Galahat Dev Logo
Galahat Dev
Home
My Alarm App Icon
Official App Policy

My Alarm: Alarm Clock & Task

View on Google Play

Privacy Policy & Data Security Statement

Effective and Last Updated: July 2, 2026

This Privacy Policy and Data Security Statement ("Privacy Policy") applies to the mobile application My Alarm: Alarm Clock & Task (published locally as Alarmım, including all localized global store releases and translated titles, collectively referred to as the "Application"), designed, developed, operated, and exclusively owned by the independent software developer GalahatDev ("Developer"). At GalahatDev, we hold user privacy as a sacred principle and believe that the protection of personal data is a fundamental right in the digital landscape. This document becomes legally binding the moment you download, install, run in the foreground or background, or passively execute the Application via the Google Play Store or any authorized distribution platform. This policy is formulated under the strict principles of the GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and KVKK (Law on Protection of Personal Data) in order to transparently outline the types of processed data, statutory legal grounds, technical architecture of hardware/software permissions, scope of ad and subscription integrations, and your legal rights without leaving room for ambiguity or misinterpretation.

1. Data Controller Declaration, Zero Data Collection Principle, and Account Exemption

Our Application is engineered from the ground up strictly adhering to the industry-standard software engineering paradigms of "Privacy by Design" and "Privacy by Default". Accordingly, our data collection framework is established as follows:

1.1. Account Registration and Authentication Exemption: To utilize any standard or premium features of the Application (creating alarms, setting routines, configuring challenge tasks, etc.), you are never required to provide a name, surname, email address, phone number, username, password, biometric credential, or authenticate via third-party social media profiles (Google, Facebook, Apple, Twitter, etc.). The Application operates on a completely anonymous and accountless foundation.

1.2. Non-Processing of Personal Data and Serverless Architecture: GalahatDev does not own, manage, or operate external remote databases or cloud storage servers. No personal, identifying, or technical telemetry—including your IP address, MAC address, IMEI number, geographical location, web browsing history, contacts, SMS messages, or installed application lists—is ever COLLECTED, PROCESSED, STORED, TRANSMITTED to remote servers, SOLD, or SHARED with third parties, data brokers, advertising agencies, or authorities (except where explicitly mandated by court orders).

1.3. Local Storage Guarantee: All customized alarm schedules, recurring weekdays, volume settings, snooze intervals, personalized ringtones, and progress records belonging to "Challenges / Tasks" modes are stored exclusively on your own mobile device within protected local storage areas (SharedPreferences and SQLite-based Room Database architecture) encrypted and sandboxed by Android. This data remains under your physical ownership. If you uninstall the Application or perform a factory reset, all local records are permanently wiped; it is technically impossible for the Developer to access, restore, or retrieve these local files remotely.

2. Advanced Device Permissions, Hardware Access, and Technical Processing Purposes

To reliably fulfill its core mission of providing an "uninterrupted wake-up" and "unsabotageable alarm" experience under the modern, rigorous security architecture of Android (particularly Android 10 and above), the Application requires user approval for specific hardware and system permissions. The technical rationale for each permission is detailed below:

2.1. Notification Permission (POST_NOTIFICATIONS): Mandatory on Android 13 and above, this permission is used to deliver alerts for upcoming alarms, display alarm interaction cards on the lock screen, and maintain an uninterrupted "Foreground Service" notification to prevent the Android operating system from terminating the alarm background engine. No marketing or behavioral tracking signals traverse this channel.

2.2. Display Over Other Apps (SYSTEM_ALERT_WINDOW / Draw Over Other Apps): When an alarm triggers, this permission allows the full-screen alarm interface to pop up immediately over any active window, whether the device is asleep, locked, or running another application (games, video players, browsers). This ensures the alarm challenge screen reliably presents itself to sleepy users.

2.3. Battery Optimization Exemption (REQUEST_IGNORE_BATTERY_OPTIMIZATIONS): Aggressive battery management implementations such as Android's "Doze Mode" and vendor-specific power algorithms (Samsung, Xiaomi, Huawei, etc.) frequently suspend or kill background timers (AlarmManager). Exempting the Application from battery restrictions is essential to trigger alarms with millisecond precision without inducing excessive or abnormal battery drain.

2.4. Hardware Camera Access (CAMERA): Activated solely when users choose task modes that require scanning a designated barcode/QR code or taking a matching photo of a specific household object (e.g., sink faucet, coffee maker) to silence the alarm. Image data processed through the camera lens is never SAVED to the local gallery and never UPLOADED to remote servers. All verification is handled in real-time on local hardware (CPU/GPU) and instantly purged from memory (RAM).

2.5. Physical Activity and Sensor Access (ACTIVITY_RECOGNITION / Accelerometer): To evaluate optional physical wake-up tasks such as vigorously shaking the phone or taking a set number of steps, the Application accesses raw data from the accelerometer, gyroscope, and step counter sensors. These sensor inputs are parsed in real time solely during an active alarm cycle and are never monitored or recorded in the background for continuous fitness tracking or location logging.

2.6. Advanced App Protection and Device Administrator Permission (BIND_DEVICE_ADMIN): Designed to stop heavy sleepers from instinctively sabotaging their wake-up routines by opening Android system settings to "Force Stop" the Application or uninstall it while the alarm is ringing. When voluntarily granted, this policy prevents the OS from terminating or removing the Application until the ongoing alarm challenge is fulfilled. It does not perform or interfere with any other administrator operations (device wipes, password changes, etc.).

3. Third-Party Advertising Integrations, Data Collection Framework, and Cookies

To maintain the continuous technical operation of the free version, cover digital distribution license expenses, and sustain active development, third-party advertising SDKs are integrated into the Application:

3.1. Google AdMob SDK Integration: The Application serves banner, interstitial, and rewarded ad formats through the infrastructure provided by Google Inc. Google AdMob may automatically collect your device's unique Google Advertising ID (AAID), hardware profile (brand, model, display resolution), carrier identifier, language preference, and advertising interaction metrics to deliver personalized ads or enforce standard frequency capping. This data is collected under Google's independent privacy umbrellas; GalahatDev has no technical capability to view, intercept, or transfer these metrics to private servers. To review AdMob data practices or opt out of personalized tracking, visit the official Google Privacy Policy.

4. In-App Purchases, Subscription Lifecycle, and Financial Data Protection Standards

For users wishing to permanently eliminate advertisements and unlock unlimited access to all wake-up challenges, the Application offers flexible and secure premium options:

4.1. Membership & Package Tiers: Users may acquire auto-renewing 1-Month or 1-Year subscriptions, or purchase a one-time Lifetime Premium tier directly via the in-app billing interface.

4.2. Financial Security & PCI-DSS Compliance: GalahatDev does not operate custom payment gateways or retain card payment records. All purchase verification, invoicing, subscription recurring fees, and cancellations are executed exclusively through the secure, PCI-DSS-compliant Google Play In-App Billing infrastructure. GalahatDev never accesses, stores, or handles credit card numbers, CVV codes, bank account credentials, or billing addresses. All billing records remain entirely under Google Play's regulatory purview.

5. Children's Privacy and Age Limitation Policy

Due to its serverless architecture, our Application does not solicit or collect personal information and does not present safety risks to minors. Nevertheless, in compliance with international legal frameworks such as COPPA (Children's Online Privacy Protection Act) and Google Play Family Policies, children under the age of 13 (or the legal age of majority in your jurisdiction) should only use the Application under the supervision of a parent or legal guardian. If you believe your child has interacted with AdMob identifiers without consent, you may configure child safety profiles via Google Play or contact us directly.

6. User Statutory Rights (GDPR / CCPA / KVKK) and Contact Channels

Although GalahatDev does not maintain remote user databases or store your personal identifiers, you retain complete statutory rights under applicable privacy legislations to query data policies or request the deletion of all local records (achievable instantly by clearing application storage or uninstalling the app). For any legal or technical inquiries, feedback, or concerns regarding permission mechanics, you can reach out through the "Contact" button inside the Application to generate a formal communication via your default email client. Inquiries are reviewed and answered within 30 business days.

7. User Feedback, Bug Reporting, and Telegram API Transmission

Messages submitted to the Developer via the "Suggestions & Bug Report" module are processed exclusively to optimize user experience, diagnose unexpected exceptions, and reinforce software stability. This transmission operates under the following safeguards:

  • Voluntary Submission: The feedback interface is entirely optional. Only the explicit text written and submitted by the user is transmitted.
  • Data Transmission Conduit: Submitted content is securely dispatched to the Developer's authenticated administrative channel over encrypted HTTPS requests powered by the Telegram Bot API infrastructure.
  • Content Restrictions & Safety: No silent background identifiers—such as device serial numbers, contacts, location tags, or saved passwords—are appended to the dispatch. Users are explicitly requested not to submit sensitive personal data, passwords, government IDs, or payment details through this open text form.
  • Scope of Use: Received feedback is examined solely for software debugging, feature iteration, and reliability diagnostics; it is never shared with third parties for commercial profiling, marketing, or advertising endeavors.