Longlist
Privacy policy
What Longlist processes, why, and how you get rid of it again.
The short version
Longlist is a list for personal life goals. It works completely without an account and without a network connection. As long as you do not sign in, your goals, notes and photos never leave your device — there is no processing on our side, because nothing reaches us.
- No ad network, no tracking, no third-party analytics SDK.
- No App Tracking Transparency prompt, because nothing is tracked across apps or sites.
- No real name and no email address when you sign in.
- No sale of data — to anyone, for any purpose.
Controller
- Tobias Paulik
- Birkenweg 20a
- 34320 Söhrewald
- Deutschland
Email: mail@tobier.de
Using the app without an account
Everything you enter lives in a database inside the app’s protected storage on your device. We never see it. City search and the world map work offline from data bundled with the app — even searching for a place creates no request to us.
Export writes a file on your device. Where it goes is your decision; it does not pass through our server.
Sign in with Apple
Signing in exists only for syncing between your devices and for shared lists. We use Sign in with Apple and explicitly request neither your name nor your email address. What reaches us is the pseudonymous identifier Apple issues for this app, plus the time you signed in.
Syncing your content
While you are signed in, the app sends your list content to our server so it appears on your other devices and in shared lists. That content is what you type yourself: titles, your “why”, progress, estimated cost and duration, the next step, milestones, links, places, photos and completion notes.
Deleted entries are first marked as deleted and only removed for good after 90 days. That is mechanics, not a reservation: a device that was offline for three weeks still has to learn about the deletion, or the entry comes back.
Shared lists
A list is shared only if you create an invitation and pass it on. Whoever redeems it sees that list’s content and becomes visible in its member list. There is no public area, no user search, and no recommendation of other people’s content.
We store the invitation code only as a hash; it expires and can be revoked. As the owner of a list you can remove any member at any time.
Purchases
The purchase itself runs entirely through Apple. We see no payment data — no card number, no billing address, no name. From our provider RevenueCat we receive whether an entitlement exists for your identifier, which product it is, and when it starts and ends.
Withdrawal under § 356a BGB
If you withdraw from a contract using the withdrawal button, we process the email address you enter there, your contract details, an optional note, and the date and time of your declaration. The address is used solely for the confirmation the law requires.
Notifications
Reminders for deadlines and seasonal windows are calculated on your device and delivered there. Nothing leaves the device for that. Only for events that the server alone knows — a change in a shared list, for instance — do we store a device token from Apple so we can send a notification. It is deleted with your account.
Logs, crash reports, statistics
- Access logs: shortened IP address, time, requested path, status code — to prevent abuse and to debug. Legal basis Art. 6(1)(f) GDPR.
- Crash reports: we run the collector ourselves; the reports contain technical detail about the crash, not your list content.
- Usage figures: aggregated only, with no device identifier and no advertising identifier.
Device permissions
Every permission is requested at the moment you use the feature that needs it — never at first launch.
- Location (“While Using”): shows goals near you and reminds you there. Your location stays on the device and is not sent to us.
- Calendar: write access only. The app never reads your calendar.
- Reminders: for exporting milestones and deadlines.
- Notifications: for reminders you switch on yourself.
Camera, microphone, contacts, health data and the photo library are never requested.
Recipients and place of processing
The server runs in the European Union. Besides Apple and RevenueCat there is a mail provider for the withdrawal confirmation and the provider of the server itself. There are no other recipients.
Backups
The database is backed up in encrypted form. Backups rotate out over time; individual snapshots may be kept for up to three years. A deletion takes effect immediately in live operation and reaches the backups as each snapshot expires.
Deleting your account
In the app under Settings → Account → Delete account. This deletes your account and the synced content on the server. The list on your device stays — the app is yours, not the account’s.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21).
Write to mail@tobier.de. Independently of that, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
You do not have to wait for us to export your data: export is built into the app, free, and works without an account.