Privacy policy
Effective date and last updated: August 24, 2026
Umbrabyte Apps is the independent mobile software studio and trade name operated by Cristian Donet Segura (NIF: 20468489F, D-U-N-S® 374071851, CNAE 6201), an individual software developer operating from Calle Pintor Camarón, nº 24, 12560 Benicasim, Castellón, Spain. This privacy policy explains how we collect, use, store, and protect personal data across this website (https://umbrabyte.app) and governs our studio-wide privacy standards for our mobile applications.
Plain language summary: Umbrabyte Apps builds focused, offline-first mobile applications designed on the principle of Privacy by Architecture. We do not require user accounts, do not operate cloud backends to intercept your documents, files, or habits, include zero intrusive advertising SDKs, and never sell, rent, or trade your personal information. Each application operates primarily locally on your device.
Data controller
The data controller for personal data processed through this website and studio support channels is:
- Full Name: Cristian Donet Segura
- Trade Name: Umbrabyte Apps
- Registered Address: Calle Pintor Camarón, nº 24, 12560 Benicasim, Castellón, Spain
- Tax ID (NIF): 20468489F
- D-U-N-S® Registered Number: 374071851
- Privacy & Support Contact: support@umbrabyte.app
- Official Website: https://umbrabyte.app
Information we collect
1. Website visitors and communications
- No account required: You do not need to create an account, log in, or provide personal credentials to browse our website.
- Direct email contact: When you email us at our official contact address, we receive your email address, your name (if included in your email client), and the content of your message. This data is used solely to respond to your inquiry.
- Local preferences: The website stores your chosen language in your browser’s
localStorage. This is strictly necessary to display content in your language and is never transmitted to our servers.
2. Mobile applications overview
Our applications—including PDF Scanner, Oasis Minimalist Launcher, Calendario Turnos, AR Ruler: 3D Tape Measure, ControlTV: Smart TV Remote, and DoneTrue—operate on a Local-First architecture:
- Data is processed on your device hardware (CPU/GPU/NPU).
- Personal databases, documents, measurements, and preferences remain in the private Android application sandbox.
- For detailed, application-specific disclosures, please refer to each application’s dedicated in-app and store privacy policy.
Legal basis for processing (GDPR / LOPDGDD)
Under Article 6 of the General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD), our processing activities rely on the following legal bases:
| Processing Activity | Legal Basis under GDPR | Description |
|---|---|---|
| Answering email inquiries & technical support | Art. 6(1)(b) & Art. 6(1)(f) | Performance of pre-contractual/contractual steps and our legitimate interest in providing effective customer assistance |
| Storing language preference in browser | Art. 6(1)(f) | Legitimate interest in delivering a functional, localized user experience (strictly necessary) |
| Optional website analytics (Google Analytics) — if opted in | Art. 6(1)(a) | Explicit consent granted via the website cookie/consent banner |
| Optional advertising measurement (Google Ads) — if opted in | Art. 6(1)(a) | Explicit consent granted via the website cookie/consent banner |
| Mandatory statutory accounting and tax compliance | Art. 6(1)(c) | Compliance with legal obligations under Spanish and EU tax and commercial law |
Retention periods
| Category of Data | Retention Period | Criteria |
|---|---|---|
| Customer support correspondence | Up to 3 years from the date of the last communication | Retained to resolve inquiries, handle follow-ups, and defend against potential legal claims |
Browser language preference (localStorage) |
Until cleared by the user in browser settings | Strictly local storage on user’s device |
| Consented analytics data (Google Analytics) | Up to 14 months (standard Google Analytics retention) | Deleted automatically upon expiration or immediately upon withdrawal of consent |
| Statutory billing & transaction records | 5 to 10 years | Maintained by Google Play and Umbrabyte in compliance with tax and commercial statutory periods |
How we use information
We use the minimal personal data we collect strictly to:
- Respond to your inquiries, bug reports, and customer service requests.
- Ensure the stability, security, and technical availability of our website and applications.
- Comply with applicable legal, fiscal, and regulatory obligations.
Strict Guarantee: We do not sell, rent, lease, or monetize your personal data. We do not engage in automated individual decision-making or behavioral profiling.
Third-party services and international transfers
Our website is hosted on modern, secure content delivery networks (Cloudflare / GitHub Pages) utilizing encrypted connections (TLS 1.3 / HTTPS). Where data is transferred outside the European Economic Area (EEA), such transfers are governed by the European Commission’s Standard Contractual Clauses (SCCs) or adequacy decisions.
- Google Play & Google Services: Distribution and billing for our mobile apps rely on Google Play. Google processes transactions under the Google Privacy Policy and Google Play Terms of Service.
- Google Consent Mode v2: On our website, optional analytics and advertising tags are kept in a strict denied state by default until you explicitly consent via our consent banner.
Cookies and similar technologies
This website does not use tracking cookies by default. It uses browser localStorage solely to preserve your preferred interface language.
If optional analytics (Google Analytics) or conversion measurement (Google Ads) are enabled in a deployment, you are presented with a clear consent banner. You may customize, accept, or reject non-essential cookies at any time via the Cookie preferences link in the footer.
Data security
We implement rigorous technical and organizational security measures to protect personal data:
- Complete end-to-end transport encryption (TLS 1.3 / HTTPS).
- Sandboxed local execution on mobile devices with hardware-backed encryption.
- Continuous vulnerability monitoring and code quality auditing.
Your rights worldwide
Regardless of where you reside, we respect and facilitate your privacy rights:
1. European Union & Spain (GDPR / LOPDGDD)
Under GDPR Articles 15 to 22, you have the right to:
- Access (Art. 15): Request confirmation and a copy of personal data we hold about you.
- Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Erasure (“Right to be Forgotten”, Art. 17): Request deletion of your personal data.
- Restriction of Processing (Art. 18): Request limitation of processing under statutory conditions.
- Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw Consent (Art. 7(3)): Withdraw previously given consent at any time.
- Lodge a Complaint: You have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at https://www.aepd.es or your national supervisory authority.
2. United States & California (CCPA / CPRA / CalOPPA)
- Notice of Collection: We collect only contact emails voluntarily provided and technical language preferences.
- Do Not Sell or Share: We do not sell personal information and do not share personal information for cross-context behavioral advertising.
- Global Privacy Control (GPC): We honor GPC and Do Not Track signals.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
3. United Kingdom (UK GDPR & DPA 2018)
UK residents hold comprehensive privacy rights enforceable through the Information Commissioner’s Office (ICO) at https://ico.org.uk.
4. Brazil (LGPD - Lei Geral de Proteção de Dados)
Brazilian residents may exercise their rights of access, correction, anonymization, blocking, deletion, and consent revocation under Article 18 of Law 13.709/2018, with recourse to the ANPD.
5. Canada, Australia, Japan & South Korea
We honor statutory privacy rights under Canada’s PIPEDA, Australia’s Privacy Act 1988 (Australian Privacy Principles), Japan’s APPI, and South Korea’s PIPA.
To exercise any right, email us at support@umbrabyte.app. We respond to verified requests within 30 days.
Children’s privacy
Our website and applications are designed for a general audience and professional use. We do not knowingly collect personal data from children under 13 years of age (COPPA) or under 16 years of age (GDPR Article 8 / Spanish LOPDGDD Article 7). If you believe a child has provided us with personal data, contact us immediately and we will promptly delete it.
Changes to this policy
We may update this privacy policy periodically to reflect product updates, new features, or legislative changes. The revised policy will be posted on this page with an updated “Effective date”. We encourage periodic review.
Contact
For privacy questions or rights requests, contact:
Cristian Donet Segura — Umbrabyte Apps
Calle Pintor Camarón, nº 24
12560 Benicasim, Castellón, Spain
Tax ID (NIF): 20468489F
D-U-N-S® Number: 374071851
Email: support@umbrabyte.app
Website: https://umbrabyte.app
Kérdései vannak a magánéletével kapcsolatban?
Ha kérdése van az adatkezeléssel kapcsolatban, vagy élni kíván jogaival, forduljon hozzánk közvetlenül.