← Back to Sip

1. What this notice covers

This notice explains the third-party SDKs and similar technologies used by Sip that may process data beyond your device. It supplements our Privacy Policy, which covers our overall data practices. Where the Privacy Policy refers to analytics, advertising, crash reporting or the weather feature, the detail is here.

"SDK" (Software Development Kit) means a library embedded in Sip that enables a specific capability — analytics, advertising, crash reporting, and so on. Unlike browser cookies, SDKs run inside the app rather than in a browser, but they serve similar purposes: measuring app behaviour, enabling ads, and diagnosing problems.


2. How we manage consent

Sip uses Google's User Messaging Platform (UMP) to present an IAB Transparency & Consent Framework (TCF) consent form on first launch.

2.1 — If you are in the EEA or UK, the form appears before any analytics or advertising SDK collects data. You choose which purposes to allow. Your choice is stored on your device and applied every time you open Sip.

2.2 — If you are outside the EEA and UK, analytics and crash collection are enabled automatically, consistent with Google's standard Firebase terms. Advertising is served under Google's terms.

2.3 — You can review or withdraw consent at any time in Settings → Manage Consent. Withdrawing consent stops future collection immediately. Data already collected is subject to the retention periods in §3 below.

2.4 — Sip applies Firebase Consent Mode v2, which defaults all four consent signals (analytics_storage, ad_storage, ad_user_data, ad_personalisation) to DENIED on every launch. No analytics or advertising data leaves your device until the UMP form resolves those signals to GRANTED.


3. SDKs that process data off-device

3.1 Firebase Analytics (Google LLC)

Purpose Understanding how Sip is used; improving features
Consent required (EEA/UK) Yes — analytics consent via UMP form
Data collected In-app events (water intake amount, caffeine intake amount, tutorial steps, streak milestones, save failures, consent decision); user properties (consent state, region, theme, daily water goal in ml, build type, streak lengths)
Not collected Weight, age, sex, activity level, individual drink names, log timestamps, location, display name
Retention 14 months (Firebase default; configurable by Tacit Labs in Firebase Console)
Processor Google LLC, acting on Tacit Labs' instructions under Google's Firebase Data Processing Terms
Transfer Data processed on Google's US infrastructure. Transfer basis: Standard Contractual Clauses (EU Commission Decision 2021/914) with UK Addendum
Google's privacy policy policies.google.com/privacy

3.2 Firebase Crashlytics (Google LLC)

Purpose Diagnosing crashes and improving stability
Consent required (EEA/UK) Yes — bundled with analytics consent
Data collected Stack trace, device model, Android OS version, Sip version name, build type, entitlement tier label (Free / Trial / Pro)
Not collected Hydration or caffeine logs, profile fields (which contain data concerning health), or any user-identifying information
Retention 90 days
Processor Google LLC, under Firebase Data Processing Terms
Transfer As per §3.1

3.3 Firebase Performance Monitoring (Google LLC)

Purpose Measuring app start time and screen load performance
Consent required (EEA/UK) Yes — bundled with analytics consent
Data collected App start time, screen load durations
Note on app start Firebase Performance installs an app-start trace before Sip's own code runs. For users who have not consented, Sip immediately disables collection; any in-memory trace is discarded before it leaves the device. No performance data is transmitted without consent.
Retention 30 days
Processor Google LLC, under Firebase Data Processing Terms
Transfer As per §3.1

3.4 Firebase Remote Config (Google LLC)

Purpose Feature flags and A/B testing
Consent required (EEA/UK) Yes — enabled after analytics consent
Data collected A standard HTTPS fetch with no personal data in the request body. Google may associate the request with a Firebase Installation ID generated post-consent.
Processor Google LLC, under Firebase Data Processing Terms
Transfer As per §3.1

3.5 Google AdMob (Google LLC)

Purpose Serving ads in the free tier of Sip
Consent required (EEA/UK) Yes — ad consent via IAB TCF UMP form
Data collected by Google Ad impression and interaction signals. Google acts as an independent data controller for ad targeting and measurement.
Android Advertising ID (AD_ID) Declared in the app manifest as required by AdMob, but collection is explicitly disabled at the SDK level. Neither AD_ID nor Android SSAID is collected or used by Sip.
EEA/UK users without consent Ads are still shown but are non-personalised.
Sip Pro Purchasing Sip Pro removes all ads.
Google's privacy policy policies.google.com/privacy
Google's ad technology policies.google.com/technologies/ads

4. SDKs and services that do not require consent

The following involve data leaving the device but operate under a contractual necessity basis or are controlled entirely by Google or the user's own Google account. They are not covered by the UMP consent form.

4.1 ipwho.is — optional IP geolocation

When active Only when you tap "Detect my location" in the weather city selector
Data sent Your device's IP address (sent as part of the HTTPS request)
What Sip receives back City name, country, approximate coordinates
What Sip stores City label and rounded coordinates in app settings — the IP address is not stored
Controller ipwho.is acts as an independent data controller for the IP lookup
Legal basis Contractual necessity — required to provide the weather feature you requested
ipwho.is privacy policy ipwho.is

4.2 Open-Meteo — weather data

When active When you search for a city by name, or when the weather feature fetches a daily temperature
Data sent City name text (geocoding search); rounded latitude/longitude to 2 decimal places (≈ 1.1 km) for forecast requests
Precise location Never sent — Sip rounds coordinates before transmission
Controller Open-Meteo acts as an independent data controller
Legal basis Contractual necessity — required to provide the weather feature you requested
Open-Meteo privacy policy open-meteo.com

4.3 Google Play Billing

When active When you purchase Sip Pro
Data handled by Google All payment processing — Tacit Labs never receives card details
Data received by Sip An opaque purchase token and product ID, stored locally on your device
Controller Google LLC for payment processing; token stored locally by Sip

4.4 Google Wearable Data Layer

When active If you have a paired Wear OS watch with the Sip watch app installed
Data sent Hydration log entries routed to your own paired watch via Google's infrastructure
Google's role Transit provider only — data is not persisted on Google servers beyond in-flight routing
Destination Your own watch, not any Tacit Labs system

4.5 Google Health Connect (androidx.health.connect.client)

When active Only if you are a Sip Pro subscriber and you turn on Health Connect sync inside Sip
Data exchanged Sip writes hydration entries (HydrationRecord) and caffeine entries (NutritionRecord with caffeine mass) into Health Connect; reads your latest body weight (WeightRecord) and recent exercise minutes (ExerciseSessionRecord) from Health Connect to keep your daily fluid goal current; also reads back previously written HydrationRecord and NutritionRecord entries during a pull-reconciliation step to import entries logged on a paired Wear OS watch
Permissions declared in the manifest android.permission.health.READ_HYDRATION, WRITE_HYDRATION, READ_NUTRITION, WRITE_NUTRITION, READ_WEIGHT, READ_EXERCISE
Where the data lives In your device's Health Connect store, operated by Google. Sip exchanges data with Health Connect on the device — nothing is sent to Tacit Labs
Lawful basis Your explicit consent, given by turning on the Health Connect toggle inside Sip. Withdraw at any time via Settings → Health Connect or by revoking Sip's Health Connect permissions in the Health Connect system app
What happens if you uninstall Sip Data Sip wrote into Health Connect remains in Health Connect under your control. To delete it you must remove it within Health Connect itself
Health Connect's privacy notice Shown within the Health Connect system app on your device; governed by your Google account

4.6 Google (Android Auto Backup, Google Fonts, Google Play)

These are managed by Google as part of the Android platform and your Google account. Tacit Labs has no control over or access to the data involved. Google's privacy policy applies: policies.google.com/privacy.


5. SDKs that do not transmit data off-device

The following libraries are used by Sip but do not send any data to Tacit Labs or any third party. They are listed here for completeness.

Library Purpose
AndroidX Room Local database for logs, custom drinks and purchase records
AndroidX DataStore Local storage for settings and profile preferences
WorkManager Scheduling local hydration reminders
Glance (widgets) Home-screen widgets
Compose UI, Navigation, Lottie, Material 3 User interface and animations
Hilt Dependency injection
About Libraries Open-source licence screen
OkHttp HTTP client used to make the requests to ipwho.is and Open-Meteo described in §4.1 and §4.2. Does not independently collect or transmit data beyond those described calls

6. How to manage your choices

Action How
Review or change analytics and ad consent Settings → Manage Consent within Sip
Disable Android Auto Backup Android Settings → System → Backup
Revoke notification permission Android Settings → Apps → Sip → Permissions
Delete all on-device Sip data Android Settings → Apps → Sip → Storage → Clear Data
Request deletion of analytics/crash data held by Google Firebase Email privacy@tacitlabs.co.uk

7. Updates to this notice

We will update this notice whenever we add, remove or materially change an SDK that processes data off-device, or when retention periods change. The "Last updated" date at the top of this notice will reflect the most recent change. Material changes will also be noted in the Sip Privacy Policy change log.


8. Questions

Contact us at privacy@tacitlabs.co.uk or write to Tacit Labs Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ.