Your posture data deserves careful handling

1. Information we collect

Account and sign-in information

When you sign in with Apple or Google, Raffi receives the information that provider makes available, which may include your display name, email address or Apple private relay address, profile photo URL, provider identifier, and a Firebase Authentication user ID. We do not receive your Apple or Google password.

Onboarding and personalization information

Raffi may store the answers you provide about your age, posture goals, situations where posture tends to slip, coaching preference, and an optional health or comfort consideration. We use these answers to create a safety level and personalized exercise plan. These details are wellness information and are not a medical record or diagnosis.

Posture and exercise information

We may store your derived posture scan measurements and score, scan method and algorithm version, daily exercise plans, scheduled exercise times, completion and validation status, posture session summaries, upright time, nudges, streak dates, and progress totals. A skipped scan is recorded as a preference so Raffi does not require it again.

Preferences and focus settings

We may store your theme, reminder setting, AirPods monitoring setting, Live Activity setting, coaching style, app-lock status, break interval, unlock exercise type, and an opaque Screen Time selection token needed to restore your chosen app-lock configuration. Raffi does not use this token to read the content of other apps, websites, messages, or browsing activity.

Subscription information

Apple processes App Store purchases and payment details. Raffi does not receive or store your payment card number. We receive purchase and entitlement information needed to unlock Raffi Pro. RevenueCat receives an app user identifier linked to your Firebase user ID and subscription receipt or entitlement data so purchases can be validated and restored across devices.

Device, website, and support information

Firebase and hosting providers may automatically process technical information such as IP address, browser or device type, operating system, request timestamps, app identifiers, diagnostic events, and security logs. If you contact us, we process your email address, message, screenshots, and any device details you choose to send. The Raffi website does not use advertising cookies or behavioral advertising.

2. Camera, TrueDepth, AirPods, and Screen Time

Camera, Vision, and TrueDepth

Raffi uses the front camera, Apple Vision, and, on supported devices, TrueDepth or ARKit signals to create a posture baseline and verify guided movements. Processing occurs in real time on your device. Raw frames and depth maps are discarded after processing and are not sent to Raffi, Firebase, RevenueCat, or advertisers. Raffi does not perform identity recognition or create a biometric identity profile.

AirPods motion

If you enable AirPods posture monitoring, supported AirPods motion sensors provide head-orientation data. Raffi uses this live signal on your device to estimate neck angle, update a Live Activity, and provide limited posture nudges. Raw motion streams are not uploaded. Derived daily summaries and preferences may be synchronized to your account.

Screen Time and app locking

If you enable Focus features, Raffi uses Apple Family Controls, Managed Settings, and Device Activity APIs to shield apps you choose after a configured interval. Apple provides opaque authorization and selection data; Raffi does not receive the private content of those apps. App-lock configuration may sync through Firestore so it can be restored for your account.

Notifications and Live Activities

Exercise reminders and posture nudges are scheduled or posted through Apple notification services based on your settings. Reminder text is generated by Raffi. You can disable notifications or Live Activities in Raffi or iOS Settings.

3. How we use information

We process information to:

Depending on where you live, our legal bases may include performing our agreement with you, your consent for optional permissions, our legitimate interests in operating and securing Raffi, and compliance with law. You may withdraw permission for optional device features at any time, although the related feature may stop working.

4. Service providers and sharing

We do not sell your personal information and do not share it for cross-context behavioral advertising. We disclose only what is reasonably necessary to operate Raffi:

These providers process information under their own terms and privacy commitments. We do not authorize them to use Raffi account data for their own advertising.

5. Storage, retention, and security

Raffi stores local data in protected iOS application storage and synchronizes account data to Google Firestore under your Firebase user ID. We keep account data while your account is active or as needed to provide the service. Support messages, security logs, purchase records held by Apple or RevenueCat, and backups may be retained for a reasonable period where necessary for fraud prevention, accounting, dispute resolution, or legal compliance.

When you delete your account in Raffi, the app requests deletion of your Firestore documents and Firebase Authentication account and clears Raffi’s local account data. Apple purchase history and records independently maintained by Apple or RevenueCat are governed by their retention obligations and may not be deleted by Raffi.

We use reasonable administrative and technical safeguards. Firebase states that covered services encrypt data in transit and services including Firestore and Firebase Authentication encrypt data at rest. No system can guarantee absolute security, so keep your device and Apple or Google account protected.

6. Your choices and rights

You can:

To make a privacy request, email wordcards.helpdesk@gmail.com with the subject “Raffi Privacy Request.” We may need to verify that the request relates to your account. You may also have the right to complain to your local data protection authority, including Turkey’s Personal Data Protection Authority or the authority in your EEA or UK country.

Raffi does not currently respond to browser “Do Not Track” signals because the website does not perform behavioral advertising or cross-site tracking.

7. Children

Raffi is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If local law requires a higher minimum age for independent consent, a parent or guardian must provide any required authorization. Raffi uses the age entered during onboarding to apply age-appropriate plan and safety behavior. Contact us if you believe a child provided information without valid permission.

8. International transfers

Raffi is operated from Turkey, while Firebase, Apple, RevenueCat, and other providers may process information in the United States and other countries. Those countries may have different data protection laws. Where required, providers use contractual and legal safeguards for international transfers.

9. Updates to this policy

We may update this Privacy Policy as Raffi changes or legal requirements develop. We will revise the date above and, for material changes, may provide notice in the app or on the website. Please review this page periodically.

10. Contact us

Batuhan Bayır · Raffi

Dumlupınar Mh. Ilıca Sk. Demir Çağla Apt. No:2/6
Nilüfer, Bursa 16285, Turkey

wordcards.helpdesk@gmail.com