AirDust Privacy Policy
Last updated: 2026-06-02
This privacy policy describes how AirDust (the Garmin Connect IQ widget and the supporting backend service at airdust.safescanapp.app) collects, uses, and protects personal data, in compliance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Bulgarian Personal Data Protection Act.
1. Data Controller
The data controller responsible for the processing described below is:
- Name: Ivaylo Minkov
- Address: Sofia, Bulgaria
- Email: airdust.app@gmail.com
AirDust is operated by an individual, not a registered company. There is no separately appointed Data Protection Officer (DPO); contact the controller directly at the email above for any data-protection request.
2. Scope
This policy covers:
- The AirDust widget installed on your Garmin device.
- The AirDust backend (the "Backend") at
https://airdust.safescanapp.app, which the Pro tier of the widget contacts for sensor data, history, and activation.
Free-tier users who never enter a Pro activation code do not authenticate against the Backend; their device may still issue unauthenticated requests to public sensor APIs (see Section 6).
3. What Data Is Processed
3.1 GPS coordinates
When you use AirDust to look up nearby air-quality sensors, the widget sends your device's current GPS coordinates (or, if you choose, a manually saved location) as query parameters to the Backend. Before any logging, the Backend snaps your coordinates to a coarse grid of approximately one kilometre (1 km) on each side. The unsnapped coordinates are used only transiently in memory to perform the sensor lookup and are never written to disk, log files, or any database.
3.2 Sensor IDs
If you choose the "specific sensor" mode in the widget, the numeric sensor ID you select is sent to the Backend (and onwards to Sensor.Community). Sensor IDs are public information published on maps.sensor.community and are not personal data on their own.
3.3 Activation codes (Pro tier only)
When you redeem a Pro activation code, the 16-character code is sent securely to the Backend along with a device identifier supplied by Garmin. The Backend verifies the code, marks it as used, and returns a long-lived authentication token bound to your device. The activation code itself is redacted in all logs before any log record is written. The authentication token is bound to your device and is long-lived — Pro is a one-time, perpetual purchase, so you never need to re-enter the code; access ends only if the code is revoked (for example after a refund or an erasure request).
3.4 IP address and activation security log
The Backend processes your IP address in two distinct ways during Pro activation:
- Transient rate limiting. Your IP address is held briefly in memory to rate-limit activation attempts per IP (a defence against automated abuse of the activation system). These entries exist only in memory and are evicted shortly after your last attempt.
- Persistent security audit. Each activation attempt is also written to a server-side security audit log recording the activation code, the Garmin-supplied device identifier, your IP address, your device's User-Agent string, a timestamp, and the outcome (success, code-already-used, invalid-code, rate-limited, or persistence-failure). This log lets the operator detect and investigate abuse of the activation-code system — for example code resale or automated guessing — and is the one place where an IP address is linked to a specific activation code and device. These records are automatically deleted 90 days after they are written, and are erased earlier on a valid erasure request (see Section 9).
The IP address recorded in the general application/request logs (as opposed to this security-audit table) is being minimised — it is truncated before logging so that no full IP address is retained in those operational logs.
3.5 Device identifier transmitted with each Pro API request
The widget sends the Garmin-supplied uniqueIdentifier as a device identifier with every Pro data request — not only during activation. The Backend validates that this identifier matches the one bound to your authentication token on every authenticated request. This device-binding check is a security control required by the Pro service contract. The identifier, being an opaque pseudonymous string assigned by Garmin, appears in hosting request logs (standard 30-day retention) and, for activation attempts, in the activation security log described in Section 3.4 (90-day retention). It is also stored, linked to your issued code, in the device-activation record that enforces the one-device-per-code rule.
3.6 Sensor history (Pro tier)
The Backend maintains a rolling 24-hour aggregate of PM2.5/PM10 samples per approximately 1 km snapped grid cell to power the Pro-tier trend chart. These records are keyed by a snapped coordinate string (e.g. 42.6816_23.3197) and are not linked to any user account, device identifier, or authentication token.
3.7 Email address (Pro tier only)
If you purchase a Pro upgrade, you provide an email address through PayPal at checkout (the homepage checkout or the optional /buy payment page). The Backend uses it to send your activation code automatically via the third-party provider Resend (see Section 6), and stores it together with the issued code so the code can be re-sent if needed and so refunds and legally-required sales records can be handled (see Sections 5 and 9). It is never used for marketing.
3.8 What is NOT processed
AirDust does not collect, process, or transmit:
- Your name (other than what you voluntarily put into a PayPal payment note);
- Health, fitness, biometric, or workout data;
- Garmin Connect account information;
- Device sensor data unrelated to GPS (heart-rate, accelerometer, etc.);
- Cookies, browser fingerprints, advertising identifiers, or any third-party analytics signals (see also
cookies-and-trackers.md); - Children's data: AirDust is not directed at users under 16 and the operator does not knowingly process data from minors.
4. Legal Basis for Processing
| Processing activity | Legal basis (GDPR Art. 6) |
|---|---|
| GPS coordinates → sensor lookup | Legitimate interest (Art. 6(1)(f)) |
| Activation code submission and token issue | Performance of contract (Art. 6(1)(b)) |
| Email send for activation delivery | Performance of contract (Art. 6(1)(b)) |
| IP-based rate limiting on the activation endpoint | Legitimate interest (Art. 6(1)(f)) |
| Activation security/audit log (code, device id, IP, User-Agent, outcome) | Legitimate interest (Art. 6(1)(f)) — fraud prevention & service security |
| Device identifier with each Pro API request | Performance of contract (Art. 6(1)(b)) |
| Offline payment / refund record retention | Legal obligation (Art. 6(1)(c)) |
The legitimate-interest balancing test (LIA) for the GPS and the IP/User-Agent/device-id processing is recorded in the operator's internal Record of Processing Activities (ROPA) maintained under Art. 30 GDPR. The ROPA is an internal compliance document, not a published page; a copy is available from the controller on request at airdust.app@gmail.com.
5. Retention Periods
| Data | Retention |
|---|---|
| Unsnapped GPS coordinates | Not retained — used in memory only |
| Snapped (1 km) coordinates in logs | Up to 30 days in hosting log retention |
| Sensor history per grid cell | Rolling 24 hours, then automatically pruned |
| Activation codes (used) | Indefinitely, to prevent re-use |
| Authentication tokens | Long-lived, bound to your device; valid until the code is revoked |
| IP addresses (rate-limit table) | Up to 10 minutes after the last request |
| Activation security log (code, device id, IP, User-Agent, outcome) | 90 days, then automatically pruned; erased earlier on a valid erasure request |
| Email address (stored with the issued Pro code) | Retained for the life of your perpetual Pro entitlement (so the code can be re-sent and the purchase honoured), plus the statutory accounting/tax retention period required of the operator under Bulgarian law after the sale. Erasable on request, except for the minimal transaction record that accounting/tax law requires the operator to keep (see Section 9). |
6. Sub-Processors and Third-Party Services
AirDust shares limited data with the following third parties to operate the service. "Snapped lat/lon" means the coarse, approximately 1 km grid coordinate described in Section 3.1 — never your precise position.
| Recipient | Role | Data shared | Location | Transfer safeguard |
|---|---|---|---|---|
| Sensor.Community e.V. (DE) | Source of citizen-run sensor readings (the static global snapshot sends no coordinates; the area/single-sensor fallback sends snapped coordinates or a sensor ID) | Snapped coordinates or sensor ID | EU | None needed (EU) |
| Google LLC (US) | Primary pollen forecast and weather/UV source (pollen.googleapis.com, weather.googleapis.com, Pro tier) | Snapped lat/lon | US | EU-US Data Privacy Framework (Google LLC is DPF-self-certified) |
| Zoomash Ltd / WeatherAPI.com (UK) | Fallback weather and UV source (api.weatherapi.com, Pro tier) | Snapped lat/lon | UK | UK adequacy decision |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. and PayPal, Inc. (US) | Payment processing for the Pro upgrade — the in-page PayPal JS SDK (www.paypal.com/sdk/js) and the order create/capture/verify/refund calls to PayPal's global REST API (api-m.paypal.com) | Payer email, payment amount, order/capture identifiers | EU (Luxembourg) and US (global API + JS SDK) | EU-US Data Privacy Framework for the US-routed elements (PayPal, Inc. is DPF-self-certified); EU processing under the Art. 28 DPA |
| Resend, Inc. (US) | Transactional email sending (activation codes) | Recipient email, activation code | US | EU-US Data Privacy Framework (Resend, Inc. is DPF-self-certified) |
| Railway Corp. (US) | Hosting of the Backend service | All Backend data, transiently in memory and logs | US | EU-US Data Privacy Framework (Railway is DPF-self-certified); its Art. 28 DPA also incorporates the 2021 EU Standard Contractual Clauses as a fallback |
Processor roles. Sensor.Community, Google LLC, Zoomash Ltd / WeatherAPI.com, Resend and Railway act as processors (or, for the open public data sources, as independent controllers of their own published datasets) for the purposes above. PayPal acts as a processor for the specific payment you instruct the operator to take, and separately as an independent controller for PayPal's own payment-network, anti-fraud, and regulatory purposes, governed by PayPal's own privacy statement. Art. 28 data-processing agreements are held and retained for Resend, Railway and PayPal; the operator maintains an internal DPA register, available from the controller on request.
International transfers. Recipients inside the EU or covered by an adequacy decision (Sensor.Community in Germany; Zoomash Ltd / WeatherAPI.com in the UK) require no additional transfer safeguard. For transfers to the US — Google LLC, Resend, Inc., Railway Corp. and the US-routed parts of PayPal, all of which self-certify to the framework — the operator relies on the EU-US Data Privacy Framework (the European Commission's adequacy decision of 10 July 2023, upheld by the General Court in Case T-553/23 on 3 September 2025), with the 2021 EU Standard Contractual Clauses in each processor's Art. 28 agreement as a standing fallback. Sensor.Community processes data under its own privacy policy (see https://sensor.community/en/privacy/).
AirDust does not use any third-party analytics, advertising, or tracking service.
7. Disclosure of Data
AirDust does not sell, rent, or trade your data. The operator may disclose data only:
- To the recipients listed in Section 6, strictly to deliver the service.
- To comply with a valid legal request from a competent Bulgarian or EU authority.
- To investigate and prevent abuse of the activation-code system (e.g. suspected resale of codes).
8. Security
- All Backend traffic is served over HTTPS (TLS 1.2+).
- Activation-code secrets and token signing keys are stored exclusively as server-side environment secrets and never committed to source control.
- The Backend enforces strict transport security (HSTS) and content-type-sniffing protection on every response.
- Privacy-safe logging is enabled in production. Coordinate-bearing data and activation codes are sanitised before any log line is emitted.
- Administrative access is restricted to the operator and protected by strong authentication.
9. Your Rights Under GDPR
You have the following rights, exercisable at any time by emailing airdust.app@gmail.com. These rights are implemented operationally: the operator runs an admin export-and-erasure path that can locate your data either by your purchase email or by your activation code / device identifier, so you can exercise them even if you no longer have the original email.
- Right of access (Art. 15) and data portability (Art. 20): request a copy of any personal data the operator holds about you. The operator produces a machine-readable export of your records (issued code, purchase email, activation/audit rows) on a verified request, keyed by your email or by your activation code/device.
- Right to rectification (Art. 16): correct inaccurate personal data (e.g. an email address used for activation).
- Right to erasure / "right to be forgotten" (Art. 17): on a verified request — which you can make by email or by supplying your activation code / device identifier — the operator erases the data under its control that is linked to you: your activation email, the device-to-code activation records, and the activation security-log rows (IP, User-Agent, device identifier, code) associated with your code(s). The issued-code record itself is retained but anonymised (email removed) and revoked, kept only as the minimal transaction record that Bulgarian accounting/tax law requires the operator to keep (GDPR Art. 17(3)(b)); revoking the code ends the Pro entitlement on your device(s) at the next refresh. Data held by external processors — PayPal's payment record and Resend's email-delivery log — is governed by their own retention policies; the operator will forward your erasure request to them on your behalf. If you want a refund as well, request it before or together with erasure (see the Refund Policy), because erasure removes the link the operator uses to issue a refund.
- Right to restriction of processing (Art. 18).
- Right to object (Art. 21) to processing based on legitimate interest. Objecting to GPS-based lookups means switching to a manually saved location or a fixed sensor ID; both modes work without sending current coordinates.
- Right to withdraw consent at any time, where consent is the legal basis (currently not used by AirDust — see the table in Section 4).
- Right to lodge a complaint with the supervisory authority (Section 12).
The operator will respond to a verified request within thirty (30) days.
10. Security Incidents
In the event of a personal data breach (as defined in GDPR Art. 4(12)), the Operator will:
- Notify the Commission for Personal Data Protection (CPDP) within 72 hours of becoming aware of the breach, where feasible, per Art. 33 GDPR.
- Notify affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms, per Art. 34 GDPR.
Breach notifications to the CPDP will include: the nature of the breach; the categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed.
11. Automated Decision-Making
AirDust does not perform any profiling or automated decision-making with legal or significant effects on you (Art. 22 GDPR).
12. Supervisory Authority
The competent supervisory authority for the operator is:
Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd. 1592 Sofia, Bulgaria Phone: +359 2 91 53 518 Email: kzld@cpdp.bg Web: https://www.cpdp.bg
You may also lodge a complaint with the supervisory authority of the EU member state where you reside or where the alleged GDPR breach occurred.
13. Changes to This Policy
The operator may update this policy from time to time. The "Last updated" date at the top of the document reflects the most recent revision. Significant changes (e.g. a new sub-processor or a new processing purpose) will be announced in the widget's in-app changelog and re-published at this URL at least thirty (30) days before taking effect. Continued use of the widget after the effective date constitutes acceptance of the revised policy.
14. Contact
For any privacy-related question, complaint, or rights request:
Ivaylo Minkov — airdust.app@gmail.com