Back

    Privacy Policy

    for the website and the iOS app "ToBlock"

    Effective: March 8, 2026

    This is a convenience translation. The German version of this privacy policy is the sole legally binding version.

    1. Controller

    The controller within the meaning of the General Data Protection Regulation (GDPR) is:

    Dominik Langer
    Freiherr-vom-Stein-Strasse 22, 60323 Frankfurt am Main
    Email: 44.chromed_primmer@icloud.com
    Germany

    A Data Protection Officer has not been appointed, as the requirements of Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) are not met.

    2. General Information on Data Processing

    This privacy policy informs you about the processing of personal data

    • when visiting the website or landing page of "ToBlock", currently published at https://toblock.lovable.app/, and
    • when using the iOS app "ToBlock".

    Personal data means any information relating to an identified or identifiable natural person.

    The processing of personal data is carried out in accordance with the GDPR and other applicable data protection regulations.

    3. Accessing the Website / Provision of the Online Service

    When you access the website, data that is technically required to deliver the website, ensure stability and security, and prevent misuse is processed.

    The website is provided via external technical service providers or hosted infrastructure. Insofar as Lovable, Lovable Cloud, Supabase, or other hosting, backend, or infrastructure providers are used in the specific setup, they process the technical data generated when using the website as recipients or processors.

    In particular, the following data may be processed:

    • IP address
    • Date and time of access
    • Pages or files accessed
    • Referrer URL
    • Browser type and version
    • Operating system
    • Hostname of the accessing device
    • Amount of data transferred
    • Status messages / server response data

    Purposes of processing: Technical provision of the website, ensuring system security and stability, error analysis, prevention of misuse.

    Legal basis: Art. 6(1)(f) GDPR.

    Legitimate interest: Secure, stable, and functional operation of the online service.

    Recipients: Hosting, backend, and infrastructure service providers used for the operation of the website, in particular the providers integrated in the specific technical setup.

    Retention period: Server log files are stored for a limited period and subsequently deleted or anonymized, unless they are exceptionally required for longer periods for misuse investigation or the assertion or defense of legal claims. The standard retention period for server log files is 30 days.

    4. Encryption

    For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to the site operator, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://" and the lock icon in your browser bar.

    When SSL or TLS encryption is activated, the data you transmit cannot be read by third parties.

    5. Cookies and Similar Technologies

    Cookies or similar technologies may be used on the website.

    Insofar as the use of such technologies is strictly necessary to provide the telemedia service or to enable specific functions expressly requested by you, this is based on the relevant legal provisions, in particular § 25(2) TDDDG (German Telecommunications-Telemedia Data Protection Act) and — insofar as personal data is processed — Art. 6(1)(f) GDPR. The German Data Protection Conference notes that § 25 TDDDG must be independently assessed when storing or accessing information on end devices.

    Purposes of processing: Technical provision, security, stability, and user-requested functions.

    Legitimate interest: Functionality and secure provision of the online service.

    Insofar as cookies or similar technologies that are not strictly necessary are used, they are only employed on the basis of your prior consent pursuant to § 25(1) TDDDG and — insofar as personal data processing follows — Art. 6(1)(a) GDPR.

    Purposes of processing: Depending on the service used, e.g. reach measurement, analysis, convenience features, or marketing.

    Withdrawal: You may withdraw your consent at any time with effect for the future.

    Note: Insofar as no non-essential cookies or similar technologies are actually used on the website, processing is limited to strictly necessary technologies.

    6. Web Analytics (Lovable Analytics)

    The website uses "Lovable Analytics," an analytics service integrated into the Lovable hosting platform. It collects pseudonymized usage data to statistically evaluate the use of the online service and improve the offering.

    In particular, the following data may be processed:

    • Number of visitors and page views
    • Bounce rate and session duration
    • Traffic sources (referrer)
    • Device and browser information

    Purposes of processing: Statistical evaluation of website usage, improvement of the online service.

    Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the needs-based design and optimization of the online service.

    Recipients: Lovable (Lovable Group AB) as operator of the hosting platform and provider of the integrated analytics service.

    Retention period: Analytics data is stored in accordance with the provider's retention periods. Further information can be found in Lovable's privacy information.

    7. Contact

    If you contact me, for example by email or via a contact form provided on the website, the data you provide will be processed to handle your inquiry.

    In particular, the following data may be processed:

    • Name
    • Email address
    • Content of the message
    • Any additional voluntary information

    Purposes of processing: Handling and responding to your inquiry, follow-up communication.

    Legal basis: Art. 6(1)(b) GDPR, insofar as your inquiry is directed at the conclusion or performance of a contract; otherwise Art. 6(1)(f) GDPR.

    Legitimate interest: Proper communication and handling of inquiries.

    Recipients: Where applicable, technical service providers for email or hosting infrastructure.

    Retention period: Data will be deleted once your inquiry has been conclusively handled and no legal retention obligations or legitimate interests in further storage remain.

    7a. Launch promotion (free codes)

    As part of the launch promotion "1 Year of ToBlock Pro Free", you can submit your email address via a form on the website to receive a single-use Apple offer code.

    • Data processed: Email address, language preference, consent record, time of request, and the assigned code.
    • Purposes of processing: Allocation and delivery of a single-use code, prevention of duplicate claims, contacting you about this app (e.g. redemption reminders, product updates).
    • Legal basis: Art. 6(1)(a) GDPR (consent).
    • Recipients: Lovable Cloud / Supabase as the technical backend provider.
    • Retention period: Until you withdraw your consent or as long as required for the promotion and any follow-up inquiries.
    • Withdrawal / deletion: You may withdraw your consent at any time by emailing 44.chromed_primmer@icloud.com. We will delete your email address without undue delay.

    8. Provision of the iOS App / Download via the Apple App Store

    The App is provided via the Apple App Store. During download, installation, and distribution- and payment-related processing, Apple processes personal data under its own data protection responsibility. Apple is independently responsible for these processing operations; Apple's privacy information applies.

    I only have influence on this data processing insofar as I make the App available in the Apple App Store.

    9. Data Processing Within the iOS App

    9.1 General Principles

    The App is designed to be data-minimizing. It can generally be used without a user account. Where possible, processing takes place locally on your device.

    If you use synchronization features via Apple iCloud or CloudKit, the data required for this is processed within the infrastructure provided by Apple. The actual technical implementation determines the scope of these processing operations.

    9.2 Optional First Name

    During setup or use of the App, you may voluntarily provide your first name to personalize content within the App.

    • Data processed: First name
    • Purpose of processing: Personalized address within the App.
    • Legal basis: Art. 6(1)(a) GDPR.
    • Storage: Locally on your device; if synchronization is enabled, additionally via iCloud or CloudKit.
    • Recipients: No transfer to the controller's own servers. When using iCloud/CloudKit, Apple may be involved as a technical provider.
    • Retention period: Until you withdraw your consent or delete the data.
    • Withdrawal: You can change or delete this information at any time in the App.

    9.3 App Content

    When using the App, you can enter and manage content, in particular tasks, notes, ideas, habits, and other content you create.

    • Data processed: Content you enter, including associated organizational and metadata, insofar as required for the use of App features.
    • Purposes of processing: Provision of the core features of the App, in particular organization, display, editing, storage, and management of your content.
    • Legal basis: Art. 6(1)(b) GDPR, insofar as processing is necessary for the provision of the App features you use.
    • Storage: Generally locally on your device. If you have enabled synchronization via Apple iCloud or CloudKit, content may additionally be processed and synchronized there.
    • Recipients: No transfer to the controller's own servers. When using iCloud/CloudKit, Apple may be involved as a technical provider.
    • Retention period: Until deletion by you.

    9.4 Location Data for Location-Based Reminders

    If you enable location-based reminders, the App may access location data from your device.

    • Data processed: Location data
    • Purpose of processing: Triggering location-based reminders.
    • Legal basis: Art. 6(1)(a) GDPR.
    • Storage: No permanent storage of location data by the controller occurs, provided the App only uses this data to trigger the function and does not store it separately.
    • Recipients: No transfer to the controller's own servers.
    • Retention period: Only as long as necessary to provide the function.
    • Withdrawal: You can disable location access at any time in iOS Settings.

    9.5 Access to Calendar Data

    If you enable the calendar feature, the App may access calendar data.

    • Data processed: Calendar events and the information required for them.
    • Purpose of processing: Display and use of your calendar data within the App.
    • Legal basis: Art. 6(1)(a) GDPR.
    • Storage: No separate data storage by the controller occurs, insofar as the App merely accesses existing calendar data and displays or uses it within the App.
    • Recipients: No transfer to the controller's own servers.
    • Retention period: Only during active use of the function or in accordance with storage within your calendar environment.
    • Withdrawal: You can disable calendar access at any time in iOS Settings.

    9.6 Local Notifications and Reminders

    If you enable reminders or notifications, the App uses the notification features provided by iOS.

    • Data processed: Notification content as well as times or other trigger conditions that you set yourself.
    • Purpose of processing: Provision of reminders and local notifications.
    • Legal basis: Art. 6(1)(a) GDPR.
    • Storage: Generally locally on your device, insofar as only local notifications are used.
    • Recipients: No transfer to the controller's own servers.
    • Retention period: Until you deactivate or delete the respective reminder or notification.
    • Withdrawal: You can disable notifications at any time in iOS Settings.

    9.7 In-App Purchases and Subscriptions

    If you use paid features or subscriptions, payment processing is handled by Apple.

    • Data processed: Information about your purchase or subscription status and transaction-related confirmations, insofar as necessary for unlocking or maintaining paid features.
    • Purposes of processing: Provision, unlocking, and management of paid features.
    • Legal basis: Art. 6(1)(b) GDPR.
    • Recipients: Apple as provider of the payment and distribution infrastructure; where applicable, additional technical service providers insofar as they are actually used for purchase status verification.
    • Retention period: As long as necessary for the provision of paid features, contract performance, or compliance with legal obligations.

    Note: Payment data itself is generally processed by Apple under its own responsibility.

    10. Recipients or Categories of Recipients

    Depending on the use of the website or App, personal data may be disclosed to or processed by the following recipients or categories of recipients:

    • Hosting, backend, and infrastructure service providers for the website
    • Providers used in the specific technical setup, in particular Lovable, Lovable Cloud, Supabase, or comparable technical service providers, insofar as they are actually used
    • Apple, in particular in connection with the App Store, iCloud, CloudKit, in-app purchases, and iOS system functions
    • Email or communication service providers, insofar as they are used for contact inquiries
    • Additional technical service providers only insofar as they are actually integrated in the specific individual case

    Where possible, no transfer of App content to the controller's own servers takes place.

    11. Data Transfers to Third Countries

    Insofar as providers based in countries outside the European Union or the European Economic Area are integrated in the use of the website or App, or personal data is processed there, a data transfer to a third country may occur.

    Such a transfer only takes place insofar as the legal requirements of Art. 44 ff. GDPR are met. This may be the case in particular

    • where an adequacy decision of the European Commission exists, or
    • on the basis of appropriate safeguards, in particular standard contractual clauses.

    Insofar as Apple services, hosting, or infrastructure service providers are used, further information on any third-country transfers and the safeguards used can be found in the privacy information and contractual documentation of the respective provider.

    12. Obligation to Provide Data

    Insofar as personal data is collected, the following applies:

    • The provision of access data when visiting the website is technically required to display the website.
    • The provision of data when contacting us is required insofar as your inquiry is to be processed.
    • Providing a first name in the App is voluntary; without this information, only personalization is limited.
    • Entering tasks, notes, ideas, habits, or other content is required if you wish to use these App features.
    • Granting access to location, calendar, and notifications is voluntary. Without these permissions, the respective additional features cannot be used.
    • Processing of purchase or subscription information is required if paid features are to be provided.

    13. Retention Period and Deletion

    Personal data is only stored for as long as necessary for the respective purposes or as required by legal retention obligations.

    In particular:

    • Access data and server log files: The standard retention period is 30 days.
    • Data from contact inquiries: until conclusive handling, and beyond only insofar as legal obligations or legitimate interests exist
    • App content: until deletion by you
    • iCloud/CloudKit data: in accordance with the features and deletion options provided by Apple
    • Purchase and subscription information: as long as necessary for the provision of paid features or compliance with legal obligations

    14. Your Rights

    Under applicable law, you have in particular the following rights:

    • Right of access pursuant to Art. 15 GDPR
    • Right to rectification pursuant to Art. 16 GDPR
    • Right to erasure pursuant to Art. 17 GDPR
    • Right to restriction of processing pursuant to Art. 18 GDPR
    • Right to data portability pursuant to Art. 20 GDPR
    • Right to object pursuant to Art. 21 GDPR
    • Right to withdraw consent pursuant to Art. 7(3) GDPR with effect for the future
    • Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR

    To exercise your rights, an informal message to the email address stated above is sufficient.

    Special notice regarding the right to object under Art. 21 GDPR: Insofar as personal data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object to the processing at any time pursuant to Art. 21(1) GDPR for reasons arising from your particular situation. The controller will then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

    15. Right to Lodge a Complaint with a Supervisory Authority

    You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent authority is in particular the data protection supervisory authority of the federal state in which the controller is based, or the supervisory authority of your habitual residence.

    16. No Automated Decision-Making

    Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.

    17. Use by Minors

    The App may also be used by persons under the age of 16. Insofar as the processing of personal data is based on consent, consent pursuant to Art. 8(1) GDPR is only lawful if it is given or approved by the holder of parental responsibility for the child, provided the child has not yet reached the age of 16. We ask guardians to accompany minors' use of the App and to contact us with any questions.

    18. Changes to This Privacy Policy

    I reserve the right to adapt this privacy policy if this becomes necessary due to technical changes, changes in the legal situation, or new features of the website or App. The currently published version shall apply in each case.