Legal Document

Privacy Policy

How we collect, use, and protect your personal data — in plain language.

Effective date
May 11, 2026
Last updated
May 11, 2026
Version
1.1
Applies to
iOS · Android · Web
Framework
GDPR (EU) 2016/679
Table of Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Retention
  6. Data Sharing
  7. Your Rights
  8. Children's Privacy
  9. DobrOS is NOT a medical service
  10. Security
  11. Cookies & Analytics
  12. Changes to This Policy
  13. Contact Us
Human Summary (TL;DR)

Hi! This is a short summary for easy orientation. The full text below is legally binding.

01

Who We Are

DobrOS is a mental wellbeing application currently operated by Ing. Alexander Frič (OSVČ — Czech sole trader, IČO: 05939470), based in Praha, Czech Republic ("DobrOS", "we", "us", "our"). If the operator of the application changes in the future, we will inform you in advance within the application.

Data Controller:
Ing. Alexander Frič (OSVČ)
IČO: 05939470
Praha, Czech Republic
Email: privacy@dobros.cloud

As the data controller, we are responsible for deciding how and why your personal data is processed. If you have any questions about this Privacy Policy or our data practices, please contact us at the email above.

The supervisory authority for data protection in the Czech Republic is the Úřad pro ochranu osobních údajů (ÚOOÚ), which you may contact at www.uoou.cz if you have concerns about how we handle your data.

02

Data We Collect

We collect only the data that is necessary to provide and improve the DobrOS service. Here is a complete breakdown:

2.1 Account Data

DataSourcePurpose
NameGoogle / Apple Sign-InPersonalizing your experience
Email addressGoogle / Apple Sign-InAccount identification, communication
User IDGenerated at registrationAccount management
Registration dateSystemAccount management

2.2 Wellbeing & App Data

DataSourcePurpose
Habits (names, frequencies, completion)You enter itHabit tracking, streak calculation
Journal entriesYou write itReflective journaling feature
Mood logsYou submit itMood tracking, insights
Mind game scoresApp generatedBrain Profile calculation
Deep Work sessionsApp generatedProductivity tracking
OKR / Goal dataYou enter itGoal management
Course progressApp generatedLearning feature
XP, levels, badgesApp generatedGamification, motivation

2.3 Technical Data

DataSourcePurpose
Device type and OS versionYour deviceApp compatibility, bug fixing
App versionAppVersion management
Crash logs and error reportsFirebase CrashlyticsStability improvements
App usage eventsFirebase AnalyticsFeature improvement, understanding usage patterns
Push notification tokensFirebase MessagingSending notifications you've enabled
What we do NOT collect: We do not collect your location, contacts, microphone input, camera input, or any biometric data in the current version of DobrOS. Any future collection of biometric or health data will require your separate, explicit consent and will be covered by an updated Privacy Policy.

2.4 Special Categories (GDPR Art. 9)

Mood entries and journal text can reveal information about your mental state. We therefore treat them as special category data under Article 9 GDPR. The basic legal basis under Article 6 GDPR is performance of contract (providing the app features); we process this special category of data only on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give at sign-up and can withdraw at any time.

Under Czech Act No. 110/2019 Coll., § 7, the digital age of consent in the Czech Republic is 15 years. Users aged 15-17 in the Czech Republic can therefore provide their own explicit consent to the processing of special-category data. In countries where local law requires a higher age for independent consent, that higher age applies. For users below the applicable age threshold, parental consent under Art. 8 and Art. 9 GDPR is required.

03

How We Use Your Data

We use your data only for the purposes described below. We never sell your data to third parties. We do not use your data for advertising targeting.

04

Legal Basis for Processing

Under GDPR, we must have a valid legal basis for each type of data processing. Here is ours:

Processing ActivityLegal Basis
Creating and maintaining your accountPerformance of a contract (Art. 6(1)(b))
Storing your habits, journal, mood, and app dataPerformance of a contract (Art. 6(1)(b))
Mood entries and journal text (special category)Performance of contract (Art. 6(1)(b)) + explicit consent (Art. 9(2)(a)) — consent withdrawable anytime in settings
Sending push notifications you have enabledConsent (Art. 6(1)(a)) — withdrawable anytime in settings
Analytics and app improvementLegitimate interests (Art. 6(1)(f)) — we balance this against your rights
Crash reporting and securityLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Note on consent: Where we rely on consent as our legal basis, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. Withdrawing consent may affect certain app features.
05

Data Retention

We keep your data for as long as your account is active or as long as necessary to provide the service. Here are the specific retention periods:

Data TypeRetention Period
Account data and app content (habits, journals, etc.)Until you delete your account
Analytics and usage events14 months (Firebase default, then automatically deleted)
Crash logs90 days
Support correspondence3 years from last contact
Financial records (if applicable)10 years (Czech accounting law requirement)
Data after account deletionDeleted within 30 days of account deletion request

When you delete your account, all personal data is permanently deleted from our systems within 30 days, except for data we are required to retain by law (such as financial records).

06

Data Sharing & Third Parties

We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We use the following service providers who process data on our behalf:

ProviderPurposeLocation
Google FirebaseDatabase, authentication, analytics, crash reporting, notificationsEU (europe-west3, Frankfurt, Germany)
Google LLCSign-in via GoogleUSA (EU Standard Contractual Clauses apply)
Apple Inc.Sign-in via Apple, iOS platformUSA (EU Standard Contractual Clauses apply)

All data stored on Firebase is kept within the EU (Frankfurt, Germany data center). Where processing occurs outside the EU (e.g., authentication infrastructure), we rely on Standard Contractual Clauses approved by the European Commission to ensure adequate protection.

We may also disclose your data if required by law, court order, or to protect the rights, property, or safety of DobrOS, our users, or the public.

07

Your Rights

Under GDPR, you have the following rights regarding your personal data. You can exercise all of them by contacting us at privacy@dobros.cloud. We will respond within 30 days.

📋 Right of Access
Request a copy of all personal data we hold about you (GDPR Art. 15).
✏️ Right to Rectification
Ask us to correct inaccurate or incomplete data (GDPR Art. 16).
🗑️ Right to Erasure
Ask us to delete your personal data ("right to be forgotten") (GDPR Art. 17).
⏸️ Right to Restriction
Ask us to stop processing your data in certain circumstances (GDPR Art. 18).
📦 Right to Portability
Receive your data in a machine-readable format to transfer elsewhere (GDPR Art. 20).
🚫 Right to Object
Object to processing based on legitimate interests (GDPR Art. 21).
↩️ Right to Withdraw Consent
Withdraw consent for consent-based processing at any time.
⚖️ Right to Complain
Lodge a complaint with the ÚOOÚ at www.uoou.cz.
Account deletion: The fastest way to delete all your data is to use the "Delete Account" feature in the app (Settings → Account → Delete Account) or visit dobros.cloud/delete. All data will be permanently removed within 30 days.
08

Children's Privacy

In line with Czech Act No. 110/2019 Coll., § 7, the minimum age for independent use of the app in the Czech Republic is 15 years. In countries where local law requires a higher age for independent consent, that higher age applies.

If we learn that someone below the applicable age threshold has signed up independently without parental consent, we delete the account without undue delay. If you believe a child has signed up in this way, please contact privacy@dobros.cloud.

09

DobrOS is NOT a medical service

DobrOS provides wellbeing education, self-reflection tools, and brain training. It is not a medical device, medical advice, diagnosis, therapy, or treatment, and it does not replace professional care by a physician, psychologist, or psychotherapist.

In case of acute psychological distress, suicidal thoughts, or immediate danger to life, please contact a crisis line immediately or call 112.

The data you keep in the app is not a medical record, is not a professional opinion, and cannot be used as medical evidence. If you are experiencing difficult mental states, please consult a physician, psychologist, or a crisis helpline.

Crisis lines (Czech Republic, all free and available 24/7):

Outside the Czech Republic please contact your national crisis helpline or call your local emergency number.

10

Security

We take the security of your data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, loss, destruction, or alteration.

Despite these measures, no system is 100% secure. If a personal-data breach occurs, we assess the risk, document the incident, and where required by Art. 33 GDPR notify the Czech Data Protection Authority (ÚOOÚ) normally within 72 hours after becoming aware of it. If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Art. 34 GDPR).

11

Cookies & Analytics

The DobrOS mobile app does not use browser cookies. We use Firebase Analytics to collect anonymized, aggregated data about how the app is used. This data does not identify you individually and is used solely for app improvement.

The DobrOS website (dobros.cloud) may use essential cookies required for its operation. We do not use advertising cookies or third-party tracking cookies. If you access DobrOS as a Progressive Web App (PWA), the same principles apply.

12

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you in the app and update the "Last Updated" date at the top of this page.

For material changes that affect how we use your personal data, we will seek your renewed consent where required by law. Continued use of the app after notification of changes constitutes your acceptance of the updated policy, to the extent permitted by law.

We encourage you to review this policy periodically.

13

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Ing. Alexander Frič (sole proprietor / OSVČ)
Company ID (IČO): 05939470
Registered office: Praha, Czech Republic
Data protection contact: privacy@dobros.cloud
Legal questions: legal@dobros.cloud
Website: dobros.cloud

If the operator of the application changes in the future, we will inform you in advance within the application.

We aim to respond to all requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Úřad pro ochranu osobních údajů (ÚOOÚ):

Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.cz

Questions about your data?

We're here to help. Reach out anytime — we respond within 30 days.