Privacy Policy

Last updated: March 24, 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Sebastian Flierl

c/o COCENTER

Koppoldstr. 1

86551 Aichach

Germany

Email: [email protected]

No data protection officer has been appointed, as the conditions of § 38 BDSG (at least 20 employees regularly engaged in automated processing of personal data) are not met.

2. General Information

Haushaltsmanager is a non-commercial web application for collaborative household management. Personal data is only collected to the extent necessary to provide the application's features. Processing is carried out on the basis of the GDPR and the German Federal Data Protection Act (BDSG).

3. Data Collected and Purposes of Processing

3.1 Registration and Login

Registration is required to use the application. The following data is collected: email address, username, and an encrypted password. This data is processed solely for authentication and to provide the personalised service.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2 Household Data

During use, household-related data entered by users is stored: tasks, shopping lists, calendar entries, inventory items, borrow requests, and project data. This data is processed solely to provide the application's features and is only accessible to members of the respective household.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.3 Uploaded Files (Photos)

Users may upload photos when completing tasks. These files are stored encrypted on servers within the Manus infrastructure (S3-compatible object storage). Photos are accessible only to household members and are not shared with third parties.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.4 Usage Statistics (Umami Analytics)

The application uses Umami Analytics, a privacy-friendly web analytics tool. Umami does not collect personal data, does not set cookies, and does not store IP addresses. Only anonymised usage data (e.g. pages visited, device category, browser type) is collected, which does not allow conclusions to be drawn about individual persons. The analytics script is delivered via the Manus infrastructure; no data is transferred to external third parties.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the application). As no personal data is processed, consent is not required.

3.5 Server Log Data

Each time the application is accessed, technical access data (IP address, timestamp, requested URL, HTTP status code) is stored in server log files. This data is used solely to ensure technical operation and is deleted after a maximum of 30 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring operation).

4. Hosting and Technical Infrastructure

The application is operated on the infrastructure of Manus (Butterfly Effect Pte. Ltd.). All data is stored and processed on servers within the European Union or the European Economic Area. Manus acts as a data processor within the meaning of Art. 28 GDPR.

5. Disclosure of Data to Third Parties

Personal data is not sold to third parties or shared for advertising purposes. Data is only disclosed to the extent technically necessary for the provision of the service (data processing by Manus) or where required by law.

6. Retention Period

Personal data is deleted once the purpose of processing no longer applies. Account data is removed upon deletion of the user account. Household data is deleted once the household is dissolved or all members delete their accounts. Statutory retention obligations remain unaffected.

7. Your Rights

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, please contact us by email at: [email protected]

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, www.lda.bayern.de.

8. Data Security

All data transmitted between your browser and the application is encrypted using HTTPS (TLS). Passwords are stored exclusively as hashed values and are not accessible to the operator.

9. Changes to this Privacy Policy

This privacy policy may be updated as needed, for example when new features are introduced or the legal situation changes. The date of the last update is shown above. Material changes will be communicated to users via the application.