AlwaysInTouch PL EN

Privacy Policy

App: AlwaysInTouch (pl.haskelar.alwaysintouch)
Last updated: 23 September 2026

In short. AlwaysInTouch is a serverless messenger. Conversations, photos, map pins and game scores never pass through our infrastructure, because there is no such infrastructure. Devices connect directly to one another — over a local network created by one of the phones' hotspots, or over Bluetooth Low Energy.

The only exception is one you trigger yourself: a Guide answer you report as offensive, untrue or harmful is sent to us (§4, point 6).

We do not operate user accounts. We do not know your name, e-mail address or phone number, because we never ask for them.

1. Data that stays on your device

The following data is stored locally only, in a database encrypted with SQLCipher whose key is held in the Android system keystore (Keystore):

The display name you choose on first launch is kept outside that database — in the app’s encrypted storage, whose key is also protected by the Keystore. The database holds it too, as the signature on your messages.

Guide conversations survive leaving a group — they are not part of a session, so neither ending the session nor the Delete data from this phone row (§7) erases them. You delete a single conversation from the Guide list (Delete conversation), and all of them at once by uninstalling the app or clearing its data.

The same goes for Guide answer reports waiting for internet (§4, point 6): they sit in the same encrypted database, disappear once sent, and unsent ones after 30 days. Delete data from this phone does not erase them, because they are your decision, not group data.

Separately, in the app's private storage (a folder other apps cannot access, but without additional encryption):

The diagnostic log (technical connection information — see §5) is kept in the folder Android/data/pl.haskelar.alwaysintouch/files/logs. Other apps cannot access it, but it can be read by connecting the phone to a computer with a cable.

Android backup is disabled for this app (allowBackup="false"), so this data is never copied to Google Drive.

Uninstalling the app deletes it irreversibly. We hold no copy of it and cannot recover it.

2. Data shared with other group members

When you join a group, its other members receive — directly from your device to theirs — whatever you send them:

You can delete your own message: its text is then erased on the phones of the group’s members. A photo that has already reached someone stays on their phone, though — deleting the message removes neither the thumbnail nor the full-size photo file. A phone that is no longer in the group does not receive the deletion.

Your position on the map is sent to no one until you do it yourself. You can share it with the group, and every time it is your explicit decision — there is no default mode and no “consent forever”:

Traffic between devices is encrypted. It passes through no intermediary server and does not travel over the internet — it stays within the local network or the Bluetooth link.

Group members are people you invite yourself, or whose invitation you accept. We have no visibility into who is in a group or what is exchanged within it.

3. Permissions and why they are needed

PermissionWhat it is used for
Location (precise and approximate) Required by Android in order to start a local hotspot (LocalOnlyHotspot) — without it a group session cannot start. It also shows your own position on your map and — only when you turn it on yourself — lets you share it with the group for a time you choose.
Camera Scanning the QR code when joining a group, taking photos to send to the group, and translating text from the camera preview (text recognition happens entirely on the device — the image is never sent anywhere).
Bluetooth (scan, advertise, connect) Discovering nearby devices and handing over network details when joining a group or restoring a dropped connection.
Wi-Fi and nearby devices Starting the hotspot on the device hosting the session, and letting the other devices join it.
Notifications Informing you about new messages and about the session state.
Foreground service / battery optimisation exemption Keeping the connection to the group alive while the screen is off. Without it the system suspends the process and the group loses connectivity. The service is also declared with the “location” type, because without it position sharing stops working with the phone in your pocket — your position is read only within the window you opened yourself. We do not ask for the “background location” permission.
Internet Only the uses listed in §4.

Your location is never sent to us or to any third party. It goes only to the members of your group, and only when you turn on position sharing yourself (§2). A separate, explicit case: when you ask the offline map wizard for the name of an area you selected, the coordinates of that area (not your position) go to OpenStreetMap — see §4, item 2.

4. The only internet connections

The app is designed to work without an internet connection. It uses the network only to get ready before a trip and to handle a purchase — never to carry what happens in the group. The complete list:

  1. RevenueCat — handling the purchase and verifying the plan you bought. RevenueCat receives an anonymous device identifier (in the form $RCAnonymousID:…), purchase details and standard technical connection data. We do not send it your name, your conversations or your location. RevenueCat's privacy policy: revenuecat.com/privacy
  2. Nominatim (OpenStreetMap) — the offline map wizard. The search term you type is sent, and when the wizard suggests a name for the area being downloaded — the coordinates of the centre of that area (to roughly city-level precision). This is not your GPS position, only the piece of the map you are looking at. osmfoundation.org
  3. Map tile server (Protomaps / OpenStreetMap) — downloading the offline map of the area you select.
  4. Cloudflare (packs.haskelar.pl) — the publisher's catalogue of packs and the pack downloads themselves (Guide content). Cloudflare sees your IP address and which file you are downloading, as with any download from a website; the storage belongs to the app's publisher. The catalogue is cryptographically signed and the app rejects a pack whose signature or checksum does not match — downloading from the publisher's server does not mean the app trusts whatever came from there. Until 4 August 2026 this role was played by GitHub (raw.githubusercontent.com).
  5. Google Play services (ML Kit) — downloading the offline translator's language packs. The app starts the download, but Google Play services on your device carry it out; the information about which language pack is being downloaded is passed on. Translation and text recognition then happen entirely offline — texts, photos and the camera image never leave the device. The ML Kit library also sends Google aggregated diagnostic data and usage statistics (device and app information, an installation identifier, performance metrics, error codes) — never the content of translations or images. policies.google.com/privacy
  6. Reporting a Guide answer — only when you send it yourself. By long-pressing a Guide answer you can report it as offensive, untrue, harmful or for another reason. The report goes to the app's publisher (support.haskelar.pl, our server behind Cloudflare) and contains: your question, that one answer, the reason you chose and an optional comment, the model and knowledge-pack versions, the language and the app version. It does not contain your name, group data, other conversations or a device identifier. Without internet the report waits on your phone and is sent automatically once a connection is back. As with any connection, your IP address is visible to Cloudflare and the server's access log — we do not add it to the report itself. We keep reports for 12 months and use them only to improve the Guide's answers — model prompts, filters and knowledge packs. Google Play's rules require this kind of reporting for AI-generated content.

Outside these six cases the app sends nothing to the internet. In particular, it contains no advertising and no analytics tooling of our own, and your conversations, photos and game scores have no path off the device other than the direct link to your group's phones (§2).

5. Diagnostic log

The app keeps a local technical log (connection state, errors) that helps diagnose connectivity problems. It lives on your device, in the folder Android/data/pl.haskelar.alwaysintouch/files/logs (other apps cannot access it, but it can be read by connecting the phone to a computer with a cable), and is never sent anywhere automatically.

You can export it and send it to us yourself from the Diagnostics screen — this happens solely on your initiative and under your control. The log may contain Wi-Fi network names and participants' display names; it does not contain message content.

6. Children

The app is not directed at children under 13 and we do not knowingly collect their data.

7. Your rights and data deletion

Because we operate no user accounts and store none of your data on servers, there is no account to delete and no dataset for which a copy could be requested.

You delete local data by uninstalling the app or clearing its data in the system settings. You can also delete the group's conversations, photos, map pins and game scores without uninstalling — in the app's Settings, with the Delete data from this phone row.

Purchase data is held by RevenueCat and in your Google Play account — for those matters, refer to the policies of those services.

8. Changes to this policy

We will announce material changes through the update notes on Google Play. The date of the most recent change appears at the top of this document.

9. Contact

For privacy matters: kontakt@haskelar.pl