Privacy Policy

Applies to our mobile apps (iOS App Store, Google Play) and related services

Last updated: 2025-08-09

This Privacy Policy describes how Codella ("we", "us", "the Controller") collects, uses, and protects the personal data of users of our mobile apps published on the Apple App Store and Google Play, as well as related services (e.g. websites, APIs, admin panels).

1) Data controller

The data controller is Codella Sp. j. Contact details: [email protected], ul. Piotra Bardowskiego 1/42, 40-836 Katowice, Poland.

2) Scope and categories of data

Depending on the app's features, we may process the following categories of data:

  • Account and contact data: first and last name, email address, phone number (if provided), user identifier.
  • Authentication data: sign-in tokens (e.g. Apple/Google Sign-In) — stored without exposing passwords.
  • Device and diagnostic data: device model, OS version, IP address, advertising identifiers (IDFA/GAID), crash logs, performance and feature-usage data.
  • Transaction data: in-app purchase (IAP) information, subscription status, transaction identifiers (without full card data).
  • Location data: approximate or precise location — only with consent and for the operation of a given feature.
  • System permissions (optional, depending on the app): access to camera, microphone, photos/files, contacts, Bluetooth, push notifications.
  • User content: messages, notes, attachments, images — only to the extent necessary to provide the service.

3) Sources of data

  • Directly from the user (forms, account setup, in-app interactions).
  • Automatically from the device and software (logs, analytics, crash data).
  • From third-party providers, if the user links an account (e.g. Apple/Google) or uses payments/ads.

4) Legal bases for processing

  • Performance of a contract or provision of a service (GDPR Art. 6(1)(b)).
  • Legitimate interest of the Controller (GDPR Art. 6(1)(f)) — e.g. security, fraud prevention, statistics.
  • Legal obligation (GDPR Art. 6(1)(c)) — e.g. tax settlements, accounting.
  • User consent (GDPR Art. 6(1)(a)) — e.g. marketing, precise location, notifications, advertising IDs.

5) Purposes of processing

  • Providing and developing app functionality and user support.
  • Authorization, security, fraud and abuse prevention.
  • Analytics and statistics (e.g. install/session/event counts, stability).
  • Handling in-app purchases, subscriptions, and payments.
  • Personalizing content and (optionally) ads — only with consent, where required.
  • Communicating with the user (e.g. support, important service notices).

6) Third-party providers and data sharing

We may use processors acting on our behalf, or independent controllers, including:

  • Analytics and crash reporting (e.g. Firebase/Google Analytics for Firebase, Apple App Analytics, Sentry).
  • Payments and subscriptions (Apple In-App Purchases, Google Play Billing).
  • Push notifications (Apple Push Notification Service, Firebase Cloud Messaging).
  • Advertising (e.g. Google AdMob) — only in apps where ads are enabled, in line with platform policies.
  • Infrastructure and hosting (e.g. cloud providers, CDN, mail servers).

7) Retention

  • We retain data for as long as necessary for the purposes described in this policy (e.g. account lifetime, billing).
  • Once the purpose ends, or on a valid user request, data is deleted or anonymized, unless the law requires longer retention.

8) Security

We apply appropriate technical and organizational measures to protect data against unauthorized access, alteration, or loss.

9) User rights (GDPR)

  • The right to access, rectify, erase, restrict processing of, and port your data.
  • The right to object to processing based on legitimate interest, and to withdraw consent at any time.
  • The right to lodge a complaint with the competent data protection supervisory authority.

10) Children

Our apps are not directed at children under 13 (or another age defined by local law). If we learn we have collected a child's data without proper consent, we will take steps to delete it.

11) International transfers

Data may be processed outside the European Economic Area. In such cases we apply appropriate safeguards (e.g. EU Standard Contractual Clauses).

12) System permissions and device sensors

Some features require access to device resources. Permissions are requested solely to enable the relevant feature and can be revoked at any time in system settings:

  • Camera and photos — e.g. for scanning, taking, and saving photos/attachments.
  • Microphone — e.g. for recording voice notes.
  • Location — e.g. for location-based services; we ask for consent before use.
  • Notifications — for sending service and (optionally) marketing information.

13) Advertising and identifiers

In apps with ads, we may use advertising identifiers (IDFA/GAID). You can reset or limit ad tracking in your device settings. Ad delivery complies with Apple and Google policies and local law.

14) Changes to this policy

We may update this Policy. A new version will be published in the app or on the website with an updated date.

For matters related to data protection, please contact us at: [email protected]