PMScope Privacy Policy
Last updated: October 2, 2026
This policy describes what data is processed in connection with the PMScope app and website (the "App"), for what purpose, on what basis, and what rights are available to the individuals concerned.
1. Who is responsible for the data
The creator and operator of the App is Dawid Cieślicki (the "Operator"), contact: pmscopeapp@gmail.com.
PMScope is a tool intended for companies and teams (an "Organization") to manage projects. Depending on the type of data, the roles are as follows:
- Account data (email address, display name, profile photo, sign-in data) — the Operator is the controller, to the extent necessary to operate and secure the App.
- Data entered within an Organization (topic content, journal entries, photos, files, calendar data, other team members' data, comments) — the controller of this data is the Organization (the company using the App), which decides what data it enters and for what purpose. The Operator acts in this respect as a data processor, providing the technical infrastructure to store and process this data on behalf of the Organization. A person whose data is concerned (e.g. an employee added to a project by their employer) should first contact their own Organization regarding this data.
2. What data is processed
| Category | Examples |
|---|---|
| Account data | email address, display name, profile photo, Google sign-in identifier (if used) |
| Organization data | company name, logo, list of members and their roles |
| Project content | project/topic names and descriptions, statuses, priorities, assignments, journal entries, comments, @mentions, calendar entries (presence, deadlines) |
| Files and photos | photos and documents added to topics, entries, and tasks |
| Technical and diagnostic data | push notification tokens, app error/crash logs, basic device and app version information |
| Website data | theme (light/dark) and language preference stored locally in the browser (localStorage) |
The App does not collect GPS location data, payment data (no payment feature exists), or biometric data on the server — any biometric app lock (fingerprint/Face ID) is verified locally on the device by the operating system and is never sent to the Operator.
3. Purposes and legal bases for processing
- Providing and maintaining the App, including sign-in, data synchronization and notifications — Art. 6(1)(b) GDPR (performance of the contract to use the App) and Art. 6(1)(f) (legitimate interest in keeping the service running).
- Security, error detection and abuse prevention — Art. 6(1)(f) GDPR (Operator's legitimate interest).
- Communication in response to inquiries sent to the contact address — Art. 6(1)(f) GDPR.
- Processing of project content entered by an Organization — on the basis and for the purposes determined by that Organization (see Section 1).
4. Data processors
The App relies on third-party service providers who process data on the Operator's behalf under appropriate agreements. Details of their own data processing practices are available in their respective privacy policies:
- Google Firebase / Google Cloud (Google LLC) — authentication, database, file storage, server-side functions, website and app hosting. Google Privacy Policy
- Google Sign-In — optional sign-in with a Google account.
- Sentry (Functional Software, Inc.) — app error and crash monitoring. Sentry Privacy Policy
- Expo / EAS (650 Industries, Inc.) — delivering app updates and relaying push notifications on some devices. Expo Privacy Policy
Data may be processed on servers located outside the European Economic Area (including as part of Google's infrastructure). In such cases, the providers apply compliance mechanisms recognized under GDPR (e.g. standard contractual clauses). The Operator has no control over the detailed security configuration of these providers and, in this respect, refers to their own privacy policies.
5. Data retention
Account and Organization data is stored for as long as the App is used. After an account or Organization is deleted, data is deleted or anonymized within a reasonable time, subject to backup copies which are cleared periodically according to the infrastructure provider's own practices. Diagnostic logs (Sentry) are retained according to that provider's default retention periods.
6. Rights of data subjects
With respect to data for which the Operator is the controller, you have the right to: access your data, rectify it, erase it, restrict its processing, data portability, object to processing, and lodge a complaint with the Polish Data Protection Authority (PUODO). To exercise these rights, contact pmscopeapp@gmail.com.
With respect to data entered by an Organization (see Section 1), these rights are exercised in the first instance by contacting that Organization.
7. Data security
The Operator applies reasonable technical and organizational measures to protect data, including access rules restricting reads and writes to active members of a given Organization only. Due to the nature of data transmission over the Internet, the Operator cannot guarantee absolute security of transmitted data and is not liable for events beyond its control, including the actions of the third-party providers listed in Section 4, connectivity failures, or unauthorized access resulting from the loss or disclosure of a user's own sign-in credentials.
8. Children
The App is not intended for individuals under 16 years of age and is not directed at children. The Operator does not verify users' age. If it is determined that a child's data has been processed without an appropriate legal basis, that data will be deleted promptly upon notification to the contact address.
9. Changes to this policy
The Operator may update this policy, in particular as the App evolves or applicable law changes. The current version is always available on this page. Continued use of the App after changes are published constitutes acceptance of them.
10. Governing law
This policy is governed by the laws of Poland.
Questions about this policy can be directed to pmscopeapp@gmail.com.