Planungshelden · Privacy
Privacy notice for Planungshelden
This privacy notice describes the processing of data in the closed test of the Planungshelden Android app.
Last updated: 7 October 2026
Scope
This notice applies to the Planungshelden Android app with the package ID de.lormalibulabs.planungshelden in its current closed test. The closed test uses only fictional organizations and fictional employee data. No public production service is currently offered.
There is no public self-registration. Employees are created administratively by their organization and can be included in schedules without having app access of their own.
Controller and contact
Privacy and deletion requests are handled manually by Sebastian Klockzim, trading as Lormalibu Labs. Contact: [email protected].
Data processed
Optional app access uses an email address, Firebase user ID, internal user ID, name, preferred language, account status, organization membership and role.
Planungshelden business data includes names, optional contact email addresses, employment and invitation states, operational positions and areas, shift times, active weekdays, planning periods, work wishes, unpublished schedule assignments, published schedule versions containing names, swap and replacement requests, and related technical identifiers and timestamps.
Free-text notes in work wishes remain part of the relevant wish. Users should not enter sensitive personal information in these notes.
The app does not record actual working time or make automated personnel decisions.
Purposes and limits of the closed test
Data is used for sign-in and access control, administrative team management, recording work wishes, preparing, publishing and displaying schedules, and organizing swaps and replacement cover. Technical access and security data supports the operation and security of the service.
The organization and employee data used in the closed test is fictional. This notice does not infer the allocation of data protection roles or a legal basis for a later service using real employee data.
Providers and processing locations
Google Firebase Authentication processes sign-in and account data. Firebase persistence retains sign-in on the device. According to the provider, authentication data is also processed in the United States.
The current staging API on Google Cloud Run and the relational Cloud SQL PostgreSQL business database are located in europe-west3 (Frankfurt). The Google Cloud Logging buckets _Default and _Required have global locations.
Expo/EAS processes technical data for requesting and delivering app updates. Google Play processes data for app installation and distribution. We do not claim that processing is restricted exclusively to the EU.
The app sends sign-in tokens and business requests over HTTPS to the protected API. The API verifies Firebase ID tokens as well as current organization membership and permissions. No database or administrator key is embedded in the app.
Retention and deletion
All Planungshelden business data is retained for four weeks. The period begins at the end of its purpose or at the end of the associated planning period. The affected business data is then removed through the controlled deletion process unless a documented reason requires temporary further retention.
Published schedules remain unchanged during this four-week period, including the names they contain. Free-text work-wish notes remain in place for the period that applies to the relevant wish. Disabling or archiving an account or employee record is not complete deletion.
Staging creates automatic Cloud SQL backups daily in Frankfurt and retains them for three days; point-in-time recovery is disabled. Google Cloud Logging retains data for 30 days in the _Default bucket and 400 days in the _Required bucket. According to Firebase, logged authentication IP addresses are retained for a few weeks; after a Firebase user is deleted, other authentication data may take up to 180 days to be removed from live and backup systems. These technical periods do not change the four-week rule for Planungshelden business data.
Account and data deletion requests are handled manually. The outcome identifies which data was deleted and which data is temporarily retained, including the reason and the end of that retention.
Advertising, analytics and tracking
The reviewed client contains no advertising, product analytics or tracking.
Your rights
Where the legal requirements are met, rights include access, rectification, erasure, restriction of processing, data portability and objection. There is also a right to lodge a complaint with a competent data protection supervisory authority.
If possible, identify the relevant organization and account email in a request. Do not send a password or sensitive wish details. Identity and responsibility are verified before the request is processed.
Send a privacy request by email
State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania
Changes to this notice
This privacy notice will be updated if features, technical processes or legal requirements change.
