Privacy Policy
Last updated: July 19, 2026
Apiaryum ("we", "us", "our") is a mobile application for beekeeping management. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Apiaryum application ("App"). We are committed to compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller is:
Kamil Tomaszewski
Dworczysko 8/1
16-506 Dworczysko, Poland
Email: support@apiaryum.com
We have not appointed a Data Protection Officer. For all matters relating to personal data, you can contact us at support@apiaryum.com.
2. What Data We Collect
2.1 Account Data
- Email address and password – when you create an account with email registration (processed by Firebase Authentication).
- Anonymous-account identifier – if you use the App without an email address, Firebase creates a pseudonymous account ID needed to keep that account's data separate from other users.
- Display name and username – optionally provided by you.
- Country and region – selected during registration for localization.
- Language preference – based on device settings or manual selection.
2.2 Beekeeping Data
We process beekeeping management data that you choose to enter into the App. This may include apiaries (with optional map location), hives, queens, inspections (with optional photos and voice notes), storage records, financial transactions, tasks, and change history.
2.3 Media
- Photos – taken by camera or selected from gallery for inspections, apiaries, and receipts. Stored locally on device and synced to cloud.
- Audio recordings – voice notes attached to inspections. Stored locally and synced to cloud.
2.4 Location Data
We do not continuously track your location via GPS. Location data is collected only when you explicitly place an apiary on a map or use the map picker. This location (latitude/longitude) is stored as part of the apiary record.
Location data is processed only on the basis of your consent and only when you actively use the map or location picker features.
2.4a Special Categories of Data
The App is not intended for processing special categories of personal data within the meaning of Art. 9 GDPR. Users should not enter such data into the App.
2.5 Voice Data
The App offers voice-controlled inspections using a keyword-spotting (KWS) model. Standard voice command processing happens entirely on your device using an on-device machine learning model (ONNX Runtime). Raw audio from local KWS commands is not sent to our servers or any third party for speech recognition purposes.
2.6 AI-Assisted Features
For users who opt in to AI-assisted inspection analysis, with availability and usage limits depending on the current plan:
- Audio recordings, language, requested response schema, and the necessary active inspection context (which may include optional apiary or hive names, available fields, and allowed values) are sent through an authenticated Cloud Function to Google Cloud Vertex AI (Gemini) for analysis and proposed inspection-field completion.
- You will be asked for separate in-app consent before using this feature for the first time. We may ask you to confirm it again if this feature or the consent terms materially change.
- Google processes this data according to their Privacy Policy.
- We store a record of this consent (for example consent date and consent version) and limited usage metrics for this feature (such as request counts or audio duration) to enforce limits, prevent abuse, and control service costs.
- The backend records limited operational metadata such as the authenticated user identifier, request duration, model and language, and request/usage counts in order to enforce limits, secure the service, troubleshoot errors, and control costs. We do not use the request content to build an advertising profile or a separate voice-training library.
2.7 Subscription Data
Premium subscriptions are processed through RevenueCat (via Google Play or Apple App Store). Your Firebase user identifier is provided to RevenueCat as the App User ID so that purchases can be linked to your Apiaryum account. We store your subscription tier and expiration date. We do not have access to your payment card details.
2.8 Push Notification Tokens
If you enable push notifications, we store your device's Firebase Cloud Messaging (FCM) token to deliver notifications. You can disable notifications at any time in your device settings.
The push notification token is processed only on the basis of your consent expressed by enabling notifications on your device.
2.9 Diagnostic and Crash Data
To keep the App stable, we collect pseudonymous diagnostic data when the App crashes or encounters an error. This is processed through Firebase Crashlytics and may include the error type and stack trace, the App version, the device model and operating system version, and a randomly generated installation identifier. This data is not intended to include your name, email, beekeeping records, or other content you enter into the App, and is not used for advertising or tracking.
Off-device crash reporting is disabled by default for new installations. It begins only if you enable diagnostics in Settings → Privacy & diagnostics, and you can switch it off again at any time. Local error logs remain on your device.
3. How We Use Your Data
- Providing and maintaining the App's beekeeping management features.
- Syncing data across devices when you are logged in.
- Delivering push notifications you subscribe to.
- Processing and managing your premium subscription.
- Providing AI-assisted analysis (with consent, depending on plan and usage limits).
- Managing AI feature limits, security, and service costs.
- Diagnosing crashes and errors to maintain and improve App stability (when diagnostics are enabled).
- Complying with legal obligations.
4. Limited Product Statistics
We collect limited feature-usage counters: at most one use of each tracked feature per App session. Events are held in memory, batched, and uploaded periodically or when the App enters the background rather than after every interaction. The upload is authenticated to prevent abuse, so Firebase may transiently process the account identifier, IP address, and security metadata during transmission.
The statistics record contains only the UTC day, a fixed feature name, an increment, and the country code derived from the country selected in the account. It does not contain a user, device, installation, or session identifier, precise location, free text, beekeeping records, or a per-user history. Country is used only for aggregate regional comparison and is not joined back to profile records.
This processing is enabled by default on the basis of our legitimate interest in measuring and improving active App features (Art. 6(1)(f) GDPR), not consent. You may object and disable future product-statistics uploads at any time in Settings → Privacy & diagnostics, without losing core App functionality. We do not use advertising identifiers or create advertising profiles.
5. Legal Basis for Processing (GDPR)
- Contract performance – processing necessary to provide the App's functionality (Art. 6(1)(b) GDPR).
- Consent – for optional features such as push notifications, location access, camera, microphone, AI processing, and enabling off-device Crashlytics diagnostics. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Art. 6(1)(a) GDPR).
- Legal obligation – where processing is necessary to comply with legal obligations applicable to us (Art. 6(1)(c) GDPR).
- Legitimate interest – for limited aggregate product measurement and ensuring service security (Art. 6(1)(f) GDPR). You may object as described in Section 10.
6. Third-Party Services
We use the following third-party services that may process your data:
- Firebase (Google) – authentication, Cloud Firestore (database), Cloud Storage (media files), Cloud Functions (backend logic), Cloud Messaging (push notifications), App Check (security). Data may be stored in Google Cloud infrastructure. https://firebase.google.com/support/privacy.
- Google Maps Platform – displaying maps and geocoding apiary locations. https://policies.google.com/privacy.
- Google Gemini AI – processing text/voice data and necessary inspection context for AI-assisted inspection analysis (with consent, depending on plan and usage limits). https://policies.google.com/privacy.
- RevenueCat – subscription management and in-app purchases; receives the Firebase user identifier as the App User ID. https://www.revenuecat.com/privacy.
- Firebase Crashlytics (Google) – optional pseudonymous crash and error diagnostics to maintain App stability (disabled by default for new installations). https://firebase.google.com/support/privacy.
As of the last update of this Policy, we do not use marketing or tracking analytics services such as Google Analytics or Firebase Analytics, and we do not display advertisements. Firebase Crashlytics is used solely for crash and error diagnostics if you enable it (see Section 2.9).
7. Data Storage and Security
- Your data is stored locally on your device (local database and app storage) and synced to Firebase Cloud Firestore and Firebase Cloud Storage.
- Selected app security data and locally cached account metadata may be stored in encrypted device storage (Flutter Secure Storage).
- Firebase App Check (Play Integrity / Device Check) is used to protect our backend from abuse.
- Access control rules ensure users can only access their own data.
8. Data Sharing
We do not sell your personal data to third parties. Your data may only be shared:
- With third-party service providers listed in Section 6, solely to operate the App.
- When required by law or to protect our rights.
9. Data Retention
We retain account and beekeeping data while your account is active and as needed to provide the service. Deleted records are removed from active storage during synchronization. AI request audio is kept only for the time needed to process the request; the temporary local recording is deleted after completion. Consent records, limited AI usage data, security logs, Crashlytics reports, and backups are retained only for the configured provider retention period or while reasonably needed for limits, security, disputes, or legal obligations, then deleted or overwritten.
Daily country-level feature counters contain no user identifier and are retained for 13 calendar months, after which an automated monthly cleanup deletes them. Authentication and security metadata processed during upload follows the retention applied to Firebase and infrastructure security logs.
10. Account Deletion and Your Rights
You can delete your account from within the App (Settings → Account → Delete Account). This removes account-linked data from active systems, subject to limited security logs, provider backup cycles, disputes, and legal obligations:
- All your data from Cloud Firestore (apiaries, hives, queens, inspections, tasks, histories, storage, and more).
- All your media files from Cloud Storage (photos, audio recordings).
- All local data from your device.
- Your Firebase Authentication record and username mapping.
Under GDPR and other applicable laws, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict processing and object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21 GDPR). In-App controls also stop future product-statistics and Crashlytics uploads.
- Data portability – receive your data in a structured format.
- Withdraw consent at any time for consent-based processing, without affecting processing before withdrawal.
- Lodge a complaint with a supervisory authority (UODO in Poland, or your local authority).
The App does not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.
To exercise any of these rights, contact us at support@apiaryum.com.
11. Children's Privacy
The App is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
12. International Data Transfer
Some data may be transferred to and processed outside the European Economic Area (EEA), in particular in connection with third-party providers such as RevenueCat and, depending on configuration, certain Google services. Where applicable, those providers state that they use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App or by other means. The "Last updated" date at the top reflects the most recent revision.
14. Contact
If you have questions about this Privacy Policy or your data, contact us: