Tolar

Android
si.vstaric.tolar

Privacy Policy — Tolar

Version: 2.0 Effective date: 26 August 2026 Application: Tolar — Android package si.vstaric.tolar

1. Controller

The controller of the personal data described in this policy, within the meaning of Article 4(7) of Regulation (EU) 2016/679 ("GDPR"), is:

N1, Programerske storitve, Vid Starič s.p. Registered office: Ob žici 7, 1000 Ljubljana, Slovenia Registration number (matična številka): 7208871000 Tax number (davčna številka): 62098195 Email: info@vstaric.si

The Provider has not appointed a Data Protection Officer, being under no obligation to do so under Article 37 GDPR. Data protection enquiries should be addressed to the email address above.

2. Summary

Tolar is a local-first Android application that stores loyalty cards, card photographs and a shopping list on the User's device. It requires no registration, contains no advertising, and includes no functionality that tracks users across other applications or websites. The Provider does not sell personal data.

Two features are optional and are disabled by default. They are independent of one another; enabling one does not enable the other.

Sync and Sharing (section 8). Loyalty cards and shopping list entries are encrypted end to end on the device and transmitted to the Provider's own server for backup, restoration on another device, and sharing with recipients chosen by the User. The server holds only ciphertext that it cannot decrypt (zero-knowledge). This data is not disclosed to any third party.

Diagnostics (section 9). Crash reports, usage counts, screen names, synchronisation timings and the shop names appearing on the User's cards are transmitted to Google. This is the only feature that discloses data to a third party. It is not end-to-end encrypted. Apart from the shop names described in section 9, it does not include card numbers, notes, photographs or list entries.

With both features disabled — the state of a fresh installation — the Application transmits nothing. This includes transmission to Google: the Application ships Google's push-messaging component, because it is the mechanism by which the Sync Service is informed of changes, but that component is disabled until Sync and Sharing is enabled. Enabling Sync and Sharing registers an installation identifier with Google, which identifies the installation rather than the User and carries no User Content. Section 4 describes this in full.

3. Data stored by the Application

All data listed below is created by the User and stored on the User's device in the Application's private storage. Unless Sync and Sharing is enabled (section 8), it is not transmitted to the Provider or to any other party. It is not transmitted to Google, subject to one exception: where Diagnostics is enabled (section 9), the shop name derived from each card title is transmitted to Google for the purpose described in that section. No other item in the table below is transmitted there in any circumstances.

DataExamplesStorage location
Loyalty card detailsCard title, optional notes, barcode or QR value and formatOn-device database (application-private)
Card photographsFront and back photographs captured by the UserOn-device file storage (application-private)
Shopping and to-do listSection names, item names, add, check-off and clear history, timestampsOn-device database (application-private)
Application settingsDisplay preferences, for example grid layoutOn-device

The Application does not collect names, email addresses, telephone numbers, contacts, location data or advertising identifiers. The Application is technically incapable of reading an advertising identifier: the permissions that would permit this are removed from the Application's manifest.

Usage analytics, crash logs and the shop names appearing on the User's cards are collected only while Diagnostics is enabled (section 9). A device installation identifier is registered with Google only once Sync and Sharing (section 4) or Diagnostics is enabled.

4. Legal bases for processing

Where the Application processes personal data within the meaning of the GDPR, the Provider relies on the following legal bases.

ProcessingLegal basis
Operation of the Sync Service: storage and transmission of encrypted envelopes, public keys, routing identifiers and push registration dataArticle 6(1)(b) GDPR — performance of a contract requested by the data subject
Diagnostics: crash reports, usage counts, screen names, performance timings, device details, shop namesArticle 6(1)(a) GDPR — consent, given by enabling the feature and withdrawable at any time by disabling it
Registration of an installation identifier and push token with Google, following activation of Sync and SharingArticle 6(1)(b) GDPR — necessary to deliver change notifications forming part of the requested service
Security, integrity and abuse prevention in respect of the Provider's serverArticle 6(1)(f) GDPR — legitimate interests in maintaining a secure and available service
Response to a lawful order properly addressed to the ProviderArticle 6(1)(c) GDPR — compliance with a legal obligation

Data stored solely on the User's device is not processed by the Provider and no legal basis is engaged in respect of it.

Withdrawal of consent under Article 6(1)(a) does not affect the lawfulness of processing carried out before withdrawal.

5. Camera

The Application uses the camera for two purposes, both performed entirely on the device:

  1. Scanning barcodes and QR codes in order to read a card's code.
  2. Capturing photographs of a card where it bears no scannable code, or for visual reference.

Barcode detection is performed on-device using a bundled, offline recognition model. Camera frames are processed locally and do not leave the device; they are neither stored nor uploaded. A photograph saved by the User leaves the device only where Sync and Sharing is enabled (section 8), and then only in end-to-end encrypted form. It is not transmitted to Google or to any other party.

The camera permission may be declined or revoked at any time in Android settings. The remainder of the Application continues to function in respect of cards already saved.

6. Network access and identifiers

6.1. Default state

With Sync and Sharing and Diagnostics both disabled — the state of a fresh installation — the Application transmits nothing, to the Provider or to Google. The Application contains no advertising SDK and no functionality that tracks the User across other applications or websites.

This includes Google's Firebase push-messaging component, which the Application ships because it is the mechanism by which the Sync Service is informed of changes. That component would ordinarily initialise on application start and register the device with Google immediately. The Application disables it in the manifest, before any of the Application's own code executes. On a device where Sync and Sharing is never enabled, it therefore registers nothing and does not contact Google.

6.2. Effect of enabling Sync and Sharing

Push delivery requires that the device be addressable. When the User enables Sync and Sharing (section 8), the Application enables that component, which registers two items with Google:

6.3. Effect of disabling Sync and Sharing

The Application disables the component and additionally requests that Google delete the push token it issued, with the result that nothing can be delivered to the device. The Application's own record of the registration is erased at the same time.

The installation identifier is retained, because Diagnostics uses the same identifier and clearing it here would silently reset that separate choice.

One consequence cannot be effected from within the Application: the Provider's server retains the row recorded for the device until a deletion mechanism is implemented. That row holds the token whose cancellation has just been requested, and can therefore no longer be used to reach the device. This row is removed where the User deletes the account under section 11, which is a distinct operation from disabling Sync and Sharing.

6.4. Relationship between the two features

Sync and Sharing and Diagnostics are independent settings; enabling one does not enable the other. Diagnostics, if enabled, also requires an installation identifier, that being the mechanism by which Google associates a crash report with an installation. The installation identifier is therefore registered by whichever feature the User enables first. The push token is associated with Sync and Sharing alone. With both features disabled, neither exists.

6.5. The installation identifier

6.6. Further disclosure

The build includes Google's on-device ML Kit barcode library. The installation package declares the INTERNET permission, added automatically by that library and by the Firebase components. Barcode recognition uses a bundled model and functions fully offline, including in flight mode.

Where Sync and Sharing is enabled, the Application connects to the Provider's synchronisation server to upload and download end-to-end encrypted cards and shopping list entries. All such traffic is encrypted in transit (HTTPS/TLS) and additionally end-to-end encrypted, such that neither the network nor the Provider's server can read the contents.

Where Diagnostics is enabled, the Application transmits crash and performance reports to Google over HTTPS.

7. Accounts and cloud storage

The Application does not use accounts, email addresses or passwords. Identity is exclusively cryptographic: on enabling the Sync Service, the device generates a key pair and a random identifier. The Recovery Phrase, which is not a password held by the Provider, is the sole means of restoring data on a new device.

With the Sync Service disabled, no server is involved. With the Sync Service enabled, data is stored on the Provider's own self-hosted server, exclusively as encrypted blobs that the server cannot decrypt (zero-knowledge). The encryption keys do not leave the User's devices and those of the recipients with whom the User has chosen to share. The Provider does not use a third-party cloud provider to process User Content. User Content is not sold and is not disclosed to any third party.

Google receives no User Content by way of the Sync Service, irrespective of the Diagnostics setting. The single item of User Content transmitted by Diagnostics — the shop name derived from a card title — is described in section 9 and does not travel by this route.

8. Sync and Sharing (optional, opt-in)

The Sync Service is optional and disabled by default. It is enabled in the Application's synchronisation settings. Until it is enabled, no data leaves the device.

Where enabled:

Data transmitted. Loyalty cards (title, notes, barcode value and format, and any card photographs) and shopping and to-do list entries. These are the only categories transmitted, and only while the feature is enabled.

End-to-end and zero-knowledge encryption. All such data is encrypted on the device before transmission. The Provider's server stores only ciphertext together with the public keys and identifiers required for routing. The Provider cannot read User Content.

Absence of accounts. Identity is a device-generated key pair. The Recovery Phrase is the sole key. No password reset exists. Where the User loses the Recovery Phrase and all devices, the encrypted data cannot be recovered, by the Provider or by any other person.

Self-hosting. Encrypted data is processed on the Provider's own server rather than a third-party cloud service and is not disclosed to any third party.

Sharing. The User may connect with chosen recipients and share cards and lists with them. Sharing is not selective: every connected recipient receives all of the User's cards, including barcode values, and all of the User's lists. A recipient may themselves connect further recipients, who then receive the same data; the User is not asked to approve them, and any connected recipient may likewise remove any other. A connection may be revoked, which prevents further sharing and takes effect for every recipient. Revocation does not recall data already delivered to and decrypted on a recipient's device.

Disabling. Disabling the Sync Service stops synchronisation. User Content remains on the device. See section 6.3 for the effect on push registration, and section 11 for account deletion.

9. Diagnostics (optional, opt-in)

The Application includes an optional Diagnostics setting at Settings → Diagnostics → "Share diagnostics", disabled by default. Until it is enabled, nothing described in this section is collected or transmitted.

This is the only component of the Application that discloses data to a third party. Where enabled, crash and usage reports are transmitted to Google using Firebase Crashlytics, Google Analytics for Firebase and Firebase Performance Monitoring. Unlike synchronised User Content, these reports are not end-to-end encrypted. They are encrypted in transit, but are readable by Google and by the Provider within its Firebase console.

9.1. Data transmitted while enabled

Crash reports. The location in the Provider's code at which the Application failed (class, method, file and line for each frame), the error type and, for a crash that terminates the Application, the technical error message. Those messages are authored so as to be incapable of containing User Content: they identify fields, counts and status codes, and never card titles, notes, barcode values or item names. For errors that the Application catches and recovers from, the message is removed in its entirety before transmission.

Usage counts. Three counters: that a card was added, and whether it carried a barcode or a photograph; the number of list items added in a single operation; and whether synchronisation was enabled or disabled. Google's standard events, such as application opened and application updated, are additionally recorded.

Screen names. A name drawn from a fixed list authored by the Provider (cards, card_detail, settings and approximately eight others). No indication of which card was opened is recorded.

Shop names appearing on the User's cards. For each card in the User's wallet, the Application transmits either the name of a retailer it already recognises — one of those whose logo is bundled with the Application — or, where the retailer is not recognised, the shop name derived from the card title. This is the only item of the User's own content transmitted by Diagnostics. Its sole purpose is to identify retailers missing from the bundled logo list, that list being the source from which the Application draws the logo displayed on each card.

Before transmission, the title is reduced: all digits are removed, so that a membership number cannot be transmitted with it; all text after the first three words is discarded; and a title consisting solely of digits is not transmitted at all. The value is transmitted once per card rather than on each viewing, and therefore does not indicate the frequency with which the User visits any retailer.

The limits of this reduction should be noted. The title is text authored by the User. Where the User has titled a card with something other than a retailer name — a personal name, for example — that value is what is transmitted. A User who prefers that no such data be transmitted should leave Diagnostics disabled, or disable it. It is disabled unless enabled by the User.

Performance timings. Application start duration, and the duration of synchronisation requests together with their result codes and payload sizes.

Device and application details. Device model, operating system version, available memory and storage, application version, and the installation identifier described in section 6.

9.2. Data not transmitted

User Content, other than the shop names described above. No card or membership numbers, barcode or QR values, notes, card photographs, shopping list items, section names or display names. This is a structural property rather than an undertaking: the only text an event may carry is a name drawn from a list authored by the Provider or a shop name reduced as described above, and the Application would fail to compile were any other value attached to an event.

The User's sync identity. The User's cryptographic account identifier is never attached to a report. A crash report therefore cannot be associated with data held by the Sync Service.

Network addresses. Synchronisation timings are reported against a placeholder address and a generic description of the request ("fetch a card blob"), never the actual address. No identifiers are transmitted, and the address of a self-hosted synchronisation server is not transmitted.

Advertising identifiers. None are transmitted, and the Application is incapable of reading one.

None of the data described in this section is used for advertising, marketing or profiling, and none of it is sold.

9.3. Disabling

Disabling Diagnostics stops all three components immediately and discards reports not yet uploaded. Reports already received by Google may be deleted on request; see section 11.

10. Recipients, processors and international transfers

10.1. Recipients

RecipientDataRoleApplies when
Hetzner Online GmbH, GermanyEncrypted envelopes, public keys, routing identifiers, push registration rowsProcessor (hosting) — content unreadable to the hostSync and Sharing enabled
Google Ireland Limited / Google LLC (Firebase Cloud Messaging)Installation identifier, push registration tokenProcessorSync and Sharing enabled
Google Ireland Limited / Google LLC (Crashlytics, Analytics for Firebase, Performance Monitoring)Data described in section 9.1ProcessorDiagnostics enabled

The Provider does not disclose data to any other recipient, save where required to do so by a lawful order properly addressed to it. In the case of synchronised data, compliance with such an order would yield ciphertext that the Provider cannot decrypt.

10.2. Place of processing

With Sync and Sharing disabled, data is processed solely on the User's own device and does not leave it.

With Sync and Sharing enabled, encrypted envelopes are stored on a server located in Germany, within the European Economic Area. No adequacy decision or transfer mechanism is required, and the contents are in any event unreadable to the host.

With Diagnostics enabled, crash and performance reports are transmitted to Google Firebase and may be processed outside the EEA, including in the United States. Such transfers rely on the Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, together with the supplementary measures published by Google in respect of Firebase. This is the only component of the Application that transmits data outside the EEA, and it is disabled unless enabled by the User.

11. Retention and deletion

11.1. Retention periods

DataRetention
Data on the deviceUntil deleted by the User, or until the Application's data is cleared or the Application uninstalled
Encrypted envelopes held by the Sync ServiceUntil deleted by the User under section 11.3, subject to the exceptions in section 11.4
Push registration rowsUntil account deletion under section 11.3
Diagnostics data held by GoogleIn accordance with Google's Firebase retention periods for the products concerned, and in any event no longer than the maximum retention period configured by the Provider in its Firebase project

11.2. Means of deletion available to the User

11.3. Account deletion

Settings → Delete account and data is permanent and requires no communication with the Provider. The Application first requests that the server erase the account, and then wipes the device. The operation removes:

11.4. Limits of account deletion

Three consequences fall outside the reach of the deletion operation and are stated here rather than left to be discovered.

Recipients retain their copies. Data shared by the User was decrypted on the recipient's device and is held by that recipient. No deletion performed by the Provider extends to another person's device.

A shared list or roster remains on the server. It belongs also to the recipients with whom it was shared, and its removal would remove their copy. It continues to carry an unreadable trace of the deleted account, but the account itself no longer exists: nothing can open it and nothing can be delivered to it.

Uploaded photograph files remain on the server. They are stored by content rather than by owner, with the consequence that an identical file may belong to more than one account; deleting one User's copy could remove another's. What remains is an unreadable, unreferenced blob to which no account points and which no person, including the Provider, can decrypt.

11.5. Failure of the deletion operation

Where the server cannot be reached at the time of deletion, nothing is deleted and the Application reports this rather than completing partially. The operation may simply be attempted again. The User may alternatively elect to wipe the device alone in that situation; doing so destroys the key that proves ownership of the account, with the consequence that the server-side copy could thereafter be removed only by contacting info@vstaric.si.

12. Backups and device transfer

The loyalty card database and card photographs are excluded from Android's automatic cloud backup (Google Drive) and from device-to-device transfer. This exclusion is deliberate: these items may contain sensitive barcode values and card images, and the Application retains them on the device rather than permitting the platform to copy them elsewhere.

The practical consequence, with Sync and Sharing disabled, is that saved cards and photographs are not carried over on uninstallation or on transfer to a new device. The Sync Service (section 8) is the supported means of backing up and transferring data between the User's own devices, in end-to-end encrypted form.

13. Rights of data subjects

Under the GDPR, and under comparable legislation elsewhere, the User has the right of access to personal data held about them, and the rights to rectification, erasure, restriction of processing, objection to processing, and data portability, together with the right to withdraw consent where processing is based upon it.

In respect of most of the data held by the Application, these rights may be exercised by the User directly, and more rapidly than the Provider could act:

Where the User prefers to make a request to the Provider, or where a right cannot be exercised within the Application, requests should be addressed to info@vstaric.si. The Provider will respond within one month of receipt, as required by Article 12(3) GDPR. The Provider will not require the User to create an account in order to make a request.

A limitation is stated here rather than left to be discovered: in respect of synchronised data, the Provider is able to erase but not to produce. Data held on the server is encrypted with keys held only by the User's devices. A request for a copy of the data held would return ciphertext that the Provider is itself unable to read. The intelligible copy is the one on the User's device.

A User who considers that their personal data has been handled improperly has the right to lodge a complaint with a supervisory authority. In the Republic of Slovenia, this is the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si.

14. Automated decision-making

The Application does not carry out automated decision-making producing legal effects or similarly significantly affecting the User, within the meaning of Article 22 GDPR, and does not carry out profiling.

15. California residents

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, confers on California residents the right to know what personal information is collected and how it is used, the right to delete it, the right to correct it, the right to opt out of its sale or sharing, and the right not to be subjected to discrimination for exercising any of these rights.

The Provider does not sell or share personal information within the meaning of those statutes. The Application contains no advertising SDK, transmits nothing to data brokers, engages in no cross-context behavioural advertising, and includes no functionality that tracks the User across other applications or websites. No "Do Not Sell or Share My Personal Information" mechanism is therefore offered, there being nothing that such a mechanism would disable.

The categories of personal information collected are those set out in section 3 (data stored on the device) and section 9.1 (data transmitted by Diagnostics). With Sync and Sharing and Diagnostics both disabled, no personal information is collected.

Requests may be addressed to info@vstaric.si. The Provider will not require the creation of an account in order to make a request.

16. Children

The Application does not knowingly collect personal information from any person, including children. It requests no name, email address, telephone number or age, contains no advertising, and does not track any person across other applications or websites.

With Sync and Sharing enabled, the only content leaving the device is end-to-end encrypted. With Diagnostics enabled, the reports transmitted to Google describe the behaviour of the Application rather than the person using it. Both features are enabled only by an explicit act of the User.

The Application is a barcode utility. It is not directed at children and its target audience is {{PLAY_TARGET_AUDIENCE_AGE_BAND}}.

17. Security and breach notification

Where a personal data breach affects the User's personal data and is likely to result in a risk to the rights and freedoms of natural persons, the Provider will notify the supervisory authority within 72 hours of becoming aware of it, and will notify affected Users directly where the risk is high, as required by Articles 33 and 34 GDPR.

The content of any such notification is shaped by the design of the Application, which it is useful to state in advance. A breach of the Provider's server exposes encrypted envelopes and not their contents. An attacker in possession of a complete copy of the database obtains ciphertext, the public keys used to verify signatures, and the timing of writes. The attacker does not obtain cards, lists, notes or photographs, the keys to which exist only on the User's devices and have never been transmitted to the Provider.

The exception is the User's device. Where a device is lost while unlocked and unencrypted, none of the foregoing protects the data upon it. The Recovery Phrase in particular is of the same value to an attacker as it is to the User.

18. Governing law

This policy, and any dispute concerning the handling of personal data under it, is governed by the law of the Republic of Slovenia and by the applicable law of the European Union, without prejudice to any mandatory protection available to the User under the law of the User's country of residence.

Nothing in this section limits the User's right to lodge a complaint with a supervisory authority or to bring proceedings before a court competent under the law of the User's place of residence.

19. Amendments to this policy

Where the data practices of the Application change, the Provider will update this policy and revise the effective date at the head of it. The version in force is that published at tolar.vstaric.si/privacy.html.

Notification. Material changes introducing any new transmission of data will be announced before they take effect. Where the User uses the Sync Service, the Application is able to display an in-application notice: such notices travel over the synchronisation connection already in use, and therefore reach the User without the Application contacting the Provider for any additional purpose. With Sync and Sharing disabled, the Application continues to transmit nothing (section 6.1). Where the User does not use the Sync Service, the published policy page and the Google Play listing are the channels through which changes are announced.

Acceptance. The Provider does not require acceptance to be indicated and maintains no record of which Users have read this policy; such a record would itself constitute information about the User that the Provider does not presently hold and does not wish to begin holding. Continued use of the Application after publication of a change constitutes acceptance of it. A User who does not accept a change may cease using the Application and delete their data at any time (section 11). No data stored by the User is conditioned upon acceptance of a policy.

The Provider is unable to require Google Play to obtain the User's renewed acceptance of this policy, installation and updating of an application through that platform being an agreement between the User and Google rather than between the User and the Provider. The page identified above is accordingly the authoritative record of the provisions in force and of the date from which they apply.

20. Contact

Enquiries concerning this policy or the privacy practices of the Application: info@vstaric.si

This policy describes Tolar (Android si.vstaric.tolar), including the optional, opt-in Sync and Sharing and Diagnostics features.