Legal
Privacy
Policy
Last updated: 9 September 2026
1. Who we are
MD2TECH S.r.l.s.
Via Monte Grappa 1, 53100 Siena (SI), Italy
VAT and tax number 01615860523
Email: info@md2tech.it
We are the data controller for the processing described here. We have not appointed a Data Protection Officer, as we do not meet the conditions set out in Article 37 of Regulation (EU) 2016/679 (GDPR).
2. Which apps this covers
This Privacy Policy applies to the mobile apps developed and published by MD2 TECH:
- SWListener — App Store (iOS) and Google Play (Android)
- CW Trainer — App Store (iOS)
- Budgetto — App Store (iOS)
- LiteSpot — not yet released on the app stores. What follows covers the processing already taking place for pre-order and test participants, and the processing planned for release.
Our website md2tech.it is an informational site: it uses no profiling cookies and requires no account.
3. What each app collects
SWListener
- Authentication: email address and user ID through Firebase Authentication. Only needed to post spots — the rest of the app works without an account.
- User content: the radio spots you post are stored in Firebase Firestore and are visible to other users of the app.
- GPS location: used on your device to work out the distance to stations. It is never sent to our servers or to anyone else.
- Purchases: handled by Apple Inc. and Google LLC, with RevenueCat Inc. verifying the subscription. We never receive your card details.
- Diagnostics: we run no diagnostic collection of our own. We only see the aggregated, anonymous reports Apple and Google make available to developers, and only if you have turned sharing on in your device settings.
CW Trainer
- Authentication: user ID and device ID, used to manage your rank and the leaderboard.
- Progress: Koch sessions, experience points and per-character accuracy, stored in Firebase Firestore.
- Leaderboard: your callsign and weekly score, visible to other users.
- Purchases: in-app purchase history handled by RevenueCat Inc. and Apple Inc.
- Diagnostics: we run no diagnostic collection of our own. We only see the aggregated, anonymous reports Apple makes available to developers, and only if you have turned sharing on in your device settings.
Budgetto
- Authentication: email address through Firebase Authentication, needed for household sharing.
- Spending data: captured receipts, items, amounts and categories, stored in Firebase Firestore. Visible to the household members you choose to share them with.
- Receipt images: processed automatically to extract the data, then deleted once processing is complete. We do not keep them.
- Purchases: Premium subscription handled by Apple Inc., with RevenueCat Inc. verifying the subscription. We never receive your card details.
LiteSpot not yet released
- Pre-orders: email address and order details for people signing up on litespot.eu. Payment is handled by Stripe, which processes card details as an independent controller.
- Athlete profiles: name, performance data and test results, stored in Firebase Firestore.
- Session data: reaction times, scores and progress over time, used to generate adaptive training programmes.
- Authentication: email and user ID for personal trainers and physiotherapists.
4. Why we process your data, and on what legal basis
We only process personal data for the purposes listed below, each with its own legal basis under Article 6 GDPR.
-
Running the app and managing your account
Art. 6(1)(b) — performance of a contract
-
Publishing content you choose to share: spots in SWListener, the leaderboard in CW Trainer, household sharing in Budgetto
Art. 6(1)(a) — consent, which you can withdraw at any time
-
Accessing your device location
Art. 6(1)(a) — consent, which you can withdraw in your system settings
-
Managing subscriptions and verifying purchases
Art. 6(1)(b) — performance of a contract
-
Keeping records of purchases
Art. 6(1)(c) — legal obligation under Italian tax law
-
Diagnosing errors, measuring stability and improving the service
Art. 6(1)(f) — our legitimate interest in keeping the apps working
-
Answering support requests
Art. 6(1)(f) — our legitimate interest in supporting our users
5. Providers that process data on our behalf
The following providers act as processors under Article 28 GDPR, or as independent controllers for the part that is theirs.
In the apps:
- Google LLC — Firebase Authentication, Firestore and Storage. Privacy Policy
- Apple Inc. — App Store, StoreKit and payment handling. Privacy Policy
- RevenueCat Inc. — verifying and managing in-app subscriptions across all our apps. Privacy Policy
- Google LLC — Google Play and its payment handling, for apps distributed on Android.
For the LiteSpot pre-order on litespot.eu only:
- Stripe, Inc. — collecting pre-order payments. Stripe processes card details as an independent controller. It is not used in any of our apps. Privacy Policy
We use no behavioural analytics and no advertising services, and we do not sell or share personal data with third parties for marketing purposes.
6. Transfers outside the European Union
Data handled through Firebase is stored in Google Cloud data centres located in the European Union (europe-west region). We do not transfer user data outside the European Economic Area for storage.
Some of the providers listed in section 5 are, however, based in the United States and may access data from outside the European Economic Area when providing technical support and maintaining their own systems.
Where that happens, the transfer relies on the Standard Contractual Clauses approved by the European Commission under Article 46 GDPR and, for providers that participate in it, on the adequacy decision covering the EU-U.S. Data Privacy Framework.
7. How long we keep your data
- Account data and content: for as long as your account is active. If you ask us to delete it, we do so within 30 days.
- Purchase records: 10 years, to meet Italian tax law obligations.
- Crash reports: we do not store these ourselves. They stay in Apple's and Google's systems, under their retention policies.
- Receipt images (Budgetto): deleted immediately after the data is extracted.
- GPS location (SWListener): never stored — it stays on your device.
8. Your rights
Under Articles 15 to 22 GDPR you have the right to:
- access your personal data and get a copy of it;
- have it corrected if it is inaccurate or incomplete;
- have it erased;
- ask us to restrict how we process it;
- receive your data in a machine-readable format and have it transferred to another controller;
- object to processing based on our legitimate interest;
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
To exercise any of these, write to info@md2tech.it. We reply within 30 days.
If you believe we are handling your data unlawfully, you can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the authority in the country where you live.
9. Deleting your account
You can ask us to delete your account for any of our apps by writing to info@md2tech.it, telling us which app and the email address on the account. We action the request within 30 days.
There is also a dedicated page with the procedure for each app: Account deletion.
10. Automated systems and AI
Some features rely on automated systems: reading receipts in Budgetto, and generating training programmes in LiteSpot.
These produce suggestions that you can always edit or ignore. We do not make solely automated decisions that produce legal effects concerning you or that similarly significantly affect you, within the meaning of Article 22 GDPR.
11. Security
Data travels encrypted (TLS) between the app and our services. Access to stored data is governed by security rules that stop one user from reading another user's data, and administrative access is limited to the people who actually need it.
No system is completely secure. If a personal data breach occurs that poses a risk to your rights and freedoms, we will make the notifications required by Articles 33 and 34 GDPR.
12. Subscriptions
In-app subscriptions are handled entirely by Apple (App Store) or Google (Play Store). MD2 TECH does not process payment data directly. Subscriptions renew automatically unless cancelled at least 24 hours before the end of the current period, which you can manage in your Apple ID or Google Play account settings.
13. Children
Our apps are not directed at children under 14, and we do not knowingly collect their personal data. Where processing is based on consent, children under 14 need the consent of a parent or guardian, as required by Article 8 GDPR and Article 2-quinquies of Italian Legislative Decree 196/2003.
If you believe a child has given us personal data, write to info@md2tech.it and we will delete it.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in our apps or in the law. Changes are published on this page with the update date shown at the top. If a change is substantial, we will also notify you inside the app.