Privacy Policy
This is a translation of the Polish original. In case of any discrepancy between the two versions, the Polish text prevails.
1. What this document covers
- This Policy describes the processing of data in two places:
- the Service — the pointmoa.eu website,
- the Application — the pointMoA Android app (package identifier
pl.fatpirat.pointmoa), distributed through Google Play.
- Sections 3–4 concern the Service only, section 5 the Application only, and the remaining sections both.
- This document is also the privacy policy referenced in the Application's Google Play listing.
2. Data controller
- The controller of personal data is Eryk Kozłowski, a natural person operating the pointmoa.eu website and publishing the Application, under the designation pointMoA.
- Contact for data protection matters: kontakt@pointmoa.eu.
- No data protection officer has been appointed — the conditions of Article 37 GDPR do not apply.
- Neither the Service nor the Application provides user accounts. There is therefore no account deletion procedure and no separate address for such requests; deletion of Application data is described in §5.7.
3. The pointmoa.eu website
The Service is designed to collect as little data as possible. Using it requires no account and no name, surname or e-mail address.
3.1. Correspondence
| Scope | e-mail address and message content |
| Purpose | replying to the message |
| Legal basis | Article 6(1)(f) GDPR — legitimate interest in conducting correspondence |
| Retention | until the matter is concluded, then 14 days at most |
Correspondence is kept solely in the Google Workspace mailbox and only for as long as the matter lasts. Once it is concluded the message is deleted — within 14 days at the latest. A deleted message then sits in the mail provider's bin for 30 days, after which the provider erases it on its own. The Controller keeps no correspondence archive of its own and no copy outside the mailbox.
3.2. Server logs
| Scope | IP address, date and time of request, page address, browser type |
| Purpose | operating and securing the Service, diagnosing errors |
| Legal basis | Article 6(1)(f) GDPR — legitimate interest in maintaining and securing the Service |
| Retention | at the hosting provider, in accordance with its own terms |
Logs are created and kept solely by the hosting provider. The Controller keeps no log archive of its own, does not download them and cannot extend their retention period.
3.3. Visit statistics — Vercel Web Analytics
The Service uses Vercel Web Analytics to measure visits and page views, identify popular pages and improve the Service. The provider is Vercel Inc.
| Scope | page views and event time, page address and path, referrer, filtered URL query parameters, approximate location (country, region, city), device type, operating system and browser with their versions |
| Purpose | aggregate statistics about use of the Service and improvements to its content |
| Legal basis | to the extent personal data is processed: Article 6(1)(f) GDPR — legitimate interest in measuring use of the Service while limiting the scope of data |
| Retention | session identification is discarded after 24 hours; aggregate statistics remain available for the retention period applicable to the Vercel plan in use |
The tool does not use cookies. Vercel distinguishes visits using a hash derived from the incoming request. It does not serve to track the same person across different websites. The 24-hour period concerns session identification, not deletion of all statistics.
The Controller receives aggregate statistics. They are not used for advertising, marketing profiling or linking activity across websites. Page views are recorded; the Service sends no custom events containing data entered into the Calculator, Targets or Shooting Licence module. Analytics concerns the website only, not the Android Application (§5).
Further processing details are set out in the Vercel Web Analytics privacy documentation.
3.4. Data we do not collect
The Service does not carry out marketing profiling or automated decision-making, does not use advertising tools or cross-site tracking, does not create user accounts and does not share data for marketing purposes.
4. Cookies and browser local storage in the Service
The full list — the name of every record, its content, lifetime and how to delete it — is set out in the separate Cookie Policy. What follows is the summary.
-
The Service stores one cookie, of a strictly necessary kind: it keeps the language chosen by the User while they move between pages. The cookie is a session cookie — it disappears when the browser is closed and does not carry the choice over to the next visit.
-
The Service additionally keeps in the browser's local storage (localStorage), not in cookies, what the User enters into the Service's tools: the data typed into the Calculator and the Targets (firearm, optic, ammunition and weather parameters), the column settings of the results table, and the learning progress and mock-exam state in the Shooting Licence module. The sole purpose is to let these entries survive a page refresh and navigation between pages. Nothing is sent to a server — the Calculator runs in the User's browser, and the Service has no backend that could receive this data.
-
The strictly necessary cookie and the local storage described in point 2 do not require consent — they are essential to provide a service explicitly requested by the User.
-
The Service uses no analytics, advertising or third-party cookies. Vercel Web Analytics (§3.3) measures visits without cookies or cross-site tracking. In this configuration the Service displays an information bar, without an “Accept/Reject” dialog. Closing it acknowledges the information; it is not consent and does not control analytics. A change to measurement or the addition of other tools requires reassessment and, where consent is required, obtaining it before those tools are enabled. See §6 of the Cookie Policy.
-
Cookies and local storage can be deleted or blocked in browser settings (site data). Blocking them does not prevent use of the Service — the User merely loses the remembered entries.
-
The Application uses neither cookies nor advertising identifiers.
5. The pointMoA Application
5.1. Principle: the app collects and sends nothing
- The Application runs entirely on the device. There are no accounts, no sign-in and no server for anything to be sent to.
- The Application does not collect and does not share any data with the Controller or with third parties. It contains no analytics, telemetry, advertising, advertising identifiers, tracking tools or third-party SDKs performing such functions.
- Consistently with this, the Data safety form in Google Play is completed as no data collected and no data shared. The store declaration and this Policy must agree — changing one requires changing the other.
- The Application holds the INTERNET system permission, required by the web engine it is built on. Every feature — calculations, data storage, photographs, shot detection, Zeroing, dry-fire training, statistics, reports and graphics — works fully offline, and the Application connects to no server operated by the Controller, because no such server exists. In versions that introduce the Pro purchase, the only network request will be a check of the purchase status with the Google Play service (§5.9).
- Links in the Application — to a manufacturer's page shown with an entry in the built-in databases, to a map the User entered in a range card, and to this Policy — open in the browser or app chosen by the system, and only once the User taps them. From that moment the rules of that site or service apply.
5.2. Data created by the User and kept on the device
The Application stores what the User enters into it. The data sits inside the app's private directory: the User's records in an IndexedDB database, and the user name and minor interface settings in the local storage of the web engine. None of it is sent anywhere.
| Armoury | firearm, optic and ammunition profiles, individual firearms and air guns (including round count and its corrections, assigned profile, modifications, and purchase date and price), firearm photographs (at most six per firearm, with captions) and the remembered firearm report layout, a service log (date, kind of work, replaced part, note, cost), ammunition products and lots, ammunition purchases including prices, the current zero and the reminder thresholds for checking it |
| Shooting log | date, start and end time, range (from the list, or name and locality), training type, shot count, malfunctions, personal notes; planned sessions with their preparation checklist |
| Competitions | name, dates, ammunition preparation and consumption, results and placings, notes |
| Zeroing | zeroing configuration (firearm or one-off set-up, optic and mount, click value, ammunition and lot, distances, conditions), shot series with accepted hits, recommended and applied clicks, result and zeroing history, checklist |
| Dry-fire training | laser training sessions: training or drill type, target and distance, the position and time of every laser spot, results, scores and times, and the camera technical data needed to judge the measurement (lens name reported by the system, sensitivity, exposure and zoom ranges, a camera operation log, frame calibration) |
| Ranges | range cards entered by the User: name, club, locality, address, directions, map link, phone number, opening hours, distances and lanes, prices, restrictions, pros and cons, rating, description, notes and one photograph; club membership with the date the fee is paid until — no membership number |
| Goals | live-fire and dry-fire goals (measure, target value, deadline). Records, insights and statistics are not stored — the Application computes them on the fly from the other data |
| Targets | scores, groups and hit analyses, target photographs (including those from Zeroing), photographs from range visits and competitions |
| User name | an optional name (40 characters at most) entered in Settings and shown in the greeting on the Start screen; empty by default |
| Interface settings | chosen language, theme (dark, light or system), units, first-run state and viewed hints, unsaved Calculator form draft, the Calculator's advanced mode settings (cant, wind direction, uncertainties and — if the User enters it — the geographic latitude for the Coriolis correction), selected target overlays, remembered report graphic layout, dry-fire settings (sound signal, chosen lens, view), the date of the last backup and of a postponed backup reminder, whether the "Next visit" line is expanded, names and localities of deleted range cards (so that they do not return when cards are created from history) |
| Version counters | applies to versions with the Pro purchase (§5.9): use of Free-version limits and of the trial period, and whether Pro has been purchased |
| Where it lives | in device memory only, in the app's directory |
| Who can read it | the User alone. The Controller has no access — no channel exists through which it could be received |
Log, competition, Zeroing and dry-fire entries, range cards and the latitude in advanced mode can indirectly reveal where and when the User was present (range name and address, locality, club membership, date and time). The User enters them, they are entirely optional, and the Application works without them.
Because this data never leaves the device and the Controller has no access to it, the Controller determines neither the purposes nor the means of its processing — and is therefore not its controller within the meaning of Article 4(7) GDPR. The User alone controls it.
5.3. Camera and photographs
- Target photographs — in the Shooting log, Competitions, Quick targets and Zeroing — are taken through the system camera, the system photo picker or — in the mode described in point 3 — through a camera preview inside the Application. Photographs of firearms, ranges, range visits and competitions are chosen by the User in the system picker. On the system routes Android asks for consent and hands the Application only the image the User selected.
- The Application declares the camera permission (
CAMERA) — solely for the camera preview inside the Application: the mode in point 3 and dry-fire training in point 4. It declares no gallery permissions — it has no access to the device's photo collection and does not browse it. - The "Photo with assist" mode shows a camera preview and suggests how to improve the framing before the photograph is taken. On first use the system or the browser asks for camera consent; consent can be withdrawn at any time in the settings — the Application then falls back to the routes from point 1. The preview image is analysed solely on the device, in memory — preview frames are never stored, sent anywhere or used for anything beyond the on-screen hints, and the preview ends the moment this screen is closed. The only thing stored permanently is the photograph the User takes; it goes where all other target photographs go (§5.2) and carries no EXIF metadata.
- Dry-fire training turns on the camera preview only after the User confirms the safety rules with the "Confirm and turn the camera on" button. Frames are processed solely on the device, in memory: the Application crops the area of the printed target and looks for the laser spot in it. It neither stores nor sends the frames — the session receives numbers: the position and time of shots, results, and the camera and calibration technical data listed in §5.2. The preview ends the moment the training screen is closed.
- The Application plays the dry-fire signals and commands: the phone generates the sound, and voice commands are read by the system speech synthesiser. The microphone is not used — the Application records no sound and has no permission that would allow it. The camera is not used for recording or recognising people, and the Application never starts it in the background.
- A photograph taken this way is not saved to the device gallery; it goes only into the app's database. Saving a finished report graphic to the "pointMoA" album is started only by the User (§5.6(2)).
- The Application reads technical EXIF metadata from the file that is needed for measurement: focal length, frame orientation, declared image dimensions, exposure time, ISO sensitivity, camera designation and the capture date. This metadata is used only in memory, at the moment the photograph is attached, for calibration. It is not stored — only the calibration result reaches the database, expressed as fractions of the image dimensions.
- The Application reads no geographic coordinates from metadata — it contains no code capable of recognising them.
- Before being stored, every photograph — of a target, a firearm, a range, a visit or a competition — is downscaled to at most 1600 pixels on its longer edge and re-encoded as JPEG. The re-encoding runs through a canvas, which removes all EXIF metadata, including any geographic coordinates recorded by the camera. What reaches the database is an image stripped of metadata.
- The Application does not use device location — it reads neither GPS nor Wi-Fi nor cell towers. The User types in the geographic latitude for the Coriolis correction (§5.2) by hand. Nor does the Application access contacts, the list of installed apps, the microphone or device identifiers.
5.4. Shot and laser spot detection
Shot-hole detection on a target photograph, the calibration and rectification of the photograph (including recognition of the pointMoA target markers in Zeroing and in dry-fire training) and laser spot detection run entirely on the device — on a bundled model and the Application's own code. Neither the photograph nor the camera image is sent anywhere for this purpose or used to train any model.
5.5. Google backup — the only automatic route off the device
🔴 This is the only mechanism that can move Application data off the device without a separate action by the User, which is why it is set out explicitly.
- The Application has Android's system backup enabled (
allowBackup). This means Application data — the whole database (profiles, log, zeroings, targets, dry-fire training, ranges, goals and photographs) together with the settings and the user name — may be copied into a backup tied to the User's Google account and restored after changing phones. - The backup is performed by Android and Google services, not by the Application. The controller has no access to it. Its retention is governed by Google's privacy policy.
- The backup is encrypted, and on devices with a screen lock it is encrypted with a key tied to that lock.
- Whether and when a backup is created is decided by the system, which applies its own size and frequency limits. With a large number of photographs the backup may not cover all the data, so it should not be relied upon as a dependable safeguard; the export in §5.6 serves that purpose.
- The mechanism can be turned off in system settings (Backup / Google One), either globally or for the Application alone, and an existing backup can be deleted from the Google account.
5.6. Export, reports, graphics and sharing
- The Application can save data to a file: a backup (JSON), reports and printouts (PDF), a graphic for social media from a session or a competition and a firearm report from a firearm card (a PNG image, or JPEG when it contains a photograph), and — from the target scan screen — a scan diagnostics file (JSON: shot-detection data and the versions of the Application, browser and system, with no photograph). Every save is started by the User only.
- Backups, PDF printouts and diagnostics go to the system share sheet, where the User chooses the destination (cloud drive, e-mail, messenger, social network, cable). A graphic can be handed over the same way or saved with the "Save image" button in the "pointMoA" album in the phone's storage — it then appears in the device gallery; if saving fails, the file goes to the share sheet. Before being handed over, the file is created in the Application's cache (§5.7).
- From the moment a destination is chosen, the data is governed by the privacy policy of the service the User selected. The Controller has no influence over this.
- A social media graphic contains only what the User ticks in its composer: a photograph or drawing of the target, results and charts, firearm, ammunition and optic, a custom title and — switchable off with separate toggles — the date and the location. A firearm report contains a photograph of the firearm and the modifications and firearm data the User selects (e.g. calibre, barrel, optic, round count). The user name from Settings is placed on none of these graphics. The Application publishes nothing by itself and signs in to no social network — it hands the finished file over solely by the route described in point 2.
- The backup file contains all data from the database, photographs included, and is not encrypted. It is worth treating like any document holding personal data. It does not contain the settings kept in local storage (§5.2), including the user name and the latitude.
- Target printouts (PDF) carry no user name. The Zeroing sheet shows the selected set-up in its header (firearm, calibre, optic, ammunition and zero). A QR code appears only on the dry-fire aim-ring target and holds only the sheet geometry and a random copy identifier.
- The Application has no Google Drive integration or any other cloud integration — it signs in to no account.
5.7. How to delete Application data
- Individual entries — deleted in the Application, in the module where they were created.
- All data at once, from within the Application — Settings → Clear data; requires typing a confirmation word. This clears the whole database (photographs, dry-fire training, ranges, goals, drafts and profiles included) together with the settings and the user name; only the chosen language is kept. It does not remove copies of files previously handed over from the Application, which remain in its cache (point 3 or 4 removes them), graphics saved in the "pointMoA" album (removed in the gallery or by point 4), or the camera permission (withdrawn in the system settings).
- All data at once, from the system — System settings → Apps → pointMoA → Storage → Clear data (cache included).
- Uninstalling the Application removes its directory together with the whole database and cache, as well as the "pointMoA" album with the saved graphics.
- Deleting data from the device does not delete the Google backup — that is removed separately, from the Google account (§5.5(5)) — nor any files the User exported or shared earlier.
- The operations in points 1–4 are irreversible: without a prior export the data cannot be recovered.
5.8. Google Play as distributor
- The Application is distributed through Google Play. Downloading, installing and updating happen within Google's service, which processes data arising from this as a separate controller, under its own privacy policy.
- Google Play services may — independently of the Application and outside its control — collect diagnostic data, including crash reports. In the Play Console the Controller sees only aggregated, statistical summaries that cannot be linked to an individual.
- The Application contains no advertising and never will. In-app purchases are described in §5.9.
5.9. Purchasing Pro
⚠️ This section describes a future state. At the time of publication the Application is entirely free and contains no in-app purchases. The rules below take effect only with the version of the Application that introduces an in-app purchase ("Pro"); earlier versions remain free without limitations. The type of purchase, the price and the terms will be stated by the Application and the Store before purchase. The section appears here in advance so that the change of model does not surprise the User.
- The seller towards the User is Google. Payment takes place entirely within Google Play, on its terms and under its privacy policy.
- The Controller receives no payment data — no card number, no billing address, no identity of the buyer. In the Play Console the Controller sees aggregated sales and settlement reports and the order numbers needed to handle a refund, from which no individual can be identified.
- 🔴 A purchase is the only Application function that contacts the network. The Application asks Google Play about the purchase state in order to know whether to unlock Pro features. The request goes to Google only and carries no data from the app's database — no log entries, no photographs, no firearm profiles.
- Purchase state is tied to the User's Google account on the Store's side, which is how Pro returns after changing phones. That link is made by Google, not by the Application.
- Limit and trial counters run on the device only and are never sent anywhere. Clearing the Application's data resets them — the Controller has no way to restore them.
- A purchase creates no account in the Application and does not change the principle in §5.1: the Controller still receives no User data.
6. Recipients of data
- Vercel Inc. (Service) — provider of hosting and Vercel Web Analytics, processing data within the scopes described in §3.2–3.3.
- E-mail provider — handling correspondence sent to the contact address, under a data processing agreement concluded with that provider. Correspondence is stored in Google Workspace.
- Google — as distributor of the Application (§5.8), seller of Pro (§5.9) and provider of Android's system backup (§5.5), in each case on its own terms.
- The data described in §5.2 has no recipients — it does not leave the device.
- Data may be transferred to third countries (outside the European Economic Area) in connection with the use of international providers' infrastructure. Such transfers take place on the basis of mechanisms provided for in Chapter V GDPR, in particular standard contractual clauses or an adequacy decision.
7. Rights of data subjects
In relation to data actually processed by the Controller — that is, the data in sections 3–4 and the order numbers referred to in §5.9(2) — Users have the right to:
- access their data and obtain a copy (Article 15 GDPR),
- rectify their data (Article 16 GDPR),
- erase their data (Article 17 GDPR),
- restrict processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on legitimate interest (Article 21 GDPR),
- lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
To exercise these rights: kontakt@pointmoa.eu.
In relation to the data in §5.2, Users exercise these rights directly and themselves: viewing and correcting in the Application, portability through export to a file (§5.6), erasure as described in §5.7. The Controller has no access to this data and therefore cannot perform these actions on the User's behalf.
8. Voluntary nature of providing data
Providing data is entirely voluntary. Not providing an e-mail address only makes it impossible to reply to a message. Data entered into the Application is voluntary in full — the Application works even if the User fills in nothing beyond the calculation fields.
9. Security
- The Service is delivered exclusively over an encrypted connection (HTTPS).
- Application data is protected by the Android sandbox: the app directory is not accessible to other applications, nor to the device user without elevated privileges. On devices with a screen lock enabled, storage is additionally encrypted by the system.
- The Application adds no encryption or password of its own to the database. Whoever has access to an unlocked phone has access to the log. A screen lock is recommended.
- In relation to the data the Controller actually holds (sections 3–4), the technical and organisational measures applied are appropriate to the risk within the meaning of Article 32 GDPR, in particular: minimisation — the Service operates no accounts or forms and collects only what is described in §3; restriction of access to a single person; two-factor authentication on administrative accounts (hosting, domain, e-mail, Google Play Console); encryption in transit; a data processing agreement concluded with the e-mail provider; and deletion of data within the periods set out in §3.
10. Children's data
Neither the Service nor the Application is directed at children. Shooting subject matter carries an age restriction in Google Play, and the Application does not take part in the "Designed for Families" programme. The Application collects no data at all (§5.1), and the Controller does not knowingly collect data of persons under 16 years of age through the Service or correspondence either.
11. Changes to this Policy
This Policy may change, in particular in connection with the release of new Modules, the development of the Application, or changes in law. Amended text is published in the Service together with the date of update and the version. Any change to the scope of data processed by the Application is introduced together with an update of the "Data safety" declaration in Google Play.
This Policy was drawn up in Polish. In the event of any discrepancy between language versions, the Polish version prevails.