Log App
Use cases Guides Roadmap How it works
DE Get the app
Use cases Guides Roadmap Compare How it works Deutsch
Privacy Terms Impressum Support
Privacy

Privacy policy

Last updated: 2026-09-14

This policy explains what personal data hechenbros processes when you use the Log App website and the Log App app, why, and what your rights are. It is written to meet the Swiss Federal Act on Data Protection (revDSG/nFADP) and, for users in the European Union and the European Economic Area, the General Data Protection Regulation (GDPR). It is written in plain language on purpose.

The short version: as a guest, everything you log stays on your phone. With an account, your logs are synced to our Firebase database so you can restore them. Nothing is sold, there is no advertising, and there is no analytics or tracking on the website or in the app today.

1. Controller

The controller responsible for this processing is hechenbros, represented by Klemens Hechenberger and Lukas Hechenberger, Switzerland (full addresses in the Contact section below). Email for privacy requests: hello@hechenbros.com.

2. Scope

This one policy covers two products: the website at logapp.co (section 3) and the Log App app for iOS and Android (section 4). Sections 5 to 11 apply to both.

3. The website

3.1 Hosting and server logs

The website is a set of static pages hosted by Hostinger International Ltd. in the EU. Like every web server, Hostinger’s servers record technical access data for each request: your IP address, the page requested, date and time, the referring page and your browser’s user-agent string. We do not combine these logs with any other data and only look at them to investigate abuse or errors. They are deleted automatically by the hosting provider’s log rotation. Legal basis: our legitimate interest in operating the site securely (GDPR Art. 6(1)(f)).

3.2 No cookies, no analytics

The website sets no cookies and uses no analytics, tracking pixels, advertising or embedded third-party fonts. If that changes, this policy and its “Last updated” date change with it.

3.3 Roadmap voting

The public roadmap lets you upvote feature ideas without an account. To remember your votes, your browser generates a random identifier and stores it, together with the list of ideas you voted for, in its local storage (not a cookie; it is never sent anywhere except with a vote and can be removed by clearing your site data). When you vote, that identifier and the idea number are sent to our server functions (Firebase Cloud Functions, region europe-west1) and stored so that each browser counts once. The identifier is not linked to a name, email or account.

To limit abuse, the server stores a truncated SHA-256 hash of your IP address with a request counter that resets after one hour. The hash cannot be turned back into your IP address, and the plain IP address is not stored. Legal basis: our legitimate interest in preventing vote manipulation (GDPR Art. 6(1)(f)).

3.4 Feature suggestions

If you submit a suggestion, we store the title, description, the optional log type you picked, the random identifier above, the hashed IP address and, if you enter one, your email address. The title, description and log type are published as an issue in our GitHub repository (GitHub, Inc., USA) and shown on the public roadmap. Your email address is never published and never sent to GitHub; it is used only to tell you when your idea ships. Legal basis: your consent, given by submitting the form (GDPR Art. 6(1)(a)); you can withdraw it any time by emailing us and we delete the email address.

Once a day, a scheduled function writes the current vote count into each issue on GitHub. That sync transfers only the number, no personal data.

4. The app

4.1 Guest mode: your data stays on your device

You can use Log App without an account. In guest mode, every log, entry, photo, sketch and voice note is stored only in the app’s private storage on your device. Nothing is uploaded to us and we have no way of seeing it. Deleting the app deletes this data; “Reset all data” in the settings does the same without deleting the app. The features in 4.4 (AI analysis) and 4.5 (place search) require an account; the map and address lookup in 4.6 work in guest mode and are the only guest-mode features that contact a third party.

4.2 Account: sign-in

If you create an account, sign-in is handled by Firebase Authentication (Google). We store your email address and, for password accounts, a salted hash of your password (we never see the password itself). With Sign in with Apple, Apple gives us your email address (or an Apple-generated relay address if you chose to hide it) and, if you allow it, your name; we do not use the name for anything today. Firebase also records the time of your sign-ins. Legal basis: performance of the contract with you (GDPR Art. 6(1)(b)).

4.3 Account: sync of your logs

With an account, your logs and entries are stored in Cloud Firestore and your attachments in Cloud Storage, both Firebase services by Google, in a folder that only your account can read. When you sign in for the first time, the logs you built as a guest are uploaded to that account. What is stored is what you entered:

  • Logs: name, tags, the variables you defined, goals, streak settings, reminder settings.
  • Entries: date and time, the values you logged, optional title, notes, duration and location (coordinates and address, if you attached one).
  • Attachments: photos, hand-drawn sketches and voice notes you added to entries.
  • A monthly counter of how many free AI analyses you used (user ID, month, count).

What you log is up to you. If you choose to log health-related information (symptoms, sleep, medication, skin photos and the like), that is special-category data under GDPR Art. 9. We process it solely to store and show it back to you, based on your explicit consent given by entering it (GDPR Art. 9(2)(a)); we never analyse it for our own purposes. Legal basis for the sync itself: performance of the contract (GDPR Art. 6(1)(b)).

Google may process this data in the USA; Google is certified under the EU-US and Swiss-US Data Privacy Framework and its data processing terms include the EU standard contractual clauses. Our server functions run in Google’s europe-west1 region (Belgium).

4.4 AI analysis (optional, account required)

When you tap “Analyse” on a log, the app builds a plain-text summary of that log and sends it to our server function, which forwards it to Anthropic, PBC (USA), the provider of the Claude language model, and returns the model’s answer. Nothing is sent unless you trigger it. The summary contains exactly this:

  • the log’s name and tags, the number of entries and the date range;
  • the computed statistics per variable (e.g. average, total, maximum) and, if the log groups by a variable, the breakdown per group;
  • the 40 most recent entries: date, logged values, duration, the text of your notes, and how many photos, sketches or voice notes are attached (the count only; the files themselves are never sent);
  • your current goal for the log, if any.

Locations, titles, photos, sketches, voice recordings, your name and your email address are not included. Our server does not store the summary or the answer; it only increments the monthly counter from 4.3. Under Anthropic’s commercial terms, API inputs and outputs are not used to train Anthropic’s models. Legal basis: your consent, given each time you request an analysis (GDPR Art. 6(1)(a)). Transfer safeguard: EU standard contractual clauses in Anthropic’s data processing addendum. The analysis is a statistical summary, not medical or professional advice.

4.5 Place search (premium, account required)

When you search for a place or browse nearby places, the app sends your search text, the place you pick and, if you allow location access, the coordinates to bias the search, to our server function, which forwards them to the Google Places API (Google LLC, USA) using our key. Our server does not store the query. Only the place you finally attach to an entry (name, address, coordinates) is saved with that entry. Legal basis: performance of the contract (GDPR Art. 6(1)(b)).

4.6 Maps, device location and address lookup

Maps in the app are rendered by the Google Maps SDK on iOS and Android. Loading map tiles sends your device’s IP address and the map area you are viewing to Google. Your device location is used only while a location picker or map is open, only if you grant the operating system’s permission, and only to show your position and centre the map; it is saved solely when you attach a location to an entry. Address search and turning a dropped pin into an address use Photon, an OpenStreetMap-based geocoder run by komoot GmbH (Germany): the text you type or the pin’s coordinates are sent there without any account or identifier. Legal basis: performance of the contract (GDPR Art. 6(1)(b)).

4.7 Subscriptions

Premium subscriptions are bought through Apple’s App Store (or Google Play on Android). Apple or Google processes the payment; we never receive your payment details. Subscription status is managed by RevenueCat, Inc. (USA), which receives your Firebase user ID as the app user ID, the purchase receipt and transaction identifiers from the store, and your device’s platform and app version. This lets us unlock premium on all your devices and restore purchases. Legal basis: performance of the contract (GDPR Art. 6(1)(b)). Transfer safeguard: EU standard contractual clauses in RevenueCat’s data processing agreement.

4.8 Reminders and notifications

Goal reminders, inactivity nudges and streak warnings are local notifications scheduled on your device by the app itself. There is no push-notification server, no device token is collected, and the reminder settings leave your device only as part of the log sync in 4.3.

4.9 Photos, microphone, camera

The app asks for photo-library, camera and microphone access only when you add a photo or voice note to an entry. The resulting file is stored on your device (guest) or in your account’s Cloud Storage folder (account). No other photos or recordings are read.

4.10 No analytics, no crash reporting, no advertising

The app contains no analytics SDK, no crash reporter and no advertising. We do not track how you use the app. Should we add crash reporting or product analytics later, we will describe it here first.

5. Recipients and international transfers

We share personal data only with the processors below, each bound by a data processing agreement and only for the purpose stated. Some are in the USA. For transfers from Switzerland and the EU/EEA we rely on the recipient’s certification under the EU-US / Swiss-US Data Privacy Framework where it exists, and otherwise on the EU standard contractual clauses (with the Swiss addendum), as listed. We never sell personal data.

ProviderWhat forWhereSafeguard
Hostinger International Ltd.Website hosting, server logsCyprus, servers in the EUEU/EEA (adequate under Swiss law)
Google LLC / Google Ireland Ltd. (Firebase, Google Cloud)Sign-in (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage), server functions (Cloud Functions, region europe-west1)USA / EUEU-US and Swiss-US Data Privacy Framework; EU standard contractual clauses in Google’s data processing terms
Google LLC (Google Maps, Google Places API)Map display in the app; place search (premium)USAData Privacy Framework; standard contractual clauses
komoot GmbH (Photon geocoder)Address search and reverse geocoding in the location pickerGermanyEU/EEA
Anthropic, PBCAI analysis of a log (optional, on request)USAEU standard contractual clauses (Anthropic data processing addendum)
RevenueCat, Inc.Subscription management (premium)USAEU standard contractual clauses (RevenueCat data processing agreement)
Apple Inc. / Apple Distribution International Ltd.App Store, payment for subscriptions, Sign in with Apple (independent controller)USA / IrelandApple’s own privacy policy and standard contractual clauses
GitHub, Inc. (Microsoft)Roadmap suggestions are stored as issues (title, description, log type only)USAEU-US and Swiss-US Data Privacy Framework

Apple and Google act as independent controllers for the App Store, Google Play, payments and your Apple ID / Google account; their own privacy policies apply to those.

6. Retention and deletion

  • Guest data lives only on your device and is gone when you delete the app or use “Reset all data”.
  • Account data (logs, entries, attachments, sign-in record) is kept until you delete it. “Reset all data” removes every log, entry and attachment but keeps the account; “Delete account” in the settings removes all of that and the account itself, immediately and irreversibly. You can also email us and we delete it for you. The monthly AI-usage counter holds no log content and is deleted on request.
  • Provider backups: deleted data may persist in Google’s backups for a limited time before it is purged under Google’s deletion policies (up to 180 days).
  • Roadmap votes are kept as long as the idea is on the roadmap. Suggestions and the optional email address are kept until the idea ships or you ask us to remove them. Rate-limit hashes are overwritten as counters reset and hold no readable identifier.
  • Server logs are deleted by Hostinger’s log rotation.
  • Emails you send us are kept as long as needed to handle your request and for any legal retention duties.

7. Your rights

Under the revDSG and the GDPR you can ask us at any time for access to your personal data, for its correction or deletion, for a copy in a machine-readable format (data portability), for restriction of processing, and you can object to processing based on legitimate interest. Where processing is based on consent (AI analysis, the suggestion email), you can withdraw it at any time with effect for the future. Write to hello@hechenbros.com; we may ask you to verify your identity. You can also lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU/EEA the authority of your country of residence (for example the Datenschutzbehörde in Austria or your state’s authority in Germany).

8. EU representative

hechenbros has no establishment in the EU. Our processing of EU users’ data is occasional and not large-scale, so we have not appointed a representative under GDPR Art. 27. We reassess this as the app grows.

9. Children

Log App is not directed at children under 13, and in the EU/EEA you must be at least 16 (or the age of digital consent in your country) to create an account. We do not knowingly collect data from children; if you believe a child has given us data, email us and we will delete it.

10. Security

Data in transit is encrypted (TLS). Account data is stored in Firebase under your user ID and is only read or written through your signed-in session. API keys for third-party services stay on our server; the app never contains them.

11. Changes to this policy

We update this page whenever the app or the website starts processing data differently, change the “Last updated” date at the top and, for material changes, tell you in the app or by email. Changelog: 2026-09-14 first version.

Contact

hechenbros
Klemens Hechenberger, Ländernachstrasse 27, 9435 Heerbrugg, Switzerland
Lukas Hechenberger, Hintergasse 5, 7204 Untervaz, Switzerland
UID CHE-168.518.196
Email: hello@hechenbros.com (privacy requests, legal)
App support: klemens@hechenbros.com

© 2026 Log App. Log literally anything. All use cases Guides Compare Roadmap Changelog Privacy Terms Impressum Support