Privacy Policy

Auf Deutsch übersetzen

Last updated: 21 September 2026

We take the protection of your personal data seriously and process it confidentially in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This policy explains what personal data we process and why. It covers both the website brainmute.app and the Brainmute Android app. Sections 3 to 5 and 11 to 12 are about the website, sections 6 to 10 are about the app, and the rest applies to both.

Contents
  1. Controller
  2. Legal bases
  3. Hosting and server log files
  4. Content delivery network and security
  5. Self-hosted fonts
  6. The app: what never leaves your phone
  7. The app: what we store on our server
  8. Your account and sign-in
  9. Subscription and payment
  10. Permissions the app asks for, and why
  11. Email contact and routing
  12. Cookies, local storage and analytics
  13. Transfers to third countries
  14. Storage periods
  15. Your rights
  16. Withdrawal of consent and objection
  17. Right to lodge a complaint
  18. Data security
  19. Minors
  20. Changes to this policy

1. Controller

Controller within the meaning of Art. 4 (7) GDPR is:

Luis Kleemann
Engelbergerstraße 3
79106 Freiburg im Breisgau
Germany

Email: [email protected]

A data protection officer is not required by law (no core activity of regular, large-scale or sensitive data processing under Art. 37 GDPR / § 38 BDSG).

For residents of Quebec (Canada), the Act respecting the protection of personal information in the private sector requires a designated person in charge of the protection of personal information. This function is exercised by the person with the highest authority in the enterprise: Luis Kleemann, owner of the sole proprietorship. Contact: [email protected], or by post at the address above.

2. Legal bases

Where we process personal data, we rely on the following legal bases:

3. Hosting and server log files

Our website is hosted by:

Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA

Further information can be found in Cloudflare's privacy policy.

When you visit the site, Cloudflare automatically processes the following data in server log files, which your browser transmits for technical reasons: IP address, date and time of access, requested file, amount of data transferred, HTTP status code, browser type and version, operating system, and referrer URL.

Purpose: delivery of the website, IT security, and defence against attacks and bot traffic.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically sound and secure website).
Storage period: server log files are kept for a maximum of 14 days. This data is not merged with other data sources.

4. Content delivery network and security

Cloudflare is also used as a content delivery network (CDN) and web application firewall (WAF). All traffic between your browser and our site is routed through Cloudflare's global network and malicious requests are filtered out. Processing your IP address is technically necessary for this.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the performance and security of the site).

5. Self-hosted fonts

This site uses the fonts Inter, JetBrains Mono, Space Grotesk and Instrument Serif (all under the SIL Open Font License). The font files are served exclusively from our own server (Cloudflare Pages). No connection to Google Fonts or any external font CDN is made when the fonts are loaded, so no IP address is transmitted to a font provider.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a consistent presentation).

6. The app: what never leaves your phone

Brainmute is an Android app that locks distracting apps and gives you missions. Most of what it needs to do that stays on your device and is never sent to us.

Legal basis: Art. 6 (1) (b) GDPR, because this is how the service you asked for works. Nothing here is processed for any other purpose.

7. The app: what we store on our server

If you create an account, the app syncs part of your data so you do not lose it when you change or reset your phone, and so friend features work. This is the complete list.

Purpose: to keep your progress across devices and to run the friend features.
Legal basis: Art. 6 (1) (b) GDPR for your own data, and Art. 6 (1) (a) GDPR (consent) for friend activity and for appearing in the leaderboard.
Processor: Supabase, for the database and for sign-in. The database is hosted in Frankfurt, Germany (region eu-central-1). We have a data processing agreement in place.

We do not use analytics, advertising or tracking of any kind. There is no Google Analytics, no Meta pixel, no TikTok pixel and no advertising ID. We do not send push notifications from a server, so no push token is created or transmitted.

8. Your account and sign-in

Brainmute requires an account. You create it at the start, and the app cannot be used without one. There is no anonymous use.

You can sign up with an email address and a password, or with your Google account. If you use Google, we receive your email address and your Google account ID from Google in order to identify you. We do not receive your password. We do not store your name or your profile picture: both are removed automatically when your account is created and whenever it changes, before anything is written to our database.

We send emails to your address for your account: the verification code when you sign up, password resets, confirmation when you change your address, and confirmation after you delete your account. There are also two security notices that you cannot unsubscribe from, because they protect your account: one when your password has been changed, and one when your email address has been changed. Sending is handled for us by Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France. The data processed are the sender address, the recipient address, the subject, the content of the email, the timestamp and the response of the receiving mail server. Processing takes place in France. According to Scaleway, no personal data is processed outside the European Union for this service and no sub-processors outside the European Union are used for it.

If an address cannot be reached, Scaleway puts it on a blocklist so that no further delivery attempts are made. The address, the reason and the period of the block are stored. The first block lasts one week, the second one month, and from the third onwards it has no time limit. We can unblock an address again.

If you create an account but do not confirm it with the code from our email, we delete it again no later than 48 hours after it was created, together with the address you gave.

So that nobody can abuse our sign-up and our email sending, we limit how often an email can be requested for an address in a row. For this we do not store your address, only a check value calculated from it, from which the address cannot be recovered. These entries are deleted after two days at the latest.

We do not pass on your IP address. The app does not send it to us, and we do not forward it to any provider. Supabase sees the IP address your device connects from and stores it in two places: in its technical logs, which are kept for one day, and with your sign-in, together with the technical identifier of the program making the connection (user agent). Only the most recent connection is kept with your sign-in. It is overwritten with each new one and deleted as soon as you sign out or delete your account.

Purpose: to identify you, to restore your data on a new device, to deliver the emails for your account, and to protect our sign-up from abuse.
Legal basis: Art. 6 (1) (b) GDPR. For the blocklist, the limit on requests and the deletion of unconfirmed accounts Art. 6 (1) (f) GDPR; our legitimate interest is reliable delivery, protection against being blocked by mail providers, and protection against abuse. For the security notices about your password and your address Art. 6 (1) (f) GDPR; our legitimate interest is the security of your account.

9. Subscription and payment

Brainmute is sold as a subscription through the Google Play Store. We never see your payment details. Your card, your address and your bank data are handled by Google and never reach us.

To know whether your subscription is active, we use RevenueCat, Inc., 1 Letterman Drive, San Francisco, CA 94129, USA. We send them your account ID, and they tell us whether you have an active subscription. They receive no other data from us. RevenueCat acts as our processor in doing so, see section 13.

If you delete your account, we also delete your record at RevenueCat, that is the subscription status and purchase history stored there under your account ID. Your purchase itself is held by Google: an active subscription continues and continues to be charged until you cancel it in the Google Play Store.

Purpose: to unlock the app for paying users.
Legal basis: Art. 6 (1) (b) GDPR.
Third country: RevenueCat is in the USA. The transfer is based on the EU standard contractual clauses.

10. Permissions the app asks for, and why

Android asks you for each of these separately. You can refuse any of them, and you can withdraw any of them later in your phone settings. Some parts of the app then stop working, but nothing else happens.

11. Email contact and routing

Emails to [email protected] are received and stored in a mailbox at IONOS SE (Elgendorfer Straße 57, 56410 Montabaur, Germany) in order to process your request. IONOS acts as our processor pursuant to Art. 28 GDPR; the applicable data processing agreement forms part of the IONOS General Terms and Conditions. Processing takes place within the European Union (primarily in Germany). To our current knowledge, there is no transfer of personal data to a third country. Data processed: sender address, recipient address, subject, message content, attachments and headers.

If you use the contact us entry in the app (tap your profile picture in the top right, the entry is in the first menu), the app opens a draft email in your own email program. The recipient, the subject and a few technical lines are pre-filled: the version of the app, your Android version and your device model (for example SM-A566B). These lines help us reproduce a problem on the right kind of device. They contain no unique device identifier, in particular no advertising ID, no serial number and no IMEI, and no location data. The app does not transmit anything by itself; the draft is only sent once you send it, and you can edit or delete these lines beforehand.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual requests) or Art. 6 (1) (f) GDPR (legitimate interest in communication).
Storage period: until your request has been dealt with; statutory retention obligations, in particular commercial and tax retention periods, remain unaffected.
Provision of data: providing your data is voluntary; without your email address and the content of your message we cannot process your request.

12. Cookies, local storage and analytics

This site does not use cookies for analysis, marketing or tracking. There is no Google Analytics, no Meta pixel and no TikTok pixel.

Cloudflare may set one technically necessary cookie (__cf_bm, lifetime max. 30 minutes) for bot defence. Legal basis: § 25 (2) no. 2 TDDDG (strictly necessary) and Art. 6 (1) (f) GDPR.

We use Cloudflare Web Analytics (Cloudflare, Inc., USA) for aggregate, privacy-friendly reach measurement. It does not set any cookies and does not store personal data (in particular no IP addresses, no device fingerprints and no cross-site identifiers). Identifying individual visitors is technically impossible, so no consent under § 25 TDDDG is required. Legal basis for the processing: Art. 6 (1) (f) GDPR. More information: cloudflare.com/web-analytics-privacy.

Because no marketing or tracking cookies are used, this site does not require a cookie consent banner. If tracking tools are added in future, this policy will be updated and, where required, your consent obtained beforehand.

13. Transfers to third countries

Some of our providers are based outside the European Union, or can access personal data from there. Where data is transferred to a third country, we put in place the safeguards required under Chapter V GDPR. Here is who they are and what each transfer is based on.

We have data processing agreements under Art. 28 GDPR with the processors we use. You can request a copy of the standard contractual clauses at [email protected].

14. Storage periods

We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations. Specific periods: server log files max. 14 days; the __cf_bm cookie max. 30 minutes; unconfirmed accounts max. 48 hours; the check values used to limit email requests max. two days; Supabase's technical logs with your IP address max. one day; the IP address and user agent of your sign-in until you sign out; everything listed in section 7 for as long as your account exists. You can delete your account at any time in the app itself: tap your profile picture in the top right, go to the ACCOUNT section and choose delete account at the very bottom. This deletes your account, your score, your streak, your friendships and your record at RevenueCat. You can also ask us to do it by writing to [email protected].

For the emails about your account the following also applies: sending and delivery data at Scaleway is stored only for as long as it is needed to investigate delivery failures and to prove delivery. Blocklist entries remain for the periods stated in section 8. Log data at our former provider Resend is deleted according to the periods that apply there, see section 13.

15. Your rights

As a data subject you have the following rights:

To exercise your rights, an informal message to [email protected] is enough.

16. Withdrawal of consent and objection

You can withdraw any consent at any time with effect for the future (Art. 7 (3) GDPR), for example by clicking the unsubscribe link in our emails. The lawfulness of processing carried out before the withdrawal is not affected. Where data is processed on the basis of legitimate interest, you can object under Art. 21 GDPR for reasons arising from your particular situation.

17. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example at the authority of your habitual residence or of our place of business:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Web: baden-wuerttemberg.datenschutz.de

18. Data security

This site uses SSL/TLS encryption for security and to protect the transmission of confidential content, recognizable by "https://" and the padlock symbol in your browser.

19. Minors

Brainmute is intended for persons aged 16 or over. The app asks for your age before you can use it. If we become aware that an account belongs to a person under 16, we delete it without delay.

20. Changes to this policy

We may adapt this policy when the legal situation or the actual data processing changes (for example when new services are integrated). The version published at brainmute.app/privacy-policy applies.