FINKI LIFE — Privacy Policy
Effective date: 12 September 2026 Version: 5.5 Applies to: the FINKI LIFE mobile application for Android and iOS, published for the Republic of North Macedonia and written to the law of that country.
0. Summary
FINKI LIFE keeps your study data on your device by default. There is no advertising, no analytics SDK, no tracking and no profiling, the app never reads your location, and you never create an account with a name, email, or password. The one exception to "never reads your location" is that a crash report, if you leave crash reporting on, arrives at the crash-reporting service with the country and city it works out from your internet connection — section 4a explains it and how to switch it off.
Data leaves your device in these situations, and no others:
| When | What leaves your device | Who receives it |
|---|---|---|
| The app refreshes public university data | An ordinary web request | FINKI/UKIM, Microsoft Outlook |
| Only if you import the class timetable | An ordinary web request for the published schedule | aSc EduPage (finki.edupage.org), where FINKI publishes it |
| Only if you connect your Moodle account | An authenticated request to your own faculty's server | FINKI/UKIM (courses.finki.ukim.mk) |
| Only if you turn on the cloud assistant | Your question, the conversation so far, and a bounded snapshot of your study data | The operator's own server function, then a model routing service and the model provider it routes to, which may use what it receives to train its own models |
| Only if you file a bug report | The category and description you typed, the app version, and — only if you attach one — the screenshot you chose | The operator's own backend, and an email delivery service, which carries the email that tells the operator a report arrived |
| If the app hits an error it cannot recover from | A description of that error: its type, message, and the app's own function names and line numbers, plus what kind of device it happened on. No data about you or your studies, though the service works out an approximate city from your connection | A crash-reporting service, on servers in the European Union |
| Every launch, and when you reopen the app | A request asking whether the app has been paused. It carries no study data and no identifier of you | The operator's own backend |
The AI Study Assistant runs on your device unless you choose otherwise. In its default on-device mode it makes no network call of any kind. A separate cloud assistant setting, off until you switch it on and confirm, sends your question and your study context to a third-party language model to get a fuller answer. That model provider may use what it is sent to train its own models, which is why the setting is off until you turn it on and why the confirmation says so before your first question leaves the phone. Section 3 describes exactly what is sent, and section 3.2 what happens to it afterwards.
Connecting Moodle is optional and, when you do, the exchange is only between your device and your own faculty's server — the operator never sees it. Section 5a covers it. Bug reporting sends what you type, and a screenshot only if you attach one — a category, your description, the app version, and an optional picture you pick yourself. The picture is emailed to the operator and stored nowhere. Section 4 covers it. Crash reports are the one thing the app sends on its own, and they describe the app's own code — an error type, a message, and a stack trace — never you or your studies. They can be switched off in App settings. Section 4a covers them.
This is a product privacy notice written by the operator. It is not legal advice to you.
1. Who is responsible (controller)
The data controller for processing described in this notice is:
an individual developer in North Macedonia ("the operator", "we", "us").
- Contact for all privacy matters, requests, and complaints: todorovski@todorx.dev
The operator has not appointed a Data Protection Officer, and is not required to, because the processing is minimal, does not involve regular and systematic large-scale monitoring, and does not involve special-category data.
Which law this notice is written to. The app is published for the Republic of North Macedonia, for students of FINKI at UKIM, and its distribution on Google Play and the App Store is limited to that country. This notice is written to the Law on Personal Data Protection of the Republic of North Macedonia (Закон за заштита на личните податоци, Official Gazette of RNM No. 42/2020 and its amendments), and the Agency for Personal Data Protection (Агенција за заштита на личните податоци, AZLP) is the supervisory authority. Your rights under that law are in section 9.
This is not a claim that no other country's law could ever apply to you — that is not the operator's to decide, and a law that applies, applies. It is a statement of who the app is for and which rules the operator has written this notice, the app, and its backend to satisfy. Nothing here is narrower than what that law requires.
2. Data stored on your device
The app stores the following in its private local storage on your device. The operator has no copy of it, no access to it, and no ability to read, restore, or delete it. With the cloud assistant off, none of it is ever transmitted; with it on, the subset listed in section 3 is sent with each question you ask.
- your name, chosen profile avatar, major, year of study, study duration, interface language, theme, and accessibility and display preferences;
- courses, course codes, professors, ECTS values, assessment components, points, maximum points, completion paths, grades, and every derived progress or average calculation;
- tasks, priorities, estimates, due dates, calendar events, timetable choices, and rooms;
- notification and reminder settings and their scheduled times;
- map searches, selected rooms, and map interactions;
- every message you send to, and every reply you receive from, the AI Study Assistant.
Clearing app storage or uninstalling the app deletes this data from the device.
On Android the app disables backup: android:allowBackup is set to
false, and the backup rules exclude every path from both cloud backup and
device-to-device transfer. Your study data is therefore not copied to Google
Drive by Android Auto Backup and is not carried across in a device transfer.
On iPhone and iPad it works differently, and you should know it. iOS, not the app, decides what a backup contains, and the storage this data lives in is part of an ordinary iCloud or computer backup. So if you back your device up, your study data is inside that backup — held by Apple under Apple's terms. The operator still never receives it and still cannot read it. Switching FINKI LIFE off under iCloud Backup in the device's own settings keeps it out.
On either platform, a manufacturer's own full-device backup, or a copy you make yourself, is outside the operator's control.
3. The AI Study Assistant has two modes
The assistant has an on-device mode, which is the default, and an opt-in cloud mode. You choose between them in App settings → AI Study Assistant → Cloud assistant. The setting starts off, and turning it on requires confirming a dialog that states what will be sent. Turning it back off takes effect immediately and needs no confirmation.
3.1 On-device mode (default)
No message you send to the assistant, and no part of your study context, ever leaves your device. The assistant is a small, deterministic, keyword-matching routine that runs locally in the app: it reads your message, your open tasks, your next class, and your saved courses — all already on your device — and composes a reply using fixed templates. There is no server call, no network request, no third-party language model, and no API key involved at any point.
3.2 Cloud mode (only if you turn it on)
Each question is sent over HTTPS to a server function operated by the operator, which forwards it to a model routing service, which routes it to the model provider serving the selected model. The current models are a router that spreads requests across free endpoints, with a second free model as a fallback when the first is unavailable. If neither answers, your question is answered by the on-device assistant instead and the app tells you so underneath the answer.
What is sent with each question:
- the text of your question;
- your major, year of study, and study duration;
- your current-year courses: name, code, ECTS, points, maximum points, completion path, any grade you saved, and the professor you selected;
- your open tasks: title, course code, due date, priority, and time estimate;
- your upcoming classes: title, course code, start time, type, room, and professor;
- the count of your open tasks and a description of your next class;
- the current date on your device, so a deadline you describe as "Friday" resolves to the right one;
- the public campus room list from the app's offline map, and the public FINKI teaching-staff names, so the assistant answers "where is 138" and "who teaches this" from real data instead of guessing;
- the earlier messages in the current conversation, up to the most recent 16 turns, so a follow-up question makes sense on its own.
What is never sent: your name, your email, your student ID, your CAS or Moodle credentials, your device identifiers, your location, and your saved Moodle course data.
The lists above are truncated before sending — at most 40 courses, 25 tasks, 20 classes, 200 rooms, and 200 staff names, with each field length-capped. The conversation is truncated to its most recent 16 turns.
Authentication. The app creates an anonymous service account for your device. It has no email, no password, and no name, and is not linked to your identity. It exists so requests can be rate limited per device (10 per hour, 30 per day, alongside a ceiling shared by everyone using the app) rather than by anything that identifies you, and so that the provider API key stays on the server and never ships inside the app. A second ceiling counts requests by the internet address they arrive from (40 per hour, 120 per day), so that one connection cannot exhaust the allowance everyone shares. The retention note below says what those counters hold and how long they last.
Failure behaviour. If the network, the function, or the model is unavailable, or you exceed the rate limit, the app silently answers with the on-device assistant instead. It does not queue or retry your question later.
Retention by the operator. The function does not write your question, your study context, or the reply to any database. They exist only in memory for the duration of the request. The operator keeps request counts for rate limiting, keyed to the anonymous account and to the internet address the request arrived from, with no message content — no question, no reply, and nothing about your studies. Those counter rows are deleted within two days.
What the routing service and the model provider may do with it — read this before
turning cloud mode on. They handle the request under their own terms, and
the provider that answers your question may use what it is sent to train its
own models. Every request says so explicitly: it carries the instruction
data_collection: allow to the routing service, so this is a choice recorded on each
request rather than a checkbox in an account dashboard, and it is the same
choice the app's confirmation dialog describes to you before you turn the
setting on.
What that means in practice: your question, and the study context listed above — your major and year, your courses and points, saved grades, open tasks, upcoming classes, and the last 16 turns of the conversation — may be retained by that provider and used to improve its models. Your name, email, student ID, credentials, device identifiers, location, and Moodle data are never sent, so what leaves is your studies without your identity attached; but a free-text question you type yourself is sent as you wrote it, so do not type anything into it you would not hand to a company you have not chosen.
The operator cannot control or guarantee an independent provider's retention or training practices; see their notices, linked in section 6. If you do not want this, leave the cloud assistant off — the on-device assistant in section 3.1 sends nothing anywhere, and it is what the app uses until you decide otherwise.
3.3 In both modes
The conversation is held in memory only for the active screen and is discarded when you leave it or close the app. It is never written to the app's local academic database.
4. Bug reporting and crash reports
Bug reporting sends nothing unless you write a report and tap send. Crash reports are the one thing the app sends on its own, and section 4a says exactly what they contain. They are handled by a crash-reporting service, and section 4a says what that means for you and how to switch it off. There is no analytics, no advertising identifier, and no other background telemetry of any kind in the app.
What is sent when you send a report:
- the category you picked from the list;
- the description you typed, truncated to 4,000 characters;
- the app version, such as
1.0.2+11; - a screenshot, only if you attach one — see below.
What is never sent: your name, your email, your student ID, your courses, grades, tasks, timetable, assistant conversation, Moodle data, device identifiers, location, and any automatic diagnostic or stack trace. If you type personal details into the description yourself, they are sent as part of it — please do not.
The screenshot is optional and is yours to choose. The report form has an Add a screenshot button. Nothing is captured automatically and nothing is read from your gallery unless you pick a picture: you choose the one image that goes, and you can remove it again before sending. Whatever is in that picture is sent, so look at it first — a screenshot of the app can show your name, your grades, your tasks, and your timetable.
What happens to the screenshot. Before the app even reads it, the picture is scaled down to 1,400 pixels wide and re-encoded, and a picture still larger than 1.5 MB is refused rather than sent. It travels with the report over HTTPS, and the server attaches it to the one email that tells the operator a report arrived. It is not written to the database, not stored in any file storage, and not logged — the saved report is your words and no image. The app keeps no copy either: the picture is held in memory only while you are writing the report, and it is deliberately left out of the saved draft, so leaving the screen loses it. The server accepts only PNG and JPEG and names the file itself, so nothing the app sends decides what a file in the operator's mailbox is called. To have the picture gone, ask for the report to be deleted as described under Retention below; the operator deletes the email with it.
Where it goes. Over HTTPS to a server function operated by the operator, which writes the report to the operator's own database. The email that notifies the operator — carrying the same text and any screenshot you attached — is delivered by an email delivery service acting for the operator. The report is not shared with anyone else.
Authentication. The report is sent under the same anonymous service account described in section 3.2 — no email, no password, no name — so reports can be rate limited per device (5 per hour, 20 per day) rather than by anything that identifies you, with a second ceiling counting reports by the internet address they arrive from (20 per hour, 60 per day). The account identifies an installation, not a person.
Retention. Reports are kept until the issue is resolved and for no longer than 24 months, then deleted. To have a report you filed deleted sooner, email the address in section 1 with roughly when and what you sent, so it can be found — the operator cannot link a report to you from your name alone.
4a. Crash reports
You are asked about this when you first set up the app, and you can change the answer at any time. When the app hits an error it cannot recover from, it sends a description of that error so the fault can be found and fixed.
You are asked on the last page of the first-run setup, beside the agreement to this notice and to the terms — as a separate switch, because agreeing to those documents is required to use the app and sending crash reports is not.
Turning it off later. Settings → App settings → Privacy → Send crash reports. It starts switched on, and switching it off stops every crash report at once — nothing is queued and sent later. Everything else in this section describes what is sent while it is on.
What is sent:
- the type of the error, such as
StateError, and its message; - the stack trace — a list of the app's own function names and line numbers;
- where the app caught it, such as
Flutter framework error; - the app version and build, such as
1.5.0+13, and whether it was a released build or one still being worked on; - what kind of device it happened on: the model and manufacturer, how much memory was free, the screen size, the orientation, and the operating system and its version;
- the language the app was running in and the device's time zone;
- which permissions the app itself holds, such as
INTERNET, and the list of software libraries the app is built from; - the country and city worked out from your internet connection — see immediately below.
Approximate location, and why it cannot be switched off separately. The app never asks for your location, holds no location permission, and reads no GPS. It does not know where you are and never sends it. What happens instead is that The service works out an approximate place — a country and a city, such as Ohrid, North Macedonia — from the internet address your report arrives from, and stores that alongside the report. This happens on that service's own servers after the report leaves your phone, so neither the app nor the operator can prevent it while crash reports are on; the operator has asked the service not to store the internet address itself, and it does not. If you would rather not share even that, switch crash reports off using the setting above, which stops the whole report from being sent.
What is never sent: your name, your email, your student ID, your courses, grades, points, tasks, timetable, assistant conversation, Moodle data or token, contacts, advertising identifier, any screenshot or picture of your screen, any record of which screens you opened or what you tapped, and any identifier that would let two reports be recognised as coming from the same phone.
Your accessibility settings are deliberately removed. The crash-reporting library collects, by default, whether you use a screen reader, larger or bolder text, higher contrast, inverted colours or reduced motion. The app strips all of it out before the report is sent. Those settings describe a person rather than a fault, and they are nobody's business but yours.
An error message is written by the app, not by you, and the app does not put your data into one. Nothing you type is included.
When. In every version, released or under development. Reports from a version still being worked on say so in the "where the app caught it" line, so the operator can tell them apart; nothing else about them differs, and the switch above turns off both.
How often. The same fault is sent once per run of the app, and a single run never sends more than 20 reports, so an app stuck in a crash loop does not repeat itself. If your phone has no working connection when a fault happens, the report waits on the phone and is sent the next time the app runs with one; it is not sent anywhere else in the meantime, and switching crash reports off discards anything still waiting.
Where it goes. Over HTTPS to a crash-reporting service, on servers in the European Union (Germany). It stores and displays the report so the operator can read it; it acts on the operator's instructions and for no purpose of its own. Reports are not sold, not used for advertising, and not shared with anyone else. The same fault from many phones is grouped into one entry with a count rather than stored one row per occurrence.
No account, and nothing that identifies your installation. Unlike a bug report, a crash report carries no account of any kind — not even the anonymous one described in section 3.2. Two crash reports from the same phone cannot be recognised as such.
Legal basis. The operator's legitimate interests under the Law on Personal Data Protection: keeping the app working for the students who use it. What is sent describes the app's own code and the kind of device it broke on, which is what makes this balance come out in your favour. You may object at any time using the address in section 1, and the switch above lets you act on that yourself without asking anyone.
Retention. The service deletes a crash report 30 days after it arrives. The operator keeps no separate copy.
5. Data sent when the app fetches public university information
To show FINKI announcements, staff information, and the academic calendar, the app makes ordinary, unauthenticated web requests to:
- the public FINKI/UKIM website, for news, announcements, the events and the jobs and internships boards, exam-schedule links, and staff directory pages;
- FINKI's published Microsoft Outlook calendar feed, for the academic calendar;
- finki.edupage.org, the aSc EduPage service FINKI publishes its class timetable on, and only when you open Import the FINKI timetable. The app reads the published schedule the same way the public timetable page does. It sends no identifier and no study data, and you choose your study group yourself — the request does not say who you are.
These are the same kind of request any web browser makes to load a public page. They necessarily expose your IP address, user agent, and the time of the request to the server that hosts the page, exactly as they would if you visited the page yourself. The app does not attach your name, your study data, or any other identifier to these requests, and does not authenticate as you. Fetched content is cached locally so the app still works offline between refreshes.
5a. Connecting your Moodle account
Signing in to Moodle is optional. Until you do, nothing in this section happens and the app never contacts courses.finki.ukim.mk on your behalf.
How the sign-in works. FINKI authenticates through CAS, so the app does not ask for your student ID and password. It opens the faculty's own sign-in page in a browser tab, and Moodle returns a limited access token to the app afterwards. Your CAS password — the same one that unlocks faculty mail and iKnow — is never seen, stored, or transmitted by this app. The token is kept in the device's own secure store — the Android Keystore or the iOS Keychain — and can be deleted at any time with Disconnect on the Moodle screen, or with Delete my data in App settings → Privacy.
What the app reads from Moodle, using that token and no more:
- the courses you are enrolled in, with their names and codes;
- the announcements posted in those courses;
- your calendar events — assignment and quiz deadlines and other dated items;
- your marks for a course, but only when you open that course — the grade report your teacher publishes, read one course at a time rather than for everything at once;
- the list of materials in a course, but only when you open that course's materials — the names of its sections, activities, and resources, and the links back to them. The files themselves are never downloaded.
What it does with them. Your enrolled courses replace the manual course list in the Courses tab, matched against the faculty curriculum so your saved points and grades stay attached to the right subject. Your Moodle deadlines appear in the Calendar tab as read-only items, and, if you turn on task reminders, raise the same reminders your own tasks do. Marks read from Moodle are shown beside the points you entered and are copied into them only when you choose to; nothing you typed is overwritten on its own. All of it is cached in the app's private local storage so the app works between refreshes and offline.
Where it goes. Nowhere. This data is exchanged only between your device and courses.finki.ukim.mk, which is your own faculty's server. The operator never receives it and has no access to it. It is not sent to the cloud assistant: section 3.2 lists what that feature sends, and your Moodle data is not in it.
Turning it off. Disconnect on the Moodle screen deletes the token and the cached Moodle data from your device. App settings → Moodle deadlines in calendar stops the deadlines appearing without disconnecting. Clearing app storage or uninstalling removes everything.
5b. The service status check
The app asks its own backend one question on launch, and again when you reopen it after a while: has this app been paused?
The operator can stop the app, or just the cloud assistant, without publishing a new version — for a faulty release, an outage at the faculty, or a cost the operator cannot carry. The app reads a single public row holding that answer, a message explaining it, and the oldest app version still supported.
What the request carries. Nothing about you. It is a read of one public row, sent with no account, no token, and no study data. Like any web request it necessarily exposes your IP address, user agent, and the time of the request to the server, and that is the whole of it. The answer is cached on your device so a pause still holds when you are offline.
Why it is not optional. A switch you could turn off would not be a switch. It is the one thing the operator can do about a broken release once it is on your phone.
6. Recipients
| Recipient | Role | What it receives | Purpose |
|---|---|---|---|
| FINKI / UKIM public web | Independent controller | An ordinary web request: IP address, user agent, timestamp | Fetching public news, announcements, and staff information |
| FINKI / UKIM Moodle (only if you connect it) | Independent controller | Your authenticated request, carrying the access token their own server issued | Returning your courses, announcements, and deadlines |
| Microsoft (Outlook/ICS feed) | Independent controller | An ordinary web request | Fetching the published public timetable feed |
| aSc EduPage (timetable import only) | Independent controller | An ordinary web request: IP address, user agent, timestamp | Serving FINKI's published class schedule |
| Google (Play, Android) | Independent controller | Distribution, installation, and OS-level data | App distribution and platform operation |
| The operator's backend platform (cloud assistant only) | Processor | The request described in section 3.2, plus the anonymous account and rate-limit counters | Hosting the function that calls the model, and rate limiting |
| The operator's backend platform (bug reports only) | Processor | The report described in section 4, plus the anonymous account and rate-limit counters. Any screenshot you attach passes through the function and is not stored | Hosting the function and the database the report is stored in |
| Email delivery service (bug report notices only) | Processor | The email telling the operator a bug report arrived: its text, and any screenshot you attached | Delivering that email to the operator's mailbox |
| Crash-reporting service (crash reports only) | Processor | The error description in section 4a: the fault, the kind of device, the app version, and the approximate place worked out from your internet connection. No account and no identifier | Storing and displaying crash reports so the operator can find and fix faults. Servers in the European Union (Germany) |
| The operator's backend platform (service status check) | Processor | An ordinary web request: IP address, user agent, timestamp | Serving the row that says whether the app is paused |
| Model routing service (cloud assistant only) | Processor for the routing itself | Your question and study context | Routing the request to a model provider |
| The model provider the request is routed to (cloud assistant only) | Independent controller for its own training use of what it receives, processor for generating your answer | Your question and study context | Generating the reply, and — because the request is sent with data_collection: allow — training its own models on what it received |
Each of these processors publishes its own privacy notice. The operator will name the processor behind any row above, and point you to its notice, on request at the address in section 1.
No personal data is sold, rented, or shared for advertising, cross-context behavioural advertising, or any purpose unrelated to running the app. The one use by another company of anything you send is the model training described in section 3.2, which happens only if you turn the cloud assistant on, and which you are told about before you do. There are no advertising, analytics, attribution, or social SDKs in the app. The one third-party SDK it does contain is the crash reporter's, which does the work described in section 4a and nothing else — it is switched off entirely when you turn crash reports off. With the cloud assistant off and no bug report sent, the only thing the operator's backend receives is the status check in section 5b, which carries nothing about you.
7. Purposes and legal bases (Law on Personal Data Protection)
The bases below are the ones the Law on Personal Data Protection of the Republic of North Macedonia provides: consent, given by an act you take yourself and withdrawable at any time, and the operator's legitimate interests, which you may object to at the address in section 1.
| Purpose | Data | Legal basis |
|---|---|---|
| Running the app's local features, including the on-device AI Study Assistant | On-device data only | No processing by the operator occurs — the data never reaches us |
| Fetching public university feeds | Ordinary web-request metadata seen by the feed host | Legitimate interests — delivering the public information you asked for |
| Importing the published class timetable | Ordinary web-request metadata seen by aSc EduPage | Legitimate interests — delivering the public schedule you asked for |
| Showing your Moodle courses, announcements, and deadlines | Your Moodle access token and the data it returns | Consent — given by connecting your Moodle account, withdrawable with Disconnect |
| Answering your question with the cloud assistant | Your question and the study context in section 3.2 | Consent — given by turning the setting on and confirming the dialog that says the model provider may train on what is sent, withdrawable at any time by turning it off |
| Handling a bug report you send | The category, description, and app version in section 4, and the screenshot if you attached one | Consent — given by sending the report, and given separately for the picture by attaching it, withdrawable by asking for its deletion |
| Finding and fixing faults that crash the app | Everything listed in section 4a: the fault, the kind of device, the app version, the language and time zone, and the approximate place worked out from your internet connection | Legitimate interests — keeping the app working for the students who use it |
| Checking whether the app has been paused | Ordinary web-request metadata seen by that platform | Legitimate interests — being able to stop a broken or unaffordable release |
| Rate limiting the cloud assistant and bug reports to keep them available and affordable | Anonymous account id, the internet address the request arrived from, request counts | Legitimate interests — preventing abuse of a free service |
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Because nothing is retained after a request completes, there is in practice nothing left to undo.
8. Retention
| Data | Retention |
|---|---|
| Local profile, courses, grades, tasks, events, settings | On your device until you delete them, clear app storage, or uninstall |
| AI Study Assistant conversation | In app memory for the active screen only; discarded when you leave it or the app closes |
| Cached public news, staff, and calendar data | On your device, refreshed periodically, until you clear app storage |
| Moodle access token, courses, announcements, deadlines, and course material listings | On your device until you disconnect, clear app storage, or uninstall |
| Cloud assistant request and reply | Held in memory for the duration of the request; not written to any operator database |
| Marks read from Moodle | On your device, refreshed when you open a course, until you disconnect, clear app storage, or uninstall |
| A bug report you send | In the operator's database until the issue is resolved, and no longer than 24 months |
| A screenshot you attach to a bug report | Never written to the operator's database or file storage. It exists as an attachment on the notification email in the operator's mailbox, deleted with that email when the issue is resolved and no later than 24 months |
| A crash report the app sends | Deleted by that service 30 days after it arrives. The operator keeps no separate copy. Repeats of the same fault raise a count rather than adding entries |
| Cloud assistant and bug report rate-limit counters | Request counts keyed to the anonymous account and to the internet address the request arrived from; no message content. Deleted within two days |
| Anonymous cloud assistant account | Until you clear app storage or uninstall; it holds no personal data |
Apart from the rate-limit counters and the empty anonymous account, the operator receives nothing to retain, anonymise, or delete on its own systems.
9. Your rights
Under the Law on Personal Data Protection of the Republic of North Macedonia you have the right to:
- access the personal data held about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase data ("right to be forgotten");
- restrict processing in defined circumstances;
- object to processing based on legitimate interests;
- data portability for data processed by consent or contract, in a structured, commonly used, machine-readable format;
- not be subject to a solely automated decision producing legal or similarly significant effects — see section 10;
- lodge a complaint with a supervisory authority.
To exercise a right, email todorovski@todorx.dev. A response is given within one month of the request, extendable by two further months where a request is complex or there are several of them, in which case you are told about the extension and why, as the Law on Personal Data Protection allows.
An important practical limit. Your study data stays on your device, and with the cloud assistant off nothing at all reaches the operator. With it on, your question and study context pass through the operator's function but are not stored; what remains afterwards is a request counter and an anonymous account holding no personal data. The operator therefore holds essentially nothing that could be the subject of an access, rectification, or erasure request, other than what you volunteer by email. You retain full direct control over your on-device data at all times, and you can stop the cloud processing entirely by turning the setting off.
Supervisory authority. The Agency for Personal Data Protection of the Republic of North Macedonia (Агенција за заштита на личните податоци, AZLP), azlp.mk. You may lodge a complaint with it at any time, and you do not have to contact the operator first.
You will not be treated differently for exercising a right.
10. Automated decision-making, profiling, and the AI Study Assistant
The operator does not carry out profiling and does not make automated decisions that produce legal effects for you or similarly significantly affect you — the thing the Law on Personal Data Protection gives you the right not to be subject to. Nothing in the app decides anything about you at all.
On-device mode. The assistant generates text from a small set of fixed templates chosen by matching keywords in your message. It does not decide anything about you, does not use machine learning, and does not infer anything beyond matching the words you typed. It is a rule-following routine, not a model.
Cloud mode. A general-purpose language model writes the reply. Whether or not any particular law calls that an "AI system", the app tells you plainly:
- you are talking to an AI model, and you are told so before you turn the setting on, in the setting itself, and in this notice;
- its output is generated text and may be wrong, out of date, or invented, and it is presented as assistance only, never as an authoritative record;
- it is not used to evaluate learning outcomes, determine access to education, assign grades, or monitor examinations, and it must not be.
Regardless of that classification, the assistant is not, and must not be used as, a substitute for official academic advice. It is not used, and must not be used, to determine or influence admission, assessment, grading, progression, financial aid, discipline, employment, or any comparable outcome.
11. International transfers
With the cloud assistant off, the app transfers no personal data out of the country on your behalf. The public feeds described in section 5 are hosted by FINKI/UKIM (North Macedonia) and Microsoft; loading them works the same as visiting those pages in a browser and is not a transfer of your personal data by the operator.
Bug reports and the service status check reach the operator's backend platform, which is hosted in the European Union (eu-west-1). Crash reports go to a crash-reporting service, whose servers for this account are in the European Union (Germany). Neither is a transfer outside the European Union. With the cloud assistant on, the request described in section 3.2 goes further: The routing service and the model providers it routes to operate from the United States and other countries.
North Macedonia's Law on Personal Data Protection allows a transfer to another country on the basis of your consent, given after being informed of the risk. That is the basis the cloud assistant rests on: it is off until you turn it on, and the dialog that turns it on tells you what is sent, where it goes, and that the provider may train on it. The processors also apply their own transfer safeguards, described in the notices linked in section 6. If you would rather nothing left your device at all, leave the cloud assistant off.
12. Children
FINKI LIFE is intended for university students in North Macedonia and is not directed to children. Under the Law on Personal Data Protection, a person may consent to an information society service on their own from the age of 14; below that age the consent of a parent or guardian is required. The app is aimed at neither group — it is built around a university curriculum and presupposes enrolment — and the operator does not knowingly collect personal data from a child. In practice it collects none from anyone beyond what stays on the device, unless a feature described above is switched on. If you believe a child has provided personal data, contact todorovski@todorx.dev.
13. Security
The operator applies measures proportionate to a small, free, single-developer app:
- study data stays in the app's private local storage, and is transmitted only for a cloud assistant question you asked for;
- the app holds no provider API key. That key lives only in the server-side function's secret storage;
- the anonymous session token and the Moodle token are kept in the device's own secure store — the Android Keystore or the iOS Keychain — and not in ordinary app preferences;
- all calls to the operator's functions use HTTPS/TLS, and each function rejects requests without a valid token, above the rate limits, or over its own size limit — 64 KB for the assistant and about 2.1 MB for a bug report, which is what one downscaled screenshot costs beside the text;
- crash reports do not pass through the operator's functions at all; they go straight to the crash reporter over HTTPS/TLS;
- fetching public FINKI/UKIM and Microsoft feeds uses HTTPS/TLS where the source supports it.
No system is completely secure. A device that is lost, stolen, or otherwise compromised may expose the local data described in section 2. Protect your device with a lock screen and keep its operating system up to date.
14. Changes to this notice
This notice may change when the app or the law changes. The version number and effective date will be updated and the revised text published at the location linked from the app. Where a change materially expands the use of personal data, notice will be given or consent obtained as the law requires.
Version 5.5 corrects two statements of fact. Section 12 said the app is not directed at anyone under 16 and called 16 the age at which a person may consent to an online service on their own under the Law on Personal Data Protection. That age is 14, not 16. The app is aimed at university students either way, and nothing about what it collects changed; the notice simply stated the law wrongly, and a notice that misdescribes the law is not one you can rely on. Section 13 said the session token is kept in the Android keystore, which stopped being the whole truth when the app was published for iPhone: it is the Android Keystore or the iOS Keychain, and the Moodle token is kept there too.
Version 5.4 records that the app is published for iPhone and iPad as well as for Android, and says what that changes. One thing genuinely differs: Android lets an app refuse to be backed up and this app refuses, while on iOS the operating system decides, so your study data is inside an iCloud or computer backup if you make one. Section 2 now says so and says how to keep it out. Nothing about what the app sends, to whom, or for how long it is kept differs between the two platforms. The distribution is still limited to the Republic of North Macedonia on both stores, and this notice is still written to Macedonian law.
Version 5.3 corrects what this notice said about rate limiting, and changes nothing about the app or the backend. Earlier versions said requests were counted per device rather than by IP address, and that the counters held a truncated address kept for the length of the counting window. Neither was accurate. The backend counts requests both per anonymous account and per internet address, it stores that address in full, and it deletes the counter rows within two days. It has always worked this way; only this notice was wrong (sections 3.2, 4, 7 and 8). The counters hold no question, no reply and nothing about your studies, and they are used for nothing but refusing a request that is over a ceiling.
Version 5.3 also publishes a change made in the app on 11 September 2026 that the published 5.2 never carried: you are asked about crash reports during the first-run setup, on the page holding the agreement to this notice and to the terms, as a separate switch beside it. Before that the setting was simply on from installation and could only be found later in App settings. It is still on unless you say otherwise, and it is still switchable in the same place (section 4a).
Version 5.2 changes how this notice names the companies that process data for the operator, and changes nothing about what they receive or what they do with it. Where earlier versions named each provider, this notice now describes it by the job it does — a backend platform, a model routing service, a crash-reporting service, an email delivery service. What each one receives, what it does with it, how long it keeps it, and which country its servers are in are all stated exactly as before. The operator will name any of them, and point you to that company's own privacy notice, on request at the address in section 1. No processing, no retention period and no legal basis has changed.
Version 5.1 records one change: crash reports now go to a crash-reporting service, on servers in the European Union, instead of to the operator's own database (sections 0, 4, 4a, 6, 7, 11 and 13). Three things follow from it, and the second is the reason this is a change worth reading. First, a crash report now says what kind of device the app broke on — the model, the maker, the free memory, the screen — which it did not before. Second, The service works out a country and city from the internet address the report arrives from and stores it; the app still never reads your location, and the operator has asked it not to keep the address itself, but the approximate place is kept, and the only way to prevent it is to switch crash reports off. Third, a report is now deleted after 30 days rather than being kept for up to 24 months. What is not sent has grown: your accessibility settings, which the crash-reporting library collects by default, are stripped out before anything is sent.
Version 5.0 records two changes, and one of them matters more than anything this notice has recorded before.
The model provider that answers a cloud question may now train on what it is sent (sections 3.2, 6, 7 and 11). Until this version every request told the routing service to refuse any provider that trains on inputs, and this notice said so. It now says the opposite, because the request now says the opposite. Nothing about this reaches you unless you turn the cloud assistant on: it is off when you install the app, turning it on requires confirming a dialog that states this in the same words, and turning it off returns you to an assistant that sends nothing anywhere. If you had cloud mode on before this version, turn it off if this is not what you agreed to — the setting is in App settings → AI Study Assistant.
This notice is now written to Macedonian law alone. Earlier versions were written to the EU General Data Protection Regulation with the Macedonian Law on Personal Data Protection beside it. The app is published for the Republic of North Macedonia and its Play Store distribution is limited to that country, so the notice now cites the Macedonian law, names the Agency for Personal Data Protection as the supervisory authority, and drops the EU-specific citations. No right you had was removed and no processing was widened by that change — the two laws grant the same rights, and everything else in this version does what version 4.2 did.
Version 4.0 replaced version 3.0, which described the AI Study Assistant as running only on the device, by adding the optional cloud assistant described in section 3.2. It is off by default: unless you turn it on, the behaviour described in version 3.0 still applies to you unchanged.
Version 4.2 records one change, which happens only if you use it: a bug report can carry a screenshot you attach yourself (section 4). Nothing is captured automatically, the picture is emailed to the operator and stored nowhere, and a report sent without one behaves exactly as it did in version 4.1. The same section now also names the email delivery service that delivers the operator's notification email, in the recipients table in section 6.
Version 4.1 records four changes, each of which happens only if you use the feature:
- bug reporting works again (section 4), sending only the category, your description, and the app version;
- the class timetable can be imported from FINKI's published schedule on aSc EduPage (section 5);
- your Moodle marks are read when you open a course, and shown beside the points you entered rather than replacing them (section 5a);
- the cloud assistant now also sends the current conversation, the public campus room list, and the public staff names, so a follow-up question and a room question can be answered properly (section 3.2).
15. Contact
Privacy questions, requests, and complaints: todorovski@todorx.dev
Official references
- Law on Personal Data Protection of the Republic of North Macedonia (Закон за заштита на личните податоци), Official Gazette of RNM No. 42/2020 and its amendments
- Agency for Personal Data Protection of the Republic of North Macedonia (AZLP)