Order Offly — free shipping
Offly

App Privacy Policy

How personal data is processed in the Offly mobile app and connected services.

🇬🇧 English version

This is an English translation of the Polish document. Mandatory data-protection rights remain unaffected.

OFFLY APP PRIVACY POLICY Mobile app | Offly Tag | Account | Supabase

Version 2.0 | effective 27 August 2026

This Policy describes the categories of data arising from the available Offly functions and known app configuration. Account data and selected server data are stored in Supabase. System functions such as app blocking, NFC, microphone, calendar, location and notifications operate only within permissions granted by the user.

1. Controller and contact

The controller is Szymon Bocianowski, Aleja Jerzego Waszyngtona 57, Warsaw, Poland, support@offly.store, +48 511 318 352 (“Offly” or the “Controller”). Offly is operated by an individual intending to register a business after exceeding the threshold under the Polish Entrepreneurs’ Law. The same individual will remain controller after registration and the details will be updated. Contact support@offly.store about privacy, rights or account deletion. No data protection officer has been appointed because no obligation has been identified at this stage.

2. Scope

This Policy applies to the Offly mobile app, user Account, Offly Tag and NFC functions, offly.store, product sales, subscriptions, technical support and communications. Apple, Google, Supabase, payment providers, carriers and other third parties may apply their own privacy policies where they act as separate controllers. The Store Privacy Policy separately covers ordering and Shop cookies.

3. How

Offly processes data

Offly combines local device functions with server functions; not everything shown in the App is sent to a server. Supabase may store Account, authentication and other data required for selected server functions. App blocking uses operating-system controls such as Family Controls/Screen Time or Android equivalents; Offly does not need message content, passwords or the contents of blocked apps. The Tag communicates through NFC, and technical tag/pairing identifiers may be processed locally or associated with the Account where a pairing function requires it. Sleep functions may use the microphone to detect snoring, sleep talking or coughing; raw audio is intended to be processed locally and not uploaded to Supabase. Calendar data may show daily events and location may support local functions such as post-alarm weather; Offly does not create a location history in normal operation. Notifications are used for alarms, reminders, sessions and service messages.

4. Categories of personal data

Account and authentication data may include an internal user identifier, email address, name or alias, authentication-provider identifiers, account status, creation dates and security metadata. Login through Apple or Google may provide the fields selected or made available by that provider.

App and settings data may include language, time zone, alarm and schedule settings, selected apps or categories to block, focus-session settings, notification preferences, paired Tag identifiers and user choices. Technical data may include device model, operating system and App versions, IP address, event timestamps, crash and diagnostic data, server logs and security information.

Support and complaint data may include correspondence, attachments, device details and issue history. Purchase and subscription data may include product, status, period, transaction identifier and information supplied by Apple, Google, Stripe or another provider; Offly normally does not receive full payment-card details. Store, delivery and Custom data are primarily covered by the Store Privacy Policy.

5. Data processed locally

Selected app selections, schedules, screen-time controls, locally produced sleep indicators and other functional information may remain on the Device. Exact storage depends on the operating system, App version and enabled functions. Deleting the App, resetting the Device or a storage failure may remove local data. Data are sent to Supabase only where a server function, Account synchronisation, security or support process requires it and the App is configured accordingly.

6. Microphone and sleep functions

The App asks for microphone access only when a function requiring it is enabled and the user grants system permission. The microphone may detect sounds such as snoring, sleep talking or coughing. Raw sound is designed to be analysed locally and not used for advertising or AI training. Offly may retain local results or indicators needed to show sleep history. Users can refuse or revoke permission in system settings; the affected feature may then stop working. Offly is not a medical device and these indicators are not a diagnosis.

7. Calendar, location, photos and notifications

Calendar permission may be used to display events relevant to a day or alarm. Location permission may support location-dependent functions, such as local weather; continuous tracking and standard location-history creation are not intended. Photo or file access is used only when the user chooses content for a feature, support request or Custom project. Notifications support alarms, reminders, sessions and service communications. Permissions can be managed in the Device settings, although disabling them may limit the corresponding function.

8. Supabase

Supabase provides backend, database and authentication infrastructure and acts as a processor for Offly project data. Stored data may include Account, authentication, server settings, pairing identifiers, subscription status, consent records, technical logs and other information necessary for enabled functions. The primary project region depends on Offly’s configuration. Supabase provides a data processing agreement and may use subprocessors. Transfers outside the EEA use safeguards required by the GDPR.

9. Purposes and legal bases

Account creation, app functions, synchronisation, pairing, support and paid services are processed to perform the user contract or take requested pre-contract steps under Article 6(1)(b) GDPR. Legal, tax and accounting obligations use Article 6(1)(c). Security, abuse prevention, service improvement, evidence and claims rely on Offly’s legitimate interests under Article 6(1)(f), balanced against user rights. Optional marketing and non-essential analytics use consent under Article 6(1)(a) and applicable electronic-communications law. Device permissions are also governed by operating-system mechanisms and applicable confidentiality rules; granting a permission does not create an unlimited right to process data.

10. Retention

Account and server data are retained while the Account exists and afterwards only for deletion processing, claims, security or legal obligations. Subscription and transaction records follow statutory and claims periods. Support and complaint records remain until resolution and for the relevant claims period. Security logs are kept for a risk-appropriate period. Consent records may be kept to prove consent and withdrawal. Local data remain until deleted by the user, the App or the operating system. Limited data may remain temporarily in rotating backups.

11. Sign-in with

Apple and Google

If enabled, Apple or Google authenticates the user and may provide an identifier, email address and name according to the user’s selection and provider rules. Those providers act under their own notices for their independent processing. Offly receives only the information required for login and Account operation.

12. Payments and subscriptions

Apple App Store, Google Play, Stripe or another indicated provider may process payment and subscription data as an independent controller or processor according to its role. Offly normally receives status, product, period and transaction identifiers, not the full card number or authentication data. Deleting the Account or App does not necessarily cancel a subscription billed by an app store; cancellation must be completed through the provider where required.

13. Recipients

Data may be shared as necessary with Supabase; Apple and Google; payment and app-store providers; hosting, email, security, analytics and support providers actually enabled; professional advisers; and authorities where required by law. Offly does not sell user data as a marketing database.

14. Transfers outside the EEA

Providers or subprocessors may process data outside the EEA. Offly uses mechanisms appropriate to the transfer, including adequacy decisions, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses with supplementary safeguards. A selected European data region does not guarantee that no authorised support or subprocessor access occurs from another country.

15. Cookies, local storage and SDKs

The website and App may use cookies, Device storage and SDKs. Essential technologies support login, security, preferences and requested functions. Non-essential analytics or marketing tools are activated only when a legal basis and any required consent exist. The exact tools may change with App configuration and will be described in the current notice or consent interface where required.

16. Marketing

Marketing messages are sent only where permitted, normally after voluntary consent. Consent can be withdrawn at any time without affecting earlier processing. Service messages necessary for an Account, transaction, security or material terms change are not marketing.

17. User rights

Subject to statutory conditions, users may request access, a copy, rectification, erasure, restriction and portability, and may object to legitimate-interest processing or withdraw consent. Users may complain to the President of the Polish Personal Data Protection Office or another competent authority. Requests may be sent to support@offly.store; Offly may verify identity where necessary.

18. Account and

Supabase data deletion

Users may request Account deletion through an in-app function, if available, or at support@offly.store. Deletion covers Account and associated server data unless retention is required by law, necessary for claims or security, or the data have been irreversibly anonymised. Local Device data may require deleting the App or using system/App controls. Account deletion does not automatically cancel external subscriptions.

19. Security

Offly uses measures appropriate to risk, including access controls, encrypted connections, authentication controls, least privilege and provider safeguards. No system is completely secure. Breaches are handled under the GDPR, including notification where statutory thresholds are met.

20. Children and minors

The Offly Tag is not a toy and must be kept away from small children. Minors may use the App only as permitted by law and, where required, with consent of a parent or guardian. Offly does not intentionally design standard operations to collect unnecessary data from children.

21. Profiling and automated decisions

Offly does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for users. Providers may use automated security and fraud controls under their own rules. If Offly introduces qualifying automated decision-making, it will provide the information and safeguards required by law.

22. Changes

This Policy may change because of law, App functions, system permissions, suppliers or security requirements. The current version and effective date will be published in the App or at offly.store. Material changes will be communicated where required, and new consent will be sought before processing that requires it. Effective date: 27 August 2026.

23. Privacy essentials

Account and selected server data may be stored in Supabase. App blocking works through operating-system controls and does not require access to message content or passwords. Raw audio used by enabled sleep detection is intended to remain on the Device. Calendar, location, photos, NFC and notifications are used only within granted permissions and for the enabled function. Users can manage permissions, request Account deletion and exercise GDPR rights at support@offly.store.