polidex — Privacy notice
Version: 2026-08-08 · Draft, pre-release
Who is responsible
Nándorfi Vince, as an individual developer. Contact details go here before release; the store listing requires them.
What we collect, and why
Everything in this list exists as a column in the database. Nothing else is collected.
| What | Why | Legal basis |
|---|---|---|
| Email address | to identify your account, confirm it is yours, and let you reset your password | performance of a contract (Art. 6(1)(b)) |
| Password | stored only as a hash by our authentication provider; we never see it | performance of a contract |
| Display name | to show you in the app | performance of a contract |
| Which documents you accepted, which version, and when | to be able to show that we processed your data lawfully | legal obligation and legitimate interest (Art. 6(1)(c), (f)) |
| Push notification token, and which device it belongs to | to send you notifications you asked for | consent |
| With Google sign-in: your name, the address of your profile picture, and your Google account id | Google hands these over when you sign in, and our authentication provider stores them | performance of a contract |
If you sign in with a Google account, Google hands over your name, your email address and the address of your profile picture -- it says so itself before you choose. These land in your authentication record. The app does not currently use your name or your picture; they sit empty in our own profile table.
We do not collect your location. The app has no location feature and asks for no location permission.
We do not profile you and we do not advertise. There is no analytics, no tracking, no advertising identifier, and nothing is shared with advertisers.
Who else sees it
Supabase, which hosts the database and the authentication service, acting as our processor. Have I Been Pwned, when you choose a password: only the first five characters of its SHA-1 hash leave your device, which identifies a bucket of thousands of passwords and cannot identify yours. Sentry, when the app crashes: it receives the error, where in the code it happened, and what kind of device it was. It is configured not to send your address or username, and not to record your screen. Sentry stores this in the European Union.
Google, if you sign in with a Google account. Google acts as its own controller in its relationship with you: it identifies you, and it decides what to hand over to us. What it hands over is listed in the table above.
Nothing is sold. Nothing is shared with advertisers.
How long we keep it
While your account exists. When you delete your account:
- it becomes invisible immediately, and you can restore it for 30 days;
- after 30 days your personal data is destroyed;
- **if you signed in with Google, polidex does not thereby disappear from the
"third-party apps with account access" list in your Google account** -- you can remove it there yourself. Your data is destroyed here; the entry at Google is between you and Google, and we have no way in;
- two things are kept, and here is why:
- the record of which document versions you accepted — this is the only evidence that we processed your data lawfully, which protects you as much as us (Art. 17(3)(e)); - a SHA-256 hash of your email address — it cannot be turned back into an address, but it can answer whether a particular address was barred, which is what stops a banned account returning the next day (Recital 47). It is kept for two years and then deleted automatically.
Your rights
Access, rectification, erasure, restriction, objection, and portability. Deletion and a copy of everything we hold about you are both available in the app under Settings; the copy is JSON, and your phone's share sheet decides where it goes -- we do not send it anywhere. The remaining rights are handled by contacting us, and we answer within one month.
You may complain to the Hungarian supervisory authority (NAIH).
Children
polidex is not intended for children under 16. Under Hungarian law, processing a child's data on the basis of consent requires parental authorisation below that age, so we ask for your date of birth before an account is created. The date stays on your device: we record only that you were old enough, never the date itself.
Changes
When this notice changes, the version at the top changes, and you will be asked to accept the new version. Previously recorded consents keep their own version, so it is always visible which text you agreed to.