In short
- We collect no personal data. The app has no accounts, no sign-in and no server.
- Your allergies, profiles and travel sets stay on your device. They are never sent to us and we cannot access them.
- No ads, no analytics, no tracking. We use no advertising identifiers and no profiling tools.
- No data is shared with third parties.
- Payments are handled by Google Play — we never see your payment details.
1. Controller and contact
- The controller under the GDPR for any data relating to the AllerGo application (the “App”) is Adrian Kazula, an individual running the AllerGo project.
- For all privacy matters, contact: bzul.dev@gmail.com.
- No data protection officer has been appointed, as the conditions requiring one do not apply.
- This policy covers the AllerGo mobile app distributed via Google Play and this website hosting the legal documents.
2. What we do NOT collect
The App is designed to work offline. Accordingly we do not collect, store on servers, or pass to anyone, in particular:
- your name, email address, phone number or postal address;
- information about allergies, illnesses or health status;
- user account data — the App has no registration and no sign-in;
- location, contacts, calendar, photos, microphone or camera data;
- the Advertising ID or any other tracking identifier;
- analytics, usage statistics, in-app events or crash reports sent to us;
- payment data — card numbers, bank details or billing information.
The App contains no advertising SDKs, no analytics SDKs and no profiling tools. We operate no server and no database to which the App would send any information.
3. Data stored locally on your device
- To function, the App saves the information you enter only in your device’s storage, in the app data area protected by Android. This includes:
- selected allergens and their display settings;
- allergy profiles (including family profiles) and the active profile;
- travel sets;
- the selected destination country, card language and interface language;
- view preferences and app settings;
- whether onboarding was completed, and the version and date of the accepted terms;
- the Pro entitlement status cached locally.
- This data is never sent to us. We cannot read it, recover it or delete it remotely.
- Home screen widgets use a separate local store on the device to display the current card. That data also never leaves the device.
- PDF files you export are saved to your device storage (the Downloads/AllerGo folder). Any further use, including sharing them with anyone, happens solely at your initiative and under your control.
4. Health and allergy information
- Allergy information belongs to the special categories of data referred to in Article 9 GDPR and calls for particular care.
- That is precisely why the App is designed so that such information never leaves your device. We do not process it as a controller, because it never reaches us.
- Note that an information card is, by its nature, shown to other people (for example venue staff). What you disclose in this way depends entirely on your decision to show, print, send or place the card on a home screen widget. A widget may be visible to anyone who can see your device.
5. Third-party services and components
The App uses a small number of third-party components. We describe them openly below, even though we send them no personal data ourselves.
5.1 Google Play Billing (purchases)
- If you choose to buy AllerGo Pro, Google carries out and settles the transaction. Google is the seller and processes payment data as a separate controller, under its own rules.
- We do not receive or store card numbers, billing data or your Google account details. The App only reads a technical entitlement status (whether a purchase is active).
- Google’s policy: policies.google.com/privacy.
5.2 The Google Play Store
- Downloading and updating the App happens through Google Play, which operates independently of us and may collect data under its own policy.
- If you have enabled system-level error reporting and usage statistics on Android, Google may provide us with aggregated, anonymised statistics and crash reports in the Play Console (for example install counts, device models, crash stack traces). These do not identify you and contain none of the content you entered in the App. This channel is controlled by Google and you can disable it in your device and Google account settings.
5.3 Android text-to-speech
- The read-aloud feature passes the card text to the speech synthesis engine installed on your operating system (for example Google’s engine or your device manufacturer’s). The card text is sent there only once you start the read-aloud yourself.
- The App may prepare a voice for the chosen language in advance, passing the engine a single neutral letter and never the content of your card.
- How that engine behaves — including whether it processes text locally or over a network connection — depends on its provider and your device settings, and is outside our control. Processing is governed by the TTS engine provider’s terms.
- The App can open your system speech settings screen, but it neither reads nor changes those settings.
- If you prefer that card content is not passed to a TTS engine, simply do not use the read-aloud feature.
5.4 This website
- This legal-documents site is hosted on GitHub Pages (GitHub, Inc.). The hosting provider may process technical access data, including IP addresses, to deliver the site and maintain security.
- The site uses no cookies, no analytics and no forms.
6. App permissions
- The App does not request access to location, contacts, calendar, camera, microphone or photos.
- The application package declares the internet and network-state permissions. The Google Play Billing library and standard system components require internet access; the App checks network state for one purpose only, so that the automatic voice preparation waits for an unmetered connection. The App’s own code makes no network calls of its own and sends your data to no server. The system speech engine may use a network connection as described in 5.3.
- PDF files are written through the system storage mechanism into the Downloads folder and do not require access to your whole device storage on current Android versions.
7. Children and teenagers
- The App is intended for users aged 13 and over and is not directed to children under that age.
- We collect no personal data from any user — including minors. Since no data is collected, we hold no data about children or teenagers either.
- The App contains no advertising, applies no tracking or profiling, and shares no data with third parties for marketing purposes.
- This approach ensures compliance with the US COPPA and with Article 8 GDPR on the data of minors — in both cases precisely because no data is collected.
- If you are a guardian with questions about a child’s privacy when using the App, contact us at bzul.dev@gmail.com.
8. Retention and deletion
- We store none of your data, so no retention periods apply on our side.
- Data stored locally remains on your device for as long as the App is installed.
- You can delete all App data yourself:
- by deleting individual profiles, sets or allergens inside the App, or
- via Android settings: Apps → AllerGo → Storage → Clear data, or
- by uninstalling the App.
- If you have enabled Android system backup, the system may back up app data to your Google account. That is an Android mechanism controlled by Google and by you; it can be disabled in your device settings.
- Purchase history remains in your Google Play account under Google’s rules and is outside our control.
9. Security
- Data saved by the App is protected by the Android application sandbox — other apps cannot access it under normal conditions.
- Because there is no data transmission, there is no risk of interception in transit to a server or of a server-side breach, as no such server exists.
- Security therefore depends on protecting the device itself. We recommend using a screen lock, keeping the system updated and avoiding apps from unknown sources. A device with unlocked administrative access (root) weakens system protections.
- If you find a vulnerability or security problem, report it to bzul.dev@gmail.com.
10. Your rights
- The GDPR grants data subjects rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
- Because we collect and store none of your personal data, we cannot identify you or link you to any data on our side (Article 11 GDPR). In practice this means you control your data yourself, on your own device, as described in section 8.
- For data processed by Google (purchases, the store, your account, system backup, the TTS engine) you exercise these rights against Google under its privacy policy.
- You have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl). You may also contact the authority for your place of residence.
- California residents: we do not sell or share personal information as defined by the CCPA/CPRA, because we collect none.
11. International transfers
We transfer no personal data outside the European Economic Area, because we collect none. Any transfers carried out by Google (in connection with the store, payments, backup or the TTS engine) and by this site’s hosting provider are made on the terms and legal bases set by those entities.
12. Legal basis
We do not process personal data of App users, so no legal basis under Article 6 GDPR arises on our side. If you write to us by email, we process the data contained in your message solely to answer you and handle your request — on the basis of our legitimate interest (Article 6(1)(f) GDPR), and for complaints in order to meet our statutory obligations (Article 6(1)(c) GDPR). We keep correspondence for as long as needed to handle the matter and demonstrate that it was handled.
13. Changes to this policy
- This policy may be updated, in particular if the App’s functionality changes, new components are added, or the law changes.
- The current version is always available at this address, with its version number and effective date.
- We will announce material changes in the App before they take effect — especially any change that would introduce data collection.
14. Contact
Adrian Kazula
Email: bzul.dev@gmail.com
15. Language versions
This policy is published in Polish and English. In the event of discrepancy the Polish version prevails, provided that this does not deprive you of the protection afforded by mandatory provisions of the law of your country of habitual residence.