Privacy Policy — Merit
Last updated: 2026-08-25
The short version
Your rates, your client names and your earnings never leave your device. There is no account, no login, and no server of ours holding your figures. Uninstalling Merit deletes them.
Three things do leave the device, and most of this document is about them: anonymous usage events (PostHog), automatic crash reports (Sentry), and the state of your subscription (RevenueCat). None of the three carries your rates, your client names, or your earnings.
That last sentence is not a marketing claim we soften later in legal fine print — it is built into the code. No event has a field for an amount, a client name or an earnings value; and just before an event is sent, every property not on an explicit allowlist is dropped. The rate step of onboarding is the clearest example: it reports that you entered an hourly rate in EUR, never the number you typed.
Who we are
Merit is published by Liminal Ninja. If you have any question about this policy or your privacy, contact us at dany.boucanova@gmail.com.
What stays on your device
Merit stores the following locally on your device only, using your device's standard app storage. None of its content is transmitted anywhere:
- Clients — the names, billing rates (hourly / daily / monthly / annual), currency, and color you assign to each client.
- Calendar / work slots — the work and on-call slots you schedule, with their dates and times.
- Profile — your name and profession, if you choose to enter them.
- Settings — your preferences, such as your default active client and the analytics switch.
- Earnings — these are not stored as such; they are calculated on the fly from your clients and slots whenever you open the app.
To power the home-screen widgets (iOS and Android), the iOS Live Activity, and the Android live notification, Merit writes a small local snapshot of your current earnings figure into a private, on-device shared storage area that only Merit and its own widget can read. This snapshot also never leaves your device.
What leaves your device
| Service | What it receives | Why | Where | Kept for |
|---|---|---|---|---|
| PostHog | Anonymous product-interaction events | Seeing which parts of the app are used and where people get stuck | European Union (PostHog EU Cloud) | 12 months, then deleted |
| Sentry | Crash and error diagnostics, with no user identifier | Finding and fixing crashes | The region configured for our Sentry organisation | 90 days, then deleted |
| RevenueCat | Purchase and subscription state | Knowing whether your subscription is active, and restoring it on a new device | United States | For the life of the subscription, plus the period the app stores require purchase records to be kept |
These three are processors: they handle this data on our instructions and for no purpose of their own. Nobody else receives anything.
PostHog — anonymous usage events
The complete list of events Merit can send: onboarding started, step viewed, rate entered, completed; paywall viewed and dismissed; trial started; purchase completed or failed; restore completed; client created; slot created; widget added; widget prompt shown and dismissed; live activity started.
The only values that can travel with them are types, counts, booleans, and identifiers of our own products: a step name and its index, a rate type and a currency code, a subscription product identifier, which screen opened the paywall, a store error code, whether a restore found a purchase, how many clients you have, and the platform and size of a widget with the day of the trial it was added on. No amount, no client name, no earnings value — see "The short version".
The PostHog SDK adds its own technical context to what we send: app lifecycle events (installed, updated, opened, became active, backgrounded), device manufacturer and model, OS name and version, app name, identifier, version and build, language, time zone, and similar technical details. Events are attached to a random identifier generated on your device, not to you — Merit never tells PostHog who you are, and has nothing to tell it: there is no account, no email, no name.
Sending an event exposes your device's IP address to PostHog, as any request over the internet does. The SDK turns PostHog's IP-based geolocation off, so no location is derived from it, and IP anonymisation is enabled in our PostHog project. Turning usage analytics off stops the events but not the contact: the SDK still fetches its own configuration from PostHog each time the app starts, so your IP address is still seen even though nothing about your use of the app is sent.
Sentry — crash diagnostics
When Merit crashes or hits an unexpected error, Sentry receives the error, its stack trace, and technical context about your device and the app version. Sentry is configured with personal-identifier collection switched off, so no user identifier is attached to the report. Roughly one operation in five is also sampled for performance traces — how long that operation took — for the same purpose: making the app work properly.
Merit attaches nothing of its own to a crash report and writes no log lines at all, so your clients, your rates and your earnings do not appear in one.
Crash reporting is not covered by the analytics switch. It is active whenever the app runs.
RevenueCat — subscription state
Subscriptions are sold by Apple and Google, not by us. Payment happens in the App Store or Play Store sheet, and Merit never sees your card, your billing address, or your store account. RevenueCat sits behind that to tell the app whether your trial or subscription is active, which product you bought, and whether the store has reported a billing problem. It identifies your purchases with an anonymous identifier it generates itself; we never give it your name, your email, or an account ID, because there is no account.
Turning usage analytics off
Profile → Settings → Privacy → Anonymous usage data. Turn it off and Merit stops sending product-interaction events immediately. The choice is stored on your device and re-applied every time the app starts, so it survives restarts and updates.
The switch covers PostHog only. Crash diagnostics and subscription state are not optional: without the first we cannot fix the crash you just hit, and without the second the app cannot tell whether you have paid.
What Merit does NOT do
- It does not use an advertising identifier and does not track you across other apps or websites. There is no App Tracking Transparency prompt because there is nothing to ask you about.
- It does not create an account or ask you to sign in.
- It does not send your rates, your client names, or your earnings anywhere.
- It does not sell, rent, or share your data with anyone beyond the three processors listed above.
- It does not access your contacts, photos, location, or microphone.
- It does not show ads.
Legal basis
Usage analytics and crash reporting rest on our legitimate interest in improving an app that works — and analytics comes with the opt-out described above. Subscription state rests on the performance of our contract with you: the app cannot honour a subscription it is not allowed to check. Everything that stays on your device is not processed by us at all — it never reaches us.
Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. Write to dany.boucanova@gmail.com and we will answer within one month.
One honest limitation: Merit has no account, and the events and crash reports described above carry a random identifier rather than anything that names you. We generally cannot tell which of them are yours, which also means we cannot single them out to show you or delete them (GDPR Article 11). What you can always do without asking us: turn analytics off in Settings, and delete everything held on your device by uninstalling the app.
Children's privacy
Merit is a productivity tool aimed at freelancers and independent professionals. It is not directed at children, and we do not knowingly collect information from them. There is no account and no profile to publish, and the data described above contains nothing that identifies a person.
Deleting your data
- Delete individual items (clients, slots) from within the app at any time.
- Remove everything held on the device at once by uninstalling Merit. Uninstalling deletes all locally stored data, including the widget snapshot.
- Usage and crash data are not deleted by uninstalling: they stay with PostHog and Sentry until the retention periods above expire. You can stop new events at any time with the Settings switch, and ask us to delete anything we can attribute to you.
- Purchase records are held by Apple or Google and by RevenueCat. A subscription is cancelled from your store account, not from Merit.
Permissions
Merit needs no special device permission to function. On Android it may ask for permission to post notifications, used only to display the live earnings notification — your own figures, on your own device. It never asks for your contacts, photos, location, or microphone.
Future versions (not in this version)
- A future version may add optional cloud sync (to back up and sync your data across your own devices). If added, it will be opt-in: you would explicitly choose to create an account and enable sync. Until you do, the app keeps working exactly as it does today, with your clients, rates and earnings on your device only.
If and when this ships, this Privacy Policy will be updated before the feature is enabled, and the "Last updated" date above will change accordingly.
Changes to this policy
If we update this policy, we will revise the "Last updated" date at the top. Material changes — a new processor, a new category of data, a longer retention — will be reflected here before the corresponding change is released.
Contact
Questions? Reach us at dany.boucanova@gmail.com.