Privacy
SanAlert works without accounts, without cookies and without analytics. Below is everything that happens to data when you use the website sanalert.pl.
Who is responsible for the data
The controller is Applied AI sp. z o.o., ul. Marcina Bielskiego 44C lok. 15, 37-700 Przemyśl, Poland, entered in the register of entrepreneurs of the National Court Register (KRS) kept by the District Court in Rzeszów, 12th Commercial Division, under KRS number 0001187092, tax number (NIP) 7952588091.
For anything about privacy, write to [email protected].
Your place stays on your device
- The place you set is stored only in your browser's storage. We do not send it to our server or to anyone else.
- When you press "Use my location", your browser and system work out the position, after the consent you give in the browser. The position stays on this device.
- The level for your place is worked out by your browser. From our server it fetches the same situation report every visitor gets, so the request does not contain your location.
- You remove the saved place with "Change place", or by clearing this site's data in the browser.
- One exception, and only on your say-so: for a place in Poland we show the link "Shelter points nearby". Pressing it opens the government site gdziesieukryc.pl (the Ministry of the Interior and Administration and the State Fire Service) with the coordinates of your place in its address, so the map opens on your area. Until you press it nothing leaves the device; after that, the data is handled by that site under its own rules. We keep no shelter register of our own.
- The shelter points nearest your place are found by your device. The website and the app fetch from our server the whole official register of shelter points that the State Fire Service headquarters (KG PSP) publishes on dane.gov.pl (the same file for everyone, refreshed weekly), so the request does not contain your place. The app keeps the file in the phone's storage so that the list works without the internet too. When you press "Route" next to a point, Apple Maps opens with that point's coordinates; the route from where you are is then worked out by Apple under its own rules.
- "Tell your family" writes a message on your device: the name of the place, the level with its time, and a link to that place on sanalert.pl. You send it yourself, with the app you choose; nothing reaches us. The place's coordinates are in the link after the # sign, and browsers never send that part of an address to any server, ours included. Whoever opens the link sees that place on their own device and can save it.
- The SanAlert app for iPhone stores your places (at most three, for example home, work and school) in the phone’s storage under the same rules: it does not send them to our server or to anyone else. If you switch notifications on, only the numbers of the squares go to the server, see "Notifications in the app".
- The SanAlert widget on the home screen and on the lock screen reads those same places from the phone’s storage, which it shares with the app, and sends them nowhere either. It works out the level the way the app does: it fetches the same situation report everyone gets, so the request does not contain your place. It does that every several minutes, including while the app is closed, and it always writes how old the data behind it is.
- If you have an Apple Watch with the SanAlert app, the phone passes those same places, and the language chosen in the app's settings, to it directly, over Apple’s connection between the iPhone and the watch paired with it, not through our server. You can also choose places (from the list of towns) and the language on the watch itself, with or without an iPhone; the latest choice holds, whichever of the two devices you made it on, and a choice made on the watch does not go back to the phone. The watch keeps them in its own storage, which it shares with the complication on the watch face, and sends them nowhere; it does not use your location for this. The watch app and the complication work out the level the way the widget does: they fetch the same situation report everyone gets, so the request does not contain your place.
- The SanAlert app for the Mac shows the level in the menu bar. You choose its places (up to three) in the app, from the list of towns; it keeps them only on that Mac, sends them neither to our server nor to anyone else, and does not use your location. It works out the level the way the iPhone app does: it fetches the same situation report everyone gets, so the request does not contain your place. It does not connect to your phone or watch. If you allow it notifications, it shows one itself when the level at one of your places rises: it works that out on the Mac, from the same report, and our server knows nothing of it and keeps nothing for it.
- The SanAlert integration for Home Assistant, if you install it, keeps the place in your Home Assistant and works out its level there: it fetches from our server the same situation report everybody gets, so the request does not contain your place. When you add a place it fetches the public grid of squares once, to find the voivodeship; that stays with you too. We store nothing for it.
- The SanAlert app for Android stores your places (at most three) in the phone’s storage under the same rules as the iPhone app: it does not send them to our server or to anyone else, and they are not part of Android’s cloud backup. You choose a place from the list of towns, with a tap on the map, or with "Use my location": then the phone’s system works out the position once, after you allow it (Android’s location service; on many phones Google’s location services run in it, under their own rules), and the app keeps it only on the phone. The app works out the level itself: it fetches from our server the same situation report and the same register of shelter points everyone gets, so no request contains your place. Its map is only our schematic map, with no map provider at all. "Route" next to a shelter point hands that point’s coordinates to the maps app on your phone (for example Google Maps), which then works out the route under its own rules. If you switch notifications on in it, only the numbers of the squares go to the server, see "Notifications in the Android app".
- If you have a Wear OS watch with the SanAlert app, the Android app passes it those same places and the language chosen in its settings, not through our server but through the Google Play services that connect the phone and the watch: directly over Bluetooth, and when Bluetooth is not available, through Google’s servers, end-to-end encrypted. You can also choose places (from the list of towns) and the language on the watch itself, with or without the phone; the latest choice holds, whichever of the two devices you made it on, and a choice made on the watch does not go back to the phone. The watch keeps them in its own storage, which it shares with the complication on the watch face, sends them nowhere and leaves them out of Android’s cloud backup; it does not use your location for this. The watch app and the complication work out the level the way the widget does: they fetch the same situation report everyone gets, so the request does not contain your place.
- The SanAlert app for Garmin watches keeps the places you choose on the watch from the list of towns (at most three), and the language chosen there, only in the watch’s own storage. It does not use your location, does not connect to the SanAlert apps on your phone and sends the places nowhere. The watch works out the level itself: it fetches the same short situation report everyone gets and finds its places in it, so the request does not contain your place. The watch sends the request over Bluetooth to the Garmin Connect app on your phone, which passes it on; a watch with Wi-Fi or LTE may send it itself.
- You can ask Siri for the level at your place, or run the “Level at my place” shortcut in the Shortcuts app, in Spotlight or with the Action button. The app on the phone prepares the answer, as the widget does: it reads the place from the phone's memory and fetches from our server the same situation report everybody gets, so the request does not contain your place. The answer, with the place's name, voivodeship and level, is shown or read out by your phone's system.
- The same browser storage keeps your display settings: light or dark mode, the kind of map, and whose machines the map shows. They do not leave the device either.
Notifications in the app
Notifications are sent by the SanAlert app for iPhone, only if you switch them on there. The sanalert.pl website sends its own, under the rules described below in "Notifications on the website", and the Android app under those in "Notifications in the Android app".
- When you switch notifications on, three things reach our server: the address at which Apple delivers notifications to your copy of the app (the token), the numbers of the squares, about 11 km on a side, that your places lie in (the app keeps at most three), and the level from which you want to be notified. Your exact position does not leave the phone.
- We do not record your IP address, the name of your device or anything that says who you are. The token alone does not let us identify you.
- Apple delivers the notification (the Apple Push Notification service). In doing so Apple sees the token and the content of the notification, for example "Approaching".
- We delete this data when you switch notifications off in the app, when Apple reports that the token no longer works (for example after the app is removed), and always after 60 days in which the app has not refreshed the record.
- The "Send a test notification" button asks our server for one notification to the same token, to check that notifications get through. Nothing new is stored. What the app checks in the phone's settings (permission for notifications, time-sensitive notifications, the scheduled summary), and the time of the last SanAlert notification, which the phone remembers for this check, do not leave the phone.
- The basis is your consent, which you give by switching notifications on (Article 6(1)(a) of the GDPR). You can withdraw it at any time by switching notifications off in the same place in the app (Article 7(3) of the GDPR). Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Notifications in the Android app
The SanAlert app for Android sends notifications only if you switch them on in it and allow them on the phone. They work under the same rules as in the iPhone app; Google delivers them.
- Until you switch them on, the app does not start Google's notification service (Firebase Cloud Messaging) and does not contact us or Google about notifications.
- When you switch them on, the phone gets from Google the address at which Google delivers notifications to this app (the registration token), and three things reach our server: that token, the numbers of the squares, about 11 km on a side, that your places lie in (the app keeps at most three), and the level from which you want to be notified. Your exact position and the names of your places do not leave the phone.
- We do not record your IP address, the name of your device or anything that says who you are. The token alone does not let us identify you.
- Google delivers the notification (Firebase Cloud Messaging, through Google Play services on the phone). In doing so Google sees the token and what the notification carries: the number of the square, the level and its reason (for example a drone, about 61 km, about 20 minutes), the time of the data and, when it is quiet again, whether an RCB or RSO message is still in force. The notification carries no finished text: the phone writes the words, in the language chosen in the app.
- We delete this data when you switch notifications off in the app (the phone then also asks Google to delete the token), when Google reports that the token no longer works (for example after the app is removed), and always after 60 days in which the app has not refreshed the record. The app refreshes it when you open it, while notifications are on.
- The "Send a test notification" button asks our server for one notification to the same token, to check that notifications get through. Nothing new is stored. What the app checks in the phone's settings (permission for notifications, sound), and the time of the last SanAlert notification, which the phone remembers for this check, do not leave the phone.
- The basis is your consent, which you give by switching notifications on (Article 6(1)(a) of the GDPR). You can withdraw it at any time by switching notifications off in the same place in the app (Article 7(3) of the GDPR). Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Notifications on the website
The sanalert.pl website can send notifications to your browser, only if you switch them on with the button beside your place and allow them in the browser's prompt. On iPhone and iPad this works only after the site has been added to the home screen.
- When you switch them on, the browser installs a small script of the site (a service worker) that only shows incoming notifications. Our server then receives: the address at which your browser's push service delivers notifications to it, two keys with which we encrypt their content, the number of the roughly 11 km square your place lies in, and the level from which you want to be notified. Your exact position does not leave the browser.
- We do not record your IP address, the type of browser or anything that says who you are.
- The notification is delivered by the push service your browser uses: Google (Chrome, Edge on Android and other Chromium-based browsers), Mozilla (Firefox), Apple (Safari) or Microsoft (Edge on Windows). We encrypt the content so that this service cannot read it; it sees the address it delivers to, and when.
- We delete this data when you switch notifications off on the website, when the push service reports that the address no longer works (for example after the site's data is cleared in the browser), and always after 60 days in which the website has not refreshed the record. The website refreshes it when you visit while notifications are on.
- The "Send a test notification" button asks our server for one notification to the same address, to check that notifications get through. Nothing new is stored.
- The basis is your consent (Article 6(1)(a) of the GDPR), which you withdraw by switching notifications off on the website (Article 7(3) of the GDPR). Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Live Activity on the lock screen
When the level at one of your places is above "Quiet", the app can show it as it changes on the lock screen and in the Dynamic Island, as a Live Activity. This works only if notifications are on and you also switch this option on, on an iPhone with iOS 17.2 or later. The activity disappears when all your places are quiet again.
- When you switch it on, the notification record gains a token from Apple at which our server can start a Live Activity on your phone. While an activity is running, a second token is added, to which the server sends its changes; we delete it when the activity ends. Apart from that we store only what the activity shows at the moment, when we started it and when we last refreshed it. The squares are the same as for notifications, and the names of your places do not leave the phone: the phone adds them itself.
- Apple delivers the activity (the Apple Push Notification service). In doing so Apple sees the tokens and its content: the numbers of your places' squares, the level in each, the kind of threat and the time the data is from.
- When the data stops being reliable, the activity says "No data", not "Quiet", and it always shows the time the data is from. While it runs, the server refreshes it every few minutes, even when nothing changes; when refreshes stop arriving, the phone marks it as out of date.
- We delete this data when you switch the Live Activity or notifications off in the app, when Apple reports that a token no longer works, and always together with the notification record after 60 days without a refresh. The basis is your consent (Article 6(1)(a) of the GDPR), which you withdraw by switching this option off (Article 7(3) of the GDPR).
What our server sees
Every few seconds the page fetches the current situation from api.sanalert.pl. The iPhone app does the same while it is open, and its widget does it every several minutes, including while the app is closed. The Apple Watch app fetches it every minute while it is on screen, and the complication on the watch face every several minutes. The Mac app fetches it every few seconds, because its level is always in the menu bar; while the display sleeps it fetches nothing. The Android app fetches it every few seconds while it is open; in the background it fetches nothing. The Wear OS watch app fetches it every minute while it is on screen, and the complication on the watch face every several minutes. The Garmin watch app fetches the short report every minute while it is open, and its glance every 15 minutes, including while the app is closed. The Home Assistant integration fetches it every 10 seconds, day and night, because it drives automations. The “Level at my place” shortcut (Siri, Shortcuts) fetches it once, each time you run it. While they are open, the page and the iPhone and Android apps also fetch from it, at most once a minute, a summary of the last 12 hours for the whole of Poland; they pick out what concerns your place themselves and show it as “What happened”. It is the same document for everyone, so the request does not contain your place. The Track record page fetches a summary of our results from it once, the same for everyone. The Night reports page fetches the list of nights and the chosen night's report from it, the same for everyone. The register of shelter points is fetched from it by the website when you open the list of points, and by the iPhone and Android apps at most once a week; it is the same file for everyone. Our server does not record visitors' IP addresses or any data that would let us recognise them.
On other websites, on screens and as an app
- A SanAlert box on the website of a town, a school or a news site is our page inside theirs. The reader's browser fetches it and the current situation from our server, as on any visit to sanalert.pl. The box uses no cookies and stores nothing in the browser. The town it shows a level for was chosen by the site's owner; it is in the box's address after “#”, so it never reaches any server, and it is not the reader's place.
- The screen view (sanalert.pl/en/tv) stores nothing. A place, if one is given, is in the address after “#” and never reaches any server.
- The website installed as an app (Chrome, Edge) works exactly as in the browser: everything described above applies to it unchanged.
Who else processes data
- Cloudflare delivers the website and passes requests on to our server. It does so on our behalf and in doing so sees your IP address and technical details of the request, such as the type of browser. Cloudflare's privacy policy.
- Apple provides the Apple map (Apple Maps) if you choose it. The website shows our own schematic map, which uses no map provider, so your browser then does not connect to Apple's servers. Under the map, in “Layers”, you can choose the Apple map: your browser then fetches it directly from Apple's servers, so Apple sees your IP address and the area of the map you are looking at. The choice stays in this browser. We also show the schematic map if the Apple map cannot be loaded. The iPhone app works the same way: with the schematic map the app does not connect to Apple's map servers, and the Apple map is fetched by the phone from Apple's servers. You can change the choice in the app's settings; it stays in the phone's storage. Apple's privacy policy.
- Apple processes your question if you ask Siri by voice, under the Siri terms you agree to in your phone's settings. The app gives Siri the answer: the place's name, voivodeship, level and its reason. The shortcut run from the Shortcuts app, Spotlight or the Action button works without Siri. Apple's privacy policy.
- Apple also delivers the app's notifications and its Live Activity if you switch them on: see "Notifications in the app" and "Live Activity on the lock screen".
- Apple works out the route to a shelter point when you press "Route" next to it: Apple Maps opens with that point's coordinates.
- Google delivers the Android app's notifications if you switch them on, through Firebase Cloud Messaging: see "Notifications in the Android app". Google Play services also carry your places and language from the Android app to a Wear OS watch when there is no Bluetooth connection between them: through Google’s servers, end-to-end encrypted. Google's privacy policy.
- Garmin passes on the requests of the Garmin watch app: the Garmin Connect app on your phone sends them on, under Garmin’s own terms. It is the same document for everyone, and the request does not contain your place. Garmin’s privacy policy.
- Android’s location service works out the phone’s position when you press "Use my location" in the Android app; on many phones Google’s location services do that, under their own rules. The app receives only the result and keeps it on the phone.
- The maps app on an Android phone (for example Google Maps) works out the route to a shelter point when you press "Route" next to it in the Android app: it receives that point’s coordinates.
- Your browser's push service (Google, Mozilla, Apple or Microsoft) delivers the website's notifications if you switch them on, without access to their content: see "Notifications on the website".
What we do not do
- We set no cookies. The notification script (service worker) appears in the browser only once notifications are switched on on the website.
- We use no analytics tools and no advertising, we do not profile and we do not sell data.
- We keep no user accounts.
Legal basis and how long data is kept
The IP address and the technical data needed to deliver the website are processed in our legitimate interest, which is making the service available and protecting it against abuse (Article 6(1)(f) of the GDPR, Regulation (EU) 2016/679). We do not keep this data. Cloudflare and Apple keep it according to their own rules.
The data needed for notifications and the Live Activity is processed on the basis of your consent and kept for as long as "Notifications in the app", "Notifications in the Android app", "Notifications on the website" and "Live Activity on the lock screen" describe.
Your rights
You have the right of access to your data, to have it rectified or erased and to have its processing restricted (Articles 15 to 18 of the GDPR), and the right to object to processing based on our legitimate interest (Article 21 of the GDPR). Write to [email protected]. You also have the right to lodge a complaint with the supervisory authority, in Poland the President of the Personal Data Protection Office (Article 77 of the GDPR), uodo.gov.pl.
Changes
Before we change what happens to data, we describe it here first. That is how notifications went: their description appeared on this page before they were switched on.
This is a translation. If it and the Polish version ever differ, the Polish version applies.
Last changed: 25 September 2026 (the box for other websites, the screen view, installing the website as an app; later that day: the choice of language in the apps, passed on to the watch too; Siri and Shortcuts: the level at your place; the Android app; notifications in the Android app; choosing the language on the watch itself; “What happened” in the Android app; the app for Wear OS watches; the app for Garmin watches). Before that: 24 September 2026 (the schematic map by default, the Apple map by choice); 23 September 2026 (night reports; the Home Assistant integration; the nearest shelter points, offline; “Tell your family”; the test notification; the Mac app's notifications; earlier that day: notifications on the website, the Live Activity on the lock screen, the “What happened” summary, the Apple Watch and Mac apps).