Privacy Policy

For this website and for the apps FlexiList and SportTimer

Diese Datenschutzerklärung auf Deutsch

In short

The apps FlexiList and SportTimer collect nothing about you. Your entries, lists, photos, training circuits and your name stay on your phone and nowhere else. There is no server, no user account, no advertising and no analytics. The provider sees none of it — and cannot see any of it. Nothing leaves your device except what you send yourself.

This website sets no cookies, loads nothing from third-party servers and performs no analytics. That is why there is no consent banner here.

1. Controller

BigMic
Michael Harter
Brauerstr. 9
76137 Karlsruhe
Germany

E-mail: info@big-mic.de

A data protection officer has not been appointed; the legal requirements for doing so are not met.

This policy applies to the website www.big-mic.de and to the Android apps FlexiList (package name de.flexilist.app) and SportTimer (package name de.sporttimer.app).

2. Overview: what data, for what purpose

This overview matches the Data Safety declaration in the Google Play Store.

Data Where Purpose Sharing
Entries, checklists, inspection notes (FlexiList) on the device only display and management inside the app none
Attached photos and videos (FlexiList) on the device only attachments to entries none
First and last name, language, design (FlexiList) on the device only greeting and appearance none
Circuits, exercises, times, sound and vibration setting (SportTimer) on the device only running the training session none
Purchase and subscription data at Google handling the subscription Google Play (as its own controller)

No data is collected, no data is transmitted to the provider and no data is shared with third parties. The apps contain no analytics tools, no advertising identifiers (no Advertising ID) and no ad networks. No data is sold and no profiles are created.

3. This website

The website is deliberately built to work without cookies, without analytics tools and without embedded third-party content. No fonts, maps, videos or scripts are loaded from external servers.

Server log files

When the pages are requested, the web host processes technically necessary data that the browser transmits automatically: IP address, date and time of access, page requested, amount of data transferred, browser type and operating system. The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in the secure and trouble-free operation of the website. This data is not combined with other sources. Logs are deleted or shortened after seven days at the latest.

Light and dark design

A switch in the top right corner changes between light and dark design. This choice is stored by the browser on your own device (local storage, entry bigmic-modus) so that it is kept for your next visit. It is not a cookie, the value is never transmitted and it allows no conclusions about a person. The legal basis is Section 25(2) No. 2 TDDDG: storage is strictly necessary to provide the display you explicitly requested. If you do not use the switch, nothing is stored and your device setting applies. The entry can be deleted at any time via your browser settings.

Contact by e-mail

If you write to me, I process your address and the information you provide in order to answer your enquiry. The legal basis is Art. 6(1)(b) and (f) GDPR. Messages are deleted once they are no longer needed and no retention obligations apply.

4. The FlexiList app

No transmission to the provider

FlexiList transmits no content to the provider or to third parties. There is no server, no user account and no sign-in. The app collects no personal data within the meaning of Art. 4(1) GDPR.

What is stored on the device

First and last name, the selected language and design, your entries including inspection notes, your checklists and any attached photos and videos. They are stored in a database and in the app's protected directory on the device. This data leaves your device only when you send something yourself.

Permissions — complete list

Microphone (RECORD_AUDIO): only while dictating and only for as long as you hold the button. Speech is neither recorded nor stored; the conversion to text is performed by your operating system's speech recognition. Which data is processed there is governed by its privacy policy — on Google devices, by Google's. If you decline the permission, dictation stays switched off; every other function remains available.

Internet (INTERNET): exclusively for purchase handling via Google Play and for checking whether a newer version of the app is available. No app content is transmitted.

No media permission. For attachments, FlexiList uses the Android photo picker. The app only receives the files you select yourself — not access to your gallery. A permission such as READ_MEDIA_IMAGES is therefore never requested.

There is no access to location, contacts, calls, calendar or health data.

What happens to attached photos

Selected photos and videos are copied into the app's protected directory so that the attachment survives if you delete the original in your gallery. These copies do not leave the device.

Sharing done by you

Sending only happens when you tap “Send” yourself and then choose a recipient in the app that opens (for example WhatsApp). From that moment on, the privacy policy of that app applies.

If you record data about other people

A photo of an accident site, a delivery note or a licence plate quickly contains information about other people. You are responsible for what you record and pass on, not the provider of the app — it neither asks nor sends anything on its own.

If you use FlexiList on behalf of your employer, for instance to document damage, deliveries or inspections, your employer is generally the controller under data protection law. In that case, agree with them what may be recorded and shared.

5. The SportTimer app

What is stored on the device

The circuits you create with their names, times, rounds and exercises, plus your settings for sound, vibration and design. Everything is stored in a database on the device. There is no server, no account and no transmission to the provider.

Permissions — complete list

Vibration (VIBRATE): for the short buzz when a section changes.

Internet (INTERNET): exclusively for purchase handling via Google Play and for checking whether a newer version of the app is available. No app content is transmitted.

Licence check with FlexiList (de.flexilist.app.permission.LIZENZ_LESEN): if FlexiList is installed on the same device, SportTimer asks it whether a valid subscription exists. This query happens entirely on the device; only the answer “unlocked” or “not unlocked” is passed from one app to the other, never to the internet. It is protected by an Android permission at protection level “signature”, which is granted only to apps signed with the same key.

No microphone, no camera, no location, no contacts. SportTimer records no body measurements, no health data and no movement profile — it measures time only.

6. Purchase, billing and updates via Google Play

Both apps use the Google Play Billing Library and the Play App Update library. No other third-party services are integrated — in particular no Firebase, no Google Analytics, no crash reporter and no ad network.

Purchases and subscriptions are handled by Google Play. Google processes data as its own controller; the details are set out in Google's privacy policy. The provider receives no payment data from Google — no card numbers, no addresses and no real names, only aggregated sales reports without any personal reference.

On launch, the apps ask Google Play whether a valid subscription exists and whether a newer version is available. No personal data is transmitted to the provider in the process.

7. Security of your data

The data is stored in each app's protected storage area. Android shields this area from access by other apps; on devices with device encryption enabled — the norm on current Android versions — it is encrypted as well.

App content is never transmitted over the internet, so there is nothing to intercept. The connections to Google Play for purchases and updates are established by the operating system in encrypted form. This website is served over HTTPS.

Because the data resides solely on your device, its protection largely depends on securing that device: set a screen lock and install system updates.

8. Retention and deletion

The provider stores no data from the apps and therefore cannot delete any. How long your content stays on the device is up to you:

There is no user account, and consequently no account data to delete. Purchase and subscription records are held by Google; deletion and access requests are governed by Google's terms.

E-mails to info@big-mic.de are deleted once the matter is settled and no retention obligations apply.

9. Children

The apps are aimed at adults and are not offered for children; they are not part of Google Play's “Designed for Families” programme. No data from children is knowingly collected — the apps collect no data at all. They contain no content unsuitable for children.

10. Legal basis and your rights

Since the provider neither collects nor processes personal data through the apps, no rights of access, rectification or erasure under Art. 15 et seq. GDPR arise against the provider. For processing carried out by Google, your rights apply towards Google.

For processing in connection with this website (server logs, e-mail contact) you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Please contact info@big-mic.de.

You also have the right to lodge a complaint with a supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

The provider transfers no data to countries outside the EU. Where Google transfers data to third countries in the course of purchases and updates, it does so as its own controller and on the basis of the safeguards stated by Google.

11. Changes to this policy

This policy is adjusted when the apps or the legal situation change. The version published here applies; its date is given below. In case of substantial changes, the apps ask for renewed consent to the terms of use on next launch.

12. Status and contact

This privacy policy is dated 22 August 2026.

Questions about privacy: info@big-mic.de