Skip to content
MetroRadar

Privacy at MetroRadar

Your data should help you travel — and nothing more.

This policy explains in plain language how the MetroRadar mobile app and metroradar.pl process data, why it is needed and how you can control it.

Last updated: 16 July 2026

We do not sell data

We do not share personal data with advertisers or data brokers.

Location is optional

It is accessed once, only when you choose the nearest-station feature.

You can request deletion

You can delete your account and associated data or ask us to do so.

Data controller

The controller of personal data processed in connection with MetroRadar is Przemysław Królikowski, the creator and operator of the MetroRadar app.

For privacy questions, rights requests or account deletion, email metroalertwarszawa@gmail.com or use the contact form and select “Privacy and personal data”. No data protection officer has been appointed; you can contact the controller directly.

Scope of this policy

This policy covers the MetroRadar mobile app for iOS and Android, metroradar.pl, its contact form and newsletter subscription, as well as correspondence and requests connected with the service.

App Store, Google Play, transport operators and external websites apply their own privacy policies. MetroRadar does not receive full payment-card details when you use an external voluntary-support link.

Data we process

The scope depends on the features you use and the permissions you grant. Not every user provides every category listed below.

The website currently uses no advertising cookies, marketing profiling or the mobile-app analytics described below. A hosting provider may keep short-lived technical logs for security and delivery.

Account and identity

Examplesdisplay name, email address, user ID and, when using Sign in with Apple, an Apple private relay address

Purposeaccount management, settings synchronisation and identifying the author of a report

Travel preferences

Examplessaved routes, favourite stations and lines, selected transport modes, alert and theme settings

Purposepersonalising the app and selecting relevant alerts

Community reports

Examplesreport content and category, line or station, time, verification status and author ID

Purposepublishing, verifying and moderating passenger information

Device and app

Examplesdevice type, operating system, app version, Firebase installation ID and push token

Purposedelivering alerts, security and service operation

Optional location

Examplesapproximate device location accessed once when you choose the nearest-station feature and grant permission

Purposeidentifying the nearest station while you are using the app

Optional usage analytics

Examplesnumber of app opens, number of sessions and time spent using the app

Purposemeasuring app usage and planning improvements, only after separate consent

Optional diagnostics

Examplesapp crash reports and related technical data sent to Firebase Crashlytics

Purposefinding and fixing errors, only after separate consent

Consents and privacy settings

Examplesstatus and version of consent for informational and marketing notifications, plus the status of analytics and Crashlytics consents

Purposeapplying your choices and identifying the version of consent you accepted

Contact and website

Examplesname, email, subject and message; IP address held briefly for rate limiting

Purposereplying to enquiries and protecting the form against abuse

Newsletter subscription

Examplesemail address, selected language, subscription source, consent version and timestamp, subscription status and technical identifier

Purposesending the newsletter and managing confirmation and unsubscribe requests

Purposes and legal bases

We process data to perform the service and contract (Article 6(1)(b) GDPR); on the basis of consent for the newsletter, optional location, optional usage analytics, Firebase Crashlytics crash reporting and informational and marketing notifications (Article 6(1)(a)); for legitimate interests such as security, abuse prevention, moderation and ordinary correspondence (Article 6(1)(f)); and to comply with legal obligations (Article 6(1)(c)).

The newsletter is voluntary and independent of the app account. It becomes active only after email confirmation. Every newsletter includes a link for withdrawing consent and removing the address from the list.

Consents for usage analytics, Crashlytics, and informational and marketing notifications are independent. Refusing any of them does not block the app’s core features. Account data may still be necessary for synchronisation and community features, while routes and stations can be selected manually without location access.

Location and push notifications

In version 2.2.2, the app may request approximate location only while it is in the foreground. Location is accessed once, after you choose the nearest-station feature and grant permission. MetroRadar does not access location in the background, use it for advertising or build a journey history. You can deny or disable the permission and select a station manually.

To deliver disruption alerts, we process a push token assigned to the app installation and your selected routes, lines and stations. Alerts are delivered through Firebase Cloud Messaging and, on iOS, Apple Push Notification service. You can disable them in the app or system settings.

Version 2.2.2 uses a separate, versioned consent for informational and marketing notifications. It is off by default, and these messages are sent only after you enable it. Granting the system notification permission does not itself provide this consent. You can withdraw it in the app and block all notifications in system settings.

Optional analytics and diagnostics

Optional usage analytics starts only after separate consent. It counts app opens, sessions and time spent using the app. Detailed data is retained locally on the device for up to 35 days, while the app backend holds a summary covering the most recent 30 days. It is not used for advertising or marketing profiling.

Firebase Crashlytics is off by default and requires separate consent. Without that consent, the app does not send crash reports to Crashlytics. You can withdraw consent at any time in app settings; withdrawal stops future reports from being sent.

Where data comes from

Data comes directly from you when you register, configure the app, save routes, submit reports, contact us or subscribe to the newsletter; from your device after permission or as part of technical operation; and from authentication and infrastructure providers where needed. Optional analytics data and Crashlytics reports are processed only after the relevant consent.

WTP and operator announcements are aggregated to report disruptions. Do not include another person’s personal data, identity documents or sensitive information in community reports.

Recipients and service providers

We do not sell personal data or provide it to advertisers. Necessary data may be processed by Google Firebase for Authentication, Firestore, Cloud Functions, Hosting and Cloud Messaging; Firebase Crashlytics only after separate consent; Apple for sign-in and iOS notifications; Google for Android services, Play distribution and Gmail; hosting providers; and public authorities or advisers where required by law.

Each provider receives only the data required to deliver its service and acts under appropriate data-protection terms or agreements.

Transfers outside the EEA

Some technology providers may process data outside the European Economic Area, particularly in the United States. Transfers rely on a GDPR-approved mechanism, such as an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses, with additional safeguards where required.

How long data is retained

Account details, routes, stations and preferences are retained until you delete them or close the account. Community reports are retained as needed to operate and preserve incident history, then deleted or irreversibly detached from the account. Push tokens remain until sign-out, feature disablement, account deletion or token inactivity. Optional analytics details remain locally for up to 35 days, and the backend summary covers the most recent 30 days.

An active newsletter address is retained until unsubscribe or withdrawal of consent. An unconfirmed subscription expires after 48 hours and is deleted in the next cleanup cycle, no more than 12 hours later. Correspondence is normally retained for up to 12 months after a case closes. The form IP rate-limit entry stays in server memory for no more than 15 minutes. Operational data is generally deleted or anonymised within 30 days of account deletion; rotating backups expire on their normal cycle.

Account and data deletion

Delete your account from the profile settings in the app. If you no longer have access, email us from the address associated with the account or use the contact form. We may ask you to confirm your identity to protect the account.

Deletion covers the account and directly related data. Data required for law, security or legal claims will be restricted and erased after the applicable period. Anonymous information that can no longer identify a person is not personal data.

The newsletter is independent of the app account. Deleting the account does not automatically unsubscribe the newsletter; use the unsubscribe link in any newsletter or contact the controller.

Delete your account in the app or submit a request

Use the account deletion option in profile settings. If you cannot access the app, contact us from the email address linked to your account.

Your rights

Under the GDPR, you may request access, rectification, erasure, restriction, data portability and, where applicable, object to processing. You may withdraw consent at any time without affecting earlier lawful processing.

You may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). We normally respond within one month; complex requests may lawfully take longer.

Security

We use access controls, authentication, encrypted transmission, least-privilege rules, backups and abuse controls appropriate to the scale and risk of the service. No internet service can guarantee absolute security, so suspected incidents are assessed and handled in accordance with applicable law.

Children

MetroRadar is a general public-transport information service and is not directed at children under 13. We do not knowingly request sensitive information from children. A parent or guardian who believes a child provided unnecessary personal data should contact us.

Changes and contact

We may update this policy when the app, providers or law change. Material changes will be communicated in the app or on the website, and the date above will be updated.

Questions and requests can be sent to metroalertwarszawa@gmail.com or through the contact form.