Version 2026-07-29
Sveta Misa app privacy notice
This notice explains which data the website and mobile app use, why it is needed, how long it is kept and which choices and rights you have.
Controller and contact
UDRUGA SMS
Udruga Građana Sveta Mati Slobode
info@sveta-misa.org
Data we use and purposes
- Public browsing: a login is not required. The server may process short-lived security/access logs.
- Account and sign-in: email, first and last name, optional mobile number, account status, login provider, one-way token hashes, session/device metadata and sign-in times. The mobile number is used only as a private contact when you request church editing access and is not published publicly. Email code, Google and Apple sign-in are supported when enabled.
- Saved churches and per-church notification choices: stored as an account feature when you choose to use it. You can remove saved churches or delete the account at any time.
- Push: installation ID, provider token, platform, device model, language, app version, permission and delivery status. Push has its own separate consent and OS permission.
- Optional first-party analytics: pseudonymous visitor/session hashes, opened route or church, language, source and device type. It is off by default and disabling it requests deletion of that visitor history.
- Nearby: foreground coordinates are sent in the request only to calculate nearby churches; they are not stored in the application database or analytics.
- Search and AI: search text may be kept for up to 30 days and, only when AI fallback is enabled, sent to OpenAI to parse the place/time. AI does not make legal or similarly significant decisions.
- Forms and community: information you submit in access/new-church requests, comments and corrections is used to review that request or content. When anti-spam protection is enabled, Google reCAPTCHA processes the challenge token, IP address and technical browser/device data to prevent automated abuse.
- App feedback: the message you choose to send, language, platform and app version. If you are signed in it is linked to your account; otherwise a contact email is required so we can understand and follow up on the suggestion. The local app-use counter that decides when to show a prompt is not sent to the server. The IP address may be used transiently for abuse prevention, but is not stored with the feedback; only a keyed rate-limit bucket is retained briefly.
Legal bases and your choices
Account, saved churches and other requested features are processed to provide the service; security controls rely on legitimate interests; legal obligations apply where required. Voluntary feedback is processed at your request and under the legitimate interest in improving the service, and is never required to use the app. Optional analytics and push each use a separate, freely withdrawable choice. Refusing them does not prevent public browsing.
Providers and transfers
Depending on enabled settings, data may be processed by the hosting/email provider, Google or Apple for sign-in, Google reCAPTCHA for web anti-spam protection, Expo/APNs/FCM or Huawei for push, OpenAI for AI search, and the active map provider. The current map provider is OpenStreetMap. Some providers may process data outside the EEA under their applicable transfer safeguards; current provider details can be requested at the contact above.
Retention
- Unverified self-registration account: 7 days.
- Expired email/login records: expiry plus at most 7 days; OAuth attempt: at most 24 hours.
- Account deletion: sign-in is disabled immediately, direct account identifiers are pseudonymised, sign-in identities and device tokens are removed, and optional public contact consent is withdrawn. An encrypted recovery copy and linked account data are retained for a maximum of 30 days solely to allow restoration requested by the account holder. The account and remaining linked data are then permanently deleted automatically.
- Active account and identities: while the account is used; favorites: until you remove them, request account deletion, or the account reaches its final deletion date.
- Inactive device: token removed immediately, row after 30 days; push delivery/outbox: 30 days; campaign: 12 months.
- Raw analytics events: 13 months; raw search/AI query: 30 days.
- App feedback, contact details and review record: 12 months.
- Operational access logs: target 14 days; backups: normal rotation up to 30 days.
Your rights
You can request access, correction, deletion, restriction, portability and object where applicable, and withdraw consent at any time. The app Privacy center provides an export, consent controls and account deletion. During the disclosed 30-day recovery period you can ask the privacy contact to restore the account; after the scheduled purge restoration is impossible. Requests are normally answered within one month. Erasure can be limited where a real legal obligation or legal claim requires retention.
You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr.
Children
Public content is available without an account. In Croatia, a person under 16 needs authorization from a parent or guardian for consent-based account features.