AllerGo

Privacy Policy

Version 1.1 · effective 27 August 2026

In short

1. Controller and contact

  1. The controller under the GDPR for any data relating to the AllerGo application (the “App”) is Adrian Kazula, an individual running the AllerGo project.
  2. For all privacy matters, contact: bzul.dev@gmail.com.
  3. No data protection officer has been appointed, as the conditions requiring one do not apply.
  4. This policy covers the AllerGo mobile app distributed via Google Play and this website hosting the legal documents.

2. What we do NOT collect

The App is designed to work offline. Accordingly we do not collect, store on servers, or pass to anyone, in particular:

The App contains no advertising SDKs, no analytics SDKs and no profiling tools. We operate no server and no database to which the App would send any information.

3. Data stored locally on your device

  1. To function, the App saves the information you enter only in your device’s storage, in the app data area protected by Android. This includes:
    • selected allergens and their display settings;
    • allergy profiles (including family profiles) and the active profile;
    • travel sets;
    • the selected destination country, card language and interface language;
    • view preferences and app settings;
    • whether onboarding was completed, and the version and date of the accepted terms;
    • the Pro entitlement status cached locally.
  2. This data is never sent to us. We cannot read it, recover it or delete it remotely.
  3. Home screen widgets use a separate local store on the device to display the current card. That data also never leaves the device.
  4. PDF files you export are saved to your device storage (the Downloads/AllerGo folder). Any further use, including sharing them with anyone, happens solely at your initiative and under your control.

4. Health and allergy information

  1. Allergy information belongs to the special categories of data referred to in Article 9 GDPR and calls for particular care.
  2. That is precisely why the App is designed so that such information never leaves your device. We do not process it as a controller, because it never reaches us.
  3. Note that an information card is, by its nature, shown to other people (for example venue staff). What you disclose in this way depends entirely on your decision to show, print, send or place the card on a home screen widget. A widget may be visible to anyone who can see your device.

5. Third-party services and components

The App uses a small number of third-party components. We describe them openly below, even though we send them no personal data ourselves.

5.1 Google Play Billing (purchases)

5.2 The Google Play Store

5.3 Android text-to-speech

5.4 This website

6. App permissions

  1. The App does not request access to location, contacts, calendar, camera, microphone or photos.
  2. The application package declares the internet and network-state permissions. The Google Play Billing library and standard system components require internet access; the App checks network state for one purpose only, so that the automatic voice preparation waits for an unmetered connection. The App’s own code makes no network calls of its own and sends your data to no server. The system speech engine may use a network connection as described in 5.3.
  3. PDF files are written through the system storage mechanism into the Downloads folder and do not require access to your whole device storage on current Android versions.

7. Children and teenagers

  1. The App is intended for users aged 13 and over and is not directed to children under that age.
  2. We collect no personal data from any user — including minors. Since no data is collected, we hold no data about children or teenagers either.
  3. The App contains no advertising, applies no tracking or profiling, and shares no data with third parties for marketing purposes.
  4. This approach ensures compliance with the US COPPA and with Article 8 GDPR on the data of minors — in both cases precisely because no data is collected.
  5. If you are a guardian with questions about a child’s privacy when using the App, contact us at bzul.dev@gmail.com.

8. Retention and deletion

  1. We store none of your data, so no retention periods apply on our side.
  2. Data stored locally remains on your device for as long as the App is installed.
  3. You can delete all App data yourself:
    • by deleting individual profiles, sets or allergens inside the App, or
    • via Android settings: Apps → AllerGo → Storage → Clear data, or
    • by uninstalling the App.
  4. If you have enabled Android system backup, the system may back up app data to your Google account. That is an Android mechanism controlled by Google and by you; it can be disabled in your device settings.
  5. Purchase history remains in your Google Play account under Google’s rules and is outside our control.

9. Security

  1. Data saved by the App is protected by the Android application sandbox — other apps cannot access it under normal conditions.
  2. Because there is no data transmission, there is no risk of interception in transit to a server or of a server-side breach, as no such server exists.
  3. Security therefore depends on protecting the device itself. We recommend using a screen lock, keeping the system updated and avoiding apps from unknown sources. A device with unlocked administrative access (root) weakens system protections.
  4. If you find a vulnerability or security problem, report it to bzul.dev@gmail.com.

10. Your rights

  1. The GDPR grants data subjects rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
  2. Because we collect and store none of your personal data, we cannot identify you or link you to any data on our side (Article 11 GDPR). In practice this means you control your data yourself, on your own device, as described in section 8.
  3. For data processed by Google (purchases, the store, your account, system backup, the TTS engine) you exercise these rights against Google under its privacy policy.
  4. You have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl). You may also contact the authority for your place of residence.
  5. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, because we collect none.

11. International transfers

We transfer no personal data outside the European Economic Area, because we collect none. Any transfers carried out by Google (in connection with the store, payments, backup or the TTS engine) and by this site’s hosting provider are made on the terms and legal bases set by those entities.

12. Legal basis

We do not process personal data of App users, so no legal basis under Article 6 GDPR arises on our side. If you write to us by email, we process the data contained in your message solely to answer you and handle your request — on the basis of our legitimate interest (Article 6(1)(f) GDPR), and for complaints in order to meet our statutory obligations (Article 6(1)(c) GDPR). We keep correspondence for as long as needed to handle the matter and demonstrate that it was handled.

13. Changes to this policy

  1. This policy may be updated, in particular if the App’s functionality changes, new components are added, or the law changes.
  2. The current version is always available at this address, with its version number and effective date.
  3. We will announce material changes in the App before they take effect — especially any change that would introduce data collection.

14. Contact

Adrian Kazula
Email: bzul.dev@gmail.com

15. Language versions

This policy is published in Polish and English. In the event of discrepancy the Polish version prevails, provided that this does not deprive you of the protection afforded by mandatory provisions of the law of your country of habitual residence.