1. Data controller and contact
The data controller for the DomoKey - Intercom and entry codes app is Jakub Serewa. For privacy-related matters, contact: kuba.serewa@gmail.com.
2. Data stored by the app
In the private list, DomoKey stores data entered by the user locally on the device: the place name, entry code or phone number, and an optional place location.
When shared lists are enabled, the app stores an encrypted list name and encrypted entry content in the cloud. It also stores the access code and a decrypted copy of downloaded lists on the device so they can be opened without an internet connection.
The app does not require an account, name, email address or other identifying information. For the technical operation of shared lists, Firebase creates a random anonymous device or installation identifier.
3. Shared lists and end-to-end encryption
The shared list name, place names, entry codes or phone numbers, and locations are encrypted on the device with AES-256-GCM before they are sent to Cloud Firestore. The key is derived locally from the access code and list identifier. The plain-text access code and encryption key are never sent to Firestore.
The cloud stores encrypted content and metadata needed for synchronization: document identifiers, creation and update dates, an anonymous list member identifier, and a cryptographic hash of the access code used to find an invitation. This metadata does not contain the plain-text content of entries.
Anyone who knows the access code can decrypt, read and edit the shared list. If the code is lost, neither the app author nor the Firebase administrator can recover or decrypt the encrypted cloud data.
4. Offline access and device storage
After a shared list is downloaded, the app stores a decrypted copy locally. The next time the app starts, it first displays data from the device and then attempts to download a newer version from the cloud when an internet connection is available.
The local cache, access code and private lists remain on the device until the list is disconnected, data is deleted in the app, app data is cleared or the app is uninstalled. Anyone with access to an unlocked device or its data may be able to access the local copy; the optional PIN or biometric lock limits access through the DomoKey interface.
5. Permissions used by the app
The app may request the following permissions:
- location - to assign a position to an entry and sort saved entries by distance,
- camera - to scan QR codes shared from the app,
- biometrics or PIN - for the optional app lock, if enabled by the user.
The user may deny these permissions in system settings. Some features may then work in a limited way.
The current location and locations assigned to entries are processed locally. If the user opens the map, the app downloads map tiles for the visible area from CARTO. The requested tile addresses may allow the provider to determine the viewed area, and the request also contains standard connection data such as the IP address and technical information about the browser embedded in the app.
Address search is performed only after the user selects this feature. The entered search phrase is sent to the Nominatim service operated by the OpenStreetMap Foundation. DomoKey does not store address search history, but the service provider may retain the query and technical connection data under its own privacy policy.
6. Sharing, export and service providers
Data from the private list is not automatically sent to the cloud. Data is sent to Cloud Firestore only when the user creates, joins or synchronizes a shared list, and it is encrypted on the device first.
Google Firebase services provide synchronization and anonymous authentication for shared lists. The provider processes encrypted content and technical metadata under its own policies and terms of service.
CARTO provides the map tiles. When the map is opened or moved, CARTO receives requests corresponding to the viewed area together with standard technical connection data. This data is used to display, maintain and protect the map service.
Nominatim, a service operated by the OpenStreetMap Foundation, provides manual address search results. Nominatim receives the entered search phrase and standard technical request data. The OpenStreetMap Foundation may process and temporarily retain this information for operational, security and map data improvement purposes under its privacy policy.
The user can export data to a JSON file, share a single entry through a QR code or give another person the access code to a shared list. These files, QR codes and access codes should be shared only with trusted people.
7. Data retention and deletion
Private data and the local cache remain on the device as described above. Shared-list entries are stored in the cloud until someone with access deletes them. Disconnecting a shared list removes its local copy and that device membership, but does not delete the list for other people.
Because the app does not maintain named accounts, a request concerning cloud data may require the list identifier or other information that allows the data to be located technically. Contact the data controller using the address provided in section 1.
8. Children's data
DomoKey is not directed at children and does not knowingly collect data from children.
9. Changes to this policy
This Privacy Policy may be updated when the app functionality or legal requirements change. The current version will be available on this page.