Privacy Policy

This English version is provided for convenience only. In case of discrepancies, the German version (Datenschutzerklärung) is legally binding.

Privacy Policy – Website modseven.net

Last updated: September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection regulations is: ModSeven Engineering Owner: Philipp Hanzik Gogolstraße 8b 90475 Nuremberg Germany Email: info@modseven.net

2. General information on data processing

As a matter of principle, we process personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. Personal data of our users is regularly processed only with the user’s consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.

3. Hosting (Vercel)

This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When this website is accessed, technically necessary data (in particular server log files) is processed by Vercel. Vercel may process data in the USA. A data processing agreement (DPA) exists between us and Vercel for transfers to the USA. Insofar as data is transferred to third countries, this is done on the basis of the EU standard contractual clauses (Art. 46(2)(c) GDPR) and, where applicable, on the basis of the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a reliable, secure and high-performance provision of the online offer).

Further information: https://vercel.com/legal/privacy-policy

4. Server log files

When you visit our website, our hosting provider (Vercel) automatically collects and stores the following data transmitted by your browser or device in so-called server log files:

  • IP address – of the requesting device (truncated/anonymised where technically possible)
  • Date and time – of the request
  • URL and method – of the requested resource
  • HTTP status code – and amount of data transferred
  • User agent – browser type, version and operating system
  • Referrer – the previously visited page, if transmitted

This data is stored for a limited time to ensure operation, security (defence against attacks) and error analysis, and is not merged with other data sources. Legal basis: Art. 6(1)(f) GDPR.

5. Cookies, language selection and cookie consent

Our website uses cookies. Cookies are small text files stored in your browser. We use both technically necessary cookies (e.g. to store your cookie decision, your language selection and, for logged-in users, a session cookie for authentication) and – after your consent – cookies for analytics purposes. The website is available in German and English. On your first visit the language is preselected automatically: for this we evaluate the country of origin derived from your IP address by our hosting provider (only the country code, e.g. “DE”) and, as a fallback, your browser’s language setting. This information is used solely to redirect you to the appropriate language version and is not stored by us. You can change your language at any time using the “DE / EN” switch in the page header.

  • cookieConsent – Stores your decision regarding the cookie banner. Duration: 365 days. Legal basis: Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
  • NEXT_LOCALE – Stores the most recently selected language (de/en) so that you see the appropriate language version directly on your next visit. Duration: 365 days. Legal basis: Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG.
  • Authentication cookie – Only set when you sign in to the internal area. Contains a signed JSON Web Token (JWT). HTTP-only, secure. Legal basis: Art. 6(1)(b) GDPR.
  • Google Analytics (_ga, _ga_*) – Only set if you explicitly consent to their use in the cookie banner. Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG.

You can withdraw your consent at any time by deleting the cookies in your browser or by contacting us by email.

6. Google Analytics

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. It is used exclusively if you have explicitly consented in the cookie banner. The data stream is named “mdsvn”, the measurement ID is G-RT96KR6VJN. Google Analytics uses cookies and similar technologies to analyse your use of the website. The information generated about your use of this website is usually transmitted to a Google server in the USA and stored there. IP anonymisation is active; your IP address is therefore truncated by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with further services related to website and internet usage.

  • Purpose – statistical evaluation of website usage in order to improve the content and structure of the site
  • Legal basis – Art. 6(1)(a) GDPR (consent) and § 25(1) TDDDG
  • Recipients – Google Ireland Ltd. / Google LLC (USA)
  • Third-country transfer – transfer to the USA on the basis of the EU-US Data Privacy Framework and EU standard contractual clauses
  • Retention period – Data transmitted from your device in the context of Google Analytics is automatically deleted after 14 months. The cookies _ga and _ga_* have a lifetime of up to 24 months.
  • Withdrawal – You can withdraw your consent at any time with effect for the future – by deleting the cookies in your browser, by declining in the cookie banner or by installing the browser add-on at https://tools.google.com/dlpage/gaoptout

Which data is processed

After consent has been given, the following data in particular is processed:

  • truncated IP address and the approximate location derived from it (country/region, no precise positioning)
  • pages visited, time and duration of the visit and the order of pages visited
  • referrer – the previously visited page or the source through which you reached the website
  • device and browser data: device type, operating system, browser, screen resolution, language setting
  • pseudonymous identifiers – the client ID in the cookies _ga and _ga_*, which links returning visits
  • interactions such as scroll depth, clicks on outbound links and standard GA4 events

No tracking without consent

Before you give your consent, no Google Analytics script is loaded and no analytics cookies are set. If you decline in the cookie banner or make no selection, no data is transmitted to Google at all. This data is not merged with other data we collect (e.g. from the contact form), and there is no automated decision-making or profiling for advertising purposes.

A data processing agreement pursuant to Art. 28 GDPR is in place with Google. Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://policies.google.com/privacy

7. Contact form

If you send us enquiries via the contact form or by email, your details from the enquiry form, including the contact details you provide there, are stored by us for the purpose of processing the enquiry and in case of follow-up questions. The following data is processed:

  • Name – to address you personally
  • Email address – to answer your enquiry
  • Subject & message – content of your enquiry
  • IP address – for protection against misuse (spam prevention, security)
  • Timestamp – of the submission

The data is stored in a database operated by us (PostgreSQL via Prisma ORM) and additionally forwarded by email to our mailbox. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient processing). The data is not passed on to third parties. Retention period: until your enquiry has been fully processed, but no longer than 24 months, unless statutory retention obligations require otherwise.

8. Email delivery (Strato)

For sending and receiving emails – in particular for contact form enquiries – we use the mail servers of Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Strato. The servers are located in Germany. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable email delivery).

Privacy policy: https://www.strato.de/datenschutz/

9. Registration and login (internal area)

If you create a user account in the internal area, we process the data you provide (e.g. name, email address, password) in order to provide the customer account. Passwords are stored exclusively as hash values using bcrypt; they are never stored in plain text. After a successful login, a signed JSON Web Token (JWT) is set as an HTTP-only cookie in your browser to authenticate you for further requests. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention period: until the account is deleted by you or by us; the session cookie has a limited validity.

10. Recipients / processors

We use the following service providers, each of which is bound by a data processing agreement pursuant to Art. 28 GDPR:

  • Vercel Inc. (USA) – hosting of the website
  • Google Ireland Ltd. / Google LLC – web analytics via Google Analytics (only with consent)
  • Strato AG (Germany) – sending and receiving emails

11. Your rights

You have the following rights vis-à-vis us with regard to the personal data concerning you:

  • Right of access – Art. 15 GDPR
  • Right to rectification – Art. 16 GDPR
  • Right to erasure – Art. 17 GDPR
  • Right to restriction of processing – Art. 18 GDPR
  • Right to data portability – Art. 20 GDPR
  • Right to object – Art. 21 GDPR
  • Withdrawal of consent – Art. 7(3) GDPR – the lawfulness of processing carried out before the withdrawal remains unaffected

To exercise your rights, an informal email to info@modseven.net is sufficient.

12. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany https://www.lda.bayern.de

13. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.

14. Currency and amendment of this privacy policy

This privacy policy is currently valid and was last updated in September 2026. Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed on this page at any time.

App Privacy Policies

Privacy Policy – Choreo

Last updated: 6 May 2026

This privacy policy describes which personal data is processed when using the Choreo app (Android) and the associated backend services (website, MagicMirror integration), for what purpose and on what legal basis.

1. Controller

The controller within the meaning of the GDPR and other national data protection laws as well as other data protection regulations is: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b, 90475 Nuremberg, Germany Email: info@modseven.net Please direct all enquiries regarding data protection, access, rectification and erasure exclusively to the email address above.

2. Scope

This policy applies to:

  • the mobile Choreo app for Android (package net.modseven.choreo)
  • the backend at https://choreo-mu.vercel.app (web pages for email confirmation, invitation acceptance, password reset)
  • the optional MagicMirror module “MMM-Choreo”, which authenticates against the backend

3. Which personal data is processed?

3.1 Registration & account

  • Email address (required, serves as login)
  • Display name (required, freely selectable)
  • Password — never stored in plain text, but hashed using bcrypt (12 rounds)
  • Profile picture / avatar (optional, uploaded by the user)
  • Role (ADMIN or MEMBER) and family membership
  • Timestamps for creation and email verification
  • Teasing pings: boolean setting for push reminders

3.2 Tasks and time tracking

  • Task definitions (title, optional description, type, interval, assignments, effort factor) — created by family members
  • Time entries: start time, end time, duration, source (TIMER/AUTO/MANUAL), optional note, assignment to user and task
  • Task instances per period with time of completion

3.3 Family / household

  • Family name and type (FAMILY or SHARED_FLAT)
  • Member list of the family
  • Optional MagicMirror token (random string granting read-only access to family data; can be generated and revoked by the family admin)
  • Invitations: recipient email, token, expiry date, acceptance status

3.4 Authentication & security

  • Refresh tokens (hashed in the database)
  • Email verification tokens (time-limited, single use)
  • Password reset tokens (time-limited — 60 minutes —, single use)
  • JWT access tokens (short-lived, not persisted server-side; stored exclusively on the user’s device in encrypted app storage)

3.5 Push notifications

  • FCM push token (issued by Firebase Cloud Messaging), per device
  • Platform identifier (android)
  • Used to send optional reminders (“teasing pings”, see 3.1)

3.6 Technical logs

On the server side, short-term access logs (IP address, user agent, time, requested URL) are generated by the hosting platform Vercel for routine operation. These are processed exclusively by Vercel for security and operational purposes (see processors below) and are not used by us for profiling.

3.7 We do not process:

  • Location data
  • Device contacts
  • Browser history
  • Advertising IDs
  • Third-party data without their consent
  • Special categories of personal data (health, biometric, political data — Art. 9 GDPR)

4. Purposes and legal bases

PurposeLegal basis
Provision of the service (account, tasks, time, family)Art. 6(1)(b) GDPR — performance of a contract
Sending email verificationArt. 6(1)(b) GDPR — performance of a contract
Sending invitation emailsArt. 6(1)(b) GDPR — performance of a contract; the address originates from the family context
Sending password reset emailsArt. 6(1)(b) GDPR — performance of a contract
Teasing pings (push reminders)Art. 6(1)(a) GDPR — consent (toggle in the settings, can be withdrawn at any time)
Security, abuse detection, logsArt. 6(1)(f) GDPR — legitimate interests
Use of MagicMirror tokenArt. 6(1)(a) GDPR — explicit action by the admin

5. Recipients / processors

We use processors within the meaning of Art. 28 GDPR with whom data processing agreements exist or for whom we rely on the respective data processing addendum:

5.1 Hosting of the web application

Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA

5.2 Database (Postgres)

Neon Inc. (or the Postgres platform currently used for the database; as of today: Neon, region Frankfurt/EU)

5.3 Push notifications

Google Ireland Limited (Firebase Cloud Messaging), Gordon House, Barrow Street, Dublin 4, Ireland

5.4 Sending emails (SMTP)

Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany

5.5 App distribution

The Choreo app is available in two ways:

  • Google Play Store (Google LLC) — installation, device and account data is processed in accordance with Google’s privacy policy
  • Direct APK download via https://choreo-mu.vercel.app/choreo.apk — delivered exclusively via Vercel (see 5.1); no additional data processing takes place beyond the server logs described in 3.6

6. Data transfer to third countries

Vercel and Google are corporations based in the USA. A transfer of personal data to the USA is possible. The transfer takes place on the basis of:

  • the EU-US Data Privacy Framework (for the respectively certified recipients)
  • additionally the standard contractual clauses (SCCs) of the EU Commission where no certification applies
  • as well as supplementary technical and organisational measures

The database (Neon) is operated in the Frankfurt (EU) region; the application data stored there is therefore not transferred to third countries.

7. Retention period and deletion

  • Account and family data remains stored as long as the account exists.
  • Time entries and tasks are generally stored permanently so that statistics and histories remain available. The user can delete individual entries in the app at any time.
  • Verification and reset tokens become unusable after redemption or expiry and are discarded during the next processing run (maximum lifetime of 60 minutes for reset, 24 hours for email verification).
  • Refresh tokens are invalidated on logout, password change or reset.
  • Invitations: 14-day lifetime, automatically invalid thereafter.
  • Push tokens are deleted when the user signs out or revokes push on the device.
  • Upon request by the user (email to info@modseven.net), the entire account including all tasks, times and avatars is deleted. In special cases (e.g. if the user is the admin of the only family administration) we will consult beforehand about handing over to another member.

8. App permissions (Android)

  • Push notifications (Android 13+): only if the user agrees; without consent the app continues to work but does not receive teasing pings.
  • Photo picker (PickVisualMedia): requested when the user wants to select an avatar image. Only the image selected by the user is read, never the entire photo library.
  • Internet and foreground service (for running timers): technically necessary.

9. Cookies and tracking

  • The app itself does not set cookies and uses no tracking (no Google Analytics, no Facebook pixel, no advertising IDs).
  • The website uses only technically necessary storage mechanisms (session storage during the email verification / reset flow), no tracking cookies.
  • No data is sold or passed on to advertising networks.

10. Avatar URLs

Profile pictures are delivered via a unique, hash-based URL of the form /api/users/<userId>/avatar?v=<sha1> so that browsers and the app can cache the image. The URL cannot be guessed (user ID and hash are both randomly generated), but the endpoints are technically publicly accessible. Anyone who knows the link can retrieve the image — comparable to an “unlisted” URL.

11. MagicMirror token

Family admins can generate a read-only token that allows a MagicMirror module to access basic family data (members, current time accounts, upcoming tasks). The token can be revoked at any time; a new token invalidates the old one.

12. Security measures

  • Transport encryption: TLS 1.2/1.3 for all connections between app, website and backend
  • Password hashing: bcrypt with 12 rounds
  • JWT signature: HS256 with a secret held server-side
  • Token rotation: refresh tokens are revoked on security events (password change, reset, logout)
  • Data minimisation: each endpoint only returns the fields required; in particular, the password hash is never transmitted to the client

13. Rights of data subjects

As a data subject within the meaning of the GDPR, you have the following rights:

  • Access (Art. 15) to the data stored about you
  • Rectification of inaccurate data (Art. 16)
  • Erasure of your data (Art. 17), insofar as no statutory retention obligations apply
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) — on request we provide a machine-readable export of your data
  • Objection (Art. 21) to processing based on legitimate interests
  • Withdrawal of consent given, with effect for the future

To exercise these rights, an informal email to info@modseven.net stating the email address associated with your account is sufficient.

14. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). As a rule, the authority of your habitual residence is responsible. In Germany, the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de is responsible for us. Users from Austria can contact the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at, dsb@dsb.gv.at.

15. Children

Choreo is primarily aimed at adults or families with parents as family admins. Accounts for minors may only be created with the consent of a parent or guardian. We do not collect data directly from children under 16 without such consent.

16. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The current version then applies to your next visit. Users will be notified by email of significant changes.

Privacy Policy – YAMA

Last updated: 8 July 2026

YAMA is a companion app for MeshCore radios. This privacy policy describes which data the app processes – the principle is local and offline: your content stays on your device, and an internet connection is only required for map tiles.

1. Controller

The controller for data processing in connection with this app is: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b 90475 Nuremberg Germany Email: info@modseven.net Web: modseven.net

2. Basic principle: local and offline

YAMA is a companion app for MeshCore radios. The app is built to process as little data as possible:

  • It uses no user accounts, no advertising and no analytics or tracking services (no Google Analytics, Firebase Analytics, advertising IDs or similar).
  • Your messages, contacts, channels, settings and measurement points are stored exclusively locally on your device and are not transmitted to us or third parties.
  • An internet connection is only required for map tiles (see section 5).

3. Data stored locally on the device

The following data is stored locally in the app and does not leave your device towards our servers:

DataPurpose
Chat messages (sent/received)display and history of your conversations
Contacts / nodes (incl. public key, name, last known position)address book and map display
Channels and channel keysparticipation in channels
Saved room passwordsautomatic re-login to room servers
GPS measurement points of the direction-finding featurelocating / direction-finding a node
App settingsconfiguration of the app

This data remains stored until you delete it in the app or uninstall the app. If Android system backup is enabled on your device, app data may be included in this device-/account-bound backup. Legal basis: Art. 6(1)(b) GDPR (provision of the functions you requested).

4. Support / contact form

If you use the support / contact form in the app, the details you enter – name, email address and your message – are transmitted to our server at https://modseven.net so that we can process your request. Without active use of this form, no such transmission takes place.

Purpose: processing your request. Legal basis: Art. 6(1)(b) or (f) GDPR (responding to enquiries). Retention period: as long as necessary to process the request, or until statutory retention periods expire.

5. Map tiles (third-party providers)

For the map view, the app loads map tiles from external map services. In doing so, the respective provider necessarily receives your IP address and the requested tile coordinates (which reflect the approximate map section viewed). Depending on the selected map style, the following are used:

  • CARTO (tiles from basemaps.cartocdn.com) – map data © OpenStreetMap contributors, style © CARTO
  • Esri (satellite, server.arcgisonline.com)

Please note the privacy policies of these providers. The map is only loaded when you open the map view. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in displaying the map).

6. Bluetooth and mesh network

The app connects to your MeshCore device via Bluetooth. Only data between the app and the device is exchanged over this connection; there is no transmission to us. Please be aware of the nature of a radio mesh network: messages you send over the network, as well as any position of your node you may have configured, are transmitted by radio and relayed by other participants/repeaters. What you send over the mesh is therefore not private vis-à-vis other network participants. This is the responsibility of the user and is not processing by us.

7. Permissions and their purpose

PermissionPurpose
Bluetooth (scan/connect)searching for and connecting to the MeshCore device
Location (coarse/fine)your own position on the map, distance measurement, direction-finding points (local only; no tracking, no sharing)
Notificationsalerts about new messages
Foreground servicekeeping the connection to the device active in the background
Internet / network stateloading map tiles

On Android 12+, Bluetooth scanning is requested with the flag “not used to derive location” (neverForLocation). Location is only used for the map functions mentioned above.

8. Disclosure to third parties

Apart from the cases mentioned in section 4 (support server) and section 5 (map providers), no personal data is passed on to third parties. No data is sold.

9. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Since most data resides exclusively on your device, you can remove it yourself at any time by deleting it in the app or uninstalling the app. For matters concerning the support server, please contact the address given in section 1. You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes to this privacy policy

We amend this privacy policy when the app or the legal situation changes. The current version published here applies.

11. Contact

If you have any questions about data protection, you can reach us at: info@modseven.net

Privacy Policy – Tummo Breath App

Effective date: March 2026

1. Data Controller

Responsible for data processing within the Tummo Breath App: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b, 90475 Nürnberg, Germany Contact: support@modseven.net

2. Health Data

The Tummo Breath App is a guided breathing exercise application. It does not collect, store, transmit, or share any health data or biometric information.

  • Local storage only – All breathing session data (e.g. session duration, round counts) is stored locally on your device only and is never transmitted to any server.
  • No health APIs – The app does not use any health or fitness APIs (e.g. Google Fit, HealthConnect).
  • No sharing – No health data is shared with third parties, advertisers, or analytics services.

3. What Data We Collect

The Tummo Breath App only collects data that you voluntarily submit through the in-app support form:

  • Name – to address you personally when responding
  • Email address – to reply to your inquiry
  • Message (free text) – the content of your request
  • Date & time – for tracking and follow-up purposes

Through the support form we do not collect IP addresses, location data, health data, or any other tracking information. Aside from the anonymous usage statistics described in section 4, no analytics or advertising SDKs are used.

4. Anonymous Usage Statistics

To improve the app and understand which features and settings are used, we collect anonymous usage statistics. No personal data is collected in this process.

What is collected

Each time you start a breathing session, the app transmits the following information to our server:

  • a random identifier generated once on your device (a random UUID). It is not linked to your name, your device, an account, or any other identifiers, and cannot be traced back to you;
  • the country derived from the region set on your device (e.g. “DE”); no GPS or location access;
  • the settings the session was started with (e.g. number of rounds, breaths per round, hold times, music/voice guidance on/off, custom mode);
  • the app version as well as the date and time of the session start.

What is NOT collected

We do not collect or store any name, email address, precise location, or other personal data. Your IP address is not stored and is not evaluated for statistical purposes (as is technically unavoidable with any internet connection, it is only processed briefly to deliver the request by our hosting provider and is not logged).

Purpose and legal basis

Processing serves exclusively the statistical evaluation and improvement of the app. To the extent that this anonymous data has any personal reference at all, the legal basis is our legitimate interest in improving and further developing the app pursuant to Art. 6(1)(f) GDPR.

Recipients / Hosting

The data is saved in a PostgreSQL database hosted by Neon Inc. in the Frankfurt (EU) region. It is therefore stored exclusively within the European Union; no transfer to a third country takes place.

Retention period

The anonymous statistics data is stored for as long as it is needed for statistical evaluation, but no longer than 24 months.

Your control

Since the data is anonymous, it cannot be attributed to you. You can prevent the transmission at any time by using the app offline / in airplane mode or by uninstalling the app.

5. Legal Basis

Data processing is based on Art. 6(1)(b) GDPR (contract performance or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to support inquiries).

6. Data Retention

Data submitted through the support form is stored for the duration of processing your inquiry and deleted within 90 days thereafter, unless legal retention obligations apply.

7. Data Deletion

You have the right to request deletion of your personal data at any time. To do so, send an informal email to support@modseven.net. We will completely remove your data within 30 days of receiving your request and confirm the deletion by email.

8. Your Rights

Under the GDPR, you have the following rights: access to your stored data (Art. 15), rectification of inaccurate data (Art. 16), erasure of your data (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority.

9. Third-Party Sharing

Your data is not shared with, sold to, or otherwise transferred to any third parties. All processing is carried out exclusively by the data controller.

10. Changes

This privacy policy may be updated from time to time. The current version is always available at this URL.

Privacy Policy – NoteStrike

Last updated: 23 September 2026

This privacy policy applies to the Android app “NoteStrike – Intelligent Note Trainer” (package name net.modseven.intelligentnotetrainer), which is distributed via Google Play. It explains which data the app processes, for what purpose, and what rights you have.

Key points at a glance

  • NoteStrike analyses the microphone signal exclusively on your device to recognise the notes you play. Nothing is recorded, nothing is stored and nothing is transmitted.
  • Settings and practice statistics are stored on your device only. We have no access to them.
  • The app has no user accounts, no advertising and no analytics or tracking services, and does not use the advertising ID.
  • Data leaves your device only in two cases that you trigger yourself: when you write to us via the feedback form (name, email address, message) and when you buy the Pro version via Google Play (payment is handled by Google).

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is: ModSeven Engineering Owner: Philipp Hanzik Gogolstraße 8b 90475 Nürnberg Germany Email: info@modseven.net

2. Microphone (RECORD_AUDIO permission)

NoteStrike needs access to the microphone to detect the pitch of the notes you play on your instrument. This is the core function of the app.

  • The microphone signal is analysed in real time in the device’s memory (pitch detection). No audio recording is created, nothing is stored and nothing is transmitted to us or to third parties.
  • The microphone is only active while you practise, i.e. as long as a practice screen is open. As soon as you leave the practice screen, microphone access ends.
  • You can revoke the permission at any time in the Android settings. Note detection will then no longer be available.

Since this data never leaves your device, we have no access to it.

3. Locally stored data (settings and practice statistics)

For the app to work and show your progress, it stores the following data exclusively in the app’s own storage on your device:

  • settings, e.g. clef, note range, round mode, accidentals, appearance (light/dark)
  • practice statistics, e.g. correctly and incorrectly played notes per note, round results, practice days
  • counters for the rating prompt (see section 5) and the status of the Pro unlock

No transmission, deletion

This data is not transmitted to us and is not linked to you as a person. You delete it by clearing the app data in the Android settings or by uninstalling the app.

Android backup

If you have enabled Google backup on your device, Android may automatically back up the app data to your Google account (Google Drive). This is an operating system feature that you control in the Android settings. We have no access to these backups; Google’s privacy policy applies to them.

4. Feedback form

Via the rating prompt (section 5) you can send us a message (“What should we improve?”). Only if you fill in the form yourself and tap “Send” is the following data transmitted in encrypted form (HTTPS) to our server at modseven.net. Name and email address are required fields so that we can reply to you:

  • Name – to address you personally
  • Email address – to reply to your message
  • Message – the content of your request; the subject “NoteStrike” is added automatically
  • IP address and timestamp – technically required when contacting our server, for protection against misuse

Storage and recipients

The data is stored in a database operated by us (PostgreSQL, hosted by Neon Inc., Frankfurt region, EU) and additionally forwarded by email to our mailbox. The server that receives the message is operated by Vercel Inc. (USA); emails are sent via Strato AG (Berlin, Germany). Data processing agreements pursuant to Art. 28 GDPR are in place with these service providers. Insofar as data is transferred to the USA, this is done on the basis of the EU-US Data Privacy Framework or the EU standard contractual clauses. The data is not passed on to other third parties or used for advertising purposes.

Purpose and legal basis

Processing and answering your message as well as improving the app. The legal basis is Art. 6(1)(b) GDPR (handling your request) and Art. 6(1)(f) GDPR (legitimate interest in improving NoteStrike).

Retention period

Until your request has been fully processed, but no longer than 24 months, unless statutory retention periods require otherwise. You can request deletion at any time (section 10).

Please do not include any information in your message that you do not wish to transmit.

5. Rating prompt

After a few practice sessions the app asks once whether you like NoteStrike (“Enjoying NoteStrike?”). The counters required for this (number of practice sessions and practice days, and whether you have already been asked) are stored locally only. Your answer is not transmitted to us.

  • “Yes, I like it” opens the NoteStrike page in the Google Play app. Google’s privacy policy applies there.
  • “Not really” opens the feedback form (section 4). Data is only transmitted once you submit it.

6. Pro version (in-app purchase via Google Play)

The Pro features of NoteStrike are unlocked through a one-time in-app purchase. The purchase is handled entirely by the Google Play billing system (Google Play Billing).

  • Payment is made exclusively to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, or Google LLC, USA) under the terms of use and privacy policy applicable there: https://policies.google.com/privacy
  • We receive no payment data (no credit card or bank details) and no information about your Google account.
  • So that the app can unlock the Pro features, it queries the purchase status from Google Play and processes the purchase confirmation generated by Google (purchase token, product ID, purchase state). This data remains on the device and is not transmitted to our servers.
  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

7. Internet access and external links

The app uses the INTERNET permission exclusively for the feedback form (section 4) and for Google Play Billing (section 6). Beyond that, the app does not establish any internet connections. The “modseven.net” link in the settings opens our website in your browser. The website’s privacy policy applies there: https://modseven.net/en/datenschutz#website

8. What NoteStrike does not do

  • no registration, no user accounts, no login
  • no analytics or tracking services (e.g. no Google Analytics, no Firebase) and no crash reports via third-party SDKs
  • no advertising and no use of the advertising ID
  • no location data, no contacts, no access to photos or files
  • no disclosure or sale of data to third parties

9. Google Play

You obtain the app via Google Play. In doing so, Google independently processes data, e.g. on installation, updates and devices and, if you have consented to this on your device, crash and usage statistics (“Android Vitals”). In the Google Play Console we only see aggregated, anonymised statistics. Google is responsible for this processing; details can be found in Google’s privacy policy.

10. Deletion of your data

  • Data on the device (settings, statistics) – delete it yourself at any time via Android settings → Apps → NoteStrike → Storage → Clear data, or by uninstalling the app.
  • Feedback messages – write to info@modseven.net. We will delete your message together with your name and email address, unless statutory retention obligations require otherwise.
  • Purchase data at Google Play – is managed by Google in your Google account.

11. Your rights

You have the following rights vis-à-vis us with regard to your personal data:

  • Right of access – Art. 15 GDPR
  • Right to rectification – Art. 16 GDPR
  • Right to erasure – Art. 17 GDPR
  • Right to restriction of processing – Art. 18 GDPR
  • Right to data portability – Art. 20 GDPR
  • Right to object – to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)

Exercising your rights

To do so, contact info@modseven.net. Please note: we have no access to the data stored locally on your device; you manage this yourself (section 10).

Right to lodge a complaint

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de

12. Children

NoteStrike is aimed at a general audience and not specifically at children. We do not knowingly collect personal data from children under 16 years of age. If you believe that a child has sent us data via the feedback form, please contact us; we will delete this data immediately.

13. Data security

All connections from the app to our server are encrypted with TLS (HTTPS). Practice data remains in the protected app storage of your device.

14. Changes to this privacy policy

We will update this privacy policy if the app or the legal requirements change. The current version can always be found at this address.

Privacy Policy – Math Shooter

Last updated: 23 September 2026

This privacy policy explains which data is processed when using the Android app “Math Shooter” (hereinafter “app”). It applies to the app distributed via Google Play with the package name modseven.mathshooterlite.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is: ModSeven Engineering Owner: Philipp Hanzik Gogolstraße 8b 90475 Nürnberg Germany Email: info@modseven.net

2. Key points at a glance

  • The app requires no user account and no registration.
  • The app shows no advertising and does not integrate any ad networks.
  • The app uses no third-party analytics, tracking or crash-reporting services.
  • The app requests no Android permissions (no access to camera, microphone, location, contacts, photos or files).
  • All game progress, settings and statistics are stored exclusively locally on the device.
  • The only third party that processes data is Google (distribution of the app via Google Play and handling of the optional in-app purchase).
  • The app is suitable for children. No personal data of children is collected.

3. Data stored locally on the device

For the app to work, it stores the following data in its own protected app storage on the device:

  • Settings – selected arithmetic operations, grade-level preset, bonus items on/off
  • Game statistics – high score, number of rounds played, correct, incorrect and missed answers, highest level reached
  • Learning progress – campaign progress (stars), progress in the times-table trainer, unlocked achievements
  • Daily challenge – date of the last participation and streak counter
  • Weak spots – a list of arithmetic problems that were answered incorrectly, including frequency (e.g. “7 × 8”), to enable targeted practice
  • Pro status – whether the Pro version has been unlocked

No personal reference

This data contains no personal reference: no names, no email addresses, no device or advertising IDs. It is not transmitted to the controller or to third parties.

Legal basis

Art. 6(1)(b) GDPR (provision of the app functions you have requested).

Retention period and deletion

The data remains stored until you delete it. You can delete statistics and weak spots in the app under “Statistics” via “Reset statistics”. Uninstalling the app completely removes all locally stored data.

4. Android backup (Auto Backup)

Android may back up the local app data (section 3) to your Google account as part of the device backup (Google One / Google Drive), provided you have enabled backup in the Android settings. This process is carried out by the operating system and Google, not by the app. You can disable the backup at any time under “Settings → Google → Backup” or delete backed-up data there. Google is responsible for this processing; Google’s privacy policy applies: https://policies.google.com/privacy

5. In-app purchase via Google Play (Pro version)

The app offers an optional, one-time in-app purchase (“Pro version”). It is handled entirely by the Google Play billing system (Google Play Billing). You do not need to grant a separate permission for this.

  • What Google processes – your Google account, payment data, purchase history as well as device and transaction data. This data is collected and processed exclusively by Google. The controller has no access to your payment data.
  • What the app receives – only the information whether the “Pro version” product has been purchased (product ID, purchase state and a purchase token generated by Google). This information is stored locally on the device to unlock the Pro features.
  • What the controller sees – In the Google Play Console, sales are shown in aggregated, non-personal form. In the event of refunds, Google may transmit an order number; this does not provide access to payment data either.

Provider

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy Google Play terms of service: https://play.google.com/intl/en/about/play-terms/

Legal basis

Art. 6(1)(b) GDPR (performance of the purchase contract).

Transfer to third countries

Google may transfer data to the USA. Google LLC is certified under the EU-US Data Privacy Framework; in addition, Google uses the standard contractual clauses of the EU Commission.

6. Distribution via Google Play

The app is downloaded and updated via the Google Play Store. In doing so, Google processes data such as your Google account, device identifiers, device and app version and, if you have allowed this in the Android settings, crash and performance reports (“Android Vitals”). The controller receives this information exclusively in aggregated and anonymised form in order to fix errors and improve the app.

Legal basis

Art. 6(1)(f) GDPR (legitimate interest in a stable and error-free app). You can disable the sharing of crash reports under “Settings → Google → Usage & diagnostics”.

7. No advertising, no tracking

The app contains no advertising, no ad SDKs, no analytics tools (e.g. Google Analytics, Firebase), no social media plugins and no third-party crash-reporting services. No advertising IDs are read and no usage profiles are created.

8. Internet connection

The app itself does not require an internet connection and does not establish any connections to servers of its own. Only the in-app purchase (section 5) and the Android backup (section 4) are handled via the Google services installed on the device.

9. Children and young people

The app is also aimed at children of primary school age. It does not collect any personal data and contains no advertising, no chat or social features and no external links. The Pro version can only be purchased via the Google account set up on the device. Parents can protect purchases with a password or block them completely via the Google Play settings or Google Family Link.

10. Contact

If you contact us by email (e.g. for support requests or bug reports), we process your email address and the content of your message in order to answer your request. The legal basis is Art. 6(1)(b) GDPR (requests in connection with the use of the app) or Art. 6(1)(f) GDPR (legitimate interest in answering requests). The data is deleted as soon as your request has been fully processed and no statutory retention obligations require otherwise.

11. Your rights

You have the following rights vis-à-vis the controller with regard to your personal data:

  • Right of access – Art. 15 GDPR
  • Right to rectification – Art. 16 GDPR
  • Right to erasure – Art. 17 GDPR
  • Right to restriction of processing – Art. 18 GDPR
  • Right to data portability – Art. 20 GDPR
  • Right to object – to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Right to lodge a complaint – with a data protection supervisory authority (Art. 77 GDPR)

Notes on exercising your rights

Since the app does not transmit any personal data to the controller, the controller generally holds no data about you. You can reset locally stored data yourself in the app at any time or delete it completely by uninstalling the app. For data that Google processes in connection with Google Play, please contact Google or use the settings of your Google account. No automated decision-making, including profiling, takes place.

12. Changes to this privacy policy

We will update this privacy policy if the app or the legal requirements change. The current version is available at https://modseven.net/en/datenschutz#mathshooter and is linked in the app’s Google Play listing. The date of the last update can be found above under “Last updated”.

Cookies

With your consent we use Google Analytics to improve the website. Without consent, only functional cookies are set.