← Suslik

Privacy Policy

Application: Suslik (Android package ro.suslik.app)
Data controller: Alexe Trofim, Romania
Contact: alexetrofim@gmail.com
Website: https://suslik.ro
Effective date: 17 July 2026

This Privacy Policy explains how the Suslik mobile application ("Suslik", "the app", "we", "us") processes personal data. Suslik is a compliance-first tool for legally authorized metal detectorists in Romania. It shows national RAN/LMI archaeological protected "no-go" zones, LiDAR relief where available, and an optional Premium probability layer, so that authorized users can stay legal and avoid protected sites. The app does not locate treasure or artifacts and does not guarantee any find.


Rezumat in limba romana (Romanian summary)

Aceasta este politica de confidentialitate a aplicatiei Suslik. Textul complet de mai jos este in limba engleza; acest rezumat prezinta pe scurt punctele esentiale.


1. Who we are

The data controller for the purposes of the EU General Data Protection Regulation (GDPR) and Romanian data protection law is Alexe Trofim, based in Romania. You can reach us at alexetrofim@gmail.com regarding any question about this policy or your personal data. Given the limited scope of our processing, we are not required to appoint a Data Protection Officer, but you can direct any privacy question to the contact above.

2. Our approach to privacy

Suslik is designed to collect as little personal data as possible. Version 1 of the app has no user accounts and no login. We do not ask for your name, email address, phone number, or any profile information. We do not use advertising, we do not sell data, and we do not embed third-party tracking or analytics SDKs. Your precise location is processed on your device and is not transmitted to us.

3. What data we process

3.1 Precise location - only during an active session

The app requests access to precise location (ACCESS_FINE_LOCATION). Precise location is used only while you have started a "Sesiune activa" (active session), which runs as a user-initiated Android foreground service. During an active session, precise location is used to:

This location processing happens on your device. The app does not collect location in the background, and this session location is not transmitted to us (it is stored locally, as described in section 3.2). To warn you about protected zones, the app compares your position against the public protected-zone reference data it has downloaded (see section 3.3); this comparison is performed locally on your device and your coordinate is not sent to us. Location processing stops when you end the session. The ongoing foreground-service notification (which requires the POST_NOTIFICATIONS permission) makes it clear when a session is active.

3.2 Data stored locally on your device

Your own waypoints, GPS tracks, finds, and notes are stored locally on your device (in an on-device Room database). This data is not transmitted to us and we have no access to it. If you uninstall the app or clear its data, this information is deleted from your device.

3.3 Map and reference data we serve to the app

The app reads reference map data from our backend API - including RAN/LMI protected zones, probability-layer cells, and pinpoints. This is public reference data served to all users and contains no personal information about you, and the app uses it to warn you about protected zones locally. Requests to this API are made by county area, not by your precise coordinate. Loading this data involves standard network requests over HTTPS.

3.4 Technical data automatically processed by our servers

Like any internet service, when the app connects to our servers to load map/reference data, our hosting and database providers automatically receive and process technical connection data, including your device's IP address, the request time, and basic request metadata (such as the type of request). This is a necessary part of delivering any internet request and is used only to route the response, keep the service secure, and prevent abuse. We do not use this technical data to build a profile of you or to track you across other apps or websites. An IP address can be personal data under the GDPR; where our processors retain it in short-lived security and operational logs, it is kept only for a limited period and then deleted or rotated out.

4. Permissions we use and why

5. Purposes and legal bases (GDPR Article 6)

We do not process special categories of personal data and we do not carry out automated decision-making that produces legal or similarly significant effects on you.

6. Data retention

We do not maintain any server-side database of your location or other personal data.

7. Service providers (processors)

We use the following infrastructure providers strictly as data processors to run the service. They act on our documented instructions and are not permitted to use the data for their own purposes:

We have data processing agreements (GDPR Article 28) in place with these providers, and they may rely on their own vetted sub-processors to deliver their infrastructure. Because these providers act only as processors on our behalf, giving them data to run the service is not a "sale" or a "sharing" of your personal data. We do not share your data with advertisers, data brokers, or any other third parties, and we do not sell your data.

8. International transfers

Our application servers and database are hosted in the European Union (Frankfurt / EU regions), and the service is designed so that personal data is processed within the EU/EEA. Some of our processors (for example, Vercel and Neon) are organisations whose parent entities are located in the United States, and in limited situations (such as support or maintenance) data may be accessed from outside the EEA. Where that is the case, the transfer is covered by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, together with the technical measures described in this policy (EU-region hosting, HTTPS/TLS encryption, and data minimisation). All communication between the app and our servers is encrypted in transit.

9. No advertising, no sale of data, no tracking

Suslik contains no advertising, performs no sale or sharing of personal data for marketing, and includes no third-party analytics or tracking SDKs. We do not build advertising profiles and we do not track you across other apps or websites.

10. Children

Suslik is intended for adults (18 years and older) engaged in a lawful hobby/interest. It is not directed at children and we do not knowingly process personal data of anyone under 18. If you believe a minor has used the app, please contact us and we will address it.

11. Data security

All network communication between the app and our backend uses HTTPS/TLS encryption. Access to our backend infrastructure is restricted. Because the app stores your personal waypoints, tracks, and finds only on your own device and does not transmit your location to us, the amount of personal data exposed to any potential incident is minimised by design. No method of transmission or storage is completely secure, but we take reasonable measures appropriate to the limited data we handle. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and affected individuals without undue delay where the risk is high.

12. Your rights under the GDPR

Subject to the conditions of the GDPR, you have the right to:

Please note an important limitation: because the app has no accounts and we do not receive or store your location or other identifying data on our servers, we generally hold no personal data on our servers that we could link to you. Under GDPR Article 11, where we cannot identify you we may be unable to act on access, rectification, or erasure requests concerning server-side data unless you provide additional information enabling identification. Your on-device data (waypoints, tracks, finds, notes) is always under your own control and can be deleted directly on your device.

13. How to exercise your rights

To exercise any of these rights, or to ask a question about this policy, contact us at alexetrofim@gmail.com. We will respond within the timeframes required by the GDPR (generally within one month).

14. Right to lodge a complaint

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro), or with the supervisory authority in your EU country of residence.

15. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published at https://suslik.ro/confidentialitate, with an updated effective date. Material changes will be reflected here.

16. Contact

Alexe Trofim
Email: alexetrofim@gmail.com
Website: https://suslik.ro
Romania
Effective date: 17 July 2026