DE EN

Privacy Policy

This privacy policy explains which personal data the iOS app "Повітряна тривога" (Air Raid Alert) - internally "Tryvoha" - processes. It applies to the app itself only. In case of doubt, the German version prevails.

In short: the app has no account, no tracking, no analytics and no crash-reporting SDKs. Your location is processed on the device only and is never transmitted. The app connects to the internet for exactly two things: to load the current air raid alerts from our backend and - if you allow notifications - to store your device's anonymous push token there. Both are described in detail below.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is the natural person who publishes "Повітряна тривога" as an individual developer:

  • Name: B. Neuhaus
  • Address: Allerstraße 26, 12049 Berlin, Germany
  • E-mail: tryvoha@borisniehaus.de

Full contact details are also in the imprint (German).

Data protection officer

The app is published by a single person as an individual developer. A data protection officer is therefore not legally required and none has been appointed.

No account, no usage data

The app requires no registration. There is no user account, no advertising ID, no analytics or tracking service and no crash reporting. We do not learn whether, when or how you use the app.

What the app stores locally on your device: the loaded air raid alerts of the last 30 days (as a cache so the map shows something offline), your settings (vibration, notifications, push radius, whether the intro has been shown) and the time of the last successful data update. None of this contains personal data; all of it is deleted when you uninstall the app.

Location - on the device only

The app requests the Location "While Using the App" permission. It needs your location to transfer the air raid alerts to scale onto your surroundings: for every alert, distance and bearing from Kyiv are calculated and plotted from your location. This calculation happens entirely on the device. Your location is not transmitted to our backend or to any other server and is not stored persistently - it is held in memory only while the app is running.

Without location access the geographic map of Ukraine keeps working; only the map transferred onto you stays empty. You can revoke the permission at any time in the iOS settings.

The legal basis is your consent, given via the iOS permission dialog (Art. 6(1)(a) GDPR).

Loading the air raid alerts (Supabase)

The alert data lives in a database at our backend provider Supabase (Supabase, Inc.). A server job fetches it every minute from the API of the volunteer project alerts.in.ua; the app itself never talks to alerts.in.ua. On launch and on every refresh the app loads the new alerts over an encrypted connection (HTTPS) and keeps a persistent connection (WebSocket, "Realtime") open to watch for new alerts while it is in the foreground.

The app transmits no information about you in doing so - no location, no device identifier, no account. Technically, Supabase receives your IP address and a user agent (app name and version, iOS version) with every request; this is unavoidable for any internet connection. The key embedded in the app only allows reading the public alerts table.

Supabase processes this data on our behalf under a data processing agreement (Data Processing Addendum as part of its terms of service); for any transfers to third countries the EU Commission's standard contractual clauses apply. Details: Supabase privacy policy. The legal basis is the provision of the function you requested (Art. 6(1)(b) GDPR).

Push notifications (Apple APNs and Supabase)

On first launch the app asks whether it may send you notifications. If you agree, Apple issues a push token for your device - a random device identifier that is only good for delivering notifications and allows no inference about your person, your Apple ID or your location. The app stores this token in our Supabase database together with:

  • the platform ("ios"),
  • the app language (e.g. "de") so the notification arrives in your language,
  • the push radius you chose (All / 50 / 100 / 200 km) - a plain number, not a location,
  • the time of registration and of the last update.

The radius refers to the map transferred onto you and is evaluated server-side as a distance from Kyiv - the server does not know your location and does not need it for this. When a new alert fires, our server job sends a notification with a generic text ("Air raid alert in Ukraine …") to your device via Apple's push service (Apple Push Notification service, Apple Inc.). The notification contains no data about you. The key in the app can only create or update tokens, not read them.

Switching off and deleting: you can disable notifications for the app at any time in the iOS settings. If you uninstall the app, the token becomes invalid; Apple reports this on the next delivery attempt and our server job deletes the entry automatically. We will also delete it earlier on request - just send us an e-mail.

The legal basis is your consent via the iOS permission dialog (Art. 6(1)(a) GDPR); processing by Apple is governed by Apple's privacy policy.

Maps and geocoding (Apple MapKit)

Both maps are rendered with Apple's MapKit. For this, your device loads the map tiles of the currently visible section from Apple - for the map transferred onto you, that is a section around your location. Apple technically receives your IP address and the requested map section; we receive none of it. According to Apple, it uses rotating identifiers for this that are not linked to your Apple ID.

If an alert exceptionally arrives from the backend without coordinates, the app has the Ukrainian area name (e.g. "Харківська область") converted into coordinates by Apple's geocoding service. Only this area name is transmitted - never your location.

The legal basis is the provision of the map function (Art. 6(1)(b) GDPR); details in Apple's privacy policy.

Content and links in the info section

The app's info section shows preview images under "More apps" that are loaded from our web server (borisniehaus.de); our web host technically receives your IP address in the process. The info section also contains links to external websites (alerts.in.ua, borisniehaus.de, PayPal). They only open, in your browser, when you tap them; from then on the respective provider's privacy policy applies.

Permissions

The app requests exactly two system permissions: Location (while using the app) for the map transferred onto you and Notifications for push notifications. Both are announced in the intro, both are voluntary, both can be revoked at any time in the iOS settings. Camera, microphone, contacts, photos or motion data are not requested.

Retention and deletion

  • On the device: cache and settings remain until you uninstall the app.
  • Push token at Supabase: until Apple reports the token as invalid (after uninstalling) or you request deletion by e-mail.
  • Air raid alerts: no personal data; the database keeps a rolling 30-day window.

Your rights

You have the rights under Art. 15-21 GDPR (access, rectification, erasure, restriction, objection, data portability), the right to withdraw consent at any time (Art. 7(3) GDPR) and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) - for Berlin that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit. Since we store no data about you other than the push token, and that token cannot be attributed to a person, we can only act on access or erasure requests for a token you tell us. Contact tryvoha@borisniehaus.de.

Apple as distribution platform

The app is distributed via the Apple App Store. Obtaining the app through the store is subject to Apple's own data processing (e.g. in the context of your account and the download), is governed by Apple's privacy policy and is outside the controller's sphere of influence.

Cookies and tracking

The app uses no cookies, performs no tracking and embeds no analytics, advertising or crash-reporting SDKs. There are no advertising identifiers, no profiling and no cross-device recognition. The only third-party library included is the Supabase client for loading alerts and registering for push.

Changes

If the app's data processing changes - for example through new features - this policy will be updated beforehand. The date below shows the current version.

Last updated

2026-10-02

← Back to the app page