Privacy Policy

Comeback mobile application

Effective date: 18 June 2026  ·  Last updated: 18 June 2026

This Privacy Policy explains what personal data the Comeback app (“Comeback”, the “App”) collects, why we collect it, who we share it with, and the rights you have. It is written to comply with the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).

Data controller. Virea Apps, United Kingdom (“we”, “us”, “our”).
Privacy contact: admin@virea-apps.com
Contents
  1. Personal data we collect
  2. How and why we use it (legal bases)
  3. AI coaching conversations
  4. Community content (public)
  5. Analytics, advertising identifiers & attribution
  6. Who we share data with
  7. International data transfers
  8. Data retention
  9. Security
  10. Your rights (GDPR — EEA/UK)
  11. Your rights (CCPA/CPRA — California)
  12. Account & data deletion
  13. Children’s privacy
  14. Changes to this policy
  15. Contact

1. Personal data we collect

We collect only what is needed to run the App. We do not access your camera, photos, location, contacts, or microphone.

CategoryExamplesSource
Account & authenticationEmail address, display name / nickname, sign-in provider (Google, Apple, or email/password), account identifier. If you use “Sign in with Apple”, we receive the relay email if you choose to hide your address.You; Firebase Authentication
Profile & learning activityYour selected goal and topic, course and lesson progress, streaks, days active, action steps.You; in-app activity
Onboarding answersThe answers you give in the onboarding questionnaire about your situation and goals.You
AI coaching conversationsThe questions and messages you send to the in-app AI coach and the responses generated for you.You
Community contentPosts, comments, likes, your nickname, and whether you posted anonymously.You
Subscription & purchase dataSubscription status, product purchased, transaction identifiers, and purchase history. We never receive your full payment-card number.RevenueCat; Apple App Store; Google Play
Usage & product analyticsScreens viewed, features used, lessons opened, posts created, and user properties such as goal, streak, subscription status, and onboarding answers.Amplitude
Advertising identifier & attributionAdvertising identifier (IDFA on iOS, only if you allow tracking; Advertising ID on Android), install-referrer and marketing-campaign data used to attribute installs and web purchases.AppsFlyer; Apple; Google
Device & technical dataDevice model, operating-system version, app version, language, time zone, IP address, app-instance identifiers, and crash diagnostics.Automatically; Firebase Crashlytics
Push notification tokenA device token used to deliver notifications you have enabled.Firebase Cloud Messaging

2. How and why we use your data, and our legal bases

PurposeLegal basis (GDPR)
Create and secure your account; authenticate youPerformance of a contract (Art. 6(1)(b))
Provide the courses, lessons, AI coaching, and community featuresPerformance of a contract (Art. 6(1)(b))
Process and verify subscriptions and entitlementsPerformance of a contract (Art. 6(1)(b))
Personalise content and recommendations based on your goals and progressPerformance of a contract; or legitimate interests (Art. 6(1)(f))
Product analytics to understand and improve the AppLegitimate interests (Art. 6(1)(f)); consent where required
Marketing attribution and measuring advertising campaignsConsent (Art. 6(1)(a)), including your App Tracking Transparency choice on iOS
Crash diagnostics, security, and fraud preventionLegitimate interests (Art. 6(1)(f))
Send notifications you have enabledConsent (Art. 6(1)(a))
Comply with legal, tax, and accounting obligationsLegal obligation (Art. 6(1)(c))
Moderate community content and enforce our TermsLegitimate interests (Art. 6(1)(f)); legal obligation

Where we rely on consent, you can withdraw it at any time (for example, by changing your device tracking or notification settings); this does not affect processing carried out before withdrawal.

3. AI coaching conversations

The App includes an AI coach. The questions and messages you send are processed by automated systems and our AI service provider(s) to generate responses, and are stored so you can revisit your threads. Please do not share sensitive personal information (for example, precise health, financial, or third-party data) in coaching messages. AI responses are generated automatically, may be inaccurate, and are provided for general informational and educational purposes only — they are not professional, medical, psychological, legal, or relationship-counselling advice. See the Terms of Service for details.

4. Community content is public

Posts, comments, and likes you share in the community are visible to other users of the App. You may post under a nickname or anonymously, but content you publish is not private. Please do not include information you would not want others to see. We operate moderation, in-app reporting, and user-blocking tools, and we may review, remove, or restrict content and accounts that violate our Terms or community guidelines.

5. Analytics, advertising identifiers & attribution

We use Amplitude for product analytics (how features are used, so we can improve them) and AppsFlyer for marketing attribution (to understand which campaigns lead to installs and subscriptions, including matching a purchase made on our website to your app install).

On iOS, before any cross-app/website tracking using your advertising identifier (IDFA), we ask for your permission through Apple’s App Tracking Transparency prompt. If you decline, we do not use the IDFA for tracking. On Android you can reset or delete your Advertising ID in your device settings. You can also limit analytics by declining tracking and by using your device’s privacy controls.

6. Who we share your data with

We do not sell your personal data. We share it only with service providers (“processors”) who act on our behalf under contract, and where required by law:

Each provider is bound by data-processing terms and may use your data only as instructed by us.

7. International data transfers

Some of our providers process data outside your country, including in the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework. You may request details of these safeguards using the contact below.

8. Data retention

We keep personal data only as long as necessary for the purposes above: account, profile, community, and coaching data for as long as your account is active and for a reasonable period afterwards; analytics and attribution data for the retention periods configured with our providers; and purchase records for as long as required by tax and accounting law. When data is no longer needed, we delete or anonymise it.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights (EEA / UK — GDPR)

Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection supervisory authority. To exercise any right, contact admin@virea-apps.com. We respond within the timeframes required by law (generally one month under GDPR).

11. Your rights (California — CCPA/CPRA)

California residents have the right to know what personal information we collect, use, and disclose; to access and delete their personal information; to correct inaccurate information; and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CCPA. We will not discriminate against you for exercising your rights. Submit requests to admin@virea-apps.com; you may use an authorised agent, and we will verify your request using your account details.

12. Account & data deletion

You can delete your account and associated personal data at any time directly in the App: Settings → Delete account. You may also request deletion by emailing admin@virea-apps.com. Some records may be retained where required by law (for example, transaction records). Content you posted publicly in the community may be removed or anonymised on deletion.

13. Children’s privacy

The App is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact admin@virea-apps.com and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide notice in the App. Your continued use after the effective date constitutes acceptance.

15. Contact

Virea Apps
United Kingdom
Email: admin@virea-apps.com