This privacy policy governs your use of the mobile application Trialo (the “Application”, Android package identifier com.flx_apps.habitexperiments), a personal trial log created and published by FLX Apps (Felix Heller), flx.es. It explains what the Application does and does not do with information. Please read it in full before installing or using the Application.
Trialo is a log for testing changes you make to your own life. You choose one or more outcomes to track — sleep quality, energy, focus or anything else you type in yourself — and rate each one once a day on a scale. When you decide to change something, you name that change, say which of your outcomes it is meant to affect, give it a fixed end date, and tick it off on the days you actually do it. At the end the Application compares the days of the trial against the days before it began, and separately compares the days you did it against the days you did not, alongside the ordinary day-to-day variation in your own ratings. It then asks you to write down whether you are keeping the habit or stopping it.
The Application does not suggest what to change. The list of changes it offers describes only behaviours and timings, such as an earlier caffeine cut-off or leaving the phone outside the bedroom. It names no supplement, no medicine and no dose, and it takes no position on whether any change works. Determining that is the point of running the trial.
It is a personal, single-device tool. There is no companion account, no cloud sync, no sharing feature, and no way for anyone, including us, to see what you have entered or whether you use the Application at all.
The Application stores, in its own private storage on your device and nowhere else:
That is the complete list. The Application keeps no usage log, records no analytics events, and does not track how or when you use it.
The Application declares two Android permissions of its own, and both exist for one optional feature: a daily reminder to rate your day. It asks for no storage, no camera, no location, no contacts, no sensors and no health data, and it has no runtime request of any kind unless you switch the reminder on.
android.permission.POST_NOTIFICATIONS, requested at the moment you turn the reminder on and not before. Decline it, or leave the reminder off, and the Application never asks again. The notification is composed on your device and says only how many things are left to rate; nothing about it reaches us or anyone else.android.permission.RECEIVE_BOOT_COMPLETED, which lets the Application re-book the reminder after you restart your phone. A pending alarm does not survive a restart, so without it a reminder you had switched on would silently stop. Nothing else runs at boot, and if the reminder is off, nothing runs at all.Google Play additionally lists the following, because they are merged into the shipped package by the libraries the Application is built on. They are named here so that the claims above can be checked against what Google Play actually shows you:
android.permission.INTERNET and android.permission.ACCESS_NETWORK_STATE, used by Google Play Billing to talk to the Google Play Store when you open the purchase screen or restore a purchase. No code of ours uses them, and nothing you enter is ever sent over them.com.android.vending.BILLING, which is what allows the Application to offer the one-time unlock through Google Play.android.permission.WAKE_LOCK and android.permission.FOREGROUND_SERVICE, declared by the AndroidX WorkManager library, which the library that draws the home screen widget (AndroidX Glance) depends on. The Application starts no service, holds no wake lock and schedules no background work of its own; the widget is redrawn when you use the app, when you tap it, and when the daily reminder fires.com.flx_apps.habitexperiments.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION, added automatically by a standard Android support library (AndroidX Core). It is defined by the Application for the Application and is a “signature” permission, meaning only code signed with the same key could ever hold it. Its sole purpose is to stop other apps on your device from sending messages to the Application’s internal components. It grants access to nothing and has no privacy implications.The Application does not collect or transmit to us any of the following, and has no technical means to do so: your name, e-mail address, phone number or contacts; the outcome you track or any rating you give it; the changes you test or the verdicts you write; your device’s advertising identifier or any persistent hardware identifier; the list of apps installed on your device; your location; your navigation within the Application; crash logs or diagnostic telemetry; or any behavioural or analytics event. We receive nothing from the Application, ever, because it makes no network request of its own.
The Application offers a single one-time in-app purchase that unlocks additional features. It is not a subscription and does not recur.
The purchase is processed entirely by Google Play Billing. We never see your payment details, your name or your billing address; Google does not pass them to us and the Application never asks for them. What the Application does is ask Google Play whether the signed-in Google account owns the unlock, and store that yes or no answer on the device so the app works without a network connection afterwards. That flag is excluded from Android’s backup, so it cannot travel to a different account. The billing library also carries Google’s own transport for reporting the state of a purchase back to Google Play (com.google.android.datatransport). That is Google’s diagnostics for Google’s purchase flow, not analytics about you, and nothing from it reaches us.
Your use of Google Play is governed by Google’s own terms and privacy policy, which we do not control. See policies.google.com/privacy.
We operate no backup service. Android’s own backup mechanism, which you control in your device settings and which is tied to your Google account, may copy the Application’s database and settings so that your history survives moving to a new phone. That data goes to Google under your own Google account, not to us. The cached purchase flag is deliberately excluded from it.
Trialo is a personal logbook. It is not a medical device and is not intended to diagnose, treat, cure or prevent any disease or condition. It contains no drug database, recommends no supplement, dose, protocol or treatment, and gives no medical advice.
The comparisons the Application shows you at the end of a trial are plain descriptions of numbers you typed in yourself: the average of your ratings during the trial, the average before it, the averages on the days you did and did not tick the habit off, and how much your ratings ordinarily move from one day to the next. It is not a clinical result and it is not evidence of cause. A single person tracking one self-reported number cannot establish that a change caused an effect, and the Application says so on the screen where it reports the comparison. Do not start, stop or alter any medication or treatment on the basis of what this Application shows you. Talk to a doctor or pharmacist.
The Application is not directed at children and we do not knowingly collect anything from anyone, of any age, because we collect nothing at all.
If the Application gains a feature that changes any of the above, this document is updated in the same release. The date at the top always reflects the version of the Application currently published.
Questions about this policy: felixheller@mailbox.org.