Privacy Policy

Last Updated: February 21, 2026

This Privacy Policy explains how Marit (“Marit,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Marit mobile app and related services (the “Service”). This Policy is intended to support users in the United States, European Union, and Canada, including GDPR and CCPA/CPRA requirements.

1. Information We Collect

1.1 Information you provide

  • Account info (email, name if provided)
  • Authentication info (if you use Google Sign-In, we receive info such as your email and basic profile details depending on your Google settings)
  • Profile photos (captured via your device camera or selected from your photo library)
  • Wellness settings and preferences you enter (sleep schedule, hydration inputs like height/weight/sex/activity level, movement reminders, eating cutoff, screen/social limits, gentleness level)
  • Custom reminders and routines you create (“User Content”)
  • Support requests and communications

1.2 Information collected automatically

  • Device information (device type, OS version, app version)
  • Identifiers (IP address, device identifiers as permitted by your OS)
  • Usage data (screens viewed, feature interactions, timestamps, crash logs, performance data)
  • Approximate location derived from IP (and precise location only if you grant permission)

1.3 Information from third parties

  • Authentication providers (e.g., Google)
  • Analytics, crash reporting, and infrastructure providers (as we add them)

2. How We Use Information

We use your information to:

  • Provide and operate the Service (authentication, notifications, schedules)
  • Personalize your experience and generate reminders
  • Improve the Service (analytics, debugging, performance, feature development)
  • Provide customer support
  • Maintain security and prevent fraud/abuse
  • Comply with legal obligations

3. Legal Bases for Processing (EEA/UK)

For users in the EEA/UK, we process personal data based on:

  • Contract necessity (providing the Service)
  • Legitimate interests (security, improvement, analytics where permitted)
  • Consent (where required, e.g., certain marketing or non-essential cookies)
  • Legal obligations

4. How We Share Information

We may share information with:

  • Service providers (hosting, analytics, crash reporting, email support tools) under contractual safeguards
  • Payment platforms (Apple/Google) for purchases (we don’t receive your full payment card details)
  • Legal and safety disclosures when required by law or to protect rights/safety
  • Business transfers (merger, acquisition, asset sale)

We do not sell personal information for money. If we ever “sell” or “share” under CCPA definitions (e.g., cross-context behavioral advertising), we will provide the required opt-out mechanisms.

5. Cookies and Tracking

We may use cookies/SDKs for:

  • Authentication/session management
  • Analytics and crash reporting
  • Preference storage

Where required (e.g., EU), we will provide a consent mechanism for non-essential tracking.

6. Data Retention

We retain personal information as long as needed to:

  • Provide the Service
  • Comply with legal obligations
  • Resolve disputes and enforce agreements

You can request deletion (see Section 9). Some data may persist briefly in backups.

7. Security

We use reasonable technical and organizational safeguards (encryption in transit, access controls, monitoring). No system is 100% secure, and you use the Service at your own risk.

8. International Transfers

If you use the Service from the EU/UK, your data may be processed in the United States or other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.

9. Your Privacy Rights

9.1 GDPR/EEA rights

You may have rights to:

  • Access, correction, deletion
  • Restrict/oppose processing
  • Data portability
  • Withdraw consent
  • Lodge a complaint with a supervisory authority

9.2 California (CCPA/CPRA) rights

California residents may have rights to:

  • Know/access categories and specific pieces of personal info collected
  • Delete and correct personal info
  • Opt out of “sale”/“sharing” (if applicable)
  • Non-discrimination for exercising rights

9.3 Canada (PIPEDA) rights

Canadian users can request:

  • Access to personal info
  • Corrections

How to exercise rights: email us at privacy@themaritapp.com. We may verify your identity.

10. Children’s Privacy

Marit is not intended for children under 13 without parental consent and supervision. We do not knowingly collect personal information from children under 13 without appropriate consent. Parents/guardians may contact us to request access or deletion of a minor’s information.

11. Changes to this Policy

We may update this Privacy Policy. We will update the “Last Updated” date and may provide additional notice for material changes.

12. Contact

Privacy questions or requests:

Email: privacy@themaritapp.com