AirDust Privacy Policy

Last updated: 2026-06-02

This privacy policy describes how AirDust (the Garmin Connect IQ widget and the supporting backend service at airdust.safescanapp.app) collects, uses, and protects personal data, in compliance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Bulgarian Personal Data Protection Act.

1. Data Controller

The data controller responsible for the processing described below is:

AirDust is operated by an individual, not a registered company. There is no separately appointed Data Protection Officer (DPO); contact the controller directly at the email above for any data-protection request.

2. Scope

This policy covers:

Free-tier users who never enter a Pro activation code do not authenticate against the Backend; their device may still issue unauthenticated requests to public sensor APIs (see Section 6).

3. What Data Is Processed

3.1 GPS coordinates

When you use AirDust to look up nearby air-quality sensors, the widget sends your device's current GPS coordinates (or, if you choose, a manually saved location) as query parameters to the Backend. Before any logging, the Backend snaps your coordinates to a coarse grid of approximately one kilometre (1 km) on each side. The unsnapped coordinates are used only transiently in memory to perform the sensor lookup and are never written to disk, log files, or any database.

3.2 Sensor IDs

If you choose the "specific sensor" mode in the widget, the numeric sensor ID you select is sent to the Backend (and onwards to Sensor.Community). Sensor IDs are public information published on maps.sensor.community and are not personal data on their own.

3.3 Activation codes (Pro tier only)

When you redeem a Pro activation code, the 16-character code is sent securely to the Backend along with a device identifier supplied by Garmin. The Backend verifies the code, marks it as used, and returns a long-lived authentication token bound to your device. The activation code itself is redacted in all logs before any log record is written. The authentication token is bound to your device and is long-lived — Pro is a one-time, perpetual purchase, so you never need to re-enter the code; access ends only if the code is revoked (for example after a refund or an erasure request).

3.4 IP address and activation security log

The Backend processes your IP address in two distinct ways during Pro activation:

  1. Transient rate limiting. Your IP address is held briefly in memory to rate-limit activation attempts per IP (a defence against automated abuse of the activation system). These entries exist only in memory and are evicted shortly after your last attempt.
  2. Persistent security audit. Each activation attempt is also written to a server-side security audit log recording the activation code, the Garmin-supplied device identifier, your IP address, your device's User-Agent string, a timestamp, and the outcome (success, code-already-used, invalid-code, rate-limited, or persistence-failure). This log lets the operator detect and investigate abuse of the activation-code system — for example code resale or automated guessing — and is the one place where an IP address is linked to a specific activation code and device. These records are automatically deleted 90 days after they are written, and are erased earlier on a valid erasure request (see Section 9).

The IP address recorded in the general application/request logs (as opposed to this security-audit table) is being minimised — it is truncated before logging so that no full IP address is retained in those operational logs.

3.5 Device identifier transmitted with each Pro API request

The widget sends the Garmin-supplied uniqueIdentifier as a device identifier with every Pro data request — not only during activation. The Backend validates that this identifier matches the one bound to your authentication token on every authenticated request. This device-binding check is a security control required by the Pro service contract. The identifier, being an opaque pseudonymous string assigned by Garmin, appears in hosting request logs (standard 30-day retention) and, for activation attempts, in the activation security log described in Section 3.4 (90-day retention). It is also stored, linked to your issued code, in the device-activation record that enforces the one-device-per-code rule.

3.6 Sensor history (Pro tier)

The Backend maintains a rolling 24-hour aggregate of PM2.5/PM10 samples per approximately 1 km snapped grid cell to power the Pro-tier trend chart. These records are keyed by a snapped coordinate string (e.g. 42.6816_23.3197) and are not linked to any user account, device identifier, or authentication token.

3.7 Email address (Pro tier only)

If you purchase a Pro upgrade, you provide an email address through PayPal at checkout (the homepage checkout or the optional /buy payment page). The Backend uses it to send your activation code automatically via the third-party provider Resend (see Section 6), and stores it together with the issued code so the code can be re-sent if needed and so refunds and legally-required sales records can be handled (see Sections 5 and 9). It is never used for marketing.

3.8 What is NOT processed

AirDust does not collect, process, or transmit:

4. Legal Basis for Processing

Processing activityLegal basis (GDPR Art. 6)
GPS coordinates → sensor lookupLegitimate interest (Art. 6(1)(f))
Activation code submission and token issuePerformance of contract (Art. 6(1)(b))
Email send for activation deliveryPerformance of contract (Art. 6(1)(b))
IP-based rate limiting on the activation endpointLegitimate interest (Art. 6(1)(f))
Activation security/audit log (code, device id, IP, User-Agent, outcome)Legitimate interest (Art. 6(1)(f)) — fraud prevention & service security
Device identifier with each Pro API requestPerformance of contract (Art. 6(1)(b))
Offline payment / refund record retentionLegal obligation (Art. 6(1)(c))

The legitimate-interest balancing test (LIA) for the GPS and the IP/User-Agent/device-id processing is recorded in the operator's internal Record of Processing Activities (ROPA) maintained under Art. 30 GDPR. The ROPA is an internal compliance document, not a published page; a copy is available from the controller on request at airdust.app@gmail.com.

5. Retention Periods

DataRetention
Unsnapped GPS coordinatesNot retained — used in memory only
Snapped (1 km) coordinates in logsUp to 30 days in hosting log retention
Sensor history per grid cellRolling 24 hours, then automatically pruned
Activation codes (used)Indefinitely, to prevent re-use
Authentication tokensLong-lived, bound to your device; valid until the code is revoked
IP addresses (rate-limit table)Up to 10 minutes after the last request
Activation security log (code, device id, IP, User-Agent, outcome)90 days, then automatically pruned; erased earlier on a valid erasure request
Email address (stored with the issued Pro code)Retained for the life of your perpetual Pro entitlement (so the code can be re-sent and the purchase honoured), plus the statutory accounting/tax retention period required of the operator under Bulgarian law after the sale. Erasable on request, except for the minimal transaction record that accounting/tax law requires the operator to keep (see Section 9).

6. Sub-Processors and Third-Party Services

AirDust shares limited data with the following third parties to operate the service. "Snapped lat/lon" means the coarse, approximately 1 km grid coordinate described in Section 3.1 — never your precise position.

RecipientRoleData sharedLocationTransfer safeguard
Sensor.Community e.V. (DE)Source of citizen-run sensor readings (the static global snapshot sends no coordinates; the area/single-sensor fallback sends snapped coordinates or a sensor ID)Snapped coordinates or sensor IDEUNone needed (EU)
Google LLC (US)Primary pollen forecast and weather/UV source (pollen.googleapis.com, weather.googleapis.com, Pro tier)Snapped lat/lonUSEU-US Data Privacy Framework (Google LLC is DPF-self-certified)
Zoomash Ltd / WeatherAPI.com (UK)Fallback weather and UV source (api.weatherapi.com, Pro tier)Snapped lat/lonUKUK adequacy decision
PayPal (Europe) S.à r.l. et Cie, S.C.A. and PayPal, Inc. (US)Payment processing for the Pro upgrade — the in-page PayPal JS SDK (www.paypal.com/sdk/js) and the order create/capture/verify/refund calls to PayPal's global REST API (api-m.paypal.com)Payer email, payment amount, order/capture identifiersEU (Luxembourg) and US (global API + JS SDK)EU-US Data Privacy Framework for the US-routed elements (PayPal, Inc. is DPF-self-certified); EU processing under the Art. 28 DPA
Resend, Inc. (US)Transactional email sending (activation codes)Recipient email, activation codeUSEU-US Data Privacy Framework (Resend, Inc. is DPF-self-certified)
Railway Corp. (US)Hosting of the Backend serviceAll Backend data, transiently in memory and logsUSEU-US Data Privacy Framework (Railway is DPF-self-certified); its Art. 28 DPA also incorporates the 2021 EU Standard Contractual Clauses as a fallback

Processor roles. Sensor.Community, Google LLC, Zoomash Ltd / WeatherAPI.com, Resend and Railway act as processors (or, for the open public data sources, as independent controllers of their own published datasets) for the purposes above. PayPal acts as a processor for the specific payment you instruct the operator to take, and separately as an independent controller for PayPal's own payment-network, anti-fraud, and regulatory purposes, governed by PayPal's own privacy statement. Art. 28 data-processing agreements are held and retained for Resend, Railway and PayPal; the operator maintains an internal DPA register, available from the controller on request.

International transfers. Recipients inside the EU or covered by an adequacy decision (Sensor.Community in Germany; Zoomash Ltd / WeatherAPI.com in the UK) require no additional transfer safeguard. For transfers to the US — Google LLC, Resend, Inc., Railway Corp. and the US-routed parts of PayPal, all of which self-certify to the framework — the operator relies on the EU-US Data Privacy Framework (the European Commission's adequacy decision of 10 July 2023, upheld by the General Court in Case T-553/23 on 3 September 2025), with the 2021 EU Standard Contractual Clauses in each processor's Art. 28 agreement as a standing fallback. Sensor.Community processes data under its own privacy policy (see https://sensor.community/en/privacy/).

AirDust does not use any third-party analytics, advertising, or tracking service.

7. Disclosure of Data

AirDust does not sell, rent, or trade your data. The operator may disclose data only:

8. Security

9. Your Rights Under GDPR

You have the following rights, exercisable at any time by emailing airdust.app@gmail.com. These rights are implemented operationally: the operator runs an admin export-and-erasure path that can locate your data either by your purchase email or by your activation code / device identifier, so you can exercise them even if you no longer have the original email.

The operator will respond to a verified request within thirty (30) days.

10. Security Incidents

In the event of a personal data breach (as defined in GDPR Art. 4(12)), the Operator will:

Breach notifications to the CPDP will include: the nature of the breach; the categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed.

11. Automated Decision-Making

AirDust does not perform any profiling or automated decision-making with legal or significant effects on you (Art. 22 GDPR).

12. Supervisory Authority

The competent supervisory authority for the operator is:

Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd. 1592 Sofia, Bulgaria Phone: +359 2 91 53 518 Email: kzld@cpdp.bg Web: https://www.cpdp.bg

You may also lodge a complaint with the supervisory authority of the EU member state where you reside or where the alleged GDPR breach occurred.

13. Changes to This Policy

The operator may update this policy from time to time. The "Last updated" date at the top of the document reflects the most recent revision. Significant changes (e.g. a new sub-processor or a new processing purpose) will be announced in the widget's in-app changelog and re-published at this URL at least thirty (30) days before taking effect. Continued use of the widget after the effective date constitutes acceptance of the revised policy.

14. Contact

For any privacy-related question, complaint, or rights request:

Ivaylo Minkov — airdust.app@gmail.com