Privacy Policy
1. Controller
The controller within the meaning of the GDPR is:
Mike Gebert
Westerwaldstr. 4
65936 Frankfurt am Main
Germany
Email: info@anumi.de
2. What data we process
2.1 Account data
When you sign in via Google or Apple, we process:
- Email address (transmitted by the sign-in provider; Apple may provide a relay address)
- Display name (first/last name from the provider profile, if you share it)
- A technical user identifier (Firebase UID), used internally to associate your votes and event participations with your account
We do not receive your password. We do not get access to your contacts, photos, location, or any other device data beyond the sign-in token.
2.2 Event and voting data
- Per event, you choose a display name (nickname); this is stored together with your vote
- Your vote and ranking
- Timestamps of joining and of the last vote submission
2.3 Technical logs
- IP address (used to prevent multi-voting and for rate limiting; deleted after 14 days)
- User agent (device/browser identifier)
- Backend request timestamp
The app uses no trackers, no Crashlytics, no Google Analytics, and no advertising SDKs.
3. Purposes and legal bases
- Purpose
- Legal basis
- Provision of the voting service (sign-in, event participation, voting)
- Art. 6 (1) (b) GDPR (contract or pre-contractual steps)
- Security, prevention of multi-voting and abuse
- Art. 6 (1) (f) GDPR (legitimate interest in tamper-resistant voting)
- Compliance with legal obligations (e.g. responses to authority requests)
- Art. 6 (1) (c) GDPR
4. Recipients and processors
4.1 Sign-in providers
- Google (Google Ireland Ltd., Dublin 4, Ireland; and, where applicable, Google LLC, USA) - for Google Sign-In and Firebase Authentication. Privacy policy: policies.google.com/privacy.
- Apple (Apple Distribution International Ltd., Cork, Ireland; and, where applicable, Apple Inc., USA) - for Sign in with Apple. Privacy policy: apple.com/legal/privacy.
Sign-in involves a third-country transfer to the USA, based on Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and the EU-US Data Privacy Framework adequacy decision (10 July 2023).
4.2 Backend hosting
Our backend (voting-backend.anumi.de) runs on servers in Germany. Data processing takes place exclusively within Germany and the European Union.
5. Retention
- Account data: until you delete your account.
- Event participation and vote: as long as your account exists. On account deletion, your participation and vote are anonymised such that re-identification is no longer possible. The anonymised records are retained to preserve the integrity of the event results.
- Technical logs (IP, user agent): 14 days rolling.
6. Account deletion
You can delete your account at any time directly from within the app (Account → Delete account). Your account data is removed immediately. Votes and event participations are anonymised (display name is replaced with “Deleted participant”; the link to your user identifier is removed).
If you cannot install or open the app, you can also request deletion by email to info@anumi.de.
7. Your rights
You have the right to:
- Access the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) - exercisable in-app, see Section 6
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
To exercise these rights, contact info@anumi.de.
8. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for us is:
Der Hessische Beauftragte fĂĽr Datenschutz und Informationsfreiheit
Postfach 3163, 65021 Wiesbaden, Germany
datenschutz.hessen.de
9. Minors
Anumi Voting is not directed at children under 16. We do not knowingly collect data from minors under 16. If you become aware that a child under 16 has created an account, please contact info@anumi.de.
10. Changes to this policy
We may update this privacy policy when app features or legal requirements change. The current version is always available at this URL.