Юридический документ Legal document
scheda.me — Privacy Policy
Last updated: 2026-07-30 · Effective: 2026-06-07
This Privacy Policy describes how scheda.me (“we”, “us”, “our”) collects, uses, and shares information when you use the scheda.me website (scheda.me) and our products, including the scheda.me mobile application (collectively, the “Services”).
scheda.me is operated by ИП Алёхин Роман Сергеевич (sole proprietor Roman Sergeevich Alekhin), registered in the Russian Federation, ИНН (INN) 713005978740, ОГРНИП (OGRNIP) 326710000026194 (“Operator”). For Russian-language disclosures required under Federal Law No. 152-FZ, see also Политика обработки персональных данных.
Information we collect
Information you provide:
- Account information. Which sign-in service you use depends on where you are. Users located in the Russian Federation sign in with Yandex ID — an information system owned by a Russian legal entity, as required by art. 8 part 10 of Russian Federal Law 149-FZ. Users outside Russia sign in with Apple ID (Sign in with Apple, Apple Inc., USA). In both cases we receive your email address and name; with Yandex ID we also receive your phone number if you consent to it. Sign in with Apple lets you hide your real email address — in that case we only ever receive Apple’s relay address. We do not create or store a separate scheda.me password.
- Profile and business data. Optional business name, working hours, services offered.
- Client records you store. Names, contact details, appointment notes, and other CRM data that you choose to enter. You are the controller of this data; we process it on your behalf.
- Payment information. If you subscribe to a paid tier (initially available for Russian Federation users only), payment is processed by ЮKassa (YooMoney). We receive transaction metadata (amount, currency, status) but never full card numbers.
- Support correspondence. Messages you send to roman@alekhin-dev.com.
Information collected automatically:
- Device and usage data. Device model, OS version, app version, and language.
- Crash reports and diagnostics. Technical reports about app errors and a small sample of app-performance measurements — see Crash reports (diagnostics).
- Identifiers. An internal user ID. We do not use advertising identifiers (IDFA / AAID) and do not track users across other apps or websites.
- Logs. IP address and timestamps when you contact our backend, kept for security and abuse prevention.
Information we do not collect:
- Precise location.
- Contacts, photos, or microphone — unless you explicitly grant access for a feature you use.
- Browsing history or activity in other apps.
Crash reports (diagnostics)
To find and fix errors, the app sends technical crash reports to the Operator’s own diagnostics server, located in the Russian Federation (the open-source GlitchTip service). Reports are not shared with third-party analytics companies and are never used for advertising or profiling.
A report contains technical information only: the error type and stack trace, the app version, the OS version, the device model, and your account identifier (before sign-in, an anonymous install identifier) so that repeated crashes can be told apart.
A report does not contain your name, email address, phone number, your clients’ data, or the contents of your records:
- email addresses and phone numbers are stripped automatically from the report text, including diagnostic messages and request URLs, in case any ever ended up there;
- the IP address is forcibly removed from the report before it is sent;
- console messages are not included.
We additionally collect a small sample (about 1% of sessions) of app performance measurements; they carry the same anonymous technical fields and none of your data.
How we use information
- Provide, maintain, and improve the Services.
- Diagnose crashes and improve app stability.
- Authenticate accounts and sync data between your devices.
- Respond to support requests.
- Process payments and prevent fraud.
- Comply with legal obligations.
Legal bases under GDPR where applicable: performance of a contract (Article 6(1)(b)), legitimate interests in operating and securing the Services (Article 6(1)(f)), consent for optional features (Article 6(1)(a)), and legal obligations (Article 6(1)(c)).
How we share information
We do not sell personal data. We share data only with:
-
Service providers (subprocessors) acting on our instructions and bound by contracts. Current list:
- Self-hosted Supabase on a dedicated server located in the Russian Federation — backend database and authentication. All user data is stored exclusively on servers in the Russian Federation.
- ЮKassa (YooMoney), for Russian Federation users — billing for paid tiers.
The diagnostics server (GlitchTip) is not a third-party service: the Operator hosts it on its own server in the Russian Federation, so crash reports are not shared with anyone.
-
Legal requests when required by law and after reviewing the request.
-
Business transfers in the event of a merger, acquisition, or sale of assets, subject to this Policy.
Your role for your clients’ data
For personal data you enter about your own clients (names, contact details, appointment notes), you act as the controller, and the Operator processes that data as a processor on your instructions. You warrant that you have a lawful basis for entering this data into the Services (for example, your client’s consent or the necessity of processing to provide your service to them).
International transfers
The Services are available to users in several countries (the list of available countries may change over time). Regardless of the country a user connects from — including users outside the Russian Federation — all user data is processed the same way: the backend (self-hosted Supabase) runs on a dedicated server in the Russian Federation, and collection, recording, and storage of personal data take place exclusively on the territory of the Russian Federation (in accordance with Article 18(5) of Federal Law No. 152-FZ). Because personal data does not leave the territory of the Russian Federation, no cross-border transfer of personal data occurs.
When you use Sign in with Apple (available only to users outside the Russian Federation), your device sends your credentials directly to Apple Inc. and the Operator receives account data from Apple; the Operator does not send personal data to Apple. Receiving data from abroad is not a cross-border transfer within the meaning of Article 12 of Federal Law No. 152-FZ.
Data retention
We retain account data for as long as your account is active. After account deletion, data is deleted or anonymized within 30 days, except where longer retention is required by law (e.g. tax records: 4 years under Russian Federation rules).
Security
We use HTTPS in transit, encryption at rest where supported by our backend, secure authentication via your sign-in provider (Yandex ID or Apple ID — see “Account information”), and access controls. No system is perfectly secure; if you become aware of a vulnerability please email roman@alekhin-dev.com.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Object to or restrict processing.
- Receive your data in a portable format.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority.
To exercise these rights, email roman@alekhin-dev.com. We respond within 30 days.
Account deletion
You can delete your account and all associated data directly in the app (Profile tab → Delete account) or by emailing roman@alekhin-dev.com. See Account deletion for details.
Children
The Services are not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact roman@alekhin-dev.com and we will delete it.
Apple App Store / Google Play disclosures
The scheda.me app discloses its data collection practices in the App Store “App Privacy” labels and the Google Play “Data Safety” section. Those disclosures reflect this Policy. Material changes are reflected in both places.
Changes to this Policy
We may update this Policy. Material changes are announced via the app or by email at least 14 days before they take effect. The “Last updated” date at the top reflects the most recent revision. The current version is always available at alekhin-dev.com/legal/scheda-privacy-en.
Contact
Operator: ИП Алёхин Роман Сергеевич
(sole proprietor Roman Sergeevich Alekhin)
ИНН (INN): 713005978740 · ОГРНИП (OGRNIP): 326710000026194
Address: Tula, Tula Oblast, Russia
Email: roman@alekhin-dev.com
Russian-language policy under 152-FZ:
Политика обработки персональных данных