In short: Opora PL has no sign-up, no accounts and no server of ours. We never receive or store your contacts, your location or the text of your messages. Everything you create in the app stays on your device, and you can erase all of it at any time with a single action in Settings.
Data processing in the Opora PL app is the responsibility of its publisher ("we", "us").
Privacy contact: info.oporapl@gmail.com.
Using the app requires no registration, no email address, no phone number and no other identifying information. We operate no backend server, no user database and no logs of your activity.
This means we are technically unable to see who uses the app, when, or how.
If you add a trusted contact, the app stores that person's name and phone number in your device's secure system storage — iOS Keychain or Android Keystore-backed storage. This data never leaves your device and is never transmitted to us.
Contacts are chosen through the system contact picker. The app does not read your address book as a whole and has no access to entries other than the one you explicitly select.
If you add a home-screen widget or a Quick Settings tile, the app publishes to it the minimum needed to draw the button: the name and initials of your primary trusted contact.
On Android the primary contact's phone number goes there too. This is a deliberate exception: the widget button dials straight from the home screen without starting the app — precisely when the extra seconds cost the most. The number is held in the app's private preferences file, which other apps cannot read, and is additionally excluded from cloud backup and device-to-device transfer, so it stays on the device it was entered on.
On iOS no number is published at all: a widget there cannot place a call and only opens the app.
As soon as you delete the contact, this data is overwritten empty.
Location is used only when you tap "Share my location", and only in foreground ("When In Use") mode.
The location permission is not requested at first launch — only when you first perform an action that needs it. You may refuse or revoke it in your system settings; the app continues to work, apart from location sharing.
Also stored locally on your device: the grammatical form you chose for phrases (masculine / feminine), your favourite phrases, your custom SOS message template, your default template, whether onboarding is complete, and internal app counters.
The app contains no separate analytics SDK. We collect no user events, build no profiles, perform no cross-app tracking and show no App Tracking Transparency prompt.
Location sharing goes through the system share sheet. The app only composes the message text with a map link — you choose the app and the recipient, and the sending is performed by that app (WhatsApp, Telegram, Viber, SMS and so on).
Once a message is sent, the data is in the hands of the service and recipient you chose, and their privacy policies apply, not this one.
So that the message carries a readable address alongside the link, the app queries the operating system's geocoder (CLGeocoder on iOS, Geocoder on Android). This means your coordinates are processed by Apple or Google as the provider of that system function. We hold no API key of our own and do not see these lookups. If address resolution is unavailable, the message is sent with the map link alone.
The link is composed as https://maps.google.com/?q={latitude},{longitude}. It is built on the device and exists only inside the message you send.
All calls — to emergency numbers, useful numbers or a trusted contact — are placed by the system phone app. Opora PL only opens the dialler with the number filled in; you confirm the call yourself. We never place calls automatically and have no access to your call history.
Subscriptions are processed by the App Store (Apple) and Google Play (Google). We never see or receive your payment details.
To verify subscription status the app uses RevenueCat, Inc. It receives an anonymous app-generated identifier, technical information about the device and app, and purchase state received from the store. This identifier is not linked to your name, email or phone number.
RevenueCat's privacy policy: revenuecat.com/privacy.
Advertising is disabled in the current version of the app. The ad module is not initialised, no ad requests are made, and no advertising identifiers are collected.
If advertising (Google AdMob) is enabled in the free tier in a future version, we will update this policy before it goes live, and in the EEA, the UK and Switzerland you will be shown a consent form (Google UMP) before any ad appears. You will then be able to change your advertising choices from the app's Settings, under "Ad privacy options", which appears exactly when the consent form requires it.
| Permission | Why | When it is requested |
|---|---|---|
| Location (while in use) | To obtain current coordinates for the message you are sending | Only after you tap "Share my location" |
The app requests no contacts permission at all: a trusted contact is chosen in a system sheet that returns only the entry you picked.
The app requests no access to the camera, microphone, photos, calendar, health data or background location.
Settings contains a "Delete all local data" action. It clears trusted contacts, favourite phrases, custom message templates, the chosen grammatical form and interface settings — and the data published to widgets and tiles.
One deliberate exception: two internal counters that govern advertising, including the pause after an emergency call. They hold nothing about you, and they survive so that deleting your data does not lift a restriction we place on ourselves.
This action does not cancel your subscription — subscriptions are managed by the app store. You can cancel in your App Store subscription settings or on Google Play.
Deleting the app from your device also removes all of its local data.
Because we hold none of your data, there is no deletion request to send us — and we could not fulfil one, since we do not have the data.
Under the General Data Protection Regulation (GDPR) you have the right to access, rectify, erase, restrict the processing of, and port your personal data.
Since the app transmits no data to servers of ours, these rights are exercised directly on your device: you can see all of your data in the app's interface and change or delete it at any moment. For data processed by RevenueCat, Apple or Google, please contact those companies directly.
You also have the right to lodge a complaint with the data protection authority where you live — in Poland, the Urząd Ochrony Danych Osobowych (UODO).
Data remains on your device until you delete it or uninstall the app. We set no retention periods because we retain nothing.
Contacts and custom templates are kept in the operating system's secure storage (iOS Keychain / Android Keystore). We rely on your device's own protections — we recommend using a passcode, Face ID / Touch ID or another biometric lock.
The app is not directed at children under 13 and does not knowingly collect any data about them.
If we change how data is handled, we will update this page and the effective date shown at the top. Material changes (such as introducing advertising) will appear here before they take effect.
Questions about this policy: info.oporapl@gmail.com.