Last updated: 3 October 2026
The following information provides an overview of what happens to your personal data when you visit this website or use the app. Personal data is any information that can be used to identify you personally.
Max Anton Schneider
c/o MDC Management#1582
Welserstraße 3
87463 Dietmannsried
Email: info@maxantonschneider.com
This website and the app are provided through the hosting platform Vercel (provider: Vercel Inc., USA). When you access the service, technical data such as your IP address, browser type, operating system, referrer URL and time of access is automatically processed in server log files where necessary to operate and secure the infrastructure. The legal basis is Article 6(1)(f) GDPR (legitimate interest in technically reliable provision of the website and app).
A data processing agreement under Article 28 GDPR is in place with Vercel where required. For transfers to the USA, Vercel relies among other things on EU Standard Contractual Clauses. More information: vercel.com/legal/privacy-policy
The user database is operated by Supabase, Inc. (970 Toa Payoh North, Singapore). Data is stored exclusively in the EU region Frankfurt (AWS eu-central-1). Supabase processes personal data only on our behalf. A data processing agreement under Article 28 GDPR is in place with Supabase. More information: supabase.com/privacy
We use Better Auth, an open-source authentication system, for signing in and operating the app. It sets cookies that are technically necessary for secure login and to maintain your session. The app cannot be used without these cookies.
| Cookie | Purpose / duration |
|---|---|
better-auth.session_token | Session management after login — session |
better-auth.csrf_token | Protection against CSRF attacks — session |
meinsystem_cookie_consent | Stores your cookie-banner selection — up to 182 days |
The legal basis is Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in application security).
We also use a cookie consent banner to store your choice concerning usage statistics. This choice is stored only in your browser and is not linked to your user account. For signed-in users, we additionally synchronise analytics consent with the account so that server-side statistics events are processed only after consent has been given. You can change your selection at any time through “Cookie settings” in the footer.
The legal basis for storing the cookie choice is Article 6(1)(f) GDPR (legitimate interest in privacy-compliant documentation of your choice) and Section 25(2) TDDDG where storage is technically necessary.
If you enable the “Statistics & product improvement” category in the cookie banner, PostHog sets cookies or stores comparable identifiers in local storage. They are set only after consent.
| Cookie | Purpose / duration |
|---|---|
ph_phc_* | PostHog session and user identifier — up to 30 days |
ph_posthog | PostHog client configuration — up to 30 days |
The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. See Section 5 for details.
PostHog: We use PostHog (provider: PostHog Inc., EU Cloud with servers in Frankfurt, EU) to measure reach, compile usage statistics, analyse errors and improve the product. Processing occurs only if you actively accept the “Statistics & product improvement” category in the cookie banner.
Data processed may include page views and navigation paths, device and browser information, referrer, timestamps, technical error reports and, after login, your internal user ID for assigning sessions. We also record custom usage events such as registration, onboarding completion, checkout steps, use of features (routines, appointments, goals, todos) and subscription-status changes. The intended analytics events do not transmit free text from routines, notes or goals. However, saving a check-in sends its energy level and flags indicating whether mood and a note are present. After login, onboarding details such as neurodivergence and greatest support need may also be linked to your internal user ID. These details are used for usage analysis and product improvement and may relate to health.
Without analytics consent, the described personal analytics events are not collected. These are separate from technical operational metrics without a user identifier. More information: posthog.com/privacy. A data processing agreement under Article 28 GDPR is in place with PostHog.
The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG for cookies/local storage. You may withdraw consent at any time with future effect through “Cookie settings” in the footer.
You can sign in with your Google account (OAuth 2.0). If you use this option, you are redirected to Google. After you consent, Google sends us the following data:
Alternatively, you can use Sign in with Apple. Apple sends us an app-specific identifier and, if you choose to share them, your name and email address. You may use Apple's private relay address instead of your real email address. The data is used to provide and manage your user account; an existing account is linked only when the provider supplies a verified matching email address.
This data is used solely to create and manage your user account. The legal basis is Article 6(1)(a) GDPR (your consent during login) and Article 6(1)(b) GDPR (performance of a contract).
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google privacy policy: policies.google.com/privacy. For Sign in with Apple: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple's notice: apple.com/legal/privacy
In the iOS app, Sign in with Apple is provided through the native system feature (expo-apple-authentication); the same data categories and legal bases apply as for the web login.
Pro-plan users can connect Google Calendar or Outlook.com to meinsystem.app. After your express consent, the following data is retrieved from the selected provider and stored in our database:
These tokens are transmitted securely using TLS and serve solely to write meinsystem.app appointments to your selected calendar or retrieve appointments from it. They are not used for other purposes or disclosed to third parties.
You can revoke the connection at any time in app settings. All stored tokens are then deleted immediately. The legal basis is Article 6(1)(a) GDPR (consent). Retention: until the connection is revoked or the account is deleted.
You can also let the mobile app write selected appointments and routines to a writable system calendar of your choice, including a shared iCloud calendar. This access happens locally through the operating-system interface: meinsystem.app does not receive iCloud credentials and does not use CalDAV. Only entries you enable are transferred; routine steps and linked lists are excluded. You can revoke calendar access at any time in system settings. The IANA time zone saved in your account is used to display appointments, routines and reminders correctly and to export them to external calendars.
If you enable push notifications, the app stores technical access data from your browser on our servers that is required to deliver notifications:
This data is used solely to deliver notifications you configure in the app, such as appointment reminders. It is not used for advertising or disclosed to third parties.
You can disable push notifications at any time in browser or app settings. Stored access data is then deleted. The legal basis is Article 6(1)(a) GDPR (consent). Retention: until deactivation or account deletion.
In the iOS and Android app, push notifications are delivered differently from the browser: instead of the web-push access data described above, a device- and app-specific push token is generated and delivered via the Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM). Here too, only technical delivery data (push token, timestamp, notification content) is processed, no further personal data. The legal basis, purpose limitation and retention correspond to the web-push details above.
Content you create in meinsystem.app—routines, calendar appointments, tasks, goals, notes and similar data—is stored in a PostgreSQL database at Supabase (Frankfurt data centre, EU) so you can access it from different devices. Content data, especially routines, notes, todo and goal titles, appointment names and daily progress, is encrypted at application level with AES-256-GCM before storage. Transmission between your device and the app is additionally encrypted with TLS.
The application processes and decrypts content on the server where required to provide features you use. This is therefore not end-to-end encryption. During normal operation, we do not manually access your personal entries. Their content is not analysed for advertising. After consent in the cookie banner, we may analyse usage behaviour, such as which features are used, in pseudonymised form for statistics and product improvement. This also includes the energy and onboarding details described in Section 5; free text is not an intended part of these analytics events. Information you voluntarily send in a support request is used only to handle it.
Your personal entries are not sold, used for advertising or shared with other users. The consent-dependent analytics details and their association with a user ID described in Section 5 are separate. The legal basis is Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(a) GDPR (consent; see Section 10).
You can delete your account and associated app data through Settings. Associated entries are removed from the active app database. Backups, records subject to statutory retention and data held by connected providers are subject to the limits described in Sections 12 and 13. Delete previously exported calendar copies with the calendar provider.
In the iOS and Android app, additional data is stored locally on your device. Your login access token is stored encrypted in the device's native secure storage (Keychain on iOS, Keystore on Android) via expo-secure-store, so you stay signed in without your credentials being accessible to other apps on the device.
The app also keeps a local copy of your app content (e.g. routines, appointments, todos) on the device via expo-sqlite, so you can use the service even with limited internet connectivity. This local copy is synchronised with our database once a connection is available again and remains exclusively on your device. Both storage locations are deleted on logout or when the app is uninstalled.
The legal basis is Article 6(1)(b) GDPR (performance of a contract, required to provide offline functionality and the signed-in state).
meinsystem.app allows you to record daily energy and mood values and optional free-text notes. This data may permit conclusions about health and is therefore a special category of personal data under Article 9 GDPR.
The following data is stored:
Processing is based exclusively on your express consent under Article 9(2)(a) GDPR. This consent is actively requested when the dashboard is first opened and stored with a timestamp in our database. You can withdraw consent at any time by deleting your account through Settings → Delete account. Associated entries are removed from the active app database; retention and provider limits are explained in Sections 12 and 13.
The entries support personal reflection in the app. With analytics consent, energy levels and flags indicating whether mood and a note are present are also sent to PostHog for product analytics (Section 5). The free-text note is not an intended part of these events. Retention and deletion limits: Sections 12 and 13.
During onboarding and after Privacy Policy updates, we obtain two separate consents: (1) general data processing and (2) express consent for energy and mood data under Article 9 GDPR. The accepted Privacy Policy version, for example “2026-04”, is stored with a timestamp in your account.
Consent is logged with date and time. The dashboard cannot be used without consent, because otherwise core data storage would have no legal basis.
Withdrawal: You may withdraw consent at any time without giving a reason by deleting your account under Settings → Delete account. Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR).
Legal bases: Article 6(1)(a) GDPR (general consent) and Article 9(2)(a) GDPR (consent for health data).
We store personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations:
| Data category | Retention period |
|---|---|
| User account & app data | Until account deletion |
| Energy & mood data (Article 9 GDPR) | Until account deletion / withdrawal of consent |
| Session tokens | Automatically deleted after expiry |
| Email confirmation & reset tokens | Automatically deleted after expiry |
| Google Calendar OAuth tokens | Until revocation or account deletion (stored encrypted) |
| Microsoft Calendar OAuth tokens and selected event metadata | Until revocation or account deletion (tokens encrypted; cache deleted on disconnect) |
| OAuth login tokens (Better Auth) | Until logout or account deletion (stored encrypted) |
| Daily-progress history | Automatically deleted after 365 days |
| Push-notification data | Until deactivation or account deletion |
| Server logs (Vercel) | Under Vercel's policy (typically for a limited period) |
| PostHog Analytics | 30 days (PostHog project setting); no new events after withdrawal |
| Payment data (Lemon Squeezy) | Statutory retention depends on the type of data; see Section 13 for providers |
| Database backups (Supabase) | No more than 30 days after creation |
| Subscription status (RevenueCat, mobile app only) | Until account deletion |
| Local access tokens (Secure Store, mobile app only) | Until logout, app uninstall or account deletion |
We use Lemon Squeezy (Lemon Squeezy LLC, 222 South Main Street Suite 500, Salt Lake City, UT 84101, USA) to process Pro-plan payments. The following data is transmitted to Lemon Squeezy:
The legal basis is Article 6(1)(b) GDPR. Lemon Squeezy uses EU Standard Contractual Clauses for transfers to the USA. Retention depends on the type of data and the responsible entity. Section 147 AO and Section 257 HGB distinguish, for example, accounting vouchers (generally 8 years) from other records. Processing by the payment provider is also subject to its privacy notice; we do not promise automatic anonymisation of all payment data.
Lemon Squeezy privacy policy: lemonsqueezy.com/privacy
If you purchase the Pro plan through the iOS or Android app, payment is processed not by Lemon Squeezy but through the in-app purchase of Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) or Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Apple or Google independently process your payment data and purchase history; we generally receive only a purchase token or purchase confirmation, not credit card or bank details.
To reconcile subscription status between the App Store or Google Play and your user account, we additionally use RevenueCat (RevenueCat, Inc., 2261 Market Street #4408, San Francisco, CA 94114, USA). The following data is transmitted to RevenueCat: a pseudonymous app user ID, purchase/subscription status (active, cancelled, expired), product and pricing information, and technical purchase tokens from Apple/Google. RevenueCat does not process your real name, email address or payment instrument data.
The legal basis is Article 6(1)(b) GDPR (performance of a contract). RevenueCat uses EU Standard Contractual Clauses for transfers to the USA. Retention: until account deletion or as required by the applicable statutory retention for the relevant type of data. Data held by the provider is also subject to its privacy notice. More information: revenuecat.com/privacy. A data processing agreement under Article 28 GDPR is in place with RevenueCat.
This website uses SSL or TLS encryption for security. You can recognise an encrypted connection by https:// in the address bar and the lock symbol in your browser.
You have the following rights concerning your personal data:
You can download your stored data at any time as a JSON file under “Export my data” in app settings (Article 20 GDPR).
You also have the right to lodge a complaint with the competent data protection supervisory authority.
For questions about data protection, please contact: info@maxantonschneider.com