Draft
Balnea privacy policy
The short version
- No account. You can use Balnea without signing up. We never ask for your name.
- Your saved list and recent searches are kept on your phone and are not synced. The words you search for are never sent to us. If usage statistics are on, we do learn which places you save and unsave (section 3.3).
- No location. The app does not ask for or use your location.
- No advertising. No ads, no advertising IDs, no selling or renting of your data, no tracking across other companies' apps.
- Usage statistics are tied to a random ID, not to you. You can turn them off at any time in More → Privacy. Crash reports are separate and are not affected by that switch (section 3.5).
- App updates carry a random ID. Each time the app is opened it asks Expo, a company in the United States, whether there is a software update. That request carries a random ID of this installation, not your name or anything about what you do in the app (section 3.2).
- Reports are optional. If you report an update, we receive what you write. Leaving an email address is optional; we delete it 90 days after we resolve your report.
- Our servers and database are in the European Union (Frankfurt, Germany). Some of our service providers handle data elsewhere, including in the United States (section 6).
The rest of this policy gives the details.
1. Who we are
Balnea is a guide to pools and spas in Yerevan. It is run by Balnea, Yerevan, Armenia.
We decide why and how the personal data described here is used. Armenian law calls this role the personal data "processor"; other laws, such as the EU GDPR, call it the "controller".
Contact for anything in this policy: hello@balnea.app.
2. What this policy covers
This policy covers the Balnea mobile app for iOS and Android.
It does not cover:
- Venue websites and map apps. When you open a venue's official site, or get directions in a map app, you leave Balnea. That site or app has its own privacy policy (section 7).
- The app stores. Apple and Google handle downloads, store accounts and store reviews under their own policies.
- Booking and payments. Balnea does not sell, reserve or take payment for visits today. If booking is added, this policy will be updated before that feature is available, to cover the extra data it needs, such as your name, phone number, bookings and payment records.
3. What we collect and why
3.1 Data stored on your phone
The app stores the following on your phone until you delete it or uninstall the app. The last column says whether any of it also reaches us.
| Data | Why | Sent to us? |
|---|---|---|
| Your saved list, with the date you saved each place | So you can come back to them. Not synced to other devices | The list itself, no. If usage statistics are on, each save and unsave is sent as an event naming the place (section 3.3), so our statistics can tell which places an installation saved |
| Your last few searches (up to 5) | Quick repeat searches. You can clear them in the app | Never. Only the kind of search is sent (section 3.3) |
| Your language | So the app remembers your choice | Yes: with usage events (if on) and with each report |
| The map app you chose for directions | So the app remembers your choice | If usage statistics are on, the directions event says which kind of map app was opened (section 3.3) |
| Your usage-statistics setting | So the app respects your choice | No |
| A random installation ID (section 3.3) | Usage statistics and report spam limits | Yes: with usage events (if on) and with each report, even when statistics are off (section 3.4) |
| A random update ID, separate from the installation ID above. The app's update software creates it the first time it checks for an update | So the update service can tell one installation's update checks from another's | Yes: to Expo, with every check for an app update and every update file the app downloads (section 3.2). It stays the same until you delete the app, and it comes back if you restore your phone from a backup |
| Downloaded app updates (the app's own code) | So the app runs its newest version | No |
| The downloaded guide (venue information and photos) | So the app works offline | No |
| An unsent report draft, including any text and email address you typed | So a draft survives if your phone closes the app in the background | Only when you send it. |
3.2 Downloading the guide and app updates
To show you venues, the app downloads the guide (venue information and photos) from our content delivery network, run by Cloudflare. Like any internet request, this reveals your device's IP address and basic technical details (such as the app version) to Cloudflare, which needs them to deliver the content and protect the service. Reports and usage statistics also travel through Cloudflare on their way to our server. Cloudflare decrypts them at the data centre that serves you (usually in Yerevan) and limits how many requests one IP address can send.
- We do not store your IP address in our database or link it to anything else about you. Cloudflare passes your IP address on to our server with each report or batch of statistics, as standard request information; our server uses it for nothing and does not log it.
- If Cloudflare blocks a request because an IP address sent too many, the blocked address is shown to us for a limited time in Cloudflare's security dashboard. We don't copy it anywhere.
- Cloudflare may keep IP addresses briefly in its own security and operations logs.
The app also checks for software updates of its own code through Expo's update service (EAS Update), each time it is opened after being closed. Each check sends:
- a random update ID (section 3.1): not your name, phone number, email, advertising ID or device serial number, and not the analytics ID of section 3.3;
- which version of the app's code is running, which version the app was installed with, and which release group this copy of the app belongs to (for example, the test version or the public version);
- the platform (iOS or Android) and our project identifier;
- if an update failed to start on your phone: the identifiers of the updates that failed and, once, the technical error message the app produced (up to 1,024 characters).
Expo also sees your IP address and, as with any request your phone makes, the app's name and version and your phone's language settings. If there is an update, the app downloads its files from Expo's servers, sending the same update ID with each file. The check does not send your saved list, your searches or anything else you do in the app. It is not affected by the usage-statistics switch (section 3.3), and resetting the analytics ID does not reset the update ID.
Expo says these requests contain no unique device identifiers and that it uses the random ID to tell whether an installation has asked for an update. Expo counts, for each update, how many installations started it and how many failed.
3.3 Usage statistics (analytics)
We collect a small set of usage events to learn whether the guide helps people find a place to go. For example: you opened a venue, saved it, opened its official site or asked for directions. The full list is short and fixed:
- the app was opened (from which entry point, such as a shared link, and whether the content came from the phone or the network)
- a search was made: only what kind of search it was (a venue, an area, an amenity, or no match) and how many results it found. The words you type are never sent. The app classifies them on your phone
- filters were applied (which filters, how many results, and whether you then followed a suggestion to loosen them)
- a venue was opened (which venue and visit option, from which screen, and the entry label and freshness of the information you saw)
- a venue was saved or unsaved (which venue, from which screen, whether it worked)
- directions or the venue's official site were opened (which venue and visit option, which kind of map app or site, whether it opened successfully)
- a report was sent (which venue, the type of issue and its severity; never what you wrote)
- the app showed a notice that information was out of date, or that a venue is unavailable
Each batch of events also carries:
- a random installation ID created by the app when it is first used (the app calls it the "analytics ID"; it is not your name, phone number, email, advertising ID or device serial number)
- a random session ID
- the app version, platform (iOS or Android), app language and the time of each event
- a group label, such as "beta", that is the same for everyone in that group
We use this only to produce statistics about the guide: for example, how many people saved a venue this week, which searches find nothing, and which languages people use. We do not use it for advertising, we do not combine it with data from other companies, and we do not try to find out who you are.
Your choice. You can turn usage statistics off at any time in More → Privacy. When they are off, the app stops recording and sending events. Turning them off does not stop crash reports (section 3.5), and a report you send still carries the installation ID (section 3.4). You can also reset the analytics ID there: the app then starts again with a new random ID that cannot be linked to the old one. Events already sent under the old ID stay on our servers until they are deleted (section 5).
3.4 When you report an update
From a venue page you can tell us that something has changed (for example, the venue is closed, a price is wrong or the entrance has moved). When you send a report we receive:
- the venue (and, if relevant, the visit option or fact) and the type of issue you chose
- what you write in the optional description, up to 2,000 characters
- your email address, only if you choose to give one so that we can reply
- the app version, platform and language, and which version of the venue information you were looking at, so we can see what you saw
- the random installation ID from section 3.3, even if usage statistics are off. We don't keep it: our server keeps only a scrambled code derived from it, used only to stop spam (for example, at most 10 reports a day from one installation) and to merge duplicate reports about the same venue
We use a report to check the venue's information with the venue or its official source. A report never changes the guide by itself. A person reviews it first. If you gave an email address, we may write to you about your report. We will not use it for anything else, such as newsletters or marketing.
Verification records. If a report leads us to check or correct the guide, our verification history may record that a user reported the change.
Please don't include sensitive information (such as health details) or other people's personal details in a report.
3.5 Crash and error reports
If the app, or our server, hits an error, a technical error report is sent to Sentry, our error-monitoring service, which stores it in the European Union. The app sends it directly from your phone to Sentry, so Sentry receives your IP address with it, as with any request; we set Sentry not to store it. An error report contains technical details:
- what went wrong in the code, and the app version and build;
- the device model, operating system version and similar technical details about the phone;
- a trail of recent technical events before the error ("breadcrumbs"), such as which screens were open, the addresses the app contacted (our content and report servers) and the app's own log messages;
- a random ID that Sentry's software creates for this installation, separate from our installation ID.
We configure Sentry not to collect personal data, and we remove email addresses, phone numbers and report text from error reports before they are sent. Session replay, screenshots and performance tracing are switched off. Crash reports are not covered by the usage-statistics switch.
If you have allowed it in your phone's settings, Apple or Google may also share crash statistics with us under their own policies (section 7).
3.6 Beta testing and research interviews
If you join our test version (Apple TestFlight or a Google Play closed test), we give Apple or Google the email address (and, for TestFlight, the name) you use with them so they can invite you. Apple and Google then show us, under their own policies, whether you accepted, your device model and system version, when the test app was installed and used, crash reports, and any feedback or screenshots you choose to send through TestFlight. If you agree to talk to us about how you used the guide, we keep notes of that conversation. We do not record a conversation unless we ask you first.
3.7 People who don't use the app
- Venue staff. To check information we sometimes contact people who work at venues. We keep their name and work contact details encrypted, together with their role, for as long as we keep in touch with the venue. Our verification history records that a fact was confirmed with that person, and when. We use these details only to verify venue information.
- People in photos. We publish a photo showing an identifiable person only with a recorded release. We remove location data (EXIF/GPS) from every photo before it is published. The original files, which may still contain it, are kept in our private storage in the EU.
- Our staff. Staff who sign in to our admin tool are covered by a separate internal notice.
3.8 What we don't collect
We do not collect your location, contacts, photos, microphone or camera; advertising identifiers; your name or phone number; payment details; or the text of your searches. The app shows no ads and asks for no push-notification permission.
4. Why we are allowed to use your data (legal basis)
| Purpose | Data | Armenian law | GDPR-style basis |
|---|---|---|---|
| Deliver the guide and app updates | IP address and technical request data, seen by Cloudflare and Expo; not stored by us. For app updates also the random update ID, sent to Expo | Necessary to provide the service you asked for? | Necessary to provide the service (contract), legitimate interests (security) |
| Usage statistics | Events, random IDs, app details | Consent: an opt-out notice, or opt-in if counsel requires it | Legitimate interests (opt-out), or consent (opt-in) |
| Reports | Venue, issue, description, app details, installation ID (kept only as a scrambled code) | Consent, given by choosing to send a report | Legitimate interests in accurate listings |
| Replying to a report | Your email address | Consent, given by choosing to enter it; you can withdraw it | Consent |
| Preventing spam and abuse | Scrambled installation code, edge rate limiting by IP address | ? | Legitimate interests (security) |
| Crash and error reports | Technical error data, breadcrumbs, IP address at receipt (not stored), Sentry installation ID | ? (not covered by the statistics switch) | Legitimate interests (keeping the app working) |
| Verifying venue information | Venue staff contact details | ? (work contacts, possibly from public sources) | Legitimate interests |
5. How long we keep it
| Data | How long |
|---|---|
| Data on your phone | Until you delete it, reset it or uninstall the app |
| Usage events | 13 months, then deleted automatically |
| Reports | 12 months after we resolve the report, then deleted automatically. |
| Your email address from a report | 90 days after we resolve the report, then deleted automatically. |
| Email conversations about a report | If we reply by email, the conversation is also kept in our mailbox. We delete it within 90 days after we resolve the report. |
| Crash and error reports | 30 days in Sentry (our current plan; up to 90 days on a larger plan) |
| The update ID and the records of update checks at Expo | |
| Server logs | About 7 days at our hosting provider (Fly.io; Fly's documentation states 7 days, checked 2026-09-29). Our server logs are designed not to contain IP addresses, email addresses or report text |
| Backups | Our database is backed up every night. Backups are encrypted and kept for 30 days, and our database provider keeps a restore history for up to 7 days. Deleted data can therefore remain in a backup for up to 30 days, until that backup expires. Temporary copies of the database, made to test an update or a restore, are deleted when the test ends. |
| Venue staff contacts | While we keep in touch with the venue. |
| Beta invitation emails and interview notes |
Deletion runs as a daily automatic job.
6. Who processes data for us, and where
We use a few service providers to run Balnea. They process data only on our instructions.
| Provider | What they do for us | Where the data is |
|---|---|---|
| Cloudflare | Delivers the guide and photos; protects our server from abuse (rate limiting); controls staff sign-in to the admin tool; stores photo originals, archived venue web pages and encrypted database backups | Worldwide network (you usually connect to the nearest data centre, for example in Yerevan). Our private storage is in the EU jurisdiction. Public content (the guide and its photos, including any photo of a person who gave a release) is stored mainly in Eastern Europe (a location preference, not a guarantee) |
| Fly.io | Runs our server, which receives reports and usage events, and makes the nightly encrypted backup | Frankfurt, Germany |
| Neon (part of Databricks) | Our database | Frankfurt, Germany (AWS eu-central-1) |
| Sentry | Crash and error reports | European Union |
| Expo | Builds the app and delivers app updates | United States |
| GitHub | Stores our source code and runs our automated checks and server updates. Our automated jobs there do not handle your personal data | United States |
| Google (Workspace) | Our mailbox, used only if we reply to a report by email | |
| Telegram | Internal alerts to our staff. Alerts never contain personal data: only record numbers and links to our admin tool | Outside Armenia |
International transfers. We keep our database, servers and private storage in the EU. EU countries are reported to be on the Armenian personal data authority's list of countries with adequate protection. Some providers are US companies, and some handle data outside the EU: Cloudflare's network, Expo, GitHub and Google.
7. Who else may see your data
- We don't sell or rent your data, and we don't share it with advertisers or data brokers.
- Venues don't receive your reports or your email address. We may tell a venue that information about it was reported as wrong, without saying who reported it.
- Apple and Google run the app stores and act under their own privacy policies. They may give us statistics about downloads and, if you allow it on your phone, crash reports. If you open the app from an invitation or shared link, or install it through Google Play, the app may note which link or campaign brought you (for example, "shared by a friend"), but not who you are.
- The map on a place's page (iPhone). The map on a place's page comes from Apple Maps. Balnea does not receive or store your location. The app does not ask for your location and the map does not show it; it shows the place. To draw the map your phone asks Apple's map service for that area, as any map does, which reveals your device's IP address and the area shown to Apple, under Apple's privacy policy.
- Map apps. When you ask for directions, we open the map app you choose (for example, Google Maps, Yandex Maps, 2GIS or Apple Maps) with the venue's location. We send nothing about you. From then on the map app's privacy policy applies.
- Venue websites. When you open a venue's official site, it opens in your browser, and that site's privacy policy applies.
- Sharing. When you share a venue, your phone's share menu sends what you choose to whoever you choose. We are not involved.
- Authorities. We disclose data to authorities only when the law requires it.
8. How we protect your data
- Connections to our servers are encrypted (HTTPS).
- Report email addresses are encrypted in our database. Only authorized staff can reveal one (today, only the founder). Revealing an address requires a fresh sign-in and is logged.
- The admin tool is protected by Cloudflare Access, and only named staff can sign in.
- Backups are encrypted before they are stored, and the decryption key is kept offline.
- We keep as little as possible, delete it on a schedule and host it in the EU.
If a security incident affects your personal data, we will inform the Personal Data Protection Agency and the affected people as the law requires.
9. Your choices and rights
In the app, at any time:
- turn usage statistics off, or reset the analytics ID (More → Privacy)
- clear recent searches, unsave places, or uninstall the app to remove everything stored on your phone, including the update ID (section 3.2).
By writing to hello@balnea.app, you can ask us to:
- tell you whether we hold personal data about you, and give you a copy
- correct it
- delete it, or stop using it
- withdraw a consent you gave, for example for us to keep your email address
We may not be able to find your data. Usage statistics are linked only to a random ID, not to your name or email, so we usually cannot tell which records are yours. To remove your influence on future statistics, reset the analytics ID or turn statistics off. For a report, tell us the venue, the approximate date and, if you gave one, the email address you used.
Complaints. You can complain to Armenia's Personal Data Protection Agency (Ministry of Justice, pdpa.am), or go to court. We would appreciate the chance to fix the problem first, at hello@balnea.app.
10. Children
Balnea is a general guide for adults planning a visit. It is not aimed at children. It has no accounts. The only contact detail it asks for is the optional email address in a report, and a report's description is free text, so anyone can type personal details into it. If you believe a child has given us personal data, write to us and we will delete it.
11. Changes to this policy
We will update this policy when the app or the law changes. This includes adding booking and payments, which will be covered before those features launch. The current version, with its date, is always in the app under More → Privacy, and the app keeps a copy of the last approved version for when you are offline. If a change significantly affects how we use your data, we will say so clearly in the app before the change takes effect.
12. Contact
Balnea, Yerevan, Armenia
Email: hello@balnea.app