Privacy Policy
Last updated: August 13, 2026
Give & Take ("the App", "we", "us", "the Controller"), operated by Andrea Cherchi, is a mobile application. This policy describes what personal data we collect, how we use it, and what rights you can exercise.
1. Data Controller
Andrea Cherchi — brand Give & Take
VAT (P.IVA): 04019130923
Privacy: privacy@andylab.it
Info: info@andylab.it
Website: give-take.app
2. Personal Data Collected
2.1 Data provided by the user
| Category | Data | Purpose |
|---|---|---|
| Account | First name, last name, email, password | Registration and authentication |
| Profile | Bio, date of birth, profile photo, preferred language | Experience personalization |
| Contacts | Name, email, photo (from address book or entered manually) | Managing movements between people |
| Movements | Amounts, lent objects, notes, due dates | Core app functionality |
| Payment info | IBAN, PayPal email (optional) | Voluntary sharing with your contacts |
| Feedback | Report type and text comment | Support and improvement |
2.2 Social login
If you sign in with Apple or Google, we receive the identity token and name if provided. We do not access your password.
2.3 Data we do NOT collect
- Geolocation
- Analytics or tracking SDKs
- Profiling cookies
- Advertising identifiers (IDFA/GAID)
3. Device permissions
| Permission | Usage |
|---|---|
| Microphone | Voice commands |
| Speech Recognition | On-device transcription |
| Camera | QR scanning, photos |
| Photo Library | Profile and contact images |
| Contacts | System picker only |
| Face ID / Touch ID | App lock |
4. Speech recognition
Speech is processed entirely on-device. No audio is sent to external servers.
5. In-app purchases
Pro subscriptions are handled by Apple StoreKit. We do not store card details.
6. Notifications
Local due-date reminders only. No remote push.
7. Server communication
Data is sent over HTTPS. Authentication uses Bearer tokens.
8. Retention and deletion
Delete your account anytime in Settings. Associated data is removed from our servers.
9. Third parties
Shared only with Apple and, if chosen, Google for auth and subscriptions. No marketing sales.
10. Security
HTTPS, password hashing, optional biometrics and expiring session tokens.
11. GDPR rights
Access, rectification, erasure, restriction, objection and portability. Write to privacy@andylab.it.
12. Children
Not intended for anyone under 16.
13. Changes
We may update this policy; the date at the top shows the latest revision.