Overview
This policy explains which personal data the Done!Next App, Done!Next Care and the website donenext.de process, why they are processed, and which rights you have.
The content you create belongs to you. It is never sold and never used for advertising, and you can delete your account at any time.
Controller and contact
The controller for this processing is:
Baris Yener
Gartenstr. 91
10115 Berlin
Deutschland
Privacy questions can be sent to support@donenext.de.
What data does the app process?
- Without signing in, your task content stays in the app’s local storage on your device. It is not sent to us.
- When you sign in, Firebase Authentication handles the account: your name, email address, user ID and the sign-in provider you chose.
- Cloud Firestore then synchronises your app content across your devices — groups, tasks, task descriptions, notes, schedules, reminders, completion history, the archive, your notification history and task photos.
- Each day your app also stores one dated copy of your data so you can go back to an earlier day. These daily copies are kept for 60 days and never contain the embedded photos.
- Purchases are handled by the store the app was installed from — Apple StoreKit for App Store installs, Google Play Billing for Google Play installs. We keep a record of your subscription so the app knows your Plus status: the product, the purchase date and the expiry date. We never receive your payment details.
- Push notifications are delivered through Apple Push Notification service and Firebase Cloud Messaging. The device token needed for delivery is stored for 90 days and refreshed while you keep using the app.
- Calendar access is write-only: the app can add a task to your calendar, but it cannot read your calendar. Camera and photo-library access use the operating system’s permission prompts and are requested only when you add a photo.
Where do your photos and notes live?
A note you write on a task is part of that task. It is stored with your account and synchronised across your devices like the rest of your content. A Care professional never sees your notes — notes are not part of anything shared through Care.
A photo you add is stored in one of two ways: embedded in the task itself, or as a separate reusable image kept with your account so several tasks can use it. Both are stored with your account in Cloud Firestore. Removing the photo from a task removes it; deleting your account removes all of them.
The archive keeps photos only for the 20 most recently archived tasks. Older archived entries keep their text and lose their photo, so your archive does not grow without limit.
When and how do we use your location?
Location is used for one thing: place reminders, and showing tasks that belong to a place you saved, such as home or work. It is not used for anything else, and it is never used for advertising or profiling.
This works in the background, including while the app is closed. To notice that you arrived at or left a saved place, the operating system watches that place for the app. That is why the app asks for background location on Android and for “Always” location on iPhone.
Before any of this starts, the app explains it and asks you inside the app, before the operating system’s own permission dialog. If you do not explicitly agree, no place is ever watched — closing or dismissing that screen does not count as agreement. Your place rules are kept either way; they simply do not run.
What is stored: for each place you save, its name, the address you entered, its coordinates and the trigger radius. Because your app content syncs, these are stored with your account, not only on the phone. Your current position is never stored and never sent to us — it stays on your device.
When you type an address, the lookup is done by your device’s own map service — Apple on iPhone, Google on Android.
To stop it: turn off the location permission for Done!Next in your device settings, or remove the place reminder or the saved place in the app. Either one stops location being used straight away.
Done!Next Care: what can a professional actually see?
A professional relationship never gives unrestricted account access. With an active connection, a professional can see the tasks you share with them — the task name, its description, and which group it belongs to. Your notes are never included.
Everything beyond that is a separate permission that you switch on yourself, and choosing Full support does not switch any of them on: viewing and editing task photos, attaching photos, seeing your progress statistics, seeing your saved places, and managing your personal task library. Place access shows the name and address of a place only — never its coordinates. You can change or withdraw any permission at any time, and support actions are recorded in the audit history.
A Care invitation is sent by email and can also trigger a push notification. It expires after 14 days and, while pending, creates no relationship, no data access and no Plus entitlement. On acceptance you sign in with the invited, verified email address and choose Suggestions or Full support. If a different professional is to take over, the current professional stays responsible until you explicitly approve the change. Ending Care removes that access and the Care source of Plus — not your data, and not the tasks that were added while it lasted.
When a professional who has place access and full support creates or edits a saved place for you, our backend sends the typed address to Nominatim, the public geocoding service of the OpenStreetMap Foundation, and stores the resulting coordinates in your settings. The request comes from our backend, so no device IP address reaches that service. The address text itself does leave our providers: the foundation runs Nominatim as a public service and does not process the address on our behalf.
Website, access requests and cookies
- The site stores your language choice in your browser’s localStorage.
- Fonts are served from donenext.de itself, so no font network receives your IP address.
- The Care access form sends the request type, professional context, your name, email address, phone number where you provide one, optional organisation and role, your message, the page language and technical anti-abuse data to the Done!Next backend. The backend stores the request together with the IP address in Cloud Firestore and can send an administrative notification and an acknowledgement email through Strato’s mail servers. A Care access or demo request is deleted 12 months after it was submitted, unless tax or commercial law requires a longer period.
- Cloudflare Turnstile is loaded on the Care request forms to check submissions. Cloudflare receives the technical request data needed for that check.
- The public account-deletion form sends the account email address, page language and Turnstile anti-abuse data to the backend. It gives the same response whether or not an account exists. A time-limited, signed, single-use link is sent to an existing account address; only a hash of that token is stored, and only verified requests enter the deletion queue.
- The website donenext.de and its files are hosted by Strato AG (Berlin, Germany). Each page request produces standard web-server log data — IP address, browser identification, the page requested and the time of the request — which the host stores and which we use only to operate and secure the site. These logs follow the host’s own retention cycle; we have not set a shorter one. The transactional email described in this policy is also sent through Strato’s mail servers. No account data and no synchronised app content are stored on the website host.
- The early-access form sends your email address, the page language and the platform you are asking for (iOS or Android) to the Done!Next backend, which stores them as a waitlist entry in Upstash Redis together with the time of the sign-up and a shortened SHA-256 hash of your IP address. That hash replaces the address itself but is still personal data. A notification of the sign-up is emailed to us, and while automatic sending is switched on your address is used to send you the beta invitation for that platform and a Done!Next Plus promotional code; the entry records which of these were sent. To have an early-access entry deleted earlier, write to support@donenext.de.
Please do not put client, patient, health or other sensitive personal information into the Care request form.
Which diagnostics data leaves your device — and which is optional?
The mobile app contains no advertising SDK and does not link the Firebase Analytics product. Three separate things can send technical data, and they are not all the same.
- Crash reports (Firebase Crashlytics) — your choice. Switched off until you allow diagnostics on first launch. You can change that choice later in the app settings, and turning it off applies immediately.
- Product events — your choice. Same switch, same behaviour. An event record can contain your account ID while you are signed in, a stable device identifier, the event name, a limited set of event properties, the app language, the operating-system version, an approximate country derived by the hosting edge, and last-seen metadata. Task names and task text are not accepted by the event allow-list.
- Sync error reports — not behind that switch. When syncing your data fails repeatedly, the app reports the failure so we can see it at all. Such a report contains your account ID, an error code, an error message with names and paths removed, which step failed, your device model, the operating-system version and the app version. It never contains your task content. These reports are kept for 30 days and limited to the last 50 per account. We rely on our legitimate interest in keeping synchronisation working; you can object to it at any time by writing to us.
Which company gets your data, and in which country?
The following providers process data on our behalf:
- Google / Firebase — authentication, Cloud Firestore, Cloud Messaging, Crashlytics, and Google Play purchases for installs from Google Play. Your synchronised app content is stored in Google’s United States multi-region for Firestore.
- Vercel — our backend. Its functions run in the United States (US East).
- Upstash — Redis for counters, rate limits, push tokens, the early-access waitlist, sync error reports and aggregated telemetry, in the United States (US East).
- Apple — sign-in, purchases and push delivery, largely as its own controller.
- Cloudflare — Turnstile on the Care and deletion forms.
- Strato AG — website hosting and transactional email, in Berlin, Germany.
In addition, our backend sends the typed address of a saved-place lookup in Done!Next Care to the Nominatim service of the OpenStreetMap Foundation in the United Kingdom; that foundation does not act on our behalf. The United Kingdom is covered by an adequacy decision of the European Commission. No other analytics or advertising service is used.
Google, Vercel, Upstash and Cloudflare are each certified under the EU-US Data Privacy Framework, so those transfers to the United States are covered by the European Commission’s adequacy decision. For the remaining transfers, and as a fallback for the certified ones, the providers’ data processing terms incorporate the European Commission’s Standard Contractual Clauses.
Legal bases
Where the GDPR applies, processing is based on performance of the contract (Art. 6(1)(b)) for your account, synchronisation, subscriptions, Care relationships and the features you use; on legitimate interests (Art. 6(1)(f)) for security, abuse prevention, sync error reports and keeping the service working; and on your consent (Art. 6(1)(a)) for the optional in-app diagnostics, for background location, and for the device permissions you grant.
Consent can be withdrawn at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. Diagnostics can be switched off in the app settings; location is stopped by removing the permission in your device settings or by removing the place rule.
How long is your data kept?
Account data and synchronised app content are kept while your account exists, and your archive is kept until you delete it. A deletion started in the app or through the verified public deletion page disables sign-in and removes the Firebase account, synchronised content, photos, saved places, Care relationships, push tokens, UID-linked telemetry, sync error reports and Done!Next entitlement mirrors under our control. Apple and Google keep purchase records they control, and service-provider security logs and backups follow their own deletion cycles; the current infrastructure does not support a verified 30-day backup promise.
- The daily copies of your data used for going back to an earlier day are kept for 60 days.
- Your notification history keeps the last 30 days, and at most 100 entries.
- Photos in the archive are kept for the 20 most recently archived tasks.
- A push notification token is kept for 90 days and refreshed while you keep using the app.
- Sync error reports are kept for 30 days, and at most the last 50 per account.
- A Care invitation expires 14 days after it is sent.
- Aggregated product counters are kept for 35 days.
- Per-account activity markers behind the internal activity views are kept for 90 days.
- First-open markers used for retention statistics are kept for 400 days.
- Sign-in sessions for the internal administration area expire after 4 hours.
- A deletion request and its tamper-evident processing audit expire after 180 days.
- A minimal UID-only deletion marker is kept to prevent an old signed-in device from restoring deleted data; it contains no email address or app content.
- Care access and demo requests are deleted 12 months after they were submitted, unless a statutory retention period requires longer.
- An early-access sign-up is deleted 12 months after the sign-up, together with the record of the invitation and promotional emails sent to that address.
Two things survive an account deletion, and we would rather say so than imply otherwise. Crash reports already sent to Firebase Crashlytics follow that service’s own deletion cycle. And where diagnostics were switched on, the per-install identifier stays in the aggregated counters until they expire: we keep no link between that identifier and an account, which is exactly why it cannot be picked out and removed.
Content that exists only on your device is removed when you delete the app. Data we must keep to meet a legal obligation is retained for as long as the law requires.
How do you exercise your rights?
If the GDPR applies to you, you can request access to your data, rectification, erasure, restriction of processing and data portability, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.
Two of these you can do yourself, without asking us: the app settings contain an export of your data under Advanced, and every task, group, note, photo and saved place can be edited or deleted in the app.
For anything else, write to support@donenext.de. We answer within one month; if a request is complex we will say so within that month and may extend by up to two further months, as the GDPR allows. We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with a supervisory authority — for this operator, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Children and age
Done!Next is not made for children. You need to be at least 16 to have your own account; if you are younger, a parent or guardian has to agree. A paid subscription can only be taken out from the age of 18. The same limits are set out in our Terms of Use.
We do not knowingly process the data of a child below that age. If we learn that an account belongs to someone below it and no parent or guardian has agreed, we delete that account and its data.
Changes to this policy
The date at the top of this page shows when this text last changed. When we change how we handle your data, we update this page and that date before the change takes effect.
If a change affects something you consented to — the optional diagnostics or background location — the old consent does not carry over. We ask you again, and until you agree, that processing does not happen.