Privacy Policy

Effective Date: December 2025
Last Updated: December 2025

At My Bad Day, we are committed to protecting your privacy and handling your personal information with care and transparency. This policy explains how we collect, use, store, and protect your information when you use our emotional wellness application and related services.

Data Controller: Alti Ore, MB

Location: Lithuania

Contact: contact@mybadday.app

Table of Contents

1. Information We Collect

1.1 Information You Provide

When you choose to use My Bad Day, you may provide:

  • Account Information: Email address, display name, profile picture, and authentication credentials
  • Mood Tracking: Daily mood entries, mood levels (1-5 scale), timestamps, and notes
  • Sleep Tracking: Sleep quality ratings, duration, factors, interruptions, and environment details
  • Period/Cycle Tracking: Cycle dates, flow intensity, pain levels, symptoms, and energy levels
  • Journal Entries: Personal reflections, thoughts, and written content
  • Relationship Data: Connection names, relationship types, interaction notes, and bond health information
  • Partner Sharing (Optional): When you choose to share data with a selected partner or close person, you grant them access to specific wellness information you select to share
  • Preferences: Notification settings and feature preferences

1.2 Technical Information Collected Automatically

We collect minimal technical information necessary to operate the app:

  • Device Information: Device type, operating system version, app version
  • Crash Reports: Technical error logs when the app crashes (to fix bugs and improve stability)
  • App Performance: Basic performance metrics to ensure the app runs smoothly

We do not track your in-app behavior, navigation patterns, or which features you use. We only collect technical data required by app stores and for maintaining app stability.

1.3 Important: You Control All Data Entry

My Bad Day operates on a "you-enter-it" principle:

  • All mood, sleep, period, and health data is manually entered by you
  • We never automatically track, infer, or collect health information
  • If you don't enter data, we don't have data
  • Each entry is a voluntary action you initiate

1.4 Information We Do NOT Collect

  • Precise GPS location data
  • Contacts, photos, or other device data without explicit permission
  • Biometric data
  • In-app behavior or navigation patterns

2. Special Category Data (Health Information)

Important: When you voluntarily enter health tracking information (mood, sleep, period/cycle data), you are providing sensitive data classified as "Special Category Data" under GDPR Article 9.

2.1 Legal Basis for Processing Health Data

We process health data based on your explicit consent (GDPR Article 9(2)(a)).

Before you enter any health data, we will:

  • Clearly explain what health data you can enter
  • Explain how this data will be used
  • Request your explicit consent
  • Allow you to use the app without these features if you decline

2.2 Your Control Over Health Data

You can at any time:

  • Withdraw consent: Disable health tracking features in settings
  • Delete health data: Request deletion of all or specific health data
  • Export health data: Download your data in a portable format
  • Restrict processing: Limit how we use your health data

3. How We Use Your Information

3.1 Legal Bases for Processing

PurposeLegal Basis
Provide core app features (store and sync data, display history)Contract Performance
Health tracking features (mood, sleep, period)Explicit Consent
AI-powered insights and recommendationsExplicit Consent
Notifications and remindersConsent
Technical stability (crash reports, performance)Legitimate Interest
Security and fraud preventionLegitimate Interest
Legal compliance (tax records, legal requests)Legal Obligation

3.2 Specific Uses

  • Store and synchronize your entries across devices
  • Display your tracking history and patterns
  • Generate weekly journal summaries (with AI consent)
  • Provide personalized wellness recommendations (with AI consent)
  • Analyze anonymized crash reports to fix technical issues
  • Monitor app performance and stability

4. Artificial Intelligence and Third-Party Processing

4.1 AI Features

My Bad Day uses artificial intelligence to enhance your experience. AI features include:

  • Weekly journal summaries
  • Mood pattern insights
  • Wellness tips and recommendations
  • Emotional coaching responses

4.2 What Data is Sent to AI Services

Data TypeWhat We SendWhat We DON'T Send
Journal summariesAnonymized text (names/emails removed)User ID, email, account info
Mood patternsAggregated statisticsRaw entries or specific dates
Wellness questionsSelected answersPersonal identifiers
Sleep dataAggregated quality scoresTimestamps or locations

Anonymization: Personal names are replaced with "[Person]", email addresses and phone numbers are removed, specific dates are converted to day names, and no user IDs are transmitted.

4.3 Consent for AI Processing

AI features require your explicit consent. You will be asked to consent when you first use AI-powered features. You may choose not to enable or use any features that utilize AI processing. The core functionality of My Bad Day remains fully available without AI features.

4.4 AI Service Provider

Our AI features use third-party AI service providers that:

  • Process data only to provide the service (not for their own purposes)
  • Are bound by data processing agreements with appropriate safeguards
  • Implement industry-standard security measures
  • Do not use data sent via API to train their own models

5. Data Sharing and Third Parties

5.1 Service Providers

We work with trusted third-party service providers to deliver our services:

Service CategoryPurposeData Shared
Cloud InfrastructureDatabase, authentication, crash reportsAccount data, tracking data, crash logs
AI ProcessingAI-powered featuresAnonymized content (with consent)
Subscription ManagementPayment processingPurchase data
App DistributionApp store distribution, paymentsTransaction data

All service providers are bound by data processing agreements that require them to protect your data in accordance with GDPR.

5.2 Partner Sharing

You control partner sharing. My Bad Day includes an optional feature that allows you to share specific wellness data with a partner or close person you select.

  • Your consent required: By inviting a partner and using this feature, you explicitly consent to share selected wellness information with that specific person
  • You choose what to share: Control which data categories (mood, sleep, cycle, insights) your partner can view
  • Revocable anytime: You can stop sharing or remove partner access at any time
  • Single partner: This feature is designed for sharing with one selected partner or close person at a time

5.3 When We Share Data with Third Parties

  • With your explicit consent
  • With service providers under strict contractual obligations
  • When required by law, court order, or government request
  • To protect the rights, safety, or property of our users or others
  • In connection with a merger or acquisition (with prior notice)

5.4 What We Never Do

  • Sell your personal data
  • Share data with advertisers
  • Use your data for targeted advertising
  • Share health data without explicit consent

6. Data Security

Security Measures

We implement industry-standard security measures:

  • Encryption: All data transmitted between your device and our servers is encrypted, and data stored in our databases is encrypted at rest
  • Access Controls: Strict access controls, multi-factor authentication for administrative access, and regular audit logs
  • Infrastructure: Hosted on secure cloud infrastructure with regular security assessments and automated threat detection

Data Breach Response

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay. We will provide details about the breach and steps taken to protect you.

7. Data Retention

How Long We Keep Your Data

We retain your personal data in accordance with GDPR requirements:

  • Account and tracking data: Retained while your account is active. When you request account deletion, the deletion process initiates immediately and all personal data is permanently deleted from active systems within 30 days, with complete removal from backup systems within 90 days.
  • Legal and billing records: Retained for up to 7 years as required by tax and legal regulations
  • Anonymized technical data: May be retained indefinitely for service stability and improvement

Account Deletion and Data Export

You control when your data is deleted. Your data remains in our systems until you request deletion. We do not automatically delete data based on inactivity.

You can export all your data in JSON format or delete your account at any time. When you request deletion, the process begins immediately with full removal from active systems within 30 days and complete purge from all backups within 90 days.

8. Your Rights Under GDPR

As a data subject under GDPR, you have comprehensive rights regarding your personal data. We make it easy to exercise these rights.

Your Rights:

  • Right to Access (Article 15): Request a copy of all personal data we hold about you
  • Right to Rectification (Article 16): Correct any inaccurate or incomplete personal data (you can edit most data directly in the app)
  • Right to Erasure (Article 17): Request deletion of your personal data (you can delete your account in settings)
  • Right to Restrict Processing (Article 18): Limit how we process your data
  • Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format
  • Right to Object (Article 21): Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for any processing at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

How to Exercise Your Rights

Most rights can be exercised directly in the app settings. For other requests, contact us at contact@mybadday.app with your request and the email address associated with your account.

We will respond within 30 days. We may request verification of your identity before processing requests.

9. International Data Transfers

Your data may be processed in the European Union (primary data storage in EU regions) and the United States (AI processing, payment processing).

For transfers outside the EEA, we ensure protection through Standard Contractual Clauses (SCCs) approved by the European Commission, data processing agreements with all service providers, and data anonymization (especially for AI processing in the US).

10. Children's Privacy

My Bad Day is not intended for children under 14 years of age (or the minimum age required by your country's law, whichever is higher).

We do not knowingly collect personal information from children under the applicable minimum age. If we discover we have collected data from a child under this age, we will delete it immediately. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

11. Changes to This Policy

We may update this privacy policy from time to time. For minor changes, we will update the "Last Updated" date and changes will be effective immediately upon posting. For material changes, we will notify you via email or in-app notification and provide at least 30 days notice before changes take effect.

We encourage you to review this policy periodically.

12. Contact Us

If you have questions about this privacy policy or our data practices:

Email: contact@mybadday.app

Data Controller:
Alti Ore, MB
Lithuania

Summary of Key Points

TopicSummary
Data collectionYou manually enter all mood, sleep, period, journal data
User controlIf you don't enter it, we don't have it
Health dataRequires explicit consent; you control all entries
AI featuresOptional; data is anonymized before processing
Data sharingOnly with service providers; never sold
SecurityIndustry-standard encryption and access controls
Your rightsAccess, delete, export, object - all supported
Partner sharingOptional; you invite and consent; revocable anytime
Data deletionDeletion starts immediately; completed within 30 days (active systems) and 90 days (backups)
Contactcontact@mybadday.app

This privacy policy is designed to comply with the General Data Protection Regulation (GDPR), the Lithuanian Personal Data Protection Law, and other applicable data protection regulations.

Last Updated: December 2025

Version: 2.0

Service provided by: Alti Ore, MB (Lithuania)