Neologos
Eco

Privacy Policy

Everything that applies to Eco is here. The general part below covers the website and all apps.

Effective from September 28, 2026

This document is translated from the Czech version for your convenience. In case of any discrepancy between language versions, the Czech version is binding.

In short

  • Drives, routes, fines and points stay on your phone and, if enabled, in your iCloud. The operator has no access to them.
  • An account is optional. You only need it for the leaderboard, groups and Premium on several devices.
  • Anonymous usage statistics are collected only with your consent, without location or trip content.
  • For weather, speed limits and navigation your location goes to Apple WeatherKit, Apple Maps and OpenStreetMap, without your identity.
  • You delete the account and its server data yourself in the app: Settings → Account → Delete account.

This summary is for quick orientation. The full text below is what applies.

1

Controller and contact

The controller of personal data processed in connection with the Eco mobile app (the "App") is Vojtěch Landa, a natural person, email: vojtajess@gmail.com (the "Operator", "we" or "us").

The Operator has not appointed a data protection officer because it is not required to do so under Article 37 of Regulation (EU) 2016/679 (the "GDPR"). For any data protection matter, contact us at the email above or through the support chat in the App.

2

Data that stays on your device

During a trip, and while automatic trip detection is on, the App processes GPS location and speed and data from your phone's motion sensors (accelerometer, gyroscope). From this data it calculates the route, score and trip events directly on the device.

Trips, routes, events, statistics and the fines, offences and points you enter are stored only on your device and, if iCloud is enabled, in your private iCloud storage (Apple CloudKit). They are not transferred to the Operator, the Operator has no access to them and is not their controller. The same applies to the car photo you can add in the Garage: the car is cut out of it on your device and the photo is never uploaded to the Operator. iCloud storage is governed by Apple's terms. The same applies to debug logs and reports of misjudged events until you expressly choose to share them.

Trip scoring is an automated evaluation of your driving behaviour. It runs only on your device, is for your information only and has no legal or similarly significant effect on you, so it is not automated decision-making under Article 22 GDPR. Fine estimates and the points log work with offence data that you enter yourself and that stays only on your device. Please enter only your own data.

3

Purposes, scope and legal bases

a) User account (optional). Nickname, profile colour, the name from Sign in with Apple if you share it, and a random Firebase UID. Purpose: creating and managing the account and linking the subscription across devices. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

b) Leaderboard, groups, family sharing and feature voting. Average score, fuel saved and number of trips per week and month; group name, code and members; in a group, after each trip, an entry with nickname, score, distance and whether a significant event occurred, without route or location; for votes, the Firebase UID and time of the vote. Group and leaderboard data are visible to other group members. Legal basis: performance of a contract.

c) Eco Premium subscription. Customer identifier at RevenueCat, the Firebase UID of a signed-in user, purchased product, subscription status and history, and App Store country. Payment details are processed exclusively by Apple; the Operator never sees them. Legal basis: performance of a contract.

d) Anonymous usage statistics (Firebase Analytics), only with your consent. App instance identifier, usage events (for example opening the App, progress through onboarding, saving a trip and the number of trips in the last 7 days, features used, permission decisions), App and system version, device model, language and approximate country or region derived from the IP address. No location, routes, trip content or fines are sent. The advertising identifier (IDFA) is not collected and advertising signals are disabled. Purpose: understanding which features are used and improving the App. Legal basis: consent (Article 6(1)(a) GDPR and Article 5(3) of Directive 2002/58/EC as implemented in national law). Nothing is collected without consent. You can withdraw consent at any time in the App (Settings → Legal → Anonymous usage statistics); collection then stops and locally stored analytics data are deleted. Withdrawal does not affect the lawfulness of processing before it. With the same consent the App also sends the Operator's server (Google Cloud, European Union region) daily aggregate counts of the screens shown and of the screen on which the App was closed, without any user or device identifier; only these totals are stored.

e) Security (Firebase App Check). Cryptographic verification that a request comes from the genuine App (Apple App Attest) and technical request data. Purpose: protecting the services against abuse and automated attacks. Legal basis: legitimate interest in securing the service (Article 6(1)(f) GDPR).

f) Measuring the Premium offer. Without any user or device identifier, the Operator's server receives the fact that the offer was shown, where it was opened from and whether a trial, purchase, restore or dismissal followed. The server stores only daily aggregate counts; the IP address is processed only transiently in transit. Legal basis: legitimate interest in evaluating the offer (Article 6(1)(f) GDPR).

g) Support chat. Message text including the previous conversation, request category, language and App version; when reporting a bug, also a technical App log (error messages and App state); an email address only if you enter it yourself. Messages are stored as a request on the Operator's server (Google Cloud, European Union region) and answered by an artificial intelligence assistant via the API of Anthropic (Claude model). Purpose: handling your request and fixing bugs. Legal basis: performance of a contract and legitimate interest in improving the App.

h) Satisfaction survey. Your answers, App version and device language, without a user identifier. Participation is voluntary. Legal basis: consent given by submitting the answers.

i) AI trip summary and weekly recap, where available. Trip statistics: score, event types, distance, average speed, weather and a verbal description of where an event happened, without GPS coordinates. Processing takes place on the Operator's server via the Anthropic API. Legal basis: performance of a contract.

j) Weather. To show the weather and driving tips, your location is sent to Apple WeatherKit. According to Apple, it is not linked to your Apple ID. Legal basis: performance of a contract.

k) ČHMÚ warnings (Czech Republic only). The App downloads the public file of current warnings from the Czech Hydrometeorological Institute and determines the administrative district for your location directly on the device. Your location is not sent to ČHMÚ; as the server operator, ČHMÚ sees only the IP address of the request.

l) Speed limits. During a trip, roughly once every 1–2 km, the coordinates of the area around your location are sent, without a user identifier, to the Overpass API service (overpass-api.de) to load OpenStreetMap map data. The service operator sees the IP address of the request. Road signs (stop signs, crossings, level crossings, traffic lights) are downloaded as files covering an area of roughly 10 × 10 km from Firebase Hosting (Google); a request reveals only that area and the IP address. If you enter a destination, the search text, the coordinates of your stops and your location are sent to Apple Maps (MapKit) to find the address and calculate the route and arrival time; Apple does not associate this data with your Apple ID. Recent destinations and your saved home and work addresses are stored only on your device. Legal basis: performance of a contract.

4

iOS permissions and whether you must provide data

You grant access to location, motion sensors and notifications in iOS and can change it at any time in the iPhone Settings. A system permission is a technical precondition for features, not a legal basis for processing under the GDPR.

Providing personal data is neither a statutory nor a contractual requirement. The data described in point 3(a)–(c) and (g)–(l) are necessary for the respective features, which cannot be used without them. Consent to usage statistics and taking part in the survey are entirely voluntary, and declining has no effect on the App's features.

5

Recipients

We do not sell personal data or use it for advertising. Recipients are:

  • Google Ireland Limited and Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions, Analytics, App Check) as processor
  • RevenueCat, Inc., USA (subscription management) as processor
  • Anthropic, PBC, USA (support chat and AI summaries) as processor; under its commercial terms it does not use API message content to train models
  • Apple Distribution International Ltd. and Apple Inc. (App Store, iCloud, WeatherKit, Apple Maps, App Attest); Apple processes purchase data as an independent controller
  • the operator of the Overpass API service (Germany) and the Czech Hydrometeorological Institute to the extent described in point 3(k) and (l)
  • other members of groups you join, to the extent described in point 3(b)
  • public authorities where required by law
6

Transfers to third countries

Some recipients are established in or process data in the USA. Transfers rely on the European Commission's adequacy decision (EU–US Data Privacy Framework) for certified recipients and otherwise on standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR). We will provide information about the safeguards used on request.

7

Retention

  • Account, leaderboard, groups and votes: for as long as the account exists. After the account is deleted, the data are removed without undue delay, and from the provider's backup systems within its standard periods.
  • Usage statistics: data linked to the instance identifier for no longer than 14 months, then only aggregate reports without identification.
  • Subscription: for the duration of the relationship and afterwards for as long as required by law; Apple and RevenueCat according to their own rules.
  • Support chat and survey: for as long as needed to handle them, at most 24 months.
  • Security and server logs: generally no longer than 30 days.
  • Data on your device and in iCloud: until you delete them (Settings → App data, Settings → Account → Delete Account) or uninstall the App.
8

Your rights

Under the GDPR you have the right:

  • of access (Article 15)
  • to rectification (Article 16)
  • to erasure (Article 17)
  • to restriction of processing (Article 18)
  • to data portability (Article 20)
  • to object to processing based on legitimate interest (Article 21)
  • to withdraw consent at any time (Article 7(3))
  • to lodge a complaint with a supervisory authority (Article 77)

You can exercise your rights by email at vojtajess@gmail.com or through the support chat, free of charge. We will reply within one month; in complex cases this may be extended by a further two months, and we will let you know in time. If we have reasonable doubts about your identity, we may ask for additional information. You can delete your account and Firebase data yourself in the App (Settings → Account → Delete Account).

The supervisory authority in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz. You may also lodge a complaint with the supervisory authority in the country where you live or work.

9

Security

Data are transmitted encrypted (TLS). Only the Operator has access to server data. The databases are protected by access rules that let each user write only their own data, and by App Check.

10

Age

The App is intended for drivers. It is not intended for anyone under 16, and we do not knowingly process their personal data.

11

Changes

We update this policy as the App and the law evolve. We will inform you in the App about material changes. If a new purpose of processing requires consent, we will ask for it in advance.

This policy is effective from 18 September 2026.

General part (applies to the website and all apps)
1

Data controller

The data controller is Vojtěch Landa, a private individual, contact: vojtajess@gmail.com. Neologos Development is not a legal entity or a registered business — it's the name under which Vojtěch Landa, as a private individual, develops and runs neologos.dev and the apps listed below.

2

What this page covers

This privacy policy is shared across neologos.dev, vejce.neologos.dev, and the apps Blackout, Eco, WorthIt, Blurt, Migrelog, and Limi. Each app also has its own section below, since it processes different data depending on what it does — the general part applies to all of them, and the app section adds to it.

3

Website traffic

neologos.dev collects basic, aggregate traffic statistics (visit counts, pages visited, approximate geographic area from IP address) via Vercel Analytics and, if enabled, PostHog. This data only exists to show whether the site is being used at all — it isn't sold, isn't shared with ad networks, and isn't linked to a name or email unless you provide one yourself (e.g. via the support chat).

4

Support chat and tickets

The Support section on the website and the support chat inside the apps let you report a bug, suggest an app improvement, ask about legal information or ask a general question. Chat messages are saved as a ticket in Firestore (Google/Firebase, see point 5). Messages in every category are answered by an AI assistant through the Anthropic (Claude) API. Anthropic acts as a processor: it handles the message, including the earlier conversation, only to produce a reply and does not use it to train models.

When you report a bug directly from an app, a technical app log (error messages and app state) is attached to the ticket so the problem can be traced. An email or name is stored only if you type it into the form yourself — it is never collected automatically.

Blackout, WorthIt, Blurt and Migrelog also include a short, optional in-app survey. At the end we ask whether you'd like us to get back to you. If you choose "No", your answers are sent without an e-mail address or any contact detail, i.e. anonymously. If you choose "Yes", your answers are sent the same way and the app opens the support chat with your answers pre-filled in the message and the e-mail address you enter yourself. The message and e-mail are then stored as a ticket as described in this section, and the e-mail is used only to reply to your feedback. The survey record itself stays without an e-mail address.

5

Shared infrastructure

The website and apps run on Firebase/Google Cloud (Firestore, Cloud Functions, Cloud Messaging) — the servers for the apps and site are set to a European region (europe-west3) wherever Firebase allows it. Google acts as a processor there under its own privacy policy (firebase.google.com/support/privacy).

Push notifications (where an app offers them) use the Apple Push Notification service — Apple only needs an anonymous device token for this, not personal data.

6

Advertising and cookies

The /brief page (Brief → Prompt) is funded by ads through Google AdSense so it can stay free. No ad script or third-party cookie loads until you consent in the cookie banner at the bottom of the page.

Once you consent, Google and its ad partners may set cookies to measure and personalize ads under their own policies (policies.google.com/privacy). You can manage ad personalization or opt out at adssettings.google.com.

You can withdraw consent at any time by clearing this domain's cookies in your browser — the banner will show up again.

7

Your rights

Under GDPR, you have the right to:

  • access your data
  • correct inaccurate data
  • erasure ("the right to be forgotten")
  • restrict processing
  • data portability
  • object to processing
  • withdraw consent at any time, where processing was based on it
  • lodge a complaint with the Office for Personal Data Protection (uoou.gov.cz)

You can exercise any of these rights simply — write to vojtajess@gmail.com or via Support (category "Legal information").

What to expect from me: I'll reply no later than 30 days after receiving the request — either sending, correcting, or deleting the data right away, or explaining why (and on what grounds) that isn't possible. For a more complex request this deadline can be extended once by another two months, which I'll tell you about within the first 30 days. To verify identity I may ask for extra information (e.g. the email or nickname used in the app), so the data doesn't end up with someone else under your name.

8

Data retention

Tickets and incidents are kept for as long as needed to resolve the request, plus a reasonable period after for traceability (typically up to 24 months), then deleted. Data stored directly in the apps (see the app sections below) follows each app's own rules — most of it can be deleted immediately right in the app.

A conversation with the assistant where you leave no email is kept on the server only as a hidden draft, so it can still be handed to a person if you add an email. Nobody reads it, and it is deleted automatically after 7 days.

9

Changes to this policy

This policy may change as the site and apps evolve. The current version is always on this page; the date of the last change is shown in the header.

Change history

  1. Screen counts with consent to statistics
  2. Added the car photo, road signs, Apple Maps and saved home and work addresses
  3. Rewritten in formal form for the September update (fines and points, weather, ČHMÚ warnings)
  4. Contact via web support, clarified bug reporting

Where next

This site uses cookies to show ads that keep the Brief → Prompt tool free. Do you agree?