Sinceby for Android
Privacy Policy
Last updated: 13 August 2026 · Applies to Sinceby for Android, version 0.0.1, and to the Sinceby web app on sinceby.app
Signed out, Sinceby is a local app. Your chores and your history live in a database on your own device and are not sent anywhere. Signing in is optional and the app is complete without it.
If you sign in — which is what a shared household needs — your email address goes to Firebase Authentication, and your household's chores, completion times and who did what are stored in Cloud Firestore so the people you live with can see the same list. If you subscribe to Pro, RevenueCat and Google Play handle the purchase.
There is still no analytics, no crash reporting, no advertising and no tracking of any kind, and there never will be. That part of the old policy is unchanged and verifiable: the app embeds no analytics or crash-reporting SDK at all.
Controller
Lukas MerzSeetalstrasse 49
5706 Boniswil
Switzerland
Email: lukas@mrz.email
Sinceby is run from Switzerland. Swiss data protection law (the revised Federal Act on Data Protection, revDSG) applies, and because the app is offered to people in the EU and EEA the GDPR applies as well (Art. 3(2) GDPR). Where the two differ, whichever gives you the stronger right is the one honoured.
What this policy covers
The Sinceby Android app, the Sinceby web app served from sinceby.app, and this website. It does not cover Google Play, your device's operating system, or any other app or site you reach from a link here — those are governed by their own policies.
What is processed, and why
1. Your chores, on your device
Whether or not you sign in, Sinceby stores on your own device: the name and emoji of each chore, its optional target interval, its optional group, whether it is pinned, whether its reminder is on, when it was created, and every time you marked it done — including a short optional note and which member of your household did it. Signed out, that attribution is a local placeholder and not an identity.
The app also stores locally: your theme choice, a cached yes/no answer about whether your Pro subscription is currently active and when it expires, the email address a sign-in link was last sent to (so the link can be completed without asking again), a marker recording that you were already asked once whether to carry your offline list into a household, and an automatic safety copy of your list taken immediately before a restore, kept in the app's own private storage.
Backup files, CSV exports and Streakless imports go through the Android system file picker to a location you choose. The app is handed only the one file you pick.
2. Your account — Firebase Authentication
Signing in is optional. Two methods are offered, both provided by Firebase Authentication:
- Email link. You enter an email address, Firebase sends a one-time sign-in link to it, and tapping that link signs you in. Processed: your email address.
- Sign in with Google. Google returns an identity token to the app. Processed: your Google account identifier, your email address, and the display name on that account.
From either method Firebase issues a user ID — a random string — which is the identity the rest of the app uses. Sinceby never receives or stores your Google password, and no password is used for the email-link method at all.
Purpose: to give you an identity so a household can be shared, so your list can follow you to another device, and so a subscription can be recognised on both the phone and the web.
3. Your household — Cloud Firestore
Once you are signed in, your list is synchronised through Cloud Firestore in
the Firebase project sinceby-prod. Stored there:
- The household: its name, who created it, and when.
- Its members: for each member, the user ID and the display name shown next to a completed chore, plus when they joined. Nothing else. There is deliberately no count, no total, no streak and no "last active" on a member — Sinceby does not keep score.
- Its chores: name, emoji, optional target interval, optional group, pinned, reminder on or off, created-at, and a cached "last done at / last done by".
- Its completions: which chore, the exact time it was marked done, which member did it, and an optional short note. This is the record the product exists to keep, so it is append-only and it names a person.
- A private pointer under your own user record saying which household you belong to.
Who can read it: only signed-in members of that household. This is enforced by server-side security rules, not by the app — a copy of the app that asked for someone else's household would be refused by the server itself.
Nothing is uploaded silently. Everything you entered before signing in stays local unless you accept an explicit, one-time offer to carry it into your household, and declining loses nothing. Signing out deletes nothing from your device.
A copy of your household's data is also cached on your device by Firestore so the app works offline; a completion logged with no signal keeps the time it actually happened.
4. Invite links
Inviting someone creates a record holding an unguessable random token, the household it lets them join, who created it and when, and an expiry 14 days after creation. Anyone signed in who holds the token can read that one record and join; tokens cannot be listed or guessed, and only the household's owner can create or revoke one. Creating a fresh link does not disable the old one — the old one stops working when it expires.
5. Purchases and Pro — RevenueCat and Google Play Billing
Sinceby Pro is an optional subscription. Purchases on Android are made through Google Play Billing; on the web, through RevenueCat's own hosted checkout. Sinceby never sees your card details, name or billing address — the payment happens entirely inside Google's or RevenueCat's flow.
Subscription status is managed by RevenueCat, which receives your Firebase user ID as its customer identifier — deliberately, so that a subscription bought on your phone is recognised in the web app — together with the purchase receipt from the store, the plan you bought, and when it renews or expires. The app stores locally only a yes/no answer and an expiry date, and a copy of that answer may be written to your own private user record so the web app can read it. Your entitlement can only be granted by the server; the app cannot grant it to itself.
6. Feedback
If you send feedback from Settings, the message, an optional contact email address you choose to add, and the app version, device model and Android version are collected. In this version that report is written to the device's own system log and is not transmitted anywhere. No chore names, no history and nothing about who did what is ever included. If a future version starts sending feedback to us, this policy will say so before that version is released.
What is not collected
- No analytics or usage statistics. The app embeds no analytics SDK — not Firebase Analytics, not any other.
- No crash or performance reporting. No Crashlytics, no equivalent.
- No advertising identifiers, no ads, no profiling. Nothing is sold or shared for marketing.
- No location, contacts, camera, microphone or photo access, and no access to your storage beyond the single file you pick yourself.
- No scores. Sinceby records who did a chore and when. It does not count, rank or compare people, and it will not.
- No third-party requests from this website. sinceby.app has no analytics, no cookies, no fonts and no trackers.
Legal bases
- Running the app and syncing your household — performance of a contract, Art. 6(1)(b) GDPR. You asked for a shared list; a shared list cannot exist without storing it somewhere both of you can read.
- Your account — Art. 6(1)(b) GDPR. Sign-in exists to deliver the features that require it, and is not required to use the app.
- The subscription — Art. 6(1)(b) GDPR for delivering it, and Art. 6(1)(c) GDPR for the records our payment processors are legally obliged to retain.
- Keeping the service secure and working — legitimate interests, Art. 6(1)(f) GDPR: expiring invite tokens, refusing unauthorised reads, and preventing abuse of the sign-in flow.
- Optional feedback, including any contact address you add — your consent, Art. 6(1)(a) GDPR, which you may withdraw at any time.
Under the revDSG the same processing is based on the contract between us, on an overriding legitimate interest, or on your consent, in the same order.
Recipients and processors
These are the only recipients of personal data, and each acts as a processor on our instructions under a data processing agreement:
- Google Ireland Limited / Google LLC — Firebase Authentication and Cloud Firestore (your account and your household data), Cloud Functions (the subscription-status webhook and account deletion), and Google Play Billing plus the Google Play in-app review flow on Android. Firebase privacy, Google privacy policy.
- RevenueCat, Inc., United States — subscription and entitlement management. Receives your Firebase user ID and your store purchase data. RevenueCat privacy policy.
Nothing is sold, rented or handed to advertisers or data brokers. Data may additionally be disclosed where we are legally required to do so.
Independently of the app, Google processes your download and any diagnostics you enabled at the operating-system level under its own policy. That is between you and Google.
Where your data is stored, and international transfers
Not all of it is in the same place, so here is the split rather than one reassuring sentence:
- Cloud Firestore — the EU. Your household content (chores, completions, who did what, groups, members, invite links) is stored in Google's eur3 multi-region, which is Belgium (europe-west1) and the Netherlands (europe-west4). It does not leave the EU in normal operation.
- Cloud Functions — the EU. The backend that receives the subscription-status webhook and performs account deletion runs in europe-west1 (Belgium), next to the database, so household data is not shipped across the Atlantic to be processed.
- Firebase Authentication — not region-pinned. Google does not let us choose a region for it, so your email address, your Google account identifier and your user ID should be assumed to be processed outside the EEA, including in the United States.
- RevenueCat — the United States. RevenueCat, Inc. is a US company, and your user ID and purchase data are processed there.
So a transfer outside Switzerland and the EEA does happen — for authentication and for subscription data, not for your chore list. Those transfers are made under Art. 44 ff. GDPR and Art. 16 f. revDSG on the following basis:
- the European Commission's adequacy decision for the EU–US Data Privacy Framework, and the Swiss–US Data Privacy Framework recognised by the Swiss Federal Council, where the recipient is certified under it; and otherwise
- the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), recognised by the FDPIC for transfers from Switzerland with the Swiss amendments, together with additional safeguards such as encryption in transit and at rest.
You can ask us for details of the mechanism relied on for a particular transfer at lukas@mrz.email.
Retention and deletion
- On your device: your data stays until you delete it. Deleting a chore removes its completions with it. Uninstalling the app, or clearing its storage in Android's settings, deletes everything local permanently. Signing out deletes nothing.
- In your household: chores and completions are kept until a member deletes them or the account is deleted. Deleting a chore in the app deletes it and its completions for everyone in the household.
- When you leave a household: your membership record and your pointer to it are deleted, and you stop seeing the list. The chores and completions stay, including the ones attributed to you — the record of who did what would otherwise become false for the people still living there. If you want your completions removed as well, ask us and we will do it.
- If you are the last one out: using "Leave this household" when nobody else is in it does not delete the household's records. Nobody can read them any more — the security rules allow reads only to members, and there are none — but they remain until they are deleted on request. Ask, and they will be. Deleting your account is different: if that leaves the household with no members, the household, its chores and its completions are deleted with it.
- Invite links stop working 14 days after they are created, and links you created are revoked when your account is deleted.
- Your account: Settings → Delete account, in the Android app or on sinceby.app. It happens immediately, and it cancels your subscription before it deletes anything. Deletion by email also still works — write to lukas@mrz.email from the address you signed in with; we reply within 7 days and complete the deletion within 30. The full procedure, and exactly what is deleted and what is kept, is on the account deletion page.
- Your subscription is cancelled as the first step of deleting your account — auto-renew is turned off on Google Play or with the web payment provider before anything is deleted, and if that cannot be done, nothing is deleted at all. Cancelling is not a refund and does not end Pro early: what you have already paid for stays yours until that period ends. Your customer record with RevenueCat is deleted with the account.
- Purchase records — what was bought, when and for how much — are kept by Google and by RevenueCat for as long as their own retention and statutory bookkeeping obligations require, which is outside our control and survives the account they belonged to.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing (Art. 15–21 GDPR; Art. 25 ff. revDSG), and to withdraw any consent you gave without affecting what was lawful before.
Erasure you can exercise yourself, immediately, without asking anyone: Settings → Delete account in either app. The account deletion page sets out what goes, what stays and what happens to a subscription. Portability you can exercise yourself too — backup and CSV export are free at every tier, signed in or out.
Portability (Art. 20 GDPR) is answered in the app itself. Settings can export your entire list and your full history as a single JSON backup file, and your history as a CSV any spreadsheet opens — everything you entered, in a structured, commonly used, machine-readable format, on demand and without asking anyone. Neither is behind the paywall and neither ever will be. If you would rather we produced the export for you, ask.
To exercise any of these, write to lukas@mrz.email. You may also complain to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), and in the EU/EEA the authority of your country of residence, place of work or of the alleged infringement.
Permissions
Verified against the app's merged release manifest, which includes the permissions the Google and RevenueCat libraries add — not just the ones written by hand. The complete list is:
INTERNETandACCESS_NETWORK_STATE— sign-in, household sync and purchases.com.android.vending.BILLING— the Google Play purchase flow.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS— lets the app ask Android to stop suspending it in the background. You can decline it and everything still works.WAKE_LOCK,FOREGROUND_SERVICE,RECEIVE_BOOT_COMPLETEDandcom.google.android.providers.gsf.permission.READ_GSERVICES— added by Google Play services so sync and billing survive the device sleeping or restarting.com.sinceby.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION— defined by the app for its own internal use; it grants access to nothing.
There is no location, contacts, camera, microphone or storage permission. Backing up, exporting and importing use the Android system file picker, which hands the app only the single file you choose.
Children
Sinceby is a household tool for general audiences and is not directed at children. An account is not offered to anyone under 16 without the consent of a parent or guardian (Art. 8 GDPR; a lower age limit applies in some EU states). The app can be used entirely without an account at any age, since nothing then leaves the device. If you believe a child has created an account, write to lukas@mrz.email and it will be deleted.
Changes to this policy
This page describes what the app does today, and it is rewritten before a version that changes it is released — not afterwards. The date at the top says when it last changed. Material changes are also noted in the app's release notes. Earlier versions of Sinceby were local-only and this policy said so; that description no longer applies to the version named at the top.
Datenschutzerklärung
Stand: 13. August 2026 · Gilt für Sinceby für Android, Version 0.0.1, und für die Sinceby-Web-App auf sinceby.app
Ohne Anmeldung ist Sinceby eine lokale App. Deine Einträge und deren Verlauf liegen in einer Datenbank auf deinem eigenen Gerät und werden nirgendwohin gesendet. Die Anmeldung ist freiwillig; die App ist auch ohne sie vollständig.
Meldest du dich an — was ein gemeinsamer Haushalt braucht —, geht deine E-Mail-Adresse an Firebase Authentication, und die Einträge deines Haushalts, die Erledigungszeitpunkte und die Angabe, wer was erledigt hat, werden in Cloud Firestore gespeichert, damit die Leute, mit denen du wohnst, dieselbe Liste sehen. Bei einem Pro-Abo wickeln RevenueCat und Google Play den Kauf ab.
Es gibt weiterhin keine Analyse, keine Absturzberichte, keine Werbung und kein Tracking, und daran ändert sich nichts. Dieser Teil der alten Erklärung gilt unverändert und ist überprüfbar: die App bindet überhaupt kein Analyse- oder Crash-Reporting-SDK ein.
Verantwortlicher
Lukas MerzSeetalstrasse 49
5706 Boniswil
Schweiz
E-Mail: lukas@mrz.email
Sinceby wird aus der Schweiz betrieben. Es gilt das revidierte Schweizer Datenschutzgesetz (revDSG); da die App auch Personen in der EU und im EWR angeboten wird, gilt zusätzlich die DSGVO (Art. 3 Abs. 2 DSGVO). Wo beide voneinander abweichen, gilt jeweils das für dich günstigere Recht.
Geltungsbereich
Diese Erklärung gilt für die Sinceby-App für Android, die Sinceby-Web-App unter sinceby.app und diese Website. Nicht erfasst sind Google Play, das Betriebssystem deines Geräts und alle anderen Apps oder Seiten, die du über einen Link von hier erreichst; dafür gelten deren eigene Erklärungen.
Welche Daten verarbeitet werden — und wozu
1. Deine Einträge, auf deinem Gerät
Ob angemeldet oder nicht, Sinceby speichert auf deinem eigenen Gerät: Name und Emoji jedes Eintrags, den optionalen Zielabstand, die optionale Gruppe, ob er angepinnt ist, ob seine Erinnerung aktiv ist, wann er angelegt wurde, und jeden Zeitpunkt, zu dem du ihn als erledigt markiert hast — samt einer optionalen kurzen Notiz und der Angabe, wer aus dem Haushalt es war. Ohne Anmeldung ist diese Zuordnung ein lokaler Platzhalter und keine Identität.
Ebenfalls lokal gespeichert werden: deine Theme-Auswahl, eine zwischengespeicherte Ja/Nein-Antwort dazu, ob dein Pro-Abo gerade aktiv ist und wann es abläuft, die E-Mail-Adresse, an die zuletzt ein Anmeldelink geschickt wurde (damit der Link ohne erneute Nachfrage abgeschlossen werden kann), ein Vermerk darüber, dass du bereits einmal gefragt wurdest, ob deine Offline-Liste in einen Haushalt übernommen werden soll, sowie eine automatische Sicherheitskopie deiner Liste unmittelbar vor einer Wiederherstellung, abgelegt im app-eigenen privaten Speicher.
Backups, CSV-Exporte und Streakless-Importe laufen über die Dateiauswahl des Systems an einen von dir gewählten Ort. Die App erhält nur die eine Datei, die du auswählst.
2. Dein Konto — Firebase Authentication
Die Anmeldung ist freiwillig. Es gibt zwei Wege, beide über Firebase Authentication:
- E-Mail-Link. Du gibst eine E-Mail-Adresse ein, Firebase schickt einen einmaligen Anmeldelink dorthin, und ein Tippen darauf meldet dich an. Verarbeitet wird: deine E-Mail-Adresse.
- Anmeldung mit Google. Google übergibt der App ein Identitäts-Token. Verarbeitet werden: deine Google-Konto-Kennung, deine E-Mail-Adresse und der Anzeigename dieses Kontos.
Aus beiden Wegen entsteht eine Firebase-Benutzerkennung — eine zufällige Zeichenfolge —, die im Rest der App als Identität dient. Sinceby erhält und speichert dein Google-Passwort nicht; beim E-Mail-Link gibt es überhaupt kein Passwort.
Zweck: dir eine Identität zu geben, damit ein Haushalt geteilt werden kann, deine Liste dir auf ein anderes Gerät folgt und ein Abo auf Telefon und im Web gleichermassen erkannt wird.
3. Dein Haushalt — Cloud Firestore
Sobald du angemeldet bist, wird deine Liste über Cloud Firestore im
Firebase-Projekt sinceby-prod synchronisiert. Dort gespeichert:
- Der Haushalt: sein Name, wer ihn angelegt hat und wann.
- Seine Mitglieder: je Mitglied die Benutzerkennung, der Anzeigename, der neben einer Erledigung steht, und der Beitrittszeitpunkt. Sonst nichts. Bewusst gibt es an einem Mitglied keine Zählung, keine Summe, keine Serie und kein „zuletzt aktiv“ — Sinceby führt keine Punkte.
- Seine Einträge: Name, Emoji, optionaler Zielabstand, optionale Gruppe, angepinnt, Erinnerung an oder aus, Anlagezeitpunkt sowie ein zwischengespeichertes „zuletzt erledigt am / von“.
- Seine Erledigungen: welcher Eintrag, der genaue Zeitpunkt, welches Mitglied, und eine optionale kurze Notiz. Das ist genau der Nachweis, für den es dieses Produkt gibt — er wird nur angehängt und er nennt eine Person.
- Ein privater Verweis in deinem eigenen Benutzerdatensatz darauf, zu welchem Haushalt du gehörst.
Wer das lesen kann: ausschliesslich angemeldete Mitglieder dieses Haushalts. Das erzwingen serverseitige Sicherheitsregeln, nicht die App — eine App-Kopie, die den Haushalt einer anderen Person anfragt, wird vom Server selbst abgewiesen.
Nichts wird stillschweigend hochgeladen. Alles, was du vor der Anmeldung eingetragen hast, bleibt lokal, bis du ein ausdrückliches, einmaliges Angebot annimmst, es in deinen Haushalt zu übernehmen; ein Nein verliert nichts. Das Abmelden löscht auf deinem Gerät nichts.
Firestore legt zusätzlich eine Kopie der Haushaltsdaten auf deinem Gerät ab, damit die App offline funktioniert; eine ohne Empfang erfasste Erledigung behält den Zeitpunkt, zu dem sie tatsächlich stattfand.
4. Einladungslinks
Eine Einladung erzeugt einen Datensatz mit einem nicht erratbaren Zufalls-Token, dem Haushalt, in den er führt, wer ihn erstellt hat und wann, sowie einem Ablauf 14 Tage nach Erstellung. Wer angemeldet ist und den Token besitzt, kann genau diesen einen Datensatz lesen und beitreten; Tokens lassen sich weder auflisten noch erraten, und nur die Eigentümerin oder der Eigentümer des Haushalts kann einen erstellen oder widerrufen. Ein neuer Link deaktiviert den alten nicht — der alte hört mit seinem Ablauf auf zu funktionieren.
5. Käufe und Pro — RevenueCat und Google Play Billing
Sinceby Pro ist ein optionales Abonnement. Käufe unter Android laufen über Google Play Billing, im Web über den gehosteten Bezahlvorgang von RevenueCat. Sinceby sieht weder deine Kartendaten noch deinen Namen oder deine Rechnungsadresse — die Zahlung findet vollständig im Ablauf von Google bzw. RevenueCat statt.
Den Abo-Status verwaltet RevenueCat. Übermittelt wird dabei bewusst deine Firebase-Benutzerkennung als Kundenkennung — damit ein auf dem Telefon gekauftes Abo auch in der Web-App gilt — zusammen mit dem Kaufbeleg des Stores, dem gewählten Tarif und dem Verlängerungs- bzw. Ablaufdatum. Lokal speichert die App nur eine Ja/Nein-Antwort und ein Ablaufdatum; eine Kopie dieser Antwort kann in deinem eigenen privaten Benutzerdatensatz abgelegt werden, damit die Web-App sie lesen kann. Die Berechtigung kann nur der Server erteilen; die App kann sie sich nicht selbst geben.
6. Rückmeldungen
Schickst du aus den Einstellungen eine Rückmeldung, werden die Nachricht, eine optionale Kontakt-E-Mail-Adresse, die du selbst angeben kannst, sowie App-Version, Gerätemodell und Android-Version erfasst. In dieser Version wird dieser Bericht in das Systemprotokoll des Geräts geschrieben und nirgendwohin übertragen. Namen von Einträgen, Verlauf und Angaben dazu, wer was erledigt hat, sind nie enthalten. Sollte eine künftige Version Rückmeldungen an uns senden, steht das hier, bevor diese Version erscheint.
Was nicht erhoben wird
- Keine Analyse- oder Nutzungsstatistik. Die App bindet kein Analyse-SDK ein — weder Firebase Analytics noch ein anderes.
- Keine Absturz- oder Leistungsberichte. Kein Crashlytics, nichts Vergleichbares.
- Keine Werbe-IDs, keine Werbung, kein Profiling. Es wird nichts verkauft oder zu Marketingzwecken weitergegeben.
- Kein Zugriff auf Standort, Kontakte, Kamera, Mikrofon oder Fotos und kein Zugriff auf deinen Speicher ausser der einen Datei, die du selbst auswählst.
- Keine Punkte. Sinceby hält fest, wer wann etwas erledigt hat. Es zählt, wertet und vergleicht keine Personen — und wird es nicht tun.
- Keine Drittanfragen von dieser Website. sinceby.app hat keine Analyse, keine Cookies, keine Schriften und keine Tracker.
Rechtsgrundlagen
- Betrieb der App und Synchronisierung deines Haushalts — Vertragserfüllung, Art. 6 Abs. 1 lit. b DSGVO. Eine gemeinsame Liste kann nicht existieren, ohne irgendwo zu liegen, wo ihr beide sie lesen könnt.
- Dein Konto — Art. 6 Abs. 1 lit. b DSGVO. Die Anmeldung dient allein den Funktionen, die sie brauchen, und ist für die Nutzung der App nicht erforderlich.
- Das Abonnement — Art. 6 Abs. 1 lit. b DSGVO für die Erbringung, Art. 6 Abs. 1 lit. c DSGVO für die Aufzeichnungen, zu deren Aufbewahrung unsere Zahlungsdienstleister gesetzlich verpflichtet sind.
- Sicherheit und Funktionsfähigkeit — berechtigte Interessen, Art. 6 Abs. 1 lit. f DSGVO: das Ablaufen von Einladungs-Tokens, das Abweisen unberechtigter Zugriffe und der Schutz des Anmeldevorgangs vor Missbrauch.
- Freiwillige Rückmeldungen samt angegebener Kontaktadresse — deine Einwilligung, Art. 6 Abs. 1 lit. a DSGVO, jederzeit widerrufbar.
Nach revDSG stützt sich dieselbe Bearbeitung in gleicher Reihenfolge auf den Vertrag zwischen uns, auf ein überwiegendes berechtigtes Interesse oder auf deine Einwilligung.
Empfänger und Auftragsverarbeiter
Dies sind die einzigen Empfänger personenbezogener Daten; beide handeln als Auftragsverarbeiter auf unsere Weisung und auf Grundlage eines Auftragsverarbeitungsvertrags:
- Google Ireland Limited / Google LLC — Firebase Authentication und Cloud Firestore (Konto und Haushaltsdaten), Cloud Functions (Webhook für den Abo-Status und die Kontolöschung) sowie unter Android Google Play Billing und der Play-Bewertungsdialog. Firebase-Datenschutz, Google-Datenschutzerklärung.
- RevenueCat, Inc., USA — Verwaltung von Abonnements und Berechtigungen. Erhält deine Firebase-Benutzerkennung und deine Kaufdaten aus dem Store. Datenschutzerklärung von RevenueCat.
Es werden keine Daten verkauft, vermietet oder an Werbetreibende oder Datenhändler gegeben. Eine Offenlegung erfolgt darüber hinaus nur, soweit wir gesetzlich dazu verpflichtet sind.
Unabhängig von der App verarbeitet Google den Download und die von dir auf Systemebene aktivierten Diagnosedaten nach seiner eigenen Erklärung. Das geschieht zwischen dir und Google.
Wo deine Daten liegen, und Übermittlung in Drittländer
Nicht alles liegt am selben Ort. Deshalb hier die Aufteilung statt eines beruhigenden Satzes:
- Cloud Firestore — EU. Die Inhalte deines Haushalts (Einträge, Erledigungen, wer was gemacht hat, Gruppen, Mitglieder, Einladungslinks) liegen in Googles Multiregion eur3, also in Belgien (europe-west1) und den Niederlanden (europe-west4). Im Normalbetrieb verlassen sie die EU nicht.
- Cloud Functions — EU. Das Backend, das den Webhook zum Abo-Status entgegennimmt und die Kontolöschung ausführt, läuft in europe-west1 (Belgien), direkt neben der Datenbank — Haushaltsdaten werden also nicht zur Verarbeitung über den Atlantik geschickt.
- Firebase Authentication — keine Regionsbindung. Google lässt hier keine Regionswahl zu. Deine E-Mail-Adresse, deine Google-Kontokennung und deine Benutzer-ID sind daher als ausserhalb des EWR verarbeitet anzusehen, auch in den USA.
- RevenueCat — USA. RevenueCat, Inc. ist ein US-Unternehmen; deine Benutzerkennung und deine Kaufdaten werden dort verarbeitet.
Eine Übermittlung ausserhalb der Schweiz und des EWR findet also statt — für die Anmeldung und für Abo-Daten, nicht für deine Einträge. Diese Übermittlungen erfolgen nach Art. 44 ff. DSGVO und Art. 16 f. revDSG auf folgender Grundlage:
- der Angemessenheitsbeschluss der Europäischen Kommission zum EU-US Data Privacy Framework sowie das vom Schweizerischen Bundesrat anerkannte Swiss-US Data Privacy Framework, soweit der Empfänger dort zertifiziert ist; im Übrigen
- die Standardvertragsklauseln der Europäischen Kommission (Durchführungsbeschluss (EU) 2021/914), vom EDÖB für Übermittlungen aus der Schweiz mit den Schweizer Anpassungen anerkannt, ergänzt um zusätzliche Massnahmen wie Verschlüsselung bei der Übertragung und im Speicher.
Auf Anfrage teilen wir dir unter lukas@mrz.email mit, worauf sich eine bestimmte Übermittlung stützt.
Speicherdauer und Löschung
- Auf deinem Gerät: Deine Daten bleiben, bis du sie löschst. Mit einem Eintrag verschwinden auch seine Erledigungen. Deinstallation oder das Leeren des App-Speichers in den Android-Einstellungen löscht alles Lokale endgültig. Abmelden löscht nichts.
- In deinem Haushalt: Einträge und Erledigungen bleiben, bis ein Mitglied sie löscht oder das Konto gelöscht wird. Ein in der App gelöschter Eintrag verschwindet samt Erledigungen für alle im Haushalt.
- Wenn du einen Haushalt verlässt: Dein Mitgliedseintrag und dein Verweis darauf werden gelöscht, und du siehst die Liste nicht mehr. Einträge und Erledigungen bleiben, auch die dir zugeordneten — sonst würde der Nachweis, wer was getan hat, für die Verbleibenden falsch. Sollen auch deine Erledigungen entfernt werden, schreib uns, dann tun wir das.
- Wenn du als Letzte oder Letzter gehst: „Diesen Haushalt verlassen“ löscht die Daten des Haushalts nicht, auch wenn danach niemand mehr da ist. Lesen kann sie niemand mehr — die Sicherheitsregeln erlauben Lesen nur Mitgliedern, und es gibt keine —, doch die Datensätze bestehen bis zur Löschung auf Anfrage. Bitte uns darum, dann tun wir es. Das Löschen des Kontos ist etwas anderes: Bleibt danach niemand im Haushalt, werden Haushalt, Einträge und Erledigungen mitgelöscht.
- Einladungslinks funktionieren 14 Tage nach ihrer Erstellung nicht mehr; von dir erstellte Links werden mit der Löschung deines Kontos ungültig.
- Dein Konto: Einstellungen → Konto löschen, in der Android-App oder auf sinceby.app. Das geschieht sofort und kündigt dein Abo, bevor irgendetwas gelöscht wird. Der Weg per E-Mail funktioniert weiterhin: Schreib von der Adresse, mit der du dich anmeldest, an lukas@mrz.email; wir antworten innerhalb von 7 Tagen und schliessen die Löschung innerhalb von 30 Tagen ab. Das vollständige Verfahren — was gelöscht wird und was bleibt — steht auf der Seite zur Kontolöschung.
- Dein Abo wird als erster Schritt der Kontolöschung gekündigt: Die automatische Verlängerung wird bei Google Play bzw. beim Zahlungsanbieter im Web abgeschaltet, bevor irgendetwas gelöscht wird — und gelingt das nicht, wird gar nichts gelöscht. Kündigen ist keine Rückerstattung und beendet Pro nicht vorzeitig: Was du bereits bezahlt hast, bleibt dir bis zum Ende der Periode. Dein Kundendatensatz bei RevenueCat wird mit dem Konto gelöscht.
- Kaufdaten — was wann zu welchem Preis gekauft wurde — bewahren Google und RevenueCat so lange auf, wie es ihre eigenen Fristen und die gesetzliche Aufbewahrungspflicht verlangen. Darauf haben wir keinen Einfluss, und sie überdauern das zugehörige Konto.
Deine Rechte
Du hast das Recht auf Auskunft, auf Berichtigung, auf Löschung, auf Einschränkung und auf Widerspruch (Art. 15–21 DSGVO; Art. 25 ff. revDSG) sowie darauf, eine erteilte Einwilligung jederzeit zu widerrufen, ohne dass die bisherige Bearbeitung dadurch unrechtmässig wird.
Die Löschung kannst du selbst ausüben, sofort und ohne jemanden fragen zu müssen: Einstellungen → Konto löschen, in beiden Apps. Die Seite zur Kontolöschung beschreibt, was verschwindet, was bleibt und was mit einem Abo geschieht.
Die Datenübertragbarkeit (Art. 20 DSGVO) beantwortet die App selbst. In den Einstellungen exportierst du deine gesamte Liste samt Verlauf als eine JSON-Backupdatei und deinen Verlauf als CSV, die jede Tabellenkalkulation öffnet — alles, was du eingetragen hast, in einem strukturierten, gängigen, maschinenlesbaren Format, jederzeit und ohne jemanden fragen zu müssen. Beides liegt nicht hinter der Bezahlschranke und wird es nie. Wenn du den Export lieber von uns bekommst, sag Bescheid.
Für all das erreichst du uns unter lukas@mrz.email. Ausserdem steht dir die Beschwerde bei einer Aufsichtsbehörde offen — in der Schweiz beim Eidgenössischen Datenschutz- und Öffentlichkeitsbeauftragten (EDÖB), in der EU/im EWR bei der Behörde deines Wohnsitzes, deines Arbeitsplatzes oder des Orts des mutmasslichen Verstosses.
Berechtigungen
Geprüft am zusammengeführten Release-Manifest der App, das auch die von den Bibliotheken von Google und RevenueCat ergänzten Berechtigungen enthält — nicht nur die selbst geschriebenen. Die vollständige Liste:
INTERNETundACCESS_NETWORK_STATE— Anmeldung, Haushaltssynchronisierung und Käufe.com.android.vending.BILLING— der Kaufvorgang über Google Play.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS— damit die App Android bitten kann, sie im Hintergrund nicht zu beenden. Du kannst das ablehnen, alles funktioniert weiterhin.WAKE_LOCK,FOREGROUND_SERVICE,RECEIVE_BOOT_COMPLETEDundcom.google.android.providers.gsf.permission.READ_GSERVICES— von den Google-Play-Diensten ergänzt, damit Synchronisierung und Kaufabwicklung Ruhezustand und Neustart überstehen.com.sinceby.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION— von der App für den internen Eigengebrauch definiert; sie gewährt keinerlei Zugriff.
Es gibt keine Berechtigung für Standort, Kontakte, Kamera, Mikrofon oder Speicher. Sichern, Exportieren und Importieren nutzen die Dateiauswahl des Systems, die der App nur die eine gewählte Datei übergibt.
Kinder
Sinceby ist ein Haushaltswerkzeug für ein allgemeines Publikum und richtet sich nicht an Kinder. Ein Konto wird Personen unter 16 Jahren nur mit Zustimmung der Eltern oder Erziehungsberechtigten angeboten (Art. 8 DSGVO; in einzelnen EU-Staaten gilt eine niedrigere Altersgrenze). Ohne Konto ist die App in jedem Alter nutzbar, da dann nichts das Gerät verlässt. Wenn du vermutest, dass ein Kind ein Konto angelegt hat, schreib an lukas@mrz.email; es wird gelöscht.
Änderungen dieser Erklärung
Diese Seite beschreibt, was die App heute tut, und sie wird vor der Veröffentlichung einer Version umgeschrieben, die daran etwas ändert — nicht danach. Das Datum oben nennt den Stand. Wesentliche Änderungen stehen zusätzlich in den Release-Notes. Frühere Versionen von Sinceby waren rein lokal und diese Erklärung sagte das; auf die oben genannte Version trifft das nicht mehr zu.