Privacy Policy — Bliscy24 (beta testing version)

Last updated: 1 September 2026

This is a translation of the original Polish-language privacy policy. In the event of any discrepancy, the Polish version at bliscy24.pl/polityka-prywatnosci is authoritative.

1. Data controller

The controller of personal data collected in the app and on the Bliscy24 website is:

Mateusz Grzybek
Kraków, Poland
Contact email: kontakt@bliscy24.pl

The controller is currently acting as a private individual. Before the app’s full public launch, the controller’s details will be updated with full business registration information.

2. App status — beta testing version

The Bliscy24 app is currently in a beta testing phase. This means that:

  • features may change, be added, or be removed without prior notice,
  • technical errors may occur affecting the operation of safety features (e.g. SOS, medication notifications, location) — the beta version of the app should not be relied upon as the sole safety system for a person under care,
  • data may be deleted during the testing phase due to technical changes.

Testing is carried out within a closed group of invited users.

3. What data we process

Registration data: first name, email address, password (encrypted), phone number.

Health data (special category data — Art. 9 GDPR): information about medications and dosage, allergies, chronic conditions, blood type, measurement results (e.g. blood pressure), wellbeing, medical documents added by the user, medical appointments.

Location data: current GPS location, location history (retained for 30 days), information about safety zones and entering/leaving them.

Children’s data (child mode): if a care circle includes a child, we process the above categories of data in relation to the child as well, entered and managed solely by the parent/legal guardian.

Technical data: device battery level, push notification tokens, app usage data required for the app to function.

Contact data within the care circle: phone numbers automatically exchanged between a caregiver and a care recipient within the same circle.

4. Purposes and legal bases for processing

PurposeLegal basis
Creating and managing an accountArt. 6(1)(b) GDPR (performance of a contract)
Safety features: SOS, location, safety zonesArt. 6(1)(a) GDPR (consent) + Art. 9(2)(a) GDPR (explicit consent — health/safety data)
Medication reminders, medical dataArt. 9(2)(a) GDPR (explicit consent for health data)
Push notificationsArt. 6(1)(b) GDPR (performance of a contract)
Contact regarding technical matters / beta testingArt. 6(1)(f) GDPR (legitimate interest — improving the app)
A child’s data in child modeArt. 6(1)(a) and Art. 9(2)(a) GDPR (parent’s/legal guardian’s consent)

5. Parent’s/legal guardian’s consent for a child’s data

If you use child mode, you represent that you are the parent or legal guardian of the child whose data you are entering, and you consent to the processing of their data (including health and location data) for the purposes described in this policy. You may withdraw this consent at any time by removing the child’s profile from the app or by contacting the controller.

6. Who we share data with

Data is processed with the assistance of the following technical service providers:

  • Supabase — the app’s database and backend. The server operates within the European Union — data does not leave the European Economic Area.
  • Firebase (Google) — push notifications. Google applies Standard Contractual Clauses for any transfer of data outside the EEA.
  • Sentry — monitoring of the app’s technical errors (data stored within the EU).

Data is not sold or shared with third-party companies for marketing purposes.

Within a single care circle, a care recipient’s data (location, medications, wellbeing, documents) is visible to the caregivers belonging to that circle — this is a core feature of the app, which the user consents to by joining the circle.

7. Data retention period

  • Account data — until the account is deleted by the user.
  • Location history — automatically deleted after 30 days.
  • Health data, documents, notes — until the account is deleted, or manually deleted by the user.
  • Upon account deletion, all associated data is removed from the system.

8. Your rights

Under the GDPR, you have the right to: access your data, rectify it, erase it, restrict its processing, transfer it, object to its processing, and withdraw consent at any time (without affecting the lawfulness of processing carried out before its withdrawal).

You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

To exercise the above rights, please contact: kontakt@bliscy24.pl.

9. Data security

Passwords are stored in encrypted form. Communication takes place over an encrypted connection (HTTPS/SSL).

10. Changes to this privacy policy

Given the beta testing phase, this policy may change. We will inform testers of material changes by email or via a notification in the app.

11. Contact

For matters concerning personal data: kontakt@bliscy24.pl

Przewijanie do góry