Privacy Policy
For Gimbal: ADHD Test & Focus · Last updated: September 12, 2026Gimbal has no account, no sign‑up and no email field. Your questionnaire answers, performance test results, notes, tasks and focus sessions are written to a database on your device and are never uploaded to us. We run no analytics, no advertising and no tracking.
The only thing that leaves your device is a purchase, if you buy Gimbal Pro: Apple or Google process the payment and a receipt is validated through RevenueCat. That path never carries your answers or results. Section 4 explains it in full.
1. Who we are
Gimbal: ADHD Test & Focus ("Gimbal", "the app") is published by Muzaffer Uyar and Hicret Uyar, independent software developers based in Türkiye, operating together under the trade name muzo.dev ("we", "us", "our"). We are the data controller for the limited processing described in section 4.
For any privacy question or request, write to contact@muzo.dev with "Gimbal privacy" in the subject line.
2. What this policy covers
This policy covers the Gimbal mobile app on iOS and Android, and the Gimbal pages on muzo.dev. Other apps and games published by muzo.dev are covered by their own privacy policy, which is different: those are ad‑supported, Gimbal is not.
These web pages set no cookies, run no analytics and load no third‑party fonts, scripts or images. Our web server keeps standard access logs (IP address, timestamp, requested page, user agent) for security and troubleshooting, which are deleted on a rolling basis.
3. What Gimbal stores on your device
All of the following is created by you, kept in the app's local database on your phone, and never transmitted to us:
| Category | Examples |
|---|---|
| Questionnaire answers | Your responses to the eight self‑report scales, including the impairment, childhood‑onset, sleep and stress questions, and the profile Gimbal computes from them |
| Performance test results | Reaction times, errors, hits and misses for Go/No‑Go, Stroop, visual search, N‑Back, task switching, time reproduction, digit span and continuous performance; plus repeat measurements over time |
| Focus and planning data | Focus sessions and their outcome, parked thoughts, tasks, projects, steps, due dates and exam dates |
| Daily check‑ins | Your short daily entries and anything derived from them, such as chronotype and executive‑function maps |
| Suggestions and experiments | The suggestions Gimbal generates for you and the weekly experiments you choose to run |
| App settings | Language, notification preferences, session defaults, and a local record of whether Pro is unlocked |
We have no copy of any of it, no way to read it remotely, and no way to restore it for you if you lose it. That is the trade‑off of an app with no account, and it is deliberate.
4. What leaves your device
Only a purchase. If you buy Gimbal Pro — as a subscription or as a one‑time lifetime purchase — the following happens outside your device:
| Who | What they receive | Why |
|---|---|---|
| Apple (App Store) or Google (Google Play) | Your payment details and store account information, handled entirely by them under their own privacy policies. We never see your name, email address, card or billing address. | To take the payment and manage the subscription |
| RevenueCat, Inc. (United States) | An anonymous app user identifier generated by the app, the purchase receipt from the store, product identifier, purchase and renewal dates, platform, app version, country and the IP address of the request | To validate the receipt and tell the app whether Pro is unlocked, including after you reinstall or change device |
That anonymous identifier is not linked to your name, email address or any of the data in section 3. No questionnaire answer, test result, note, task or session is ever sent to RevenueCat, to us, or to anyone else.
RevenueCat's privacy policy: revenuecat.com/privacy. Apple: apple.com/legal/privacy. Google: policies.google.com/privacy.
5. What we never do
- No advertising of any kind, and no ad identifiers (no IDFA, no AAID). Gimbal does not show the App Tracking Transparency prompt because it does not track you.
- No analytics or product telemetry SDKs, and no crash reporting SDK of our own.
- No profiling for marketing, no data brokers, no data enrichment.
- We do not sell or share personal information, and we never have. Under the CCPA/CPRA this includes "sharing" for cross‑context behavioural advertising.
- We do not use your health‑related information for advertising, marketing, or to train any model.
If your operating system is set to send crash reports to Apple or Google, those go to the platform vendor under their policies, not to us. Any crash report we receive that way is aggregated and contains no content from section 3.
6. Health‑related information
ADHD symptom answers and attention test results are sensitive: in the EU/UK they are special category data under Article 9 GDPR, and in Türkiye they are special categories of personal data under KVKK Article 6. Gimbal's design answers that risk by never collecting them — they are generated, stored and deleted entirely on your own device, under your control. We never receive them, so we never process them.
Gimbal does not read from or write to Apple Health or Google Health Connect, and does not request access to them.
7. Device backups — read this one
If you have iCloud Backup, Google One backup for Android or a local computer backup enabled, your device may include Gimbal's local database in that backup. The copy is made by your operating system, is held in your cloud account under Apple's or Google's terms, and is not accessible to us. If you do not want your Gimbal data in a backup, turn off backups for Gimbal in your device settings. See Your Data & Deletion for the exact steps.
8. Legal bases for processing (GDPR / UK GDPR)
- Performance of a contract (Art. 6(1)(b)) — validating your purchase and unlocking Pro, including restoring it on a new device.
- Legitimate interests (Art. 6(1)(f)) — preventing purchase fraud and abuse, and keeping our web server secure. We have balanced these against your rights; the data involved is minimal and pseudonymous.
- Legal obligation (Art. 6(1)(c)) — keeping the transaction records that tax and consumer law require of the stores and of us.
We do not rely on consent for the above, because none of it is optional if you choose to buy Pro. If you never buy Pro, no personal data reaches us at all.
9. International transfers
RevenueCat, Inc. is based in the United States, so purchase validation data is processed there. Transfers rely on the European Commission's Standard Contractual Clauses together with the safeguards described in RevenueCat's own documentation. Apple and Google operate globally and describe their own transfer mechanisms in their policies.
10. Retention
- On your device: until you delete it. Everything can be erased from Settings inside the app, and uninstalling the app removes the database with it.
- Purchase validation data: retained by RevenueCat for as long as the entitlement is active and afterwards under their retention schedule; store‑side transaction records are kept by Apple and Google for the periods their own policies and applicable tax law require.
- Web server logs: rotated and deleted on a rolling basis, typically within 30 days.
- Support emails: kept while the matter is open and for up to 24 months afterwards, then deleted.
11. Your rights
Depending on where you live you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to lodge a complaint with a supervisory authority. In Türkiye these are your rights under KVKK Article 11; in the EU/UK, Articles 15–22 GDPR; in California, the CCPA/CPRA; similar rights exist in other jurisdictions.
In practice:
- Data on your device is already fully under your control — you can view, change, export where the app offers it, and delete it at any time without asking us. We cannot access it, so we cannot action a request about it.
- Purchase validation data is the only personal data we can act on. Email contact@muzo.dev from the address associated with your store account, tell us the platform and the approximate purchase date, and we will locate the anonymous identifier and action your request. We answer within 30 days.
- Payment and billing records held by Apple or Google must be requested from them; we have no access to them.
We will never charge you for making a request, and never ask for more identifying information than the request needs.
12. Children
Gimbal is rated for users aged 13 and over and is not directed to children under 13. We do not knowingly collect personal information from children. Where the digital consent age in your country is higher than 13 (it is 16 in several EU member states), users below that age should use Gimbal only with the involvement of a parent or guardian. See the Children's Privacy Notice.
13. Security
Gimbal's data is protected primarily by your device: the app's database lives in the app's private storage, which the operating system isolates from other apps. Use a device passcode or biometric lock — on an unlocked, shared or rooted/jailbroken device, no app can protect its data. Traffic to the stores and to RevenueCat is encrypted with TLS. Our website is served over HTTPS.
14. Third parties we use
| Provider | Purpose | Data involved |
|---|---|---|
| Apple · App Store | Distribution, payments, subscriptions | Your store account and payment data, held by Apple |
| Google · Google Play | Distribution, payments, subscriptions | Your store account and payment data, held by Google |
| RevenueCat, Inc. | Receipt validation and entitlement | Anonymous identifier, receipt, product, dates, platform, country, IP |
That is the complete list. There is no fourth entry — no analytics provider, no ad network, no attribution SDK, no cloud database.
15. Changes to this policy
If we change this policy, the "Last updated" date above changes with it, and a material change — for example adding any new recipient of data — will be announced in the app before it takes effect. Previous versions are available on request.
16. Contact
Questions, requests or complaints: contact@muzo.dev. We reply within 3 business days and resolve formal data requests within 30 days. If you are in the EU/UK or Türkiye and are not satisfied with our answer, you may complain to your local data protection authority.
17. Summary for store privacy labels
This section maps the policy onto the questions Apple's App Privacy and Google Play's Data safety forms ask, so that what you read here and what you see on the store page are the same thing.
| Store question | Gimbal |
|---|---|
| Data used to track you | None |
| Data linked to you | None |
| Data not linked to you | Purchase history only, and only if you buy Pro (app functionality) |
| Health & fitness data collected | None — it is created and kept on your device and is never transmitted |
| Data encrypted in transit | Yes, for the purchase path; nothing else is transmitted |
| Data deletion request | Delete everything in‑app from Settings; purchase records by emailing us |
| Account required | No account exists, so there is nothing to delete or recover |
Gimbal's tests are self‑assessment and screening tools. They do not diagnose anything, are not a medical device, and do not replace an evaluation by a qualified professional. See the Medical Disclaimer.