Privacy Policy — Botano Shift Alarm
Thank you for using Botano Shift Alarm. This document explains what data the app touches, why it needs it, and what we cannot see at all.
In one sentence
Everything you create in this app — alarms, schedule marks, notes — stays on your own phone. It is never uploaded to any server, and the developer cannot see it.
Only two outside services ever touch information from your device: Google's advertising service (section 3) and payment processing when you buy membership (section 4). Neither of them receives your alarms or your schedule.
Holiday data is downloaded from public files, and nothing about you is sent when it is (section 2). Automatically marking holidays as days off works for Taiwan only, and is off by default everywhere else.
1. What you create
This includes:
- Alarm settings (time, repeat rules, sound, vibration)
- Working / day-off / shift marks on the calendar
- Notes you write yourself
- App preferences
All of this is stored locally on your device. There is no registration, no sign-in and no cloud sync, and the developer has no way to read any of it.
(If you buy membership, only the fact that you bought it is stored with an outside service, so that it can be restored when you change phones. Your alarms, schedule and notes are not there — see section 4.)
Uninstalling the app deletes all of it. We hold no backup and cannot recover anything for you. That is the price of not uploading — and also the point of it.
About backup files
The app can export and import a backup. The file contains the data listed above, and you decide where it goes and who sees it:
- Save it to your device, and the file sits in your own storage
- Send it somewhere through the share sheet (cloud storage, a messaging app), and that data enters the control of that service, under its privacy policy
Either way, the developer never handles the file and never receives it.
2. Network connections
The app connects to the network in these situations:
(a) Loading ads
See the next section. This stops once you buy membership.
(b) Ad consent settings
Before any ad is loaded, the app asks Google whether users in your region must be asked for advertising consent first (the EU and the UK require this). The answer is based on your IP address; the app never reads your location and sends nothing else. A consent form appears only where one is required — elsewhere you will never see it. See section 3.
(c) Checking whether you have bought membership
A request to RevenueCat, described in section 4. It sends a random identifier, not anything about you personally.
(d) Holiday data
Which source is used depends on the region you pick under Settings → Holiday region:
- Taiwan: the government holiday calendar, used to mark national holidays and make-up workdays
- Everywhere else: Google's public holiday calendar, used for holiday names only (for example "Christmas Day"). Days are never marked as off automatically from this source.
Both are public static files, and nothing about you is sent — not your alarms, not your marks, not a device identifier, not your location. As with any network request, Google's copy sees your IP address, and the URL reveals which region you selected.
The sync runs at most once every 30 days, and only while you have the app open.
Settings has two switches ("Show holiday names" and "Mark holidays as days off"). With both switched off, no request of this kind is ever made — the app falls back to its built-in rules, and alarms are unaffected.
3. Third-party service: Google AdMob (advertising)
Users who have not bought membership see ads, served by Google AdMob.
To deliver ads, Google accesses information on your device, which may include:
- Advertising ID
- Basic device and app information (model, OS version, language, approximate region)
- Ad impressions and clicks
This data is collected and used by Google and is not passed to the developer. The developer sees only aggregated revenue statistics, which cannot be traced to any individual user.
For how Google uses this data, see:
You can limit ad tracking: Android's Settings → Google → Ads lets you delete your advertising ID and turn off ad personalisation. You will still see ads afterwards, just less relevant ones.
Buying membership removes ads entirely, and the ad SDK is then no longer loaded.
4. Payment data when you buy membership
Purchases are completed entirely on Google Play's own screens.
You never enter card details inside this app, and the developer never sees your card number, billing address or any payment details. Google handles that data under its own privacy policy.
RevenueCat
To remember that you have purchased, the app uses RevenueCat to verify and store your purchase status. It receives:
- A random identifier generated by the app to represent "the user of this device". It is not linked to your name, email address or Google account
- Purchase records: which item, when it was bought, whether it is currently active, whether it was refunded
- Basic device and platform information (operating system, app version, country/region)
It does not receive your alarms, your schedule or your notes, and it does not receive your payment method.
This service exists so that your purchase can be restored after you change phones or reinstall the app. If the record lived only on your phone, it would be deleted along with the app.
Related policies:
Refunds
Refunds are handled by Google Play; the developer does not handle your money. Once a refund completes, membership is removed the next time the app checks your purchase status.
5. Feedback
When you choose to use the feedback feature, the app opens your own email client with the subject line, basic device details (model, OS version, app version) and your purchase identifier (the random string described in section 4) pre-filled.
You decide what the message says, and nothing is sent until you send it. You can delete all of that before sending, and doing so does not affect whether your message is received. Messages received are used only to reply and to improve the app.
6. Permissions the app requests, and why
None of these are used to collect data. They are what it takes to wake you at the time you asked for:
| Permission | Why it is needed |
|---|---|
| Exact alarms | So the alarm rings at the minute you set, instead of being delayed by tens of minutes |
| Full-screen notifications | To show the ringing screen directly while the screen is locked |
| Notifications | To show the ringing notification and membership expiry reminders |
| Start at boot | To reschedule your alarms after a restart. Without it, the alarm on the night you restart will not ring |
| Wake lock | To stop the system sleeping and cutting off the sound while the alarm rings |
| Foreground service | To keep playing the sound while ringing, without being reclaimed by the system |
| Vibrate | To vibrate while ringing (can be turned off per alarm) |
| Ignore battery optimisation | To stop power-saving features from disabling alarms |
| Network | The connections described in section 2 |
| Read the audio file you choose | To read the file when you set a custom sound. The app only touches the one file you explicitly choose; it does not browse your music library |
| Display over other apps | To show the ringing screen while you are using your phone. Without it, an alarm only appears as a notification that you must open to stop |
About the copy of your custom sound
When you choose an audio file as your alarm sound, the app copies it into its own storage and plays that copy from then on.
There are two reasons, both about the alarm actually being able to ring: after a restart, the original file cannot be read until you unlock the screen; and if you later delete or move that track, or it lives on a memory card you remove, the sound would stop working.
That copy stays on your own phone and is never uploaded anywhere. When you change your alarm sound, copies no longer used by any alarm are deleted the next time you open the app; uninstalling removes them all.
7. What we do not do
Stated explicitly, to avoid any misunderstanding:
- No account system — no registration or sign-in, not even for membership (see section 4: it uses a random identifier, not an account)
- No analytics (no Google Analytics, no Firebase, nothing of that kind)
- No crash reporting
- No location data
- No access to contacts, call logs, messages or photos
- Nothing is sold — the developer holds no data that could be sold
8. Children's privacy
This app is not designed for children under 13 and does not knowingly collect personal data from children.
9. Data retention and deletion
- What you create: kept on your device until you delete the alarm, clear app data, or uninstall the app
- Advertising data: retained and deleted by Google under its own policy; you can control it through the Android ad settings described above
- Purchase records: retained by Google Play and RevenueCat under their respective policies. This record deliberately outlives the app on your device — that is exactly why your purchase can be restored when you reinstall or change phones
The developer stores no data that could identify you.
10. Changes to this policy
If this policy changes, the "last updated" date at the top will be updated. Significant changes will also be explained inside the app.
11. Contact
Contact address for this policy: botanodev@gmail.com