BlayaSoft

Privacy Policy

Last updated: 14 July 2026

This policy explains what data my website and mobile apps process, why, on what legal basis, and the rights you have over it.

Ivan Blajić (“I”, “me”, “my”) is the controller responsible for the personal data described here. It applies to my website blayasoft.com and to my mobile applications (together, the “Service”). By using the Service you agree to the processing described below.

01 What data I process

My apps are designed to keep your data on your device. Most features — mapping, coordinate conversion, terrain and line‑of‑sight analysis, and similar tools — run entirely offline and locally. Any files, maps, or photos you import are stored and processed on your device and are not uploaded to any server I operate.

The only data that leaves your device is described in the sections below: purchase information needed to manage what you have paid for, optional anonymous analytics and crash reports, and — only if you choose it — location sent to an external service you connect to yourself.

02 Location data

Several apps use your device location to provide navigation, mapping, coordinate, and terrain features. Your location is processed on your device only. I do not receive it, and it is not sent to any server I operate or to any analytics provider.

The one exception: services you connect to yourself. If you deliberately configure an app to connect to an external service of your own choosing — for example, a TAK server whose address you enter — the app transmits your location to that server so the feature you requested can work. You control whether to connect, which server to use, and when to stop sharing. I have no access to or control over servers you connect to and am not responsible for how they handle your data.

03 Purchases & subscriptions

Payment is handled entirely by Apple. I never see or store your card or payment details — that information goes directly to Apple under its own terms and privacy policy.

To unlock paid features, restore purchases, and keep subscriptions in sync across your devices, my apps may use RevenueCat as a processor. RevenueCat receives a randomly generated app‑user identifier together with the purchase information Apple provides (such as product IDs, transaction and receipt data, and subscription status). It does not receive your name, email, or card number. RevenueCat processes this data on my behalf under a data processing agreement.

04 Analytics & crash reports

My apps may use Google Firebase — specifically Firebase Analytics and Firebase Crashlytics — to collect anonymous usage statistics and crash reports. This helps me understand which features are used and diagnose and fix stability problems. The data is aggregated and pseudonymous; it is not used to identify you and is not linked to your name or contact details. Firebase's handling of this data is described in Privacy and Security in Firebase.

Where consent is required, this collection runs only after you opt in, and it stays off by default until then. You can withdraw consent at any time from the app's privacy settings, which stops further collection. Firebase processes this data on servers operated by Google, including in the United States, so the transfer safeguards in section 7 apply.

05 Website

When you visit my website, my server may briefly process your IP address, access time, browser and operating system, language setting, the page requested, and whether the request succeeded. This is technically necessary to deliver the site and to protect it against attacks such as denial‑of‑service.

My website uses no tracking cookies. Log data is deleted shortly after your visit, and no later than two months where it is retained to investigate an attempted attack.

If you contact me by email, I process the details you send (your name, email address, and message) solely to answer you, and delete them no later than one year after your request is handled.

06 Sharing & processors

I do not sell your data. I share it only in these cases:

07 International transfers

Some processors are located outside the European Economic Area, including in the United States. Where data is transferred outside the EEA, I rely on appropriate safeguards: the European Commission's Standard Contractual Clauses, and — for US providers certified under it — the EU‑US Data Privacy Framework. You may request a copy of the relevant safeguards using the contact details below.

08 Retention

I keep personal data only as long as needed for the purpose it was collected. Website logs are deleted shortly after your visit (up to two months for security investigations); contact messages within one year of handling your request; purchase records for as long as needed to provide and support your purchases and to meet legal and tax obligations. Anonymous analytics and crash data are retained per your provider's policy and are not linked to you.

09 Your rights

If you are in the EEA or the UK, you have the right to:

To exercise any of these, email me at the address below. You also have the right to lodge a complaint with a supervisory authority — the data protection authority in your country of residence, or in Croatia the Agency for the Protection of Personal Data (AZOP, azop.hr).

10 Security

I use reasonable technical and organisational measures to protect your data. No method of transmission or storage is completely secure, however, so I cannot guarantee absolute security.

11 Children

The Service is not directed to children under 16, and I do not knowingly collect their personal data. If you believe a child has provided personal data, contact me and I will delete it.

12 Changes

I may update this policy from time to time. The “Last updated” date above shows the current version; changes take effect when posted here. Please review it periodically.

13 Contact

Questions about this policy or your data? Email me at blayasoft@gmail.com.