1. Controller (data controller)
The party responsible under the General Data Protection Regulation (GDPR) is:
Yannic Labonte
Webergasse 3
40668 Meerbusch
Germany
Email: yannic.labonte@gmail.com
Further details are in the Imprint.
2. Overview and principle
PoolPilot is a native app that talks directly to your pool controller (ProCon.IP, VIOLET or BADU Blue) on your own network. There is no user account — PoolPilot requires no name, no email address and no password. Core operation is purely local.
For individual optional features PoolPilot operates its own servers (the “PoolPilot Cloud”, hosted at Hetzner in Germany). They are only contacted when you enable the respective feature (section 4). Your identity is then always an anonymous random identifier, not a real personal record. PoolPilot processes as little data as possible and never uses it for advertising or profiling.
3. Data inside the app (local)
Controller connection details
To let the app talk to your controller, you enter its address (host/IP) plus a username and password. These credentials are stored only locally on your device — in the system Keychain on iOS, in encrypted, Android-Keystore-backed app storage (EncryptedSharedPreferences) on Android. They leave your device only to reach your controller — for remote access also the remote host you entered, or (with the PoolPilot relay) your own relay agent on your home network. PoolPilot never receives these credentials.
Readings and settings
Readings and status values are fetched from your controller and shown on the device, or cached for the widgets and the watch view. This data likewise stays on the device / within the app's storage.
4. Optional remote access and push
Remote access and push are two separate things — with very different relationships to the PoolPilot servers.
a) Remote access — usually without PoolPilot
To reach your controller while away, there are two ways:
- Native remote access (the common case): for VIOLET and VIOLET-compatible controllers like the BADU Blue via the manufacturer's own access, for ProCon.IP via your own DynDNS/port forwarding or a VPN. Here the app talks directly to the controller or the remote host you entered — the PoolPilot servers are not involved and see neither the connection nor your credentials.
- PoolPilot relay (optional): if you set up the PoolPilot relay, remote access runs through the encrypted tunnel. For this PoolPilot processes an anonymous household identifier, a per-device proof-of-ownership token (stored only as a hash), your controller's LAN address and a random identifier. Because the tunnel is decrypted at a PoolPilot server, the PoolPilot infrastructure can technically see the relayed controller traffic; PoolPilot does not store it and keeps no connection history.
b) Push notifications — always via PoolPilot
Unlike native remote access, every push delivery runs through the PoolPilot servers in Germany and then via Apple or Google:
- PoolPilot processes your device's push token (Apple APNs / Google FCM), your locale and a device installation ID.
- On a warning (e.g. critical pH) PoolPilot processes the affected reading, its type and the pool name you chose, to generate the notification; the title and text then go to Apple or Google.
- For VIOLET boxes there is a particularly lean free-push variant with no account and no household: the app sets up the push source with PoolPilot, and the box itself sends its message to the PoolPilot delivery endpoint — only an access identifier, an app-generated device ID and the push token flow, no purchase or household identity.
- So you can re-read notifications in the app later, PoolPilot stores the title and text of a push notification for a limited time (at most 30 days) on the PoolPilot servers in Germany and deletes them automatically afterwards. For VIOLET this includes the free notification text sent by the box.
Abuse prevention
For protected requests to the PoolPilot servers, the operating system confirms that this is a genuine device running the genuine PoolPilot app (Apple App Attest / Google Play Integrity). Only a random, per-install key identifier or a short-lived verification token is transmitted — no serial number, no location, no persistent device characteristic. On Android this verification token is checked by Google (Play Integrity).
PoolPilot stores no connection history, no persistent IP address of your app and no real names. The legal basis is Art. 6(1)(b) GDPR; for enabling push additionally your consent (lit. a).
5. Purchases and subscriptions
Write features are part of PoolPilot Pro. Purchases and subscriptions are handled by the Apple App Store or Google Play; payment goes through your account there. PoolPilot receives no payment data (e.g. card numbers).
To manage entitlements (“Pro” active/inactive) PoolPilot uses RevenueCat (RevenueCat, Inc., USA). On PoolPilot’s behalf, RevenueCat processes a pseudonymous app user identifier and store purchase/receipt information to verify subscription status. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement under Art. 28 GDPR is in place with RevenueCat.
6. Optional crash reporting
The app contains no analytics, tracking or advertising SDKs. It does include
optional crash reporting, which is off by default — it runs only
after you switch it on under Settings → Crash reporting, and you can switch it off
again at any time. When enabled, technical diagnostics about a crash or error (e.g. the type of
error, a stack trace, the app version, the device model and OS version) are sent to
Sentry (Functional Software, Inc.), which processes them on PoolPilot’s behalf to help PoolPilot
find and fix bugs. Reports are scrubbed of credentials before they leave the device
— your controller password and the Authorization header are never transmitted — and
contain no pool readings. The legal basis is your consent (Art. 6(1)(a) GDPR); withdrawing it
(switching the setting off) stops any further reporting. A data processing agreement under
Art. 28 GDPR is in place with Sentry, and the data is stored in the EU (see sections 9
and 10).
7. This website
Hosting (GitHub Pages)
This website is served via GitHub Pages (GitHub, Inc., a Microsoft company). When you access it, technically necessary access data — such as your IP address, date/time, the file requested and your browser — is processed by the host to deliver the site and keep it running securely. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation).
No cookies, no analytics
The website sets no cookies, uses no analytics tools, and embeds no third-party resources (e.g. third-party web fonts). Fonts are bundled locally. That is why there is no cookie banner.
8. Support
For support you can open a GitHub issue. Its contents and your GitHub profile are public there and processed by GitHub; using it is voluntary. Alternatively you can reach PoolPilot by email — PoolPilot then processes the data you provide solely to handle your request (Art. 6(1)(b) and (f) GDPR).
9. Recipients and transfers to third countries
Depending on the feature used, data may be transferred to: Apple and Google (push, purchases, device attestation), RevenueCat (subscription status), Sentry (crash reporting, EU data residency), Hetzner (hosting the PoolPilot Cloud in Germany) and GitHub/Microsoft (website, support). Transfers to the USA (Apple, Google, RevenueCat, GitHub/Microsoft) rely on the EU Standard Contractual Clauses (SCCs) and/or those providers' certification under the EU-US Data Privacy Framework. Data processing agreements under Art. 28 GDPR are in place with RevenueCat and Sentry; crash reports are stored by Sentry in the EU.
10. Retention
- App and connection data: on your device until you delete it or uninstall the app.
- Push tokens: until invalidated by Apple/Google or you disable push.
- Alert and event data: server-side for 30 days, then deleted automatically.
- Remote-access data (relay, controller): until you remove it in the app; inactive relays after 90 days.
- Crash reports: only if crash reporting is enabled, around 90 days at Sentry.
- Backups: encrypted database backups are kept for 14 days on an EU storage volume (Hetzner) and then deleted automatically.
- Hosting logs: kept by the host only for as long as needed for security.
- Support correspondence: kept as long as needed to handle it.
11. Requesting data deletion
Data on your device
Connection profiles, credentials and cached readings live solely on your device. You delete them yourself by removing the relevant profile in the app or uninstalling the app — that removes this data entirely. No request to PoolPilot is needed.
Data on the PoolPilot servers
If you use remote access (relay) or push, PoolPilot stores individual data server-side: your device's push registration, your anonymous household identifier and controller details (identifier, LAN address). You can remove much of it yourself by disabling push or removing the controller/relay in the app. The only billing-related identifier is the pseudonymous app-user identifier held by RevenueCat (see section 5). On request PoolPilot deletes all server-side data that belongs to PoolPilot; email yannic.labonte@gmail.com.
So PoolPilot can locate and delete your subscription record without follow-up questions, please include:
- Platform: Android (Google Play) or iOS (App Store)
-
The order or transaction ID of your purchase — on Google Play the Order ID in the format
GPA.XXXX-XXXX-XXXX-XXXXX(from your purchase history or the Google order confirmation), on Apple the transaction ID from your Apple receipt (email) - The email of the store account (Google or Apple ID) used for the purchase
- The approximate purchase date and the product (monthly or yearly plan)
Note: statutory retention obligations (e.g. for tax-relevant records) may exempt some data from immediate deletion.
12. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21). You can withdraw any consent at any time with effect for the future.
13. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or of the alleged infringement.
14. Changes
PoolPilot updates this policy when the app, the services used, or the legal situation change. The version published on poolpilot.eu applies.