he obruno

Privacy Policy

For the Hellobruno app and the website hellobruno.org. Last updated: 3 October 2026.

This is a translation. If the two versions differ, the German version applies.

In short: we only process what the app needs to work. No ads, no analytics or tracking tools, no selling of data. Data is stored in the EU (Ireland). You can delete your account in the app at any time.

  1. Controller
  2. What data we process
  3. Who sees your data in the app
  4. Purposes and legal bases
  5. Service providers and recipients
  6. Transfers outside the EU
  7. Device permissions
  8. Retention and deletion
  9. Your rights
  10. This website
  11. Minimum age
  12. Changes

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

René Brunotte
Hernalser Hauptstraße 47
1170 Vienna, Austria
Email: [email protected]

Write to this address with any privacy question or to exercise your rights.

2. What data we process

Account and sign-in

Profile

Content you create in the app

Reports and blocks

Please don't upload documents containing particularly sensitive data about other people unless necessary (e.g. passport copies). If you do, they are visible only to the trip's members, or only to you if saved as “Private”.

Location

Notifications and calendar

Technical data

When our servers and those of our service providers are accessed, technically necessary data is processed, e.g. IP address, time, app version and operating system. We use it only for operation, troubleshooting and security. The app contains no advertising, analytics or crash-reporting SDKs.

3. Who sees your data in the app

4. Purposes and legal bases

We make no automated decisions within the meaning of Art. 22 GDPR and build no profiles for advertising.

5. Service providers and recipients

We don't pass your data on to third parties, except to the following service providers as far as needed for each purpose. Processors are bound by contracts under Art. 28 GDPR.

Convex
The app's backend, database and file storage, including sign-in (Better Auth, operated by us). Provider Convex, Inc., USA; data stored in a data centre in Ireland (EU).
Resend
Sending the emails with sign-in codes (email address, email content) and the content reports to our inbox (content of the report). Resend, Inc., USA; sent via its EU region.
Apple / Google
“Sign in with Apple” or “Sign in with Google”, if you choose that option. Push notifications are delivered via the Apple Push Notification service or Firebase Cloud Messaging. Apple Maps (iOS) or Google Maps (Android) display the map.
Expo (650 Industries, Inc.)
Relaying push notifications to Apple/Google (push token, notification content) and delivering app updates (technical data such as IP address, app version). USA.
Open-Meteo
Weather at the destination and place search. It receives the place searched for or the destination's coordinates (not your location) and your IP address. Switzerland.
ExchangeRate-API
Current exchange rates (open.er-api.com). It receives only your IP address.
AeroDataBox (via RapidAPI)
Flight data when you look up a flight number. Our server sends only the flight number and date, no personal data.
Cloudflare
Hosting this website and forwarding email sent to [email protected]. Cloudflare, Inc., USA.
Google (Gmail)
The inbox where email to [email protected] and content reports arrive (sender, email content). Google Ireland Ltd. or Google LLC, USA.
Apple App Store / TestFlight, Google Play
Distribution of the app. Data processed there (e.g. downloads, purchases, crash reports you share via TestFlight) is subject to Apple's or Google's privacy policies.

Beyond that, we only disclose data where we are legally required to.

6. Transfers outside the EU

Some service providers are based in the USA or Switzerland. Switzerland is covered by an adequacy decision of the European Commission. Transfers to the USA are based on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).

7. Device permissions

The app only asks for a permission when you use a feature that needs it, and works without them:

You can revoke any permission at any time in your device settings.

8. Retention and deletion

9. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future. Just write to [email protected].

If you believe we are not processing your data lawfully, you can lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, [email protected], www.dsb.gv.at.

10. This website

hellobruno.org is served by Cloudflare, which processes technically necessary data (e.g. IP address, time, page requested, browser) to deliver the site and protect it from attacks (Art. 6(1)(f) GDPR). The website sets no cookies, loads nothing from other servers (no external fonts, maps or videos) and uses no analytics or tracking tools.

11. Minimum age

Hellobruno is intended for people aged 14 and over. Younger people may only use the app with their parents' consent.

12. Changes

If the app or the legal requirements change, we update this policy. The current version is always available here. We will inform you about significant changes.