Skip to content
CoThrive
Personal HabitsPrivate habits, your rhythm.Habit GroupsStay consistent together.ChallengesFriendly competition.Compound RoutinesStack habits in order.Progress & RemindersStreaks and smart nudges.
How it worksGuidesPricingAboutContact
Get CoThrive

Legal · Privacy

Privacy Policy

How personal data is processed when you use the CoThrive app and website.

Last updated: 21 July 2026

On this page

  1. 1. Data Controller
  2. 2. Scope
  3. 3. What data we process
  4. 4. Purposes and legal bases (GDPR)
  5. 5. Recipients and service providers
  6. 6. International data transfers (especially the USA)
  7. 7. Visibility, groups, and current feature availability
  8. 8. Retention and deletion
  9. 9. No automated decision-making (Art. 22 GDPR)
  10. 10. Age limit and sensitive information
  11. 11. Your rights and choices
  12. 12. Account deletion and provider records
  13. 13. Website: cookies/tracking
  14. 14. Changes
On this page
  1. 1. Data Controller
  2. 2. Scope
  3. 3. What data we process
  4. 4. Purposes and legal bases (GDPR)
  5. 5. Recipients and service providers
  6. 6. International data transfers (especially the USA)
  7. 7. Visibility, groups, and current feature availability
  8. 8. Retention and deletion
  9. 9. No automated decision-making (Art. 22 GDPR)
  10. 10. Age limit and sensitive information
  11. 11. Your rights and choices
  12. 12. Account deletion and provider records
  13. 13. Website: cookies/tracking
  14. 14. Changes

This Privacy Policy explains how personal data is processed when you use the CoThrive mobile app, referral links, support channels, and the website https://www.cothriveapp.com. It is a privacy notice, not a request for consent and not part of the Terms of Service.

1. Data Controller

The controller for personal data processed under this Privacy Policy is Luca Benjamin Stoll. Contact: info@cothriveapp.com.

Postal address & controller details
Controller
Luca Benjamin Stoll
Address
Hilda-Rempel-Str. 10C, 31319 Sehnde, Lower Saxony, Germany
Email
info@cothriveapp.com

No data protection officer has been appointed.

2. Scope

This policy applies to:

  • the CoThrive mobile app on the platforms on which it is offered, including Habits, Habit Groups, Challenges, Compound Routines, friends, nudges, posts, streaks, analytics, referrals, and subscriptions;
  • CoThrive referral and deep links;
  • the CoThrive website, including its contact form;
  • privacy, support, moderation, and legal requests sent to us.

We receive data directly from you, automatically from your app, device, and browser, from other CoThrive users who interact with you, and from sign-in, app-store, subscription, attribution, and infrastructure providers.

3. What data we process

3.1 Account, authentication, and profile data

When you register or sign in using email/password, Apple, or Google, we process in particular:

  • email address (for Apple, possibly a relay address);
  • authentication provider and provider-linked identifiers;
  • display name, chosen by you or initially supplied by Apple or Google;
  • profile picture (optional);
  • Firebase user ID, account-creation and sign-in timestamps, and authentication/security metadata;
  • time zone derived from device or region settings for correct day, reminder, and week logic.

Authentication is handled through Firebase Authentication. Apple and Google separately process the information required for their sign-in services under their own privacy terms.

To support friend discovery, requests, and nudges, CoThrive maintains a limited public-profile record containing your display name, optional profile picture, and whether friend nudges are enabled. The current access rules make this record technically readable to authenticated, App Check-verified CoThrive clients that know or obtain its record identifier; the app presents it through supported social flows.

3.2 Onboarding, Habits, routines, and progress

To configure and provide the app, we process data such as:

  • onboarding answers, including how you discovered CoThrive, selected use cases, selected Habit goal, goal and obstacle identifiers, and any custom goal text you enter;
  • Habit names, descriptions, categories, schedules, weekdays, interval or weekly targets, reminder settings, and completion method;
  • completion, backtrack, streak, consistency, contribution, and analytics data, including relevant local dates and time-zone context;
  • Compound Routine names, child routines, order, schedules, and completion state;
  • local onboarding, configuration, cache, and offline state needed to resume the experience.

CoThrive is not a medical service and does not ask for diagnoses or medical records. Habit names, custom goals, images, and free text can nevertheless reveal health, religious, or other sensitive information. Please do not use CoThrive to store diagnoses, treatment information, or other special-category data.

3.3 Groups, Challenges, friends, and social data

For private social and challenge features, we process in particular:

  • Habit Group and Challenge identifiers, names, descriptions, join codes, members, roles, invitations, schedules, status, and results;
  • friend codes, friend requests, friend connections, and block lists;
  • aggregate progress shown to friends and participant-scoped progress, rankings, streaks, and contributions shown in Groups or Challenges;
  • the relationship between Compound Routines and their child routines.

3.4 Posts, images, and exported content

CoThrive allows image posts in eligible personal Habits, Habit Groups, and Challenges. We process the image in Cloud Storage and post metadata in Firestore, such as creation time, user ID, the relevant Habit, Group, or Challenge, display name, profile image reference, and progress at posting time.

Images are converted to an optimized format before upload. The processing is designed to remove embedded metadata such as EXIF location data; CoThrive does not create a dedicated location field for posts.

When you export or share content, it is processed locally where possible and handed to the operating system share sheet or destination selected by you. The selected third party then processes it under its own terms.

3.5 Reminders, friend nudges, and notifications

We use Firebase Cloud Messaging (FCM) and in-app records for reminders, friend nudges, challenge or group events, and operational notifications. Depending on the feature, we process:

  • one or more FCM tokens, notification permission and preference state, and delivery or read state;
  • notification title, body, timestamp, type, and relevant Group or Challenge reference;
  • for friend nudges, sender and recipient user IDs, sender display name, recipient time zone and local date, status, delivery counters, and an optional Challenge reference;
  • limited current progress and open-Habit information used server-side to decide whether a nudge is available and to select an appropriate message.

3.6 Moderation, reports, support, and contact

Group owners and admins can remove members or posts. CoThrive may also process reports and enforcement records. This can include who performed an action, the affected account or content, the time, a reason or description, screenshots or other evidence, and the outcome.

If you contact us directly or use the website form, we process your name, email address, subject, message, submission time, and delivery status. The website also temporarily uses the requester’s IP address as a rate-limit key to enforce a limit of three contact submissions per ten minutes (stored in Redis when configured, otherwise briefly in server memory).

3.7 Referral and deep-link data

When a CoThrive referral or deep link is created, opened, claimed, or rewarded, we may process:

  • invite code, referrer and referred-user IDs, source, campaign, app version, deep-link URL, and receive, claim, onboarding-completion, qualification, and reward timestamps;
  • referral status, rejection or failure reason, correlation and provider grant IDs, reward days, and reward-expiry information;
  • link, click, attribution, device, operating-system, IP/network, and device-identifier data made available to Singular, including an advertising identifier where the platform and settings provide one.

A pending referral payload is stored locally for up to seven days so that it can be claimed after sign-up and onboarding. Referral-link diagnostics can also be attached to Firebase Crashlytics and, in shortened form, Firebase Analytics for troubleshooting; a referral URL or code may therefore appear in those diagnostics.

3.8 Subscriptions and plan entitlement

Apple or Google processes the purchase itself. Through RevenueCat and the relevant store, we process:

  • CoThrive user ID or RevenueCat app-user ID;
  • store, product, package, entitlement, purchase, renewal, expiry, and promotional-access status;
  • receipt or transaction references and technical diagnostics, but not your full card or bank details.

Paywall and subscription analytics events can include the selected plan, package or product identifier, displayed price and currency, and whether the purchase, restore, or paywall step succeeded.

3.9 Device permissions and local storage

Depending on your use, CoThrive may request camera, photo/media, notification, or save/export access. You can revoke permissions in your device settings, although the related feature may then stop working.

Firestore offline persistence, cached media, app preferences, onboarding state, pending referral data, and analytics queues may be stored locally. You can usually remove local data through operating-system functions or by uninstalling the app.

3.10 Product analytics: PostHog and Firebase Analytics

The current app uses PostHog and Firebase Analytics in parallel. Both initialize as part of app startup; the current release does not provide a separate in-app analytics switch.

Before sign-in, PostHog can associate events with an automatically generated device or installation-level distinct identifier. After sign-in, CoThrive identifies the PostHog profile with the Firebase user ID. PostHog is configured with its EU ingestion endpoint and records app lifecycle and selected product events, for example onboarding and account creation, feature creation or deletion, Habit completion, nudges, paywall and subscription interactions, and aggregate activity counts.

Firebase Analytics records automatic screen views and selected events and user properties, which can include sign-in or sign-up method, onboarding discovery source, selected use-case and goal identifiers, feature actions, referral diagnostics, and error or outcome categories.

The tools can process user or app-instance identifiers, event time, app version, device model, operating-system and locale information, screen or feature context, and network information. Event names and properties are designed not to include post images, contact-message text, or full email addresses.

3.11 Crashes, performance, configuration, and security

We use Firebase Crashlytics, Firebase Performance Monitoring, Firebase Remote Config, and Firebase App Check.

  • Crashlytics receives crash and non-fatal error reports, stack traces, app and device state, the signed-in Firebase user ID, and custom context such as the current screen or relevant Group reference;
  • Performance Monitoring measures app-start, screen, and network performance and can process request timing, app-instance, device, and temporary IP-associated data;
  • Remote Config supplies configuration and feature flags;
  • App Check processes integrity tokens and security signals to distinguish genuine app requests and prevent abuse.

3.12 Website contact and performance data

When you visit the website, Vercel processes request data needed to host and secure it, such as IP address, date and time, requested URL, response status, referrer, and user agent.

Vercel Web Analytics and Speed Insights process page, referrer, browser, device, country/region, and Core Web Vitals or performance data. Website custom events are categorical, such as App Store CTA placement, selected product mode, or contact success/failure. Contact field contents are not attached to analytics events.

3.13 App font delivery

The current mobile app permits Google Fonts to retrieve a font at runtime if it is not already bundled or cached. In that case, Google can receive ordinary connection data such as IP address, request time, app or device network context, and user-agent information. The website itself serves its fonts locally.

4. Purposes and legal bases (GDPR)

4.1 Performance of a contract (Art. 6(1)(b) GDPR)

For:

  • account creation, login, and account management;
  • Habits, Habit Groups, Challenges, Compound Routines, friends, posts, progress calculations, reminders, nudges, exports, and account deletion;
  • processing subscription and promotional-entitlement status and providing paid features;
  • processing a referral that you choose to claim and granting an eligible reward;
  • responding to requests that concern your account or the Services before or during the contract.

The email address or provider account, account identifier, and core feature records are required to create and operate an account. If you do not provide them, we cannot provide the account-based Services. Profile pictures, image posts, friend features, nudges, referrals, exports, and notification permission are optional, but the selected feature cannot work without the data it requires.

4.2 Consent (Art. 6(1)(a) GDPR)

We rely on consent where we ask for it, for example for the operating-system notification permission. You can withdraw consent at any time with effect for the future, including through device settings where applicable.

Access to or storage of information on a device can additionally require consent under Section 25(1) TDDDG or equivalent ePrivacy rules unless an exception applies. A legitimate interest under the GDPR does not replace that consent. The current app release initializes PostHog, Firebase Analytics, and the configured Singular integration at startup and does not yet provide a separate in-app analytics consent or opt-out control; this Privacy Policy itself is not consent.

4.3 Legitimate interests (Art. 6(1)(f) GDPR)

Subject to overriding consent requirements and your rights, our legitimate interests include:

  • IT security, abuse prevention, and infrastructure protection (App Check, rules, and logs);
  • stability, troubleshooting, and performance monitoring;
  • understanding aggregate feature use and improving the Services where the processing can lawfully be based on legitimate interests;
  • protecting the referral program against duplicate, self-referral, and fraudulent claims;
  • enforcing Community Rules, investigating reports, and protecting other users;
  • responding to general enquiries, preventing contact-form abuse, and measuring aggregate website performance.

You can object to processing based on legitimate interests for reasons arising from your particular situation. See Section 11.

4.4 Legal obligations and legal claims (Art. 6(1)(c) and (f) GDPR)

We process or retain data where necessary to comply with law, respond to authorities, preserve evidence, establish or defend legal claims, or meet tax and accounting obligations connected with payments.

4.5 Special-category data

CoThrive is not designed to intentionally process special-category data under Art. 9 GDPR. Do not enter diagnoses, treatment information, biometric identifiers, or other special-category data in Habit names, custom goals, images, descriptions, reports, or support messages. If a future feature intentionally requires such data, we will establish an Art. 9 legal condition and provide any additional notice or explicit-consent flow before enabling it.

5. Recipients and service providers

A current list of sub-processors and instructions for requesting a Data Processing Agreement (DPA) is published on the Subprocessors page at https://www.cothriveapp.com/subprocessors.

5.1 Google Firebase (Google LLC)

Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, Performance Monitoring, Remote Config, and App Check provide authentication, database, storage, backend, notifications, analytics, diagnostics, configuration, and integrity protection.

5.2 PostHog (EU Cloud)

PostHog provides product analytics. CoThrive uses the EU ingestion endpoint hosted in Frankfurt. PostHog processes an automatically generated distinct identifier, the user identifier supplied by CoThrive after sign-in, app and device information, lifecycle and feature events, event properties, and network data needed to receive the events.

5.3 Singular Labs, Inc.

Singular provides referral-link handling, deep-link attribution, and related fraud or delivery diagnostics in builds where the integration is configured. It can process link and campaign parameters, IP/network and device information, app events, and device or advertising identifiers made available by the platform.

5.4 RevenueCat, Inc.

RevenueCat processes app-user identifiers, store receipt and transaction references, product and entitlement state, promotional entitlement periods, and technical diagnostics to manage Pro access, restore purchases, and grant referral rewards.

5.5 Apple and Google

Apple and Google can process data as independent controllers when you use Sign in with Apple, Google Sign-In, the Apple App Store, Google Play, in-app purchases, operating-system push delivery, or platform integrity services. We receive account or purchase status rather than your full payment-card details.

5.6 Google Fonts

Google can receive connection data if the mobile app retrieves a font file at runtime. The website serves its fonts locally.

5.7 Vercel, EmailJS, and Upstash

Vercel hosts, secures, and measures the website through Web Analytics and Speed Insights. EmailJS Pte. Ltd. delivers validated website contact messages and receives the submitted contact fields and delivery metadata for that purpose. When configured, Upstash Redis stores short-lived contact rate-limit counters keyed by IP address.

5.8 Other recipients

We may disclose data to professional advisers, courts, authorities, or other recipients where required by law or necessary to establish, exercise, or defend legal claims. We do not sell personal data and do not use the website for advertising pixels.

6. International data transfers (especially the USA)

Some providers or their support teams process data outside the EU/EEA, including in the USA, Singapore, Israel, or the United Kingdom. PostHog uses an EU ingestion endpoint, but provider support and sub-processors can still involve international access.

Where no EU adequacy decision applies, transfers are based in particular on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where appropriate, supplementary measures. A provider may also rely on an adequacy framework such as the EU–US Data Privacy Framework if it is valid and the recipient is certified. You can request information about the applicable safeguard by contacting us.

7. Visibility, groups, and current feature availability

Personal Habit details and personal posts are intended to remain visible to you unless you export or share them. Friends see limited profile data and aggregate progress, not the full details of your personal Habits.

Habit Groups and Challenges are participant-scoped and normally joined through a code or invitation. Participants can see the profile, progress, rankings, contributions, and posts needed for that shared space. Group owners and admins can also access moderation information and take the actions described in the app.

Join, friend, and referral codes can be forwarded by recipients. Private-by-design does not mean that another participant cannot take a screenshot, export content they are entitled to access, or share information outside CoThrive. Do not upload third-party or sensitive content without the required permission.

8. Retention and deletion

We retain personal data only for as long as needed for the stated purpose, legal obligations, security, or legal claims. The following periods or criteria apply:

  • core account, profile, Habit, membership, friend, Challenge, Compound Routine, post, nudge, and notification data: generally while your account or the relevant feature record exists, followed by the deletion process described in Section 12;
  • a pending referral payload on the device: up to seven days; referral and reward records: while needed to administer the reward, prevent duplicate or fraudulent claims, handle deletion requests, and preserve legal claims;
  • contact-form rate-limit key: approximately ten minutes (Redis when configured, otherwise server memory); contact and support correspondence: until the request is resolved and, where needed, generally up to the end of the applicable limitation period;
  • provider-controlled analytics and diagnostic retention is subject to the relevant project configuration and provider rules, including:
    • Firebase Analytics user- and event-level data: according to the Firebase console setting; standard properties offer provider-configurable periods such as 2 or 14 months, while aggregate reports can remain longer;
    • Firebase Crashlytics crash reports: generally 90 days;
    • Firebase Performance Monitoring: IP-associated data generally 30 days and installation-associated or de-identified performance data generally 60 days;
    • Singular user-level attribution logs: according to the Singular account and contract settings and the purpose; provider-documented export windows vary by record type;
    • PostHog events: according to the CoThrive project retention setting and until no longer required for product analytics; identifiable events are deleted or de-identified when the purpose no longer requires the user link.
  • Firebase Authentication can retain logged IP information for several weeks; after a deletion request, deletion from active systems and backups can take up to 180 days under Firebase’s provider process;
  • purchase, entitlement, accounting, fraud, moderation, and legal-claim records: for the period required by applicable law or reasonably needed to establish or defend claims.

Technical backups, security logs, and data already aggregated or irreversibly de-identified can remain beyond the live-data period where they can no longer reasonably be linked back to you or are required for security and legal compliance.

9. No automated decision-making (Art. 22 GDPR)

CoThrive does not carry out solely automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. CoThrive uses rule-based logic, for example reminders and streak logic.

10. Age limit and sensitive information

CoThrive is intended for users aged 16 and older. Users under 16 must not create or use an account. If we learn that an under-16 user has provided personal data, we will take appropriate steps to restrict the account and delete the data.

The app is a general habit service, not a medical record, treatment, diagnosis, or emergency service. Do not enter special-category data or sensitive information about another person unless you are legally entitled to do so.

11. Your rights and choices

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection. Where processing is based on consent, you may withdraw it at any time with effect for the future. Where processing is based on legitimate interests, you may object for reasons arising from your particular situation; direct marketing, if ever used, can be objected to at any time.

To exercise your rights, including a provider-side deletion request for analytics, attribution, or subscription records, contact info@cothriveapp.com. We may need to verify your identity. You can also change notification permissions in device settings, change supported social settings in the app, delete individual content where available, or start account deletion in the app.

The current app does not provide a separate analytics opt-out control. Contact us if you object to analytics linked to your account; we will assess and implement the request subject to applicable law and the technical capabilities of the providers.

You have the right to lodge a complaint with a data protection supervisory authority. The State Commissioner for Data Protection of Lower Saxony (LfD Niedersachsen) is generally the supervisory authority for the controller, without limiting your right to contact another competent authority.

12. Account deletion and provider records

The in-app account-deletion flow starts a server-side process intended to remove the Firebase Authentication account and linked CoThrive records, including profile and public-profile records, memberships, friends and requests, Habits, Groups, Challenges, Compound Routines, posts, storage files, notifications, nudges, referral records, and related nested data.

Some cleanup steps, especially storage files and cross-record references, are best-effort operations and can fail independently. Provider-controlled records in PostHog, Firebase Analytics, Crashlytics, Singular, and RevenueCat are not all deleted automatically by the current server-side function. They instead follow the retention periods in Section 8 unless you ask us to coordinate provider-side deletion. A limited account-deletion event may also be recorded for reliability and aggregate measurement.

Deleting your CoThrive account does not cancel an Apple App Store or Google Play subscription. Cancel the subscription separately in the applicable store settings to stop future renewals. Deleting a RevenueCat customer record also does not cancel the store subscription.

Data may remain temporarily in provider backups, fraud/security records, or records required by law or legal claims. If the automated process does not complete or you want confirmation, contact info@cothriveapp.com.

13. Website: cookies/tracking

The website uses Vercel Web Analytics and Speed Insights for cookie-free, aggregate usage and performance measurement. Vercel Web Analytics creates a daily, salted hash from request characteristics such as IP address and user agent to distinguish visits; the hash is discarded within 24 hours. Speed Insights measures Core Web Vitals and related technical performance.

The website also records categorical events such as App Store CTA placement, product-mode selection, and contact success or failure stage. It does not use advertising pixels, and contact message text, names, and email addresses are not sent as analytics event properties.

Technically necessary request processing and storage can be used to provide and secure the site. If we introduce non-essential cookies, advertising technology, or device storage/access that requires consent, we will obtain that consent before use and update this policy.

14. Changes

We may update this Privacy Policy when the Services, providers, data flows, or legal requirements change. The current version and its date are published on this page. If a change materially affects how existing personal data is used, we will provide an appropriate additional notice before the change takes effect and obtain consent where the law requires it.

Last updated·21 July 2026
CoThrive

Build consistency with the people who help you keep showing up.

Get CoThrive for iPhoneFree to start. Android is in development.

Product

Personal HabitsHabit GroupsChallengesCompound RoutinesProgress & RemindersPricing

Learn

How it worksGuidesSocial habit trackerAccountability partners

Company

AboutContactPrivacyTermsSubprocessorsImprint
Thrive together.

© 2026 CoThrive. All rights reserved.