Privacy Policy
Effective date: May 1, 2026
Data We Collect
Account Data
- Email address (for authentication)
- Name (for display within the app)
Usage Data
- Time tracking records (work sessions, breaks, downtimes)
- Order and production data entered by users
- Device token for push notifications (iOS)
Diagnostic & Performance Data
- Crash reports and error logs (via Sentry) — linked to a pseudonymous user ID only, no name or email
- Session replays on error (via Sentry) — all text masked, all media blocked before transmission
- Page performance metrics (via Vercel Speed Insights) — anonymized, no user identifiers
Why We Collect Data
- Authentication: Email and name for account access
- Core functionality: Time records, orders, production data
- Notifications: Device token to deliver push notifications
- Stability: Crash logs to improve app reliability
How We Store Data
- All data stored in PostgreSQL database hosted by Supabase (EU region)
- Data in transit encrypted via TLS/HTTPS
- Data at rest encrypted by Supabase infrastructure
- Authentication tokens stored in iOS Keychain (for biometric login)
Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, storage | Account data, usage data |
| Vercel | Application hosting & performance monitoring | Anonymized request logs, page performance metrics |
| Sentry | Error monitoring & session replay | Crash reports linked to pseudonymous user ID only; replays with masked text and blocked media |
| Google Gemini | AI order processing (optional) | Order document content |
Your Rights (GDPR)
- Access: Request a copy of your data
- Deletion: Request deletion of your account and all associated data
- Portability: Export your data in standard formats
- Correction: Update incorrect personal data
To exercise these rights, contact: kontakt@zretelne.sk
Data Retention
- Account data: retained while account is active
- Time records: retained per company policy
- Crash logs: 90 days (Sentry default)
- Device tokens: deleted on logout or account deletion
Account Deletion
You can request complete deletion of your account and all associated data by contacting kontakt@zretelne.sk. Your company administrator can also delete your account from the settings panel. All personal data will be permanently removed within 30 days of the request.
Biometria (Face ID / Touch ID)
Pre prihlásenie cez Face ID a Touch ID využívame iOS Secure Enclave a systémové Keychain API. Biometrické údaje (sken tváre, odtlačok prsta) zostávajú výhradne lokálne na vašom zariadení a nikdy sa neprenášajú na naše servery ani k tretím stranám. Aplikácia od operačného systému dostáva iba odpoveď „úspešné overenie“ alebo „neúspešné overenie“.
App Tracking Transparency
Aplikácia Chronify nepoužíva framework Apple App Tracking Transparency a netrackuje vás naprieč aplikáciami iných spoločností. Nepoužívame reklamné SDK a nezdieľame vaše údaje s tretími stranami pre účely reklamy alebo cieleného marketingu.
Network monitoring
Capacitor Network plugin používame výhradne pre detekciu offline stavu, aby sme vám vedeli zobraziť upozornenie pri prerušenom spojení. Plugin nezbiera ani neodosiela žiadne údaje o sieti, IP adrese, mobilnom operátorovi ani o lokalizácii zariadenia.
In-app deletion
Účet môžete zmazať priamo z aplikácie v sekcii Nastavenia → Účet → Zmazať účet. Po potvrdení sa prihlasovacie údaje odstránia okamžite a personálne údaje sa vymažú do 30 dní podľa GDPR retention policy. Historické záznamy práce a auditu môžu zostať v anonymizovanej forme zachované u vašej spoločnosti z dôvodu integrity účtovníctva a oprávneného záujmu zamestnávateľa.