░░ legal
TUHIKIMI APP PRIVACY POLICY
§ 1. DEFINITIONS
- Controller / Publisher – Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik, ul. Żelazna 51/53, 00‑841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754, to the extent that he determines the purposes and means of the processing of personal data.
- App – the Tuhikimi mobile application for Android devices.
- Local Data – data used by the App on the Device which, under the App’s current architecture, is not transmitted to the Publisher or stored on the Publisher’s servers.
- Google Play – the Google Play platform and related Google services used to distribute the App and handle purchases.
- ML Kit – Google ML Kit Digital Ink Recognition, Google technology used by the App to recognise handwriting.
- Policy – this App Privacy Policy.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- User – a person using the App.
- Device – an Android device on which the App is installed.
§ 2. CONTROLLER AND SCOPE OF THE POLICY
- The controller of personal data processed by the Publisher in connection with the App is Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik, address disclosed in the Polish Central Register and Information on Economic Activity (CEIDG): ul. Żelazna 51/53, 00‑841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754.
- For matters concerning personal data protection, the Publisher may be contacted via the contact form available at https://tuhikimi.app/#contact.
- This Policy concerns the processing of data in connection with use of the App. For transparency, it also describes operations performed locally by the App on the Device, even though the Publisher does not receive that data and has no remote access to it. The description of such operations does not mean that the data is transmitted to the Publisher’s systems. The rules governing processing in connection with use of the tuhikimi.app website are described in the separate Website Privacy Policy.
§ 3. DATA ASSOCIATED WITH USE OF THE APP
3.1. Premium Access and Google Play
- Purchases of premium features are handled through Google Play. The Publisher does not receive the User’s payment card details or other full payment instrument details.
- The App obtains from Google Play technical information necessary to determine whether the Device has an entitlement to Premium Access. The result of that verification may be stored locally on the Device so that premium features can also operate without a current Internet connection. The Publisher does not transmit the locally stored entitlement status, purchase identifiers or tokens to its own server infrastructure, does not maintain its own database of Users, purchases or Premium Access entitlements, and has no remote access to such information stored on the Device.
3.2. Voluntary error reports
- The error-reporting function is optional and disabled by default. The App does not transmit error reports automatically or in the background.
- If the User independently chooses to report an error, the App may prepare a draft message containing technical information useful for diagnosing the issue, such as the Device model, Android version, App version or a diagnostic log excerpt.
- The draft report is opened in the User’s email application. Before sending, the User may review, modify or remove its contents. The report is transmitted to the Publisher only as a result of the User independently sending the message from their own email application.
- The report is not intended to transmit the address book, the list of installed applications or the content of the User’s handwriting.
§ 4. DATA PROCESSED LOCALLY BY THE APP
- The App uses data stored on the Device in order to provide its core functions. This includes, in particular, contact data, information about applications installed on the Device and locally stored information about Premium Access status. Contact data and application information may be indexed and searched locally, and the App may store on the Device information about the frequency with which individual results are selected in order to rank search results accordingly.
- Under the App’s current architecture, contact data, information about installed applications, the local index, local scoring and locally stored Premium Access status are not transmitted to the Publisher or stored on the Publisher’s servers. The Publisher has no access to the contents of the User’s address book, the list of applications installed on the Device or the locally stored Premium Access status.
- After a contact or application is selected, the App passes the relevant command to the Android system or the relevant application on the Device. Information used to perform such an action remains on the Device, subject to operations performed by the operating system or the selected external service.
- Characters drawn or written by the User are recognised using ML Kit. The content of the handwriting and the recognition result remain on the Device, and recognition itself is performed locally. Recognition models may be downloaded from Google infrastructure.
- Irrespective of local recognition, according to Google’s current documentation, ML Kit packages may transmit to Google technical and diagnostic data concerning operation of the SDK, including in particular Device and App information, installation identifiers not intended to uniquely identify a user or device, performance and usage metrics and – for Digital Ink Recognition – configured languages. This data is processed by Google in connection with ML Kit; the Publisher does not use it for its own behavioural analytics of Users in the App.
- The User may manage the App’s access to Device data and functions through Android system settings. Clearing App data or uninstalling the App deletes Local Data stored by the App on the Device, subject to data stored independently by Android or other applications.
§ 5. PURPOSES AND LEGAL BASES OF PERSONAL DATA PROCESSING BY THE PUBLISHER
| Purpose of processing | Legal basis |
|---|---|
| Handling User correspondence, enquiries, complaints and support | Article 6(1)(b) GDPR – where the contact concerns the Agreement or steps taken prior to entering into it; otherwise Article 6(1)(f) GDPR – the legitimate interest in conducting correspondence and handling submissions |
| Diagnosing errors and technical problems reported by the User | Article 6(1)(f) GDPR – the legitimate interest in ensuring proper operation of the App; to the extent related to performance of the Agreement, also Article 6(1)(b) GDPR |
| Compliance with legal obligations | Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights |
§ 6. DATA RECIPIENTS
- With respect to personal data actually received or processed by the Publisher, data may be entrusted to service providers used to support the App and contact with the User, in particular Google Workspace in connection with correspondence and voluntary error reports.
- Irrespective of the above, certain third parties may process data independently as separate controllers. This applies in particular to Google in connection with Google Play, payment processing and technical and diagnostic data associated with ML Kit. The Publisher does not determine the purposes and rules of such processing carried out independently by Google; the applicable information is set out in Google’s terms and policies.
- Data may also be disclosed to professional advisers, including law firms or accounting service providers, as well as to public authorities and other entities entitled to receive data under applicable law.
§ 7. TRANSFERS OF DATA OUTSIDE THE EEA
- Some service providers or independent controllers, in particular entities within the Google group, may process personal data outside the European Economic Area or use infrastructure with a global reach.
- Where the Publisher is responsible for a transfer of data outside the EEA, the transfer is carried out in accordance with Chapter V GDPR, in particular on the basis of a European Commission adequacy decision (including, where applicable, the EU-U.S. Data Privacy Framework) or using appropriate safeguards such as Standard Contractual Clauses. Information on the mechanism applicable to a specific transfer may be obtained by contacting the Publisher.
§ 8. DATA RETENTION BY THE PUBLISHER
| Data category | Retention period or criterion |
|---|---|
| User correspondence and submissions | for the period necessary to handle the matter and thereafter for a period justified by the need to document the course of correspondence or protect against claims |
| Voluntary error reports | for the period necessary to diagnose and resolve the issue and thereafter to the extent justified by documenting the handling of the submission or protecting against claims |
| Data processed to comply with legal obligations or protect claims | for the period resulting from applicable law or until expiry of the applicable limitation period for claims |
§ 9. RIGHTS OF DATA SUBJECTS
- To the extent that the Publisher processes personal data as a controller, the data subject has, subject to the conditions set out in the GDPR, the rights of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Article 6(1)(f) GDPR.
- Where processing is based on consent, the data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
- The Publisher does not receive copies of the Local Data described in § 4 and has no remote access to it; therefore, the Publisher cannot search for, retrieve, rectify or provide such data in response to a request addressed to the Publisher. The User can manage that data directly on the Device, in particular through the App or Android system settings, by clearing App data or uninstalling the App.
- The data subject has the right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (https://uodo.gov.pl).
§ 10. PROVISION OF DATA AND AUTOMATED DECISION-MAKING
- Providing data in correspondence or an error report is voluntary; however, failure to provide data enabling the matter to be identified or a reply to be given may make it impossible to handle the matter.
- The Publisher does not use personal data to make decisions concerning the User based solely on automated processing that produce legal effects or similarly significantly affect the User. Local ranking of search results based on selection frequency operates on the Device and is not used for such decision-making.
§ 11. DATA SECURITY
The Publisher applies appropriate technical and organisational measures to protect personal data processed by it in connection with the App, taking into account the nature of the data, the scope of processing and the related risk. The App’s architecture limits the scope of data transmitted outside the Device by performing core search functions locally.
§ 12. CHANGES TO THE POLICY AND CONTACT
- This Policy may be updated in particular in connection with changes to the App, services used, applicable law or the manner in which personal data is processed. The current version of the Policy is published at a permanent, publicly accessible address designated by the Publisher.
- If a change to the Policy involves a material change in the manner in which personal data is processed, the Publisher will provide data subjects with appropriate information to the extent and in the form required by law.
- For matters concerning this Policy or the processing of personal data, the Publisher may be contacted via the contact form at https://tuhikimi.app/#contact.