Privacy Policy
Last updated: 22 August 2026
Imenko is a Croatian baby-names app. This policy explains what we store, why, for how long, and what you can do about it. It covers both the website at www.nabavi-imenko.com and the Imenko mobile app. It is written to describe what the software actually does — where a section says we do not collect something, that is because there is no code that collects it.
Who is responsible for your data
The data controller for the purposes of the General Data Protection Regulation (GDPR) is:
- Controller: Solar Blue d.o.o.
- Privacy contact: developer@solar-blue.com
The short version
- Imenko has no user accounts — no email address, no password, no name. You never tell us who you are.
- To save your swipes and match them with your partner's, the app registers your device and gives it an anonymous identifier. That identifier joined to your swipe history is personal data under the GDPR, even though it names nobody.
- Your partner never sees your individual swipes. Only names you both liked become visible, as matches — plus one further fact if you pair: whether Imenko Pro is active through the other of you.
- We never sell your data and never share it for advertising.
- You can delete any swipe, unpair from your partner, or ask us to erase your device record and everything attached to it.
Your device identity (instead of an account)
Imenko has no sign-up. The first time you open the app it registers your device with our server, which returns a secret token. The app stores that token in the iOS Keychain or the Android Keystore and sends it with every request. The token is what proves a request is yours — it takes the place of a username and password.
What we store about your device
- A random device identifier that we generate ourselves — not your device's serial number, advertising ID, IMEI or MAC address
- A SHA-256 hash of your device token, never the token itself
- Your platform (iOS or Android)
- Your language preference (English or Croatian), so notifications arrive in the right language
- A Firebase push token, if you enable notifications
- Timestamps for when the device was registered, last updated and last seen
We do not store your name, email address, phone number, contacts, photos, precise location, advertising identifier or any device fingerprint. There is no field in our database for any of them.
We want to be precise about one thing, because many privacy policies are not: although none of the above identifies you by name, a persistent identifier tied to a record of your activity is still personal data under the GDPR. We treat it as such, and every right described below applies to it in full.
Because the server keeps only a hash of your token, we cannot recover or reissue it. If you delete the app, reset your device or otherwise lose the token, the app registers a new device and the old record is orphaned — we can no longer connect it to you, even in order to delete it at your request. Contact us before uninstalling if you want that record removed.
Swipes and favourites
When you swipe a name we record the verdict, so your favourites survive a reinstall and so matching can work at all.
- Which name you swiped, and whether you liked it, disliked it or marked it as a maybe
- When you first swiped it and when you last changed your mind
- Nothing else — a swipe is a device, a name, a verdict and two timestamps
You can delete an individual verdict at any time from within the app, which removes the record entirely. Deleting a like also dissolves any match built on it, for both you and your partner.
Pairing with a partner
Two people can pair their devices and see the names they both liked. Pairing is optional, and nothing in this section applies unless you choose to use it.
What your partner can see
- Names you have both liked, as matches, with the time each match was created
- How many matches you have
- A shared filter set, if either of you sets one — for example “girls’ names, four to six letters”
- Whether Imenko Pro is active through you — one bit of information, and only so their app can explain why the paid features are unlocked
What your partner can never see
This is enforced by the design of our API rather than by a promise in a policy: the data is simply absent from every response your partner's app is able to request.
- Your individual swipes, including anything you disliked or marked as a maybe
- Names you liked that they did not
- Your device identifier, platform or language
- When you last used the app
- Anything about a subscription beyond that single fact — not its price, product, store, purchase date or expiry
That one bit is the single, deliberate exception to the rule above, and we would rather name it here than let you discover it. Imenko Pro covers both partners, so once you pair, each of you can tell that the other is a subscriber if the paid features are unlocked and you did not pay for them yourself. Our API returns exactly two values on this point — the tier, and whether it comes from you or from your partner — and nothing else about the other person's purchase exists in any response either app can request.
To pair, one of you creates an eight-character invite code that is valid for 48 hours. Anyone holding that code can pair with you until it is used or expires, so treat it like a password and send it only to your partner. Creating a new code immediately invalidates the previous one.
Either of you can unpair at any time. Matches disappear for both sides immediately. Your own swipes are kept, so if you pair again later your matches are recalculated from that history.
Push notifications
If you enable notifications we store a Firebase Cloud Messaging token for your device and use it to send exactly two kinds of message:
- A match notification, sent to your partner when a like of theirs completes a match
- A partner-connected notification, sent to you when someone accepts your invite code
We send nothing else — no marketing, no re-engagement nudges. Notification text is composed on our server in the language stored for the receiving device. You can turn notifications off in your device settings at any time, and the app then clears the stored token. We also clear it automatically when Firebase reports that it is no longer valid.
Support and feedback
If you write to us through the support form, we store what you submit:
- The subject and description you wrote
- Your email address, only if you chose to give one
- The time you submitted it
The email field is optional and exists solely so that we can reply. If you leave it blank we still receive the message; we simply cannot answer it. The form is not connected to your device identity, so a submission cannot be linked back to your swipes.
The name catalogue
The names, meanings, origins, histories and popularity figures in Imenko are compiled from published public sources:
- The Croatian Bureau of Statistics (Državni zavod za statistiku) — annual counts of names given to newborns, and the 2021 Census count of living bearers
- A publicly published atlas of Croatian personal names and their distribution across counties
- The Croatian name-day calendar and the Croatian Bishops’ Conference liturgical calendar
- Public reference works on name meanings, origins and history
This catalogue is reference material about names, not about people. It holds no records of identifiable individuals, and nothing you do in the app is ever added to it.
Where we show how many people in Croatia carry a name, the figure comes from the 2021 Census. The Bureau suppresses any count below ten in order to protect privacy, so in those cases Imenko displays “fewer than 10” rather than a number. We never estimate or infer a suppressed figure.
The website: cookies and analytics
The website uses Google Analytics 4 under Consent Mode v2, configured to deny by default. Until you accept in the cookie banner — and permanently if you decline — Google Analytics sets no cookies and stores nothing on your device.
- Google Analytics 4 — page views and interaction events, only after you consent. Legal basis: your consent, Art. 6(1)(a) GDPR
- Vercel Analytics — a cookieless page-view count that identifies nobody and stores nothing on your device, so it runs regardless of your choice
- Sentry — error monitoring for the website. When a page or our server fails, Sentry receives the error message, the technical stack trace, the URL, your browser type and your IP address. The IP address is kept so we can tell a genuine fault apart from an automated scan or an attack, and act on the latter — Recital 49 GDPR names network and information security as a legitimate interest. It sets no cookies and stores nothing on your device, so it runs regardless of your cookie choice. We have configured it not to send request or response bodies, cookies, or the contents of any form. Legal basis: legitimate interests, Art. 6(1)(f) GDPR
- Local browser storage — your theme, language and cookie choice, kept on your device and never sent to us
You can change or withdraw consent at any time through “Cookie settings” in the footer, or by clearing your browser storage. Google may process analytics data in the United States under the EU–U.S. Data Privacy Framework.
The mobile app: analytics and crash reporting
The Imenko app uses Firebase Analytics to understand which features are used, and Firebase Crashlytics to diagnose crashes. Neither is used to build a profile of you, and neither receives your swipes, your matches or anything about your partner.
What these collect
- Usage events — screens opened, searches run, filters applied, features used
- Device information — app version, device model, operating-system version and language
- Crash diagnostics — stack traces and error logs when the app fails
- Not collected — no names, email addresses, phone numbers or any other directly identifying information
Turning it off
You can disable analytics and crash reporting at any time in the app's privacy settings. Firebase Analytics data is retained for at most 14 months and crash reports for 90 days, after which Google deletes them automatically. Our legal basis is our legitimate interest in keeping the app working and improving it (Art. 6(1)(f) GDPR), and you may object at any time using that same setting.
Subscriptions and payments
Imenko is free to download. An optional subscription, Imenko Pro, unlocks additional features. Subscriptions are managed through RevenueCat, which communicates with the App Store and Google Play on our behalf.
Payments
- All payments are processed by Apple or Google, never by us
- We never see or receive your card number, bank details or billing address
- We cannot charge you directly; every charge is made by the store you bought through
What we store about a subscription
- Whether your subscription is active, expired or in a grace period
- Which entitlements you hold and when the current period ends
- An anonymous subscriber identifier used to match a purchase to your device
- The purchase history the store reports to us
- Your device's tier — free or premium — which only RevenueCat's webhook can set. No request from a device can change its own tier
Sharing Pro with your partner
One Imenko Pro subscription covers both paired partners. To make that work, when your app asks about your pairing we tell it whether the paid tier applies and whether it comes from you or from your partner. That is the only thing about the other person's subscription that ever leaves our server — see “Pairing with a partner” above. The terms of use cover what it means contractually: the subscriber is the only customer, and coverage ends when the subscription lapses or when either of you unpairs.
How we protect it
- Your device token is stored only as a SHA-256 hash, so a leak of our database would not yield a usable token
- The app never connects to our database directly; every request passes through our API, which holds the database credentials server-side
- Row-level security is enabled on every table with no public access policies, so the public API key cannot read any of it
- All traffic is encrypted in transit over HTTPS
- Device-scoped responses are marked private and are never cached by any intermediary
- Rate limiting protects against bulk extraction and abuse
Legal bases for processing
Under Art. 6 GDPR we rely on the following:
- Performance of a contract, Art. 6(1)(b) — your device identity, swipes, partner pairing, matches and subscription status. Without these the app cannot do what you installed it to do
- Consent, Art. 6(1)(a) — website analytics cookies and push notifications. You may withdraw either at any time, without affecting anything processed before you did
- Legitimate interests, Art. 6(1)(f) — app analytics, crash and error reporting on both the app and the website, security and abuse prevention. Our interest is in a working, secure app, weighed against the fact that none of this identifies you directly
- Legal obligation, Art. 6(1)(c) — keeping transaction records where tax or consumer law requires it
How long we keep it
We keep data only for as long as it serves the purpose it was collected for:
- Device record, swipes and matches — until you ask us to erase them, or until you uninstall the app and the record is orphaned
- Push token — until you disable notifications, or until Firebase reports it invalid, whichever comes first
- Partner link and shared filters — deleted the moment either side unpairs
- Invite codes — 48 hours, or until used
- Feedback messages — 24 months, so we can follow up and notice recurring problems
- Subscription records — for the life of the subscription, and afterwards for as long as tax law requires
- Website analytics — at most 14 months
- Crash and error reports — 90 days
Who else processes your data
We use the providers below. Each acts on our instructions as a processor under a data-processing agreement, and each has its own privacy policy:
- Supabase — database hosting (European Union)
- Vercel — application hosting and cookieless page-view analytics
- Google (Analytics, Firebase) — website analytics
- Firebase — push notifications, app analytics and crash reporting
- Sentry — error monitoring for the website (European Union)
- RevenueCat — subscription management
- Apple / Google Play — payment processing and app distribution
Some of these providers are based in the United States. Transfers rely on the EU–U.S. Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses otherwise. Our database and application are hosted in the European Union.
We do not sell your personal data, we do not share it with data brokers, and we do not use it for advertising or to build advertising profiles. No third party receives your data for its own purposes.
Children
Imenko is intended for adults planning or expecting a child and is not directed at children. We do not knowingly collect data from anyone under 16, the age at which a person can consent to online services on their own in Croatia. If you believe a child under 16 has used the app and left data with us, contact us and we will delete it.
Your rights
Under the GDPR you have the right to:
- Access — ask what we hold about your device and receive a copy
- Rectification — have inaccurate data corrected
- Erasure — have your device record and everything attached to it deleted
- Restriction — ask us to stop processing while a dispute is resolved
- Portability — receive your swipes and matches in a machine-readable format
- Object — object to processing based on legitimate interests, including app analytics
- Withdraw consent — for cookies or notifications, at any time and without penalty
Most of these you can exercise directly in the app: delete individual swipes, unpair from your partner, or switch off analytics and notifications. For anything else, email us and we will respond within one month. Because there is no account system, please write from the app's support form or include the device identifier shown in the app's settings — otherwise we have no way to tell which record is yours, and we will not guess.
If you believe we have handled your data unlawfully, you may complain to the Croatian supervisory authority: Agencija za zaštitu osobnih podataka (AZOP).
Changes to this policy
We may update this policy as the app changes. The revision date at the top always reflects the last substantive change. If a change materially affects how we use your data we will tell you in the app before it takes effect, rather than relying on you to re-read this page.
Contact
For any privacy question, or to exercise any of the rights above, write to developer@solar-blue.com