Asarus

Privacy Policy FidiBox

Last updated : August 21, 2026

This privacy policy applies specifically to the FidiBox mobile application, published by Asarus. It is distinct from the general privacy policy of the asarus.fr website.

Data controller

SAS Asarus
90 bis rue de Fougères, 35700 Rennes

1. About this application

FidiBox is an Android mobile application built with Flutter by Asarus, designed to keep your loyalty cards (barcodes and QR codes) directly on your phone.

  • App name: FidiBox
  • Publisher: SAS Asarus
  • Android package identifier: com.asarus.fidibox
  • Platform: Android (Flutter)

2. Data we collect directly

FidiBox has no user account, no server and no synchronization. We, the publisher, collect no personal data: your cards, images and settings stay on your device and never reach us. The only collection that exists in the app is Google's advertising collection, described in section 7, and the in-app purchase removes it entirely.

FidiBox is not intended for and not directed at children under 13. We do not knowingly collect any data about them.

3. Offline operation and local storage

Your loyalty cards (barcodes, QR codes) are stored only locally on your device, using the local Hive database. They leave your phone only if you yourself trigger a backup export.

4. Importing cards

FidiBox lets you import cards from several sources: a Catima export, a Fidme archive, photos from your gallery, or manual entry. This import is processed locally on your device: the files and photos used are neither sent to nor stored on a server.

5. Backup and export

You can export a backup of your cards at any time. This export uses Android's native share system: you choose where to send the file (email, personal cloud storage, etc.). Asarus never has access to this file.

6. Android permissions used

FidiBox requests the following permissions:

  • Camera (CAMERA): to scan the barcodes and QR codes of your cards.
  • Network access (INTERNET, ACCESS_NETWORK_STATE): to load the ads shown in the app.
  • Biometrics (USE_BIOMETRIC, USE_FINGERPRINT): to lock access to the app with your fingerprint or face recognition, if you enable this option.
  • Advertising permissions (ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_TOPICS): standard permissions on recent Android versions, used by the Google AdMob advertising SDK.
  • Advertising ID (AD_ID): used by Google AdMob to serve the banner, see section 7.
  • Billing (BILLING): required for the "remove ads" in-app purchase, see section 7.

7. Advertising (AdMob) and in-app purchase

FidiBox displays a banner ad provided by Google AdMob and offers a single one-time in-app purchase (no subscription) to remove ads.

To serve the banner, Google collects and processes your Android advertising ID, a resettable identifier you can reset or delete in your phone's settings (Settings, Google, Ads), technical data about your device and its configuration, your IP address and therefore an approximate location, and information about the ads shown and your interactions with them.

This data is collected by Google, not by us: we have no access to it. It may be shared with Google's advertising partners for serving, measurement and fraud prevention. Google acts here as an independent data controller, and its policy applies (link below).

Your consent. On first launch, FidiBox shows you a GDPR-compliant consent form, provided by Google's consent management platform. There you choose whether your data may be used to personalise ads. Declining does not prevent you from using the app: ads are then shown in a non-personalised form.

You can change that choice at any time, under the app's Settings, "Privacy and ads". The same form reopens there.

The transaction is handled by Google Play Billing. We never see your payment details, your name or your address: Google tells us only that a valid purchase exists. The app keeps nothing but a local "ads removed" flag, and the purchase permanently removes the banner along with all the collection described above.

Google Privacy Policy

8. Biometric lock

The biometric lock relies entirely on the security mechanisms provided by the Android system. Neither FidiBox nor Asarus has access to your biometric data, which remains managed by your device.

9. Sharing data with third parties

Other than the Google AdMob SDK mentioned above, FidiBox does not share any data with third parties. No data is sold.

10. Security

Your cards are stored locally on your device. Their protection therefore also depends on your phone's own security measures (screen lock, biometrics). We recommend enabling the app lock if your device is shared.

11. Your rights

Since Asarus does not collect or retain any data about you, there is no processing on our part over which to exercise a right of access, rectification or erasure: your data stays under your sole control, on your device. To delete it, use the app's delete or archive features, or uninstall it. For any question, you can write to us at the address above.

You may also lodge a complaint with your national data protection authority. In France this is the CNIL.

Contact the CNIL

12. Changes to this policy

This policy may change, in particular when a feature is added. Any significant change will be indicated on this page, with an updated date.