Privacy Policy
Important notice on language: This Privacy Policy was originally drafted in German. The English version below is a courtesy translation. In the event of any discrepancy between the German and English versions, the German version shall prevail. The original German version is available at index.html.
Summary: Beemaster stores all data locally on your device. Personal data is encrypted. No advertising or marketing data is collected. Your beehive data stays with you.
1. Controller (Art. 4 No. 7 GDPR)
The controller responsible for data processing within the meaning of the GDPR is:
- Name: Jens Kübler
- Address: Max-Beckmann-Straße 39, 76227 Karlsruhe, Germany
- Email: support@dolphincrusher.com
A data protection officer has not been appointed (none required by law).
1a. Legal Bases for Processing
Where we process personal data, processing is based on the following legal bases:
- Art. 6 (1) lit. a GDPR – consent (e.g. optional beekeeper profile, location access, voice notes, Firebase Analytics)
- Art. 6 (1) lit. b GDPR – performance of a contract (provision of App functions, premium purchases)
- Art. 6 (1) lit. c GDPR – legal obligation (e.g. retention duties under commercial / tax law)
- Art. 6 (1) lit. f GDPR – legitimate interest (e.g. stability, security, Crashlytics for bug fixing)
2. What Data Is Collected?
📱 Required App data
Data required for the basic functions of the App:
| Type of data | Purpose | Storage |
|---|---|---|
| Beehive data | Management of your apiary | Locally on device |
| Inspection notes | Documentation | Locally on device |
| GPS locations | Map view of beehives | Locally on device |
| Reminders | Notifications | Locally on device |
👤 Optional personal data
You may optionally provide for your beekeeper profile:
- Name / apiary name
- Email address
- Phone number
- Address / location
✓ Encryption: Personal data is stored encrypted using the Android Keystore.
📸 Media
- Photos: Beehive images (optional, stored locally)
- Voice notes: Audio recordings (optional, stored locally)
📊 Automatically collected data
| Type of data | Purpose | Shared with third parties? |
|---|---|---|
| Crash logs | Improve App stability | Firebase Crashlytics |
| Usage statistics | App improvement | Firebase Analytics |
| Device ID | Error diagnosis | Firebase |
⚠️ Firebase data protection: Crash logs and anonymous usage data are transmitted to Google Firebase. More information: firebase.google.com/support/privacy
3. Data NOT Collected
Beemaster does not collect:
- ❌ No advertising ID
- ❌ No marketing data
- ❌ No contacts without consent
- ❌ No SMS or calls
- ❌ No browser history
- ❌ No health data
- ❌ No financial data
- ❌ No social media profiles
4. Permissions
| Permission | Use |
|---|---|
| Location (GPS) | Display beehives on map |
| Camera | Photos of beehives |
| Microphone | Voice notes |
| Notifications | Reminders for beekeeping tasks |
| Storage | Map data (OSMDroid) |
5. Data Storage
Locally on your device
- Room database: All beehive data
- DataStore: App settings
- Android Keystore: Encrypted sensitive data
No cloud (basic version)
✓ Your data stays with you: In the free version, no data is stored on servers. All data remains locally on your device.
6. Third-Party Providers
Firebase (Google)
- Crashlytics: Automatic error reports
- Analytics: Anonymous usage statistics
- Privacy: firebase.google.com/support/privacy
OpenAI API (optional)
- Purpose: AI-based beekeeping assistance (premium)
- Active: Only on explicit use
- Privacy: openai.com/privacy
7. Your Rights (GDPR)
You have the right to:
- Access (Art. 15 GDPR): What data is stored about you
- Rectification (Art. 16 GDPR): Correction of incorrect data
- Erasure (Art. 17 GDPR): Complete deletion of all data
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): Export in a structured, machine-readable format
- Objection (Art. 21 GDPR): Against processing based on legitimate interests
- Withdrawal of consent (Art. 7 (3) GDPR): With effect for the future
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular the authority of your habitual residence. The supervisory authority responsible for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg)
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Email: poststelle@lfdi.bwl.de
Web: www.baden-wuerttemberg.datenschutz.de
8. Protection of Children and Minors
This App is not intended for children under 13 years of age. No targeted data is collected from children.
9. Data Security
- ✅ Encrypted data transmission (HTTPS/TLS)
- ✅ Encrypted storage (Android Keystore)
- ✅ No cloud storage (local data)
- ✅ Regular security updates
10. Google OAuth Authentication
This App uses Google OAuth 2.0 for user authentication. When signing in with Google, the following data is processed:
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Google Account Email | Account creation and authentication | Art. 6 (1) lit. a GDPR (Consent) |
| Google Profile Name | User display in the App | Art. 6 (1) lit. a GDPR (Consent) |
| Google Profile Picture (optional) | User display in the App | Art. 6 (1) lit. a GDPR (Consent) |
| Google User ID | Unique user identification | Art. 6 (1) lit. a GDPR (Consent) |
📊 Google OAuth Scopes Requested
The App requests the following permissions from Google:
https://www.googleapis.com/auth/userinfo.email– Access to your Google Account email addresshttps://www.googleapis.com/auth/userinfo.profile– Access to your Google Profile (name, picture)openid– OpenID Connect for secure authentication
✓ Minimal Permissions: We request only the absolutely necessary Google permissions. No read access to Gmail, Google Drive, or other Google services.
🔄 Data Transfer to Supabase
For storing authentication data, Supabase (Supabase Inc., 548 Market St, San Francisco, CA 94104, USA) is used as a data processor:
- Purpose: JWT token management and user authentication
- Legal Basis: Art. 6 (1) lit. b GDPR (Contract performance)
- Safeguards: EU Standard Contractual Clauses (Art. 46 GDPR)
- Privacy Policy: supabase.com/privacy
💾 Storage and Deletion
- Storage Period: Until account deletion or App uninstallation
- Deletion: Automatically upon logout or manual account deletion in the App
- Withdrawal: You can withdraw consent at any time by:
- Logging out in the App (Settings → Account → Logout)
- Revoking Google permission at myaccount.google.com/permissions
🇺🇸 Third Country Transfer
Google is a US company. Data transfer to the US is based on an adequacy decision by the EU Commission (EU-US Data Privacy Framework, July 2023).
- Google Privacy Policy: policies.google.com/privacy
- Google Terms: policies.google.com/terms
11. Changes
This Privacy Policy may be updated. You will be notified of material changes within the App.
12. Changelog
| Version | Date | Change | Re-Consent Required? |
|---|---|---|---|
| 2.0 | 2026-08-18 | Added Google OAuth Authentication, added OAuth-specific data processing | ✅ Yes (new data processing) |
| 1.0 | 2026-05-05 | Initial version | - |
13. Language
This Privacy Policy was drafted in German. The English version is a courtesy translation. In the event of any discrepancy between the German and English versions, the German version shall prevail.
Contact for questions
For questions about data protection or to exercise your rights:
- 📧 Email: support@dolphincrusher.com
- 📮 Address: Jens Kübler, Max-Beckmann-Straße 39, 76227 Karlsruhe, Germany