Privacy

Clear data, plain language.

This policy explains how SmettiAmo 1.0 handles data on the Android phone, the Wear OS companion and, only when selected, Google-linked Firebase services.

Effective and last updated: 22 July 2026 · Policy version 1.0

Controller, scope and contacts

The data controller is Teo Bella, the natural person responsible for the SmettiAmo project, operating under the name “Teo Bella Studio”. For privacy matters, email privacy@smettiamo.app; for technical support, email support@smettiamo.app.

This policy covers the SmettiAmo Android and Wear OS apps, the smettiamo.app website, optional cloud backup, and communications initiated by the user. The service is intended for people aged 18 or older and is not directed at children.

In brief: you can use SmettiAmo only on your devices or choose cloud backup linked to your Google account. There is no advertising, analytics, marketing profiling or sale of data.

Two ways to use SmettiAmo

Device-only

Device-only mode creates no Firebase Authentication user, personal Firestore data area, heartbeat or journey backup and does not upload smoking history. The journey remains on the phone, works offline, and the phone and Watch can continue to communicate locally through the Wear OS Data Layer.

This mode cannot restore the journey after uninstalling the app, clearing app data, losing the phone or moving to another phone.

Optional Cloud backup

To enable it, you must confirm that you are at least 18, explicitly choose Cloud backup, give separate consent and select a Google account. Google Sign-In is the only method used to create a new cloud account. Anonymous authentication is not used for new accounts.

Cloud backup remains offline-first: a temporary cloud outage does not prevent safe local use. The same Google account can enable recovery on another phone; differences between a local and cloud journey require an explicit choice and are never merged automatically.

Data handled on your devices

The phone may store cigarette-event identifiers and times, journey identifier and start date, initial consumption, daily and interval goals, pack price and quantity, currency, the selected lifetime-estimate profile, settings history, achievement unlocks, preferences, consent state, and technical operation state needed for restoration or deletion.

Statistics, savings, Health percentages and milestones are normally calculated on the device and are not uploaded as separate cloud records. Smoking data is health-related, but the estimates shown are informational and motivational rather than personal clinical measurements.

Cloud-backup data and Google identity

When you choose Cloud backup, Firebase Authentication creates a technical UID and processes the Google provider identity and associated email address. Depending on information returned by Google or Firebase, authentication metadata may also include a display name or profile-image URL. SmettiAmo does not copy your email address, display name or profile image into Firestore journey documents.

Cloud Firestore may store:

  • cigarette-event identifier and time;
  • journey identifier and start date;
  • initial consumption, daily goal and personal interval goal;
  • pack price, cigarettes per pack and currency;
  • the selected lifetime-estimate profile;
  • goal, price or settings history needed to restore the journey;
  • achievement unlock timestamps;
  • technical creation, update, deletion and synchronisation timestamps;
  • a root technical heartbeat containing the last-active time.

The Firebase UID identifies the account in authentication and document paths. Current event documents do not intentionally contain a device identifier or phone model. App language, age confirmation, consent, Google/Firebase tokens, diagnostics, cache and operational journals are not included in the journey backup.

Google/Firebase SDKs may also process technical information needed for authentication, security and service operation, such as app or installation identifiers, IP address, and technical information about the system, device and SDK version.

Phone and Wear OS

The phone and Watch exchange the minimum journey and event state needed for the companion experience through the Wear OS Data Layer, including recent events, goals and essential statistics. This user-device connection is not public cloud backup, and the Watch does not access Firebase independently.

SmettiAmo does not use physiological sensors, Health Connect, heart-rate data, medical records, location, contacts, microphone, camera or an advertising identifier.

Purposes and reasons for processing

  • record the journey, show statistics and estimates, and retain requested preferences;
  • provide, restore, secure and synchronise the cloud backup selected by the user;
  • authenticate the cloud account, prevent improper access, and complete requested resets or deletions;
  • respond to support or privacy communications initiated by the user;
  • handle data-subject requests and comply with applicable obligations.

Optional cloud processing of smoking-related journey data is based on the user’s explicit choice and consent. Activities strictly necessary to provide and secure the requested cloud service, handle communications, and meet applicable obligations or requests are processed according to the reason relevant to that situation. You can withdraw the cloud choice by disabling backup; withdrawal does not affect processing already carried out lawfully.

Providers, location and security

Google/Firebase acts as a service provider for authentication, cloud storage, security and technical operation. SmettiAmo’s Cloud Firestore database is configured in the European multi-region eur3. Firebase Authentication is operated from data centres in the United States. Other Google/Firebase technical processing may take place on international infrastructure under the provider’s terms and applicable safeguards.

Firebase services protect data in transit through HTTPS; Cloud Firestore and Firebase Authentication also apply encryption at rest. Access to cloud documents is restricted to the authenticated owner. Proportionate safeguards are applied, but no system can guarantee absolute security.

The website is delivered through Cloudflare Pages. To deliver and protect the pages, Cloudflare may process technical request and security data such as IP address, system configuration, referring URLs and language preferences under its terms. SmettiAmo does not use this data for advertising, profiling or marketing analytics.

SmettiAmo uses no advertising, analytics, Crashlytics, Firebase Performance Monitoring, advertising cookies, tracking pixels, third-party embeds or marketing profiling. Data is not sold.

Website, support and communications

The website is static and uses no analytics, tracking tools or local storage to profile visitors. Technical data strictly necessary for delivery and security through Cloudflare may still be processed as described above. Email actions open the user’s configured mail client and do not send content to a website backend.

If you contact support or privacy, the email address, text and attachments you voluntarily send are processed. Optional technical details generated by the app contain only the app name, version name and code, Android version and SDK level, device manufacturer and model, app language, cloud status, report timestamp and timezone.

Retention and data management

Device-only data remains on the devices until it is removed by the user, the app or the system. Uninstalling or clearing app data removes the local journey but is not a request to delete any cloud account.

Start the journey again deletes journey events, progress, settings and backup where applicable, but in Cloud mode retains the Google-linked Firebase identity and technical heartbeat. Disable Cloud backup deletes and verifies events, backup and heartbeat and initiates deletion of the Firebase identity while keeping the local Phone and Watch journey. Permanently delete all data deletes and verifies cloud data, initiates deletion of the Firebase identity, clears local data and wipes the Watch immediately or when it next reconnects. None of these operations deletes the user’s Google account.

According to the Firebase documentation current on the date of this policy, Firebase Authentication retains logged IP addresses for a few weeks and, after the controller initiates user deletion, removes other authentication information from live and backup systems within 180 days. Any provider technical logs or backup copies follow the periods stated in the applicable terms.

Support and privacy emails are retained only for the time needed to handle the request and applicable obligations. You may request deletion, except for information that must lawfully be preserved. See the Data deletion page for detailed paths and requests.

Rights, requests and complaints

Where applicable, you may request access, correction, deletion, restriction, objection or portability and may withdraw consent. Email privacy@smettiamo.app. To protect the data, only proportionate information needed to verify your identity and link to the account concerned may be requested.

You may lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority where applicable. For general technical support, use support@smettiamo.app.

Changes to this policy

This page will be updated when relevant data, features, providers or obligations change. The date and version above identify the applicable text; appropriate notice will be provided on the site or in the app for significant changes.