Privacy Policy
Effective as of 14 August 2026. Replaces the previous version of 13 August 2026.
This policy explains what SketchLab (the “app”) collects, why, who it is shared with, and how you can get it deleted. It applies to the SketchLab / DrawMax mobile app on Android and iOS, and to the servers that support it.
SketchLab is operated by Hichem HAMMADACHE, 467 route de la Pompignane, 34170 Castelnau-le-Lez, France (“we”, “us”). For any question about this policy or your data, contact contact@sketchlabapps.com.
1. What we collect
| Data | Why | Where it is stored |
|---|---|---|
| Email address, display name | Create and sign you into your account; let other users identify you by your public username | Google Firebase Authentication, and our own servers |
| Account identifiers (Firebase user ID, our internal user ID, sign-in method used) | Link your content, progress and subscription to your account | Google Firebase Authentication, and our own servers |
| Your drawings and any photos you import, your profile picture, tutorials you submit to the community, and the reason text when you report someone else's content | Provide the core function of the app: save your artwork, publish it if you choose to, and moderate reported content | Our own servers. Image files are stored on our infrastructure, not on a third-party image host |
| Activity in the app: tutorial progress, bookmarks, views, likes, votes in polls, ranking position | Save your progress across devices, produce the community feed and the artist ranking | Our own servers |
| Answers to the questions asked when you first open the app | Recommend tutorials that match your level and interests | Our own servers |
| Push notification token, device model and platform, app language, and the time zone your device reports (e.g. “Europe/Paris”), if any | Send you the notifications you enabled, and serve content in your language. For some of the notification campaigns we send, we also use the reported time zone to schedule that notification at a reasonable local hour rather than sending it at whatever time it happens to be where our servers are | Google Firebase Cloud Messaging / Apple Push Notification service, and our own servers |
| The date your account was created | Basic account administration; and, in aggregate across all accounts, to measure how many people are still active some time after they join (“retention”) | Our own servers |
| A running count, for each of the 24 hours of the day (UTC), of how often your account has been active at that hour — 24 numbers, not a log of dates or events | Reviewed in aggregate to understand overall usage patterns. For some of the notification campaigns we send, we also use it to estimate the local time of day you tend to use the app — so that notification can be scheduled at a reasonable hour when your device has not reported a time zone | Our own servers |
| The most recent time your account made a signed-in request to our servers | Basic account administration; measured in aggregate, alongside the account creation date above, to understand how many people remain active some time after they join (“retention”). Also used, for some of the notification campaigns we send, to skip sending you one if you have used the app in roughly the last twenty minutes — so that a notification does not arrive right after you have already opened it yourself | Our own servers |
| Two small internal bookkeeping values used to pace “come back” reminder notifications: a snapshot of the last time you were active, and the highest reminder stage already sent for it (for example, after 3, 7 or 30 days without activity) | Make sure we never send you more than one reminder per inactivity stage, and stop sending them altogether once the last configured stage has been reached. Not shown to you directly; once you are active again, the stored stage is disregarded, and is only overwritten the next time a reminder is actually sent | Our own servers |
| Your choices for each of the five notification categories (social activity, new content, contests, inactivity reminders, commercial offers) — whether each is on or off — and, for every time you actually change one of these choices, which category, the previous and new value, and when | Apply the choices you made when we send you a notification; and, in aggregate across all accounts (never singling out your own choices), measure how many people turn off which category and when, so we can tell whether we are sending too many notifications | Our own servers |
| Which tutorials you open, and which category or sub-category screens you view, once per day per item | Reviewed in aggregate to understand which tutorials and categories are popular or trending. The version linked to your account is also used, if you decline to tell us your preferred drawing style when asked (see the next row), to work out a tentative preference from what you open afterwards, and to suggest broadening your declared interests if what you actually browse keeps differing from them — you would always be free to decline either | Our own servers, linked to your account for up to 60 days, then deleted. We also keep the same counts without any link to your account (just a daily total per tutorial or category), which we may keep indefinitely for our own internal statistics |
| Whether we have asked you to state your preferred drawing style, and whether you answered or declined (and when); separately, whether we have proposed broadening your declared interests towards a category you browse often but never declared, and whether you accepted or declined that proposal; and, only if you declined the first of these two and kept opening enough distinct tutorials afterwards, a tentative "which category you seem to prefer" guess worked out from that browsing (see the row above) — kept separate from, and always overridden by, anything you actually tell us directly | Avoid asking you the same question twice, or proposing the same thing twice once you have answered or declined it once; and, for either your stated preference or (only in its absence) the tentative guess described above, order the tutorials and drawing categories you are shown in a way that reflects what you told us, or seem to prefer even though you did not tell us so directly — the tentative guess is always replaced by, never allowed to override, anything you declare yourself, and you can see and correct or dismiss it at any time (see §6) | Our own servers |
| The text you type into the in-app tutorial search, and whether it returned any results | Understand which characters or drawing styles people look for but cannot find, so we can decide what to add to the catalogue next | Our own servers, combined into totals by normalized search term (lower case, accents removed, extra spaces collapsed) — never linked to your account, device or IP address, even temporarily |
| Crash reports and non-fatal errors (stack traces, device state at the time of the crash) | Diagnose and fix crashes | Google Firebase Crashlytics — Android and iOS |
| A small, fixed set of usage events (app opened, account created, artwork published, subscription screen viewed) plus which screen is shown, tied to a non-identifying internal user ID | Understand which parts of the app are used, to decide what to improve | Google Analytics for Firebase — Android only at present |
| Subscription status and purchase history | Unlock paid features and honour restores across your devices | RevenueCat, Apple App Store / Google Play Billing, and our own servers |
| Advertising data: your IP address, technical information about your device (manufacturer and model, OS version, screen, language, memory/storage/processor characteristics, mobile network operator), identifiers the advertising network generates for your app install, and the events needed to show and measure an ad, including viewability (impression, click). If you consent to personalized ads, your device's advertising identifier (Android AAID, Apple IDFA) as well. | Show the ads that fund the free features of the app, and, if you consent, make them more relevant to you | Google AdMob — Android; Unity Ads (Unity Technologies) — iOS. See §3 |
Anonymous use
You can use much of the app without creating an account. In that case a technical, anonymous account is created so your progress can be saved. It holds no email address and no name. If you later sign in, that progress is attached to your new account.
Advertising
On Android: an interstitial ad when you start a tutorial, an interstitial ad when you open the app (at most once every 4 hours, and never more than one interstitial of either kind every 5 minutes), and a banner ad under the step bar. On iOS: a banner ad under the step bar only. New installs see no interstitial ads until the third tutorial is opened, and subscribers see no ads at all. These ads are served by Google AdMob on Android and by Unity Ads (Unity Technologies) on iOS, and fund the free features of the app.
By default, ads are non-personalized. On Android, we tell Google AdMob that you have not consented to personalized advertising, using its “non-personalized ads” request setting; where the law requires it (the EU, the UK or Switzerland), Google's consent tool (User Messaging Platform) may also show you its own certified consent form, in addition to the question described above. On iOS, we tell Unity Ads that you have not consented, using its developer consent signals (“userConsent = false”, “userOptOut = true”, “nonBehavioral = true”). If you consent to personalized ads, we tell the network serving ads on your platform — Google AdMob on Android, Unity Ads on iOS — that it may use your device's advertising identifier (Android AAID, Apple IDFA) to show you more relevant ads. On iOS, consenting also requires Apple's App Tracking Transparency permission: after you accept our own question, iOS shows its system prompt, and personalized ads are enabled only if you allow tracking there. If you decline either one, ads on iOS remain non-personalized. On iOS you can also change Apple's tracking permission at any time in iOS Settings → Privacy & Security → Tracking.
You choose whether to allow personalized ads the first time you are asked, and you can change your mind at any time from the Profile tab, under “Personalized Ads”. On iOS, if you have already refused Apple's tracking prompt, you must also re-enable tracking for SketchLab in iOS Settings → Privacy & Security → Tracking before personalized ads can be turned back on.
What we do not collect
- No personalized advertising without your consent. We ask for your consent before allowing our advertising partner — Google AdMob on Android, Unity Ads on iOS — to use your device's advertising identifier (Android AAID, Apple IDFA), and you can withdraw that permission at any time from your profile — see “Advertising” above.
- No tracking across other companies' apps or websites, and no sale of personal data.
- No precise location, no contacts, no microphone.
2. Why we are allowed to process it (legal basis)
- Performance of a contract — account, saving and publishing your artwork, subscription, and basic account metadata such as its creation date.
- Legitimate interest — keeping the service secure and working, moderating reported content, fixing crashes, showing non-personalized ads that fund the free features of the app, and measuring, on internal reports that only ever show aggregate counts of accounts, how many people remain active some time after they join. Where we say above that we schedule some notifications at a reasonable local hour — using your device's reported time zone or, failing that, your inferred hourly activity pattern — that scheduling capability has shipped and is used for some of the notification campaigns we send; it is not applied to every notification (for instance, an urgent announcement may still be sent to everyone at once). For the same set of campaigns, we also use the time your account was last active to skip sending you a notification if you have just used the app yourself. We also keep two small bookkeeping values per account — described in the table in §1 — so that a “come back” reminder notification is sent at most once per inactivity stage and stops altogether once the last configured stage is reached, rather than repeating indefinitely. We also review, in aggregate statistics that are never linked to an individual account, what people search for in the tutorial catalogue but cannot find, so we can decide what content to add next. We also review, in the same kind of aggregate and never-linked-to-an-account statistics, which tutorials and categories are opened or viewed the most, to understand what is popular or trending in the catalogue; we separately keep a shorter-lived, account-linked version of the same signal (see the table in §1), which we use both to later suggest broadening your declared interests if warranted, and — only if you decline to tell us your preferred drawing style when asked, and only after you keep opening enough distinct tutorials afterwards — to work out a tentative preference on our own. We also keep track, per account, of whether we have asked either of these two questions and how you answered, so that we never ask the same one twice (see the table in §1); any preference we work out this way is always overridden the moment you tell us directly what you actually prefer.
- Consent — push notifications; personalized advertising (your device's advertising identifier — Android AAID or Apple IDFA — is only shared with our advertising partner, Google AdMob on Android or Unity Ads on iOS, if you consent); and the small, fixed set of product usage events (Android only — see §1) used to understand which parts of the app are used. Advertising and usage statistics are governed by the same choice, which we ask for when you first open the app. You can withdraw it at any time (see §6).
- Legal obligation — keeping records of purchases and of content takedowns.
3. Who we share it with
We do not sell your data. It is shared only with the providers we need to run the app, each acting on our instructions:
- Google (Firebase) — Authentication, Cloud Messaging, Crashlytics, Analytics, Installations.
- Apple — Sign in with Apple, push notifications, App Store purchases.
- RevenueCat and Google Play Billing — subscription management.
- Google (AdMob) — serves the ads shown in the app on Android (see “Advertising” in §1). It receives your IP address, technical information about your device, and the events needed to show and measure an ad, including viewability measurement (impression, click). It also receives your device's advertising identifier (Android AAID) if you consent to personalized ads. Where the law requires it (the EU, the UK or Switzerland), Google's consent tool (User Messaging Platform) may show you its own certified consent form, in addition to the question described in “Advertising” above.
- Unity Ads (Unity Technologies) — serves the ads shown in the app on iOS (see “Advertising” in §1). It receives your IP address, technical information about your device (manufacturer and model, operating system version and build, screen size and density, language and keyboard layouts, memory, storage and processor characteristics, mobile network operator, browser user agent, app version and install source), identifiers generated by Unity for your app install (and, where available, the Apple vendor identifier), and the events needed to show and measure an ad, including viewability measurement (impression, click). It also receives your device's advertising identifier (Apple IDFA) if you consent to personalized ads.
- Our hosting provider — our servers are in France, at OVH SAS (2 rue Kellermann, BP 80157, 59100 Roubaix, France), where our database and your uploaded images are stored.
Content you choose to publish (artwork, public username, profile picture, community tutorials) is visible to other users of the app. That is the point of publishing it — but it is your choice, and you can unpublish or delete it at any time.
Some of these providers are based outside your country, including in the United States. Transfers to those providers rely on the safeguards they put in place, such as the EU Standard Contractual Clauses.
4. How long we keep it
- Your account and content — until you delete your account, and then removed as described in §5.
- Crash reports — for the retention period applied by Firebase Crashlytics.
- Advertising data — for the retention period applied by the advertising provider that served the ad (Google AdMob on Android, Unity Ads on iOS).
- Analytics events — 14 months, the Firebase Analytics retention setting configured on the project.
- Purchase records — 10 years, to meet our accounting and tax record-keeping obligations.
- Moderation records (reports, takedowns, blocks) — 1 year.
- Which tutorials/categories you open or view, linked to your account — 60 days, then deleted (or sooner if you delete your account, see §5). The account-independent daily totals mentioned in §1 are not linked to you and may be kept indefinitely.
5. Deleting your account
You can delete your account from inside the app, in your profile settings. Deletion removes your account record — including its creation date, declared time zone, hourly activity counts, last-active time and inactivity-reminder bookkeeping described in §1 — your artwork and uploaded image files, your profile picture, your likes, votes, bookmarks and progress, your onboarding answers, your notifications, your notification category choices and the history of when you changed them, which tutorials and categories you opened or viewed, whether we asked you to state your preferred drawing style or proposed broadening your declared interests (and how you answered either), any tentative preference we worked out on our own from your browsing, and the reports you filed. It also deletes your Firebase authentication identity (the email address, unique identifier and display name Firebase holds to sign you in) — once deleted, that email address is free to be used to create a new, separate account, but your previous account cannot be recovered or restored by support.
Two things may survive deletion: content that was already required to be kept for moderation or legal reasons, and backups, which are overwritten on their normal rotation within 14 days.
Deleting the app from your device does not delete your account — use the in-app option, or write to contact@sketchlabapps.com.
6. Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive a copy in a portable format, and withdraw consent. To exercise any of these, write to contact@sketchlabapps.com. We answer within one month.
You can also turn off push notifications in your device settings at any time. Personalized ads and usage analytics are both governed by the choice you make when you first open the app — you can change it at any time from the Profile tab, and turning it off stops analytics collection immediately. If you would rather ask us directly, write to contact@sketchlabapps.com.
If we have worked out a tentative guess about your preferred drawing style from what you browse (see the row about this in the table in §1), you can see what we currently believe, tell us your actual preference to correct it, or simply dismiss the guess without stating one, at any time from the Profile tab.
If you are in the EU or UK and believe we have mishandled your data, you may complain to your national data protection authority. The data controller is established in France and can be reached at the address above.
7. Children
The app is not directed at children under 13. We do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Because users can publish drawings and see other users' drawings, published content is moderated and can be reported and taken down. See the Terms of Use.
8. Security
Traffic between the app and our servers is encrypted in transit (HTTPS). Access to our servers and database is restricted to the people who need it. Backups of the database are taken automatically. No system is perfectly secure, but if a breach affects your data we will notify you and the competent authority where the law requires it.
9. Changes to this policy
If we change this policy we will update the effective date above, and, for changes that materially affect you, tell you in the app before they take effect.