In brief:

The MyLocalSafe app processes your passwords, notes, card and profile data (the "Safe") exclusively locally on your device. The provider has no access to this content, there are no user accounts, no cloud synchronisation and no transmission to the provider's own servers. The app itself has no internet permission.

Data processing in the narrower sense only affects three separate areas:

  1. Google Play: When purchasing the premium version, Google handles payment (Google Play Billing) and app delivery (Google Play Store, Play Services). These processes run at operating system level, outside the app's control.
  2. This website: When accessed, server log files (IP, date, browser) are created at the hosting provider. A LocalStorage entry stores the selected language.
  3. Support contact: When you send an email, we process your message to handle your request.

Details on all points can be found in the following chapters.

Note: This English version is provided as a convenience translation. In the event of any discrepancy, the German version at mylocalsafe.eu/datenschutz.html shall be legally binding.

1. Subject of this Privacy Policy

This Privacy Policy provides information about the nature, scope, and purpose of the processing of personal data in connection with the use of the "MyLocalSafe" application and the associated website.

MyLocalSafe is designed as a locally processing application. The processing of personal data in the so-called "Safe" takes place exclusively on the user's device in encrypted form. No transmission or disclosure of this content to the provider or to servers operated by the provider takes place. The app has no network permission for this purpose.

Processing is carried out in accordance with the principle of data minimisation pursuant to Art. 5(1)(c) GDPR.

2. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Jörg Schambeck
Gailenreuther Str. 3d
81243 München
Germany

Contact:
Email: contact@mylocalsafe.eu
Website: https://mylocalsafe.eu

(Note: The domain mylocalsafe.de redirects to mylocalsafe.eu via an HTTP 301 redirect.)

VAT ID: DE285502830

3. Categories of data and processing context

Depending on which functions are used, the following categories of data may be processed in connection with the use of MyLocalSafe and the associated website:

3.1 Safe data (local user data)

This includes in particular:

  • Access credentials (e.g. username, password, URL, notes)
  • Two-factor authentication data (2FA/OTP)
  • Files (e.g. documents, images)
  • Security questions (optional)
  • Payment and card data (For local management only. The storage of security codes [CVV/CVC] is a voluntary, user-initiated function for purely local information management; the responsibility for weighing the data security on the device lies solely with the user.)

This data is processed and stored in encrypted form exclusively on the user's device. According to the current technical state, no server-side processing or knowledge of it by the provider takes place.

3.2 Technical metadata and usage data (app)

In connection with the use of the application, the following technical information may be processed:

  • Device information (e.g. operating system, device model)
  • App configurations
  • Technical error and crash data (if enabled)
  • Usage information within the scope of Google Play Services

This data is processed exclusively for the provision, stability, and security of the application.

3.3 Support and communication data

When you contact us by email, the transmitted data is processed, in particular:

  • Email address
  • Message content
  • Voluntarily submitted additional information

3.4 Server log files and website data

When the associated website is accessed, the hosting provider (ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany) processes technically necessary server log files:

  • IP address (anonymised)
  • Date and time of access
  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing computer

To store the selected language on the website, LocalStorage (key: mls-lang) is also used.

4. Purpose of processing

Personal data is processed for the following purposes:

  • Provision and operation of the application and the website
  • Local storage and encryption of user data
  • Authentication and security functions
  • Error analysis and stability improvement
  • Handling of support requests
  • Compliance with legal and regulatory requirements

5. Legal bases for processing

Where personal data is processed, this is done on the basis of the following legal grounds:

  • Art. 6(1)(b) GDPR: Performance of a contract or pre-contractual measures (use of the app, support requests).
  • Art. 6(1)(f) GDPR: Legitimate interest in the security, stability, and error-free operation of the website and the app, as well as technical further development.
  • Art. 6(1)(a) GDPR: Consent of the user (e.g. for optional diagnostic data via the device settings).
  • § 25(2) No. 2 TDDDG: For the technically necessary use of LocalStorage to store the language preference on the website.

6. Technical and organisational measures

MyLocalSafe employs the following measures to ensure data security:

  • AES-256 encryption of local data (AES-256-GCM for local Safe data)
  • AES-256-encrypted ZIP backups (using a zip4j implementation to integrate password protection)
  • Hardware-backed key management (Android Keystore, where available)
  • Password derivation using PBKDF2-HMAC-SHA256 (600,000 iterations)
  • Disabling of Android Auto Backup (allowBackup=false)
  • Protection against screen recording (FLAG_SECURE)
  • Automatic locking mechanisms on inactivity

The security of data processing depends substantially on the integrity of the respective device. On compromised systems (e.g. root access), security may be reduced.

7. Third parties and data recipients

7.1 Google Play Billing

Google Play Billing is used to process in-app purchases.

  • Legal basis: Art. 6(1)(b) GDPR
  • Recipient: Google Ireland Limited, Dublin, Ireland
  • Data categories: Transaction data, product identifiers, device information (no payment-relevant bank data)

7.2 Google Play Services / ML Kit

For certain system functions (e.g. OCR, authentication, system integration), Google Play Services and ML Kit are used. Processing partly takes place at system level through the operating system or the Google services. The app itself does not process any Safe content outside the device. These data transmissions occur within the operating system's background processes and are beyond the app's control.

  • Legal basis: Art. 6(1)(b) and (f) GDPR
  • Recipient: Google Ireland Limited, Dublin, Ireland

7.3 Error diagnostics

If enabled by the user in the operating system, crash reports may be transmitted to Google. This transmission occurs at system level and is outside the application's sphere of influence. A technically intended transmission of Safe content to the provider is excluded.

  • Legal basis: Art. 6(1)(a) GDPR (consent via device settings)

8. App permissions

The application uses only technically necessary permissions:

  • Camera: For the local QR code and OCR scan function.
  • Storage access: For manual, user-initiated data import and export.
  • Biometrics: For system-based, on-device unlocking.
  • Network: The app itself has no internet permission and does not communicate with the provider's servers. Data transmissions in the context of Google Play Billing or Play Services (see Section 7) occur at operating system level and are outside the app's control.

9. Tracking, profiling, and advertising

MyLocalSafe does not process any data for advertising purposes. In particular, there is:

  • No tracking for marketing purposes by the app itself
  • No creation of user profiles
  • No use of advertising IDs within the application
  • No disclosure of Safe content to advertising networks

10. Contact

When you contact us by email, the transmitted data is processed exclusively to handle the respective request.

  • Legal basis: Art. 6(1)(f) GDPR, where applicable Art. 6(1)(b) GDPR
  • Storage period: Only as long as necessary to conclusively handle the request.

11. Storage period

Personal data is generally stored only for as long as is necessary for the respective purposes. Local app data remains on the user's device until:

  • Manual deletion by the user within the app, or
  • Uninstallation of the application via the operating system

No server-side storage of the Safe data by the provider takes place. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the web hosting provider.

12. Rights of data subjects

Data subjects have the rights under Art. 15 et seq. GDPR, in particular the rights to information/access, rectification, erasure, restriction of processing, and data portability.

Since no server-side processing of the data stored in the Safe takes place and this content is not available to the provider, these rights with regard to this Safe data can only be exercised by the user themselves within the application. Where processing is based on consent (e.g. point 7.3), this can be withdrawn at any time with effect for the future in the device's system settings.

13. Notice regarding the right to object under Art. 21 GDPR

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (processing based on legitimate interests). This applies in particular to processing in the context of website hosting (Section 3.4), third-party services (Section 7.2), and support communication (Section 10). The objection can be sent informally to the contact details specified in Section 2 (Jörg Schambeck, contact@mylocalsafe.eu).

14. Supervisory authority

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany

15. Final provisions

This Privacy Policy may be amended in the event of technical or legal changes. The current version is available at mylocalsafe.eu/datenschutz.html.