Next10. Back to Home

Privacy Policy

Effective Date: 26.08.2026

This privacy policy explains how Next10 collects, uses, stores, and protects your personal data when you use our app. We built Next10 to help you track your habits and goals, and we take your privacy seriously. Please read this policy carefully to understand your rights and how your data is handled.

Contents

  1. Data Controller
  2. What Data We Collect
  3. Purposes of Processing & Legal Basis
  4. Sub-processors (Third Parties We Use)
  5. International Data Transfers
  6. Data Visible to Other Users
  7. Data Retention & Account Deletion
  8. Children's Privacy
  9. Leaderboard Processing
  10. Your Rights
  11. Security
  12. Changes to This Policy

1. Data Controller

The controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:

Nazar Mishchenko
Email: nazar.mischenko13@gmail.com

For any questions about this privacy policy or to exercise your data protection rights (see Section 10), you can contact the above email address at any time.

Since Next10 is currently operated by an individual rather than a registered company, no separate Data Protection Officer (DPO) has been appointed — this is not legally required at your current scale under GDPR (a DPO is mandatory only for large-scale systematic monitoring or large-scale special-category data processing, which doesn't apply here).

2. What Data We Collect

2.1 Account & Authentication Data

Collected via Supabase Authentication when you register:

  • Google Sign-In: your Google account email and name
  • Apple Sign-In: your Apple ID email (or Apple's private relay email) and name
  • Email/password: the email and password you provide

Purpose: to create and secure your account, and to verify your identity when you sign in. Your password is hashed and stored securely by Supabase Authentication and is never accessible in plain text by us.

2.2 Public Profile Data

Visible to other users (to friends, or to any user if your profile is not set to private) — stored in our profiles table:

  • Nickname (display name), including a lowercase version used to make your nickname searchable by other users
  • Profile photo
  • Account creation and last-updated timestamps
  • Whether your account is private
  • Your pinned friends
  • Computed completion statistics only: daily, weekly, monthly, and yearly completion percentages, and your current streak — shown as raw numbers only

Purpose: to let you build a public profile, be found by other users, and show your progress to friends without exposing what your goals or habits actually are.

2.3 Private App Data (Habits & Goals)

Stored in our goals and completions tables — never visible to any other user, including friends. This data exists solely so your habits and goals are preserved and synced if you switch devices:

  • Your name, app theme, onboarding status, and a copy of your profile photo
  • Your full goals and habits: titles, schedules, reminder times, icons, deadlines
  • Your complete habit completion history

Purpose: to enable cross-device sync, so that if you switch phones or reinstall the app, all of your habit and goal data is restored exactly as you left it.

2.4 Social / Friends Data

  • Friend connections and the date they were formed
  • Friend requests: sender's nickname, profile photo, and timestamp

Purpose: to power the friends and social features of the app.

2.5 Data Stored Locally Only (never sent to our servers)

Vacation mode dates and app language preference stay on your device only.

2.6 A Note on Free-Text Fields

Habit and goal titles are free text you choose yourself. If you voluntarily include sensitive information in these fields (e.g., referencing a health condition or medication), it is stored privately as described in 2.3 and is never shown to other users. We do not analyze or process this content for its meaning.

2.7 Analytics & Usage Data

To understand how the app is used and to improve it over time, Next10 uses PostHog, a product analytics service. When you use the app, PostHog collects the following on our behalf:

  • The names of screens you visit within the app (for example, "Home", "Tracker", "Statistics", "Profile", "Paywall"), and the order in which you navigate between them
  • In-app events, specifically: when you open the app, when the app is moved to the background, when you complete registration (sign-up), when you sign in to an existing account, when you finish the onboarding flow, and when the paywall screen is shown to you or when you start a subscription
  • Your user identifier — the anonymous account ID assigned by Supabase — linked to your email address after sign-in, so that events can be attributed to a consistent user profile across sessions
  • Basic session and device metadata automatically collected by the PostHog iOS SDK, such as device type, operating system version, app version, and the time events occur
  • Interaction signals such as rage clicks, meaning rapid repeated taps in the same area of the screen, which PostHog detects automatically and which we use to identify confusing or broken parts of the interface

This data does not include the content of your goals, habit names, completion history, or any other private app data described in Section 2.3. It is used solely to understand usage patterns, diagnose problems, and make product improvements. It is not used for advertising and is not sold or shared with any party other than PostHog as described in Section 4.

3. Purposes of Processing & Legal Basis

Creating and securing your account — using your auth data (2.1) — is processed on the legal basis of contract necessity (Art. 6(1)(b) GDPR).

Verifying subscription and payment status — using your account ID and subscription status, processed via Apple's In-App Purchase system, Google Play Billing, and/or a third-party subscription platform (see Section 4 for current sub-processors) — is processed on the legal basis of contract necessity (Art. 6(1)(b) GDPR).

Syncing your habits and goals across devices — using your private app data (2.3) — is processed on the legal basis of contract necessity (Art. 6(1)(b) GDPR).

Providing your public profile, friend search, and social features — using your public profile and friends data (2.2, 2.4) — is processed on the legal basis of contract necessity (Art. 6(1)(b) GDPR).

The leaderboard and percentile ranking feature — using your computed completion statistics (2.2) — is processed on the legal basis of contract necessity (Art. 6(1)(b) GDPR), as it is an advertised built-in feature of the app.

Collecting analytics and usage data to understand how the app is used and to improve it — using your analytics data (2.7) — is processed on the legal basis of legitimate interest (Art. 6(1)(f) GDPR). Our legitimate interest is to maintain a functioning, improving product by understanding user behavior at an aggregate and individual-session level. We have assessed that this interest is not overridden by your privacy rights, given that no sensitive or content-level data is included, that the analytics are conducted using an EU-hosted service, and that we do not use this data for advertising or profiling beyond product improvement.

4. Sub-processors (Third Parties We Use)

We use the following service providers to operate Next10. Each processes personal data only on our instructions and is bound by data processing agreements:

Supabase (PostgreSQL Database & File Storage) processes your public profile, private app data, friends and social data, and profile photos. Your data is stored in Supabase's EU-region infrastructure, hosted on AWS and physically located within the European Economic Area.

Supabase (Authentication) processes your email, name, and sign-in credentials. These are also stored within Supabase's EU-region infrastructure on AWS, within the European Economic Area.

Google (Google Sign-In) processes your Google account email and name if you choose to sign in with Google. This is governed by Google's own privacy policy.

Apple (Sign in with Apple) processes your Apple ID email (or Apple's private relay email) and name if you choose to sign in with Apple. This is governed by Apple's own privacy policy.

PostHog (Product Analytics) processes your analytics and usage data as described in Section 2.7, including screen views, in-app events, your user identifier, and device metadata. PostHog is used to help us understand how the app is navigated and where issues arise, so we can improve the product. Your data is stored on PostHog's EU Cloud infrastructure, physically located within the European Economic Area (Frankfurt, Germany, hosted on AWS eu-central-1). PostHog, Inc. is a US-based company acting as a data processor under a Data Processing Agreement. Any access to your data by PostHog personnel from outside the EEA is governed by Standard Contractual Clauses approved by the European Commission.

Apple In-App Purchase / Google Play Billing / third-party subscription processor (TBD) processes your subscription status. The specific provider and location will be confirmed once selected.

5. International Data Transfers

All of your core data — including your public profile, private app data, friends and social data, profile photos, and authentication records — is stored in Supabase's EU-region infrastructure, hosted on AWS and physically located within the European Economic Area. Your data does not leave the EEA as a result of storage or normal app operation.

Supabase, Inc. is a US-based company acting as a data processor under a Data Processing Agreement (DPA). Any access to your data by Supabase personnel from outside the EEA — for example, for infrastructure support or security monitoring — is governed by Standard Contractual Clauses (SCCs) as approved by the European Commission, which is the legal mechanism recognized for transfers of personal data from the EU to countries without an adequacy decision.

Your analytics data processed by PostHog is stored on PostHog's EU Cloud infrastructure, physically located within the European Economic Area (Frankfurt, Germany). PostHog, Inc. is a US-based company, and any access to this data by PostHog personnel from outside the EEA is likewise governed by Standard Contractual Clauses as approved by the European Commission.

If you sign in using Google or Apple, those providers may also process limited data outside the EU as part of their own authentication systems, governed by their respective privacy policies (see Section 4).

6. Data Visible to Other Users

Unlike most of your data, some information in Next10 is visible to other people using the app. Here's exactly what is shown, to whom, and when:

If your profile is public (the default, unless you set it to private): your nickname is searchable by any user of the app; your profile photo is visible to any user who finds your profile; and your completion statistics (daily, weekly, monthly, and yearly percentages plus your streak) are visible as raw numbers only — no goal names, habit names, or any other detail about what you're actually working on.

If your profile is set to private: your profile is not discoverable via search, and only your confirmed friends can see your nickname, profile photo, and completion statistics.

To your friends specifically, regardless of whether your profile is public or private: they see the same profile and statistics described above, and nothing from your private app data (Section 2.3). Your actual goals, habit names, schedules, and completion history are never visible to friends or any other user, under any setting.

When you send or receive a friend request: the other person can see your nickname and profile photo as part of the request.

On the leaderboard: only your percentile rank appears — no nickname, photo, or any identifying detail is shown to other users through the leaderboard itself.

Analytics data collected by PostHog (Section 2.7) is never shown to other users. It is accessible only to us as the data controller and to PostHog as the data processor.

7. Data Retention & Account Deletion

We retain your data for as long as your account remains active, since it is necessary for the app's core functionality (sync, profile, leaderboard).

Deleting your account: You can delete your account at any time directly within the app. When you do:

  • Your public profile, private app data (goals, habits, completion history), and friend connections are permanently deleted from our Supabase database
  • Your authentication record is deleted from Supabase Authentication
  • Any pending friend requests you sent or received are removed
  • Friend relationship records held by your former friends are also removed as part of this process
  • Your user profile in PostHog is dissociated from your account, and we will submit a deletion request to PostHog for any personal data associated with your user identifier. Analytics events that do not contain identifying information may be retained in aggregate form.

Backups: Due to how our infrastructure provider (Supabase/AWS) operates, deleted data may persist briefly in backup systems before being permanently purged. This is standard across cloud infrastructure and does not mean your data remains accessible or in use — it is simply the technical process of full deletion propagating through backup layers.

8. Children's Privacy

Next10 is rated 16+ on the App Store. It is intended for users aged 16 and older. If you are younger than 16, please only use the app with the permission and supervision of a parent or guardian.

We do not have a technical way to verify a user's age beyond what Apple or Google's account systems require. If you are a parent or guardian and believe your child has used Next10 and provided personal data, you can contact us at nazar.mischenko13@gmail.com to request that the data be reviewed or deleted, using the account deletion process described in Section 7.

We do not use any user's data — regardless of age — for advertising or sale to third parties.

9. Leaderboard Processing

Next10 includes an always-on leaderboard feature that shows you your percentile rank compared to other users, based on weekly and monthly habit and goal completion rates.

To calculate this, our system compares the completion statistics described in Section 2.2 across all users. No nickname, profile photo, goal name, habit name, or any other identifying detail is included in this calculation's output or shown to any user through the leaderboard. You only see your own numeric percentile rank.

Because this feature is a core, advertised part of the app, it is processed under the same legal basis as the rest of the app's functionality (contract necessity, Art. 6(1)(b) GDPR) — see Section 3.

10. Your Rights

Under GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate data (most profile/app data can be edited directly in the app)
  • Erasure — delete your account and all associated data, available directly in the app (Section 7), or by contacting us
  • Restriction — request that we limit processing of your data in certain circumstances
  • Object — object to processing based on legitimate interest. This right is specifically relevant to our analytics processing (Section 2.7), which is based on legitimate interest (Art. 6(1)(f) GDPR). If you wish to object to the collection of your analytics data, you can contact us at the email address below and we will work with you to address your request.
  • Data portability — request your data in a structured, commonly used format
  • Withdraw consent — not applicable, as we do not rely on consent as a legal basis for any processing described in this policy
  • Lodge a complaint — with your local data protection authority. In Germany, you can find your competent authority via the Conference of the Independent Data Protection Authorities of the German Federal and State Governments (DSK)

To exercise any of these rights, contact us at nazar.mischenko13@gmail.com.

11. Security

We take reasonable technical and organizational measures to protect your data, including:

  • Encryption of data in transit between the app and our servers
  • Access to our Supabase project restricted to the account owner (Nazar Mishchenko)
  • Reliance on Supabase Authentication for credential handling, so passwords are never stored or accessible in plain text by us
  • Supabase Row-Level Security (RLS) policies that enforce the visibility boundaries described in Section 6 (e.g., private app data is technically inaccessible to any user other than its owner)
  • Analytics data transmitted to PostHog is sent over encrypted HTTPS connections and stored in PostHog's EU Cloud infrastructure

No method of electronic storage or transmission is 100% secure. While we work to protect your data, we cannot guarantee absolute security.

12. Changes to This Policy

We may update this privacy policy from time to time, for example if we add new features, change service providers, or as required by law. If we make material changes — such as adding a new sub-processor or changing the purpose for which your data is used — we will update the "Effective Date" below and, where appropriate, notify you within the app.

We encourage you to review this policy periodically.

Effective Date: 26.08.2026

© 2026 Next10. All rights reserved.  |  Terms of Service  |  Cookie Policy  |  Impressum