party for any purpose.
• In the event that children's data is inadvertently collected, it is deleted - not transferred, processed, or shared.
App Store Compliance
• PixMixy complies with Apple App Store Guidelines regarding child safety, including the App Store Review Guidelines Section 1.3 (Kids Category) and Section 5.1.1 (Data Collection and Storage).
• PixMixy complies with Google Play Families Policy requirements, including the Designed for Families program requirements and the Google Play Developer Policy on child safety.
• PixMixy is not listed in any children's or family-oriented categories on any app store.
Reporting Underage Users
• If you believe that a child under the age of 13 (or under 16 in the EU/EEA) has created an account on PixMixy or that we have inadvertently collected personal information from a child, please contact us immediately at
[email protected].
• We will investigate all reports promptly and take appropriate action within 24 hours of verification.
Ongoing Commitment
• We conduct regular reviews of our child safety practices and policies to ensure continued compliance with evolving laws, regulations, and industry standards.
• We train our team on child safety obligations and data protection requirements for minors.
• We stay informed of updates to COPPA, GDPR provisions for minors, and app store child safety requirements, and update our practices accordingly.
7. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data. You may exercise these rights at any time by contacting us at [email protected] or, where available, through in-app functionality:
• Right of Access: You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used, machine-readable format within 30 days of your request.
• Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data we hold about you. You can update most information directly through the app's Settings page.
• Right to Erasure (Right to Be Forgotten): You have the right to request the deletion of your personal data. You can delete your account and all associated data through Settings > Danger Zone. Upon deletion, all your data will be permanently removed as described in Section 8.
• Right to Data Portability: You have the right to request a copy of your data in a structured, commonly used, machine-readable format (e.g., JSON or CSV), and to have that data transmitted to another controller where technically feasible.
• Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data under certain circumstances, such as when you contest the accuracy of the data or object to processing.
• Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
• Right to Object: You have the right to object to the processing of your personal data where processing is based on legitimate interests, including profiling based on those interests.
• Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority (data protection authority) in your country of residence if you believe that our processing of your personal data violates applicable data protection law.
8. Account Deletion
PixMixy provides a self-service account deletion feature. You may delete your account at any time from Settings > Danger Zone within the app.
What Gets Deleted
When you delete your account, the following data is permanently and irreversibly removed:
• Your profile information (name, email, profile picture)
• All habit tracking logs and streaks
• All fitness and workout data
• All meal and nutrition entries
• All financial transaction records and budgets
• All study session logs and exam schedules
• All achievements, goals, and milestones
• All platform-wide progress data
• All active sessions and authentication tokens
• All preferences and settings
Deletion Timeline
• Immediate: Your account is suspended and you are logged out of all devices. You will no longer be able to sign in.
• Within 30 days: All personal data is permanently deleted from our primary database systems.
• Within 90 days: All residual copies in encrypted backup systems are purged.
Important Notes
• Upon deletion, you will be immediately logged out of the application.
• This action is permanent and irreversible. Once your account is deleted, your data cannot be recovered.
• If you wish to use PixMixy again after deletion, you will need to create a new account. No previous data will be available.
9. Data Security
We take the security of your personal data seriously and implement industry-standard technical and organizational measures to protect it:
• Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security), the latest and most secure encryption protocol for data in transit.
• Encryption at Rest: All personal data stored in our MongoDB database is encrypted at rest using AES-256 encryption, an industry-standard encryption algorithm used by governments and financial institutions worldwide.
• Password Security: User passwords are hashed using bcrypt with appropriate cost factors, making them computationally infeasible to reverse. We never store plaintext passwords.
• Session Management: Authentication session tokens are rotated regularly and automatically invalidated after periods of inactivity to minimize the risk of session hijacking.
• Access Controls: We follow the principle of least privilege. Access to user data is restricted to authorized personnel only, and only to the extent necessary to perform their duties.
• Security Assessments: We conduct regular security assessments, including vulnerability scanning and code reviews, to identify and remediate potential security weaknesses.
• Incident Response: We maintain incident response procedures to detect, investigate, and respond to data security incidents promptly. In the event of a breach that affects your personal data, we will notify you and the relevant supervisory authorities as required by applicable law.
11. Cookie & Local Storage Policy
PixMixy uses a minimal approach to cookies and local storage, limited to what is strictly necessary for the Service to function:
• Session Authentication Tokens: We store a secure authentication token in your browser's localStorage to keep you signed in between sessions. This token is encrypted and is automatically cleared when you sign out or when it expires.
• User Interface Preferences: We store your UI preferences (such as theme selection and layout settings) in localStorage so that your experience is consistent across visits.
• No Third-Party Tracking Cookies: PixMixy does not use any third-party tracking cookies. We do not integrate with any analytics platforms that place cookies on your device.
• No Advertising Cookies: PixMixy does not use advertising cookies, retargeting pixels, or any similar tracking technologies.
• Essential Cookies Only: Any cookies used by PixMixy are strictly essential for the operation of the Service and do not require separate consent under applicable cookie laws (including the EU ePrivacy Directive).
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.
• Notification of Material Changes: If we make material changes to this policy that affect how your personal data is collected, used, or shared, we will notify you via email (sent to the address associated with your account) and/or through a prominent in-app notification before the changes take effect.
• Continued Use: Your continued use of PixMixy after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the changes, you should discontinue use of the Service and delete your account.
•
Previous Versions: Previous versions of this Privacy Policy are available upon request. Contact us at
[email protected] to request a copy of any prior version.
• Review Date: We review this Privacy Policy at least annually, and after any significant changes to our data processing practices.