In short
- Petra stores the emergency card you fill in, the groups you join, their files and routes, and your position only while trip mode is on.
- Your card is shared only with the members of groups you join, and only the parts those groups ask for.
- Everything the app keeps on your phone is encrypted. Positions are deleted after 30 days. Deleting your account removes your data straight away.
- We do not sell your data, show advertising or use your data to build advertising profiles.
1. Who is responsible
Sándor Szilágyi, [Registered address], is the controller of your personal data. For anything about privacy, write to support@hernadlabs.com. [If a data protection officer is appointed, add their contact details here.]
2. What we collect
- Account: your email address, name and profile photo, and a sign-in identifier from Google or Apple if you sign in with them. Passwords are handled by our authentication provider and are never visible to us.
- Emergency card, identity: name, date of birth, nationality, photo, and passport or ID card numbers and scans if you add them.
- Emergency card, medical: blood type, allergies, conditions, medication, pregnancy, mobility needs, height, weight and notes. This is health data, a special category under Article 9 GDPR.
- Insurance: travel and health insurance policies, European Health Insurance Card details, and car insurance, with any documents you attach.
- Other people: the names, phone numbers, relationship and location of your emergency contacts and next of kin.
- Groups: groups you create or join, join requests, trip dates, sharing settings, group files, routes (GPX or KML) and route images.
- Location: while trip mode is on in one of your groups during its active dates, your position, its accuracy, the time, and your phone's battery level.
- Technical: crash and error reports, and basic performance data, described in section 5.
- Subscription: which plan your account is on and, if you buy Pro, that a subscription is active and when it renews or ends. Your payment details stay with Apple or Google and never reach us.
- Forum: the posts, pictures, comments and votes you publish, shown with your first name to everyone signed in to Petra.
- Usage: which features are used, for example that a group was created or joined, linked to a random account identifier. Never the content of your card, your location, names or your email address.
3. Why we use it, and on what legal basis
Where we rely on consent, you can withdraw it at any time, for example by removing the details from your card, turning off location access for Petra in your phone's settings, leaving a group, or deleting your account. Withdrawal does not affect what happened before it.
- To provide Petra under our Terms of Use, including your account, groups, sync, storage and plan limits: performance of a contract (Art. 6(1)(b) GDPR).
- Health data, and identity document scans you choose to store: your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), given on the consent screen. See the Health Data Notice.
- Location during trip mode: your consent (Art. 6(1)(a) GDPR), given by joining a group and allowing Petra to use your location, and withdrawable at any time. See the Location and Trip Mode Notice.
- Details of emergency contacts and next of kin: our and your legitimate interest in having someone to contact in an emergency (Art. 6(1)(f) GDPR). Where life is at risk, also the vital interests of the person concerned (Art. 6(1)(d) and Art. 9(2)(c)).
- Crash reports and security: our legitimate interest in keeping the app working and secure (Art. 6(1)(f) GDPR).
- Usage statistics: your consent (Art. 6(1)(a) GDPR). The app asks once and sends nothing until you say yes; you can turn it off at any time in Profile, under Usage statistics.
- Forum posts, comments and votes: our and your legitimate interest in answering questions in the open (Art. 6(1)(f) GDPR). You choose what to post and can delete it.
- Keeping records the law requires, for example for payments: legal obligation (Art. 6(1)(c) GDPR).
4. Who can see your data
- Members of your groups: the parts of your card each group is set to share, your group files, and your positions recorded during that group's active dates. They can see this on their phones, including offline.
- Group organisers: who is in the group, and join requests.
- Nobody else. We do not publish your card, and our staff access data only when needed to fix a problem you reported, to keep the service secure, or when the law requires it.
5. Service providers
We use these providers to run Petra. Each processes data only on our instructions under a data processing agreement:
- Supabase: database, file storage, authentication and live updates. Data is hosted in [Supabase project region, e.g. EU (Frankfurt)].
- Sentry (Functional Software, Inc.): crash and error reports, sent to its EU data centre in Germany. Reports describe the error and the device; the app is set not to attach IP addresses or account details to them.
- PostHog (PostHog, Inc.): usage statistics, sent to its EU data centre. The app sends only named feature events and a random account identifier; it does not send your card, location, name or email, does not record screens, and turns off looking up a location from your IP address.
- Google and Apple: sign-in, if you choose it. Their own privacy policies apply to your Google or Apple account.
- Apple Maps (iOS) and Google Maps (Android): map tiles for the route and position map. The map provider receives the area of the map being shown.
- Apple and Google, again, for subscriptions: a Pro subscription is bought and paid for in the App Store or Google Play. They take the payment and hold your payment details; we never see them. We receive only the fact that a subscription is active, and when it ends.
- RevenueCat, Inc.: manages subscriptions across the two stores and tells our server whether your subscription is active. It receives your Petra account identifier, which store the purchase was made in, and the purchase, renewal and expiry dates. It does not receive your card, your location, your name or your email address.
6. Transfers outside the EEA
Some providers, or their sub-processors, are based in the United States. Where data leaves the European Economic Area, it is protected by the EU-US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.
7. How long we keep it
- Your card, files and groups: until you delete them or your account.
- Positions: as long as the group chose -- until the end of the trip, 7 days or 30 days -- and never more than 30 days. Leaving a group, or the group being deleted, removes the positions no other group of yours covers. Deletion runs every hour, on the server and on each phone.
- Forum posts and comments: until you or we delete them, or you delete your account.
- Join requests: until accepted, declined or the group is deleted.
- Deleting your account removes, immediately, your card, your files, your positions, your membership of every group, and every group you organise with its files and members.
- Backups made by our hosting provider may still contain deleted data for up to [number of days backups are kept], after which it is overwritten.
- Crash reports: [90] days.
- Usage statistics: [12 months].
8. On your phone
- The app keeps your card, your groups, other members' shared cards, group files and saved maps on your phone so they work offline. All of it is encrypted with AES-256-GCM, using a key held in your phone's secure storage that only works while the phone is unlocked and is not included in backups.
- Without an account, your card is stored on your phone only and never sent to us.
- Leaving a group, being removed, or the group being deleted removes that group's copies from the phone. Signing out keeps your encrypted copies so they are there when you sign back in; deleting your account, or removing the app, deletes them.
- If you export a file or route to your phone's storage or share it with another app, that copy is no longer encrypted or controlled by Petra.
8a. Storage in the app and the browser, and cookies
- The phone app uses no cookies. What it keeps on the phone is described in section 8.
- The web version keeps your sign-in session in the browser's storage, because you could not stay signed in without it. This needs no consent.
- Only if you allow usage statistics, PostHog stores a random identifier in the app or the browser so that events from the same device can be counted together. Say no, or turn it off in Profile, and nothing is stored or sent.
- We use no advertising, social or tracking cookies, and share nothing with advertisers.
8b. Emails
- We only email you about your account: confirming your address, resetting your password, and changes to these documents or to a paid plan. These are part of the service and cannot be unsubscribed from while you have an account.
- We send no newsletters or marketing. If that ever changes, we will ask first, and every such email will have a link to stop them.
9. Security
Data is encrypted in transit. Access on our servers is enforced per user and per group by the database itself, so members can only read what their groups share. No system is perfectly secure; if a breach affects your data we will tell you and the authority as the law requires.
10. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- correct it (most of it you can edit in the app);
- have it erased (delete it in the app or delete your account);
- restrict or object to processing based on legitimate interest;
- receive it in a portable format;
- withdraw consent at any time.
To use these rights, write to support@hernadlabs.com. We answer within one month. You also have the right to complain to a data protection authority, in particular where you live or work; in Hungary this is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11, naih.hu.
11. Children
Petra accounts are for adults aged 18 or over. We do not knowingly collect data from children through their own accounts.
12. Changes
We will show you any important change to this policy in the app before it applies. The date at the top shows when it last changed.