Skip to main content
revdev

Legal

Privacy policy

This policy applies to Private Workout Log (package com.lukk.workoutlog) and the additional mobile applications listed in section 2. In short: our apps run entirely on your device and do not collect, store, or transmit any personal data.

Effective date: 2 July 2020

1. Who we are

The applications covered by this policy are developed and published by:

  • Łukasz Sarna — sole developer, operator, and data controller. Based in Warsaw, Poland. Contact: luksarna@gmail.com.
  • RevDev — trading name of Łukasz Sarna for the consultancy and mobile-app publishing activity. Contact: kontakt@revdev.tech.

For the purposes of the EU General Data Protection Regulation (GDPR), Łukasz Sarna acts as the data controller. Because the apps do not process personal data, no records of processing activities are maintained, and no Data Protection Officer has been appointed (no obligation under Article 37 GDPR).

2. Apps covered by this policy

The following mobile applications, published by Łukasz Sarna under the RevDev trading name, are covered by this privacy policy:

  • Private Workout Log Google Play package com.lukk.workoutlog — participates in the Google Play Families programme and is directed to children.

Each Play Store listing for an app covered here links to this exact URL as its privacy policy. New applications will be added to the list above before their Play Store listing goes live; this policy never covers an app whose package ID is not explicitly named here.

3. What data we collect

None. Our applications are designed to be fully offline and self-contained. We do not collect, store, share, or transmit:

  • Personal information (name, email address, phone number, postal address).
  • Account credentials or sign-in identifiers (the apps require no account at all).
  • Device identifiers (Android Advertising ID, IMEI, MAC address, serial number).
  • Location data (precise or approximate).
  • Contacts, calendar, messages, photos, or files outside the app’s sandbox.
  • Microphone, camera, or sensor data.
  • Usage analytics, crash reports, performance metrics, screen views, or behavioural events.
  • Cookies, web beacons, or similar tracking technologies.

No personal data leaves your device through our apps. We do not operate backend servers that receive user data. If a future app under this policy needs to process sensor input (for example a camera feature for on-device processing), the policy and the Play Store Data Safety form will be updated before that app ships.

4. Legal basis for processing

Article 6(1) GDPR requires a legal basis for any processing of personal data. Because the apps do not process personal data, no legal basis is invoked and none is required. If this changes, the policy will be updated to identify the applicable legal basis under Article 6(1) and, where relevant, Article 9(2) GDPR before the change takes effect.

5. Recipients and third-party services

We do not integrate third-party advertising networks, analytics SDKs, crash-reporting services, attribution services, social-network SDKs, or any other third-party libraries that collect or transmit user data. The apps do not contain advertising of any kind.

Recipients of personal data: none. We do not share, sell, rent, or otherwise disclose personal data to any third party because we do not have any personal data to disclose.

The Google Play Store itself may collect data when you download or update the app (for example, installation events and aggregated crash statistics from the Android operating system). That processing is governed by Google’s own privacy policy and is outside our control. We do not receive personally identifiable information from those reports.

6. Android permissions

If an app requests an Android permission (for example storage), it is used exclusively for the feature you explicitly invoke, and the resulting data stays on your device. The required permissions for each app are listed on its Google Play Store listing under “App permissions”.

You can review or revoke any granted permission at any time via the Android system settings: Settings → Apps → [App name] → Permissions.

7. Data storage and retention

Any data the app creates (for example preferences, saved progress, user-created content) is stored locally on your device, inside the app’s private sandbox or in folders you explicitly choose. Uninstalling the app removes this data, except for files you exported to shared device storage.

Retention period: not applicable. Because no personal data is collected or transmitted, there is nothing for us to back up, retain, or delete on our side. Local data on your device is under your exclusive control.

8. International transfers

None. Because we do not collect or transmit personal data, no personal data is transferred outside the European Economic Area or to any third country.

9. Children’s privacy

At least one of the applications covered by this policy is directed to children — see the per-app designation in section 2. For those apps we comply with the U.S. Children’s Online Privacy Protection Act (COPPA, 16 CFR Part 312), the Google Play Families Policy, and Article 8 GDPR on the processing of children’s personal data.

COPPA operator disclosure (16 CFR § 312.4(d)):

  • Operator: Łukasz Sarna (trading as RevDev).
  • Address: Warsaw, Poland. Written correspondence should be sent by email to the addresses below.
  • Email: kontakt@revdev.tech or luksarna@gmail.com.

Our child-directed apps:

  • Do not collect any personal information from children (or any other user).
  • Do not require sign-in, registration, or any account.
  • Do not contain third-party advertising, personalised or otherwise.
  • Do not contain in-app purchases unless explicitly disclosed on the Play Store listing for that specific app.
  • Do not include social features, chat, or user-to-user communication.
  • Do not link to external websites or services without a clear, age-appropriate gate.
  • Do not use persistent identifiers for behavioural advertising or cross-app tracking.

Because we do not collect personal information from children, no verifiable parental consent mechanism (per 16 CFR § 312.5) is required. Parents and legal guardians nevertheless retain every COPPA right: to review what (if any) information has been collected, to refuse further collection, and to have any information deleted. Contact us at the addresses above and we will respond within one month (Article 12(3) GDPR) and as soon as reasonably possible for COPPA requests.

GDPR Article 8 — age threshold for valid consent: Article 8(1) GDPR sets the default at 16 and allows EU Member States to lower it to as low as 13. Poland, under Article 5 of the Personal Data Protection Act of 10 May 2018, sets the threshold at 16. Other Member States vary between 13 and 16. Because our apps do not collect any personal data from anyone, no consent is sought and the threshold is moot for our processing — it is stated here for completeness.

10. California residents (CCPA / CPRA)

This section addresses the California Consumer Privacy Act and the California Privacy Rights Act. It applies to California residents using our apps.

Categories of personal information collected, sold, or shared: none of the statutory categories apply. We do not collect, sell, or share any of the following:

  • Identifiers (name, alias, postal address, IP address, email, account name, device ID, etc.).
  • Customer records (the Cal. Civ. Code § 1798.80(e) category).
  • Characteristics of protected classifications.
  • Commercial information.
  • Biometric information.
  • Internet or other electronic network activity information.
  • Geolocation data.
  • Audio, electronic, visual, thermal, olfactory, or similar information.
  • Professional, employment, or education information.
  • Inferences drawn from any of the above.
  • Sensitive personal information as defined by the CPRA.

Do Not Sell or Share My Personal Information: not applicable. We do not sell or share personal information, including for cross-context behavioural advertising. No “Do Not Sell or Share” link is provided because there is nothing for the opt-out to act on.

Consumer rights: California residents have the right to know what personal information is collected, to delete it, to correct it, to opt out of its sale or share, to limit use of sensitive personal information, and to non-discrimination for exercising these rights. Because we hold no personal information about you, an access, deletion, or correction request has nothing to act on; we will respond confirming that within 45 days of receipt as required by Cal. Civ. Code § 1798.130(a)(2).

11. Your rights and supervisory authorities

Under the GDPR, UK GDPR, and similar laws you have the right to access, correct, delete, or restrict the processing of your personal data, to object to processing, to withdraw consent at any time, and to data portability. Because our apps do not collect or store personal data on our side, we have no records to access, correct, or delete. Local data on your device is under your exclusive control and can be removed by uninstalling the app.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is:

  • Prezes Urzędu Ochrony Danych Osobowych (UODO) — President of the Personal Data Protection Office.
  • ul. Stawki 2, 00-193 Warszawa, Poland.
  • Web: uodo.gov.pl (opens in new tab).

If you live in another EEA Member State, you may also lodge a complaint with the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement (Article 77 GDPR). A directory is maintained by the European Data Protection Board at edpb.europa.eu (opens in new tab).

12. Security

Because no personal data is collected or transmitted, the attack surface for data loss is limited to the device itself. Release builds of our Android apps are minified and shrunk via R8 / ProGuard, dependencies are kept up to date, and we follow standard Android development practices. Device-level security (screen lock, operating-system updates, encryption) is the responsibility of the device owner.

13. Website that hosts this policy

This privacy policy lives at revdev.tech/privacy-policy/, a static website hosted on lh.pl shared hosting (Apache server) in Poland. The website itself does not set cookies, load analytics, embed third-party scripts, run a contact form, or call any external API. Visiting the page does not create an account or store anything in your browser beyond the standard browser cache.

Like every web host, lh.pl’s Apache server records standard access-log entries for incoming requests. A typical entry contains your IP address, the user agent of your browser, the URL you requested, the HTTP status code, and a timestamp. Those logs are generated and retained by the hosting provider for technical operation, debugging, and abuse prevention. We do not pull, export, or analyse those logs. Their retention period and processing are governed by the hosting provider’s own privacy notice at lh.pl (opens in new tab).

14. Changes to this policy

We may update this policy from time to time, for example to reflect a new feature in one of the apps or a change in applicable law. Material changes will be announced by updating the “Effective date” at the top of this page and, where appropriate, with a notice inside the affected app on next launch. The current version of this policy is always available at https://revdev.tech/privacy-policy/.

15. Contact

Questions about this policy, requests under data-protection law, COPPA, CCPA / CPRA, or any privacy concern can be sent to either address below. We respond within one month of receipt, in line with Article 12(3) GDPR. That period may be extended by two further months where necessary, taking into account the complexity and number of requests; we will inform you within one month if an extension is needed and the reason for it.