Privacy Policy
Mój Kredyt is a mortgage overpayment tracker. We do not connect to your bank and do not provide financial advice. This policy explains what data we process and why.
1. Data controller
The data controller is the owner of the Mój Kredyt app. Contact: jrydzewski.contact@gmail.com.
2. Local-first principle
The app works fully without an account. Loan and overpayment data is stored on your device by default (local SQLite database). Cloud sync is optional.
3. Data we process
- Loan data - amounts, dates, interest rates, schedule, bank name (from a picker), currency.
- Overpayments - amounts, dates, effect (shorten term / lower installment), optional notes, recurring rules.
- Account data (optional) - email address and Firebase Authentication user ID (Google, Apple, or email/password sign-in).
- Sync data (optional) - a copy of the above in Google Cloud Firestore, linked to your account.
- Diagnostic data (crashes) - device model, OS and app version, error stack trace. Collected only in the production build to fix crashes. Does not include loan amounts, emails, or notes.
- Usage statistics - the fact that an action happened in the app (e.g. finishing setup, adding an overpayment, opening a screen) with general categories (e.g. “shorten term” or “lower installment”), plus device model, OS and app version, language and approximate country. Events from the same installation are linked by a random app instance ID: it is not an advertising ID and it is not linked to your account. We do not send amounts, balances, rates, dates, loan names, banks, notes or email. You can turn them off in Settings (“Help improve the app”).
We do not collect location, contacts, photos, or bank account access.
4. Purposes and legal bases (GDPR)
- Providing app features (tracker, calculations, history) - Art. 6(1)(b) GDPR.
- Optional cloud backup and sync - Art. 6(1)(a) GDPR (consent via voluntary sign-in).
- Local notifications for planned overpayments - Art. 6(1)(b) GDPR; requires device permission.
- Crash reports (app stability) - Art. 6(1)(f) GDPR (legitimate interest of the controller).
- Usage statistics without data that identifies you directly (which features are used, to improve the app) - Art. 6(1)(f) GDPR (legitimate interest of the controller). You can object by turning statistics off in Settings; it takes effect immediately.
5. Where data is stored
- Device - local database until you delete the app or use “Delete all data”.
- Cloud (optional) - Firebase Authentication and Cloud Firestore (Google). Data is isolated per user (
users/{uid}/…). - Crash diagnostics - Firebase Crashlytics (Google), production builds only. Reports stored by Google under their policy.
- Usage statistics - Google Analytics for Firebase (Google Ireland Limited as processor). Kept for 14 months, without Google signals and without ad personalization.
6. Sharing
We do not sell data or share it with advertisers. Data goes only to:
- Google Firebase (auth and sync) - when you use an account;
- Google Firebase Crashlytics (crash reports) - in the production app build;
- Google Analytics for Firebase (anonymous usage statistics) - when enabled in Settings;
- Apple / Google - only for sign-in, under their policies.
7. Your rights
You may access, rectify, erase, restrict, port, or withdraw consent. In the app:
- Delete all data (Settings) - wipes local data; with an active account also removes cloud copy and Firebase account.
- Email jrydzewski.contact@gmail.com.
8. Security
Cloud connections use HTTPS/TLS. Email passwords are handled by Firebase - the app does not store them. Firestore rules restrict access to the signed-in user only.
9. Children
The app is not directed at children under 16. We do not knowingly collect children’s data.
10. Changes
This policy may be updated. The date at the top reflects the latest version. Material changes will be communicated in the app or by email.
11. Complaints
You may lodge a complaint with your local data protection authority.