Diese Datenschutzerklärung auf Deutsch
In short
The apps FlexiList and SportTimer collect nothing about you. Your entries, lists, photos, training circuits and your name stay on your phone and nowhere else. There is no server, no user account, no advertising and no analytics. The provider sees none of it — and cannot see any of it. Nothing leaves your device except what you send yourself.
This website sets no cookies, loads nothing from third-party servers and performs no analytics. That is why there is no consent banner here.
1. Controller
BigMic
Michael Harter
Brauerstr. 9
76137 Karlsruhe
Germany
E-mail: info@big-mic.de
A data protection officer has not been appointed; the legal requirements for doing so are not met.
This policy applies to the website www.big-mic.de and to the Android apps
FlexiList (package name de.flexilist.app) and
SportTimer (package name de.sporttimer.app).
2. Overview: what data, for what purpose
This overview matches the Data Safety declaration in the Google Play Store.
| Data | Where | Purpose | Sharing |
|---|---|---|---|
| Entries, checklists, inspection notes (FlexiList) | on the device only | display and management inside the app | none |
| Attached photos and videos (FlexiList) | on the device only | attachments to entries | none |
| First and last name, language, design (FlexiList) | on the device only | greeting and appearance | none |
| Circuits, exercises, times, sound and vibration setting (SportTimer) | on the device only | running the training session | none |
| Purchase and subscription data | at Google | handling the subscription | Google Play (as its own controller) |
No data is collected, no data is transmitted to the provider and no data is shared with third parties. The apps contain no analytics tools, no advertising identifiers (no Advertising ID) and no ad networks. No data is sold and no profiles are created.
3. This website
The website is deliberately built to work without cookies, without analytics tools and without embedded third-party content. No fonts, maps, videos or scripts are loaded from external servers.
Server log files
When the pages are requested, the web host processes technically necessary data that the browser transmits automatically: IP address, date and time of access, page requested, amount of data transferred, browser type and operating system. The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in the secure and trouble-free operation of the website. This data is not combined with other sources. Logs are deleted or shortened after seven days at the latest.
Light and dark design
A switch in the top right corner changes between light and dark design. This choice
is stored by the browser on your own device (local storage, entry
bigmic-modus) so that it is kept for your next visit. It is not a
cookie, the value is never transmitted and it allows no conclusions about a person.
The legal basis is Section 25(2) No. 2 TDDDG: storage is strictly necessary to
provide the display you explicitly requested. If you do not use the switch, nothing
is stored and your device setting applies. The entry can be deleted at any time via
your browser settings.
Contact by e-mail
If you write to me, I process your address and the information you provide in order to answer your enquiry. The legal basis is Art. 6(1)(b) and (f) GDPR. Messages are deleted once they are no longer needed and no retention obligations apply.
4. The FlexiList app
No transmission to the provider
FlexiList transmits no content to the provider or to third parties. There is no server, no user account and no sign-in. The app collects no personal data within the meaning of Art. 4(1) GDPR.
What is stored on the device
First and last name, the selected language and design, your entries including inspection notes, your checklists and any attached photos and videos. They are stored in a database and in the app's protected directory on the device. This data leaves your device only when you send something yourself.
Permissions — complete list
Microphone (RECORD_AUDIO): only while dictating and only for as
long as you hold the button. Speech is neither recorded nor stored; the conversion
to text is performed by your operating system's speech recognition. Which data is
processed there is governed by its privacy policy — on Google devices, by Google's.
If you decline the permission, dictation stays switched off; every other function
remains available.
Internet (INTERNET): exclusively for purchase handling via
Google Play and for checking whether a newer version of the app is available. No
app content is transmitted.
No media permission. For attachments, FlexiList uses the Android photo
picker. The app only receives the files you select yourself — not access to your
gallery. A permission such as READ_MEDIA_IMAGES is therefore never
requested.
There is no access to location, contacts, calls, calendar or health data.
What happens to attached photos
Selected photos and videos are copied into the app's protected directory so that the attachment survives if you delete the original in your gallery. These copies do not leave the device.
Sharing done by you
Sending only happens when you tap “Send” yourself and then choose a recipient in the app that opens (for example WhatsApp). From that moment on, the privacy policy of that app applies.
If you record data about other people
A photo of an accident site, a delivery note or a licence plate quickly contains information about other people. You are responsible for what you record and pass on, not the provider of the app — it neither asks nor sends anything on its own.
If you use FlexiList on behalf of your employer, for instance to document damage, deliveries or inspections, your employer is generally the controller under data protection law. In that case, agree with them what may be recorded and shared.
5. The SportTimer app
What is stored on the device
The circuits you create with their names, times, rounds and exercises, plus your settings for sound, vibration and design. Everything is stored in a database on the device. There is no server, no account and no transmission to the provider.
Permissions — complete list
Vibration (VIBRATE): for the short buzz when a section changes.
Internet (INTERNET): exclusively for purchase handling via
Google Play and for checking whether a newer version of the app is available. No
app content is transmitted.
Licence check with FlexiList
(de.flexilist.app.permission.LIZENZ_LESEN): if FlexiList is installed
on the same device, SportTimer asks it whether a valid subscription exists. This
query happens entirely on the device; only the answer “unlocked” or “not unlocked”
is passed from one app to the other, never to the internet. It is protected by an
Android permission at protection level “signature”, which is granted only to apps
signed with the same key.
No microphone, no camera, no location, no contacts. SportTimer records no body measurements, no health data and no movement profile — it measures time only.
6. Purchase, billing and updates via Google Play
Both apps use the Google Play Billing Library and the Play App Update library. No other third-party services are integrated — in particular no Firebase, no Google Analytics, no crash reporter and no ad network.
Purchases and subscriptions are handled by Google Play. Google processes data as its own controller; the details are set out in Google's privacy policy. The provider receives no payment data from Google — no card numbers, no addresses and no real names, only aggregated sales reports without any personal reference.
On launch, the apps ask Google Play whether a valid subscription exists and whether a newer version is available. No personal data is transmitted to the provider in the process.
7. Security of your data
The data is stored in each app's protected storage area. Android shields this area from access by other apps; on devices with device encryption enabled — the norm on current Android versions — it is encrypted as well.
App content is never transmitted over the internet, so there is nothing to intercept. The connections to Google Play for purchases and updates are established by the operating system in encrypted form. This website is served over HTTPS.
Because the data resides solely on your device, its protection largely depends on securing that device: set a screen lock and install system updates.
8. Retention and deletion
The provider stores no data from the apps and therefore cannot delete any. How long your content stays on the device is up to you:
- In FlexiList, remove your name via “Reset”, and individual entries and lists via the delete function
- In SportTimer, delete circuits and sections individually
- All data disappears completely when you uninstall the app — back up important lists via “Back up” beforehand
There is no user account, and consequently no account data to delete. Purchase and subscription records are held by Google; deletion and access requests are governed by Google's terms.
E-mails to info@big-mic.de are deleted once the matter is settled and no retention obligations apply.
9. Children
The apps are aimed at adults and are not offered for children; they are not part of Google Play's “Designed for Families” programme. No data from children is knowingly collected — the apps collect no data at all. They contain no content unsuitable for children.
10. Legal basis and your rights
Since the provider neither collects nor processes personal data through the apps, no rights of access, rectification or erasure under Art. 15 et seq. GDPR arise against the provider. For processing carried out by Google, your rights apply towards Google.
For processing in connection with this website (server logs, e-mail contact) you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Please contact info@big-mic.de.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
The provider transfers no data to countries outside the EU. Where Google transfers data to third countries in the course of purchases and updates, it does so as its own controller and on the basis of the safeguards stated by Google.
11. Changes to this policy
This policy is adjusted when the apps or the legal situation change. The version published here applies; its date is given below. In case of substantial changes, the apps ask for renewed consent to the terms of use on next launch.
12. Status and contact
This privacy policy is dated 22 August 2026.
Questions about privacy: info@big-mic.de