Controller and scope
This Privacy Policy explains how personal data is processed in connection with the TesSa: tessere e documenti mobile application (the “App”), the related website at https://baleendevs.github.io/tessa (the “Site”) and the features made available through them (together, the “Services”).
The data controller for the processing described in this Policy is Carlo Andreotti, an independent individual developer operating under the name Baleen Developers, Via dei Boschi 30, 15072 Casal Cermelli (AL), Italy (“Baleen Developers”, “we”, “us” or “our”). No data protection officer has been appointed because the processing carried out does not currently require one under applicable law.
TesSa is intended for users in Italy. This Policy covers both information kept under the user’s control on the device and the limited personal data processed by us or by third-party services through the App or Site. It should be read together with the TesSa Terms of Use.
Document data stored locally
The App lets users enter, import, scan and display information relating to health cards, identity documents, driving licences and other supported documents, including images, identifying details, barcodes and QR codes. This content may be highly confidential. It is stored locally in an encrypted database on the user’s device and is not uploaded to or retained in a TesSa-operated account, server or cloud-storage service.
We do not receive, view or remotely retrieve document content kept in the App. Users control that content and can edit or delete it through the App or remove the App’s local data. Deleting the local copy does not delete backups, screenshots, messages, shared links or other copies previously created or transferred by the user.
TesSa does not provide user accounts, synchronisation between devices or a cloud backup service. The operating system or a service independently chosen by the user may nevertheless create or retain device backups under that provider’s settings and privacy terms.
If a user stores information relating to a minor or another person, the user is responsible for having the legal authority to do so and for using and sharing that information lawfully.
Information provided directly to us
We do not require registration and do not directly collect names, postal addresses, phone numbers, passwords, payment-card details or document content merely because a person uses the App or visits the Site.
If you contact us for support, a privacy request or another enquiry, we receive the email address and any name, message, attachments and technical details that you voluntarily provide. Please do not send copies of identity documents, health cards, full barcodes, backup files or other sensitive information unless it is strictly necessary and we have specifically asked you to do so through an appropriate channel.
- support and privacy correspondence, including the sender’s email address and message content;
- technical information voluntarily supplied to diagnose a problem;
- records necessary to handle a complaint, comply with law or establish, exercise or defend legal claims.
Technical data processed automatically
The App and Site use limited third-party infrastructure. Depending on the platform, configuration, permissions and privacy choices, those providers may automatically process the following categories of data:
- device and application information, such as device type, operating system, language, app version, application or advertising identifiers and network provider;
- network and approximate-location information derived from the IP address, but not precise GPS location requested by TesSa;
- limited usage, diagnostic, advertising and performance events, such as app launches, sessions, pages viewed, ad impressions, ad interactions and error information;
- privacy, advertising and consent choices made through the operating system, app store or a provider’s consent interface.
TesSa does not create custom behavioural profiles or custom usage logs. Google Analytics for Firebase is currently included on Android and may automatically record events and device properties; Firebase Analytics is currently disabled in the iOS configuration. Google Mobile Ads may automatically record advertising events on both supported platforms. The Site uses Google Analytics 4 for aggregate access statistics (subject to prior consent), and GitHub Pages, as the Site host, logs visitor IP addresses for security purposes.
Device permissions and features
The App may request access to device features only to provide functions selected by the user. Permission can be denied or later changed in the device settings, although the related feature may then be unavailable.
- Camera: to scan supported barcodes or QR codes and acquire document images when requested;
- Files, photos or storage: to import or save images and to create, select or restore backup files;
- Biometric authentication: optional fingerprint or facial verification is performed by the operating system; TesSa receives only the success or failure result and does not receive or store biometric templates.
TesSa does not request access to precise geolocation, contacts, calendars, SMS messages, social-media accounts or the microphone, and does not use social login.
Purposes and legal bases
Where the GDPR applies, we process personal data only when a legal basis is available. The applicable basis depends on the data and context:
- performance of a contract or steps requested before entering one, to provide requested App functions, support and the TesSa PRO purchase;
- consent, for personalised advertising and non-essential analytics, identifiers or similar technologies where consent is required by law;
- legitimate interests, to secure the Services, prevent fraud and abuse, diagnose problems, understand aggregate Site traffic and protect or defend legal rights, provided those interests are not overridden by users’ rights;
- compliance with a legal obligation, including lawful requests and accounting, consumer-protection or data-protection requirements.
Document content processed only on the device is handled at the user’s request to provide the chosen functionality and is not transmitted to us by default. We do not use personal data for direct marketing, sell personal data, or make decisions producing legal or similarly significant effects through automated profiling.
Advertising and analytics
The free version of the App may display advertising through Google AdMob. AdMob and its authorised advertising partners may process advertising identifiers, IP address, device and app information, consent choices and ad interaction data to deliver, limit, secure and measure advertising. The content of documents stored in TesSa is not intentionally provided to AdMob or advertisers. TesSa PRO removes advertising from the App.
Where required by law, personalised advertising and access to non-essential device identifiers must be based on valid consent. Without valid consent, Google and its partners may process data only where another legal basis applies, including for limited or contextual advertising, security, fraud prevention, frequency capping or measurement where legally permitted.
On the Site, Google Analytics 4 (provided by Google Ireland Limited / Google LLC) is used solely to measure aggregate visits and page views. Analytics cookies are set only if you provide your explicit consent through the cookie banner. Event data retention is set to 2 months. Document viewing pages (/share) do not contain any analytics code and document data is never transmitted to Google. Further information and an opt-out browser add-on are available on Google's privacy pages.
App-store purchases
The optional one-time TesSa PRO purchase is processed exclusively by Apple through the App Store or by Google through Google Play. We do not directly receive or store payment-card numbers or complete billing details. The applicable store may provide the App with limited information such as the product identifier, transaction or receipt data and purchase or entitlement status so that PRO can be activated or restored.
Apple and Google process store-account, payment, tax, refund and transaction information under their own terms and privacy policies. Requests concerning payment methods or the store’s transaction records should be directed to the relevant store.
Backups and user-controlled sharing
TesSa can create an encrypted backup file locally. We do not automatically receive or retain a copy. The user chooses where a backup is stored or transmitted and is responsible for protecting it and any information needed to access it. A storage, messaging or cloud service selected by the user processes the file under its own privacy terms.
When a user chooses to share document information, TesSa may generate a link or QR code containing selected data in the URL. The data is encoded, including through Base64 encoding, but is not encrypted or password-protected. Anyone who obtains the link or QR code may be able to decode, read, copy or further share its contents.
The link and its contents may appear in messages, browser history, link previews, screenshots, access or security logs, and services used to share or open it, including the Site hosting provider. We do not maintain a separate TesSa-controlled database copy of the shared document data and cannot revoke or remotely delete a link after it has been shared.
Sharing is initiated and controlled by the user. Users should review the included data, choose trusted recipients and appropriate channels, and remove copies from messages, histories or third-party services when no longer needed.
Recipients and third-party services
Depending on the feature and platform used, limited personal data may be processed by the following recipients. They receive only the categories necessary for their respective services and may act as processors or independent controllers according to the circumstances and their terms:
- Google, including AdMob, Google Analytics for Firebase, Google Play and the email service used for support;
- Apple, for App Store distribution, in-app purchase processing and platform services;
- Google, through Google Analytics 4, for aggregate Site access measurement (subject to consent);
- GitHub, through GitHub Pages, for static Site hosting and hosting security logs;
- public authorities, courts, professional advisers or other persons where disclosure is required by law or reasonably necessary to establish, exercise or defend legal claims.
We do not disclose personal data to corporate affiliates, data brokers, marketing-list providers or business partners, and we do not sell or rent personal data. Independent services deliberately selected by a user, such as a messaging or cloud-storage provider used to share a link or backup, receive data from the user rather than from a TesSa-controlled server.
International data transfers
Document content kept only in the App is not transferred internationally by us. Some third-party providers are established in, store data in, or permit access from countries outside the European Economic Area, including the United States. Their infrastructure and subprocessors may operate in additional countries.
Where required, such transfers are protected through an applicable adequacy decision, a provider’s participation in a recognised data-transfer framework, European Commission standard contractual clauses or another lawful safeguard described in the provider’s terms. We do not claim our own certification under the EU–US Data Privacy Framework. Users should consult the linked provider notices for current locations and safeguards.
Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it is processed, subject to the following criteria:
- document data remains locally on the device until the user deletes it or removes the App data; exported backups and shared copies remain until deleted by the user or the third party holding them;
- support and privacy correspondence is kept for the time needed to answer and follow up, and longer only where necessary for a legal obligation or legal claim;
- locally stored PRO entitlement information remains until the App data is deleted, while Apple or Google retains transaction records under its own legal obligations and policy;
- analytics, advertising, hosting and security information is retained according to the applicable provider settings and policies and is deleted or aggregated when no longer required for the stated purpose.
Security
TesSa uses measures designed to protect locally stored information, including an encrypted local database, encrypted backup files, the operating system’s application sandbox and optional App access controls such as a PIN or device biometric authentication. Access to camera and files is subject to operating-system permissions.
No storage or transmission method is completely secure. Users must protect their device, App access code, backups and sharing links, install security updates and avoid rooted or jailbroken devices. Sharing-link payloads are encoded but not encrypted and should not be treated as confidential once disclosed to another person or service.
Minors
The Services are intended for users aged 18 or over and are not directed to minors. We do not knowingly solicit personal data directly from minors. If we learn that a minor has sent personal data to us without appropriate authorisation, we will take reasonable steps to delete it where required.
An authorised adult may use the App to store information concerning a minor under that adult’s care. That information remains local unless the adult chooses to export or share it, and the adult is responsible for having an appropriate legal basis and protecting the minor’s information.
Your privacy rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- obtain confirmation of whether personal data concerning you is processed and request access to it;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive data you provided in a portable format where the legal requirements are met;
- withdraw consent at any time without affecting earlier lawful processing;
- lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority.
Requests may be sent to baleen.devs@gmail.com. We may ask for information reasonably necessary to verify the request, but we are not required to collect additional data solely to identify a person. If we cannot link technical or aggregate data to the requester, we will explain that we are unable to identify the relevant record unless the requester provides information that makes identification possible.
We cannot access, export, correct or remotely delete document data that exists only on a user’s device. The user can manage that data directly in the App. Requests concerning data controlled independently by Apple, Google, GitHub or a service chosen by the user may need to be submitted to that provider.
Where consent applies, it may be withdrawn through any consent controls made available by the relevant provider, through applicable device or platform privacy settings, or by contacting us. Withdrawal may affect personalised advertising or optional analytics but does not affect the App’s core local document-storage functions.
Third-party sites and services
The Services may contain links to or interact with independent third-party sites and services. We do not control their content or privacy practices. Review the relevant privacy notice before providing data or using an external service. This does not limit any responsibility we have under applicable law for our own selection or integration of a provider.
Changes to this Policy
We may update this Policy to reflect changes to the Services, providers or law. The revised version will be posted on this page with a new effective date. Where required by law, or where a change materially affects how personal data is processed, we will provide additional notice through an appropriate channel.
Contact
For privacy questions or to exercise applicable rights, contact Carlo Andreotti, operating under the name Baleen Developers, at baleen.devs@gmail.com or by post at Via dei Boschi 30, 15072 Casal Cermelli (AL), Italy.
This contact channel does not provide remote access to information stored only on a user’s device. Please describe the request without sending unnecessary copies of documents or other sensitive data.
