Bilargo Exit — Privacy Policy

Effective date: September 28, 2026

This Privacy Policy explains how Bilargo — Michał Lipski, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland, with registered address at Aleja Partyzantów 51A, 24-100 Puławy, Poland, NIP 7161515351, REGON 061686949 (“Bilargo”, “we”, “us” or “our”), handles information when you use the Bilargo Exit iOS application (the “App”) and related support materials.

Bilargo is a trade name of the sole proprietorship operated by the natural person Michał Lipski. For the purposes of the EU General Data Protection Regulation (“GDPR”), Bilargo / Michał Lipski is the data controller for personal data we process.

1. Summary

Bilargo Exit is designed to work on your device, without accounts and without our servers.

As currently offered:

The App does not use artificial-intelligence models and does not send your content to any AI service.

2. Information processed locally

The App may process and store locally on your device:

This local information remains on your device unless you share or export content yourself (Section 5), or your own device/iCloud backup settings copy it as part of a standard device backup.

3. Camera, photo picker, location, and notifications

Camera, location and notification permissions are optional and requested only when you use the corresponding feature. Denying them leaves the core checklist available; you can mark items manually or skip them.

4. Purchase information

If you buy Bilargo Exit Pro (as a monthly or yearly subscription, or as a lifetime purchase) or restore purchases, Apple processes the transaction. We do not receive your payment card details. We may receive or process limited entitlement information from Apple, such as whether an active Pro entitlement is associated with the Apple Account in use. Apple's processing is governed by Apple's own terms and privacy policy.

5. Sharing and export you initiate

If you share a summary card or export a photo, iOS presents the system share sheet and you decide where that content goes. Content you move out of the App is then handled by the destination app or service outside our control.

Pro also lets you export a list or a backup file. You choose whether to include reference photos, check history (including checks in progress), and check photos. A text export contains only the list name and item titles. Files you save or share may leave the device through the destination you choose; they are separate copies and are not removed when you delete data in the App. Exit does not add password encryption to these files. Keep them in a location and share them with recipients you trust. Importing a file stores its selected content in the App.

6. Support communications

If you contact us for support or privacy requests, we may process the information you provide, such as your name or email address, the content of your message, device/app details you choose to include, and attachments you voluntarily send.

Launch notifications. If you write asking to be told when the App is released, we keep your email address for that single purpose and delete it within three months of launch. The legal basis is your own request (Art. 6(1)(a) GDPR); reply to us at any time to be taken off the list.

Please do not send sensitive personal data unless it is necessary for your request.

7. Data we do not intentionally collect

As of the effective date of this Policy, we do not collect your checklists, photos, check history, or location on our own servers. We operate no servers for the App. We do not use analytics or advertising SDKs, we do not sell personal information, and we do not use the App for advertising tracking.

8. Purposes and legal bases for processing

Where GDPR applies, we rely on the following legal bases:

Purpose Data involved Legal basis
Providing checklists, photo checks, history, reminders and App functionality Information processed locally on your device Performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in operating the App (Art. 6(1)(f) GDPR)
Managing your Pro entitlement Apple entitlement information Performance of a contract (Art. 6(1)(b) GDPR); legitimate interest in preventing abuse of licensing features (Art. 6(1)(f) GDPR)
Handling support and privacy requests Contact details and message contents you provide Performance of a contract (Art. 6(1)(b) GDPR), legal obligation (Art. 6(1)(c) GDPR), and legitimate interest in customer support (Art. 6(1)(f) GDPR)
Compliance, legal claims and App Store obligations Records necessary to comply with law or defend claims Legal obligation (Art. 6(1)(c) GDPR) and legitimate interest (Art. 6(1)(f) GDPR)

9. Data sharing

We do not sell your personal data.

Relevant third parties may include:

10. International data transfers

Some third parties involved in App distribution or support may be located outside the European Economic Area, including in the United States. In particular, Apple may process App Store data in accordance with its own transfer mechanisms (such as Standard Contractual Clauses or an applicable adequacy framework). Where we transfer support-related personal data ourselves, we use an applicable transfer mechanism such as Standard Contractual Clauses.

11. Local storage and retention

Because the App is local-first:

If you uninstall the App or remove local data, some or all local information may be deleted, subject to iOS behavior, device/iCloud backups you control, and other system-level storage.

12. Security

We use a local-first architecture to reduce unnecessary data transfer, but no software environment can be guaranteed to be perfectly secure. You are responsible for securing your device, your Apple Account, your exported files, and your device backup settings (including iCloud Backup).

13. Your choices

You may be able to:

14. Your GDPR rights

If you are in the EU/EEA or GDPR otherwise applies, you have the right to:

For Poland, the supervisory authority is:

Prezes Urzędu Ochrony Danych Osobowych (PUODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl

To exercise your rights, contact us at privacy@bilargo.com. Because App data is stored on your device, we generally cannot access or delete it for you; you can delete it directly on your device.

15. Children

The App is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data through a support or privacy request, contact us at privacy@bilargo.com.

16. Automated decision-making

We do not use personal data for automated decision-making that produces legal or similarly significant effects within the meaning of Art. 22 GDPR.

17. Changes

We may update this Privacy Policy from time to time. If we do, we will update the effective date above and publish the current version at https://exit.bilargo.com/privacy. Where required by law, we will provide appropriate notice.

18. This website

This policy is about the App. The website you are reading it on processes one more thing, and it is worth stating plainly: our hosting provider, Cloudflare, collects standard server logs — IP addresses, request timestamps, and browser user-agent strings — when serving these pages. An IP address is personal data, so here is the full picture. We process it for the security and performance of the site; the legal basis is our legitimate interest, Art. 6(1)(f) GDPR. Cloudflare processes these logs for us, as our processor and on our instructions. On the plan we use, raw request logs are not available to us at all — exporting them is an Enterprise-only feature — and the request-level data we can see, which includes IP addresses, covers the previous seven days and nothing older. We keep no separate copies, and what Cloudflare retains for its own purposes is set out in its own privacy policy. Cloudflare runs a global network: requests are served from its edge servers, while the metadata about those requests is processed in its data centers in the United States and in Europe. Transfers outside the EEA rely on the European Commission's standard contractual clauses in their controller-to-processor module; those clauses form part of Cloudflare's data processing addendum. Cloudflare's Privacy Policy describes its own practices.

This site sets no cookies, runs no analytics, and has no contact forms. Your rights, described above, cover this processing too.

19. Contact

If you have privacy questions, contact:

We keep both language versions — Polish and English — in substantive alignment. For consumers in Poland the Polish version is the binding one.