Privacy Policy
Last updated: 20 July 2026 · Effective date: 20 July 2026
This Privacy Policy explains how personal data is collected, used and protected in connection with the website appscaling.monster (the "Website") and the Stud Detector mobile application for Android, distributed via Google Play (package com.stud_detector) (the "App"). Together they are referred to as the "Services".
Please read this Policy together with our Terms of Service.
1. Who is responsible for your data (Data Controller)
The Services are operated by Yurii Ivanyshyn, a private individual resident in Poland, acting as the controller of your personal data within the meaning of Regulation (EU) 2016/679 (the "GDPR").
All privacy matters — including requests for our postal correspondence address — are handled directly at contact@checkengine.space. We have not appointed a Data Protection Officer, as we are not required to do so.
2. Short summary
| What | Do we collect it? |
|---|---|
| Magnetometer / sensor readings from your wall scans | No — processed only on your device, never transmitted to us |
| Camera images | No — the live camera view is rendered on your device in real time, never recorded or transmitted |
| Your name, address, phone number | No |
| Account / login data | No — the App has no user accounts |
| Payment card details | No — all payments are handled by Google Play |
| Precise location (GPS) | No |
| Contacts, photos, files, microphone | No |
| Website cookies / trackers | No — the Website is a static page with no cookies or analytics |
| App usage statistics and crash reports | Yes — via Google Firebase, in pseudonymised form (Section 5) |
We do not sell your personal data, we do not share it with data brokers, and we do not use it for advertising networks.
3. The Website
The Website is a static informational page. It has no contact forms, no user accounts, no analytics scripts, no advertising and no cookies other than those strictly necessary for the page to be delivered to you.
Like every website on the internet, our hosting provider automatically records technical connection data in server logs: IP address, date and time of the request, the page or file requested, browser type / user-agent and operating system, and the referring website (if any).
- Purpose: delivering the Website, ensuring its security and stability, detecting and preventing abuse and attacks.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and functioning website.
- Retention: kept by our hosting provider for a maximum of 30 days and then deleted or anonymised, unless a longer period is required to investigate a specific security incident.
- Hosting provider: Vercel Inc., acting as our processor under a data processing agreement.
If we ever add cookies, analytics or a contact form to the Website, this Policy will be updated before those features go live and — where required — your consent will be requested first.
4. Data processed only on your device (never sent to us)
The core function of the App is to detect anomalies in the magnetic field near a wall. The following data never leaves your device and is never accessible to us:
- Magnetometer and motion-sensor readings — read continuously while you scan and processed locally by the detection engine. They are held in memory only for the duration of the scan.
- Camera image — where the App shows a live camera view behind the scanning interface, frames are rendered on-screen in real time. Nothing is captured, saved, photographed, recorded or uploaded. The camera permission is optional and the App remains usable if you deny it.
- Calibration values and app settings — stored in the App's private storage on your device.
- Scan records stored in the App's local database, if you use features that save them.
All of this data is removed when you uninstall the App or clear the App's data in Android settings. Because it never reaches us, we cannot access, export or delete it on your behalf.
5. Data collected in the App
The App uses services provided by Google. Depending on the service, Google acts as our processor or as an independent controller (see Section 6).
5.1 Firebase Analytics (usage statistics)
What: pseudonymous app-instance identifier, events describing how the App is used (e.g. screen views, onboarding steps completed, a scan started, the paywall shown), device model, operating system version, device language, app version, and an approximate location (country/region) derived from the IP address. The IP address is not stored by us and is used by Google only for coarse geo-resolution.
Why: to understand which parts of the App are used and where users get stuck, so we can improve the product.
Legal basis: Art. 6(1)(a) GDPR — your consent, requested in the App. If you do not consent, or you later withdraw consent, these statistics are not collected. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
5.2 Firebase Crashlytics (crash and stability reports)
What: crash stack traces, App version, device model, operating system version, free memory/storage state at the moment of the crash, and a pseudonymous installation identifier. Crash reports do not contain your sensor data, camera images, contacts, files or location.
Why: to identify and fix crashes and defects. Legal basis: Art. 6(1)(a) GDPR — your consent, requested in the App.
5.3 Firebase Remote Config
What: a pseudonymous installation identifier, App version and device data, used to deliver configuration values (such as which pricing screen variant to show).
Why: to configure and test App features without shipping a new release. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating and improving the App.
5.4 Google Play Install Referrer
What: information provided by Google Play about how the App reached your device (e.g. the campaign or referral parameters attached to the install), read once at first launch.
Why: to measure which channels bring users to the App. Legal basis: Art. 6(1)(a) GDPR — your consent, where required.
5.5 Purchases and subscriptions (Google Play Billing and RevenueCat)
All purchases are made through Google Play, not through us. Google is the seller of record and processes your payment. We never receive or store your card number, bank details, billing address or full name from a purchase.
We do receive the status of your entitlement (for example: whether an active subscription exists, its type and expiry, and a purchase token used to verify it). We use this solely to unlock paid features and to handle support and refund enquiries.
To manage subscriptions we use RevenueCat (RevenueCat, Inc., USA), acting as our processor. RevenueCat sits on top of Google Play Billing and validates purchase receipts, retrieves the available plans and prices, restores previous purchases and computes whether your entitlement is active.
What is sent to RevenueCat: a randomly generated, anonymous app-user identifier created by the SDK on your device, the Google Play purchase token and receipt for a purchase you make, the resulting subscription/entitlement state, and basic technical data (app version, platform, country/store, and the IP address inherent to any internet request).
What is NOT sent: the App runs RevenueCat in anonymous mode — there are no accounts and no login, so we do not create, collect or transmit any name, e-mail address, advertising identifier or other identity of yours to RevenueCat. RevenueCat never receives your card or bank details, and it never receives your sensor readings, camera images or scan data.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract between you and us for the provision of paid App features. Google's own processing of your payment data is governed by Google's Privacy Policy and the Google Play Terms of Service; RevenueCat's processing is described in the RevenueCat Privacy Policy.
5.6 Support correspondence
If you write to us by e-mail, we process your e-mail address, the content of your message and any information you choose to include.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in answering enquiries; and Art. 6(1)(b) GDPR where your message concerns a contract with us. Retention: up to 24 months after the matter is closed, or longer where needed to establish, exercise or defend legal claims.
6. Who we share data with (recipients)
We disclose personal data only to:
| Recipient | Role | Purpose |
|---|---|---|
| Google Ireland Ltd. / Google LLC (Firebase) | Processor | Analytics, crash reporting, remote configuration |
| Google Ireland Ltd. / Google LLC (Google Play) | Independent controller / seller of record | App distribution, payments, subscriptions |
| RevenueCat, Inc. | Processor | Subscription management: receipt validation, entitlement status, restoring purchases |
| Vercel Inc. | Processor | Hosting the Website |
| Accountants, legal or IT advisers | Processor / controller | Only where necessary, under confidentiality |
| Public authorities | Controller | Only where we are legally obliged to disclose |
We do not sell, rent or trade personal data, and we do not share it for third-party advertising or profiling.
7. International transfers
Our providers may process data outside the European Economic Area, in particular in the United States. Where this happens, the transfer is protected by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or an adequacy decision (e.g. the EU–US Data Privacy Framework, where the recipient is certified), together with supplementary technical and organisational measures. You may request a copy of the relevant safeguards by writing to us.
8. Retention
- Website server logs: up to 30 days.
- Analytics data (Firebase): up to 14 months, then automatically deleted or aggregated.
- Crash reports: up to 90 days.
- Purchase / entitlement records: for the duration of the subscription plus the period required by tax and accounting law in Poland (generally 5 years from the end of the tax year) and by limitation periods for claims.
- Support e-mails: as described in Section 5.6.
- On-device data: until you delete it or uninstall the App.
9. Your rights
Under the GDPR you have the right to:
- access your data and obtain a copy (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erase your data — the "right to be forgotten" (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest, at any time, on grounds relating to your particular situation (Art. 21);
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
- lodge a complaint with a supervisory authority.
To exercise any of these rights, e-mail contact@checkengine.space. We will respond within one month; if the request is complex we may extend this by two further months and will tell you why.
Because the App has no accounts and the identifiers we hold are pseudonymous, we may need additional information from you (for example your App instance ID, available in the App's settings, or your Google Play order number) to locate your data. If we cannot identify you, we may be unable to fulfil the request (Art. 11 GDPR).
Supervisory authority in Poland: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warszawa, Poland — uodo.gov.pl. You may also complain to the authority in your own EU country of residence.
How to switch analytics off: open the App → Settings → Privacy and turn off analytics and crash reporting. You may also uninstall the App at any time, which stops all collection.
10. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you, and we do not create individual behavioural profiles within the meaning of Art. 22 GDPR.
11. Children
The Services are not directed at children. The App is intended for users aged 16 and over (or the minimum age at which consent to data processing is valid in your country, if that age is higher). We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Security
We apply appropriate technical and organisational measures, including encrypted transport (HTTPS/TLS), keeping sensitive processing on-device, using reputable providers under data processing agreements, and limiting access to data to what is necessary. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Changes to this Policy
We may update this Policy — for example when we add a feature or change a provider. The "Last updated" date at the top always shows the current version. If a change is material, we will give notice on the Website and, where appropriate, in the App before it takes effect. Where a change requires your consent, we will ask for it.
14. Contact
Yurii Ivanyshyn, Poland
E-mail: contact@checkengine.space