Privacy Policy

Last updated: July 13, 2026

1. About this Privacy Policy

This Privacy Policy explains how the CritCase app («the App», «we», «us») processes personal data in accordance with:

CritCase is an educational app for healthcare professionals and students who want to practice clinical scenarios, emergency medicine and medical knowledge.

2. Data Controller

Data Controller:

RYDNINGEN MEDICAL (sole proprietorship / enkeltpersonforetak)
Org. no. 937 302 258
Sjarkvegen 72, NO-9017 Tromsø, Norway
Proprietor: Thorbjørn André Rydningen
Privacy inquiries: privacy@critcase.app
General support: support@critcase.app

3. What data do we collect?

3.1 Data we DO NOT collect

CritCase does not collect:

3.2 Data stored locally on your device

The following data is stored on your device:

Data type Purpose Storage location
Game progress Points, level, completed cases Local device storage (backed up to the cloud if you sign in – see 3.3)
Favorites Your favorited cases Local device storage (backed up to the cloud if you sign in – see 3.3)
Achievements Unlocked achievements and timestamps Local device storage (backed up to the cloud if you sign in – see 3.3)
Statistics Number of exercises, average score Local device storage (backed up to the cloud if you sign in – see 3.3)
Activity dates Days you've used the app Local device storage (backed up to the cloud if you sign in – see 3.3)
Settings Theme choice, sound settings Local device storage

If you use the app without signing in («guest mode» – the default), your progress stays on your device only. Cloud backup happens only if you choose to sign in (see section 3.3). Even in guest mode, the app creates a random, anonymous Firebase user ID that enables the optional cloud features (leaderboard, challenges, purchases); Firebase logs IP address and user agent for security purposes when this ID is issued.

3.3 User account and cloud backup (optional)

You can choose to sign in with Apple or Google to back up your progress. Signing in is entirely optional – the app is fully functional without an account. If you sign in, we process:

Data type Purpose Storage location
Email address Account recovery and identifying the account. If you use Apple's «Hide My Email», we only receive a relay address (@privaterelay.appleid.com or @private.icloud.com), not your real address Firebase Authentication (USA)
Name (optional) Only if the sign-in provider shares it at first sign-in Firebase Authentication (USA)
Sign-in provider Which service (Apple or Google) your account is linked to Firebase Authentication (USA)
User ID (UID) Identifies your account Firebase Authentication (USA)
IP address and user agent Logged by Firebase Authentication for security purposes at sign-in Firebase Authentication (USA)
Training progress XP, level, streaks, activity dates (which days you used the app), completed cases, quiz and drill statistics, achievements, favorited cases, practice-repetition schedule, nickname, role and leaderboard opt-in are backed up to the cloud Google Firestore

Purpose: Backing up and restoring your progress across devices, and account recovery.

Legal basis: Contract (GDPR Art. 6(1)(b)) – you request the backup service yourself by signing in.

Retention: Account data is deleted when you delete your account. Residual copies in backups are purged within approx. 180 days (Firebase).

Recipients: Apple and Google are independent controllers for the sign-in itself. Google (Firebase) and RevenueCat act as our processors. Firebase Authentication stores account data exclusively in US data centers (see section 6).

Important about accounts:

3.4 Local notifications

The app may send local notifications to remind you about daily challenges. These notifications:

3.5 Push notifications (Firebase Cloud Messaging)

If you enable push notifications, we use Firebase Cloud Messaging (FCM) to send you real-time notifications about challenges (completed challenge, new duel, expiring challenge).

Push notifications require your explicit consent (opt-in, off by default). The device token is linked to your user ID, not to your name or email, and is deleted when you delete your account or disable push notifications.

The token is stored in Google Firestore; notifications are delivered via Google's global infrastructure (see section 6). Legal basis: Consent (GDPR Art. 6(1)(a)).

3.6 Usage analytics (Firebase Analytics)

If you consent to usage analytics (off by default), we use Google Firebase Analytics to understand how the app is used:

Data type Purpose Storage location
App usage events Understand which features are used Google Firebase (USA)
Screen views Improve navigation and UX Google Firebase (USA)
Session duration Understand engagement Google Firebase (USA)
Device type/OS Ensure compatibility Google Firebase (USA)
Pseudonymous app-instance ID Aggregate usage statistics Google Firebase (USA)

Important about usage analytics:

Legal basis: Consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time in settings.

3.7 Crash reporting (Firebase Crashlytics)

We use Firebase Crashlytics to identify and fix errors in the app (crash logs, app version, device type and OS version). Crashlytics is disabled by default and is only activated if you consent to usage analytics. Data is processed by Google in the USA (see section 6). Legal basis: Consent (GDPR Art. 6(1)(a)).

3.8 Leaderboard (Optional – Requires consent)

The app offers an optional global leaderboard. If you choose to participate:

Data type Purpose Storage location
Display name Identify you on the leaderboard Google Firestore
Total score Ranking on the leaderboard Google Firestore
Level and title Show your progress Google Firestore
User ID Link your score to you Google Firestore

Important about the leaderboard:

3.9 Subscription and purchases (CritCase Pro)

The app offers an optional premium service (CritCase Pro). Purchase information is handled as follows:

We do not have access to payment information; purchases are handled exclusively by App Store / Google Play. RevenueCat Inc. (USA) operates as a data processor in accordance with GDPR (see section 6 on transfers). Legal basis: Contract (GDPR Art. 6(1)(b)).

3.10 Challenges (Optional – Requires consent)

The app offers an optional challenge feature where you can challenge friends to quiz duels:

Data type Purpose Storage location
Display name Identify you to your opponent Google Firestore
Quiz score Compare results Google Firestore
Correct answers Show detailed results Google Firestore
Time spent Compare speed Google Firestore
Challenge code Allow friends to join Google Firestore
Question IDs Ensure both get the same quiz Google Firestore
User ID Link the challenge to you Google Firestore

Important about challenges:

3.11 In-app content feedback

If you submit feedback on content in the app, we store your message together with your user ID, app version and platform in Google Firestore, so we can correct content errors. Feedback is deleted when you delete all your data in settings. Legal basis: Legitimate interest (GDPR Art. 6(1)(f)).

4. Legal basis for processing

We base our data processing on the following legal grounds under GDPR Article 6:

Processing Legal basis
Storing progress locally on the device Legitimate interest (GDPR Art. 6(1)(f)) – necessary for app functionality
Cloud backup of progress (signed-in users only) Contract (GDPR Art. 6(1)(b))
User account (Apple/Google sign-in) Contract (GDPR Art. 6(1)(b))
Local notifications Consent (GDPR Art. 6(1)(a))
Push notifications (FCM) Consent (GDPR Art. 6(1)(a)) – requires explicit opt-in
Usage analytics (Firebase Analytics) Consent (GDPR Art. 6(1)(a)) – off by default
Crash reporting (Crashlytics) Consent (GDPR Art. 6(1)(a)) – off by default
Leaderboard (Firebase) Consent (GDPR Art. 6(1)(a)) – requires explicit opt-in
Challenges (Firebase) Consent (GDPR Art. 6(1)(a)) – requires active action
Purchases and subscription (RevenueCat) Contract (GDPR Art. 6(1)(b))
In-app content feedback Legitimate interest (GDPR Art. 6(1)(f))

5. Data sharing

5.1 Local data

Data stored only locally is never shared.

5.2 Leaderboard data (optional)

If you choose to participate in the leaderboard, your chosen display name, score and level are shared with other users via Google Firestore.

5.3 Challenge data (optional)

If you create or participate in a challenge, your display name, score, number of correct answers and time spent are shared with your opponent via Google Firestore. The data is intended for you and your opponent; see section 3.10 regarding technical accessibility for other signed-in app users.

5.4 Analytics data

If you have consented, we share pseudonymised usage data with Google Firebase Analytics to improve the app. This data is not used for advertising and is not sold to third parties.

5.5 Sign-in providers (Apple / Google)

When you sign in with Apple or Google, the provider processes the sign-in itself as an independent controller, under its own privacy policy. We only receive your email address, optionally your name, and a technical ID – never your password.

5.6 What we DO NOT share

6. International transfers (outside the EEA)

Parts of the processing take place in the USA:

Service Processing location Transfer mechanism
Firebase Authentication (account data) Exclusively US data centers EU–US Data Privacy Framework (DPF) – Google LLC is certified
Firebase Analytics and Crashlytics USA EU–US Data Privacy Framework (DPF)
Firebase Cloud Messaging Google's global infrastructure EU–US Data Privacy Framework (DPF)
Google Firestore (leaderboard, challenges, cloud backup, feedback) Google Cloud; Google LLC (USA) acts as processor EU–US Data Privacy Framework (DPF)
RevenueCat Inc. USA European Commission Standard Contractual Clauses (SCCs) in its data processing agreement

Transfers to Google LLC are based on the European Commission's adequacy decision for the EU–US Data Privacy Framework (GDPR Art. 45). For processors that are not DPF-certified, we rely on the European Commission's Standard Contractual Clauses (SCCs, GDPR Art. 46).

You can obtain a copy of the safeguards (the Standard Contractual Clauses) by contacting us at privacy@critcase.app. DPF certifications can be verified at www.dataprivacyframework.gov.

7. Data storage and deletion

7.1 Storage period

Local data is stored on your device for as long as the app is installed. If you are signed in, your account data and the cloud backup of your progress are stored until you delete them or delete your account.

7.2 Data deletion

You can delete all stored data by:

  1. Delete everything (recommended): Go to Settings → Privacy & Data → «Delete all my data». This deletes all local data, all cloud data (account, cloud backup, leaderboard, challenges, feedback) and your account – all in one step.
  2. Reset progress: Go to Settings → Privacy & Data → «Reset Progress» to only delete local game data.
  3. Uninstalling: Uninstall the app to delete all local data. Note: if you are signed in, the cloud backup and account remain until you delete them.
  4. Without the app installed: Use the deletion page at critcase.app/delete-account-en.html to request deletion without reinstalling the app.

When you delete your account, data is deleted from our systems without undue delay. Residual copies in backups are purged within 180 days (Firebase).

8. Your rights

Under GDPR, you have the following rights:

Right Description How to exercise
Access View what data is stored All data is visible in the app (statistics, achievements)
Rectification Correct inaccurate data Reset progress in settings
Erasure Have data deleted In the app (Settings → Delete all my data) or via the deletion page at critcase.app/delete-account-en.html
Data portability Get data in machine-readable format Settings → «Export my data» – includes your local app data, your account data (if signed in) and your cloud-stored documents (progress backup, leaderboard entry, challenges, feedback)
Restriction Require that the processing of your data be restricted (GDPR Art. 18) Contact privacy@critcase.app
Objection Object to processing based on legitimate interest (GDPR Art. 21) Contact privacy@critcase.app
Complaint Complain to supervisory authority Norwegian Data Protection Authority: www.datatilsynet.no

9. Children's privacy

CritCase is an educational app aimed at healthcare professionals and students over 18 years of age. We do not knowingly collect data from children under 18.

10. Security

Your data is protected by:

11. Changes to this Privacy Policy

We may update this Privacy Policy. For significant changes, we will:

12. Contact

Do you have questions about privacy or wish to exercise your rights?

Privacy and rights: privacy@critcase.app

General support: support@critcase.app

Norwegian Data Protection Authority (Supervisory Authority):
P.O. Box 458 Sentrum
0105 Oslo, Norway
www.datatilsynet.no

This Privacy Policy applies to the CritCase app distributed via Apple App Store and Google Play Store.