Shameless

Privacy policy

Effective 25 September 2026

1. Who is responsible for your data

Shameless is operated by Petr Antonín (the controller).

For privacy questions or requests, email support@shamelessapp.org.

2. Data we process

We process the following categories of personal data when you use Shameless.

Account and profile data

We use this data to create and secure your account, display your profile, apply your settings, and provide the service.

Group and social data

We use this data to operate private groups, show rankings and activity, enable social features, enforce community rules, and respond to abuse reports.

Your display name, avatar, roast preference, screen-time totals, roasts, and activity are shown to members of the relevant group. Group photos and profile photos are intended to be displayed within Shameless. A person who obtains a direct photo URL may be able to access that photo, so do not upload sensitive images.

Photos and Cloud Storage

If you choose a profile or group photo, Shameless uploads the selected image to Cloud Storage for Firebase. We process the image file, its storage path, content type, size, and download URL. The file may also contain metadata embedded by your device or photo application. Photos are optional; you may use an emoji or group icon instead.

Screen-time totals

If you expressly enable screen-time sharing and grant Android Usage Access, Shameless reads the periods when the phone screen is on and interactive and calculates daily totals. We upload daily totals, dates, and your time zone to the groups you have joined so that Shameless can produce daily and weekly rankings.

Shameless does not upload the names of individual apps, websites, messages, typed content, or the content displayed on your screen. Turning off sharing stops future uploads but does not automatically erase totals already stored. You may delete those totals by leaving the relevant group, deleting your account, or asking us to erase them.

Device and notification data

When your account is created, saved, or loaded, the Android app obtains a Firebase Cloud Messaging (FCM) registration token and reads the Android system identifier known as ANDROID_ID. On Android 8 and later, ANDROID_ID is normally specific to the combination of the device, Android user, and app-signing key. It is not an advertising identifier.

We store ANDROID_ID as the key for a device record so that the app can update one record for that installation. The record contains the FCM token, Android platform information, notification-enabled status, and last-seen time.

This device registration occurs even when you have not enabled notifications. In that case, or when Android notification permission has not been granted, the record is marked as notifications disabled and Shameless does not use it to send optional push notifications. If you enable notifications, we use the token and your preference to deliver the notifications you selected. FCM tokens may be refreshed by Firebase over time.

Technical and security data

Firebase and Google may process technical data such as IP addresses, user-agent information, service logs, request timestamps, application identifiers, and diagnostic or security information to provide, secure, and prevent abuse of the infrastructure used by Shameless.

3. Why we process your data

Where the GDPR applies, we rely on the following legal bases:

Optional push notifications are sent only when enabled in Shameless and permitted by Android. The underlying inactive device record described above may be created before you enable notifications.

4. Service providers and international processing

Shameless uses Google Firebase as a processor and infrastructure provider, including:

Firebase Authentication is operated from the United States. Other Firebase services may use Google infrastructure in the European Economic Area and other countries. Where required, Google provides transfer safeguards through its Firebase Data Processing and Security Terms, including Standard Contractual Clauses. More information is available in Firebase Privacy and Security and the Firebase Data Processing and Security Terms.

We do not sell your personal data and do not use screen-time totals for advertising.

5. Retention and deletion

We generally retain account, profile, group, screen-time, device, and social data for as long as your account is active and the data is needed to provide Shameless.

Deletion from active systems may not immediately remove temporary cached or backup copies maintained by our infrastructure provider. Google may also retain security and service logs for the periods described in its applicable terms. We may retain information where and for as long as a legal obligation requires it, or where necessary to establish, exercise, or defend a legal claim.

6. Your choices and rights

Depending on applicable law, you may ask us to:

You can change notification and roast settings, stop screen-time sharing, revoke Android Usage Access, block members, report roasts, and leave groups in the app.

You can permanently delete your account in Profile → Delete account, or submit a request at our account-deletion page. We may need to verify that you control the account or its email address before completing a request.

You may complain to a data-protection authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (ÚOOÚ).

7. Children

Shameless is intended for people aged 16 and older. We do not knowingly allow anyone under 16 to create an account. If you believe a child under 16 has provided personal data to Shameless, contact support@shamelessapp.org so that we can investigate and delete the data where appropriate.

8. Security

We use authentication, access rules, restricted server-side operations, and encryption in transit. Firebase also encrypts supported service data at rest. No service can guarantee absolute security. Contact us promptly if you believe your account or data has been compromised.

9. Changes to this policy

We may update this policy when Shameless, our providers, or applicable law changes. We will publish the revised policy and update its effective date. If a change materially affects how we use your data, we will provide additional notice where required.

10. Contact

Email: support@shamelessapp.org