QUITTImpulse-purchase brakeEN · DE

Privacy Policy

1. Overview

This privacy policy explains which personal data is processed when using the website quitt.info and the Quitt app.

Summary:

  • The app does not process any personal data on the provider's servers. There is no user account, no remote profile, and no transmission of usage data.
  • All data created in the app remains locally on your device.
  • Optionally, and only after explicit activation, the app's locally stored data can be included in your operating system's backup on iOS.
  • The website contains no cookies, no tracking, no advertising, and no content loaded from third-party servers. Only technically unavoidable access data at the hosting provider is generated.

Part A describes the website, Part B the app. Part C applies to both.

2. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Martin Bens
Carl-Schüller-Str. 31 1/2
95444 Bayreuth
Germany

Email: spigandromeda+quitt@gmail.com

No data protection officer has been appointed, as the statutory requirements for doing so are not met.

Part A — Website quitt.info

A.1 Hosting and server log files

The website is provided as a static website via GitHub Pages. The provider is:

GitHub, Inc.
88 Colin P. Kelly Jr. Street
San Francisco, CA 94107
USA

When you access the website, your browser transmits technically necessary data to GitHub's servers, where it is recorded in server log files. This includes:

  • IP address of the requesting device
  • Date and time of the request
  • Name and URL of the file accessed
  • Amount of data transferred and HTTP status code
  • Referrer URL (previously visited page)
  • Information about browser and operating system

This processing is technically required to deliver the website and also serves operational security and stability. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in providing the website reliably and securely without having to operate our own server infrastructure.

The provider of this website has no access to these log files and does not evaluate them. They are not combined with any other data. For information on how long GitHub retains log files, see GitHub's privacy statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement

Transfer to the USA

Server locations include the USA. This means a transfer to a third country takes place. GitHub, Inc. maintains its own certification under the EU-US Data Privacy Framework (DPF). The EU Commission has determined an adequate level of data protection for companies certified under the DPF. GitHub's listing can be found at https://www.dataprivacyframework.gov/participant/6174

No data processing agreement

No data processing agreement exists with GitHub. The Bayerisches Landesamt für Datenschutzaufsicht (Bavarian State Office for Data Protection Supervision) takes the view that hosting purely static websites used for self-presentation, where no personal data flows to the operator and no tracking takes place, does not constitute processing on behalf of a controller. Rather, the short-term storage of IP addresses is attributable to the hosting provider's facilitation of access and serves its own security purposes.

Source: https://www.lda.bayern.de/media/veroeffentlichungen/FAQ_Hosting_keine_Auftragsverarbeitung.pdf

These conditions are met here: the website is static, no tracking takes place, and no personal data is transmitted to the provider of this website.

A.2 No cookies, no tracking, no external content

This website does not use cookies and does not employ comparable techniques to store information on your device within the meaning of Section 25 of the German TDDDG (Telecommunications Digital Services Data Protection Act). Consent is therefore not required, and no cookie banner is used.

No audience measurement, web analytics, or profiling takes place.

All content on the website — including fonts, images, stylesheets, and videos — is delivered by the website itself. No content is loaded from third-party servers. In particular, no content delivery networks, no embedded videos from video platforms, no map services, and no social media plugins are used.

A.3 Transport encryption

The website is delivered exclusively over a TLS-encrypted connection, recognizable by the https:// prefix in the browser's address bar.

A.4 Contact by email

The website does not contain a contact form. If you contact me by email, I process the data you provide — in particular your email address and the content of your message — solely to handle your inquiry.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries); insofar as your inquiry is directed at concluding a contract, additionally Art. 6(1)(b) GDPR.

The email address given is operated through the Gmail service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the content and metadata of incoming emails as part of providing the service; a transfer to Google LLC in the USA cannot be ruled out. Further information: https://policies.google.com/privacy

Your inquiries are deleted as soon as they are no longer required, but at the latest once the underlying matter has been conclusively resolved and no statutory retention obligations stand in the way.

Part B — Quitt App

B.1 Principle: no data collection by the provider

The app does not process any personal data on the provider's servers. In particular:

  • There is no user account and no registration.
  • No server-side or remote profile exists.
  • The app does not transmit usage, diagnostic, or crash data to the provider.
  • No third-party advertising, analytics, or tracking SDKs are integrated.
  • No data is sold, rented, or passed on to third parties.

The provider never has access to the content you record in the app.

B.2 Data stored locally on your device

All data you create in the app is stored exclusively in the app's local storage area on your device. This includes in particular: your purchase checks (product name, price/cost and usage information, and your answers to the six questions), the results calculated from them (score, verdict, and cost calculation), parked purchases with a follow-up date, status, and optional information about your state at the time of the check, the archive of completed checks with timestamps and receipt number, and your local profile (income information, weekly working hours, standing states, and settings).

This data does not leave your device unless you yourself activate the backup function described in B.3, or export your data as a file using the export function in Settings. An exported file is entirely in your hands; what happens to it is your decision.

Because the provider has no access to this data, it is not, to that extent, subject to the provider's responsibility within the meaning of the GDPR. You can delete it yourself at any time by removing individual entries in the app's archive or by deleting the app from your device. Uninstalling the app causes the operating system to delete the local data.

B.3 Optional inclusion in the device backup (iOS)

On iOS, the app offers the option of including the app's locally stored data — all data listed in B.2 — in your operating system's backup. This function is disabled by default and only takes effect after you explicitly activate it (opt-in). On Android, the app's data is permanently excluded from the device backup; inclusion is not provided there.

If you activate the function on iOS, the affected data becomes part of the device backup created by the operating system. Depending on your device and system settings, this backup may be stored locally on a computer or in iCloud Backup. The iCloud service is operated by Apple Inc. or Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.

The app's provider has no access to these backups and is not involved in their creation, storage, or management. Whether, when, and where a backup is created is determined solely by you through your operating system and platform account settings. The respective platform operator is responsible for processing carried out as part of the backup service.

Activation is based on your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time with future effect in the app's settings. Backups already created remain unaffected and must be managed through your device's system settings.

Further information from Apple: https://www.apple.com/legal/privacy/

B.4 Access to device functions and permissions

The app requests a single permission: notifications. It is optional and serves solely to remind you of parked purchases once their cooling-off period has expired. If you decline the permission, the reminder is not sent; parking itself continues to work.

Beyond this, the app does not request permissions to access the camera, microphone, location, contacts, calendar, photos, or other protected device functions.

B.5 Obtaining the app through the App Store and Google Play

The app is distributed via the Apple App Store and Google Play. When you download the app, the respective platform operator processes personal data, such as your account identifier, email address, device identifier, and the time of download.

The app's provider has no influence over this processing. Responsibility for it lies exclusively with the respective platform operator:

  • Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland — https://www.apple.com/legal/privacy/data/en/app-store/
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — https://policies.google.com/privacy

The platform operators provide the provider with aggregated, non-personal statistics, such as the number of downloads and regions of origin. It is not possible to draw conclusions about individual persons from this.

B.6 Availability of this policy

This privacy policy is linked in the respective store listing before download and can be accessed within the app at any time via Settings → Legal → Privacy.

Part C — General Information

C.1 Your rights

You have the following rights against the controller, provided the statutory requirements are met:

  • Access (Art. 15 GDPR) to the data processed about you
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR on grounds arising from your particular situation (Art. 21 GDPR)
  • Withdrawal of consent with future effect (Art. 7(3) GDPR); the lawfulness of processing carried out prior to withdrawal remains unaffected

To exercise these rights, an informal message to the email address given under section 2 is sufficient.

Please note: for data stored exclusively locally on your device, the provider is factually unable to fulfill these rights, as they have no access to it. You can view, change, and delete this data yourself directly.

C.2 Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement.

The supervisory authority responsible for the controller is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
https://www.lda.bayern.de

C.3 Retention period

Unless a specific retention period is stated in this policy, personal data is deleted as soon as the purpose of its processing no longer applies and no statutory retention obligations stand in the way.

C.4 No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

C.5 Changes to this privacy policy

This privacy policy will be updated if the processing described here or the legal situation changes. The version available on this page always applies.

Last updated: August 2026

This privacy policy was drafted on the basis of a text generated with the Datenschutz-Generator by eRecht24 (https://www.e-recht24.de) and adapted in substance for this offering.

This English version is a courtesy translation. The German version at quitt.info/datenschutz is authoritative.

spigandromeda+quitt@gmail.comGitHubPrivacyLegal NoticeEN · DE
Type: Archivo & IBM Plex MonoA free-time project. No newsletter, promised.