English · Deutsche Version
KiezPilot: Privacy Policy
Effective date: 14 June 2026 · Last updated: 29 September 2026
KiezPilot ("the app", "we") helps parents in Berlin find family-relevant places and events. We built the app to be private by design: in this version we collect no name, no email address, no phone number, and no other information that directly identifies you.
This policy explains what limited data the app does process, why, and your rights under the EU General Data Protection Regulation (GDPR).
1. Who is responsible (controller)
Ramzi Merhej
Neuenburger Straße 22a
10969 Berlin, Deutschland
Email: privacy@kiezpilot.com
(See also our Impressum.)
2. What we process, why, and on what legal basis
2.1 Your KiezPilot identifier
When you first open the app, it creates a random, device-bound identifier (a UUID). In this version there is no sign-up: we never ask for or store your name, email address, phone number, or a password.
Against that identifier, our server stores exactly the following, to the extent you provide it:
- your language;
- your home Kiez and Bezirk, and whether you set them from your location or chose them yourself;
- your family setup and the birth month and birth year of each child you add (details and legal basis: §3);
- the interests you picked and your notification preferences;
- when you finished setup and acknowledged the usage notice;
- technical details about your installation: platform, app version, build and runtime version, update channel, and the id of the update you last downloaded (we need these to match a crash report to the right version of the app);
- Your device's language setting (e.g. "de-DE" or "tr-TR"), in addition to the language you choose in the app, solely to analyze which languages our users actually speak.
On top of that come your contributions and ratings (§2.4), photos you contribute (§2.13), your push subscription if you turn on severe-weather alerts (§2.9), the usage records (§2.10), and the places and events you save (favorites, §2.3).
Because the identifier is stable and that information is linked to it, we treat the identifier and that information as pseudonymous personal data under the GDPR. Authentication is handled by our processor Supabase (see §4).
Do you have to provide any of this? No. There is no statutory or contractual obligation to give us any of it, and you do not have to provide any of it in order to use the app. If you leave it out, the recommendations are simply more general. The only thing that is necessary is the identifier itself: without it we cannot provide the parts of the app that need a server.
- Legal basis: Art. 6(1)(b) GDPR for the identifier, your language, your home Kiez and Bezirk, your family setup, your interests and your notification preferences; they are necessary to provide the service you asked for (recommendations tailored to your family; for your children's details see §3, for contributions see §2.4). For when you finished setup and acknowledged the usage notice, and for the technical installation details, we instead rely on Art. 6(1)(f) GDPR (legitimate interest in managing setup, proving delivery of the usage notice, and diagnosing errors safely); checking for app updates with Expo, which uses your installation id for this, rests on Art. 6(1)(b) GDPR to provide and maintain the app in conformity with the contract.
2.2 Location
If you grant location permission, the app uses your device location while you are using the app to find places and events near you. Your coordinates are sent to our backend to return nearby results. For weather-aware suggestions and official weather warnings, the app calls the Bright Sky weather API (see §4) directly from your device; Bright Sky receives your coordinates rounded to about 1 km (two decimal places; the precise ones are never sent for this) and, unavoidably, as with any internet connection, your device's IP address. We do not store those requests. The app likewise fetches the public-holiday and school-holiday calendar directly from openholidaysapi.org (see §4); no location and no identifier is sent with it. We do not build a movement profile, do not track you in the background, and do not store your location as a history.
- Legal basis (location): Art. 6(1)(a) GDPR (your consent, given via the operating system permission). You can withdraw it any time in your device settings; the app then falls back to a default Berlin view.
- Legal basis (public-holiday and school-holiday calendar): Art. 6(1)(b) GDPR, independent of your location consent, because openholidaysapi.org is queried for Berlin as a whole and this only serves providing the calendar you requested.
2.3 Your saved places, and what stays only on your device
When you save a place or an event (favorites), we store that choice against your identifier (§2.1) so it is not lost if the app’s local data is cleared. We store only which place or event you saved and when. Nothing about why, and nothing about where you were. The app keeps its own copy on your device and reads from that, so your saved items work offline. When you delete your data (§6), the saved places are deleted too.
We store your language against your identifier on our server (§2.1) in addition to the local copy; the severe-weather settings described in §2.9 are likewise stored on our server. Purely visual display preferences with no link to your identifier stay only on your device and are removed when you uninstall the app. (When you open a place’s or an event’s detail page, that also creates a usage record on our server; see §2.10.)
- Legal basis: Art. 6(1)(b) GDPR.
2.4 Community contributions (optional)
If you choose to add or correct information about a place (e.g. "is it fenced in?", "report outdated info"), that contribution is saved against your identifier (§2.1) and may be shown to other parents as "reported by parents". Please do not include any personal information in free-text contributions. How we handle reported content, and how you can flag something, is on the Report content page.
- Legal basis: Art. 6(1)(a) GDPR, the consent you give by submitting the contribution. Withdrawal: you can withdraw it at any time by deleting your data in the app (§6) or writing to privacy@kiezpilot.com. We then delete the free text of your contribution and the link to your identifier; the lawfulness of processing before the withdrawal is unaffected. What happens to a fact that has already been checked is described in §6.
2.5 Map tiles
Maps are rendered using map images ("tiles") from OpenStreetMap. To deliver those images, the OpenStreetMap Foundation necessarily receives your device's IP address when a map loads. The OpenStreetMap Foundation decides about that processing on its own account; for this it is not our processor but its own controller. It is governed by the OpenStreetMap Foundation Privacy Policy.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing a map).
2.6 Technical/operational logs
Our backend provider Supabase processes technical data (such as IP address and request metadata) transiently for security and to operate the service. This is standard processor logging and is not used to identify or profile you. Retention: these logs are deleted automatically at Supabase after 7 days (the retention of the plan we are on); we do not export them and do not analyse them per person. Cloudflare also processes connection data in order to serve the kiezpilot.com website; see §4 and §2.11.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the service securely and reliably).
2.7 Product analytics
We use no third-party product-analytics tool. We previously trialed PostHog (EU-hosted infrastructure); capture was switched off in the app code on 26 August 2026, and the PostHog project, with whatever trial data was still in it, was deleted on 6 September 2026. What we do measure ourselves (place and event views, search metrics, and which recommendations were shown, on our own server) is set out in full in §2.10; that is not third-party analytics, but it is measurement, and we name it here so the two sections do not read as a contradiction. If we ever use a third-party analytics tool, it will only run with your explicit consent (off by default), and we will update this policy first. The app asks you this question once, when you first open it: "May we measure how the app is used?", with two equally prominent buttons, Accept and Only necessary. Nothing is pre-selected. Your answer is stored only on your device, is never sent to us, and you can change it at any time under Settings → Privacy. While no third-party tool is in use, your answer changes nothing in practice; it is the switch such a tool would have to pass. Your answer does not affect the technical logs (§2.6), the crash reports (§2.8) or the usage records (§2.10): those rest on Art. 6(1)(f), not on your consent. We do not use any advertising or cross-app-tracking technologies.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the app).
2.8 Crash reporting
If the app crashes or encounters a technical error, we use Sentry (our project sits in Sentry's European data region, in Germany) to receive a technical report so we can fix the problem. A report contains:
- the error message and the technical trail leading up to it, the app version, the device model, and the OS version;
- a random installation id that the Sentry SDK generates on your device, so that several reports from the same installation belong together. This is not your KiezPilot identifier from §2.1 (that is never sent to Sentry);
- an approximate location (country and city) that Sentry derives from your connection.
Your IP address is not stored with the report: the SDK is configured with PII sending switched off and does not pass it on. Network traces collected on the way to an error have their coordinates stripped on your device before the report is sent. We know neither your name nor your email address, so we cannot and do not pass them on.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable, safe app).
- Retention: Sentry deletes the events on our plan automatically after 30 days.
2.9 Severe-weather alerts (optional)
If you switch on severe-weather alerts (off by default; you turn them on with an explicit tap), we send you a push notification when the German Weather Service (Deutscher Wetterdienst, DWD) issues a severe-weather warning for your area. To do this we store, linked to your identifier (§2.1):
- a push notification token (a delivery address for your device, issued by Apple/Google via Expo), used only to deliver these alerts, never for tracking or analytics; and
- a coarse region code (your Ortsteil, one of Berlin's ~97 districts). This is derived on your device from your location; your precise GPS coordinates never leave your device and are not stored; only the district code is sent, and it is overwritten (no location history is kept).
- Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG (your consent). You can withdraw consent at any time in Settings → Severe-weather alerts; turning it off removes the push token and region code promptly from active systems (isolated backup copies expire within 90 days as described in §5). The lawfulness of processing before the withdrawal is unaffected.
- Retention: the push token and region code are kept until you turn the alerts off or delete your data (§6), at the outside, until the limits in §5.
- Recipients: the Expo push service (650 Industries, Inc., USA) and the push gateways of Apple and Google deliver the notification to your device; this involves a transfer to the US (§4).
2.10 Usage records (server-side)
In addition to the purely local data described in §2.3, our server stores a few usage signals, linked to your identifier (§2.1), to measure whether the app’s recommendations actually help:
- Place and event views: when you open a place’s or an event’s detail page, we store which one that was and when.
- Recommendation context: when the Home screen assembles recommendations, we store which places were shown and under what conditions (e.g. weather, day of week, indoor/outdoor). No coordinates and no ages of your children.
- Search metrics: when you search, we store the length of what you typed (as a number), the result count, and whether the search matched one of our categories. We store the search text itself in one case only: when your search returns no results, we store what you typed, not linked to your identifier (§2.1), so that we learn what parents are looking for that the app does not yet know. These texts are automatically deleted after 90 days at the latest. For searches that do return results, we still never store the search text.
These records are not shown back to you in the app (no history, no “recently viewed” list) and are not used to target you individually with advertising; they exist solely for internal product measurement (e.g. “do rainy-day recommendations actually get opened?”).
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring and improving whether our recommendations actually help).
- Retention: These records stay linked to your identifier for at most 12 months. After that we combine them into daily totals that carry no identifier and delete the individual records. If you delete your data sooner (§6), these records go with it. Deleted data is gone from our weekly backups within 90 days (§5).
2.11 Link and QR-code counts (website)
When you scan one of our QR codes or open a /go link on kiezpilot.com, we increment a counter in our own database. That counter has exactly four fields: channel, operating-system group (iOS, Android, other), Berlin calendar day, and a number. Neither your IP address, nor any identifier, nor a timestamp finer than the day is written into it, and no cookie is set.
For the redirect to work at all, our website provider Cloudflare receives, as with any page request, your IP address and your browser's identification (user agent); the redirect reads the user agent to decide whether to send you to the App Store or to Google Play, and that is where the operating-system group comes from. We do not pass the channel label, or anything else from this request, on to Apple or Google; either way you land on our plain store listing.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing which of our own channels people use to find us). Beyond reading the user agent to choose the right store, nothing is stored on or read from your device, and no cookie is set, so no consent under § 25 TDDDG is required.
- Retention: the counter rows contain no personal data and are kept indefinitely.
2.12 When you write to us
If you send us an email (hello@kiezpilot.com, privacy@kiezpilot.com) or report a piece of content (Report content), we process your message, your sender address, and whatever you tell us in it, in order to deal with your request. The email travels through Cloudflare Email Routing and arrives in a Google mailbox (Gmail); both act as our processors for this (§4).
For messages to hello@kiezpilot.com we also keep a copy in our own database at Supabase (§4, Frankfurt), so that enquiries do not sit unnoticed in a mailbox. What we keep: your sender address and display name, the subject, the text of your message, the date and time, and (as a note, not as a file) the filename, file type and size of any attachment. We do not store the attachments themselves there; they stay in the mailbox only.
- Legal basis: Art. 6(1)(b) GDPR where your request concerns your use of the app; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). For requests about your data-subject rights, additionally Art. 6(1)(c) GDPR (our legal obligation to answer you).
- Retention: the copy in our database is deleted automatically 90 days after it arrives. We keep the message in the mailbox for as long as dealing with your request, and being able to show that we dealt with it, requires, and delete it afterwards unless a statutory retention period applies.
2.13 Photos you contribute (optional)
You can contribute a photo of your own to a place or an event in the app. Before anything is uploaded, the app scales the photo down on your device and removes the metadata embedded in the image, including where it was taken. Only adults can contribute photos: with the licence grant you confirm that you are 18 or older. We do not ask for a date of birth.
Under your identifier (§2.1) we store:
- the photo, in storage that is not public, together with its checksum, its format, its size, and the place or event it belongs to;
- your licence grant and your confirmation that no person is recognisable in the photo, each with the version of the text you agreed to and the time;
- the review status (in review, accepted, rejected or withdrawn) and, if it was rejected, the reason;
- the app version, platform and app language at upload, so that we can match a fault to the right app version.
Without your name. We do not ask for your name and we do not store it. A published photo is credited "Foto: KiezPilot-Community".
Review and publication. We look at every photo before it appears. We do not publish photos in which a person is recognisable. Only after we approve a photo do we show a copy publicly: in the app and on kiezpilot.com, on the page of the place or event and in the preview that appears when someone shares that page. Under your licence grant the photo may also appear in KiezPilot's app-store listings.
Withdrawing. While your photo is still in review, you can withdraw it in the app; the app then deletes the uploaded file. To withdraw a photo that has already been published, email hello@kiezpilot.com; we then take it out of the app and off the website.
- Legal basis: Art. 6(1)(b) GDPR. We process these details to perform the agreement about your photo that you enter into with the licence grant. Unlike the facts in §2.4, this processing therefore does not rest on consent. After a withdrawal we keep the record of the grant (time, text version, checksum) with your submission until you delete your data (§6) or your identifier expires (§5). Our legitimate interest is being able to defend ourselves against claims, for example if someone disputes the grant (Art. 6(1)(f) GDPR). For an accepted photo we also keep a copy of the record that does not contain your identifier, for as long as the published photo is stored here. This too rests on that legitimate interest (Art. 6(1)(f) GDPR); as far as the copy is needed for that purpose, Art. 17(3)(e) GDPR excludes the right to have it erased. While your submission is stored, we can link this copy to your submission through the published photo. When the published photo is deleted, this copy of the record is deleted with it.
- Do you have to provide this? No. Contributing a photo is voluntary. Without the licence grant and the confirmation about people in the photo, however, we cannot accept a photo.
- Retention: your submissions stay stored under your identifier until you delete your data (§6) or your identifier expires after 24 months of non-use (§5). They are then deleted. For a photo that was accepted and published, we keep a copy of the record of the grant (the text version, the checksum and the time of the grant) for as long as the published photo is stored here; this copy does not contain your identifier and is deleted together with the published photo. A published photo then stays visible with no link to your identifier, credited "Foto: KiezPilot-Community", until you withdraw it. We keep the uploaded original file of an accepted or rejected photo in the non-public storage as the record of what was given to us, and delete it when you ask us to. There is currently no automatic deletion period for that file, including when you delete your data or your identifier expires. The same applies to the original file of a photo that was still in review when you deleted your data or your identifier expired.
2.14 Information about establishments from public sources (Art. 14 GDPR)
This section is not addressed to the people who use the app, but to people whose details we take from public sources without collecting them from those people directly.
What. KiezPilot shows parents places and activities for families, such as playgrounds, museums, courses, clubs and doctors' practices. For these establishments we store business details: name, address, phone number, website, opening hours and, where the source gives one, an email address. We also keep the entry as the source delivers it. Mostly these details concern companies or organisations. They are personal data where they concern an individual, for example a doctor's practice named after the doctor.
Where from. Publicly available sources, mainly OpenStreetMap, the Berlin open-data portal (daten.berlin.de) and the establishments' own websites. All sources are listed on the Data sources page.
Why. So that parents can find and reach an establishment. We show these details in the app, and some of them on kiezpilot.com. Where the source gives an email address we store it, but we do not currently display it.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is showing families which activities exist near them and how to reach them; the establishment itself or a public body published these details so that people can find them.
- Recipients: the details we display are publicly visible in the app and on kiezpilot.com. They are stored with our processor Supabase (§4).
- Retention: for as long as we keep the establishment in our data. We re-read the sources regularly and take over changes when we do.
- Your rights: you may object to this processing at any time under Art. 21 GDPR on grounds relating to your particular situation. Write to privacy@kiezpilot.com and name the entry. You also have the rights in §6, including the right of access and the right to lodge a complaint with a supervisory authority.
We publish this information here instead of writing to each person concerned, because notifying each person individually would involve a disproportionate effort given the number of entries (Art. 14(5)(b) GDPR).
What we do NOT do
- No advertising, no ad identifiers, no cross-app tracking (no App Tracking Transparency prompt is needed).
- No selling of personal data and no sharing for advertising. We share personal data only with the parties named in §4 and only for the purposes named there, and with public authorities where we are legally obliged to.
3. Children's data
KiezPilot is a tool for parents and caregivers and is not directed at children. Children get no identifier and no profile with us; there is nothing a child could use the app with.
What we store. For each child you add, we store exactly two things: the birth month and the birth year. Nothing else: no name, no gender, no exact date of birth, no photo, no health or childcare information. The app computes the age from month and year to filter suggestions; we do not additionally store the age.
Where it comes from. From you. You enter it as the parent or caregiver; a caregiver without parental responsibility may only do this with the legal representative's authority. We do not collect it from your child and we obtain it from no other source. This policy is at the same time the Art. 14 GDPR information for the child whose details you enter here.
What it is for. Only to filter and sort places and events by age suitability. We do not use it for advertising, we do not build a profile of your child from it, and we do not pass it to anyone who is not named in §4.
- Legal basis: Art. 6(1)(f) GDPR, the legitimate interest of your child and your household in getting age-appropriate rather than arbitrary suggestions. We deliberately do not rest this on Art. 6(1)(b): your child is not a party to your use of the app, and a contract with you cannot carry the processing of your child's data. Art. 8 GDPR (a child's consent to information-society services) does not apply here, because the service is not directed at children and no child gives consent.
- Right to object: because we rely on a legitimate interest, you may object at any time on grounds relating to your particular situation under Art. 21 GDPR. In practice, removing the child in the app or deleting your data (§6) is enough; you can also write to us.
- Recipients: only our processor Supabase, which runs the database (§4). This information is not sent to Apple, Google, Expo, Sentry, Cloudflare, or anyone else.
- Retention: the same as the rest of your profile (§5). Remove a child, or delete your data, and it is removed promptly from active systems (isolated backup copies expire within 90 days as described in §5); otherwise the 24-month limit for unused identifiers applies at the latest.
- Your child's rights: The rights belong to the child. You as the parent, or another legal representative, exercise them on the child's behalf; a child with sufficient understanding may also exercise them personally. A caregiver without parental responsibility may only enter the child's details with the legal representative's authority. You exercise the rights directly in the app (change, remove, delete) or via privacy@kiezpilot.com.
The information sits with Supabase (§4) as part of your pseudonymous profile; it is not linked to a name, an email address, or a phone number, because we hold none of those.
4. Who receives your data, in what role, and where
Processors (they process data only on our instructions, under a data-processing agreement):
- Supabase (database, authentication, storage): Supabase Pte. Ltd., Singapore. Our project is pinned to the EU region Frankfurt (Germany); under the data-processing addendum the data is stored and primarily processed there. Because the company is established outside the EEA, access from a third country (for support or operations, say) is not excluded; the EU Commission's Standard Contractual Clauses cover that. Supabase uses its own sub-processors and publishes them in a public list.
- Sentry (crash reports, §2.8): Functional Software, Inc. ("Sentry"), San Francisco, USA. Our project sits in Sentry's European data region (Germany). For transfers to the US, Sentry relies on the EU-US Data Privacy Framework and, in addition, on the Standard Contractual Clauses.
- Cloudflare (hosting and delivery of the kiezpilot.com website, and routing of email to our mailbox): Cloudflare, Inc., San Francisco, USA, with a global network. Processes visitor IP addresses, request metadata, and email metadata for the website and for receiving email, not for the app itself. Transfers rely on the EU-US Data Privacy Framework and the Standard Contractual Clauses.
- Google (the mailbox our contact addresses arrive in, §2.12): Gmail; Google Ireland Limited and Google LLC, USA. Transfers to the US rely on the EU-US Data Privacy Framework and the Standard Contractual Clauses.
- Expo (650 Industries, Inc., USA). Two things: delivery of the severe-weather push messages (only if you switch them on, §2.9) and delivery of app updates. For updates, the app asks Expo at launch whether a new version exists; Expo receives your device's IP address, the operating system, and a random token by which Expo can tell whether an update has already been downloaded. Expo is certified under the EU-US Data Privacy Framework and uses the Standard Contractual Clauses in addition.
Independent controllers (they decide about the processing themselves; we cannot instruct them, and their own privacy policies apply):
- Apple and Google: for obtaining the app from their stores and for the diagnostics built into their operating systems. For delivering a push message to your device (§2.9) their push gateways act on our behalf; the transfer to the US this involves relies on the Standard Contractual Clauses agreed between our processors.
- OpenStreetMap Foundation (map tiles, §2.5): established in the United Kingdom; the transfer relies on the EU Commission's adequacy decision for the United Kingdom.
- Bright Sky (weather data derived from Deutscher Wetterdienst open data): called directly by the app, receiving your coordinates and your IP address; hosted in Germany (Hetzner).
- openholidaysapi.org (public-holiday and school-holiday dates for Berlin): called directly by the app, receiving your device's IP address; no location and no identifier is sent.
PostHog (product analytics) used to be integrated and no longer is: the project was deleted on 6 September 2026 (§2.7). It is therefore no longer a recipient.
Transfers to third countries, said plainly. Our database and authentication run in Frankfurt, and the crash reports sit in Sentry's German region. Even so, "your data never leaves the EU" would be false: Supabase is a company established in Singapore; Sentry, Cloudflare, Expo and Google are established in the USA; and the push and update paths lead there. Each of those transfers is covered by the safeguards named above: an adequacy decision, the EU-US Data Privacy Framework, or Standard Contractual Clauses under Art. 46(2)(c) GDPR. You can obtain a copy of the relevant safeguards on request at privacy@kiezpilot.com.
5. How long we keep data
Your record and your contributions are kept until you delete them or request deletion (see §6). Beyond that, three fixed limits apply even if you never ask us:
- Usage records (§2.10): 12 months. After that we combine them into daily totals that carry no identifier and delete the individual records.
- Search texts of zero-result searches (§2.10): 90 days. These texts are not linked to your identifier; they are deleted automatically, independently of any deletion of your data.
- Unused identifiers: 24 months. If an identifier goes unused for 24 months, we automatically delete it together with the data linked to it. "Unused" means: the app has triggered no sign-in and no activity for that identifier in that time; what counts is the most recent of those moments (last activity, last sign-in, last change, or when the identifier was created).
Alongside those, the periods stated in each section apply to the individual kinds of data:
- Operational and security logs at Supabase: 7 days (§2.6).
- Crash reports at Sentry: 30 days (§2.8).
- Push token and region code: until you turn severe-weather alerts off (§2.9).
- Your messages to us: the copy in our database, 90 days; the message in the mailbox, for as long as dealing with the request and showing that we dealt with it requires (§2.12).
- Link and QR counter: indefinitely, but with no personal data in it (§2.11).
- Photos you contribute, and the uploaded original files: as described in §2.13.
- Information about establishments from public sources: as described in §2.14.
- Cloudflare and the independent controllers named in §4 (OpenStreetMap Foundation, Bright Sky, openholidaysapi.org, Apple, Google) determine the retention of the connection data arising with them themselves; we do not receive that data.
Data stored on your device remains until you uninstall the app. Reinstalling the app creates a new identifier; the old record stays on our servers at first, can no longer be attributed by us to any person, and is deleted after those same 24 months at the latest.
Backups. Once a week we take a full backup copy of the database. Those copies sit separately from the running service, are never read by the app or the website, exist solely to recover from data loss, and expire automatically after 90 days. A single row cannot be lifted out of such a copy, which is why the copy expiring is how the deletion is completed there too: within 90 days of your deletion at the latest. If we ever had to restore a backup, we re-apply every deletion made after the point that copy was taken immediately afterwards; that is a fixed step of our restore procedure.
6. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). We hold no name, email address, or phone number, so exercising some of these rights requires you to give us your identifier (§2.1) and we will tell you how to read it.
- Objection (Art. 21 GDPR): wherever we rely on a legitimate interest (usage records (§2.10), crash reports (§2.8), map tiles (§2.5), link counting (§2.11), your children's details (§3), information about establishments from public sources (§2.14), and the record of a photo grant kept after a withdrawal, as well as its copy for published photos (§2.13)), you may object at any time on grounds relating to your particular situation. An email to privacy@kiezpilot.com is enough.
- Withdrawing consent (Art. 7(3) GDPR): location (§2.2) in your device settings, severe-weather alerts (§2.9) in the app settings, contributions (§2.4) by deleting your data or writing to us. In each case the lawfulness of processing before the withdrawal is unaffected.
- To delete your data: in the app, open Settings → Account → "Delete my data" to permanently erase your identifier and everything linked to it (this cannot be undone): your profile, your children's details, usage records, ratings, your push subscription, the free text of your contributions, and your photo submissions. One exception, which we name rather than bury: if something you reported has already been checked and merged into a place's details ("has a changing table", for example), that fact stays; the link to your identifier is deleted, so it can no longer be attributed to you. For photos: a published photo stays visible with no link to your identifier; the uploaded original file stays in the non-public storage until you ask us to delete it; for a published photo, a copy of the record of the grant that does not contain your identifier is also kept for as long as the published photo is stored here (§2.13). You can also email privacy@kiezpilot.com. Uninstalling the app removes all data stored on your device.
- Questions / requests: privacy@kiezpilot.com
- You also have the right to lodge a complaint with a supervisory authority (in Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit).
7. Changes to this policy
We may update this policy; the "Last updated" date above reflects the current version. Material changes will be surfaced in the app.
8. Contact
Data protection: privacy@kiezpilot.com · everything else, and all channels: Contact · illegal content: Report content.