LoliPopp
Privacy Policy — „LoliPopp“ App
Last updated: April 2026
This privacy policy applies exclusively to the LoliPopp mobile app (iOS and Android). A separate privacy policy applies to the website applein.blue.
1. Controller
Daniel Nimz
Am Heergarten 145
38375 Räbke
Germany
Email: daniel@applein.blue
2. Overview of data processing in the app
I process the following categories of personal data in the app:
| Category | Data | Purpose |
|---|---|---|
| Account data | Email address, password hash (not the plaintext password), nickname, avatar (optional) | Registration, login, account management, display to other members |
| Content data | Events („Pops“), groups, RSVPs, optional comments, AI-generated invitation texts | Providing the core app functions |
| AI inputs | User prompts / conversations actively submitted by the user to the AI feature | Generating AI responses |
| Push token | Expo push token (anonymous device identifier for push notifications) | Sending notifications |
| Device info | Operating system version, app version, language | Error analysis, compatibility (no tracking) |
| Error logs | Technical error messages, stack traces, timestamps | Debugging and stability |
No advertising. No analytics services. No cross-app or cross-device tracking.
Note on account data
- Email address — for login, account confirmation and system notifications.
- Password hash — stored encrypted at Supabase, never visible in plaintext.
- Nickname — self-chosen display name within the app, visible to other members of shared groups.
- Avatar — optional profile picture, uploaded and stored in Supabase Storage (EU), visible to other members of shared groups.
You can change or remove your nickname and avatar at any time in the profile tab. You can change your email address via account settings (with a confirmation mail sent to the new address).
3. Legal bases
- Art. 6 (1) (b) GDPR — performance of a contract (providing the app, account management)
- Art. 6 (1) (f) GDPR — legitimate interest (stability, error analysis, abuse prevention)
- Art. 6 (1) (a) GDPR — consent (e.g. for push notifications, revocable any time in device settings)
- Art. 46 GDPR — appropriate safeguards for third-country transfers (standard contractual clauses, see section 5)
4. Services used / processors
4.1 Supabase (Auth, database, storage)
Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 — European instance.
Server location: Frankfurt am Main, Germany (EU region eu-central-1 or comparable). Data does not leave the EU when using the core functions.
Purpose: Authentication, storage of account and content data, file storage.
Legal basis: Art. 6 (1) (b) GDPR. A data processing agreement under Art. 28 GDPR is in place with Supabase.
4.2 Mailjet SAS — Email delivery (EU)
Provider: Mailjet SAS, 4 rue Jules Lefebvre, 75009 Paris, France.
Server location: EU (France) — no third-country transfer.
Purpose: Delivery of transactional emails (account confirmation, password reset, login notifications).
Data transferred: Email address, mail metadata (subject, timestamp, delivery status), IP addresses of delivery servers.
Legal basis: Art. 6 (1) (b) GDPR (performance of contract — account management). A data processing agreement under Art. 28 GDPR is in place with Mailjet.
More information: https://www.mailjet.com/legal/privacy-policy/
4.3 Anthropic (Claude API) — third country USA
Provider: Anthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA.
Server location: USA (third country under GDPR).
Purpose: Processing of user inputs by the „Claude“ AI model to generate AI responses within the app.
Data transferred: Texts / prompts actively entered by the user and, where applicable, the current session’s conversation history. No email address, no account ID, no real name is transmitted unless strictly required for the function.
Legal basis: Art. 6 (1) (b) GDPR (performance of contract — the AI feature is a core part of the app) in conjunction with Art. 46 (2) (c) GDPR (EU Commission standard contractual clauses as appropriate safeguard for the third-country transfer).
Storage at Anthropic: According to Anthropic, data transferred via the API is not used to train the models. However, Anthropic retains the data for up to 30 days for abuse and safety monitoring; after that, it is deleted. Content flagged as abusive may be retained longer.
Note: You should not unnecessarily enter sensitive personal data (e.g. health data, identifiable data of third parties) into AI inputs.
More information: https://www.anthropic.com/legal/privacy
4.4 Expo Push Service — third country USA
Provider: 650 Industries, Inc. („Expo“), 1100 Alakea Street, Suite 1170, Honolulu, HI 96813, USA.
Server location: USA (third country).
Purpose: Relay of push notifications to Apple APNs (Apple Push Notification service) or Google FCM (Firebase Cloud Messaging).
Data transferred: Your device’s anonymous Expo push token and the content of the respective push notification.
Legal basis: Art. 6 (1) (a) GDPR (consent, granted via your device’s system prompt and revocable at any time), Art. 46 (2) (c) GDPR (standard contractual clauses).
Withdrawal: In your device settings under „Notifications → LoliPopp“.
More information: https://expo.dev/privacy
4.5 Apple Push Notification Service (APNs) — third country USA
Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
Server location: USA (third country).
Purpose: When push notifications are delivered to iOS devices, the anonymous push token and the notification content are routed through Apple’s APNs infrastructure. There is no technical alternative for iOS apps — every push notification on iPhone or iPad goes through Apple’s infrastructure.
Legal basis: Art. 6 (1) (a) GDPR (consent granted when push is activated in the app), Art. 46 (2) (c) GDPR (standard contractual clauses). Apple is additionally certified under the EU–U.S. Data Privacy Framework (Art. 45 GDPR).
Apple Privacy Policy: https://www.apple.com/legal/privacy/
4.6 Apple App Store / Google Play Store
When downloading and installing the app from the Apple App Store or Google Play Store, Apple or Google independently collect data (e.g. Apple ID / Google account, device information, downloads, crashes, possibly payment information). This processing is outside my control and is the responsibility of Apple and Google respectively.
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Privacy Policy: https://policies.google.com/privacy
5. Third-country transfers (USA) — legal framework
For the services described in 4.3, 4.4 and 4.5, personal data is transferred to the USA. The USA is considered a third country under the GDPR.
I base these transfers on the European Commission’s Standard Contractual Clauses (SCCs) (Implementing Decision (EU) 2021/914) pursuant to Art. 46 (2) (c) GDPR. The respective providers are contractually obliged to comply with these clauses.
Where a provider is certified under the EU–U.S. Data Privacy Framework (EU Commission adequacy decision of 10 July 2023), the transfer is additionally based on Art. 45 GDPR.
You have the right to obtain a copy of the appropriate safeguards. An informal request to daniel@applein.blue is sufficient.
Despite these safeguards, a residual risk remains that US authorities (in particular intelligence agencies) may access transferred data without equivalent legal protection to EU fundamental rights.
6. App Tracking Transparency (iOS) — no tracking
The app does not use tracking within the meaning of Apple’s „App Tracking Transparency“ framework. No cross-device or cross-app profiling takes place, no advertising identifiers are read, no data is shared with data brokers. An ATT prompt is therefore not shown.
7. App permissions
The app may request the following permissions. You can revoke each of them at any time in your device settings.
- Notifications — for push messages
8. Age restriction
LoliPopp is intended for users aged 16 and above. Persons under 16 may only use the app with the consent of their parents or legal guardians (Art. 8 GDPR).
We do not knowingly collect personal data from children under 16. If we become aware that an account belongs to a person under 16 without parental consent, we will delete it immediately. Please report such cases to daniel@applein.blue.
9. Retention periods
- Account data: as long as the account exists; after account deletion, data is removed from active systems without delay, at the latest within 30 days. Backup rotations may cause data to remain briefly in encrypted backups; these are overwritten regularly.
- Content data: as long as the account exists or until the user deletes it.
- AI inputs at Anthropic: up to 30 days (see section 4.3).
- Push token: until the app is uninstalled or notification permission is withdrawn.
- Error logs: maximum 90 days.
10. Account deletion
You can delete your account at any time:
- In the app: via „Settings → Account → Delete account“.
- By email: request to
daniel@applein.blue, stating the email address associated with the account.
Upon deletion, your account and content data are removed from the active database. Statutory retention obligations remain unaffected.
11. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21 GDPR). Consents can be withdrawn at any time with effect for the future (Art. 7 (3) GDPR).
Requests to: daniel@applein.blue.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for me:
State Commissioner for Data Protection Lower Saxony (LfD Niedersachsen)
Prinzenstraße 5
30159 Hannover, Germany
Website: https://www.lfd.niedersachsen.de
13. Changes
In the event of material changes to this privacy policy, I will inform users in advance within the app or by email to the address on file for the account.