Your privacy is important to us. This Privacy Policy explains how ImAllergicToIt ("we", "our", or "the Application") collects, uses, and protects your personal information when you use our service to create and manage your digital allergy cards.
1. Data Controller
ImAllergicToIt is operated by an individual, not by a company. The data controller for the processing described in this policy is:
- Simone Saverio Fildi, operating the service under the name ImAllergicToIt
- Email: info@imallergicto.it
You can contact us at the email address above for any question relating to this policy or to exercise the rights described in section 8. If you need a postal address in order to exercise your rights, ask us at that address and we will provide one.
2. Data We Collect
We collect and process the following categories of personal data:
- Registration data: your email address and a hashed password when you create an account. You may optionally add a display name and a preferred language.
- Health-related data: the allergies and intolerances you select (e.g. gluten, lactose, peanuts), their severity level, and the free-text notes you choose to enter in order to generate your allergy card. This is special-category data under GDPR art. 9 and is processed solely on the basis of your explicit consent (see section 4).
- Consent records: the date and time at which you gave your explicit consent to the processing of health data, accepted the Terms and Conditions, and made the age declaration, together with the version of the Terms and of this policy in force at that moment. We keep these records in order to be able to demonstrate that consent was given, and to which text, as GDPR requires.
- Technical data: standard server-side log information (such as IP address and browser type) generated when your browser connects to our infrastructure, and used only to operate and secure the service.
3. No Tracking, No Analytics, No Advertising
The Application contains no third-party analytics, no tracking, no session replay, no advertising, and no profiling. We do not measure how you move through the app, we do not record your screen or your navigation, and we do not build any profile about you.
No information about you is sent to any analytics provider — because there is none. There are no analytics or advertising cookies and no tracking identifiers. The only data we hold about you is the data you deliberately enter into your account, described in section 2, stored on our own infrastructure.
Details of the small amount of strictly necessary information stored in your browser are set out in our Cookie Policy.
4. Purposes and Legal Bases of Processing
- To let you create, save, translate and export your allergy card. Legal basis: performance of the contract between you and us (GDPR art. 6(1)(b)) for the account itself, and — for the allergy, intolerance, severity and notes data, which is health data — your explicit consent (GDPR art. 9(2)(a)).
- To give you secure access to your account and to send you the transactional emails needed to verify your address or reset your password. Legal basis: performance of the contract (art. 6(1)(b)).
- To keep the service secure and operational (server logs, abuse and rate-limit protection). Legal basis: our legitimate interest in the security of the service (art. 6(1)(f)).
Your explicit consent to the processing of health data is collected at registration through a dedicated, separate checkbox — distinct from the acceptance of the Terms and Conditions — and the moment it is given is recorded. You may withdraw that consent at any time by deleting your account from your profile, which erases the account, the cards and the health data. Withdrawing consent does not affect the lawfulness of the processing carried out before the withdrawal.
5. Service Providers and International Transfers
We do not sell your personal data and we do not disclose it to third parties for commercial purposes. Your data is processed by the following service providers, which act as data processors on our behalf, under contract and on our instructions:
- Convex — hosting and database services, strictly necessary to deliver the service. Convex is the only processor that holds your health data. The data is hosted on infrastructure located in the European Union (region eu-west-1, Ireland).
- Resend — delivery of transactional emails only (email verification and password reset). Resend processes your email address only and receives no health data. As Resend is based in the United States, this involves a transfer of your email address outside the EU/EEA, carried out on the basis of the Standard Contractual Clauses approved by the European Commission.
- Cloudflare — hosting of the website itself: the pages, scripts and images your browser downloads are served from Cloudflare's global network (Cloudflare, Inc., United States). Like any web host, Cloudflare receives your IP address and browser information when it serves you a page. It never receives your health data, which is not part of the website's files: it is stored in the Convex database and only ever travels between your browser and Convex.
- Buy Me a Coffee — the optional donation button. The button is loaded from Buy Me a Coffee's servers (United States), which means that when a page loads, your IP address and browser information reach them, as happens with any externally hosted element. It stores nothing on your device, and it receives no health data, no email address and no information about your account. In addition, a Content-Security-Policy enforced on every page restricts, at the browser level, the destinations to which the site — including the donation button — can send data. Unlike Convex and Resend, Buy Me a Coffee is not a processor acting on our instructions: it receives this connection data directly from your browser as an independent controller, under its own privacy policy. We load the button on the basis of our legitimate interest (GDPR art. 6(1)(f)) in keeping a free service funded, and the transfer to the United States concerns only the technical connection metadata that loading any external content inherently entails: we pass the button no health data, no email address and nothing about your account. Buy Me a Coffee is not certified under the EU-U.S. Data Privacy Framework, so we tell you about this transfer transparently here, so that you can make an informed choice. If you choose to click the button and donate, you leave our service for theirs.
No other third party receives your personal data. We may disclose data if we are legally obliged to do so, for example in response to a valid order from a competent authority.
6. Data Retention
- Your data is kept for as long as your account exists, and no longer. Your account data, cards, health data and consent timestamps are retained so that the service can work: an allergy card that disappeared on its own would defeat the purpose of the service.
- We do not delete inactive accounts automatically. If you stop using the service, your card stays where you left it and will still be there when you come back. Deciding when your data goes is your call, not ours.
- Deletion on request. If you delete your account from your profile, your account, your cards and your health data are erased immediately and irreversibly. We cannot restore them afterwards. You can do this at any time, without giving a reason.
- Technical logs are kept only for the short period needed to operate and secure the service.
7. Security
We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. Passwords are stored hashed and never in plain text. Health data is linked exclusively to your own account and is accessible only to you when you are signed in. Data is transmitted over encrypted connections.
8. Your Rights (GDPR)
If you are in the European Union or the European Economic Area, Regulation (EU) 2016/679 (GDPR) gives you the right to:
- Access your personal data and obtain a copy of it (art. 15).
- Rectify inaccurate data (art. 16).
- Erase your data, including your account, your cards and your health data (art. 17).
- Restrict or object to processing (arts. 18 and 21).
- Data portability: receive your data in a structured, commonly used, machine-readable format (art. 20).
- Withdraw your consent to the processing of health data at any time (art. 7(3)).
How to exercise them. You can exercise your rights of access and portability yourself, at any time, from your profile page: the data export feature lets you download all of your data — account details, cards, card items and consent timestamps — as a JSON file. You can also delete your account from the same page, which erases your account, your cards and your health data. As an alternative to these self-service tools, you may exercise any of your rights by writing to us at info@imallergicto.it.
Right to lodge a complaint (art. 13(2)(d)). If you believe your data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority — in the EU/EEA, the Data Protection Authority of the country where you live, where you work, or where the alleged infringement took place. For example, in Italy this is the Garante per la protezione dei dati personali (www.garanteprivacy.it). We would nevertheless be grateful if you contacted us first, so that we can try to resolve the matter.
9. United States — California and Other States
The following applies if you are a resident of California, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Under that law, your allergy, intolerance, severity and notes data is "sensitive personal information", because it concerns your health.
- We do not sell your personal information and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. There is no "Do Not Sell or Share My Personal Information" mechanism to offer, because there is nothing to opt out of.
- We do not use or disclose sensitive personal information for any purpose other than providing the service you asked for — that is, generating and managing your allergy card.
- Right to know: you may request the categories and specific pieces of personal information we hold about you. The data export in your profile provides this immediately.
- Right to delete: you may delete your account and all associated data from your profile, or ask us to do it for you.
- Right to correct: you may correct inaccurate personal information, directly in the app or by contacting us.
- No discrimination: we will not treat you differently for exercising any of these rights.
- Global Privacy Control: GPC and similar opt-out preference signals are honoured by default, because the service performs no tracking, no selling and no sharing of personal information in the first place.
Residents of other US states with comparable privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas and others — have equivalent rights of access, deletion, correction and portability, which you may exercise in the same ways described above.
10. Minors and Cards Created by a Parent
At registration we ask you to declare that you are old enough to consent on your own behalf under the law of your country (GDPR art. 8), or that you are acting with the authorisation of whoever holds parental responsibility for you.
Cards created for a child. A common use of this service is a parent or guardian creating an allergy card for their child. If you are the person holding parental responsibility, you may create and manage a card containing your child's health data. In that case you are the one giving the explicit consent required by GDPR art. 9 for that data, and you are responsible for it: you confirm that you are entitled to provide the child's health information and that it is accurate. All the rights described in this policy — access, export, correction, deletion — can be exercised by you on the child's behalf from the account you created.
We do not knowingly allow a child below the age of digital consent to create an account without the involvement of the person holding parental responsibility. If you believe this has happened, write to us at info@imallergicto.it and we will delete the account and the associated data.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If the change is significant, we will inform you through the Application or by email. The date at the top of this page always shows when it was last updated.
12. Contact
For any question about this Privacy Policy or about how your data is handled, contact us at info@imallergicto.it.