Privacy Policy
Last updated: September 23, 2026
Short version: the Trisle app keeps everything on your device. This website asks before it measures anything — Google Analytics runs only if you explicitly accept, you can withdraw at any time, and payments are handled by Polar.sh as merchant of record. The details are below.
1. Scope of this policy
This Privacy Policy explains how the Trisle website (“Website”, published at trisle-app.github.io/Trisle_Website) and the Trisle Android application (“App”) handle information, and the rights you have in relation to that information. It applies to every visitor to the Website, every customer who purchases the App, and every user of the App, regardless of where you are located. It is written to satisfy the information duties of Articles 13 and 14 of the EU General Data Protection Regulation (“GDPR”) and, to the extent applicable, equivalent laws such as the UK GDPR and the Swiss Federal Act on Data Protection.
If any translated version of this policy (where one is made available) conflicts with this English version, the English version governs.
2. Who is responsible (the “controller”)
The controller for the data processing described in this policy is the operator of Trisle (“Operator”, “we”, “us”), an independent software developer publishing the Website and the App under the “Trisle” name. You can reach us at any time through the channels listed in section 15 (Contact).
Trisle is a product of an independent developer. It is not affiliated with, endorsed by, or sponsored by Apple Inc. or Google LLC. All third-party trademarks belong to their respective owners.
3. The Trisle App — data stays on your device
The App is designed to process everything locally on your device. The content of your notifications, your music, battery level, locations inside navigation islands, and everything else the App displays never leaves your phone: the App has no servers, no user accounts, and no cloud sync. Specifically:
- No telemetry. The App does not embed third-party analytics, advertising, crash-reporting or tracking SDKs, and it does not transmit usage statistics anywhere.
- No accounts. You do not create a profile, and we do not receive your name, email address, or contacts through the App.
- Permissions, and why. The App requests two standard Android permissions: notification listener access (so islands can mirror notifications that arrive on your device) and “display over other apps” (so islands can float above the interface). Both are granted by you in Android settings, are used exclusively for the on-screen feature they enable, and can be revoked at any time, which simply disables the related feature.
- No root, no data export. The App does not require rooting and does not read, collect, or forward your files, contacts, messages, or precise location.
If you contact us for App support, we process only what you choose to send us in that conversation (see section 4.4). Screenshots you share voluntarily should be stripped of personal content before sending.
4. Information the Website processes
4.1 Usage data via Google Analytics (only with your consent)
With your prior consent — and only with your prior consent — the Website uses Google Analytics 4 (“GA4”, property G-0Z165PW33N), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Before you accept, nothing is measured: no analytics script is downloaded, no analytics cookie is set, and no request is sent to Google. After you accept, GA4 processes the following categories of data to help us understand which pages and features are useful:
- pages viewed, session duration, referrer, and outbound link clicks (such as clicks on the buy buttons);
- technical attributes of your browser and device: browser type and version, operating system, screen resolution, language, device model category;
- your approximate location derived from your IP address at city or region level. GA4 does not log or store individual IP addresses, and IP addresses are never used by us to identify you;
- events such as purchase conversions (value €5.99, currency EUR, and the Polar checkout reference used as the transaction identifier) and cookie-banner choices.
4.2 Data stored on your device (local storage)
| Item | Type | Purpose | Duration |
|---|---|---|---|
| trisle.locale | Local storage entry | Remembers the interface language you selected, so the site opens in it next time. | Until you clear your browser storage |
| trisle.consent.v1 | Local storage entry | Stores your analytics consent choice and its timestamp, so we do not have to ask again and can honour your decision on every visit. | Until you change or withdraw it |
| _ga, _ga_<container> | First-party cookies set by GA4 | Distinguish visitors and sessions for aggregate statistics. Set only after you accept analytics. | Up to 2 years (refreshed by subsequent visits) |
4.3 Purchase information (processed by Polar)
Purchases are completed through Polar.sh, which acts as merchant of record for the sale of the App. When you buy the App, Polar processes your order, payment, applicable VAT/GST, and the confirmation email. We receive from Polar the minimum order data needed to deliver the product and handle refunds: the checkout reference, the product purchased, the amount, and your receipt contact details as included by Polar. We never see or store your full payment card details. For information on how Polar processes your payment data, see Polar’s own privacy policy, available on polar.sh.
4.4 Information you provide voluntarily
If you contact us for support or feedback, we process whatever you choose to include (typically your email address and a description of the issue). We use it solely to answer and resolve your request.
5. Purposes and legal bases (GDPR Art. 6)
| Purpose | Data categories | Legal basis |
|---|---|---|
| Aggregate, consent-based site analytics (GA4) | Usage data, technical attributes, approximate location | Art. 6(1)(a) GDPR — consent (withdrawable at any time) |
| Selling and delivering the App, invoicing, taxes, refunds | Order and payment reference data (via Polar) | Art. 6(1)(b) GDPR — performance of the purchase contract |
| Protecting the Website and infrastructure from abuse, and defending legal claims | Technical log attributes held by hosting providers | Art. 6(1)(f) GDPR — legitimate interests, balanced against your rights |
| Answering support requests you initiate | What you send us | Art. 6(1)(b)/(f) GDPR — handling your request |
| Remembering language and consent choices | Local storage entries listed in section 4.2 | Strictly necessary / requested by the user (ePrivacy derogation) |
6. Google Analytics in detail
- Consent-gated loading. The Website implements Google Consent Mode v2 together with strict prior consent: the GA4 library is only downloaded after you press “Accept” in the consent banner. If you decline, nothing loads and nothing is measured — there are no “cookieless pings” in the background either.
- No cross-site tracking, no advertising use. We use GA4 only to evaluate our own Website. We have disabled advertising features and do not use GA data to build advertising profiles.
- Retention. Event-level data is retained in the GA4 property for a maximum of 14 months, after which Google deletes it automatically.
- Data sharing settings. Google processes the data on our behalf under the Google Analytics Terms of Service and the EU Standard Contractual Clauses incorporated for service providers in the EEA. Google is certified under the EU-U.S. Data Privacy Framework.
- Your opt-outs. You can withdraw consent at any time via the “Cookie settings” link in the Website footer, or by clearing your browser storage. Independently of us, you can install Google’s official opt-out browser add-on (tools.google.com/dlpage/gaoptout) or block analytics in your browser settings.
7. Recipients and categories of recipients
We deliberately keep the circle of recipients tiny. Apart from the App itself — which sends nothing anywhere — the following processors and independent controllers may come into contact with data:
- Google Ireland Ltd — GA4 analytics (only after consent);
- Polar.sh (Polar Software, Inc. and its payment providers) — checkout, payment, tax and refund handling as merchant of record;
- GitHub, Inc. — static hosting of the Website via GitHub Pages; requests are logged by GitHub for security and abuse prevention under GitHub’s privacy statement;
- public institutions, only where we are legally compelled (court order, tax law).
We do not sell personal data, we do not rent it, and we do not use it for third-party advertising. There are no data-broker relationships of any kind.
8. International data transfers
Our providers may process data outside the European Economic Area (for example in the United States). Where that happens, transfers rely on an adequacy decision of the European Commission — such as the EU-U.S. Data Privacy Framework, under which Google and GitHub are certified — or, failing that, on the European Commission’s Standard Contractual Clauses together with technical and organisational safeguards. You may request a copy of the relevant safeguards using the contact details in section 16.
9. How long we keep data
- GA4 data: maximum 14 months, then automatically deleted by Google;
- Consent record: kept locally in your browser until you change it; on our side we do not maintain a central consent database, the local timestamped record is the proof of consent;
- Order data: retained by us and Polar for the duration required by tax and commercial law (typically 6 to 10 years depending on jurisdiction), reduced to the statutory minimum;
- Support conversations: deleted when resolved, unless retention is needed to defend legal claims;
- Local storage on your device: until you clear it.
10. Your rights
Under the GDPR — and equivalent laws where they apply to you — you have the following rights regarding your personal data:
- Access (Art. 15) — obtain confirmation and a copy of your data;
- Rectification (Art. 16) — correct inaccurate data;
- Erasure (Art. 17) — have your data deleted;
- Restriction (Art. 18) — restrict processing while a dispute is resolved;
- Data portability (Art. 20) — receive data you provided in a machine-readable format;
- Objection (Art. 21) — object to processing based on legitimate interests;
- Withdrawal of consent (Art. 7(3)) — withdraw your analytics consent at any time with effect for the future, via the “Cookie settings” footer link or by clearing your browser storage;
- Complaint (Art. 77) — lodge a complaint with your local supervisory authority, in particular in the EU member state of your habitual residence or place of work.
To exercise any right, contact us as described in section 16. We respond within one month, as required by law. Where a request concerns payment or order data that only Polar holds as merchant of record, we will either forward your request or point you to Polar’s own data-subject request channel.
11. Children
The Website and the App are not directed at children, and we do not knowingly collect personal data from children below the age at which consent of a holder of parental responsibility is required in your country (not below 16 in the EU; 13 where US law applies). If you believe a child has provided us with personal data, contact us and we will delete it promptly.
12. Security measures
We protect data with measures appropriate to the risk: the Website is served exclusively over HTTPS; the App processes data on-device so there is no central data store to attack; we collect the minimum data necessary; analytics runs without storing IP addresses; and payment details never pass through our hands. Where we use processors, they are bound by data processing agreements.
13. Do Not Track and browser signals
There is currently no industry-consensus response to “Do Not Track” signals. Instead of relying on such signals, we treat the choice you make in our consent banner as the binding control over analytics: decline once and analytics never loads on any of your visits until you change your mind.
14. Changes to this policy
We may update this policy to reflect changes in the Website, the App, the services we use, or the law. The “Last updated” date above always shows the current version. If a change is material — in particular any expansion of data collection that would require fresh consent — we will ask for your consent again through the banner before continuing.
15. Contact
You can reach the Operator for any privacy matter:
- via the support contact stated on your purchase receipt (the fastest route for purchase-related questions), or
- by opening an issue at github.com/trisle-app/Trisle_Website/issues for Website questions.
If we respond to a request about the App, we will never ask you to send the content of your notifications — there is no scenario in which we need it, because the App never sends it anywhere.
16. Quick summary
- The App is fully on-device: no accounts, no telemetry, nothing uploaded.
- The Website uses Google Analytics only if you explicitly accept; decline and nothing is collected at all.
- Payments and receipts are handled by Polar.sh as merchant of record; we never see your card details.
- You can withdraw consent anytime via “Cookie settings” in the footer, and you have all GDPR rights via the contact channels above.