Privacy Policy
Effective date: 23 August 2026 Last updated: 31 August 2026
This Privacy Policy explains how Egglaxy ("Egglaxy", "we", "us", "our") collects, uses, stores, shares and protects information when you use the Egglaxy mobile application (the "App") for iOS.
Egglaxy is an egg cooking timer. It has no user accounts, no sign-up, no login and no server of ours. Everything you set inside the App — your last recipe, your custom timers, your alarm tone, your preferences — is stored locally on your device and never reaches us.
There is one important exception, and we want it stated at the top rather than buried: the App is supported by advertising. Advertising is served by Google AdMob, and to serve it Google collects information from your device, including advertising identifiers and your IP address. Section 3.2 describes exactly what that means, and Section 13 describes how to turn it off — including how to remove ads permanently with a one-time purchase.
If you do not agree with this Policy, please do not install or use the App.
1. Who we are (Data Controller)
| Operator | Egglaxy, an independent app developer based in Ukraine |
| Privacy contact | ancoapps.support@gmail.com |
| App | Egglaxy — egg cooking timer for iOS |
For users in the European Economic Area (EEA), the United Kingdom and Switzerland, Egglaxy acts as the Data Controller for the limited categories of personal data described in this Policy.
For advertising, Google acts as an independent controller (or, in some configurations, as a joint controller) for the data it collects through the AdMob SDK. This is explained in Section 6.1 — it matters, because it means some of your choices are exercised with Google rather than with us, and we tell you where.
Users anywhere can write directly to ancoapps.support@gmail.com with any privacy question, and we will respond within the timeframes set out in Section 16.
2. Summary (TL;DR)
- We have no accounts and no servers. We do not know who you are. There is no profile of you anywhere in our possession.
- Your cooking settings, custom timers, alarm choice and preferences stay on your device. We never receive them.
- The App uses your location once, and only to read the altitude, so boiling times can be corrected for where you are. The altitude number is used in a calculation and is never stored by us and never transmitted anywhere. Your coordinates never leave your device.
- The App shows ads through Google AdMob. Google collects device identifiers, IP address, and information about the ads you see and interact with. Under California law this counts as "sharing" personal information for cross-context behavioural advertising, and you have the right to opt out — see Sections 9.2 and 13.
- In the EEA, UK and Switzerland, ads are only personalised if you consent through the consent form shown at first launch. You can change that decision at any time in Settings → Privacy options.
- On iOS we also ask, separately, for App Tracking Transparency permission. Saying no is fully supported — the App works exactly the same, you simply see less relevant ads.
- You can remove ads permanently with a one-time in-app purchase. It is not a subscription: you pay once and ads never come back. Apple processes the payment; we never see your card details.
- The App uses Firebase Analytics to count how it is used — which screens are reached, which recipes are cooked, whether the walk-through is finished. It is linked to our AdMob account, so that ad revenue can be read alongside it — which means analytics data and advertising data are joined. In the EEA, UK and Switzerland it only runs if you consent. See Section 3.5.
- We do not sell your personal information for money, and we run no crash reporter and no tracking pixels of our own.
- Uninstalling the App deletes everything it stored on your device.
Example. You boil a 62 g egg to a soft yolk on a Tuesday morning. The egg's weight, the doneness you picked and the timer you ran are written to your phone and to nowhere else. What Google's advertising SDK learns from that session is unrelated to the egg: it learns that a device with a certain advertising identifier, at a certain IP address, opened an app and had an opportunity to see a banner.
3. Information we collect and where it is stored
We distinguish between four categories.
3.1 Information stored only on your device
The App saves the following on your device. None of it is transmitted to us or to anyone else. It never leaves the device except in an iCloud or iTunes device backup, if you have those enabled — that backup is between you and Apple, and is governed by Apple's privacy policy, not ours.
| What | Why it is stored |
|---|---|
| Last recipe cooked (method, doneness, egg weight, egg count, starting temperature) | So the App opens on what you cooked last instead of a blank screen |
| Custom timers you created | So your own times survive a relaunch |
| Alarm tone selection | So the alarm sounds the way you chose |
| Keep-screen-awake, haptics, skip-preparation-steps preferences | So the App behaves the way you set it |
| Guidance mode per cooking method | So each method opens in guided or plain-timer mode as you prefer |
| Whether you completed onboarding | So the welcome flow is shown once and never again |
| Which edition of this Policy and the Terms you accepted, and when | So the consent screen is not shown again, so we can prove consent was given, and so we can ask again — and only ask again — when these documents change materially |
| How often permission explanations have been shown, and when | So the App does not ask you for the same permission repeatedly |
| Advertising frequency counters — session count, first-launch date, ads shown today, cooldown timestamps, and the expiry of any ad-free period earned by watching a rewarded video | So the App can enforce its own limits on how often an ad may appear. These counters are a restraint on advertising, not a profile of you, and they stay on the device |
We have no technical means to read any of this. There is no endpoint it could be sent to.
3.2 Information collected by Google for advertising
The App integrates the Google Mobile Ads SDK (AdMob). When an ad is requested or displayed, Google — not us — collects and processes information from your device. Based on Google's published documentation for publishers, this includes:
- Advertising identifiers — the iOS Identifier for Advertisers (IDFA), where you have permitted tracking, and/or the Identifier for Vendors (IDFV) and other app-set or first-party identifiers;
- IP address, from which an approximate location (typically city or region level) can be derived. This is not the GPS location described in Section 3.3, and the two are never combined by us;
- Device and technical information — device model, operating system version, language, screen characteristics, network and carrier information, time zone;
- Ad interaction data — which ads were requested, shown, viewed, clicked or dismissed, how long they were visible, and whether an ad led to an app install;
- App information — the app's identifier and version, and coarse signals about how the app is being used at the moment an ad is requested;
- Diagnostic data — crash logs that are not tied to you, and performance measurements such as launch time, hang rate and energy use, which Google uses to find faults in its own SDK;
- In-app interactions — app launches, taps and video views, to the extent they inform how an ad is delivered and measured;
- SKAdNetwork / attribution signals — Apple's privacy-preserving install-attribution framework, which reports conversions to advertisers in aggregate without identifying you.
What Google does with it. Google uses this data to select and deliver ads, to cap how often you see the same ad, to measure ad performance, to detect invalid traffic and fraud, and — only where personalised advertising is permitted — to build and use interest profiles for ads personalisation across apps and sites.
Personalised versus non-personalised. Which of those Google may do depends on your choices:
| Your situation | What Google may do |
|---|---|
| EEA / UK / Switzerland, consent given for personalised ads | Personalised ads, using identifiers and interest profiles |
| EEA / UK / Switzerland, consent refused | Non-personalised or limited ads. Identifiers may still be used for frequency capping, fraud prevention and aggregate reporting — this is a legitimate-interest processing that Google performs; personalisation does not occur |
| iOS App Tracking Transparency prompt declined | The IDFA is not available. Cross-app tracking does not occur. Contextual and non-personalised ads still appear |
| Remove Ads purchased, or a rewarded ad-free period running | No ad is requested at all, so Google collects nothing for advertising in that session |
Important: we do not receive this data. We see only aggregate, non-identifying reports in the AdMob console — impressions, clicks, estimated revenue, broken down by country and ad format. Those reports cannot be traced back to you and contain no personal information about you.
Google's own explanations, which we ask you to read because they are the authoritative description of Google's processing:
- Google Privacy Policy — https://policies.google.com/privacy
- How Google uses information from sites or apps that use its services — https://policies.google.com/technologies/partner-sites
- Google Advertising — https://policies.google.com/technologies/ads
3.3 Location — used for altitude, never stored, never sent
Water boils at a lower temperature the higher you are, so an egg takes longer. To correct for that, the App can read your altitude.
We want to be precise about how narrow this is:
- The App asks iOS for a single location fix, with accuracy deliberately set to the kilometre level — the coarsest useful setting. It does not request precise GPS, and it does not monitor your location continuously.
- From that fix the App reads one number: the altitude in metres. That number is clamped to a sensible range and passed into the cooking-time calculation.
- The latitude and longitude are discarded immediately. They are not written to disk, not logged, and not transmitted.
- The altitude is not stored by us and is not transmitted anywhere. It exists in device memory for the duration of the calculation.
- The permission is When In Use only. The App cannot read your location in the background.
- This is entirely optional. If you decline, the App works normally and simply assumes sea level. You can also set the altitude by hand.
This location data is never given to Google, to advertisers, or to anyone else. The approximate location that advertising derives from your IP address (Section 3.2) is a separate, coarser thing that we neither control nor receive.
3.4 Purchases
The App offers one in-app purchase: Remove Ads, a one-time, non-consumable purchase that turns advertising off permanently. It is not a subscription. Nothing renews and nothing recurs.
- The purchase is processed entirely by Apple through the App Store. We never see your name, your payment card, your billing address or your Apple Account.
- The purchase is verified on your device against Apple's cryptographic signature. There is no receipt-validation server of ours, because there is no server of ours.
- All the App keeps is the fact, held locally, that the entitlement is owned — which is what stops the ads.
- Restoring the purchase on a new device works through your Apple Account and involves only Apple.
Apple's handling of your purchase is governed by Apple's privacy policy: https://www.apple.com/legal/privacy/
3.5 Analytics
The App reports how it is used to Firebase Analytics, a Google service, so that we can tell whether a feature works — whether people finish the walk-through, whether a recipe is ever opened, whether the timer is started and then abandoned.
What is reported. A fixed list of events, decided when the App is built and not extendable at run time: that consent was accepted and which edition of these documents it covered; that a step of the walk-through was reached or the walk-through finished; that a cook was started, finished or cancelled, with the method, doneness and egg size chosen; that a recipe page was opened; that the ad-removal screen was shown; that a purchase completed or a restore found something; that a rewarded video was watched to the end or was not. Alongside them Google's SDK records the usual technical context: an app instance identifier generated on your device, the device model, the operating system version, the App version, the language, the coarse region derived from your IP address, and how long a session lasted.
What is not reported. Nothing you type or measure — not your egg weights, not your custom timer names, not your altitude, not your coordinates, not your IP address as a stored value, and nothing that identifies you as a person. There is no account to attach any of it to.
Joined to advertising. The Firebase property is linked to our AdMob account, so that ad revenue can be read next to the rest of the picture rather than as a number without context.
What reaches us from that link is narrow: for each advertisement shown, one event carrying its format, which network filled it, and the revenue it is estimated to have earned. We never receive your advertising identifier, your IP address, or which advertisements you were shown — that stays with Google.
What the link permits is broader: Google may combine the two sets of data on its own side. How far that goes is your decision, because the App passes your answers from the consent form straight through — advertising storage and advertising user data follow your Purpose 1 answer, and ad personalisation is enabled only where you consented to both profile-building and profile-based ad selection. Refusing does not switch the link off; it narrows what Google may do with what crosses it. Because that combination is permitted at all, Apple counts this as tracking — the test is what may be joined, not what we happen to look at — and it is covered by the App Tracking Transparency prompt you already see. Declining that prompt is a complete answer.
Your choice. In the EEA, UK and Switzerland, analytics storage depends on the same consent you give at first launch: decline and nothing is collected and no identifier is created. Elsewhere it runs by default. Either way, Settings → Privacy options changes the decision at any time.
How long, and on what basis. Event data is kept two months in Google's systems, the shortest window the service offers, after which only aggregate counts remain. The legal basis is consent (Article 6(1)(a) GDPR) where consent is required, and our legitimate interest in knowing whether the App works (Article 6(1)(f)) where it is not. Google acts as our processor for this data and as an independent controller for its own service operation; see https://firebase.google.com/terms/data-processing-terms
3.6 What we deliberately do not do
To leave no ambiguity, the App contains no:
- analytics SDK other than Firebase Analytics, described in Section 3.5 (no Google Analytics, no Amplitude, no Mixpanel);
- crash-reporting or performance-monitoring SDK of ours. Be aware that Google's advertising SDK collects crash logs and performance data of its own, listed in Section 3.2 — we neither receive it nor can switch it off while the App shows ads;
- attribution or install-tracking SDK other than Apple's own SKAdNetwork;
- social-network SDK, and no "sign in with" of any kind;
- advertising network other than Google AdMob;
- server, database, or API of ours that your data could reach.
We also do not access your contacts, calendar, photos, camera, microphone, health data or HealthKit.
4. How we use information, and our legal bases
For users in the EEA, the UK and Switzerland, the GDPR requires us to state a legal basis for each purpose. Here they are.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Running the timer, remembering your settings | On-device preferences (3.1) | Contract (Art. 6(1)(b)) — this is the service you asked for. Note we are not a recipient of this data at all |
| Correcting cooking times for altitude | A single altitude reading (3.3) | Consent (Art. 6(1)(a)) — given through the iOS location prompt, withdrawable at any time in iOS Settings |
| Sending you the alarm and cooking notifications | Local notification scheduling on your device | Consent (Art. 6(1)(a)) — given through the iOS notification prompt |
| Showing personalised ads | Advertising identifiers, IP, ad interaction data (3.2) | Consent (Art. 6(1)(a)) — collected through the Google-certified consent form at first launch, withdrawable at any time |
| Showing non-personalised ads, frequency capping, fraud prevention, aggregate measurement | Advertising identifiers, IP, ad interaction data (3.2) | Legitimate interests (Art. 6(1)(f)) — funding a free app and protecting it from fraud, balanced against your interests. Where local law requires consent for device storage, that consent is collected through the same form |
| Limiting how often ads appear | On-device frequency counters (3.1) | Legitimate interests (Art. 6(1)(f)) — and the interest served here is yours |
| Processing the Remove Ads purchase | Handled by Apple (3.4) | Contract (Art. 6(1)(b)) |
| Proving you accepted this Policy and the Terms | The edition you accepted and the date you accepted it, stored on your device (3.1) | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) — Article 7(1) requires us to be able to demonstrate consent, and recording which edition you saw is what makes that possible |
| Understanding how the App is used | Analytics events and the app instance identifier (3.5) | Consent (Art. 6(1)(a)) where consent is required for storing information on your device, and legitimate interests (Art. 6(1)(f)) elsewhere — knowing whether a feature works is the only way to decide whether to keep it |
| Answering your support email | Whatever you choose to write to us | Legitimate interests (Art. 6(1)(f)) — responding to a person who contacted us |
We do not use your information for automated decision-making that produces legal or similarly significant effects.
5. Permissions the App requests
Every permission is requested in context, with an explanation shown first, and every one of them can be refused without losing access to the App's core function.
| Permission | Why | If you refuse |
|---|---|---|
| Notifications | To tell you the egg is ready when the App is not on screen | The timer still runs and the in-app alarm still sounds while the App is open. You will not get a notification if you leave the App |
| Location (When In Use) | A single reading, for altitude only (Section 3.3) | The App assumes sea level, or you can enter the altitude yourself. Nothing else changes |
| Alarms | So the alarm can reach you through Silent mode and a Focus | The alarm falls back to a standard notification and in-app sound, which Silent mode or Focus may suppress |
| App Tracking Transparency | To allow the IDFA to be used for personalised advertising | You see non-personalised ads instead. The App works exactly the same |
You can change any of these at any time in iOS Settings → Egglaxy.
The App also plays audio in the background — this is how the alarm reaches you when your screen is locked. It uses no microphone and records nothing.
6. Third parties
The App shares data with a deliberately short list.
6.1 Google (AdMob, the User Messaging Platform and Firebase Analytics)
- Who: Google Ireland Limited (for EEA/UK users) and Google LLC.
- What they receive: the categories in Section 3.2 — advertising identifiers, IP address, device and technical information, ad interaction data.
- Why: to select, deliver, cap and measure advertising, and to prevent fraud.
- Their role: Google acts as an independent controller for much of this processing, meaning Google determines its own purposes and is directly accountable to you for them. For certain limited processing Google acts as our processor.
- Consent management: the consent form you see at first launch is Google's User Messaging Platform (UMP), a Google-certified Consent Management Platform registered with the IAB Europe Transparency and Consent Framework (TCF). Your choices are recorded as a TCF consent string on your device and passed to Google and its ad-technology partners.
- Google's advertising partners: where you consent to personalised advertising in the EEA/UK, your consent may extend to Google's ad-technology partners. The current list is shown inside the consent form itself, under the vendor list, and is maintained by Google — we do not control it and cannot restate it accurately here, which is why we point you to the live list.
- Their policy: https://policies.google.com/privacy
Firebase Analytics is the same company and, deliberately, the same account: the analytics property is linked to our AdMob account, so ad revenue is reported alongside app usage. Google acts as our processor for the analytics data under the terms at https://firebase.google.com/terms/data-processing-terms, and as an independent controller for the advertising side. The link permits Google to combine data collected under those two roles. What comes back to us is only ad revenue and format — never identifiers, addresses or the advertisements themselves. Section 3.5 sets this out in full.
To stop the advertising entirely: buy Remove Ads. When the entitlement is owned, no ad request is made at all and the SDK collects nothing for advertising — so there is no ad revenue to report and nothing for the link to carry. Analytics itself continues unless you switch it off in Settings → Privacy options.
6.2 Apple Inc.
Apple is involved in three separate ways, all of them governed by Apple's own privacy policy rather than ours:
- App distribution — Apple knows you downloaded the App, because Apple runs the App Store. We see only anonymous, aggregate App Store analytics (downloads by country, and so on) if we enable them.
- In-app purchase — Apple processes the Remove Ads payment and handles restoring it (Section 3.4).
- SKAdNetwork — Apple's privacy-preserving attribution framework, which reports app installs to advertisers in aggregate, without identifying you.
Apple's policy: https://www.apple.com/legal/privacy/
6.3 Hosting of these documents
We do not run a website. The only pages we publish are the ones you are reading — this Policy and the Terms of Use — served from Firebase Hosting (Google) so that the App can display them and so that they are publicly reachable.
Opening them makes an ordinary web request, and Firebase Hosting keeps standard server logs of it, including your IP address, for a limited period for security and operational purposes. We do not read those logs for any other purpose, and we run no analytics, cookies or trackers on these pages.
6.4 Legal disclosure
We may disclose information if we are legally required to — by a court order, a lawful government request, or applicable law — or where it is necessary to protect our rights, safety or property. Because we hold essentially no data about you, in practice there is very little we could ever disclose.
6.5 Business transfer
If the App is ever sold or transferred, this Policy would transfer with it, and you would be notified through an App update and a notice at this URL before any change in how data is handled.
6.6 No other recipients
We do not share, rent, trade or otherwise disclose personal information to any other party. We have no data brokers, no affiliate networks, no email list and no CRM.
7. International transfers
Google and Apple are global companies and process data in multiple countries, including the United States.
Where personal data of EEA, UK or Swiss users is transferred outside those regions, the transfer relies on the safeguards those companies maintain:
- EU–US Data Privacy Framework (and its UK Extension and Swiss–US framework), under which both Google and Apple are certified;
- Standard Contractual Clauses approved by the European Commission, together with supplementary technical and organisational measures.
We ourselves are based in Ukraine, which the European Commission has not issued an adequacy decision for. In practice this matters very little, because we receive no personal data from you: what reaches us is an aggregate advertising report and, only if you choose to write to us, the contents of your support email.
8. How long information is kept
| Data | Retention |
|---|---|
| On-device preferences and custom timers (3.1) | Until you delete them in the App, reset the App, or uninstall it. Uninstalling removes all of it |
| Accepted edition and acceptance date (3.1) | Same — held until uninstall, as proof of what was agreed to and when |
| Advertising frequency counters (3.1) | Same. Daily counters reset every day; the install date persists until uninstall |
| Altitude reading (3.3) | Not retained at all — it exists only in memory during the calculation |
| Advertising data held by Google (3.2) | Per Google's retention schedule, which we do not control. See Google's privacy policy. TCF consent strings are typically refreshed at least every 13 months |
| Analytics events and the app instance identifier (3.5) | Two months, the shortest window Google offers, after which only aggregate counts remain. Nothing is collected at all if you decline consent |
| Purchase record (3.4) | Held by Apple, tied to your Apple Account, for as long as Apple's policies provide. This is what makes "Restore Purchases" possible years later |
| Support emails you send us | Up to 24 months after the matter is resolved, then deleted |
9. Your rights
Wherever you are located, we honour the rights below. To exercise any of them, contact ancoapps.support@gmail.com.
Please note an unusual practical point: for most of your data there is nothing for us to act on, because we never had it. Your cooking data is on your device and under your control at all times. Where a right concerns advertising data, it is usually exercised most effectively with Google, and we tell you where below.
9.1 Rights under the GDPR (EEA / UK / Switzerland)
- Right to be informed — this Policy provides that information.
- Right of access — you may request a copy of any personal data we hold. In practice we hold almost none: the analytics described in Section 3.5 reach us only as aggregate counts, with no way to single out your device, and everything else stays on your phone. For advertising data held by Google, use Google's own tools at https://myaccount.google.com/ or contact Google directly.
- Right to rectification — your settings are editable in the App at any time.
- Right to erasure — delete your custom timers in the App, or uninstall the App, which removes everything it stored. Resetting your advertising identifier in iOS Settings → Privacy & Security → Tracking / Apple Advertising breaks the link to advertising data held about that identifier.
- Right to restrict processing — refuse consent for ads personalisation, decline the tracking prompt, or purchase Remove Ads.
- Right to data portability — your cooking preferences are simple settings on your device. We hold nothing to port.
- Right to object to processing based on legitimate interests, including profiling for direct marketing. You may object to ads personalisation at any time through Settings → Privacy options in the App. Objecting to direct marketing is absolute — we do not carry out any direct marketing at all.
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. See Section 13 for exactly how.
- Rights related to automated decision-making — we perform none with legal or similarly significant effects.
- Right to lodge a complaint with the supervisory authority in your country of residence.
We will respond within one month of receipt. Where a request is particularly complex, we may extend this by up to two further months, and will tell you about the extension and the reason within the first month, as permitted by Article 12(3) GDPR.
9.2 Rights under the CCPA / CPRA (California residents)
We must be direct about one point, because it is the one that matters most here.
We do not sell your personal information for money. However, showing personalised advertising through Google AdMob constitutes "sharing" personal information for cross-context behavioural advertising as that term is defined in the CPRA. You have the right to opt out of that sharing, and Section 13 tells you how — the fastest route is to decline the App Tracking Transparency prompt, or to purchase Remove Ads.
The categories involved, in the CCPA's own vocabulary:
| CCPA category | Collected? | Shared for cross-context behavioural advertising? |
|---|---|---|
| Identifiers (advertising identifiers, IP address, device identifiers) | Yes, by Google | Yes, unless you opt out |
| Internet or network activity (ad interactions, app usage signals) | Yes, by Google | Yes, unless you opt out |
| Geolocation data — approximate, derived from IP | Yes, by Google | Yes, unless you opt out |
| Geolocation data — precise | No. The altitude reading in Section 3.3 never leaves your device and is never shared | No |
| Commercial information (the Remove Ads purchase) | By Apple, not by us | No |
| Personal identifiers (name, email, address), biometric data, sensitive personal information, education or employment data | No. None of it, ever | No |
Your rights:
- Right to know what categories are collected, used and shared — the table above.
- Right to access the specific pieces held about you. We hold none; for Google's data, use Google's tools.
- Right to delete — uninstall the App, and reset your advertising identifier in iOS Settings.
- Right to correct inaccurate information.
- Right to opt out of sale or sharing — see Section 13.
- Right to limit the use of sensitive personal information — we collect none, so there is nothing to limit.
- Right to non-discrimination — exercising any privacy right will never cause the App to work worse for you. Declining tracking gives you exactly the same App with less relevant ads.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
To exercise these rights, email ancoapps.support@gmail.com. You may use an authorised agent. We will respond within 45 days, extendable by 45 further days where reasonably necessary, as permitted by California Civil Code § 1798.130.
9.3 Rights under other laws
Users in Brazil (LGPD), Canada (PIPEDA), Ukraine ("On Personal Data Protection"), Turkey (KVKK), South Africa (POPIA), Japan (APPI), South Korea (PIPA), Australia (Privacy Act), and US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana — have substantially similar rights, including the right to opt out of targeted advertising. Email us at ancoapps.support@gmail.com naming the law you wish to exercise rights under, and we will respond within the time that law requires.
We honour Global Privacy Control and similar opt-out preference signals where they are technically transmitted to us.
10. How we protect information
The strongest protection here is structural rather than technical: we do not collect your personal data, so we cannot lose it. There is no database of ours to breach, no credentials of yours to steal, and no server of ours to compromise.
Beyond that:
- Data on your device is protected by iOS's own sandbox and file-system encryption, which is tied to your device passcode and to Apple's Secure Enclave.
- All network traffic made by the advertising SDK uses TLS, enforced by App Transport Security.
- Purchases are verified using Apple's cryptographic signatures, checked on-device.
- The App requests the narrowest permission that will do the job — location accuracy is set to kilometre level, not precise GPS, and only "when in use".
- No third-party SDK is present beyond Google's advertising SDK and Apple's own frameworks. Every additional SDK is an additional risk, so we ship as few as the App can function with.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever occurs that affects your rights, we will notify you and the relevant supervisory authority within the time limits the applicable law sets — 72 hours under the GDPR.
11. Cookies and similar technologies
The App is not a website and uses no cookies. It does use technologies that serve a comparable function, and which the ePrivacy Directive treats similarly:
- Advertising identifiers (IDFA, IDFV) — described in Section 3.2.
- Local storage on your device — the settings listed in Section 3.1, and data the advertising SDK writes to cap how often you see an ad and to remember your consent choices.
- The app instance identifier written by Firebase Analytics — described in Section 3.5. It is generated on your device, belongs to the installation rather than to you, and disappears when the App is deleted.
In the EEA and UK, storing or reading information on your device for advertising or for analytics requires consent, which is what the first-launch consent form collects. The same answer governs both: decline it and no analytics identifier is created at all.
The pages carrying these documents set no cookies and run no analytics. They are static files and nothing else — there is no website beyond them.
12. Children's privacy
The App is not directed to children and is not intended for use by children under 13 (or the higher minimum age that applies in your country — 16 in several EEA member states).
- We do not knowingly collect personal information from children.
- The App is not tagged for child-directed treatment under COPPA in AdMob, and it is not part of Apple's Kids category, precisely because it serves general-audience advertising.
- Advertising is served on the basis that the user is not a child.
If you believe a child has used the App and that information about them has been collected, contact ancoapps.support@gmail.com and we will take the steps available to us — which, given that we hold nothing, means helping you reset the advertising identifier and directing your request to Google.
A note for parents: if you hand your phone to a child to time an egg, the practical protections are to purchase Remove Ads (after which no ad is requested at all) or to enable Guided Access in iOS.
13. Your advertising and analytics choices — how to turn them off
This section is the practical one. Every option below is real, works today, and none of them degrades the App.
1. Remove ads permanently — the complete option. Purchase Remove Ads in the App (Settings → Remove Ads). It is a one-time purchase, not a subscription. Once owned, the App makes no ad request at all, so no advertising data is collected from your device by the ad SDK. The purchase restores on your other devices and after a reinstall through Restore Purchases.
2. Withdraw or change consent for personalised ads (EEA / UK / Switzerland). Open Settings → Privacy options in the App. This reopens Google's consent form, where you can change or fully withdraw your choices. Withdrawing consent means you will see non-personalised ads instead — never no ads, unless you take option 1.
3. Decline App Tracking Transparency (all iOS users). When asked whether Egglaxy may track you, choose Ask App Not to Track. To change it later: iOS Settings → Privacy & Security → Tracking → Egglaxy. Turning off Allow Apps to Request to Track at the top of that screen denies it for every app at once.
4. Reset or limit your advertising identifier. iOS Settings → Privacy & Security → Apple Advertising lets you turn off personalised Apple ads. Resetting the identifier breaks the link between you and the advertising profile built against the old one.
5. Opt out with Google directly. Google's own ad settings are at https://adssettings.google.com and https://myaccount.google.com/data-and-privacy.
6. Industry opt-outs. The Digital Advertising Alliance's AppChoices app (https://youradchoices.com/appchoices) and the NAI's mobile opt-out (https://optout.networkadvertising.org/) provide cross-network opt-outs.
7. Switch off analytics. Open Settings → Privacy options — the same form as option 2. Declining consent for storing information on your device stops Firebase Analytics entirely: no events are sent and no app instance identifier is created. In the EEA, UK and Switzerland nothing is collected until you have agreed in the first place. This is the one control that buying Remove Ads does not cover: that purchase stops the advertising, which is a separate thing from the measurement.
A note on what "no ads" means. Options 2 through 6 change how ads are targeted, not whether they appear. Only option 1 — the Remove Ads purchase — stops advertising entirely. We would rather say that plainly than let the opt-out list imply otherwise.
14. Changes to this Policy
We may update this Policy. When we do, we will:
- update the "Effective date" and "Last updated" at the top;
- publish the updated Policy at this same URL, which is the URL the App links to; and
- for material changes — a new third party, a new category of data, a new purpose, or any change that reduces your rights — present the updated Policy on the Consent screen at the next App launch and ask you to accept it before continuing.
Continued use of the App after a non-material update (a typographical fix, a clarification, a reorganisation) constitutes acceptance of the updated Policy.
15. Apple's account-deletion requirement
App Store Review Guideline 5.1.1(v) requires apps that let users create an account to also let them delete it from inside the app.
Egglaxy creates no accounts, so there is nothing on a server to delete. The equivalent control is on your device: delete your custom timers in the App, or uninstall the App, which removes every preference, timer and flag it created. This satisfies both the letter and the purpose of that guideline for our model.
16. Contact us
For any privacy question, data subject request, or to exercise any right in Section 9:
- Email: ancoapps.support@gmail.com
- Post: our postal address, telephone number and email are published on the App's App Store product page in the European Union, as the Digital Services Act requires of a trader. They are also available on request anywhere else.
We aim to acknowledge enquiries within 5 business days and to respond substantively within the limits the applicable law sets — currently one month under the GDPR (extendable by two further months for complex requests) and 45 days under the CCPA / CPRA (extendable by 45 further days). We will tell you in advance if we need an extension, and why.
If you are in the EEA, UK or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. For advertising data, you may also complain to the Irish Data Protection Commission, which is Google Ireland Limited's lead supervisory authority.
This Privacy Policy was last updated on 31 August 2026. The current version is always available at https://egglaxy-prod.web.app/en/privacy and from the App's Consent screen and Settings → Privacy Policy.