Who is responsible
Petr Drábek, Czech Republic, is the operator of ApiNote and the controller of personal data covered by this policy. ApiNote has also used the developer name Pedros studio. Contact: pedrosmobileapps@gmail.com.
This policy covers the ApiNote mobile apps for Android and iOS. The website, contact form and newsletter have a separate privacy notice. Creating an app account does not subscribe you to the newsletter.
Your account and beekeeping records
Firebase Authentication provides account creation, sign-in and password recovery. Depending on your platform and chosen sign-in method, account information includes a user identifier, email address and the name or profile image supplied by Apple, Google or Facebook. Social sign-in uses provider credentials or tokens; ApiNote does not receive your password for that provider. Email-and-password registration is processed by Firebase.
Records you enter are stored in Firebase Firestore under your account. They include apiary names, addresses, registration numbers and coordinates; hives; inspections and notes; queens, evaluations and breeding series; treatments, feeding, harvests and mite counts; tasks; and financial entries. Financial records can include amounts, payment methods, counterparties and document numbers. Enter other people’s details only when appropriate.
Local settings and caches support the app’s operation. They include sign-in state, language and units, onboarding answers, selected currency, subscription state and AI-use counters. An account is needed for account-based storage and synchronisation; camera, microphone and location access are not required for ordinary manual record entry.
Inspection photos and device storage
Photos attached to inspections are copied to the app’s local photo storage. This feature does not upload the image files to a Firebase photo library or synchronise them as cloud attachments. Removing an individual attachment deletes the app’s corresponding local file; it does not delete the original from your photo library.
Images selected for an AI conversation are different: the app saves a local copy and sends it to OpenAI when you submit the conversation. Deleting a conversation’s saved text does not necessarily remove its separately stored image files.
Signing out does not erase all local photos, conversations or exported files. Protect a shared device accordingly. Device backups and copies you save outside ApiNote are controlled separately by your device, backup provider or chosen destination.
Voice inspections and the AI advisor
AI voice features send the recording to OpenAI for transcription. The transcript is then sent for structured record extraction; the voice assistant can also include the selected apiary and hive names. You can review the proposed records before saving them to your account.
The AI advisor sends the messages in the conversation, earlier replies and any included images to OpenAI. Continuing a saved conversation can send that history again. Voice dictation in the advisor also uses transcription. Manual entry is available without using AI.
The app stores chat sessions locally, retaining up to 30 saved session files and pruning older sessions when saving. You can delete one or all saved conversations in Chat history. This limit applies to session files, not separately stored chat images or provider records.
Native speech-recognition features can use the speech service supplied by your operating system. Recognition is not guaranteed to happen entirely on the device. Recordings use temporary local files or memory; the recorder attempts to remove temporary recording files after reading them.
OpenAI says API content is not used for model training by default, unless the API customer opts in. Its standard chat-completion abuse logs may retain content for up to 30 days, with legal or safety exceptions. Transcription has different retention rules. These are provider defaults, not a claim that ApiNote has verified special retention or data-sharing settings.
Use AI only for information you are comfortable submitting. Avoid passwords, payment-card details and unrelated sensitive information. AI suggestions can be inaccurate; they are not a veterinary diagnosis or an automated decision about your legal rights.
Locations, maps and weather
Apiary coordinates, addresses and other location details you enter can be saved with your records. Current-device-location features request the relevant permission. Refusing or withdrawing permission does not delete positions previously entered or saved.
Maps and location lookup use platform services, including Google Maps on Android and Apple’s map services on iOS. Weather requests send apiary coordinates or an entered place name to OpenWeather. Elevation requests send coordinates to Open Topo Data. Network providers also receive technical connection information, such as your IP address.
Location access is used for the location features you open; the app’s flight-radius display is a planning aid, not a record of bee movements. You can select an apiary location yourself and manage device permissions in system settings.
Permissions and reminders
Camera access supports taking photos and scanning hive codes. Photo selection lets you choose an existing image. Microphone and speech-recognition permissions support the voice features you start. You can refuse or withdraw these permissions in device settings; the corresponding features may then be unavailable.
Task reminders are scheduled as local notifications through Android or iOS. Depending on device settings, a reminder may show task or apiary information on the lock screen. Task records themselves can still be stored in your account even though delivery of the reminder is local.
Exports, sharing and QR labels
Selected datasets are exported as CSV files, or as a ZIP containing multiple datasets, in the device’s cache. The app shares the result through the destination you choose. Exports can contain apiary coordinates, notes and financial information. Deleting a record in ApiNote does not update or recall an exported copy.
Generated hive QR codes contain a hive identifier; the label can also display the hive name. Scanning matches the identifier against the hives available in the app. The label is not a password or an authorisation to publish your records, but anyone who can see a label can read its visible content and encoded identifier.
Subscriptions and purchases
Apple App Store or Google Play processes store purchases. ApiNote uses product, transaction and entitlement information to recognise your subscription, restore purchases and enable paid features. ApiNote does not receive your full payment-card details from these store transactions.
Manage or cancel subscriptions in the relevant store account. Deleting ApiNote or its login does not automatically cancel a subscription or delete records held independently by the store.
Usage information and analytics
The app contains Google Analytics for Firebase event reporting for onboarding, sign-in, paywall views, plan selection, purchases and restoration. Parameters include screen and sign-in method, selected plan, success or failure, beekeeping experience, hive-count range or count, and whether an apiary location was supplied. The location event records that a location exists, not its coordinates.
The inspected custom events do not include inspection notes or conversation text. The Analytics SDK can also process app and device information and identifiers, so analytics must not be treated as necessarily anonymous.
The current app has no dedicated in-app analytics consent or withdrawal control. Collection and retention also depend on the Firebase/Analytics project configuration. Contact us about analytics data or an objection; changing a website newsletter preference does not change app analytics.
Technical connection and error information may also be processed to operate the services and investigate failures. This policy does not list Firebase Crashlytics as an active app integration.
Why information is processed
Account access, storing and synchronising your chosen records, recognising purchases, and processing the AI or other app requests you initiate are necessary to provide those requested services. Where the GDPR applies, the basis is performance of the service contract under Article 6(1)(b), to the extent that processing is necessary for that purpose.
Necessary service security, abuse prevention, troubleshooting and responding to support enquiries serve our legitimate interests under Article 6(1)(f), subject to your rights. Processing required by law relies on Article 6(1)(c).
Where optional processing requires consent, including non-essential analytics or particular device access, that consent must be obtained before the processing and must be withdrawable. A device permission or acceptance of this policy is not blanket consent. The analytics-control limitation described above must be resolved before this notice is approved for public use.
How long information is kept
Account and cloud records remain available for the account and its record history until deleted or no longer needed for that purpose. There is no automatic age-based expiry for hive histories in the inspected app. You can delete individual records through the relevant app functions and request deletion of remaining data.
Local inspection photos remain until removed or the app’s local data is erased. Chat session files are kept until deletion or pruning at the 30-session limit; separately stored chat images may remain longer. Finished exports remain in the cache or wherever you save or share them until those copies are removed. Temporary recording cleanup is attempted, not guaranteed in every failure or interruption.
Support correspondence is kept while needed to resolve the enquiry, handle related follow-up or meet a legal obligation. Data needed for security, a legal obligation or a dispute may be retained for that limited purpose. A deletion request can ask what is retained and why.
Provider deletion is not always immediate. Firebase states that deleted authentication information can take up to 180 days to leave its live and backup systems. This is not a Firestore deletion guarantee. Analytics, other provider logs and backups follow their respective settings and obligations; no unverified project-specific deletion period is promised.
Request account and data deletion
For complete account-and-data deletion, email pedrosmobileapps@gmail.com, preferably from your account email, and state that you want your ApiNote account and associated data deleted. Contact us before deleting the login where possible, so that your records can be located. If you already deleted it, include the email and sign-in method previously used.
You can also choose Delete account in the app’s Settings. The current action removes the Firebase Authentication login and clears some sign-in and entitlement settings. It does not establish complete deletion of Firestore subcollections or local files; do not rely on that button alone for complete erasure.
We may request only the information reasonably needed to verify identity and locate the data. Never send your password, sign-in code or payment-card details. Explain if your request should cover only particular records rather than the entire account.
Export anything you want to keep first, remove local copies you no longer need and manage your store subscription separately. Where the GDPR applies, requests must normally be answered within one month. A permitted extension or refusal must be explained, including the reason and your options.
Your rights and choices
Under applicable data-protection law, you may request access and a copy of your personal data, correction, erasure, restriction of processing and portability. You may object to processing based on legitimate interests and withdraw consent without affecting the lawfulness of earlier processing. These rights have conditions and exceptions.
Send requests to pedrosmobileapps@gmail.com. You can also complain to the Czech Office for Personal Data Protection (ÚOOÚ), or another competent supervisory authority, including in your place of residence in the EEA. Local law may provide additional rights where it applies.
Optional permissions can be changed in device settings. Manual record entry does not require AI processing. ApiNote’s AI suggestions do not make solely automated decisions with legal or similarly significant effects.
Protecting your information
ApiNote uses account authentication, device protections and the security measures of its service providers. These measures do not make every device, backup or network risk-free. Keep your device and sign-in details protected, and check what an export or shared photo contains.
Logging out is not a complete device wipe. Before handing a device to someone else, deal separately with local app data, photo-library originals, exported files and backups. Contact us if you suspect unauthorised access or a privacy incident.
Children and policy updates
ApiNote is a beekeeping record-keeping tool, not a service directed at children. If you believe a child has provided personal information inappropriately, contact us so the matter can be investigated and the data handled under the applicable requirements.
The date above identifies this document’s latest update. Changes to functions, providers or data processing may require an updated notice. Material changes will be communicated through the app, this website or another appropriate channel. The private release-review notice remains applicable until this version is approved for public use.