egglaxy

Privacy Policy

Effective date: 23 August 2026 Last updated: 31 August 2026

This Privacy Policy explains how Egglaxy ("Egglaxy", "we", "us", "our") collects, uses, stores, shares and protects information when you use the Egglaxy mobile application (the "App") for iOS.

Egglaxy is an egg cooking timer. It has no user accounts, no sign-up, no login and no server of ours. Everything you set inside the App — your last recipe, your custom timers, your alarm tone, your preferences — is stored locally on your device and never reaches us.

There is one important exception, and we want it stated at the top rather than buried: the App is supported by advertising. Advertising is served by Google AdMob, and to serve it Google collects information from your device, including advertising identifiers and your IP address. Section 3.2 describes exactly what that means, and Section 13 describes how to turn it off — including how to remove ads permanently with a one-time purchase.

If you do not agree with this Policy, please do not install or use the App.


1. Who we are (Data Controller)

Operator Egglaxy, an independent app developer based in Ukraine
Privacy contact ancoapps.support@gmail.com
App Egglaxy — egg cooking timer for iOS

For users in the European Economic Area (EEA), the United Kingdom and Switzerland, Egglaxy acts as the Data Controller for the limited categories of personal data described in this Policy.

For advertising, Google acts as an independent controller (or, in some configurations, as a joint controller) for the data it collects through the AdMob SDK. This is explained in Section 6.1 — it matters, because it means some of your choices are exercised with Google rather than with us, and we tell you where.

Users anywhere can write directly to ancoapps.support@gmail.com with any privacy question, and we will respond within the timeframes set out in Section 16.


2. Summary (TL;DR)

Example. You boil a 62 g egg to a soft yolk on a Tuesday morning. The egg's weight, the doneness you picked and the timer you ran are written to your phone and to nowhere else. What Google's advertising SDK learns from that session is unrelated to the egg: it learns that a device with a certain advertising identifier, at a certain IP address, opened an app and had an opportunity to see a banner.


3. Information we collect and where it is stored

We distinguish between four categories.

3.1 Information stored only on your device

The App saves the following on your device. None of it is transmitted to us or to anyone else. It never leaves the device except in an iCloud or iTunes device backup, if you have those enabled — that backup is between you and Apple, and is governed by Apple's privacy policy, not ours.

What Why it is stored
Last recipe cooked (method, doneness, egg weight, egg count, starting temperature) So the App opens on what you cooked last instead of a blank screen
Custom timers you created So your own times survive a relaunch
Alarm tone selection So the alarm sounds the way you chose
Keep-screen-awake, haptics, skip-preparation-steps preferences So the App behaves the way you set it
Guidance mode per cooking method So each method opens in guided or plain-timer mode as you prefer
Whether you completed onboarding So the welcome flow is shown once and never again
Which edition of this Policy and the Terms you accepted, and when So the consent screen is not shown again, so we can prove consent was given, and so we can ask again — and only ask again — when these documents change materially
How often permission explanations have been shown, and when So the App does not ask you for the same permission repeatedly
Advertising frequency counters — session count, first-launch date, ads shown today, cooldown timestamps, and the expiry of any ad-free period earned by watching a rewarded video So the App can enforce its own limits on how often an ad may appear. These counters are a restraint on advertising, not a profile of you, and they stay on the device

We have no technical means to read any of this. There is no endpoint it could be sent to.

3.2 Information collected by Google for advertising

The App integrates the Google Mobile Ads SDK (AdMob). When an ad is requested or displayed, Google — not us — collects and processes information from your device. Based on Google's published documentation for publishers, this includes:

What Google does with it. Google uses this data to select and deliver ads, to cap how often you see the same ad, to measure ad performance, to detect invalid traffic and fraud, and — only where personalised advertising is permitted — to build and use interest profiles for ads personalisation across apps and sites.

Personalised versus non-personalised. Which of those Google may do depends on your choices:

Your situation What Google may do
EEA / UK / Switzerland, consent given for personalised ads Personalised ads, using identifiers and interest profiles
EEA / UK / Switzerland, consent refused Non-personalised or limited ads. Identifiers may still be used for frequency capping, fraud prevention and aggregate reporting — this is a legitimate-interest processing that Google performs; personalisation does not occur
iOS App Tracking Transparency prompt declined The IDFA is not available. Cross-app tracking does not occur. Contextual and non-personalised ads still appear
Remove Ads purchased, or a rewarded ad-free period running No ad is requested at all, so Google collects nothing for advertising in that session

Important: we do not receive this data. We see only aggregate, non-identifying reports in the AdMob console — impressions, clicks, estimated revenue, broken down by country and ad format. Those reports cannot be traced back to you and contain no personal information about you.

Google's own explanations, which we ask you to read because they are the authoritative description of Google's processing:

3.3 Location — used for altitude, never stored, never sent

Water boils at a lower temperature the higher you are, so an egg takes longer. To correct for that, the App can read your altitude.

We want to be precise about how narrow this is:

This location data is never given to Google, to advertisers, or to anyone else. The approximate location that advertising derives from your IP address (Section 3.2) is a separate, coarser thing that we neither control nor receive.

3.4 Purchases

The App offers one in-app purchase: Remove Ads, a one-time, non-consumable purchase that turns advertising off permanently. It is not a subscription. Nothing renews and nothing recurs.

Apple's handling of your purchase is governed by Apple's privacy policy: https://www.apple.com/legal/privacy/

3.5 Analytics

The App reports how it is used to Firebase Analytics, a Google service, so that we can tell whether a feature works — whether people finish the walk-through, whether a recipe is ever opened, whether the timer is started and then abandoned.

What is reported. A fixed list of events, decided when the App is built and not extendable at run time: that consent was accepted and which edition of these documents it covered; that a step of the walk-through was reached or the walk-through finished; that a cook was started, finished or cancelled, with the method, doneness and egg size chosen; that a recipe page was opened; that the ad-removal screen was shown; that a purchase completed or a restore found something; that a rewarded video was watched to the end or was not. Alongside them Google's SDK records the usual technical context: an app instance identifier generated on your device, the device model, the operating system version, the App version, the language, the coarse region derived from your IP address, and how long a session lasted.

What is not reported. Nothing you type or measure — not your egg weights, not your custom timer names, not your altitude, not your coordinates, not your IP address as a stored value, and nothing that identifies you as a person. There is no account to attach any of it to.

Joined to advertising. The Firebase property is linked to our AdMob account, so that ad revenue can be read next to the rest of the picture rather than as a number without context.

What reaches us from that link is narrow: for each advertisement shown, one event carrying its format, which network filled it, and the revenue it is estimated to have earned. We never receive your advertising identifier, your IP address, or which advertisements you were shown — that stays with Google.

What the link permits is broader: Google may combine the two sets of data on its own side. How far that goes is your decision, because the App passes your answers from the consent form straight through — advertising storage and advertising user data follow your Purpose 1 answer, and ad personalisation is enabled only where you consented to both profile-building and profile-based ad selection. Refusing does not switch the link off; it narrows what Google may do with what crosses it. Because that combination is permitted at all, Apple counts this as tracking — the test is what may be joined, not what we happen to look at — and it is covered by the App Tracking Transparency prompt you already see. Declining that prompt is a complete answer.

Your choice. In the EEA, UK and Switzerland, analytics storage depends on the same consent you give at first launch: decline and nothing is collected and no identifier is created. Elsewhere it runs by default. Either way, Settings → Privacy options changes the decision at any time.

How long, and on what basis. Event data is kept two months in Google's systems, the shortest window the service offers, after which only aggregate counts remain. The legal basis is consent (Article 6(1)(a) GDPR) where consent is required, and our legitimate interest in knowing whether the App works (Article 6(1)(f)) where it is not. Google acts as our processor for this data and as an independent controller for its own service operation; see https://firebase.google.com/terms/data-processing-terms

3.6 What we deliberately do not do

To leave no ambiguity, the App contains no:

We also do not access your contacts, calendar, photos, camera, microphone, health data or HealthKit.


4. How we use information, and our legal bases

For users in the EEA, the UK and Switzerland, the GDPR requires us to state a legal basis for each purpose. Here they are.

Purpose Data used Legal basis (GDPR Art. 6)
Running the timer, remembering your settings On-device preferences (3.1) Contract (Art. 6(1)(b)) — this is the service you asked for. Note we are not a recipient of this data at all
Correcting cooking times for altitude A single altitude reading (3.3) Consent (Art. 6(1)(a)) — given through the iOS location prompt, withdrawable at any time in iOS Settings
Sending you the alarm and cooking notifications Local notification scheduling on your device Consent (Art. 6(1)(a)) — given through the iOS notification prompt
Showing personalised ads Advertising identifiers, IP, ad interaction data (3.2) Consent (Art. 6(1)(a)) — collected through the Google-certified consent form at first launch, withdrawable at any time
Showing non-personalised ads, frequency capping, fraud prevention, aggregate measurement Advertising identifiers, IP, ad interaction data (3.2) Legitimate interests (Art. 6(1)(f)) — funding a free app and protecting it from fraud, balanced against your interests. Where local law requires consent for device storage, that consent is collected through the same form
Limiting how often ads appear On-device frequency counters (3.1) Legitimate interests (Art. 6(1)(f)) — and the interest served here is yours
Processing the Remove Ads purchase Handled by Apple (3.4) Contract (Art. 6(1)(b))
Proving you accepted this Policy and the Terms The edition you accepted and the date you accepted it, stored on your device (3.1) Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) — Article 7(1) requires us to be able to demonstrate consent, and recording which edition you saw is what makes that possible
Understanding how the App is used Analytics events and the app instance identifier (3.5) Consent (Art. 6(1)(a)) where consent is required for storing information on your device, and legitimate interests (Art. 6(1)(f)) elsewhere — knowing whether a feature works is the only way to decide whether to keep it
Answering your support email Whatever you choose to write to us Legitimate interests (Art. 6(1)(f)) — responding to a person who contacted us

We do not use your information for automated decision-making that produces legal or similarly significant effects.


5. Permissions the App requests

Every permission is requested in context, with an explanation shown first, and every one of them can be refused without losing access to the App's core function.

Permission Why If you refuse
Notifications To tell you the egg is ready when the App is not on screen The timer still runs and the in-app alarm still sounds while the App is open. You will not get a notification if you leave the App
Location (When In Use) A single reading, for altitude only (Section 3.3) The App assumes sea level, or you can enter the altitude yourself. Nothing else changes
Alarms So the alarm can reach you through Silent mode and a Focus The alarm falls back to a standard notification and in-app sound, which Silent mode or Focus may suppress
App Tracking Transparency To allow the IDFA to be used for personalised advertising You see non-personalised ads instead. The App works exactly the same

You can change any of these at any time in iOS Settings → Egglaxy.

The App also plays audio in the background — this is how the alarm reaches you when your screen is locked. It uses no microphone and records nothing.


6. Third parties

The App shares data with a deliberately short list.

6.1 Google (AdMob, the User Messaging Platform and Firebase Analytics)

Firebase Analytics is the same company and, deliberately, the same account: the analytics property is linked to our AdMob account, so ad revenue is reported alongside app usage. Google acts as our processor for the analytics data under the terms at https://firebase.google.com/terms/data-processing-terms, and as an independent controller for the advertising side. The link permits Google to combine data collected under those two roles. What comes back to us is only ad revenue and format — never identifiers, addresses or the advertisements themselves. Section 3.5 sets this out in full.

To stop the advertising entirely: buy Remove Ads. When the entitlement is owned, no ad request is made at all and the SDK collects nothing for advertising — so there is no ad revenue to report and nothing for the link to carry. Analytics itself continues unless you switch it off in Settings → Privacy options.

6.2 Apple Inc.

Apple is involved in three separate ways, all of them governed by Apple's own privacy policy rather than ours:

Apple's policy: https://www.apple.com/legal/privacy/

6.3 Hosting of these documents

We do not run a website. The only pages we publish are the ones you are reading — this Policy and the Terms of Use — served from Firebase Hosting (Google) so that the App can display them and so that they are publicly reachable.

Opening them makes an ordinary web request, and Firebase Hosting keeps standard server logs of it, including your IP address, for a limited period for security and operational purposes. We do not read those logs for any other purpose, and we run no analytics, cookies or trackers on these pages.

6.4 Legal disclosure

We may disclose information if we are legally required to — by a court order, a lawful government request, or applicable law — or where it is necessary to protect our rights, safety or property. Because we hold essentially no data about you, in practice there is very little we could ever disclose.

6.5 Business transfer

If the App is ever sold or transferred, this Policy would transfer with it, and you would be notified through an App update and a notice at this URL before any change in how data is handled.

6.6 No other recipients

We do not share, rent, trade or otherwise disclose personal information to any other party. We have no data brokers, no affiliate networks, no email list and no CRM.


7. International transfers

Google and Apple are global companies and process data in multiple countries, including the United States.

Where personal data of EEA, UK or Swiss users is transferred outside those regions, the transfer relies on the safeguards those companies maintain:

We ourselves are based in Ukraine, which the European Commission has not issued an adequacy decision for. In practice this matters very little, because we receive no personal data from you: what reaches us is an aggregate advertising report and, only if you choose to write to us, the contents of your support email.


8. How long information is kept

Data Retention
On-device preferences and custom timers (3.1) Until you delete them in the App, reset the App, or uninstall it. Uninstalling removes all of it
Accepted edition and acceptance date (3.1) Same — held until uninstall, as proof of what was agreed to and when
Advertising frequency counters (3.1) Same. Daily counters reset every day; the install date persists until uninstall
Altitude reading (3.3) Not retained at all — it exists only in memory during the calculation
Advertising data held by Google (3.2) Per Google's retention schedule, which we do not control. See Google's privacy policy. TCF consent strings are typically refreshed at least every 13 months
Analytics events and the app instance identifier (3.5) Two months, the shortest window Google offers, after which only aggregate counts remain. Nothing is collected at all if you decline consent
Purchase record (3.4) Held by Apple, tied to your Apple Account, for as long as Apple's policies provide. This is what makes "Restore Purchases" possible years later
Support emails you send us Up to 24 months after the matter is resolved, then deleted

9. Your rights

Wherever you are located, we honour the rights below. To exercise any of them, contact ancoapps.support@gmail.com.

Please note an unusual practical point: for most of your data there is nothing for us to act on, because we never had it. Your cooking data is on your device and under your control at all times. Where a right concerns advertising data, it is usually exercised most effectively with Google, and we tell you where below.

9.1 Rights under the GDPR (EEA / UK / Switzerland)

We will respond within one month of receipt. Where a request is particularly complex, we may extend this by up to two further months, and will tell you about the extension and the reason within the first month, as permitted by Article 12(3) GDPR.

9.2 Rights under the CCPA / CPRA (California residents)

We must be direct about one point, because it is the one that matters most here.

We do not sell your personal information for money. However, showing personalised advertising through Google AdMob constitutes "sharing" personal information for cross-context behavioural advertising as that term is defined in the CPRA. You have the right to opt out of that sharing, and Section 13 tells you how — the fastest route is to decline the App Tracking Transparency prompt, or to purchase Remove Ads.

The categories involved, in the CCPA's own vocabulary:

CCPA category Collected? Shared for cross-context behavioural advertising?
Identifiers (advertising identifiers, IP address, device identifiers) Yes, by Google Yes, unless you opt out
Internet or network activity (ad interactions, app usage signals) Yes, by Google Yes, unless you opt out
Geolocation data — approximate, derived from IP Yes, by Google Yes, unless you opt out
Geolocation data — precise No. The altitude reading in Section 3.3 never leaves your device and is never shared No
Commercial information (the Remove Ads purchase) By Apple, not by us No
Personal identifiers (name, email, address), biometric data, sensitive personal information, education or employment data No. None of it, ever No

Your rights:

We do not knowingly sell or share the personal information of consumers under 16 years of age.

To exercise these rights, email ancoapps.support@gmail.com. You may use an authorised agent. We will respond within 45 days, extendable by 45 further days where reasonably necessary, as permitted by California Civil Code § 1798.130.

9.3 Rights under other laws

Users in Brazil (LGPD), Canada (PIPEDA), Ukraine ("On Personal Data Protection"), Turkey (KVKK), South Africa (POPIA), Japan (APPI), South Korea (PIPA), Australia (Privacy Act), and US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana — have substantially similar rights, including the right to opt out of targeted advertising. Email us at ancoapps.support@gmail.com naming the law you wish to exercise rights under, and we will respond within the time that law requires.

We honour Global Privacy Control and similar opt-out preference signals where they are technically transmitted to us.


10. How we protect information

The strongest protection here is structural rather than technical: we do not collect your personal data, so we cannot lose it. There is no database of ours to breach, no credentials of yours to steal, and no server of ours to compromise.

Beyond that:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever occurs that affects your rights, we will notify you and the relevant supervisory authority within the time limits the applicable law sets — 72 hours under the GDPR.


11. Cookies and similar technologies

The App is not a website and uses no cookies. It does use technologies that serve a comparable function, and which the ePrivacy Directive treats similarly:

In the EEA and UK, storing or reading information on your device for advertising or for analytics requires consent, which is what the first-launch consent form collects. The same answer governs both: decline it and no analytics identifier is created at all.

The pages carrying these documents set no cookies and run no analytics. They are static files and nothing else — there is no website beyond them.


12. Children's privacy

The App is not directed to children and is not intended for use by children under 13 (or the higher minimum age that applies in your country — 16 in several EEA member states).

If you believe a child has used the App and that information about them has been collected, contact ancoapps.support@gmail.com and we will take the steps available to us — which, given that we hold nothing, means helping you reset the advertising identifier and directing your request to Google.

A note for parents: if you hand your phone to a child to time an egg, the practical protections are to purchase Remove Ads (after which no ad is requested at all) or to enable Guided Access in iOS.


13. Your advertising and analytics choices — how to turn them off

This section is the practical one. Every option below is real, works today, and none of them degrades the App.

1. Remove ads permanently — the complete option. Purchase Remove Ads in the App (Settings → Remove Ads). It is a one-time purchase, not a subscription. Once owned, the App makes no ad request at all, so no advertising data is collected from your device by the ad SDK. The purchase restores on your other devices and after a reinstall through Restore Purchases.

2. Withdraw or change consent for personalised ads (EEA / UK / Switzerland). Open Settings → Privacy options in the App. This reopens Google's consent form, where you can change or fully withdraw your choices. Withdrawing consent means you will see non-personalised ads instead — never no ads, unless you take option 1.

3. Decline App Tracking Transparency (all iOS users). When asked whether Egglaxy may track you, choose Ask App Not to Track. To change it later: iOS Settings → Privacy & Security → Tracking → Egglaxy. Turning off Allow Apps to Request to Track at the top of that screen denies it for every app at once.

4. Reset or limit your advertising identifier. iOS Settings → Privacy & Security → Apple Advertising lets you turn off personalised Apple ads. Resetting the identifier breaks the link between you and the advertising profile built against the old one.

5. Opt out with Google directly. Google's own ad settings are at https://adssettings.google.com and https://myaccount.google.com/data-and-privacy.

6. Industry opt-outs. The Digital Advertising Alliance's AppChoices app (https://youradchoices.com/appchoices) and the NAI's mobile opt-out (https://optout.networkadvertising.org/) provide cross-network opt-outs.

7. Switch off analytics. Open Settings → Privacy options — the same form as option 2. Declining consent for storing information on your device stops Firebase Analytics entirely: no events are sent and no app instance identifier is created. In the EEA, UK and Switzerland nothing is collected until you have agreed in the first place. This is the one control that buying Remove Ads does not cover: that purchase stops the advertising, which is a separate thing from the measurement.

A note on what "no ads" means. Options 2 through 6 change how ads are targeted, not whether they appear. Only option 1 — the Remove Ads purchase — stops advertising entirely. We would rather say that plainly than let the opt-out list imply otherwise.


14. Changes to this Policy

We may update this Policy. When we do, we will:

Continued use of the App after a non-material update (a typographical fix, a clarification, a reorganisation) constitutes acceptance of the updated Policy.


15. Apple's account-deletion requirement

App Store Review Guideline 5.1.1(v) requires apps that let users create an account to also let them delete it from inside the app.

Egglaxy creates no accounts, so there is nothing on a server to delete. The equivalent control is on your device: delete your custom timers in the App, or uninstall the App, which removes every preference, timer and flag it created. This satisfies both the letter and the purpose of that guideline for our model.


16. Contact us

For any privacy question, data subject request, or to exercise any right in Section 9:

We aim to acknowledge enquiries within 5 business days and to respond substantively within the limits the applicable law sets — currently one month under the GDPR (extendable by two further months for complex requests) and 45 days under the CCPA / CPRA (extendable by 45 further days). We will tell you in advance if we need an extension, and why.

If you are in the EEA, UK or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. For advertising data, you may also complain to the Irish Data Protection Commission, which is Google Ireland Limited's lead supervisory authority.


This Privacy Policy was last updated on 31 August 2026. The current version is always available at https://egglaxy-prod.web.app/en/privacy and from the App's Consent screen and Settings → Privacy Policy.