Privacy Policy
Effective date: 2026-02-06 · Last updated: 2026-02-06
This Privacy Policy explains how Rhinitips (the “App”) collects, uses, shares, and protects personal data when you use the App in the European Union / EEA.
Quick summary (not a substitute for the full policy):
- The App may process precise location (if you grant permission) to show local pollen/air quality information.
- If you create an account, the App stores your email and any account settings you choose to save (e.g., saved locations, optional daily hayfever ratings).
- The App uses third-party service providers (e.g. Supabase, Google, Sanity) to deliver core functionality.
- The App does not use analytics/crash tracking providers at this time.
Medical disclaimer (important)
The App provides pollen and air quality forecasts and related informational content. It is not a medical device and does not provide medical advice.
- No medical advice: Information provided by the App is for general informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment.
- Consult a professional: If you need medical advice or treatment, contact your doctor or other qualified healthcare professional.
- Emergencies: If you think you may have a medical emergency, call your local emergency number immediately.
- Limitation: To the maximum extent permitted by applicable law, the App and its operator disclaim responsibility for decisions you make based on the App’s information.
1. Who is responsible for your data (Controller)
Data Controller: Next Level Development BV
Contact email: privacy@rhinitips.com
If you are contacting us to exercise GDPR rights, please use the contact email above.
2. Scope
This policy applies to:
- The Rhinitips mobile App (iOS/Android) and its in-app features.
- Requests you make to our backend services and third-party APIs when using the App.
This policy does not cover third-party services that you access independently (e.g., if you visit Google’s or Sanity’s websites directly).
3. Personal data we process
3.1 Account data (if you sign up / sign in)
If you create an account through Supabase Authentication, we process:
- Email address
- Authentication data (e.g., hashed password handled by the auth provider, session tokens)
- Profile metadata you choose to provide, such as a username
3.2 Location data
The App can work with location in several ways:
- Device location (precise GPS): If you grant location permission, the App can access your device’s approximate/precise coordinates to provide local forecasts.
- Manually selected location: You can search for a place or select a location on a map.
- Saved locations (if signed in): If you are signed in and choose to save locations, we store: latitude/ longitude, label and place name, country code and postal code (when available), “primary location” flag and timestamps.
If you use the App without an account, your selected location may still be used to fetch forecasts, but it is not stored to your account in our database.
3.3 Optional daily hayfever rating data
If you choose to use symptom-related features, the App may store an optional daily rating (e.g., 1–5) associated with a day key. Because this may relate to your health, it can be considered health-related personal data. You control whether you provide this data.
3.4 Technical and usage data
When you use the App, our service providers (and sometimes we) may process technical data such as IP address and request metadata, and general security logs.
At this time, the App does not implement separate analytics/crash tracking SDKs (such as Sentry, Firebase Analytics, PostHog, Amplitude).
4. How we use your data (purposes)
- Provide core features, including location-based pollen and air quality forecasts
- Create and manage your account (if you sign up)
- Store your preferences and saved items (saved locations, optional ratings)
- Maintain security, prevent fraud/abuse, and troubleshoot problems
- Comply with legal obligations where applicable
5. Legal bases under GDPR
We rely on one or more of: performance of a contract (Art. 6(1)(b)); consent (Art. 6(1)(a)) for location and optional health inputs; legitimate interests (Art. 6(1)(f)) for security; and legal obligation (Art. 6(1)(c)) where applicable.
6. Sharing and recipients (processors)
Service providers: Supabase (auth, database); Google APIs (location, geocoding, pollen/air quality); Sanity (CMS for content).
We may disclose personal data if necessary to comply with law or protect rights and security. We do not sell personal data.
7. International data transfers
Where data is processed outside the EEA, we rely on appropriate safeguards under GDPR (such as Standard Contractual Clauses) and/or other valid transfer mechanisms.
8. Data retention
- Account data: kept while active; deleted or anonymized on account deletion.
- Saved locations and ratings: until you delete them or your account.
- Backups: residual copies may persist for a limited period.
9. Security
We implement reasonable technical and organizational measures to protect personal data. No system can be guaranteed 100% secure.
10. Your rights (EEA)
Subject to GDPR, you have the right to: access, rectify, delete, restrict processing, data portability, object, and withdraw consent.
Contact us: privacy@rhinitips.com to exercise your rights. You may lodge a complaint with your local data protection supervisory authority in the EEA.
11. Children
The App is not intended for children under 16. We do not knowingly collect personal data from children under 16.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and provide notice where appropriate.
13. Contact
Email: privacy@rhinitips.com
Controller: Next Level Development BV