This Privacy Policy explains what data is processed by the Kur mesti? mobile application (the App) and its related service. The App is built to collect as little data as possible: it works without an account, without signing in, and without data that directly identifies you.
1. Who is responsible & contact
The Kur mesti? team is responsible for data processing in the App. For any privacy question, write to mintaras@grybauskas.lt.
2. What data we process
| Anonymous device identifier | When the App first launches, a random identifier is generated, stored on your device, and sent with requests. It is used to apply daily fair-use limits and to prevent abuse. It is not linked to your name, email address, or any other personal data. |
|---|---|
| Item photos | Photos you take are sent to our server so the item can be recognised. They are used only for recognition and are kept for no longer than 48 hours, after which they are deleted automatically. |
| Item descriptions in text | If you describe an item in words instead of photographing it, the text you enter is sent to our server and processed the same way a photo is — solely to identify the item and prepare an answer. Do not include personal data in descriptions. |
| Selected area | Your selected area (municipality, council, or district) is sent with each request so the answer matches local sorting rules. If you use "Use my location", your GPS coordinates are converted to an area on your device — precise coordinates are not sent for this purpose. |
| Drop-off map queries | When you open the drop-off map, the coordinates of the map view are sent to our server solely to return nearby drop-off points. They are not tied to your identity and are not used to build a location history. |
| Feedback ("Not identified correctly?") | If you submit a free-text note, it is kept for a longer period so we can improve recognition. Please do not include personal data in it. |
| Push notifications | If you enable notifications, a push token is issued by Apple and Firebase Cloud Messaging so the App can receive topic-based messages (for example, updates relevant to your area). The token is not linked to your identity, and you can disable notifications at any time in system settings. |
| Technical and usage data | Server logs temporarily record technical details (request time, errors). The App uses Google Firebase analytics and crash reporting (see section 4), which collect aggregated usage and crash data. |
3. Why we process it (legal bases)
- Providing the service — recognising the item and preparing an answer (performance of a contract / legitimate interest in providing the service you request).
- Limits and security — preventing abuse and keeping the service reliable (legitimate interest).
- Quality improvement — feedback and aggregated analytics help us improve the App (legitimate interest).
4. Third parties
To make the App work, some data is processed by trusted service providers:
- Google (Gemini API) — your photo or text description is sent to Google's AI service, which recognises the item and prepares the answer. Google may process data outside the European Economic Area, subject to appropriate safeguards.
- Google Firebase (Analytics, Crashlytics, Cloud Messaging) — collects aggregated usage statistics and crash reports so we can improve stability, and delivers push notifications if you enable them.
- Map tiles — the drop-off map loads its background map from a map-tile provider, which receives standard technical request data (such as your IP address) when tiles are fetched.
- Server hosting — the App's server runs with an infrastructure provider that stores data on our behalf.
More about Google's data handling: policies.google.com/privacy.
5. How long we keep data
- Photos — up to 48 hours, then deleted automatically.
- Feedback text — kept as long as needed to improve quality, and reviewed periodically.
- Technical logs — for a short period necessary for operation and security.
6. Your rights
Under the GDPR (and the UK GDPR, where it applies), you have the right to request access to your data, its correction or deletion, restriction of processing, and to object to processing. Because the App has no accounts and no data that identifies you, you can remove most data yourself:
- photos are deleted automatically within 48 hours;
- uninstalling the App removes the anonymous device identifier and your local history from the device.
For any request, contact mintaras@grybauskas.lt. You also have the right to lodge a complaint with your supervisory authority — in Lithuania, the State Data Protection Inspectorate (vdai.lrv.lt); in the UK, the Information Commissioner's Office (ico.org.uk); in Germany, your state's data protection authority.
7. Children
The App is not directed at children and does not knowingly collect their data.
8. Data security
We apply reasonable technical and organisational measures to protect data. However, no transmission over the internet is completely secure, so absolute protection cannot be guaranteed.
9. Changes to this policy
We may update this policy from time to time. We will announce material changes in the App or on this page by updating the date at the top.
10. Contact
Privacy questions: mintaras@grybauskas.lt.