Privacy

Privacy policy

Last updated {{LAST_UPDATED}}

The short version

Your goal and your progress live on your phone. When you ask 1% for a path, the text of your goal is sent to our backend and on to Google's Gemini API, which writes the steps. That is the only text of yours that ever leaves your device. There is no analytics SDK, no advertising, no tracking and no cookies.

Who is responsible

The controller for this data, in the sense of the GDPR, is:

{{COMPANY_NAME}}
{{COMPANY_ADDRESS}}
Germany

Privacy contact: {{PRIVACY_EMAIL}}

What stays on your device

The goal you wrote, the steps you have been given, which ones you marked done, your streak, your total number of steps and your level are stored in a local database inside the app on your iPhone.

That data is not uploaded so we can browse it, back it up or count it. We do not have a screen anywhere that shows us your goal text.

If you have iCloud device backup switched on, iOS may include the app's local data in your own encrypted Apple backup. That backup is yours and is handled under Apple's terms, not ours.

What leaves your device, and when

One thing does: the text of your goal, at the moment a path is generated.

Here is the whole route. You type a goal. The app sends that text over an encrypted connection (HTTPS) to our backend, which runs as Supabase Edge Functions hosted in the EU. The backend passes the text to Google's Gemini API, which writes the steps. The steps come back the same way and are stored on your device.

The processors involved:

  • Supabase — our backend and database. Edge Functions and project data are hosted in the EU.
  • Google — the Gemini API, which generates the step text.

Nothing else you write goes anywhere. We do not send your completions, your streak, your level or your usage patterns to either of them.

Please do not put names, addresses or other sensitive personal details into your goal text. It does not make the steps better, and it is the one field that leaves the phone.

The steps are written by AI

Every step you see in 1% is generated by a large language model. It is not written by a coach, an editor or any other person, and it is not reviewed by a person before you see it.

We state this here, and in the app, because Article 50 of the EU AI Act requires that you know when you are interacting with AI-generated content. A language model can be wrong, repetitive or badly judged. Use your own judgement about whether a given step is right for you, and skip anything that is not.

1% is a general self-improvement app and is not a substitute for professional advice or care.

Accounts

There are two kinds of account, and neither has a password.

Anonymous account

On first launch the app creates an anonymous account for you automatically, so your subscription and your generated paths can be attached to something. It holds a random identifier and nothing about who you are.

Sign in with Apple

If you choose to sign in, Apple gives the app an opaque user identifier, and — only if you agree to share it — an email address. That address may be one of Apple's private relay addresses, which is fine; we never need to know your real one. We receive no name, no photo, no profile and no password.

We use the identifier to recognise the same account on a new device. We use an email address, if we have one, to reply to you if you write to support.

Subscriptions and payment

Subscriptions are sold by Apple through the App Store and managed with RevenueCat, which keeps track of whether a given account has an active subscription.

The app never sees your card details, your name or your billing address. Apple handles the payment and Apple's own privacy policy covers it. What RevenueCat holds is an anonymous app user identifier, the transaction identifiers Apple issues and the status of your subscription.

What we do not do

  • No analytics SDK. We do not measure screens, sessions or funnels.
  • No advertising and no ad identifiers. We do not ask for tracking permission because we have nothing to track you with.
  • No third-party cookies. No first-party cookies either, in the app or on this site.
  • No fingerprinting, no device graph, no cross-app or cross-site profiles.
  • No selling or sharing of personal data. There is nothing to sell.

If crash reporting is ever added, it will be stated here first, and it will carry technical crash information only — never your goal text, your steps or anything else you wrote.

Legal grounds

Generating your steps
Article 6(1)(b) GDPR — performing the contract you entered into by using the app. Without sending the goal text there is no path to give you.
Account and subscription records
Article 6(1)(b) GDPR — running your account and your subscription.
Sign in with Apple, if you use it
Article 6(1)(b) GDPR, and Article 6(1)(a) for an email address you choose to share.
Keeping the service working and stopping abuse
Article 6(1)(f) GDPR — our legitimate interest in a backend that stays up and is not being drained by automated requests.

Where the data is

Our backend and database run on Supabase infrastructure in the EU.

Google's Gemini API may process your goal text outside the EU, including in the United States. That transfer is covered by the European Commission's Standard Contractual Clauses together with Google's own transfer safeguards. If you would rather your goal text stayed inside the EU only, the honest answer today is that generating a path is not possible on those terms, and you should not use the app.

How long things are kept

  • On your device — until you delete the app or clear its data. Deleting the app from your iPhone removes the local database with it.
  • Account records — until you delete your account. Deletion removes the account row and everything attached to it.
  • Generated paths — a generated path may be kept on our side as a cache so the same request does not have to be regenerated. After account deletion, anything retained is held without any link to a person or an account.
  • Support email — kept as long as needed to deal with your message, then removed.
  • Subscription records — Apple and RevenueCat keep transaction records for as long as tax and accounting rules require. That part is not ours to erase.

Your rights

Under the GDPR you can ask us for:

  • Access — a copy of what we hold about you.
  • Correction — a fix for anything wrong.
  • Deletion — removal of your account and its records.
  • Portability — your data in a machine-readable file.
  • Restriction and objection — including objecting to anything we do on the grounds of legitimate interest.
  • Withdrawal of consent — where you gave it, with no effect on what happened before.

The fastest route for deletion is inside the app: Settings, then Account, then Delete Account. It happens immediately. More about deletion.

For anything else, write to {{PRIVACY_EMAIL}}. We reply within {{SUPPORT_RESPONSE_TIME}} and answer inside one month, as the GDPR requires.

You also have the right to complain to a data protection supervisory authority. Ours is {{SUPERVISORY_AUTHORITY}}. You may also go to the authority where you live.

Children

1% is not directed at children. Do not use it if you are under 13, or under 16 in the European Union. We do not knowingly keep data from anyone in that range; if you believe a child has an account, write to {{PRIVACY_EMAIL}} and we will remove it.

This website

This site is static HTML and CSS. It sets no cookies, loads no fonts, embeds no scripts, and makes no requests to any other origin. Your visit is not counted anywhere. Standard access logs may be kept by whoever hosts the files.

Changes

If this policy changes in a way that matters, the date at the top changes and the app tells you the next time you open it. Small wording fixes will not get an announcement.

Contact

Privacy questions: {{PRIVACY_EMAIL}}
Everything else: {{SUPPORT_EMAIL}}

Postal address and responsible person are on the imprint.