Mesura
English

Privacy Policy

Last updated

Mesura is a construction calculator built for people who work on site, which means it is built to work offline. Almost everything you put into it — your projects, measurements, notes and saved calculations — stays on your phone and is never sent to us.

This policy explains exactly what the app does with data, who else is involved, and how to exercise your rights. It covers the Mesura mobile app for iOS and Android.

Who is responsible for your data

Mesura is published by Vladislavs Petkuns, an individual developer. Under the EU General Data Protection Regulation (GDPR) and the UK GDPR that makes Vladislavs Petkuns the data controller for the limited personal data described here.

You can reach us at any time at mesura.app@gmail.com.

We have not appointed a Data Protection Officer, because a one-person operation processing this little pseudonymous data is not required to have one. Writing to the address above reaches the person responsible.

What stays on your device

The following never leaves your phone unless you deliberately export or share it. It lives in a private database inside the app's own storage area, which the operating system keeps isolated from other apps.

We cannot see any of it. There is no account to sign in to, no cloud sync operated by us, and no server of ours that this data is sent to.

Your device's own backup system is a separate matter: an iCloud or Google backup of your phone can include the app's database. That backup is governed by Apple's or Google's terms, not by this policy.

What leaves your device

Three Google (Firebase) services, one product-analytics service and one purchase service receive data. None of them receives anything you type into a calculator.

Usage analytics — Google Firebase Analytics

We record a deliberately small set of events so we can tell which calculators are worth improving: that a calculation was completed and which calculator it was, that a result was saved or exported, that a list item was added, that the upgrade screen appeared and whether a purchase or restore followed, that the plain calculator or the spirit level was used, and how far you got through the first-run introduction. Every parameter is a fixed label from a short list — a calculator type, a screen name, a count — never a value you entered, and never the contents of a project.

Alongside those events, Firebase Analytics automatically collects standard technical information: a randomly generated app instance identifier, your device model and operating system version, the app version, your language and country, and an approximate location (typically city level) derived from your IP address. Google does not retain the full IP address for analytics purposes.

That identifier belongs to this installation of Mesura. It is not your Apple ID or Google account, it is not the device advertising identifier, and it cannot follow you into other companies' apps. Reinstalling the app produces a new one.

Product analytics — PostHog

The same short list of events described above is also sent to PostHog, a product-analytics service. It receives the event names and their fixed labels, an anonymous identifier generated for this installation, your device model and operating system, the app version, and an approximate location (typically city level) derived from your IP address. It receives nothing you type into a calculator.

This data is stored on PostHog's European cloud, hosted in the European Union. Session replay — the feature that would record what is on your screen — is deliberately switched off, because it would send the quantities and prices you enter to a third party. As with Firebase, these events are collected only in released versions of the app.

Crash reports — Google Firebase Crashlytics

When the app crashes or hits an unexpected error we receive a report: the error type and stack trace, the app and operating system version, the device model, and device state at that moment such as available memory and whether the device is rooted or jailbroken. Reports are tied to a random installation identifier, not to you.

Reports also carry short diagnostic log lines that the app writes about its own operations — for example that a purchase check failed. These are written by us and describe the app, not your content.

Remote configuration — Google Firebase Remote Config

On launch the app fetches a small configuration file from Google — for instance the oldest app version we still support, so we can prompt you to update after a breaking change. The request carries an installation identifier and app and device details. It carries nothing about your projects.

Purchases — RevenueCat, Apple and Google

Mesura Pro is a single one-time purchase. Payment is taken by Apple or Google, never by us: we never see your card number, billing address or full name.

To confirm a purchase is genuine and to let you restore it on another device, purchase receipts are processed on our behalf by RevenueCat, Inc. (United States). RevenueCat assigns your installation an anonymous identifier and stores the receipt, the product bought, the purchase and any refund date, the store country, and basic app and device information. What we see is anonymous customer records and aggregate revenue — not your identity.

Apple and Google also process the transaction under their own privacy policies, as independent controllers.

The review prompt

After you have saved a few calculations the app may ask the operating system to show Apple's or Google's own "rate this app" dialog. That dialog is drawn and handled entirely by the store. We are not told whether it appeared, whether you rated the app, or what you said.

The spirit level and your device sensors

The spirit level reads your device's accelerometer — the same sensor that rotates your screen. On both iOS and Android this needs no permission, and it reveals nothing about your location or your surroundings.

Readings are used to draw the bubble in real time and are discarded immediately. They are never stored and never transmitted. The only thing recorded is that the level was opened.

What we never collect

Sharing and exporting is your decision

Mesura can produce a PDF or hand a summary to your device's standard share sheet. When you do that, the file goes wherever you send it — email, a messaging app, cloud storage — and is then handled by that service under its own terms. The file is generated on your device and does not pass through us.

Why we are allowed to process this

For people in the EEA and the UK, our legal bases under Article 6(1) GDPR are:

Who else receives data

The complete list of recipients:

There is no one else. We do not sell data, we do not pass it to advertisers or data brokers, and we do not use it to build profiles about you.

These providers may process data in the United States and other countries outside the EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Ask us and we will tell you which safeguard applies.

How long data is kept

Your choices and rights

If you are in the EEA or the UK you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out.

In practice most of what Mesura holds sits on your device and is under your direct control — you can view, edit, export and delete it inside the app without asking us for anything.

Stopping analytics and crash reporting

Mesura does not currently offer an in-app switch for analytics. Uninstalling the app ends all collection immediately, and the data already collected expires under the retention periods above. If you would like collection stopped while continuing to use the app, write to us and we will tell you the options for your platform.

Making a request

Email mesura.app@gmail.com. We reply within one month, as Article 12(3) GDPR requires. Be aware that analytics and crash data are pseudonymous: we usually cannot connect them to a named person, and where we cannot identify you from the data we hold we will say so, as Article 11 GDPR allows.

You also have the right to complain to your local data protection authority. In Latvia that is the Data State Inspectorate (Datu valsts inspekcija), dvi.gov.lv.

Children

Mesura is a professional tool for construction work. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has provided personal data through the app, contact us and we will delete it.

Security

Data on your device is protected by the operating system's app sandbox and, on a device with a passcode set, by full-device encryption. Data travelling to our providers is encrypted in transit with TLS.

No system is perfect. We keep the risk small mainly by not holding your data in the first place.

If you are in California or another US state

We do not sell personal information and we do not share it for cross-context behavioural advertising, as the California Consumer Privacy Act defines those terms. We do not collect sensitive personal information.

California, Colorado, Connecticut, Utah, Virginia and similar state laws give you rights to know, delete and correct. Use the contact details below and we will honour them as far as pseudonymous data allows.

Changes to this policy

If we change how Mesura handles data we will update this page and the date at the top. For a material change — a new category of data, a new recipient, a new purpose — we will tell you in the app before it takes effect.

Earlier versions are available on request.

Contact

Vladislavs Petkuns

Email: mesura.app@gmail.com

We aim to answer within a few working days, and within one month at the latest.