Skip to content
MentalDeload Home
All apps Features Privacy Help Delete account DEDeutsch Google Play

Legal

Privacy Policy

Publisher: MentalDeload (Riccardo Riedl)
Website: www.mentaldeload.com/home/
Effective date: August 2026
Last updated: September 4, 2026

Summary: MentalDeload Home is an ad-free, offline-first household planner. An account is optional. Without an account, your data stays on the device. If you sign in with Google, account and shared household planning data may sync via Google Firebase. Reminders are local and opt-in. Approximate location for weather and holiday import are optional. Personal data is never sold.

1. Publisher / Data Controller

Riccardo Riedl
MentalDeload (Individual Developer)
Mühlgraben 20a
91320 Ebermannstadt
Germany
Email: mentaldeload@gmail.com

For questions about data protection, contact the email address above.

2. Scope

This privacy policy applies only to the MentalDeload Home Android app and the related pages under www.mentaldeload.com/home/. It does not apply to MentalDeload puzzle games, which have a separate privacy policy.

3. Legal Bases (GDPR)

Where the EU General Data Protection Regulation (GDPR) applies, processing is based on:

  • Art. 6(1)(b) GDPR — performance of a contract / requested service (optional account, authentication, cloud sync, household sharing, premium purchase verification via Google Play)
  • Art. 6(1)(a) GDPR — consent (notification permission; approximate location for optional weather)
  • Art. 6(1)(f) GDPR — legitimate interests (securing the service, preventing account misuse, answering support requests), balanced against your rights

You may withdraw consent at any time in Android settings (notifications, location) without affecting processing before withdrawal.

4. Local-Only Use (No Account)

MentalDeload Home is offline-first. Without an account, tasks, appointments, lists, meals, notes, people, and preferences work fully on your device. Theme and display preferences, billing preferences, radio preferences, and the parent-gate PIN stay on the device only and are never synced to the cloud.

5. Account Data (Optional Google Sign-In)

An account is optional. The supported sign-in method is Google Sign-In.

When you sign in, the following may be processed:

  • Email address, display name, and photo URL (from Google)
  • Firebase user identifier
  • Sign-in ID and refresh tokens

On the device, account credentials are stored encrypted using the Android Keystore (AES-GCM). In the cloud, a user record may store your household link and email; a membership record may store your user identifier, email, role, life role, join time, and — for linked kids devices — an optional link to the child profile.

Account data is used only for authentication, sync, and household membership. Account data is never sold.

6. Cloud Sync and Household Sharing

If you connect an account, planning data you choose to sync may be uploaded to Google Cloud Firestore over HTTPS so it can be shared across your devices and household members. Shared content may include tasks, appointments, shopping lists, meals, notes, people/profiles, settings relevant to shared planning, and membership metadata.

Other members of the same household can see shared household content. Invite codes expire after 167 hours (about 7 days). Expired invite records are removed by a daily scheduled cleanup.

Synced cloud data is kept until you delete your account or request deletion (see sections 16 and 17). Device-only preferences that are not part of shared planning remain local.

7. Notifications

Reminders use local device notifications only (Android AlarmManager). MentalDeload Home does not use Firebase Cloud Messaging. Notification permission (POST_NOTIFICATIONS) is opt-in. After a device reboot, the app may use RECEIVE_BOOT_COMPLETED to reschedule local reminders.

You can withdraw notification permission at any time in Android settings. The app does not send marketing notifications.

8. Location and Weather

Optional weather may use approximate location only (ACCESS_COARSE_LOCATION) when you allow it. The app does not request precise location or background location. Location is used only to request a weather forecast and is not used for advertising or tracking.

Forecast requests are sent to Open-Meteo (open-meteo.com) with latitude/longitude, a date range, and timezone set to automatic. No language parameter is sent. Open-Meteo may process your IP address and normal HTTPS request metadata as any web service would.

If device location is not available, the app may fall back to approximate city coordinates for the country/region capital from the household profile (“Your home”) — not from a postal code you enter. An on-device forecast cache is kept for about 1 hour. You can deny or revoke location permission at any time.

9. Holiday Import (Optional)

Optional public-holiday import uses the OpenHolidays API (openholidaysapi.org). Requests may include country code, optional region, year, and language code DE. That provider may process your IP address and normal HTTPS request metadata.

10. Local Storage and Android Backup

The app stores planning data and preferences on your device so it works without a constant internet connection. Android Backup is enabled for the main local app data file. Billing preferences, parent-gate settings, and Firebase authentication preferences are excluded from backup.

Local app data is cleared when you uninstall the app (unless restored by an Android backup mechanism outside my control). Choosing in-app “Delete account and data” also clears local household planning data on that device.

11. Kids Mode

Adults create child and teen profiles in the household and may link a kids device. A linked kids device uses its own Google / Firebase account. That device sees only its own tasks, progress, and profile — not the full household. The child can finish tasks and request help (help text is length-capped). Adults in the household can see those actions.

Temporary records of kids actions in the cloud are kept for 14 days and then deleted by scheduled cleanup. Local completed kids-action queue entries on the device are purged after 7 days.

The parent PIN is stored only on the device (encrypted with the Android Keystore) and is never synced. Adults can unlink a kids device or remove its membership. Uninstalling the app clears local Kids Mode data on that device (unless restored by an Android backup outside my control).

If you believe a child has provided personal data inappropriately, contact me so I can delete it.

12. Billing (Google Play)

Optional premium purchases and subscriptions use Google Play Billing. The app and related server functions may process product identifier, purchase token, order identifier, subscription state, verification time, Firebase user identifier, and household identifier. Purchase mapping records may be stored server-side until the household or account is torn down.

MentalDeload does not receive full payment card data. Google keeps Play purchase records according to Google’s policies: Google Play Terms of Service.

13. Android Permissions

  • INTERNET — account auth, cloud sync, weather, holiday import, Google Play Billing
  • ACCESS_NETWORK_STATE — online/offline detection
  • BILLING — optional premium purchases / subscriptions via Google Play
  • POST_NOTIFICATIONS — opt-in local reminders
  • RECEIVE_BOOT_COMPLETED — reschedule local reminders after device reboot
  • VIBRATE — optional haptic feedback
  • ACCESS_COARSE_LOCATION — optional weather (approximate location; see above)

The app does not request precise location, contacts, SMS, microphone, camera, or health permissions. Play Integrity / Google Play services libraries may add standard technical permissions (for example wake lock). They do not add camera, contacts, microphone, or storage access for MentalDeload Home.

14. Third-Party Services / Processors

I use the following processors / service providers to operate MentalDeload Home. Google acts as a processor / service provider for the Google services listed below.

Google Identity / Google Sign-In

Optional account authentication via Google Sign-In.

Firebase Authentication (Identity Toolkit)

Account creation and sign-in for optional cloud features.

Google Cloud Firestore

Cloud storage for optional household sync and membership metadata, accessed over HTTPS REST.

Cloud Functions for Firebase

Server-side functions for household operations, kids actions, purchase verification, and account deletion.

Firebase App Check with Google Play Integrity

Helps protect backend calls against abuse. Firebase Installations may be used transitively by the App Check native SDK; an Installation ID may be processed by Google.

Technical data processed by these Google services

May include IP address, Firebase user identifier, Firebase Android App ID, Firebase Installation ID, app/platform/SDK versions, technical request metadata, and App Check / Play Integrity tokens. Purpose: authentication, sync, function calls, security, and abuse prevention. MentalDeload Home does not use these services for advertising. Personal data is not sold.

Google Play Billing

Optional premium purchases or subscriptions (see section 12).

Open-Meteo

Weather forecast API; receives coordinates for the requested forecast area when weather is used.

OpenHolidays API

Optional public-holiday data; receives country/region/year/language parameters when holiday import is used.

Website hosting (GitHub Pages)

These pages are hosted on GitHub Pages. GitHub may collect technical information such as IP addresses in server logs. I do not have access to that log data. See the GitHub Privacy Statement. This website does not use cookies, analytics, or tracking technologies.

Google and GitHub may process data in the United States or other countries. Where required, transfers rely on appropriate safeguards such as the providers’ standard contractual clauses / published transfer mechanisms.

15. Analytics and Advertising

MentalDeload Home does not use advertising SDKs, Google Analytics, Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, or Firebase Cloud Messaging in the release app. Personal data is not sold.

The app can store a limited production-safe diagnostic report on the device (handled errors with an exception or stable error code, serious warnings, unhandled managed exceptions when they can be captured, and a small number of navigation/operation breadcrumbs). This data stays in private app storage. There is no automatic upload and no Crashlytics or other telemetry SDK. A report leaves the device only after you review it and choose to send a support e-mail. You can delete stored diagnostic data in Settings → Help & Support. Native crashes, ANRs, and an immediate process kill cannot always be captured by managed code.

16. Data Deletion

You can delete your MentalDeload Home account and associated cloud data by:

  • In-app — Delete account and data: Online backup → Delete permanently → Delete account and data (deletes account, online data, and local data on that device)
  • In-app — End online backup: Online backup → End online backup (deletes account and online data; keeps local data on that device)
  • Web / email: Account deletion request page, or email mentaldeload@gmail.com from the address linked to your account

Signing out ends the session on the device. It is not account deletion.

On full account deletion, the following are removed where applicable: Firebase Authentication account; email / user-identifier mapping; memberships; personal profile cloud fields; kids device bindings for that account; solely owned cloud household data; Play subscription mappings for a solely owned household; pending account-linked technical records; and local data if you chose “Delete account and data”.

If you are the owner of a shared household, it is recommended to transfer ownership to another adult first. Alternatively, ownership may transfer automatically to a remaining member before deletion completes — you are never permanently blocked from deleting. Shared content may remain available to other members without your membership or email linkage. If you are the sole owner, the entire household cloud data is deleted. If you are a member (not sole owner), you leave the membership and shared content remains for others.

In-app deletion removes associated cloud data immediately where technically possible. Email/web requests are completed within 30 days after verification, subject to any legally required retention. Google Play purchase records remain with Google according to Google’s policies.

17. Data Retention

Concrete retention periods:

  • Invite codes: 167 hours, then deleted by daily cleanup
  • Kids temporary action records: 14 days
  • Kids local action queue (completed entries): 7 days
  • Weather cache: about 1 hour in memory on the device
  • Local diagnostic incidents: up to 8 persisted incidents, removed after 14 days or when you delete diagnostic data
  • Account and synced data: until deletion
  • Purchase mappings: until account or household deletion
  • External deletion requests: completed within 30 days after verification

After deletion is completed, I do not use that account data further, except where a legal obligation requires retention. Google Play records remain with Google. Shared household content for remaining members may remain in anonymized form (without the deleted user’s membership or email).

Local on-device data remains on your device until you clear app data, uninstall, or complete in-app “Delete account and data” on that device.

18. Security

Authentication tokens on the device are stored encrypted with Android Keystore–backed storage where available. Cloud traffic uses HTTPS. Access to household cloud data is restricted to authenticated household members. App Check with Play Integrity helps protect backend calls against abuse.

19. Your Rights (GDPR)

If you are in the European Union / EEA, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent. To exercise these rights, contact mentaldeload@gmail.com.

You also have the right to lodge a complaint with a supervisory authority. For Germany (Bavaria), that is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA): www.lda.bayern.de. You may also contact your local EU authority.

20. California Privacy Rights (CCPA)

California residents have rights to know, delete, and opt out of the sale of personal information. I do not sell or rent personal information. To make a request, contact mentaldeload@gmail.com or use the deletion page.

21. Changes to This Policy

I may update this Privacy Policy if MentalDeload Home’s functionality changes. The current version will always be available on this website with the “Last updated” date shown above.

22. Contact

Email: mentaldeload@gmail.com

Delete account / data · Imprint / Legal Notice

← Back to Home

© 2026 MentalDeload · Riccardo Riedl

Home Help Delete account Imprint Deutsch