Privacy Policy
1.Data Controllers
The Ciało service is operated jointly on Android and iOS. The data controllers are:
- Mieszko Misztal — publisher of the Android version on Google Play.
- Rafal Rubiszewski — publisher of the iOS version on the Apple App Store.
We act as joint controllers within the meaning of Article 26 of the GDPR. We jointly determine the purposes and means of processing your personal data through a shared backend infrastructure used by both platforms.
The essence of our joint-controller arrangement is as follows: we share responsibility for the App's data processing, we use a common backend, and we have agreed on a single contact point for handling your requests. Regardless of which platform you use, you may exercise all of your rights against either of us — we coordinate internally.
cialo.dev@gmai.com
2.Scope of this Policy
This Policy describes how we process personal data when you use the Ciało mobile application on Android or iOS (the “App”). It applies to both platforms; where the platforms differ, we say so.
3.Data We Collect
We collect only the data needed to operate the App and provide its features.
3.1. Account and authentication
- Email address and name received from your login provider via Auth0 (Auth0 may federate to Google or Apple sign-in).
- A unique user identifier issued by Auth0.
- Authentication tokens (access token and refresh token) stored securely on your device.
3.2. Device and technical data
- Device model, operating system version, language, time zone, App version, and an install identifier.
- A push notification token (Firebase Cloud Messaging on Android and iOS; Apple Push Notification service is also used on iOS). The token is uploaded to our backend and linked to your account so we can deliver notifications.
3.3. Beacon and venue presence
- When you are near a venue beacon, the App detects the iBeacon signal (UUID, major, minor) and records entry/exit events together with timestamps and signal strength.
- We do not collect raw GPS coordinates. Location permissions are requested only because Android and iOS require them in order to perform Bluetooth scanning.
3.4. Health and fitness data (step count)
- The App reads your step count during event time windows in order to award activity-based rewards.
- Android: step count is read from Google Health Connect with your explicit
grant of the Read steps permission (
android.permission.health.READ_STEPS). We do not read any other Health Connect data type and we do not write to Health Connect. - iOS: step count is read from the system CoreMotion framework
(
CMPedometer). The App does not use Apple HealthKit. - We upload the aggregated step count and the time range it covers to our backend. We do not upload individual step records or other fitness data.
3.5. In-app activity, diagnostics and crashes
- Events, screens viewed and feature usage, used to understand how the App is used and to improve it.
- Crash logs and performance/diagnostic data, used to identify and fix bugs.
- Collected via Firebase Analytics and Firebase Crashlytics (Android), and via Firebase Analytics and Microsoft Visual Studio App Center Analytics + Crashes (iOS).
3.6. User-generated content (the “wall” feature)
- Short videos (up to approximately 30 seconds) that you intentionally record and submit. The camera and microphone are accessed only while you are actively recording.
3.7. Barcode / QR scanning (Android only)
- Codes that you scan are processed locally on your device by Google ML Kit. Only the scan result (for example, an event code) is sent to our backend.
3.8. What we do not collect
- We do not collect precise GPS coordinates beyond what Bluetooth scanning requires.
- We do not access your contacts, calendar, photo library (other than the video you actively record), biometric data, payment data, or advertising identifiers (IDFA, Android Advertising ID).
- We do not sell your data, and we do not share it with advertisers.
4.Purposes and Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the App and your account | (b) performance of a contract |
| Detecting beacon presence and awarding event rewards | (b) performance of a contract |
| Reading step count for activity-based rewards | (a) consent (granted via the Health Connect / Motion & Fitness permission) |
| Sending push notifications about events and rewards | (a) consent or (f) legitimate interest |
| Diagnostics, analytics and crash reporting | (f) legitimate interest in improving the App |
| Security and abuse prevention | (f) legitimate interest |
| Compliance with legal obligations | (c) legal obligation |
You may withdraw any consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
5.Recipients of Data
We share data only with trusted processors and partners that act on our instructions or are necessary to operate the App:
- Microsoft Azure (EU region) — hosting of the backend used by the App.
- Auth0 (Okta, Inc.) — authentication and identity.
- Google Firebase — push delivery (Cloud Messaging), analytics and crash reporting.
- Apple Push Notification service (Apple Inc.) — push delivery on iOS.
- Microsoft Visual Studio App Center — analytics and crash reporting on iOS.
- Google Health Connect (on-device, Android) — source of step count data.
- Google ML Kit (on-device, Android) — barcode/QR scanning.
- Professional advisors (legal, accounting, IT) bound by confidentiality.
6.Data Retention
- Account data — for as long as your account exists, and for up to [12 months] after deletion to handle disputes, abuse claims and legal obligations.
- Beacon and step-count records — for up to [24 months] after collection, after which they are deleted or aggregated into anonymous statistics.
- Diagnostic and crash data — typically up to [90 days] at the analytics/crash provider, in line with their retention settings.
- User-generated videos — until you delete them, your account, or until we remove them in line with this Policy.
- Records required by law — for the period required by applicable law.
7.Your Rights
Under the GDPR you have the right to:
- access your data and obtain a copy,
- rectify inaccurate or incomplete data,
- have your data erased (“right to be forgotten”),
- restrict processing,
- portability of data you provided,
- object to processing based on legitimate interest,
- withdraw any consent at any time,
- lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) or your national supervisory authority.
You can exercise any of these rights against either joint controller. The simplest path is to write to cialo.dev@gmail.com — we coordinate internally and will action your request within 30 days. You can also delete your account and the data associated with it directly in the App at Settings → Account → Delete account.
8.Device Permissions
The App uses the following system permissions. You can revoke any of them at any time in your device settings; some App features will then stop working.
Android
- Bluetooth scan and connect — to detect iBeacons at venues.
- Approximate and precise location — required by Android to perform any Bluetooth scan; we do not record GPS coordinates.
- Foreground service for location and connected devices — keeps beacon scanning alive while you are at a venue; a status notification is shown while it runs.
- Notifications — to deliver event updates and rewards.
- Health Connect — Read steps — to count steps for activity-based rewards.
- Camera and microphone — only while you are recording a video for the “wall” feature.
- Exact alarm — to wake the App at scheduled event times.
iOS
- Bluetooth — iBeacon detection.
- Location — to enable beacon scanning at venues, including in the background while you are at an event.
- Motion & Fitness — step count via CoreMotion.
- Camera and microphone — only while you are recording a video for the “wall” feature.
- Notifications — for event updates and rewards.
- Background modes: Bluetooth-central, location updates, background fetch, background processing and remote notifications, all to support continuous beacon detection at venues.
9.Children
The App is not directed to persons under [16 years of age] and we do not knowingly collect their data. If we learn that data of a person under that age has been provided without a guardian’s consent, we will delete it without undue delay.
10.Security
- Transport encryption (TLS) for all communication between the App and our backend.
- Role-based access control on backend resources.
- Secure storage of authentication tokens on your device.
- Regular updates and security reviews of dependencies.
- Data minimization across all features.
11.Third-Party Services
The App integrates third-party SDKs and services governed by their own privacy policies:
- Auth0 by Okta — okta.com/privacy-policy
- Google Firebase (Cloud Messaging, Analytics, Crashlytics) — firebase.google.com/support/privacy
- Apple Push Notification service (iOS) — apple.com/legal/privacy
- Microsoft Visual Studio App Center (iOS) — privacy.microsoft.com
- Google Health Connect (Android) — health.google/health-connect-android
- Google ML Kit (Android) — developers.google.com/ml-kit/terms
- Facebook SDK — facebook.com/privacy/policy
- Google Sign-In — policies.google.com/privacy
12.International Transfers
Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission and on any additional safeguards required by applicable law. You can request a copy of the safeguards in place by writing to cialo.dev@gmail.com.
13.California and US State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you have the right to know, access, correct, delete and opt out of the “sale” or “sharing” of your personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising. To exercise these rights, contact cialo.dev@gmail.com.
14.Changes to This Policy
We may update this Policy from time to time. We will inform you of material changes in the App or by email at least [14 days] before they take effect. The current version is always available at [link to policy].
15.Contact
For any privacy-related matter, on either platform, the simplest path is the shared contact: