1. Controller (data controller)
The party responsible under the General Data Protection Regulation (GDPR) is:
Yannic Labonte
Webergasse 3
40668 Meerbusch
Germany
Email: yannic.labonte@gmail.com
Further details are in the Imprint.
2. Principle
PoolPilot is a native app that talks directly to your pool controller (ProCon.IP or VIOLET) on your own network. There is no account with us, no cloud, no advertising and no analytics/tracking services; optional crash reporting (off by default) is described in section 3. We process as little data as possible.
3. Data inside the app
Controller connection details
To let the app talk to your controller, you enter its address (host/IP) plus a username and password. These credentials are stored only locally on your device — in the system Keychain on iOS, in encrypted, Android-Keystore-backed app storage (EncryptedSharedPreferences) on Android. They leave your device only to send requests to that specific controller. We never receive them.
Readings and settings
Readings and status values are fetched from your controller and shown on the device, or cached for the widgets and the watch view. This data likewise stays on the device / within the app's storage.
Crash reporting (optional, off by default)
The app contains no analytics, tracking or advertising SDKs. It does include
optional crash reporting, which is off by default — it runs only
after you switch it on under Settings → Crash reporting, and you can switch it off
again at any time. When enabled, technical diagnostics about a crash or error (e.g. the type of
error, a stack trace, the app version, the device model and OS version) are sent to
Sentry (Functional Software, Inc.), which processes them on our behalf to help us
find and fix bugs. Reports are scrubbed of credentials before they leave the device
— your controller password and the Authorization header are never transmitted — and
contain no pool readings. The legal basis is your consent (Art. 6(1)(a) GDPR); withdrawing it
(switching the setting off) stops any further reporting. A data processing agreement under
Art. 28 GDPR is in place with Sentry, and the data is stored in the EU (see sections 7
and 8).
4. Purchases and subscriptions
Write features are part of PoolPilot Pro. Purchases and subscriptions are handled by the Apple App Store or Google Play; payment goes through your account there. We receive no payment data (e.g. card numbers).
To manage entitlements (“Pro” active/inactive) we use RevenueCat (RevenueCat, Inc., USA). On our behalf, RevenueCat processes a pseudonymous app user identifier and store purchase/receipt information to verify subscription status. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement under Art. 28 GDPR is in place with RevenueCat.
5. This website
Hosting (GitHub Pages)
This website is served via GitHub Pages (GitHub, Inc., a Microsoft company). When you access it, technically necessary access data — such as your IP address, date/time, the file requested and your browser — is processed by the host to deliver the site and keep it running securely. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation).
No cookies, no analytics
The website sets no cookies, uses no analytics tools, and embeds no third-party resources (e.g. third-party web fonts). Fonts are bundled locally. That is why there is no cookie banner.
6. Support
For support you can open a GitHub issue. Its contents and your GitHub profile are public there and processed by GitHub; using it is voluntary. Alternatively you can reach us by email — we then process the data you provide solely to handle your request (Art. 6(1)(b) and (f) GDPR).
7. Recipients and transfers to third countries
Depending on use, data may be transferred to Apple, Google, RevenueCat, Sentry and GitHub/Microsoft. Apart from Sentry, these providers may process data in the USA. The transfer to RevenueCat is covered by a data processing agreement incorporating the EU Standard Contractual Clauses (SCCs); transfers to Apple, Google and GitHub/Microsoft rely on the SCCs and/or those providers' certification under the EU-US Data Privacy Framework. Crash reports — only if you enable crash reporting — are stored by Sentry in the EU (EU data residency), which keeps the data within the EU; should any transfer to a third country nonetheless occur, it is covered by a data processing agreement under Art. 28 GDPR including the SCCs as a safeguard.
8. Retention
App and connection data stay on your device until you delete them or uninstall the app. Crash reports — only if you enable crash reporting — are retained by Sentry for a limited period (by default around 90 days) and then deleted automatically. Hosting logs are kept by the host only for as long as needed for security. Support correspondence is kept as long as needed to handle it.
9. Requesting data deletion
Data on your device
Connection profiles, credentials and cached readings live solely on your device. You delete them yourself by removing the relevant profile in the app or uninstalling the app – that removes this data entirely. No request to us is needed.
Data held by RevenueCat
The only data stored server-side on our behalf is the pseudonymous app-user identifier and store purchase/receipt information held by RevenueCat (see section 4). On request we have the corresponding record deleted there. Email yannic.labonte@gmail.com.
So we can locate and delete your record without follow-up questions, please include:
- Platform: Android (Google Play) or iOS (App Store)
-
The order or transaction ID of your purchase – on Google Play the Order ID in the format
GPA.XXXX-XXXX-XXXX-XXXXX(from your purchase history or the Google order confirmation), on Apple the transaction ID from your Apple receipt (email) - The email of the store account (Google or Apple ID) used for the purchase
- The approximate purchase date and the product (monthly or yearly plan)
Note: statutory retention obligations (e.g. for tax-relevant records) may exempt some data from immediate deletion.
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21). You can withdraw any consent at any time with effect for the future.
11. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or of the alleged infringement.
12. Changes
We update this policy when the app, the services used, or the legal situation change. The version published on poolpilot.eu applies.