DE EN

Privacy Policy

This privacy policy explains what personal data the iOS app "SurvKit" processes. It applies exclusively to the app itself.

SurvKit is built strictly according to privacy by design (Art. 25 GDPR): the app processes personal data exclusively locally on your device. There is no server, no account, no cloud, no telemetry and no analytics SDKs. The only exceptions are the voluntary feedback form and the processing of the in-app purchase - both described in detail below.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is the natural person publishing "SurvKit" as an independent developer:

  • Name: B. Neuhaus
  • Address: Allerstraße 26, 12049 Berlin, Germany
  • Email: survkit@borisniehaus.de

Full contact details can also be found in the imprint.

Data protection officer

"SurvKit" is published by a single person as an independent developer. A data protection officer is therefore not legally required and none has been appointed.

No account, no server, no transmission

SurvKit requires no registration and operates no backend. All data you enter is stored exclusively locally on your device and transmitted to no one (the only exception: the feedback form, see below):

  • Emergency profile (e.g. blood type, allergies, emergency contacts) - local, protected by iOS Data Protection
  • Document vault - local, encrypted with AES-256-GCM, key stored in the iOS keychain
  • Location & tracks - kept in memory, or stored locally when you start a recording
  • Supplies, notes, checklists, learning progress - local
  • Messenger messages - end-to-end encrypted (Curve25519 + ChaChaPoly), sent directly to a device within Bluetooth / Wi-Fi range, with no server in between

The legal basis for this purely local processing is the provision of the functions you request (Art. 6(1)(b) GDPR).

Internet connections only at your request

The app only connects to the internet when you actively trigger it. For technical reasons, the respective third party receives your IP address and a user agent:

  • Offline map packages (GitHub Releases): the requested file name; map data © OpenStreetMap (ODbL)
  • Wikipedia articles (Wikipedia REST API): the titles of the requested articles
  • Weather (Open-Meteo): rounded coordinates for the forecast
  • Food barcode lookup (OpenFoodFacts): the scanned barcode number
  • Local AI model (Hugging Face): one-time download of the model file
  • Vehicle manuals: opening the manufacturer portal you selected

We do not log these requests; no identifiers beyond what is technically necessary are transmitted. The legal basis is the provision of the function you explicitly requested (Art. 6(1)(b) GDPR). Downloaded content then works offline.

Feedback form (Supabase)

Under Profile → Send feedback you can send us a message. This is the only way content you enter ever leaves the device, and it is triggered exclusively by you tapping "Send" - nothing is transmitted in the background.

Transmitted are: your feedback text, an optional email address (only if you would like a reply), and - to help classify the report - the app and build version, iOS version, device model and language setting. Not transmitted are your emergency profile, vault contents, location, supplies, notes or any other app data. The recipient is a Supabase database (Supabase Inc.); the key embedded in the app can only insert data, not read it. The legal basis is the handling of your request (Art. 6(1)(b) GDPR).

In-app purchase "SurvKit Pro" (Apple / RevenueCat)

SurvKit can be used without restriction for seven days; after that, extended areas are unlocked via a single one-time in-app purchase (no subscription). The core emergency features remain free permanently. The purchase itself is processed by Apple (StoreKit / App Store); to display the price, validate the purchase and restore purchases, the app uses the SDK of the service provider RevenueCat, Inc.

RevenueCat receives an anonymous app user ID generated by RevenueCat, App Store receipt data, the app version, device type and language setting - no name, no email address, no Apple ID. The purchase status is cached locally; the app does not check in the background. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Details: RevenueCat privacy policy.

Permissions

SurvKit only requests system permissions (location, camera, microphone, notifications, local network / Bluetooth) when a feature needs them - such as the camera for the document scanner or location for the map and compass. Data from these permissions is processed exclusively locally and never transmitted. Notifications are purely local (e.g. expiry dates in your supplies) - there are no push servers.

Storage period and deletion

All data resides exclusively on your device and remains stored until you delete it in the app or uninstall the app. An encrypted export (backup) only happens when you trigger it yourself, and is stored wherever you choose to save it.

Your rights

You have the rights under Art. 15-21 GDPR (access, rectification, erasure, restriction, objection, data portability) as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Since all data resides locally on your device, you can exercise access, rectification and erasure at any time directly in the app. For any questions, contact survkit@borisniehaus.de.

Apple as distribution platform

SurvKit is distributed via the Apple App Store. Obtaining the app through the store is subject to Apple's own data processing (e.g. in the context of your account and the download), is governed by Apple's privacy policy and is outside the controller's sphere of influence.

Cookies and tracking

SurvKit uses no cookies, performs no tracking and embeds no analytics, advertising or crash-reporting SDKs.

Last updated

2026-08-26

← Back to the app page