Deutsche Version

Privacy Policy for the App "INRlog"

Last updated: August 14, 2026

1. Controller

The party responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

Matthias Kurte
Brucher Str. 52
32545 Bad Oeynhausen
Germany

Email: support@inrlog.de

Imprint

2. Definitions

Modelled on Art. 4 GDPR, this privacy policy is based on the following definitions:

3. Legal Bases for Data Processing

As a matter of law, in principle any processing of personal data is prohibited and only permitted where the processing falls in particular under one of the following grounds for justification:

4. Principles of Data Processing

The app "INRlog" processes personal and, in particular, sensitive health data — especially INR values and medication information. It was therefore developed with a strict principle of data minimisation: no data is transmitted to external servers. All data created or entered in the app is stored exclusively on the device and is neither analysed nor transmitted to external parties.

There is no tracking, no analysis of usage behaviour, and no integration of advertising networks or analytics services (e.g. Google Analytics, Firebase Analytics).

The data stored locally on the device is processed exclusively by the users themselves on their own device; the developer has no access to it. Where the developer does process personal data — for example when users make contact by email (see Section 8) — the applicable legal basis under Art. 6 GDPR is stated in the respective section.

The "About this App" section contains a link to buymeacoffee.com for users who wish to voluntarily support the developer. This link is only opened on explicit user action. Clicking it establishes a connection to an external service; the developer is not responsible for the data processing of that service. The privacy policy of Buy Me a Coffee applies.

5. Local Data Storage on the Device

INRlog stores the following data exclusively in the app's private storage on the device. It is not accessible to other apps or services under the operating system's security model and will be removed when the app is uninstalled.

The stored INR values and medication data constitute health data and therefore fall within the special categories of personal data within the meaning of Art. 9 GDPR. Since the developer has no access to this data at any time and the processing is carried out exclusively by you as the user on your own device for personal purposes, it falls under the exemption for personal and household activities under Art. 2(2)(c) GDPR. The developer is therefore not acting as a controller within the meaning of the GDPR in this regard.

In addition, the app actively excludes this data from automatic cloud backups (iOS: iCloud backup, Android: Google backup). Health data is therefore not transferred to cloud services via the operating system's device backup either.

Retention period: The data remains stored until the users delete it themselves (individual entries via swipe gesture, or completely via "Reset App") or the app is uninstalled.

5.1 Local Database (SQLite)

INR measurements:

Medication entries:

App settings:

5.2 App Preferences (SharedPreferences)

6. Reminders (Local Notifications)

INRlog can optionally send reminders for medication intake and INR measurements. These are exclusively locally scheduled notifications on the device. No data is transmitted to a server, and no third-party service is used.

The following device permissions are required for this purpose:

No further permissions are requested beyond these purposes. In particular, no access to the camera, microphone, location, or contacts is required.

7. Data Export, Backup and Restore

Users can optionally export their INR measurements and medication entries as a CSV or PDF file. The file is created locally on the device and shared via the native share sheet of the operating system. The app itself does not transmit any data automatically — any transfer to external services occurs only through the user's deliberate selection of a third-party app (e.g. email, cloud storage, messenger) in the share sheet.

Full backup (JSON format): In addition, users can create a full backup as a JSON file. This contains all entries as well as the complete settings history and the notification settings. As with the CSV/PDF export, the file is created locally and shared exclusively via the operating system's share sheet through the user's deliberate selection. The backup file contains health data in plain text and should therefore be stored and shared with corresponding care.

Restore (import): A previously created backup can be selected via the operating system's file picker and imported into the app. The data is transferred exclusively locally from the file deliberately chosen by the user into the app's storage; no transfer to external servers takes place. No access to the device's file system beyond this occurs.

8. Contact by Email

The "Contact & Feedback" feature opens the email app installed on the device with a prepared draft. The app itself does not send any data — the message is only sent by the users via their own email app.

When users make contact by email, the developer processes the submitted information (name, email address, subject, message, and the app version if included) in order to handle and answer the request. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering requests) or Art. 6(1)(b) GDPR where the request relates to the conclusion or performance of a contract.

The email correspondence is deleted as soon as it is no longer required for handling the request and no statutory retention obligations apply. Users should not include health data (e.g. specific INR values) in support requests unless it is necessary for their enquiry.

9. No Automated Decision-Making (Including Profiling)

The developer does not intend to use personal data collected from you for any automated decision-making process (including profiling).

10. Data Processing by the App Platform

When downloading and using the app, technically unavoidable data is processed by the platform operators:

In particular, when downloading, the email address, the username, the customer number of the downloading account, the individual device identifier, and the time of the download are transmitted to the app store. The developer of the app has no influence over these processing activities. Accordingly, the developer is not responsible for this collection and processing; responsibility for it lies solely with the app store. Further information is available in the privacy notices of the respective app store providers:

11. Rights as a Data Subject

Under the GDPR, users are fundamentally entitled to the following rights:

The following applies depending on the type of data:

For general questions about data protection in connection with this app, users may contact the developer at the address provided in Section 1.

12. Changes to This Privacy Policy

This privacy policy may be updated if the legal framework or the app's functionality changes. The current version is available at:

https://www.inrlog.de/privacy-policy.html

For questions about privacy, please contact the developer at: support@inrlog.de