Privacy Policy
Last updated: 2026-07-31
1. In short
Genug sends no personal data to the provider. There is no server and there are no user accounts. Everything you record in the app stays on your device and — if you have iCloud switched on — in your own private iCloud database. The provider has no access to it and no way of obtaining any.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Julian FurchertDinxperloer Str. 13
46399 Bocholt
Deutschland
Email: privacy@genug.app
3. Data the app processes
What you record in Genug is stored locally on your device. If iCloud is switched on in your device settings, the operating system also syncs that data through Apple CloudKit into the private database of your iCloud account, and from there to your other Apple devices.
That private database belongs to your iCloud account, not to the provider. The provider receives no key, no copy and no access — neither technically nor organisationally.
- No registration, no email address, no profile.
- No transmission of content to servers of the provider.
- No disclosure to third parties, no sale of data.
- No analytics, tracking or advertising SDKs in the app.
- No app tracking in the sense of Apple's ATT framework.
Two features touch the system layer and are named here for completeness. The daily reminder is optional and off by default. If you switch it on, Genug asks once for the system’s notification permission and schedules the reminder locally on your device; no data is transmitted and no push service is used. The export writes your entries into a text file and hands it to the system’s share sheet — where it goes is your decision at that moment. It is the only thing that ever leaves Genug.
4. Apple’s role
Apple is independently responsible for operating iCloud and the App Store. If you use iCloud, Apple’s privacy policy and the agreement between you and Apple apply to it. The provider of this app is not party to that and receives no data about you through it.
Apple gives developers aggregated, non-personal statistics in the App Store (download counts, for instance). Those figures allow no conclusion about individuals, and the provider does not collect them independently. Whether your device sends diagnostic and crash reports to Apple is your choice in your device settings.
5. Legal basis
Where the app processes personal data at all, it does so exclusively on your device and in your iCloud account, in order to provide the function you asked for (Art. 6(1)(b) GDPR). No processing by the provider takes place.
6. Retention and deletion
You decide how long anything is kept. Today can be changed in the app — a second tap takes a theme back; past days are deliberately not editable. You delete everything by removing the app from your device and deleting its data in your device’s iCloud settings. Because the provider holds no copy, nothing then remains that it could delete.
7. This website
This website is a purely static site. It sets no cookies, embeds no third-party maps or scripts and performs no analytics. The fonts it uses are served from this server, not fetched from a third party. There is no contact form; contact is by email.
The site is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When the site is called up, Vercel processes technically necessary connection data — among them the IP address, the time, the address requested and the headers sent — in server log files. The legal basis is the legitimate interest in secure and trouble-free operation (Art. 6(1)(f) GDPR). A data processing agreement under Art. 28 GDPR is in place with Vercel.
Vercel is a company based in the United States, so personal data may be transferred to a third country in the process. The transfer is based on the provider’s certification under the EU-US Data Privacy Framework and, in addition, on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
8. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR) against the controller. Since the provider holds no data about you, a request for access will as a rule come back empty.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
9. Contact
Questions about data protection:
10. Changes
If the app or the legal situation changes, this policy is adjusted. The version published here is the one that applies.