1. Controller
VIRAL GROWTH Ventures GmbHSimplon Straße 14
D-10245 Berlin
Germany
Represented by Managing Director Daniel Minini
Email: dementica@minini.de
2. Processing on your device
Onboarding answers, display settings, learning progress, check-ins, recently used situations and saved phrases are stored locally on your device using Apple technologies such as UserDefaults and SwiftData. These contents are not automatically transmitted to us.
Local storage is necessary to provide the app functions you expressly request. Where section 25 TDDDG applies, the legal basis is section 25(2)(2) TDDDG; for personal data, Article 6(1)(b) GDPR. Local data remains until you delete it in the app or uninstall the app.
2a. Optional account and cross-device backup
Demenz Coach can be used fully without an account. If you enable optional backup, you can sign in with Apple or with a telephone number and one-time SMS code. Firebase Authentication processes a random user identifier and information about the selected sign-in method. With Apple, your name, email address or an Apple relay address may be transmitted depending on your choice. For phone authentication, Google also processes and stores the number for spam and abuse prevention; your mobile provider may charge for the SMS.
An additional sign-in method is linked to an existing account only after explicit confirmation. Accounts are not merged automatically based on an email address or telephone number.
After sign-in, voluntarily created care profiles, support entries, experiences and favourites are stored through Cloud Firestore in the Firebase project and synchronised between signed-in devices. The data is held in the Firebase database in the europe-west1 region. Under the access rules used, each account can access only its own records. Do not enter diagnoses, patient records or other identifiable health information about a person receiving care in these profiles.
The legal basis for authentication and synchronisation is Article 6(1)(b) GDPR. Cloud data remains until individual content or the account is deleted. Under “Settings → Account & Backup”, you can export your data, sign out, or permanently delete the account and cloud data. Signing out does not delete cloud or local data. Local data is managed per device and kept separate for the guest state and each signed-in account.
3. Personal AI assistance, feedback and voice input
A personal request is transmitted only after your explicit consent. For text requests, our backend processes the situation description and technically necessary request data. Optional feedback is transmitted together with the related situation, the selected outcome and the phrase and step previously shown, so that a local learning can be created. For voice input, the audio recording you actively make is transmitted for transcription; spoken feedback is evaluated together with that context after transcription. A generated response may also be processed for multilingual display.
Processing uses Google Cloud Functions for Firebase in the europe-west1 region and the OpenAI API. Without an additional optional quality consent, requests to the OpenAI Responses API use store: false. If the separate quality option, which is off by default, is enabled, OpenAI stores newly submitted text including relevant context and the generated responses as application state in our OpenAI project logs for up to 30 days. Access is intended for internal quality review by authorised team members. Disabling the quality option prevents new response objects from being stored; previously stored entries expire within 30 days. Personal AI assistance remains available without this quality option.
OpenAI does not use API inputs and outputs for model training unless a separate explicit data-sharing option is enabled. Separate security logs may be retained for up to 30 days under OpenAI's then-current rules. Our backend does not maintain its own persistent content database of situation descriptions, feedback, responses or audio files.
The legal basis for personal AI processing and for the separate quality option is Article 6(1)(a) GDPR in each case. Both choices can be changed or withdrawn independently at any time with future effect under “Settings → Privacy & Data”. The locally available standard content remains usable without consent.
Enter anonymised situations only. Do not enter or record names, addresses, contact details, dates of birth, insurance numbers, detailed patient records or other information that identifies a person receiving care.
The app is not intended to process identifiable health data of third parties. Anyone who transmits another person's data contrary to this instruction must independently ensure that they have valid authority and a legal basis under Article 6 and, for health data, Article 9 GDPR. If in doubt, do not transmit the information.
4. Security, configuration and abuse prevention
Firebase Remote Config provides technical configuration. Firebase App Check and Apple App Attest help verify that requests come from a genuine app installation. Network data, in particular the IP address, is processed briefly for operations, error diagnosis, security checks and rate limits; a pseudonymous security identifier is derived from it. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure, stable and abuse-resistant operation.
Backend responses use Cache-Control: no-store. Security and infrastructure logs are kept only as long as necessary for their purpose or to meet legal obligations.
5. Usage analytics and crash diagnostics
Google Analytics for Firebase is disabled by default. Only after you voluntarily enable it in settings are technical usage events processed, for example whether onboarding, an assistance request or a purchase flow worked. An app instance identifier and device, app and interaction data may be involved. The legal bases are Article 6(1)(a) GDPR and, where required, section 25(1) TDDDG. Consent can be withdrawn at any time in settings with future effect.
Firebase Crashlytics processes technical crash and error data, including app version, device model, operating system, time, technical states and stack traces. Diagnostics are used to maintain app stability and security and can be disabled for future reports in the app settings. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and stable app operation.
Situation descriptions, audio files, saved phrases and check-in content are not sent as analytics parameters or Crashlytics custom data. We do not set a user identifier in Crashlytics.
6. Purchases, subscriptions, Apple Ads and Adapty
Apple processes purchases and subscriptions. We do not receive complete payment details. Where premium management is enabled, the app uses Adapty to display offers and verify subscription status. This may involve a random app profile identifier, IP address, device and app information, offer interactions, and purchase and subscription status.
If you open the app after interacting with an Apple Ads placement, Adapty may process privacy-preserving attribution data through Apple's AdServices interface. This can include campaign, ad group, keyword, ad placement, country, and download or redownload status. We use this information to attribute installs, trials, subscriptions, and revenue to our own Apple Ads campaigns and evaluate their performance. Apple's advertising identifier (IDFA) remains disabled; we do not use this data for cross-app tracking or personalised advertising.
The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(f) GDPR for reliable provision, abuse prevention and privacy-preserving performance measurement of our own advertising. Purchase and attribution data is retained in accordance with statutory retention duties and the rules of Apple and Adapty.
7. Website, Google Analytics, support and GitHub Pages
This website is provided through GitHub Pages. When you access it, GitHub processes technically necessary data such as IP address, time, requested file, referrer, browser and device information. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure provision of these information pages.
Google Analytics 4 with measurement ID G-5NRN1EMJDC loads only after you select “Allow analytics”. We send no analytics request to Google before that consent. After consent, processed data may include pages and sections viewed, approximate session duration, referrer, browser, device and approximate location information, and clicks on central website functions. We do not send form entries, care situations, health data or a user identifier to Google Analytics. Advertising storage, advertising user data, personalised advertising and Google Signals are disabled.
Your choice is stored in your browser's local storage under demenzcoach.analyticsConsent.v1. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent is voluntary and can be withdrawn for the future at any time through “Privacy settings” at the bottom of the page. The website will also attempt to remove the Google Analytics cookies it set.
For support requests by email, we process the sender address, message and metadata to handle the request. The legal basis is Article 6(1)(b) GDPR for contract-related requests and otherwise Article 6(1)(f) GDPR. Support messages are deleted when no longer needed unless legal retention duties apply. Do not send health data by email.
8. Recipients and international transfers
- Google Ireland Limited / Google LLC: Firebase Authentication, Cloud Firestore and other Firebase and cloud infrastructure, App Check, Remote Config, Crashlytics and optional analytics.
- OpenAI Ireland Limited and affiliated processors: AI responses, translations and transcription.
- Apple Distribution International Ltd. and affiliated companies: Sign in with Apple, app distribution, platform services, purchases and subscriptions.
- Adapty Tech Inc.: optional offer and subscription management.
- GitHub B.V. / GitHub, Inc.: hosting this website.
Where data is processed outside the European Economic Area, transfers are based, depending on the provider, on an adequacy decision, in particular the EU-US Data Privacy Framework, and/or EU Standard Contractual Clauses with supplementary safeguards. Further details are available in each provider's privacy notice.
9. Requirement to provide data and automated decisions
You are not legally required to provide personal text or voice input or analytics data. Without it, personal AI assistance, voice input or optional analytics cannot be used. We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not conduct advertising profiling. Responses are generated automatically by an AI system and labelled in the app as AI suggestions.
10. Your rights
Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). Consent may be withdrawn at any time for the future under Article 7(3) GDPR. Processing before withdrawal remains lawful.
Data held only locally can be deleted only on the relevant device under “Settings → Privacy & Data”, because we cannot access it. For an optional account, you can export data and permanently delete the cloud data directly under “Settings → Account & Backup”. Send other requests to dementica@minini.de. We may request additional information necessary to verify identity.
11. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for our company is in particular:
Berlin Commissioner for Data Protection and Freedom of InformationAlt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de
12. Provider information
13. Updates and language versions
We update this policy when functions, providers or the legal framework change. The published version with the date above applies. The German and English versions are intended to have the same meaning. In case of discrepancies, the German version prevails to the extent legally permissible; mandatory rights associated with another contract language remain unaffected.