PuckApp Privacy Policy
Last updated: 11 September 2026
PuckApp has not launched yet (target: soon). This document describes the intended data-processing rules and takes effect once the app becomes available.
This policy explains what personal data the PuckApp mobile app (“PuckApp”, “the app”) and its backend service collect, why, who it is shared with, and the rights you have.
Who is responsible for your data
The data controller for PuckApp is SG Software Development (Szymon Gaweł), based in Poland. For any privacy question or request, contact puckapp@sgsoftware.pl.
What we collect and why
We collect only what the app needs to work. We do not sell personal data, and we do not use it to train AI models.
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address and password (stored only as a salted hash) | Account creation, sign-in, account-related messages | Performance of a contract — Art. 6(1)(b) |
| Display name and household membership | Recognising who triggered an action at home | Art. 6(1)(b) |
| NFC tag configuration (names, assigned actions) | Running the action you programmed when a tag is tapped | Art. 6(1)(b) |
| Event history (which tag, when, by whom) | Showing notifications and the task list to household members | Art. 6(1)(b) |
| Push notification token | Delivering the notifications you opted into | Consent — Art. 6(1)(a) |
| PuckApp PRO subscription status (if you use it) | Unlocking full app functionality | Art. 6(1)(b) |
| IP address, request metadata and server logs | Security, abuse prevention and debugging | Legitimate interest — Art. 6(1)(f) |
Who we share data with
We share data only with service providers needed to run PuckApp, under data processing agreements — including our hosting provider and our push-notification provider. We will name these providers specifically here before launch. We may also disclose data where required by law, or to establish, exercise or defend legal claims.
International transfers
Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or another GDPR transfer mechanism. Contact us for detail on a specific provider.
How long we keep data
- Account and configuration data — kept while your account exists, normally erased within 30 days of deletion.
- Event history — kept while the account exists, unless you clear it sooner in the app.
- Server logs — typically 30–90 days.
- Backups — deleted data also disappears from backups on the backup rotation cycle, within about 35 days.
Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent at any time. You can delete your account in the app or via the deletion page. For any other request, email puckapp@sgsoftware.pl.
If you believe we have handled your data unlawfully, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Security
Passwords are stored only as salted hashes. Data is encrypted in transit with TLS. Access to production systems is limited to what is needed to operate the service. No system is perfectly secure, but we take reasonable measures to protect your data.
Children
PuckApp is meant for household members who create their own account, and is not directed to children below the age of digital consent in their country. If you believe a child has provided us data without guardian consent, contact us and we will delete it.
Changes to this policy
We may update this policy. The “Last updated” date always reflects the current version, and we will notify you in the app or by email of material changes before they take effect.
Contact
SG Software Development (Szymon Gaweł) — puckapp@sgsoftware.pl