Privacy notice
Last updated 2026-08-27.
Who is responsible
The data controller is Elisoft EOOD (ЕЛИСОФТ ЕООД), UIC 206008244, VAT BG206008244, zh.k. Trakia, bl. 175, vh. V, et. 2, ap. 5, 4023 Plovdiv, Bulgaria. APK Rescue is a trading name of that company. Write to [email protected] about anything on this page.
What we collect
This website sets no cookies, and loads nothing that sets one. It asks you for nothing in order to read it.
It counts two things, both of them on our own server as it answers your request: that a page was opened, and that a message was sent through the form or failed to send. Each count carries which page it was and your country, and that is the whole record.
Nothing runs in your browser to do this. There is no analytics script on this site, nothing is stored on your device, and nothing is read from it — not a cookie, not local storage, not your scroll position, not the address of the page you came from. The page and the country come from the request your browser already had to make in order to be sent the page.
That decides something we would rather have had. We cannot tell whether you read as far as the prices, or started filling in the form and stopped — the questions any site would like answered. Measuring them means watching your browser and reporting back, and European law treats that as reaching into your device whether or not the result names you. So we do not.
Because there is no identifier of any kind, these are events and not people: someone who opens the page twice is two counts. We cannot tell one reader from another and we do not try. The one honest exception is the count for a message being sent, which sits in the same minute as the message itself — that one we could connect to you, and we treat it as part of your enquiry.
The contact form collects only what you type into it: your name, your email address, an optional Play Store link or package name, and your message. It has no attachment field — please do not send code, signing keys, passwords or access tokens through it. We do not store the form message on this website. It is turned into an email and lives in our mailbox from then on, exactly like an email you had written yourself. A copy also stays with Resend, the provider that delivers it for us, which ages out on Resend's own schedule — 30 days on its standard plans — and is deleted within 90 days if we close the account.
The form is protected by Cloudflare Turnstile, a spam check that replaces a captcha. To run it your browser loads a script from Cloudflare, and your IP address, your browser's user agent and a fingerprint of how it connects, together with a token, are sent to Cloudflare so it can tell a person from a bot. We do not receive or keep the result beyond “passed” or “did not pass”. Turnstile is the only thing this page loads from a server other than the one hosting the site. It runs when you first use the form, not when you open the page — if you never touch the form, nothing is sent to the spam check at all. Cloudflare also hosts this site, so opening any page reaches them either way — the check is the part you can avoid.
If you email us, we hold what you chose to send: your name and email address, whatever you wrote, and anything you attached or linked — typically a Play Store link, a repository, or a build.
Why, and on what legal basis
- To answer you and prepare a triage or a quote — Art. 6(1)(b) GDPR, steps taken at your request before a contract.
- To perform the work and invoice it, if we go ahead — Art. 6(1)(b) GDPR.
- To keep accounting records Bulgarian law requires us to keep — Art. 6(1)(c) GDPR.
- To see whether this page works — how often it is opened, and how often someone writes to us — Art. 6(1)(f) GDPR. Our legitimate interest is knowing whether the site is worth keeping, measured without identifying anybody.
- To stop the contact form being used by bots — Art. 6(1)(f) GDPR. Our legitimate interest is not receiving automated spam through a form we have to read.
Your code and your app
Anything you send us about your app is treated as confidential. We do not publish it, share it, or reuse it for another client. We will not write about your app publicly without asking you first, in writing, for that specific piece of writing.
If you grant us access to your Play Console or your repository, grant the least permission that lets the work happen, and withdraw it when the work ends. We will tell you the minimum we need.
Who else sees it
Cloudflare, which hosts this website, runs the Turnstile spam check and passes the form on; Resend, which delivers the form as an email; our email provider, which hosts the mailbox; and our accountant, who processes invoices. They act on our instructions. We do not sell data and do not use it for advertising.
The page counts stay with Cloudflare. Cloudflare does not publish where Workers Analytics Engine keeps them, and the setting that would pin it to a region is not on the plan this site uses — so we cannot promise you they never leave the EU. What we can tell you is what is in them: a page, a country, and a number. Where Cloudflare does process them outside the EU, its data processing agreement incorporates the European Commission's Standard Contractual Clauses — the same kind of safeguard named below for our email delivery.
Resend processes email in the United States, so a message you send through the form is transferred there. Resend relies on the EU-U.S. Data Privacy Framework and, where that does not apply, on the European Commission's Standard Contractual Clauses — Art. 46(2)(c) GDPR. Ask us and we will point you at the current copy of those clauses. Apart from that, from the page counts above, and from anything our email provider does under the same safeguards, your data stays in the EU or the EEA.
How long we keep it
The page counts: a page being opened is only a count, with nothing in it that points at a person, so there is nothing to delete and nothing to give you a copy of. The count for a message being sent or failing to send is different, as the section above says: it sits beside a message we do know about, and we treat it as part of that enquiry. Cloudflare holds all of them for three months and then they are gone.
The spam check: we keep nothing from it — only whether it passed, and only for the moment it takes to accept or refuse your message. What Cloudflare keeps is on Cloudflare's own terms; it does not publish a retention period for Turnstile, so we will not state one for it.
Enquiries that do not become work: deleted within 12 months. Client correspondence and project material: for the duration of the engagement and 5 years after, so we can answer questions about work we did. Invoices and accounting records: as long as Bulgarian tax and accounting law requires.
Your rights
You may ask for a copy of your data, ask us to correct or erase it, ask us to restrict or stop processing it, and ask for it in a portable form. Write to [email protected] and we will answer within one month.
Separately, you have the right to object. The page counts described above run on our own legitimate interest, not to answer you and not because the law requires them. You may object at any time, on grounds relating to your situation — Art. 21(1) GDPR. Let us be plain about what that can and cannot do here. The counting happens on our server while it answers your request, and nothing in a count identifies you, so we have no way to recognise your future visits and leave them out — there is no browser setting that changes it either, and we will not pretend otherwise. What an objection can do is reach the counting itself: write to us and tell us why. We will weigh it, and unless we have compelling grounds that override your reasons we will stop — and because we cannot single you out, the only way we can stop is for everyone. You can also ask us what is being counted, and we will tell you.
The same applies to the spam check. It also runs on our legitimate interest rather than to answer you, and you may object to it on the same grounds. Write to the address above and we will take your message another way.
If you think we have handled your data wrongly, you can complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), cpdp.bg, or to the supervisory authority in your own country.
Changes
If this notice changes, the date at the top changes with it.