Privacy Policy

Last updated: May 2026

1. Who We Are

Shikan is operated by Pygocen Ltd (Company No. 16080946), a company registered in England and Wales. Registered address: Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE. We are the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR).

2. Information We Collect

Account information: When you create an account, we collect your email address and display name. You may optionally set a username and profile avatar.

Meditation data: Session duration, completion timestamps, routine configurations, and program progress are stored to provide your session history and analytics.

Device information: We collect basic device identifiers for push notifications and crash reporting.

3. Website Cookies and Analytics

This website (shikanmeditation.com) is separate from the Shikan mobile app and has its own consent flow. We distinguish between three categories of browser storage:

Essential: a small number of first-party storage entries keep you signed in to the ambassador or admin dashboards (Firebase Authentication session token) and remember UI preferences you set yourself (e.g. the demo-mode toggle). These are always on — they do not require consent under the UK Privacy and Electronic Communications Regulations (PECR) or the EU ePrivacy Directive, because the site cannot function without them.

Analytics: if enabled, we load Google Analytics 4 (gtag.js) to understand which pages are visited and where visitors come from. We use Google Consent Mode v2 to honour your choice: when analytics is set to denied, Google's SDK does not store identifiers or send full event data to our property — pings without identifiers may still fire so the underlying configuration works, but no individual usage profile is built.

Marketing:if enabled, we permit Google's ad-related signals (ad_storage, ad_user_data, ad_personalization) for measuring future paid campaigns. We do not currently run any third-party advertising trackers other than Google's own consent-aware tags; this category exists so any future campaign respects whatever you chose here.

The cookie banner at the bottom of the page lets you Accept all, Reject all, or open the details panel to toggle Analytics and Marketing individually. Your choice is stored in your browser's local storage (key shikan_cookie_consent_v1) and persists across visits. To change it later, click the Cookies link in the site footer — the banner reopens with your current preferences pre-filled.

4. How We Use Your Information

  • To provide and improve the app experience
  • To sync your data across devices (if you have Shikan Pro)
  • To display your profile to friends you connect with
  • To send push notifications you have opted into (session reminders, friend activity)
  • To analyse app usage and performance (Firebase Analytics, Firebase Crashlytics)
  • To display ads to free-tier users via Google AdMob

5. Legal Basis for Processing (EEA/UK)

We process your personal data on the following legal grounds:

  • Contract: Processing necessary to provide the app and its core features (account management, meditation tracking, data sync, push notifications).
  • Consent: Personalised advertising, ad measurement, and analytics data collection. Where required by law, we ask for your consent before these services are activated. You can withdraw consent at any time through the Privacy Settings option in the app.
  • Legitimate interest: Crash reporting (Firebase Crashlytics) to maintain app stability and security. We disable crash reporting if you decline consent in regions where this is required.

6. Data Storage and International Transfers

Your meditation data is stored locally on your device using a SQLite database. If you are signed in, select data is synced to Google Cloud Firestore to enable multi-device access and social features. Data is stored on servers located in the United States and Europe.

Where your data is transferred outside the UK or EEA (for example, to servers in the United States), we rely on the safeguards provided by our third-party service providers. Google's services operate under the EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs) approved by the European Commission. RevenueCat processes data in the United States under SCCs. These mechanisms ensure that your data receives an adequate level of protection as required by the UK GDPR and EU GDPR.

7. Third-Party Services

We use the following third-party services:

  • Firebase Authentication — account management
  • Cloud Firestore — data sync and social features
  • Firebase Cloud Messaging — push notifications
  • Firebase Analytics — anonymous usage analytics
  • Firebase Crashlytics — crash reporting and app stability
  • Google AdMob — advertising (free tier only)
  • RevenueCat — purchase management

Each service has its own privacy policy governing their use of your data. Google's services are governed by Google's Privacy Policy.

8. Apple Health

On iOS, if you enable “Sync to Apple Health” in Settings, Shikan writes your completed meditation sessions to Apple Health as Mindful Sessions, recording their start and end times so they count toward your Mindful Minutes. This is off by default and happens only after you turn it on and grant permission.

Shikan does not read any data from Apple Health, and this information is stored only on your device by Apple Health — it is never sent to our servers or shared with third parties. You can turn it off at any time in Shikan's Settings, or revoke access in iOS Settings → Privacy & Security → Health.

9. Social Features

If you use social features, your display name, username, avatar, and recent session activity may be visible to users you have added as friends. You can remove friends or block users at any time. Blocked users cannot see your profile.

10. Advertising

Free-tier users see banner advertisements provided by Google AdMob. AdMob may collect device advertising identifiers and usage data to serve and measure ads. AdMob works with third-party ad networks and partners, which may also receive this data — you can view the full list of Google's ad technology partners at Google's partner list.

In the EEA and UK, ads and related data collection are only activated after you provide consent through the consent dialog shown on first launch. You can change your consent choice at any time via Settings → Privacy Settings in the app. If you decline consent, no ads are shown and no ad-related data is collected.

Shikan Pro users do not see any ads.

11. Data Retention and Deletion

Your meditation data, routines, and profile information are retained as long as your account is active. Firebase Analytics data is retained for 2 months. Firebase Crashlytics crash reports are retained for 90 days. Ad-related data collected by Google AdMob is subject to Google's retention policies. You can export your data at any time from the app settings.

Account deletion: You can delete your account directly from the app (Settings → Delete Account). This permanently removes your account and all associated data, including your profile, meditation history, routines, and settings. Alternatively, you may request deletion by contacting us at info@shikanmeditation.com.

12. Your Rights

Under the UK GDPR and EU GDPR, you have the right to:

  • Access the personal data we hold about you
  • Export your meditation data
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Restrict or object to certain processing activities
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time for consent-based processing (advertising, analytics), without affecting the lawfulness of processing before withdrawal

To manage your advertising and analytics consent, go to Settings → Privacy Settings in the app. For all other requests, contact us at info@shikanmeditation.com.

13. Children's Privacy

Shikan is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child, please contact us.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email.

15. Contact

If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at: info@shikanmeditation.com

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EU, you may contact the data protection authority in your country of residence.