Version 1.7 - Last updated: 1 August 2026
Loopelo is a mobile application and website operated as a service that connects parents and guardians to exchange children's items, access personalized educational content, discover family-friendly places and activities, chat with an AI parenting assistant ("Lena"), and track their environmental impact. Together, the mobile application and website form the "Service".
This Privacy Policy describes what personal data we collect, why we collect it, how we process it, who we share it with, how long we keep it, and what rights you have. We process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the German Federal Data Protection Act (BDSG), the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG, formerly TTDSG), the Austrian Data Protection Act (DSG), the Swiss Federal Act on Data Protection (revFADP/nDSG), the Estonian Personal Data Protection Act, and other applicable data protection laws.
Loopelo is also subject to the Digital Services Act (Regulation (EU) 2022/2065, "DSA") and the AI Act (Regulation (EU) 2024/1689). Where relevant, we identify the obligations these instruments place on us.
If a term appears in capitalized form, it has the meaning given in our Terms of Service.
The controller within the meaning of the GDPR is:
NexTechnologies OÜ
Tartu mnt 67/1-13b
Kesklinna linnaosa, Tallinn
10115 Harju maakond, Estonia
Estonian Commercial Register (Äriregister), registrikood 17533344
Authorised member of the management board: Dr. Mohammad Amin Yazdi
Email: [email protected] · Phone: +49 176 34691656
Loopelo is the product name of the service provided by NexTechnologies OÜ.
Data Protection Officer. We have assessed our processing activities under Art. 37 GDPR and have determined that the appointment of a Data Protection Officer is not currently mandatory. Privacy enquiries should be addressed to the email above. We will reassess this designation as our processing scale evolves and will publish a DPO contact here if a designation becomes mandatory.
EU representative. Because the controller is established in the European Union (Tallinn, Estonia), Article 27 GDPR does not require a separate Union representative.
Swiss representative. If you are located in Switzerland, you may direct enquiries to the email above. We will appoint a Swiss representative under Art. 14 nFADP if and when our Swiss user base requires it.
If you choose to add a child profile to your account, we process the following data about the child:
Children's profiles are never visible to other users. They are used only to personalize content shown to the parent. See Section 10 for our broader children's-data approach.
Location permission may be withdrawn at any time in your device's system settings. The Service will fall back to your manually entered zip code.
If you choose to verify a phone number, we process and store the number for the purpose of verification and identity assurance. Verification messages are delivered via Amazon Web Services Simple Notification Service (AWS SNS). Phone verification is optional. If you remove your phone number, the stored value and any verification metadata are deleted.
Message encryption. Message content (1:1 chats, community group chats, and Lena conversations) and images sent in chats are encrypted in transit and stored encrypted at rest using application-level encryption; the encryption key is held separately from the database. Loopelo staff cannot read message content in normal operation: decryption in our administration interface requires a deliberate, time-limited unlock that is recorded in an audit log, and is used only for safety reviews (for example, when you report a chat and choose to include its history for review) and to comply with legal obligations.
Loopelo does not receive your payment-card details. All in-app purchases (subscriptions and credit packs) are processed by Apple App Store and Google Play Store, which act as payment merchant of record (Vertragspartner für die Bezahlung) and remit applicable Value-Added Tax in your country of residence.
If you offer items as a trader within the meaning of Article 3(f) DSA, we additionally collect and may publicly display: business name, business address, VAT identification number, and business registration number. This data is processed under Article 6(1)(c) GDPR (legal obligation under DSA Article 30).
If you request management of a listing as the operator of a place or the organiser of an event through our claim form ("Claim your listing"), we collect: your name, the business name, optionally your role, your email address, optionally your phone number, your message, and the IP address of the submission. We use this solely to verify that you belong to the business, to reply to you, and then to unlock management of the listing for you. We process the IP address to prevent abuse (limiting automated bulk submissions). A Loopelo account is not required to submit a claim, but is required to manage a listing afterwards.
We process the personal data described in Section 3 on the following lawful bases under Article 6 GDPR:
| Processing purpose | Lawful basis |
|---|---|
| Account creation, authentication, account administration | Art. 6(1)(b) - performance of the contract |
| Item listing, exchange, messaging between users (including community group chats) | Art. 6(1)(b) - performance of the contract |
| Local item matching using zip code and zip-centroid coordinates | Art. 6(1)(b) - performance of the contract |
| Use of GPS to derive your zip code (only when you grant location permission) | Art. 6(1)(a) - your consent (the device-permission grant constitutes the consent action) |
| Lena AI conversational assistant | Art. 6(1)(a) - your explicit consent on first use |
| AI-assisted toy photo analysis (suggested categorisation, weight, carbon-footprint estimate) | Art. 6(1)(b) - performance of the listing contract |
| AI-assisted event-form auto-population from a flyer photo | Art. 6(1)(b) - performance of the contract; for any third-party personal data printed on the flyer, Art. 6(1)(f) - legitimate interest, balanced against the manifestly public nature of the data on the flyer |
| NSFW content moderation of uploaded photos and of images sent in message threads | Art. 6(1)(f) - legitimate interest in preventing harmful content and protecting minors |
| Child-safety review, evidence preservation and law-enforcement reporting | Art. 6(1)(c) - legal obligation (in particular Art. 18 DSA); Art. 6(1)(f) - legitimate interest in platform safety and the protection of minors |
| In-Service recommendations based on your interactions | Art. 6(1)(b) and (f) - performance of the contract and our legitimate interest in providing relevant content |
| Push notifications you have subscribed to | Art. 6(1)(b) - performance of the contract |
| Promotional notifications and emails (where applicable) | Art. 6(1)(a) - your consent (revocable in-app at any time) |
| Reviews and trust signals | Art. 6(1)(f) - legitimate interest in transparent community trust |
| Reports, blocking, and platform-safety actions | Art. 6(1)(f) - legitimate interest in service safety; Art. 6(1)(c) - legal obligations under DSA |
| Tax records and statutory accounting retention | Art. 6(1)(c) - legal obligation (in particular § 147 AO; § 257 HGB) |
| Trader transparency disclosures | Art. 6(1)(c) - legal obligation under DSA Article 30 |
| Defending and asserting legal claims | Art. 6(1)(f) - legitimate interest |
| Handling listing-claim requests (operators / organisers) | Art. 6(1)(b) - pre-contractual steps taken at your request; Art. 6(1)(f) - legitimate interest in the accuracy of our listings and in preventing abuse (IP address) |
Where processing relies on consent (Art. 6(1)(a)), you may withdraw your consent at any time without affecting the lawfulness of any prior processing. The mechanism for withdrawal is the same as the mechanism for granting (Art. 7(3) GDPR): toggles in your in-app settings, or the OS-level location permission, as the case may be.
Where processing relies on legitimate interest (Art. 6(1)(f)), you may object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). For direct-marketing communications, your right to object is absolute (Art. 21(2)) and is exercised through the in-app notifications toggle.
Lena is an AI conversational assistant that uses Google's Gemini API. When you interact with Lena, the following data is sent to the Gemini API for the purpose of generating a response:
Note on the nickname and free text. The nickname transmitted to Gemini is the name you freely chose and which is labelled "Nickname" in the app; it need not be your child's real name, and we expressly recommend using a pseudonym. Because your messages to Lena are transmitted verbatim, anything you type into the chat also reaches the Gemini API. Please do not enter your child's real name or other directly identifying data into the chat.
We use Google's paid Gemini API (generativelanguage.googleapis.com with billing enabled). Per Google's Gemini API Additional Terms, paid-tier inputs and outputs are not used by Google to train Google's AI models or improve Google's products.
Lena is presented with an in-app disclosure on first use; your continued use after this disclosure constitutes your consent under Art. 6(1)(a) GDPR. Using Lena may cost credits; the applicable credit cost is shown to you in the app. Lena does not provide medical, legal, or financial advice. This disclosure satisfies our obligations under Article 50 of Regulation (EU) 2024/1689 (AI Act), applicable from 2 August 2026.
When you upload photos for an item listing, we send the images to Google's Gemini API to suggest a category, an approximate weight, a material classification, and an environmental-impact (carbon-footprint) estimate. Suggestions are advisory; you can edit them before publishing.
When you create an event, you may optionally upload a photo of a printed flyer or poster. We send this image to Google's Gemini API, which extracts text fields (event name, description, date, time, location) and returns the result for you to review and edit before saving. The extraction is advisory; nothing is published without your confirmation. If, after creating the event, you choose to attach the flyer image as the event's display picture, it is then treated as ordinary User Content under our Terms of Service. If you do not attach it, the image is discarded after extraction.
Third-party data on flyers. A flyer may incidentally contain personal data of third parties (for example, an organiser's name, telephone number or email address that has been printed publicly on the flyer). To the extent we process such data through the extraction step, we rely on Article 6(1)(f) GDPR (our legitimate interest in providing the event-creation feature, balanced against the manifestly public nature of the data on the flyer). You are responsible for ensuring that you have the right to use the flyer image and that uploading it does not infringe third-party copyright, trade-mark, personality or other rights (see Section 8 of the Terms of Service).
We use Amazon Web Services Rekognition to scan uploaded item photos for adult, suggestive, or otherwise inappropriate content. Where a photo is flagged, the listing is held for human administrator review before publication. No automated decision producing legal effects (Art. 22 GDPR) is taken on the basis of NSFW detection alone.
Images sent in chats. In addition to item photos, every image sent in a message thread (1:1 and community group chats) is automatically screened by Amazon Web Services Rekognition for content that violates our guidelines. Where an image is flagged, it is hidden from the conversation, an internal report is created for human review, and the sender is informed. Only the image being screened is transmitted to Rekognition - never any message text.
Child safety. We do not tolerate child sexual abuse material (CSAM) or any content that endangers minors. Under Regulation (EU) 2021/1232 (as extended), we voluntarily screen images shared in chats using the automated system described above; suspected child-safety content is always reviewed by a human before final action. Where our review substantiates a child-safety concern, we preserve the relevant content as evidence in a restricted quarantine, remove it from distribution, and may report it to the competent law-enforcement authorities in line with our legal obligations, including Article 18 of the Digital Services Act (Regulation (EU) 2022/2065). Legal bases: Article 6(1)(c) GDPR (legal obligation) and Article 6(1)(f) GDPR (legitimate interest in platform safety and the protection of minors). In these cases we may refrain from informing the affected account where informing it would jeopardise an investigation.
We display personalized recommendations for items, articles, places, and communities. The main parameters our recommender uses are, for each content type: your zip-centroid location, your interests and household tags, the age range of your children's profiles, your past interactions (views, likes, bookmarks), and the freshness and proximity of the candidate content. You can influence the recommendations by editing your interests, your children's age range, and by interacting with content. This disclosure addresses our obligations under Article 27 of the Digital Services Act.
Sponsored places. Among place recommendations, we may include a limited number of sponsored places - businesses that pay to be promoted within the Service. Sponsored places are clearly labelled "Sponsored" in the app. They are shown only when they fall within a fixed distance of your area, and their ordering is determined by their proximity to you, your selected interests, the age-appropriateness of the place for your family, and the agreed level of promotion. Sponsored placement never overrides our safety rules, and we do not share your personal data, or your children's data, with the sponsoring business. The corresponding contractual terms are set out in the "Sponsored and promoted places" provision of Section 7 of the Terms of Service.
Carbon-footprint values shown for items are AI-generated estimates and have not been independently verified. They are provided for orientation only and should not be relied upon for any commercial or regulatory purpose.
None of our AI or algorithmic systems take decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of Article 22 GDPR. Trust signals (reviews, reports) inform human-in-the-loop moderation but never automatically suspend an account.
We share personal data with the following categories of recipients and named processors, each bound by a data processing agreement that complies with Article 28 GDPR:
| Provider | Purpose | Data sent | Country |
|---|---|---|---|
| Google LLC - Gemini API | AI features (Lena, item photo analysis, event-flyer extraction, embeddings) | Conversation text (verbatim), item photos, event-flyer photos, context block (child nickname, approximate age, gender) | United States (with EU regional endpoints where available) |
| Google LLC - Maps & Places Platform | In-app maps and place / address information | Map tile and place requests (device IP, place / coordinate queries) | United States |
| Hetzner Online GmbH | Server hosting and storage (application, database and user-uploaded media such as item photos, avatars, message images) | All data stored on our servers in the Service | Germany (Nuremberg), EU |
| Cloudflare, Inc. | Content delivery network, web application firewall and reverse proxy (delivery, DDoS/attack protection, traffic routing) and encrypted off-site backups via Cloudflare R2 | IP address and request metadata (in transit); encrypted backup copies of the database and user-generated media | United States |
| Amazon Web Services - Rekognition | NSFW content moderation | Uploaded item photos and images sent in message threads (no message text) | EU (Frankfurt) |
| Amazon Web Services - Simple Notification Service (SNS) | SMS verification codes | Phone number, verification code | EU (Frankfurt) |
| Amazon Web Services - Simple Email Service (SES) | Transactional email (verification, password reset, notifications) | Email address, message body | EU (Frankfurt) |
| RevenueCat, Inc. | Subscription management and entitlement webhooks | Pseudonymous user identifier, subscription events | United States |
| Clerk, Inc. | Social login (Sign in with Apple, Sign in with Google) | Email address, OAuth provider identifier | United States |
| 650 Industries, Inc. (Expo) | Push notification delivery | Device push token, notification content (title and body; for chat notifications e.g. sender name and message excerpt) | United States |
| Firebase Cloud Messaging (Google) / Apple Push Notification Service | Push notification routing | Device push token, notification payload | United States / Ireland (Apple) |
| OpenStreetMap Foundation (Nominatim, Overpass) and Wikimedia Foundation | Zip-code-to-coordinates lookup, reverse-geocoding and enrichment of place information | Zip code or coarse coordinates (no user identifier) | EU / United Kingdom / United States (Wikimedia) |
| Apple Distribution International Limited | In-app purchases on iOS (merchant of record) | Purchase event, anonymous transaction identifier | Ireland (EU) |
| Google Ireland Limited | In-app purchases on Android (merchant of record) | Purchase event, anonymous transaction identifier | Ireland (EU) |
| Listing-claim requests | Until your request has been handled, and for up to twelve months afterwards to prevent abuse and to document granted management rights; deleted thereafter. Requests classified as spam are deleted after twelve months. |
Other recipients. We may also disclose personal data to (i) law enforcement, regulators, or courts, where required by binding legal process; (ii) our professional advisers (lawyers, auditors, accountants), bound by professional confidentiality; (iii) any successor entity in the event of a corporate restructuring, merger, or sale of assets, in which case the recipient will be bound by the same protections set out in this Policy.
We do not sell your personal data. We do not share your personal data with advertising networks, data brokers, or any third party for their own marketing purposes.
Your data is primarily stored and processed within the European Union: the application, the database and your user-uploaded media reside on our servers in Nuremberg, Germany, in an ISO/IEC 27001-certified data centre operated by Hetzner Online GmbH; certain processing operations (for example, email and SMS delivery and image moderation via Amazon Web Services) take place in Frankfurt. Some processors listed in Section 6 are established in the United States or operate from outside the EU/EEA. Where such transfers occur, they rely on the following safeguards under Articles 44-49 GDPR:
| Provider | Transfer mechanism |
|---|---|
| Google LLC (Gemini, Maps, FCM) | EU-US Data Privacy Framework (DPF) certification + EU Standard Contractual Clauses |
| Amazon Web Services (Rekognition, SNS, SES) | EU-US Data Privacy Framework certification + EU Standard Contractual Clauses; primary processing region is EU (Frankfurt) |
| Cloudflare, Inc. | EU-US Data Privacy Framework (DPF) certification + EU Standard Contractual Clauses |
| Apple Distribution International | EU-US Data Privacy Framework certification (Apple Inc.); EU contracting entity for in-app purchases |
| RevenueCat, Inc.; Clerk, Inc.; 650 Industries, Inc. | EU Standard Contractual Clauses |
| OpenStreetMap Foundation (Nominatim, Overpass); Wikimedia Foundation | UK adequacy (Commission Decision (EU) 2021/1772) for UK-hosted requests; EU GDPR for EU-hosted requests; EU Standard Contractual Clauses for Wikimedia (US). Only coarse geodata without a user identifier is transmitted. |
A copy of the relevant transfer mechanism (Standard Contractual Clauses) or, where applicable, the provider's DPF certification, can be requested at [email protected]. We carry out and document a Transfer Impact Assessment (TIA) for each transfer to a non-adequate country in line with the European Data Protection Board's Recommendations 01/2020.
We retain personal data only as long as is necessary for the purposes set out in this Policy. The principal retention rules are:
| Data category | Retention |
|---|---|
| Account and profile data | For the lifetime of your account, with the inactivity rules below. |
| Inactivity | If your account has been inactive for 22 months, we send a warning by email; if you remain inactive at 24 months, your account is deleted or anonymized. |
| Children's profile data | Deleted when you delete the child profile or when you delete your account. |
| Verification codes (email and phone OTP) | Cleared upon use or upon expiry of the verification window (typically minutes). |
| Item listings and item photos | Until you remove them or delete your account; on account deletion, items are removed and the associated stored media is purged on a scheduled basis. |
| Messages | Anonymized when your account is anonymized; message rows on other users' threads are retained with content blanked, to preserve thread integrity. |
| Community group-chat messages | Remain visible to the remaining members after you leave a community; anonymized when your account is anonymized (content blanked, attribution removed). Messages removed by you or a community administrator are no longer displayed in the chat; we may retain them for as long as the group chat exists in order to investigate violations of law or our Terms and to comply with legal obligations. When a community is deleted or archived for inactivity, its group chat becomes inaccessible to all users and is permanently erased at that point. Your read position and chat notification preferences are deleted when your account is deleted. |
| Reviews | Anonymized when your account is anonymized - the review text is preserved attributed to a "[deleted user]" placeholder; your username is removed. |
| Community / event data | Events you created remain available with the creator name replaced by "[deleted user]" upon account deletion. Your RSVPs are deleted on account deletion. |
| Behavioural records (article views, item likes, bookmarks, RSVPs) | Deleted on account deletion. |
| Block list | Deleted on account deletion. |
| RevenueCat user identifier | Cleared on account deletion. |
| Subscription billing record (plan name, dates, transaction identifier) | Up to ten years from the end of the relevant tax year, in accordance with §§ 147 AO, 257 HGB. |
| Credit transaction history | Up to ten years from the end of the relevant tax year, in accordance with §§ 147 AO, 257 HGB; thereafter purged by scheduled task. |
| DSA trader registration data (Art. 30) | For the duration of trader status plus six months, then deleted. |
| Backups | Encrypted backups are retained for up to 7 days; deletions propagate at the next backup rotation. |
| User and system-generated reports (including resolution and statement of reasons) | Three years after resolution, for the defence of legal claims and the detection of repeat offenders; then deleted. |
| Quarantined child-safety evidence | Retained in a restricted quarantine until the competent authority confirms it is no longer required, then deleted. |
| Decryption audit log (administrative access to message content) | Three years, then deleted. |
Where data has been irreversibly anonymized (within the meaning recognised in EDPB Opinion 28/2024), it ceases to be personal data and may be retained for aggregate statistics.
Subject to the conditions set out in the GDPR, you have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you at any time. The Service provides an in-app data export at Menu > Export My Data, which delivers a machine-readable JSON archive including: account profile, optional profile fields, children's profile data, optional phone number, items listed, messages sent (including community group-chat messages), reviews written, communities and events you created or attended, your interactions with articles (views, reactions, bookmarks), toy likes, your saved searches, your block list, your credit transactions, your notification preferences, your subscription plan, and your registered device tokens. If you cannot access the in-app export, contact [email protected].
Most profile information is editable in the app. For data you cannot edit yourself (for example, the email associated with your account), contact [email protected]. Reviews you have published cannot be self-edited after admin approval; if a published review contains inaccurate personal data, please contact us and we will rectify or delete it as appropriate.
You can delete your account from within the app, or via our web form at https://loopelo.com/delete-account.php. On account deletion, your personal data is deleted or - where this is required to preserve the integrity of shared content (for example, reviews or your messages on another user's thread) or for statutory retention reasons - anonymized, as set out in Section 8.
You may request restriction of processing in the cases listed in Article 18 GDPR by emailing [email protected].
The in-app export described in Section 9.1 is provided in a structured, commonly used, machine-readable JSON format suitable for transmission to another controller of your choice.
You may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Contact [email protected].
Direct marketing. Where we process personal data to send you promotional communications, you have an absolute right to object under Article 21(2) GDPR. You can exercise this right at any time, with no need to email us, by switching off the relevant toggles in your in-app notification settings. The opt-out is as easy as opt-in.
Where processing is based on your consent (see the table in Section 4), you can withdraw it at any time, with no effect on the lawfulness of processing prior to withdrawal. Withdrawal mechanisms include the OS-level location permission (for GPS-derived zip lookup), the in-app notification toggles (for promotional communications), and dedicated in-app controls for AI features such as Lena.
You may lodge a complaint with the data protection supervisory authority of your habitual residence, place of work, or place of the alleged infringement. The principal authorities are listed in Section 14.
We will respond to verified rights requests within one month of receipt. Where a request is particularly complex or where we receive a high volume of requests from you, we may extend this period by a further two months and will inform you, with reasons, within the initial month.
Minimum age. Loopelo accounts can be registered only by users who are at least 16 years old. At registration, you are asked to confirm - in a single combined checkbox alongside your acceptance of these Terms and this Privacy Policy - that you meet this age requirement. We do not currently collect your own year of birth or any other age data about you.
This 16-year minimum is the default age for digital-services consent under Article 8(1) GDPR and matches Germany's national implementation. In Member States that have set a lower age (for example, Austria 14), Loopelo applies the higher 16-year floor as a matter of business policy.
Children as data subjects. Loopelo is designed for parents and guardians, not for direct use by children. If you choose to add a child profile to your account, you act as the parent / guardian and provide the data. Children have rights as data subjects under Articles 12, 15, 17, 21 and others; you may exercise these rights on their behalf via the same channels described in Section 9, and as soon as the child has the maturity to understand them, jointly with the child.
Data minimization for children's profiles. We collect only what is needed for personalization: a nickname (we recommend a pseudonym), the year of birth (used to derive an approximate age), and optionally gender. We do not collect the child's full name, school, address, exact date of birth, photograph, or any contact data.
What children's data is sent to AI services. When you use the Lena AI assistant (Section 5.1), the nickname you set, an approximate age derived from it (calculated from the year of birth) and optionally the gender of your children may form part of the context block sent to the Gemini API. The nickname is a name you freely choose, labelled "Nickname" in the app, and need not be the child's real name; we recommend using a pseudonym. Because your messages to Lena are transmitted verbatim, please do not enter your child's real name or other directly identifying data into the chat.
Children's data and promoted content. We do not direct advertising or marketing communications to children, and children are never the recipients of our Service. We do not build advertising profiles of children, we do not use a child's identity, name, or precise data for advertising, and we never share children's data with advertisers or sponsoring businesses. Where the Service shows sponsored places to you, the parent (see Section 5.5), the approximate age band derived from a child's profile may be used - in the same way it is used for ordinary recommendations - solely to keep the sponsored places age-appropriate for your family. This age-appropriateness signal is one of several ranking factors and is not used to track your child or to build a commercial profile of your child.
Visibility. Children's profiles are never visible to other users. They are used only to personalize content shown to the parent.
Our approach is informed by the European Data Protection Board's Statement on Age Assurance (2025) and the Irish Data Protection Commission's Fundamentals for a Child-Oriented Approach to Data Processing (2021).
We apply the technical and organisational measures required by Article 32 GDPR. These include: TLS encryption in transit; encryption at rest of databases and backups; application-level encryption at rest for private message content and chat images, with the encryption key held outside the database and administrative decryption restricted to an audit-logged, time-limited unlock; hardware-backed (Secure Enclave / Android Keystore) storage of authentication tokens on your device; refresh-token-based session management without storage of plain-text passwords on the device; access controls and least-privilege access for our personnel; periodic credential rotation; and audit logging of administrative actions.
Where we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay, and where feasible within 72 hours, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay in accordance with Article 34 GDPR.
The Loopelo mobile application does not use cookies. It uses the following on-device storage:
expo-secure-store; Android Keystore) for authentication refresh tokens. We do not store passwords on the device.These storage mechanisms are strictly necessary to provide the Service you have requested. Pursuant to § 25(2) Nr. 2 of the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) and equivalent provisions of the ePrivacy Directive (2002/58/EC), no separate consent is required.
The mobile application does not embed any third-party analytics, attribution, advertising, or tracking SDK. We do not access advertising identifiers (IDFA on iOS, AAID on Android). We do not request App Tracking Transparency permission because we do not engage in cross-app tracking.
Our website uses:
You can change your choice at any time via the persistent Cookie Settings link in the website footer; your preferences are stored and respected on your next visit. Withdrawing consent is as easy as granting it; you do not need to clear cookies from your browser.
We may update this Privacy Policy. The current version and effective date are shown at the top of this page.
A version history is available upon request at [email protected].
Privacy enquiries: [email protected]
General contact: [email protected]
Supervisory authorities:
You may also lodge a complaint with any other supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.