Skip to main content

Legal

Privacy Policy

This policy covers aantstudio, this website, and every app we publish. General principles apply to all of them; each app then has its own section describing exactly what it collects.

Last updated · 19 August 2026

This policy has been written to match our apps' real behaviour, but it has not been reviewed by a lawyer — have a solicitor check it before you rely on it for a jurisdiction with specific requirements.

1. Who we are

aantstudio builds and publishes the apps listed on this site. This policy covers those apps and this website. Contact us at contact@aantstudio.com.

2. General principles

These hold across every app we publish:

  • We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
  • We do not share your data for advertising. Where an app shows ads, this is stated plainly in that app's section below.
  • We collect the minimum an app needs to work, and each app's section says exactly what that is.
  • You can refuse a permission and keep using whatever does not depend on it.

3. This website

This site has no advertising trackers and sets no marketing cookies. If you send us a message through a form on this site, we receive the name, email address and message you typed, and use them only to reply to you.

App-specific

OldFriend

OldFriend is a social habit and games app. It has accounts, and it collects more than our other apps because the features require it.

Account information

  • Email address — to create your account, confirm it, and let you sign back in. It is never shown to other users, ever.
  • Username and profile photo — visible to other people in the app. That is their purpose.
  • Password — stored only as a salted hash by our authentication provider. Nobody, including us, can read it.

Location — including in the background

This is the most sensitive thing we collect, so it gets its own section.

  • During a live race or a tracked walk, we record your GPS position continuously — including while the app is in the background or your screen is off. That is the only way to measure a distance you walk with your phone in your pocket. Tracking starts when you start a race or a walk and stops when it ends. It never runs at any other time.
  • On a challenge check-in, we attach the coordinates where a photo or video was taken, so the people in that challenge can see the proof is genuine.
  • Who sees it: your distance and position during a race are visible to the other people in that race. A check-in's location is visible to people in that challenge. Your location is never shown to strangers, never sold, and never used for advertising.
  • You can refuse. Declining location permission disables races and route tracking. Everything else in the app keeps working.

Health and fitness data

If you use the Health tab we collect steps, calories burned, distance, sleep duration, and any height, weight and age you enter to set a goal. On Android, with your permission, we read steps and sleep from Health Connect so figures match what your phone or watch already recorded.

This data is yours. It is used to show you your own progress and to work out the pace your goal needs. It is not shared with other users, not used for advertising, and not sold. Aggregate step counts appear on a race leaderboard only for races you choose to join.

Photos, video and proof

Challenge check-ins and dare forfeits are photos or short videos you record. They are visible only to people in the same challenge or to the friend you dared. Proof media is deleted automatically after 30 days, from both your device and our storage. Settled dares are cleared after 24 hours, unfilmed ones after 72 hours, and unanswered dares after a week.

Messages

Direct messages are encrypted with a key unique to each conversation before they leave your device. We store the encrypted text and cannot read the contents. Reported messages can be reviewed by a moderator, which is the one exception and exists so harassment can be acted on.

Purchases

Subscriptions are handled by the app store. We never see or store your card details — the store tells us only whether a subscription is active. Diamonds, limits and entitlements are calculated on our servers.

Notifications

If you allow them, we store a push token for your device to send reminders, invites and challenge updates. Turning notifications off in your device settings stops them.

Device permissions

Android and iOS ask for each of these separately, and every one can be refused. What breaks when you refuse is named beside it.

  • Camera — to record the photo or video proof for a challenge check-in or a dare.
  • Microphone — video proof records sound with the picture. It is only active while you are recording, and we never listen at any other time.
  • Photos and videos — so you can submit an existing photo or video instead of recording a new one, and set a profile picture. We read only the files you pick.
  • Location, including in the background — races and tracked walks only, as described above.
  • Physical activity — to count steps on the device for the Health tab.
  • Health Connect (Android) — to read steps, distance, calories and sleep your phone or watch already recorded, so our figures match theirs.
  • Notifications — reminders, invites, nudges and challenge updates.

Third-party services

  • Supabase — database, authentication and file storage.
  • Google Play Billing — subscriptions on Android.
  • Firebase Cloud Messaging — delivering push notifications.
  • Resend — sending confirmation and account emails.

How long we keep things

  • Proof photos and videos — 30 days, then deleted automatically.
  • Dares — 24 hours once settled, 72 hours if a forfeit is owed, 7 days if unanswered.
  • Account data, challenges, posts and messages — until you delete your account.

Deleting your account

You can delete your account from inside the app, under Me. It removes your profile, posts, messages, challenges, proof media and health data. It cannot be undone. See Account Deletion for the full list and for how to request deletion by email if you have lost access to the app.

App-specific

Grabbo

Grabbo is a video downloader and editing toolkit for Android. It has no account and no sign-in, and it does not have a profile to attach anything to.

What we collect

  • No email, name, contacts, photos or location are collected. There is nothing to register for.
  • The links you paste stay on your device. They are sent to the site you are downloading from, as any browser would, and are not sent to us or logged by us.
  • Your download history is stored on your phone only. You can clear it at any time from inside the app, and uninstalling removes it.
  • The files you download stay on your device. They never pass through our servers.
  • Editing happens on your phone. Trimming, merging, compressing, making a GIF or a ringtone and every other tool runs locally. Nothing is uploaded to be processed.

Device permissions

  • Storage — to write the file you asked for into your Downloads folder, or into a folder you pick yourself.
  • Notifications — to show download progress and tell you when a download has finished.
  • Ignore battery optimisation (optional) — Android suspends background work aggressively, which stalls a long download when the screen is off. Declining it keeps everything working; downloads may just pause until you reopen the app.

Third-party services

  • Google AdMob — included in the app but currently switched off. No ads are requested and no advertising identifier is read in the build you can install today. If ads are turned on in a future release, AdMob may collect a device advertising identifier and coarse usage signals under its own privacy policy, and this section will say so plainly.
  • Google Play Billing — handles the optional Pro purchase. We never see or store your payment details; Play tells us only whether Pro is active.

Grabbo talks directly to the sites whose links you paste. Those sites have their own privacy policies and see the request as they would see any visitor.

Data retention and deletion

Because Grabbo holds no account, there is nothing on our side to delete. Clearing the download history inside the app, or uninstalling it, removes everything Grabbo has stored.

Data security

Data in transit is encrypted with TLS. Access to production systems is limited to people who need it, and authentication and payment details are handled by the specialist providers named above rather than stored by us.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Email contact@aantstudio.com and we will respond within 30 days.

California residents (CCPA)

We do not sell or share personal information as those terms are defined by the CCPA. You have the right to know what we collect, to request deletion, and not to be discriminated against for exercising either.

European Economic Area and UK (GDPR)

We process your data to perform the service you asked for, and on the basis of consent where a permission is involved. You have the right of access, rectification, erasure, restriction, portability, and to object. You may also complain to your local supervisory authority.

Children

Our apps are not intended for children under 13, or under the minimum age required where you live if that is higher. We do not knowingly collect data from children. If you believe a child has an account, email us and we will remove it.

Changes to this policy

If we change how we handle your data we will update this page and change the date at the top. Significant changes will also be announced in the app they affect.

Contact

Questions about this policy or your data: contact@aantstudio.com.