S&T Exchanger Privacy Policy
Data used for accounts
When an account is created or used, Firebase Authentication processes the account email address, optional display name, provider identity, verification status, and a Firebase user ID. Passwords and Google credentials are handled by the authentication provider and are not stored by S&T Exchanger.
When Google Sign-In is selected, the bundled Google Sign-In service may process account-linked name, email address, phone number, coarse location, user and device identifiers, other account data, and usage data for sign-in functionality and service analytics. S&T Exchanger does not use this information for advertising or tracking.
Data used for subscriptions
Google Play or the Apple App Store processes payment information. The app backend receives store-signed or opaque subscription evidence and status so it can verify Pro access. The backend stores a protected store record or one-way identifier hash, the linked Firebase user ID, product identifier, expiry, renewal status, and verification time. The app never grants Pro access solely from device-reported purchase data.
Engineering data
Heat-exchanger inputs, projects, custom fluids, unit settings, report-customer data, and generated reports remain local to the device under the current app architecture. They are not uploaded by the account or subscription feature.
Security and service providers
The app uses Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase App Check with Play Integrity on Android and App Attest on iOS, Google Sign-In, Google Play Billing, and Apple StoreKit. These providers may process unlinked diagnostic data, technical logs, usage data, and device or integrity signals under their own terms. S&T Exchanger does not use Firebase Analytics, advertising, or cross-app tracking in the approved configuration.
Retention
Account and subscription-verification records are retained while the app account exists and they are needed to provide or verify account access. Store-notification deduplication markers are retained only as needed to prevent duplicate processing. Account-linked Firebase records are deleted when the app account is deleted. Engineering data stored locally remains until app storage is cleared or the app is uninstalled. Google Play, Apple, and Firebase may retain records under their own policies and legal obligations.
Deletion
Use the in-app Delete account action or follow the account deletion instructions. Account-linked Firebase entitlement and store-mapping records are removed by the backend deletion process. Local device data remains until app storage is cleared or the app is uninstalled. Deleting the account does not cancel a Google Play or App Store subscription.
Contact
Contact S&T Exchanger support with privacy questions.