This privacy policy explains what personal data the app "SurvKit" processes. It covers the iOS and the Android version and applies exclusively to the app itself.
SurvKit is built strictly according to privacy by design (Art. 25 GDPR): the app processes personal data exclusively locally on your device. There is no server, no account, no cloud, no telemetry and no analytics SDKs. The only exceptions are the voluntary feedback form, the processing of the in-app purchase and the crash reports, which can be switched off - all three described in detail below.
The Android version processes less. It has no feedback form and no crash reports; it goes online for two things only, both of which you trigger yourself: the in-app purchase, which Google Play handles, and downloading offline map packages. The separate section Android version below lists every difference.
The controller within the meaning of the General Data Protection Regulation (GDPR) is the natural person publishing "SurvKit" as an independent developer:
Full contact details can also be found in the imprint.
"SurvKit" is published by a single person as an independent developer. A data protection officer is therefore not legally required and none has been appointed.
SurvKit requires no registration and operates no backend. All data you enter is stored exclusively locally on your device and transmitted to no one (the only exception: the feedback form, see below):
The legal basis for this purely local processing is the provision of the functions you request (Art. 6(1)(b) GDPR).
The app only connects to the internet when you actively trigger it. For technical reasons, the respective third party receives your IP address and a user agent:
We do not log these requests; no identifiers beyond what is technically necessary are transmitted. The legal basis is the provision of the function you explicitly requested (Art. 6(1)(b) GDPR). Downloaded content then works offline.
Under Profile → Send feedback you can send us a message. This is the only way content you enter ever leaves the device, and it is triggered exclusively by you tapping "Send" - nothing is transmitted in the background.
Transmitted are: your feedback text, an optional email address (only if you would like a reply), and - to help classify the report - the app and build version, iOS version, device model and language setting. Not transmitted are your emergency profile, vault contents, location, supplies, notes or any other app data. The recipient is a Supabase database (Supabase Inc.); the key embedded in the app can only insert data, not read it. The legal basis is the handling of your request (Art. 6(1)(b) GDPR).
SurvKit can be used without restriction for seven days; after that, extended areas are unlocked via a single one-time in-app purchase (no subscription). The core emergency features remain free permanently. The purchase itself is processed by Apple (StoreKit / App Store); to display the price, validate the purchase and restore purchases, the app uses the SDK of the service provider RevenueCat, Inc.
RevenueCat receives an anonymous app user ID generated by RevenueCat, App Store receipt data, the app version, device type and language setting - no name, no email address, no Apple ID. The purchase status is cached locally; the app does not check in the background. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Details: RevenueCat privacy policy.
If the app crashes, it sends a technical error report on the next start. This function is active after installation. The privacy step during first launch names it explicitly and shows the corresponding switch right next to it; you can turn it off there and at any time later under Profile → About the app → Diagnostics. Switching it off takes effect immediately - the Sentry SDK is shut down and no longer opens a connection.
Only technical details about the crash are transmitted: error message and call stack (stack trace), the location in the program code, app and build version, iOS version, device model, language setting and time zone, plus a pseudonymous installation identifier that the Sentry SDK assigns per device. Not transmitted: screenshots, your GPS location and any content from the emergency profile, document vault, supply list or notes. No usage behaviour is recorded and no user profile is created.
About the IP address: the app does not send it. When the report is delivered, the Sentry server inevitably sees it - that cannot be prevented from within the app. For this project the option "Prevent Storing of IP Addresses" is enabled, so the address is not stored. A rough location derived from it (country and city) does remain stored with the event; this is a server-side Sentry feature and cannot be switched off.
The processor is Functional Software, Inc. ("Sentry"), San Francisco, California, USA. Reports go to the EU region of the service (ingest.de.sentry.io) and are stored in data centres within the European Union. The basis is a data processing agreement (Data Processing Addendum as part of the terms of service); for any transfers to the USA the European Commission's standard contractual clauses apply. Reports are deleted automatically after Sentry's retention periods. Details: Sentry's privacy policy.
The legal basis is our legitimate interest in a stable and error-free app (Art. 6 (1) (f) GDPR). Errors that only occur on particular devices or in particular languages are practically impossible to find otherwise. You can object to this processing at any time by switching the toggle off (Art. 21 GDPR).
SurvKit only requests system permissions (location, camera, microphone, notifications, local network / Bluetooth) when a feature needs them - such as the camera for the document scanner or location for the map and compass. Data from these permissions is processed exclusively locally and never transmitted. Notifications are purely local (e.g. expiry dates in your supplies) - there are no push servers. This list describes the iOS version; which permissions the Android version requests, and what for, is listed one by one under Android version.
The Android version of SurvKit is narrower in scope than the iOS one, and that applies to data processing as well. For it, the following holds:
INTERNET and ACCESS_NETWORK_STATE
permissions with it in order to report purchases to Google. There is no way to sell
in Google's store without it. The code reader looks nothing up: it decodes on the
device.
github.com (map packages),
api.open-meteo.com (weather), wikipedia.org (articles),
world.openfoodfacts.org (food barcodes),
www.ema.europa.eu (package leaflets) and huggingface.co
(a one-time download of an AI model that then runs on the device).
Wikipedia, the package leaflets and the AI model belong to features the
Android version does not have yet - they are listed here already so that
this text does not lag behind the app. The food scanner, by contrast, is there: it
sends the barcode number to OpenFoodFacts and gets back the name, brand, quantity
and ingredient list. The comparison against your allergen profile happens on the
device - your list of allergens is never transmitted. Once loaded,
a product stays available offline. Only what makes up the request is transmitted: a file name, rounded
coordinates, an article title, a barcode number. The app sends no cookies, no device
identifiers and no advertising IDs; the user agent names the app and its version,
because public interfaces require one. There is no service that fetches in the
background.
POST_NOTIFICATIONS) for the reminder about
expiring supplies. Requested only once you enter your first expiry date; the
notification is created on the device, without any push server.
RECEIVE_BOOT_COMPLETED) so those reminders
survive a restart of the phone.
ACCESS_FINE_LOCATION,
ACCESS_COARSE_LOCATION) for the position display in the compass -
coordinates, altitude, UTM and MGRS -, for your own position on the map, for track
recording and for the weather. In every case but one the position stays on the
device: it is displayed, or stored there if you start a recording. The one
exception is the weather - coordinates rounded to two decimal places go to
Open-Meteo, because a forecast without a place is not a forecast. Compass and map
also work without this permission, simply without the position. Below Android 12 the
Bluetooth scan additionally requires location; that is a rule of the system and
serves to find devices there, not to locate you.
RECORD_AUDIO) for the noise meter.
Nothing is recorded. The app computes the loudness from the live
signal and discards it immediately; none of it is stored or sent.
CAMERA) for the code reader and the document scanner.
The code reader evaluates the image on the device and discards it; the document
scanner puts the capture straight into the encrypted vault on your device. No image
leaves the phone.
BLUETOOTH_SCAN, BLUETOOTH_CONNECT,
BLUETOOTH_ADVERTISE; below Android 12 BLUETOOTH and
BLUETOOTH_ADMIN) for the Bluetooth messenger. Requested when you open
that screen. The scan carries the neverForLocation flag: it serves to
find devices and is not used to derive your location. If you decline, the messenger
keeps working over the local Wi-Fi. Bluetooth is not a requirement for the app - if
the device has none, only this one screen is missing.
FOREGROUND_SERVICE,
FOREGROUND_SERVICE_LOCATION) for track recording on the
map. It is the only thing that keeps running while the app is closed - and
only while you have started it: from "start recording" to "stop recording", never
automatically, never after a restart of the phone. A notification with a stop button
stays visible in the status bar the whole time. The recorded track is stored on the
device and sent nowhere; you can delete it again in the app.
com.android.vending.BILLING, INTERNET
and ACCESS_NETWORK_STATE for the purchase, plus
USE_BIOMETRIC and USE_FINGERPRINT for the app lock and the
vault.
The offline map, the weather, the Bluetooth messenger and the food scanner are now included and described above. As soon as the Android version gains another of the features that only the iOS version has so far - Wikipedia, package leaflets or the AI assistant - this section will be updated beforehand. The six counterparts that come into question for that are already listed above in full.
All data resides exclusively on your device and remains stored until you delete it in the app or uninstall the app. An encrypted export (backup) only happens when you trigger it yourself, and is stored wherever you choose to save it.
You have the rights under Art. 15-21 GDPR (access, rectification, erasure, restriction, objection, data portability) as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Since all data resides locally on your device, you can exercise access, rectification and erasure at any time directly in the app. For any questions, contact survkit@borisniehaus.de.
SurvKit is distributed via the Apple App Store and via Google Play. Obtaining the app through either store is subject to Apple's or Google's own data processing (e.g. in the context of your account and the download), is governed by their privacy policies and is outside the controller's sphere of influence.
SurvKit uses no cookies, performs no tracking and embeds no analytics or advertising SDKs. There are no advertising identifiers, no profiling and no cross-device recognition. The only diagnostics SDK embedded is Sentry for crash reports - limited to crashes, without usage behaviour and switchable off at any time (see above). The Android version does not contain even that.
2026-09-15