🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
SoloRythm

SoloRythm Privacy Policy

How SoloRythm separates private local work-rhythm records from optional recovery and limited operational services.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local private core Personal work-rhythm records stay in the encrypted device database
Optional recovery Drive checkpoints are encrypted on the device before upload
Limited operations Account, push, support and entitlement data exclude wellness content
Global rights Access, correction, export and deletion requests are supported
On this page
  1. Overview
  2. Data We Handle
  3. How We Use Data
  4. Sharing and Processors
  5. Storage and Residency
  6. Cloud and Backups
  7. Retention
  8. Security
  9. Your Rights
  10. Children
  11. International Transfers
  12. Changes
  13. Contact

SoloRythm is a local-first work-rhythm and general wellness companion operated by Blue Sparrow. This policy explains what stays on the device, what optional providers process, and the controls available globally.

Overview

Blue Sparrow operates SoloRythm as a solo developer based in India. SoloRythm supports check-ins, focus sessions, breaks, reminders, journal entries, weekly reflection, burnout-awareness prompts and private progress views.

Blue Sparrow applies privacy principles reflected in the EU General Data Protection Regulation, the United Kingdom GDPR, privacy laws in the United States including applicable state rights, India's Digital Personal Data Protection framework and other applicable regional requirements. This is an operational commitment, not a regulatory certification.

Blue Sparrow does not sell or rent personal data, show third-party advertising or use work-rhythm content for targeted advertising. SoloRythm does not include Firebase Analytics or Firebase Crashlytics in the audited app build.

Plain-language summary

Your personal work-rhythm history is encrypted locally. Only limited identity, device, notification, purchase, support and service data goes to the providers needed for the features you use.

Data We Handle

SoloRythm stores check-in answers, daily intentions, focus labels and history, pause periods, breaks, reminder schedules, journal entries, weekly reflections, burnout-awareness answers, streak inputs, progress history, preferences and related settings in its local app data. The Drift and SQLite database is encrypted on the device. Blue Sparrow's operational API rejects these wellness fields and does not synchronize this content.

Account and service data can include a Firebase user identifier, Google-provided email, display name and profile image, account status, app version, platform, major operating-system version, locale, a random device identifier, notification-permission state, Firebase Cloud Messaging token, entitlement and product state, request timestamps, service revisions, security outcomes and bounded error records.

Support data can include the name, reply email, subject and message a user chooses to submit. A separately generated redacted diagnostics export can contain technical status selected by the user; it is designed to exclude wellness values, credentials, tokens, passphrases and encryption keys. Users should still review any message or export before sending it.

How We Use Data

Local work-rhythm content is used on the device to provide check-ins, focus, breaks, reminders, journal, reflections, progress and exports. Operational information is used to authenticate accounts, register a device for generic push delivery, manage account state, verify Premium access, provide support, process deletion, prevent misuse and maintain service reliability.

Depending on the context, processing is based on providing the requested service, the user's consent or choices for optional features, legitimate security and operational needs, or an applicable obligation. Notification and Drive permissions can be changed through the app, device or Google account controls, although the related feature may stop working.

Core work-rhythm reminders are scheduled locally. Firebase Cloud Messaging is limited to generic operational, account, security or service messages and is designed not to include check-in answers, focus intentions, journal text, reflection answers or progress history.

Sharing and Processors

Blue Sparrow discloses data only as needed to provide a requested feature, operate and secure SoloRythm, respond to support, meet a valid obligation, protect people or support a business transition with appropriate safeguards.

Providers and platforms can include:

  • Google Sign-In and Firebase Authentication for account identity and access.
  • Firebase Cloud Messaging and Blue Sparrow's notification service for generic push delivery.
  • Google Drive for optional user-authorized encrypted recovery storage in the app-data area.
  • Google Play for distribution and billing, and RevenueCat plus Blue Sparrow's subscription gateway for purchase and entitlement status.
  • Blue Sparrow's operational API, database, hosting and backup providers for account, device, entitlement, deletion and service records.
  • Blue Sparrow's support and mail services for messages users choose to submit and replies.

Providers receive information needed for their role and apply their own terms, retention, security and geographic processing arrangements. SoloRythm does not currently ship a Telegram connection; a capability name retained in source does not establish an active integration.

Storage and Residency

Private work-rhythm records remain in the encrypted app database. Android application backup is disabled and the checked-in Android rules exclude app databases, files and preferences from cloud backup and device transfer. Operating-system and device behavior outside the audited configuration can change independently.

Optional recovery checkpoints are encrypted on the device before upload to the hidden app-data area of the user's Google Drive. The encrypted archive contains the selected local wellness snapshot. Blue Sparrow does not receive the archive bytes, recovery passphrase or backup key. Google determines storage locations and transport metadata for the user's Drive account.

Blue Sparrow-controlled operational records and service backups are intended to remain in European Union infrastructure, subject to confirmation of the active production and backup deployment. This qualified intention does not apply to every provider or every item of data.

Blue Sparrow is operated from India and support access can occur from India. Google, Firebase, Drive, Play, RevenueCat, mail and other providers may process limited identity, notification, billing, communication or security data in other regions under their own infrastructure and safeguards.

Cloud and Backups

Drive recovery requires separate user authorization for the Google Drive app-data scope. SoloRythm creates encrypted checkpoint payloads and manifests, verifies uploaded bytes and binds restoration to the matching account. The recovery passphrase protects the portable recovery material, and Blue Sparrow cannot reset it or bypass the cryptography.

Drive recovery is not live multi-device synchronization. SoloRythm retains a bounded set of recent, weekly and monthly checkpoints and attempts to remove superseded objects. Provider failures or lost authorization can delay removal. Disconnecting Drive in the app clears the local connected state but does not itself revoke Google consent or delete existing checkpoints.

A user can generate a human-readable JSON or Markdown export to a selected local destination. The app does not upload that export to Blue Sparrow. The file can contain sensitive plaintext wellness content, and any storage provider, app or recipient selected by the user then handles the copy under its own practices.

Retention

Local records remain until removed through app controls, account deletion, app-data clearing or uninstalling, subject to device behavior. User-created exports remain wherever the user saved or shared them. Accessible Drive checkpoints remain until removed by checkpoint rotation, an available deletion action or Google account controls.

Operational account, device and entitlement information remains while needed to provide SoloRythm. Support messages, delivery records, security events, billing records and deletion tombstones can remain for purpose-based periods needed for support, fraud prevention, accounting, service protection or an applicable obligation. Production retention and backup-rotation schedules require operational verification before more exact promises can be made.

The in-app deletion flow always requires local deletion and reauthentication. A user can also select deletion of configured operational records and accessible Drive checkpoints. The flow then deletes local data and keys and attempts to delete the Firebase Authentication identity. If Drive deletion fails, the flow keeps sign-in access so the user can retry. Uninstalling, signing out or deleting the SoloRythm account does not cancel a Google Play subscription.

Provider logs, support communications, purchase records, deletion tombstones and rotating backups may remain for their applicable periods. Copies exported or shared by the user are outside SoloRythm's deletion control.

Security

Safeguards include encrypted local SQLite storage, device sandboxing, disabled Android backup, HTTPS or TLS for remote requests, provider-issued authentication, an operational API allowlist that rejects wellness fields, encrypted server-held identifiers and tokens where implemented, redacted diagnostics, and encrypted Drive checkpoints with account binding and integrity verification.

No system can promise complete security. Users should protect their device, Google account and recovery passphrase; keep SoloRythm updated; review plaintext exports; and report suspected unauthorized access promptly. Blue Sparrow cannot recover a forgotten recovery passphrase or decrypt an inaccessible checkpoint.

Your Rights

Depending on location and circumstances, a person may have rights to know or access personal data, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of qualifying sale or targeted advertising, and raise a concern with a privacy authority. SoloRythm does not sell personal data or use work-rhythm content for targeted advertising.

Users can edit or delete local records, change permissions, create an export and start in-app account deletion. To request help with operational data or exercise an applicable right, email [email protected]. Blue Sparrow may verify identity and account access before acting and will respond within applicable timeframes without unlawful discrimination.

Children

SoloRythm is not directed to children under 16 and does not knowingly invite them to create accounts. A higher minimum age may apply where a user lives. If a parent or guardian believes a child provided personal data, contact [email protected] so the situation can be reviewed and appropriate action taken.

International Transfers

Blue Sparrow is operated from India. Blue Sparrow-controlled operational processing is intended for European Union infrastructure subject to production confirmation, while providers can process limited data elsewhere and Google controls the location of encrypted Drive objects. Privacy protections differ between regions.

Where safeguards are required, Blue Sparrow relies on available measures such as provider data-protection terms, contractual protections, recognized adequacy arrangements or consent where appropriate. The rights and contact channel in this policy remain available globally.

Changes

Blue Sparrow may update this policy as SoloRythm, its providers or applicable requirements change. The updated date will change, and material changes may also be announced in the app or at https://bluesparrow.dev. Additional notice or consent will be provided where required.

Contact

Blue Sparrow is operated by a solo developer based in India.

  • Privacy and data requests: [email protected]
  • General support: [email protected]
  • Website: https://bluesparrow.dev

Email provides a practical way to verify and track requests without publishing additional contact details.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.