Privacy Policy

Last updated: 16 July 2026

1. Data Controller

The data controller within the meaning of the GDPR is the provider named in the app's legal notice (Impressum). Full contact details can be found there.

2. Hosting and Backend Infrastructure

Our App communicates with a proprietary server backend. This backend and the associated database (PostgreSQL) are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server location is Frankfurt am Main, Germany.

Processing is based on our legitimate interest in the secure and efficient provision of the App (Art. 6(1)(f) GDPR). We have entered into a data processing agreement (DPA) with Hetzner.

On our servers we store the following data:

All of the above data is stored until your account is deleted. For security purposes, server log files (including IP addresses) may be temporarily processed and are automatically deleted after a few days.

3. Registration and Login (Firebase Auth)

We use Firebase Authentication for user authentication, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you sign in with your Google or Apple account, we receive access to the email address stored in your account and a unique authentication ID (UID) to create and manage your profile. This data processing is carried out for the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.

The Firebase UID is stored until your account is deleted. Firebase may process data on servers in the USA. Google is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection.

4. Push Notifications (Expo & FCM)

When you enable push notifications, a unique, anonymised device ID (push token) is generated and stored on our server in Germany. Our server sends the notification via the Expo Push API (BriteSnow LLC) and Firebase Cloud Messaging (FCM), which delivers it to your device. The legal basis is your explicit consent (Art. 6(1)(a) GDPR).

The push token is stored until your account is deleted. You can disable push notifications at any time in the app settings; your token will be deactivated immediately.

5. Error Analysis and Crash Reporting (Firebase Crashlytics)

To improve stability and fix errors, we use Firebase Crashlytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

In the event of an app crash or error, technical diagnostic data is automatically transmitted to Firebase Crashlytics, including device type, operating system version, app version, error messages, and stack traces. No personal content (e.g. watchlist data, email addresses) is transmitted. Firebase Crashlytics uses a randomly generated installation ID to associate crash reports.

The legal basis is our legitimate interest in the stability and error correction of the App (Art. 6(1)(f) GDPR). Google is certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection pursuant to Art. 45 GDPR. Crash data is automatically deleted after 90 days.

6. Premium Services and In-App Purchases

When you purchase premium features, payment processing is handled directly by the Google Play Store or Apple App Store. To manage premium access, we use RevenueCat (RevenueCat Inc., USA).

RevenueCat processes pseudonymised app user IDs and purchase receipts to activate your premium status. We do not process or store any bank or credit card data.

Data transfer to the USA is based on EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR. RevenueCat is additionally certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection pursuant to Art. 45 GDPR. The legal basis for processing is the performance of the user agreement (Art. 6(1)(b) GDPR).

7. Public Profile and Community

The App includes community features (profiles, following, member search). Every profile has a visibility setting: “Public”, “Friends only” or “Private”. For accounts created on or after 16 July 2026, visibility is set to “Public” by default.

With the “Public” setting, your profile is visible to all signed-in users of the App and can be found via the member search and in suggestion rows. The following is visible:

Regardless of the visibility setting, your diary, your statistics, and your monthly and annual recaps are not accessible to other users; only you can view this data. Your email address is never shown to other users. Reviews and community lists you publish, however, are public irrespective of this setting.

If your profile is public, other users can follow you. A follower record is stored in the process (who has been following whom, and since when); it appears in the follower and following lists of both profiles, is announced to the followed user as a notification, and causes your activity to appear in the follower's feed. Following is one-sided and requires no confirmation. You can remove followers at any time, and unfollowing is possible at any time.

With “Friends only”, the profile data listed above is visible solely to confirmed friends; with “Private”, only to you. In both cases your profile cannot be found via the member search and cannot be followed. You can change the visibility at any time in your profile; the change takes effect immediately.

Accounts created before 16 July 2026 were not automatically switched to “Public”. They retain their existing setting and are asked once within the App whether they wish to make their profile public.

The legal basis for providing the community features is the performance of the user agreement (Art. 6(1)(b) GDPR). Where you make your profile public yourself, processing is based on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future by changing the visibility. For newly created accounts, the default public visibility is based on our legitimate interest in discoverable community profiles (Art. 6(1)(f) GDPR); you may object to this processing at any time by changing the visibility (Art. 21 GDPR).

8. No Sharing for Advertising Purposes

We do not share your personal data with third parties for advertising purposes. Data is only shared with the service providers named in this policy and only to the extent necessary for providing the App.

9. Data Deletion and Account Management

You can delete your account and all associated data (watchlist, settings, push tokens, Firebase UID) at any time. To do so, go to the app settings and select the account deletion option. Your data will be immediately removed from our database at Hetzner and from Firebase Auth.

10. Your Rights

You have the right at any time to:

For enquiries, please contact the email address provided in the imprint.

Language Version

This privacy policy was originally written in German. In the event of any contradictions or discrepancies between the translated and the German version, the German version shall be exclusively legally binding.