This is a courtesy translation; in case of any discrepancy, the Spanish version prevails.
Project Majordomo
Privacy Policy
Last updated: September 5, 2026
1. Who is responsible for your data
Data controller: Luvnus
App: Project Majordomo
Privacy contact: luvnus.es@gmail.com
Luvnus is the controller responsible for this app; Project Majordomo is the name under which it is distributed.
2. What Project Majordomo is
Project Majordomo is a personal mobile app with several independent tools: calendar, tasks, weekly planner, clock (timer, Pomodoro, and stopwatch), chess, chess clock, QR code scanner, calculator, and flashlight.
Everything you write stays on your phone. There are no user accounts, no sign-up, your agenda is not synced with any server, and we do not share your data with anyone for commercial purposes.
That said, the app does collect usage statistics and some minimal technical data. This policy explains exactly what and why.
3. What data we process
We process three types of information, none of which includes the content you write:
- Usage statistics: which parts of the app are used and with which settings.
- Technical operating data: crash reports.
- Minimal data to deliver distant reminders, if the app needs to back them up on a server.
The content of your events, tasks, notes, meals, games, and scanned codes never leaves your device.
4. Usage statistics (Firebase Analytics)
We use Firebase Analytics, from Google, to understand which parts of the app are actually used.
What we deliberately collect:
- Which module you open (calendar, tasks, clock, chess…).
- Which mode you use within a module: schedule or meals in the planner, basic or scientific in the calculator, steady or intermittent in the flashlight, timer, Pomodoro, or stopwatch in the clock.
- In chess, whether you play against the machine or another person, and at what difficulty level.
- Which time control you choose on the chess clock.
- Important actions: creating, editing, or deleting an event; completing a timer or a Pomodoro session; scanning a code.
- The language and visual theme you have selected.
- Whether you grant or deny the permissions the app requests.
- Whether you open a notification, and of what type it was.
- Errors, grouped by category (for example, "failure reading from storage"), never with their message.
All of this data falls into closed categories. The app cannot send free text to Firebase: technically, no field exists that would allow it.
What Firebase collects automatically, without us requesting it:
- A pseudonymous install identifier (
app_instance_id), generated on install and lost on uninstall. - Lifecycle events: first open, usage session start, app update, and app uninstall.
- Platform, operating system version, app version, language, and device model.
- The country from which the app is used, inferred from the IP address. That IP address is used solely to infer the country and is not retained as part of the reports.
We have disabled the collection of detailed location data, so your city or your location is not collected.
We cannot disable the install identifier while using Firebase Analytics. That is the reason this app cannot claim to "collect no data at all".
5. What we NEVER collect
We do not send to any analytics service or any server:
- Titles, descriptions, notes, or locations of your events.
- The text of your tasks or your lists.
- The menus or meals in your planner.
- The content of the QR codes you scan, or the web addresses they contain.
- The operations or results of the calculator.
- The moves, positions, or names of your chess games.
- The recurrence rules of your events, their exceptions, or their individual edits.
- The internal identifiers of your events or their alerts.
6. Reminders and notifications
Calendar reminders, timers, and Pomodoro sessions are scheduled on your own device. The text you see in those notifications comes from what you wrote and never travels to any server.
On iPhone with iOS 26 or later, and only if you authorize it, timers may ring through AlarmKit, Apple's alarm system, so they ring even if your phone is on silent. That authorization is always requested with an explicit tap and only affects the timer.
7. Remote backup of reminders
Operating systems limit how many notifications an app can have scheduled in advance. If you do not open the app for months, the most distant reminders might not end up ringing.
To cover that case, the app can rely on its own server (Supabase) that acts as a last-resort alarm clock.
What that server receives:
- An anonymous install identifier. This is not an account: it carries no name, no email, no password, no data of yours. It is created automatically and is lost if you uninstall the app.
- The platform (iOS or Android).
- A technical identifier used to send you a notification (push token).
- Your time zone.
- The date up to which your device already has its own alerts scheduled.
- For each alert that needs backing up: a technical key and the exact date and time it must ring, plus its delivery status.
What it does NOT receive: the title, the text, the location, the notes, the recurrence rule, or any other content of your events. With what is stored on that server your agenda cannot be reconstructed: it is only known that an anonymous install has an alert due at a given time.
When that alert is sent, the message you receive is always the same and is generic:
Reminder — You have a reminder. Open the app to see it.
The app then resolves, on your device, which event it refers to.
This backup is a mechanism separate from the local notifications described in the previous point. If it is unavailable, your local notifications keep working exactly the same.
8. Third-party services
Not all of them have the same level of access. This is exactly what each one sees:
| Service | Purpose | What it receives |
|---|---|---|
| Google — Firebase Analytics | Usage statistics | The events described in point 4 and Firebase's automatic data. Never your content |
| Google — Firebase Crashlytics | Crash reports | Technical crash data and three app-version identifiers. We do not send your own identifiers or browsing traces |
| Supabase | Remote backup of reminders | Only what is described in point 7 |
| Expo — push notification service | Delivering the generic alert | The delivery identifier and the generic text |
| Apple (APNs) and Google (FCM) | Notification transport | The infrastructure through which that generic alert travels to your phone |
Apple and Google act here purely as transport: it is the mandatory path for a notification to reach a mobile phone.
9. Permissions
The app requests only these permissions, and always as a result of an action you take:
- Notifications: to show you reminders, timers, and Pomodoro alerts.
- Exact alarms (Android): so a timer rings at the exact minute. Without it, the system may delay it by up to an hour.
- Alarms (iOS 26 or later, optional): so timers ring even if the phone is on silent.
- Camera: solely to scan QR codes. Images are not saved or sent anywhere.
- Vibration, internet access, and audio settings: technical permissions that do not access any personal information.
You can withdraw any of these permissions from your device settings. The app will keep working, with the corresponding functionality disabled.
10. How long we retain data
Remote backup of reminders (technically defined periods):
- An alert that has been delivered or has failed is deleted 30 days later.
- An alert whose time passed more than 7 days ago is deleted.
- An alert that exhausts its delivery attempts is deleted.
- An install with no activity for 12 months is deleted, along with everything associated with it, provided it has no pending alert left.
Usage statistics (Firebase Analytics): event-level and install-level data is retained for 14 months, after which Google deletes it. Aggregated reports, which no longer allow a specific install to be distinguished, may be retained for longer.
Crash reports (Firebase Crashlytics): retention is determined by Google's platform. The exact period is yet to be confirmed.
Data on your device: it remains for as long as you have the app installed. It is completely deleted when you uninstall it.
11. Security
- The content of your calendar, your tasks, and your notes never leaves the device.
- The anonymous remote-backup session is stored in the system's secure storage (Keychain on iOS, Keystore on Android), not in a regular file.
- The backup server enforces rules that prevent one install from accessing another install's data.
- Communications are encrypted using HTTPS.
12. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by writing to luvnus.es@gmail.com.
You should be aware of a particularity of this app: there are no user accounts. The identity used for the remote backup is anonymous and is not linked to your name, your email, or any data that identifies you. Because of this, in practice:
- We cannot locate your data based on your name or email, because we do not have them.
- The most direct and complete way to erase everything is to uninstall the app: this deletes the content on your device, invalidates the install identifier, and causes its remote data to expire.
- If you want to exercise a right over the remote data of a specific install, you will need to provide us with the corresponding anonymous identifier so we can locate it.
You can also withdraw the permissions described in point 9 at any time, and file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if you believe we have not addressed your rights.
13. Minors
The app is not specifically directed at children under 14, does not request any identifying personal data, and does not allow the creation of a public profile or communication with other people.
14. Advertising and tracking
The app does not show advertising and does not track you across apps or websites. Specifically:
- We do not use Google Signals.
- We do not use personalized advertising.
- We do not use any advertising identifier (the
AD_IDpermission is removed on Android; on iPhone we do not request tracking permission, so we do not access the IDFA). - We do not use User-ID or any identifier of our own to recognize you.
- We do not perform remarketing or build advertising audiences.
Be precise when reading this: it means we do not use your data for advertising or advertising-related tracking. It does not mean no identifier exists at all: Firebase Analytics generates a pseudonymous install identifier, as explained in point 4.
15. Changes to this policy
If we change what the app collects, we will update this policy and its date. Relevant changes will be announced within the app itself or on the store listing.
16. Contact
Luvnus — luvnus.es@gmail.com
