Legal documents
Privacy Policy
1. Data controller
Tomasz Wilczyński is the controller of personal data processed in the Ogarniacz app. Contact for data protection matters: [email protected].
The controller has not appointed a Data Protection Officer (DPO); this is not required under the GDPR at the current scale of processing. The controller accepts all questions, requests to exercise rights and complaints concerning personal data at the address above.
2. What data we process
Account data: email address and password (the password is managed by Supabase Auth and is not stored by the controller in a readable form), and display name.
Family data: children (name, age/date of birth, colour and preferences), adults (name, role and colour), events (title, description, date, time, assignee and checklists), trips (destination, dates, number of days, accommodation type, personal plans and needs, weather data, packing lists and recorded costs with a name, amount, currency, category and date), recurring items assigned to a child/adult, and family invitation details (invitee email address and invitation status).
Family data also includes undated notes, their custom labels and an optional indication of the caregiver responsible for an item; shopping lists and their items; charges recorded in the Organization section; and manually entered household budget data (bank account names and balances, credit card names and debts, balance history by date, expected income per caregiver, a safety buffer and a daily spending budget).
Data sent to the AI import feature: screenshots, photos, PDF/TXT files or voice recordings submitted to recognize events, and receipt photos or card-payment screenshots submitted to read trip costs. We do not archive images or recordings as files or import history; a cost is stored only after the user accepts or corrects it (see section 6).
Data for reminders outside the app: email/web push channel settings, frequency, send time, technical web push subscription endpoint, and short digest/notification content (event titles and times, names of assigned children, and the number of items to take care of).
Calendar subscription link data: if you generate a permanent .ics link, the backend stores a token hash to validate the link and a separately encrypted copy needed to show the active URL again. The feed may contain event titles, dates, times, assigned people and checklist items in the description. The link works without logging in, so treat it as a secret; you can revoke it in the app.
Technical and diagnostic data: error reports (Sentry, see section 5.4), daily AI usage counters, and technical activity events for operational service monitoring (for example, successful sign-in, the technical name of an opened screen, timestamp, response times, basic web startup and performance metrics, and account and family IDs). Activity events do not contain family content such as children's names, event titles, notes, checklists or uploaded files.
On Ogarniacz's English and German public websites, we record an anonymous page view, language, page type and a broad source category: Google, Bing, direct visit or another referral. A page view is recorded at most once per page in a browser tab. We do not record the full referrer, search query, account or family content. A random identifier deduplicates events; statistics may include bots and do not represent unique people. When a tagged visit continues to the app, we also record safe campaign parameters and demo or registration stages, as described on the public Privacy Policy page.
3. Purposes and legal bases for processing
• Creating and operating an account and signing in — performance of the contract (Terms of Service).
• Storing and synchronizing family data — performance of the contract.
• AI analysis of submitted screenshots, documents or recordings — performance of the contract; the user initiates this feature by submitting a file or content for analysis.
• Invitations to share a family — performance of the contract and legitimate interests (enabling caregivers to collaborate).
• Sending optional email/web push reminders after the user enables them — performance of the contract.
• Providing an optional .ics calendar subscription link — performance of the contract.
• Daily AI feature limits — the controller's legitimate interests (preventing misuse and controlling costs).
• Error diagnostics (Sentry) — legitimate interests (service stability).
• Operational service monitoring (technical activity events, section 2) — legitimate interests (service stability and development).
4. Who enters children's data and on what basis
Ogarniacz is an app for caregivers, not children. An adult (parent/caregiver) creates and operates the account and enters information about their children as part of managing the family. Children do not create accounts or sign in and are not direct users of the app within the meaning of the GDPR.
The parent or caregiver is responsible for ensuring that entering a child's data into the app is lawful and that an appropriate legal basis for processing exists. The controller processes children's data only to the extent necessary to provide the service described in the Terms of Service to the caregiver using the app.
5. Who receives data (service providers)
We do not sell data. The providers below process data on our behalf under data processing agreements.
Supabase (database and authentication) stores all account and family data and handles sign-in and the creation of account activation, invitation and password reset links. Its infrastructure operates in the European Union. The related emails are delivered by Resend (see below).
Railway (backend hosting) and Cloudflare Pages (web app hosting) process requests in transit; Supabase stores persistent data.
AI provider — OpenAI LLC: the content of your request (for example an image, receipt, card-payment screenshot, document, recording/transcription, trip description, personal packing plans and needs, or other packing-list context) is sent directly to OpenAI LLC for analysis. Ogarniacz does not save the source file in its database or as import history; we store only the result you accept.
We have disabled organization-level API call logging on the OpenAI account used by Ogarniacz, and send Responses API calls with store:false. According to OpenAI's documentation, API data is not used to train or improve OpenAI models unless the account owner explicitly enables such data sharing. We do not currently have formally approved zero data retention (ZDR) or modified abuse monitoring, so OpenAI may still process limited data for security, abuse detection or legal compliance.
The controller may change the AI model provider to another provider with a comparable level of security if needed to deliver the service. OpenRouter is configured solely as a technical backend fallback. If a provider change affects the scope or purposes of processing, retention or transfers outside the EEA, this Privacy Policy and, if necessary, the Terms of Service will be updated before the change is deployed to production.
Sentry (error monitoring): when a technical error occurs, we send a diagnostic report. We deliberately do not send event content, children's/adults' names, checklist contents, uploaded files or session tokens.
Weather data — MET Norway and OpenStreetMap (Nominatim): for trips starting in the next few days, we retrieve an actual forecast. We send only the destination name (to Nominatim for geocoding) and the trip coordinates and dates (to MET Norway for forecasts), without names, account data or other family data. For more distant trips, weather remains an estimate prepared by the AI provider.
Resend (email delivery): emails sent by Ogarniacz — account activation, family invitations, password resets and optional morning reminder digests if enabled by the user — are delivered by Resend, Inc. and sent from [email protected]. Resend processes the recipient's email address and message content.
Web push: when push notifications are enabled, we store the browser's technical subscription (endpoint and public keys) and use it only to send reminders. Notification content includes a short digest title/description, a link to the app and a badge count. Delivery is handled by the browser or operating system's push service.
Calendar subscription link: after a .ics link is generated, an external calendar such as Google Calendar or Apple Calendar retrieves events through a non-guessable URL without signing in. The backend finds the feed using a one-way token hash and stores an encrypted copy of the active URL. Anyone with the link can read the feed, so you can revoke it in the app. Synchronization is one-way, from Ogarniacz to the external calendar.
Transfers outside the European Economic Area: Supabase's primary database operates in the EU. Some infrastructure providers (for example Cloudflare, Railway and Sentry) may process technical data or traffic metadata, or handle requests through global infrastructure, including outside the EEA. OpenAI LLC, and OpenRouter if the fallback is deliberately switched on, may process submitted content on servers in the United States. Resend, Inc., an email delivery provider based in the United States, may process recipients' email addresses and message content outside the EEA. A browser or operating system push service may process the technical endpoint and notification content outside the EEA, depending on its provider. Transfers use Standard Contractual Clauses (SCCs) or another GDPR-compliant mechanism. MET Norway's forecast service operates in Norway (EEA); Nominatim geocoding is provided by the OpenStreetMap Foundation, based in the United Kingdom, a country covered by an EU adequacy decision.
6. Files submitted for import — no archiving
Screenshots, shopping-list and receipt photos, card-payment screenshots, PDF/TXT documents and voice recordings submitted to the import feature are used only for one-time analysis and are not stored in our database or import history. We store only events, accepted shopping-list items or corrected and approved trip costs; we discard the source file on our side. We do not build an archive of submitted files. Any retention by the AI provider is described in section 5.3.
7. Data security
• The connection between your device and the backend, and between the backend and Supabase, is encrypted (TLS/HTTPS).
• Data in the Supabase database is encrypted at rest at the provider's infrastructure level.
• We additionally encrypt sensitive family content on the server: event and charge titles and descriptions; notes and their label names; children's and adults' names; trip destinations, plans and personal needs; packing-list and preparation items; shopping-list names and items; trip costs including names, amounts, currencies, categories and dates; manually entered budget account/card names; income breakdowns by caregiver; and a copy of the active calendar-feed token. Only technical data needed for calculations remains unencrypted, such as dates and identifiers, accommodation type, calendar-token hash, bill amounts and manually entered account/card balances, safety buffer and daily spending budget. Trip costs are encrypted as a whole. The current household budget does not store bank statements or individual transaction lists.
• This is not end-to-end encryption. The key is held on our side, so the controller and the AI provider (while an import is being analyzed) can technically read the unencrypted content. This is necessary for the app to display data, send reminders and recognize events using a language model.
• The app has no dedicated health-data module, but ordinary text fields can contain any content. We recommend not entering particularly sensitive data unless necessary.
• The app's local cache on your device is stored unencrypted in the device's local storage. A family invitation token is stored in the same way. We recommend protecting your device with a screen lock.
• Database access to family data is limited to accounts belonging to that family. The backend filters every read and write by family/user ID.
8. Data retention period
• Account and family data: for as long as the account remains active.
• After an account deletion request, we promptly begin deleting the login account and app data. If a technical error interrupts the final step, a persistent job retries automatically until it is complete. Data shared with other caregivers in the same family is not deleted.
• Family invitations expire automatically 7 days after they are sent if they have not been accepted.
• Daily AI usage counters: retained short-term to enforce daily limits and deleted with the account.
• Technical activity events: retained for operational service monitoring. When an account is deleted, they are permanently detached from account and family IDs and are no longer linked to any person.
• Sentry diagnostic reports: retained according to the provider's standard retention period (up to 90 days by default), without family personal data.
• Files submitted for AI import: not stored in Ogarniacz's database or import history; any retention by the AI provider is described in section 5.3.
• Database backups: they may be made under the current Supabase infrastructure plan and project settings. Data may remain for a limited time in technical backups, according to the plan's retention period. Backups are used only to restore the service after a failure and are not an active user data history.
9. Your rights
Under the GDPR, you have the right to access your data and receive a copy; rectify inaccurate data; erase data; restrict processing; transfer data; object to processing based on legitimate interests; and lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). You can also export events yourself at any time as an .ics file or share them with an external calendar through a revocable subscription link.
Requests to exercise these rights can be sent to [email protected].
10. Account deletion
You can delete your account yourself in the app's Profile. If you are the only caregiver in the family, the whole account and family are deleted, including recurring events, trips, checklists, shopping lists, notes, charges, budget, invitations and calendar feed. If you own a family with other caregivers, you must remove them from the family first. If you are a caregiver but not the owner, shared data stays with the family and passes to the owner.
The process starts promptly. We first prepare the family data securely, then delete the login account and app data. If a temporary outage interrupts final cleanup, a persistent job retries automatically. Limited presence in technical backups is subject to section 8.
11. Cookies and local storage (web version)
The web app uses browser local storage (localStorage) for the sign-in session and local data cache. For up to 30 days, it may also store safe campaign parameters, the Google/Bing search-engine category, a random visit ID, and recorded demo, registration and authentication stages. On the public EN/DE pages, sessionStorage prevents the same page view from being reported again in one tab. We do not store the referrer URL or search query. We do not use cookies for tracking or advertising and do not use third-party analytics that track users across sites.
12. Changes to this Privacy Policy
We will notify you in the app about material changes to this policy.
13. Contact
For matters concerning personal data protection: [email protected].