This policy explains what information Accrue handles, why it is handled, where it goes, and the choices available to you.
Accrue is not for client information
Do not enter client names, initials, dates of birth, case numbers, contact information, diagnoses, session notes, or other clinical information into Accrue. The app is designed to record the type, date, and duration of work, not the identity or clinical details of a client.
Information we collect
Depending on the features you use, Accrue processes:
- Account information, including your name, email address, and a unique account identifier. If you use Sign in with Apple and hide your email address, we receive Apple's private relay address.
- Professional recordkeeping information, including supervised hours, activity categories, dates, durations, sites, supervisors, supervisor credentials you enter, program, state, license track, registration details, and your own non-clinical reminders.
- Purchase information, including product identifiers, purchase and subscription status, transaction or receipt information, and a pseudonymous app user identifier used to unlock paid access and restore purchases.
- Limited technical information needed to operate authentication, synchronization, purchases, security checks, Apple system services, product analytics, and crash diagnosis. Product analytics use a random device-scoped identifier and a small set of predefined events. Diagnostics may include crash stack traces, app and operating-system versions, device model, MetricKit performance diagnostics, and coarse city, region, and country derived by Sentry from a diagnostic request. Sentry is configured to discard the raw IP address.
How we use information
We use information only to provide and maintain Accrue, including to sign you in and sync records; calculate ledgers and prepare exports; verify paid access and restore purchases; protect account creation with a privacy-preserving password breach check; understand whether onboarding and paid-access flows work as intended using anonymous, predefined product events; diagnose crashes and operational failures without attaching account identity or record content; respond to support requests; and comply with legal obligations or protect the service from misuse.
Service providers and transfers
- Google Firebase Authentication and Cloud Firestore. Firebase signs you in and stores a synchronized copy of your records under your account identifier. Firebase Analytics and automatic data collection are disabled in the app.
- RevenueCat and Apple StoreKit. RevenueCat and Apple process purchase history, transaction or receipt information, product identifiers, technical purchase information, and a pseudonymous app user identifier so Accrue can validate purchases, provide paid access, and restore purchases. Apple processes payments under your Apple Account and its own privacy policy.
- PostHog. PostHog processes a random device-scoped identifier and predefined events such as paywall views, selected plan type, purchase outcome, restore outcome, and onboarding completion. Accrue does not identify users to PostHog. Automatic screen capture, element capture, session replay, surveys, feature flags, logs, error capture, and location enrichment are disabled. Event properties are restricted to plan and outcome values plus basic app/device version information.
- Sentry. Sentry processes crash reports, sanitized operational error codes, app and operating-system versions, device model, a device-scoped diagnostic identifier, MetricKit performance diagnostics, and coarse city, region, and country derived from a diagnostic request so we can maintain reliability. Sentry is configured to discard the raw IP address. Accrue does not set a Sentry user, and disables default personal information, breadcrumbs, network capture, screenshots, view hierarchy, session replay, logs, and performance tracing. Events are scrubbed again before transmission.
- Sign in with Apple. Apple processes authentication when you choose that option.
- Apple Maps search completion. Text you type while searching for a work site is sent to Apple's search completion service. Accrue does not request your device location.
- Have I Been Pwned password range service. When you create an email password, Accrue sends only the first five characters of its SHA-1 hash to
api.pwnedpasswords.comand compares the response on your device. Your password and the rest of the hash do not leave the device.
These providers may process information in the United States and other locations where they operate, subject to their own legal and security obligations.
Storage and security
Your local Accrue records are stored on your device. When you are signed in, a synchronized copy is stored in Cloud Firestore under your account identifier. Access controls restrict that copy to your authenticated account. We use platform security features and reasonable administrative and technical safeguards, but no storage or transmission system can be guaranteed completely secure.
Retention and deletion
We retain account and synced record data while your account is active. Delete your account from Settings → Account → Delete account. Accrue asks you to reauthenticate, then deletes synced records, the sign-in account, and local records on that device. Deletion is intended to be immediate, although service-provider backups and legally required records may persist for a limited period.
Deleting an Accrue account does not cancel an Apple subscription. Manage or cancel subscriptions in your Apple Account subscription settings.
Apple and RevenueCat may retain transaction records as required for purchase validation, fraud prevention, accounting, or legal compliance. PostHog and Sentry retain limited analytics and diagnostic data according to our configured retention and their service obligations. Room to Grow LLC does not control Apple's independent transaction-retention obligations.
Your choices
- Review and edit your records in the app.
- Export records you choose.
- Delete your Accrue account and synced records in Settings.
- Manage or cancel an auto-renewing subscription through Apple.
- Contact us to ask a privacy question or request assistance.
Children
Accrue is intended for adults in professional training and is not directed to children under 13.
Changes to this policy
We may update this policy as the app or applicable requirements change. We will update the date above when we do.
Contact
For privacy questions, email admin@roomtogrowllc.com.