Privacy Policy for the App "INRlog"
1. Controller
The party responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Matthias KurteBrucher Str. 52
32545 Bad Oeynhausen
Germany
Email: support@inrlog.de
2. Definitions
Modelled on Art. 4 GDPR, this privacy policy is based on the following definitions:
- "Personal data" (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person ("data subject"). A person is identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data, or to information concerning their physical, physiological, genetic, mental, economic, cultural, or social identity. Identifiability may also arise from linking such information with other information or additional knowledge. The manner in which the information came about, its form, or its embodiment is irrelevant (photos, video, or audio recordings may also contain personal data).
- "Processing" (Art. 4 No. 2 GDPR) means any operation which involves handling personal data, whether or not by automated (i.e. technology-supported) means. This includes in particular the collection (i.e. acquisition), recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, or destruction of personal data, as well as any change to an objective or purpose originally underlying a processing operation.
- "Controller" (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- "Third party" (Art. 4 No. 10 GDPR) means any natural or legal person, public authority, agency, or body other than the data subject, the controller, the processor, and the persons who, under the direct authority of the controller or processor, are authorised to process the personal data; this also includes other legal entities belonging to the same group.
- "Processor" (Art. 4 No. 8 GDPR) means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller, in particular in accordance with its instructions (e.g. an IT service provider). In data protection terms, a processor is in particular not a third party.
- "Consent" (Art. 4 No. 11 GDPR) of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
3. Legal Bases for Data Processing
As a matter of law, in principle any processing of personal data is prohibited and only permitted where the processing falls in particular under one of the following grounds for justification:
- Art. 6(1) sentence 1(a) GDPR ("Consent"): Where the data subject has, freely, in an informed manner, and unambiguously, by a statement or other clear affirmative action, signified agreement to the processing of personal data relating to them for one or more specific purposes;
- Art. 6(1) sentence 1(b) GDPR: Where processing is necessary for the performance of a contract to which the data subject is party, or in order to take pre-contractual steps taken at the data subject's request;
- Art. 6(1) sentence 1(c) GDPR: Where processing is necessary for compliance with a legal obligation to which the controller is subject (e.g. a statutory retention obligation);
- Art. 6(1) sentence 1(d) GDPR: Where processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- Art. 6(1) sentence 1(e) GDPR: Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- Art. 6(1) sentence 1(f) GDPR ("Legitimate interests"): Where processing is necessary for the purposes of the legitimate (in particular legal or economic) interests pursued by the controller or a third party, except where the overriding interests or rights of the data subject prevail (in particular where the data subject is a minor); or
- Section 25(2) TDDDG: Where the storage of information in the end user's terminal equipment, or access to information already stored in the end user's terminal equipment, is strictly necessary in order for the provider of a digital service to provide a digital service expressly requested by the user.
4. Principles of Data Processing
The app "INRlog" processes personal and, in particular, sensitive health data — especially INR values and medication information. It was therefore developed with a strict principle of data minimisation: no data is transmitted to external servers. All data created or entered in the app is stored exclusively on the device and is neither analysed nor transmitted to external parties.
There is no tracking, no analysis of usage behaviour, and no integration of advertising networks or analytics services (e.g. Google Analytics, Firebase Analytics).
The data stored locally on the device is processed exclusively by the users themselves on their own device; the developer has no access to it. Where the developer does process personal data — for example when users make contact by email (see Section 8) — the applicable legal basis under Art. 6 GDPR is stated in the respective section.
The "About this App" section contains a link to buymeacoffee.com for users who wish to voluntarily support the developer. This link is only opened on explicit user action. Clicking it establishes a connection to an external service; the developer is not responsible for the data processing of that service. The privacy policy of Buy Me a Coffee applies.
5. Local Data Storage on the Device
INRlog stores the following data exclusively in the app's private storage on the device. It is not accessible to other apps or services under the operating system's security model and will be removed when the app is uninstalled.
The stored INR values and medication data constitute health data and therefore fall within the special categories of personal data within the meaning of Art. 9 GDPR. Since the developer has no access to this data at any time and the processing is carried out exclusively by you as the user on your own device for personal purposes, it falls under the exemption for personal and household activities under Art. 2(2)(c) GDPR. The developer is therefore not acting as a controller within the meaning of the GDPR in this regard.
In addition, the app actively excludes this data from automatic cloud backups (iOS: iCloud backup, Android: Google backup). Health data is therefore not transferred to cloud services via the operating system's device backup either.
Retention period: The data remains stored until the users delete it themselves (individual entries via swipe gesture, or completely via "Reset App") or the app is uninstalled.
5.1 Local Database (SQLite)
INR measurements:
- Measured INR value
- Date and time of the measurement
- Optional note (e.g. special circumstances)
Medication entries:
- Number of tablets taken
- Calculated dosage
- Date and time of intake
- Optional note
App settings:
- INR target range (minimum value, maximum value)
- Medication name (e.g. Marcumar, Warfarin)
- Dosage per tablet and unit
- Optional standard dosage (default tablet count)
- Validity period of the settings
5.2 App Preferences (SharedPreferences)
- Reminder settings (enabled status, interval, time of day)
- Selected app language
- Acceptance of the medical disclaimer
- Selected time range of the chart view (dashboard)
6. Reminders (Local Notifications)
INRlog can optionally send reminders for medication intake and INR measurements. These are exclusively locally scheduled notifications on the device. No data is transmitted to a server, and no third-party service is used.
The following device permissions are required for this purpose:
- Android: Send notifications (POST_NOTIFICATIONS), restore notifications after device restart (RECEIVE_BOOT_COMPLETED)
- iOS: Display notifications (Alert, Badge, Sound)
No further permissions are requested beyond these purposes. In particular, no access to the camera, microphone, location, or contacts is required.
7. Data Export, Backup and Restore
Users can optionally export their INR measurements and medication entries as a CSV or PDF file. The file is created locally on the device and shared via the native share sheet of the operating system. The app itself does not transmit any data automatically — any transfer to external services occurs only through the user's deliberate selection of a third-party app (e.g. email, cloud storage, messenger) in the share sheet.
Full backup (JSON format): In addition, users can create a full backup as a JSON file. This contains all entries as well as the complete settings history and the notification settings. As with the CSV/PDF export, the file is created locally and shared exclusively via the operating system's share sheet through the user's deliberate selection. The backup file contains health data in plain text and should therefore be stored and shared with corresponding care.
Restore (import): A previously created backup can be selected via the operating system's file picker and imported into the app. The data is transferred exclusively locally from the file deliberately chosen by the user into the app's storage; no transfer to external servers takes place. No access to the device's file system beyond this occurs.
8. Contact by Email
The "Contact & Feedback" feature opens the email app installed on the device with a prepared draft. The app itself does not send any data — the message is only sent by the users via their own email app.
When users make contact by email, the developer processes the submitted information (name, email address, subject, message, and the app version if included) in order to handle and answer the request. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering requests) or Art. 6(1)(b) GDPR where the request relates to the conclusion or performance of a contract.
The email correspondence is deleted as soon as it is no longer required for handling the request and no statutory retention obligations apply. Users should not include health data (e.g. specific INR values) in support requests unless it is necessary for their enquiry.
9. No Automated Decision-Making (Including Profiling)
The developer does not intend to use personal data collected from you for any automated decision-making process (including profiling).
10. Data Processing by the App Platform
When downloading and using the app, technically unavoidable data is processed by the platform operators:
- When installing from the Apple App Store, Apple Inc. is the responsible data controller.
- When installing from Google Play, Google Ireland Ltd. is the responsible data controller.
In particular, when downloading, the email address, the username, the customer number of the downloading account, the individual device identifier, and the time of the download are transmitted to the app store. The developer of the app has no influence over these processing activities. Accordingly, the developer is not responsible for this collection and processing; responsibility for it lies solely with the app store. Further information is available in the privacy notices of the respective app store providers:
11. Rights as a Data Subject
Under the GDPR, users are fundamentally entitled to the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Withdrawal of consent given pursuant to Art. 7(3) GDPR with effect for the future
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example with the supervisory authority responsible for the developer:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf, Germany
Phone: 0211/38424-0
Fax: 0211/38424-999
The following applies depending on the type of data:
- Locally stored data (INR measurements, medication entries, settings) resides exclusively on the device; the developer has no access to it. It can be deleted at any time directly in the app — individual entries via swipe gesture, or completely via the "Reset App" function in the app settings.
- Email correspondence (when making contact as described in Section 8) is processed by the developer. In this respect, the rights listed above can be exercised directly against the developer via the contact address provided in Section 1.
- Platform data (collected by Apple or Google during download and use of the app) falls under the responsibility of the respective platform provider. Formal GDPR requests should be directed to Apple or Google directly — see the links in Section 10.
For general questions about data protection in connection with this app, users may contact the developer at the address provided in Section 1.
12. Changes to This Privacy Policy
This privacy policy may be updated if the legal framework or the app's functionality changes. The current version is available at:
https://www.inrlog.de/privacy-policy.html
For questions about privacy, please contact the developer at: support@inrlog.de