العربية · Čeština · Dansk · Deutsch · English · Español (LatAm) · Suomi · Français · हिन्दी · Magyar · Bahasa Indonesia · Italiano · עברית · 日本語 · 한국어 · Nederlands · Norsk · Polski · Português (BR) · Română · Русский · Slovenčina · Svenska · ไทย · Türkçe · Українська · Tiếng Việt · 简体中文

Privacy Policy — Moje Szczepienia

Last updated: 2026-09-17 · Effective date: 2026-05-06

1. Who we are

Moje Szczepienia is a mobile vaccination organizer for families: a calendar, history, and reminders for vaccinations of family members. The app is informational and organizational only — it does not diagnose, treat, prevent illness, nor replace medical consultation. All vaccination entries are stored locally on your device in encrypted storage; no readable medical data is ever sent to our servers. What does pass through our servers is listed in section 3.2: optional sign-in details, end-to-end encrypted sync data that we cannot decrypt, and technical data needed to deliver notifications.

Data controller: Maciej Siemiński — the developer of Moje Szczepienia. Contact: mail@macsiem.dev

For the version of the app distributed via Google Play, the data controller is LICENCEPRO POLSKA Sp. z o.o., ul. Huculska 6, 00-730 Warszawa, Polska.

This Privacy Policy explains what personal data Moje Szczepienia processes, how, why, and what rights you have.

2. Plain-language summary

Moje Szczepienia is a personal vaccination organizer — vaccination records stay on your device in encrypted local storage. We do not run a server that stores readable medical data. We use Unity Ads (only on the Settings screen, never on health-data screens), Sentry for crash reporting, an optional backup in your own iCloud (Apple) and/or Google Drive, optional end-to-end encrypted sync between your devices, and Apple / Google billing for in-app purchases. The app is not a medical device and does not provide diagnosis, treatment, or medical recommendations. You have full GDPR rights including access, deletion, and portability — most exercisable directly in the app.

3. Data we process

3.1 Local-only data

Vaccination data (family member profiles, vaccinations, dates, notes, photos of the vaccination booklet/sticker) are stored locally on your device, in encrypted MMKV storage (key generated randomly and kept in Apple Keychain / Android Keystore). We never send this data in readable form to our servers or to any third party. It leaves your device only if you turn on one of the optional features described in section 3.2. So that the Premium trial does not start over, the trial start date is also kept in Apple Keychain / Android Keystore and in your backup; it contains no vaccination data and is not removed by "Erase all data" (see section 8).

3.2 Optional account, backup in your own iCloud or Google Drive, sync between your devices, and notifications

Account sign-in. You can sign in with Apple or Google. Our account service (hosted by Cloudflare) then stores an internal user ID, the identifier of your Apple / Google account and your email address if the provider shares it. It stores no vaccination data. Deleting the account in the app removes this information.

Backup in your own iCloud. If you connect an Apple account, the app keeps an encrypted backup of your data, including photos of the vaccination booklet (reduced to at most 2048 pixels on the longer side), in its private database in your iCloud. Only this app can access that database, and the app cannot see any of your other iCloud data. On iPhone the app uses the iCloud account signed in on the phone. On Android you sign in on Apple's page in the system browser, so the app never sees your Apple password; Apple then gives the app an iCloud session token, which is kept encrypted on your device (Android Keystore), and Apple asks you to sign in again at least every 2 weeks. The return from that sign-in to the app passes through our page auth.szczepienia.macsiem.dev (hosted by Cloudflare), which does not store the token. The encryption key is kept in the same private database, so on a new phone — iPhone or Android — you restore your data just by signing in with Apple. This also means that Apple, as the storage provider, may be technically able to access the backup, depending on the data protection settings of your Apple account. To delete this backup, on an Apple device open Settings → your Apple Account → iCloud → Manage Storage, choose this app and delete its data.

Backup in your own Google Drive. If you connect a Google account, the app keeps an encrypted backup of your data, including photos of the vaccination booklet (reduced to at most 2048 pixels on the longer side), in its private app folder on your Google Drive. The folder is hidden, only this app can access it, and the app cannot see any of your other Drive files. The encryption key is kept in the same private folder, so on a new phone you restore your data just by signing in with Google — no recovery words needed. This also means that Google, as the storage provider, is technically able to access the backup, as with any other data in your Google account. If you connect both Apple and Google, the backup is kept in both places. No copy of your data, from either backup, is stored on our servers. You can turn the backup off in Settings, which stops further uploads. To delete the backup itself, remove the app's hidden data in Google Drive (Settings → Manage apps).

Sync between your devices. If you pair devices, entries travel between them end-to-end encrypted through our relay (hosted by Cloudflare). The relay stores only encrypted data that it cannot decrypt, together with the push notification tokens of the paired devices, until you unpair or for up to 365 days after the last activity. Notifications about new entries are delivered through the Expo push service and contain no vaccination data.

Announcements and notifications. To show in-app announcements and send notifications, the app registers with our notification service (hosted by Cloudflare) a random installation identifier, a push notification token, the platform, language, app version, release channel and whether Premium is active. This contains no vaccination data and is kept until you ask us to delete it.

Encrypted file. You can also export an encrypted backup file and keep it wherever you choose, for example iCloud Drive, Google Drive or Files.

3.3 Diagnostic data (Sentry)

Moje Szczepienia integrates Sentry (sentry.io) for crash and error reporting. Sentry collects:

Sentry does not collect your content (entries, files, vaccination records, photos, archives), usernames, or other PII. Diagnostic data is retained by Sentry for up to 90 days.

3.4 Advertising (Unity Ads)

Moje Szczepienia shows non-invasive ads on Settings only (no ads on vaccination data screens). Ads are delivered by Unity Ads, whose SDK collects:

Default mode is non-personalized ads. On iOS, the App Tracking Transparency (ATT) prompt asks for your consent before any tracking-grade identifier is used; on Android you control the Advertising ID under system Settings. Ads can be permanently disabled via the Lifetime / Premium IAP.

3.5 In-app purchases (IAP)

Moje Szczepienia offers paid features through Apple In-App Purchase (iOS) and Google Play Billing (Android). When you make a purchase:

Available products: lifetime premium unlock, optional tip jar, optional annual subscription.

3.6 Device permissions

Each permission is requested contextually. You can deny any permission and still use the core features (where applicable).

3.7 What we do NOT collect

4. Why we process this data (purposes)

5. Legal basis (GDPR Article 6)

For users in the European Economic Area, United Kingdom, and Switzerland:

6. Recipients (with whom we share data)

We do not sell personal data. The categories of recipients are limited to providers strictly required to run the app:

RecipientPurposeData categoryPrivacy policy
Unity Technologies (Unity Ads)Serve adsAdvertising ID, device & ad metricshttps://unity.com/legal/privacy-policy
Functional Software Inc. (Sentry)Crash reportingStack traces, device metadatahttps://sentry.io/privacy/
Apple Inc. (App Store / IAP)In-app purchase processing on iOSPurchase token, account-level entitlementhttps://www.apple.com/legal/privacy/
Google LLC (Play Billing)In-app purchase processing on AndroidPurchase token, account-level entitlementhttps://policies.google.com/privacy
Apple Inc. (iCloud)Optional backup in your own iCloud (iOS and Android)Encrypted app data and its encryption key in the app's private database; on Android also the iCloud session token sent with each requesthttps://www.apple.com/legal/privacy/
Google LLC (Google Drive)Optional backup in your own Google Drive (iOS and Android)Encrypted app data and its encryption key in the app's private folderhttps://policies.google.com/privacy
Cloudflare, Inc.Hosting of account sign-in, the page that returns you to the app after Apple sign-in on Android, the device-to-device sync relay and the notification serviceAccount identifiers and email; the iCloud session token passing through the return page (not stored); end-to-end encrypted sync data; installation identifier, push tokens and app detailshttps://www.cloudflare.com/privacypolicy/
650 Industries, Inc. (Expo push service)Delivery of notificationsPush token, notification text without vaccination datahttps://expo.dev/privacy

We may disclose data if required by a valid court order or other binding legal process, after verifying the request and notifying you where lawful.

7. International transfers

Some of the recipients above are located outside the European Economic Area (mainly in the United States). Where transfers occur, they are protected by:

You can request a copy of the relevant safeguards by writing to mail@macsiem.dev.

8. Retention

DataWhere it livesHow long
Your in-app dataYour device only (encrypted)Until you delete it, uninstall the app, or wipe app data
Backup in your iCloudThe app's private database in your Apple accountUntil you delete the app's data in iCloud storage settings on an Apple device
Backup in your Google DriveThe app's private folder in your Google accountUntil you delete the app's hidden data in Google Drive
Account sign-in detailsOur account service (Cloudflare)Until you delete the account in the app
Encrypted device-to-device sync dataOur relay (Cloudflare)Until you unpair, or up to 365 days after the last activity
Notification registrationOur notification service (Cloudflare)Until you ask us to delete it
Premium trial start dateApple Keychain / Android Keystore on your device, and your backupKept after "Erase all data" so the trial does not start over; removed when the app is uninstalled on Android (on iPhone the Keychain may keep it) or when the backup is deleted
Advertising IDUnity Ads systemsPer Unity's retention policy
Sentry crash dataSentry systemsUp to 90 days from the event
IAP purchase token / receiptYour device + Apple / GoogleUntil you uninstall; Apple / Google keep transaction records per their own policies

9. Your rights (GDPR Art. 15–22)

You have the following rights regarding your personal data:

To exercise any right, write to mail@macsiem.dev. We respond within 30 days (extendable by 60 days for complex requests, with notice).

10. Right to lodge a complaint (GDPR Art. 77)

If you believe we are processing your data unlawfully, you may file a complaint with a supervisory authority. For Polish residents:

Prezes Urzędu Ochrony Danych Osobowych (PUODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl

You may also file a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement in another EEA country.

11. Children's privacy

Moje Szczepienia is not directed at children under 13 (under 16 where applicable per local law). We do not knowingly collect personal data from children under that age. Where parents enter children's vaccination data into the app, the app acts as a personal organizer for the parent; the entries remain on the parent's device under the parent's control. If you believe a child has provided us personal data without parental consent, contact us at mail@macsiem.dev and we will delete it promptly.

The "Designed for Families" / "Ages 5+" Apple / Google flags are not set on Moje Szczepienia — the app is rated for general audiences 13+.

12. Security

No system is 100% secure; please keep your device updated and use strong device locks.

13. App Tracking Transparency (iOS) and Advertising ID

On iOS, before any tracking-grade identifier is used by Unity Ads, Moje Szczepienia shows the system App Tracking Transparency prompt. If you decline, Moje Szczepienia serves only non-personalized ads.

On Android, you can reset or limit your Advertising ID under Settings → Google → Ads. Choosing "Delete advertising ID" stops Unity Ads from using a personal identifier; non-personalized ads continue to be shown.

14. In-app purchases

Moje Szczepienia offers the following in-app products through Apple App Store and Google Play: lifetime premium unlock, optional tip jar, optional annual subscription.

All payment data is handled by Apple Inc. (App Store / iTunes account) or Google LLC (Play Billing). We never see your card number, your billing address, or your full Apple ID / Google account. Apple and Google return only an opaque purchase token and entitlement metadata that we use to unlock features. Subscriptions can be cancelled at any time in iOS Settings → Apple ID → Subscriptions or in the Google Play app → Subscriptions; cancellation rules are governed by Apple / Google.

15. Changes to this policy

We may update this policy as the app, third-party SDKs, or applicable law change. Material changes will be announced in-app and the "Last updated" date at the top will change. Continuing to use Moje Szczepienia after a change constitutes acceptance of the updated policy.

16. Contact

For privacy questions, exercise of rights, or concerns about this policy:

Maciej Siemiński Email: mail@macsiem.dev

Canonical version of this policy: https://macsiem.github.io/szczepienia-privacy/ Source: https://github.com/MacSiem/szczepienia-privacy