Legal
Privacy Policy
This policy covers the NurCore iOS application and the website at irfanpangestu.dev. Both are operated by Nur Irfan Pangestu as an individual.
Effective 10 September 2026 · Last updated 10 September 2026
The short version
- Nothing is sold, rented, or shared with advertisers. There are no ads and no ad identifier (IDFA) is requested.
- You are not tracked across other companies’ apps or websites.
- The app works without an account. Signing in is optional and only needed for one screen.
- You can ask for your data to be deleted by email, and it will be.
1. The NurCore iOS app
1.1 What is collected
| Data | Why | Tied to you? |
|---|---|---|
| Email address | Only if you choose to sign in. It identifies your account. | Yes |
| Account identifier | A session token kept on your device so you stay signed in. | Yes |
| Device identifier | An app-instance ID generated by Firebase Analytics. It is not your device’s serial number and does not follow you to other apps. | No |
| Usage data | Which screens are opened and which actions are triggered, so the app can be improved. | No |
| Crash data | Stack traces, app version, and device model when the app crashes, so the crash can be fixed. | No |
Usage and crash data are not linked to your identity. The app never calls Firebase’s user-identifier API, and the only properties attached to analytics events are the build flavor, the app version, and the operating system version.
1.2 What is never collected
- Location, contacts, photos, calendar, microphone, camera, and health data. The app never requests these permissions.
- The advertising identifier (IDFA). No App Tracking Transparency prompt is shown because nothing is tracked.
- Payment or financial information. The app has no in-app purchases and no subscriptions.
1.3 Who processes it
Google Firebase (Analytics and Crashlytics) processes the usage and crash data on our behalf, under Google’s own terms. No other third party receives data from the app. Account data is held on the API the app signs in against, and is used only to authenticate you.
1.4 How long it is kept
Analytics data is retained by Firebase for up to 14 months and then deleted automatically. Crash reports are retained for 90 days. Account data is kept until you ask for it to be removed. Signing out clears the session token from your device immediately.
1.5 Your choices
- Do not sign in. Every screen except the authentication screen works without an account.
- Delete the app. Removing it deletes the session token and stops all analytics and crash reporting from your device.
- Ask for deletion. Email the address at the bottom of this page and your account data will be deleted. No account is required to make the request — write from the address you signed up with.
2. The irfanpangestu.dev website
The site records anonymous visit analytics: page views, approximate location derived from your IP address at country and city level, referring site, browser, operating system, device type, and screen size. Your IP address itself is not stored alongside those records, and no advertising or cross-site tracking cookies are set.
Some preferences — your light or dark theme choice, for instance — are stored in your browser’s local storage. They never leave your device.
3. Children
Neither the app nor the site is directed at children under 13, and neither knowingly collects data from them. If you believe a child has provided data, email the address below and it will be removed.
4. Changes to this policy
If this policy changes in a way that affects what is collected or why, the effective date at the top of this page changes with it. Material changes will be summarised here rather than made silently.
5. Contact
Questions, corrections, or deletion requests: nurirppan@gmail.com. Requests are answered within 30 days.