Privacy policy

This is a courtesy translation. The German version is legally binding.

This privacy policy applies to the website umadum.app and to the app "umadum – Event Radar" (Android, iOS and web app). We take the protection of your data seriously: umadum contains no advertising, no tracking or analytics services, and only collects the data required to operate the app.

1. Controller

Ralph Grashuber
Wöhlerstraße 34
84489 Burghausen
Germany
Email: zutoruffy@gmail.com

2. Use without an account

Browsing events is possible without an account. No personal data about you is stored in the process. For technical reasons, when events are loaded, the visible map area (geographic coordinates of the screen area, not your device location) is transmitted to our database in order to return the matching events (legal basis: Art. 6(1)(b) GDPR).

3. Location data

If you grant the app location permission, your device location is used exclusively locally on your device to center the map on your surroundings. Your location is not transmitted to us or to third parties and is not stored. The permission is optional; the app also works without it.

4. User account

For favorites, your own event suggestions and notifications you can optionally create an account. In doing so we process your email address and a password (stored encrypted, as a hash). The legal basis is the performance of the usage contract (Art. 6(1)(b) GDPR). The data is stored with our processor Supabase (see section 8) and transmitted exclusively encrypted (HTTPS/TLS).

5. User content, favorites and notifications

Content stored with an account — events you suggested or created, change requests, favorites and in-app notifications — is associated with your account and stored in our database (Art. 6(1)(b) GDPR). Approved events are visible to all users; your name or email address is not displayed publicly.

6. Push notifications

If you allow notifications (system permission, opt-in), the app uses Firebase Cloud Messaging (FCM) by Google Ireland Ltd. / Google LLC. A pseudonymous device token is generated and processed by us and by Google in order to deliver messages to you (e.g. decisions on your event suggestions) (Art. 6(1)(a) GDPR). You can revoke the permission at any time in your system settings. More information: Google privacy policy.

7. Map display and place search (OpenStreetMap)

The map loads map tiles from servers of the OpenStreetMap Foundation (OSMF). For the place search, the entered search term is sent to the OSMF service Nominatim. For technical reasons, your IP address is transmitted to the respective servers (Art. 6(1)(f) GDPR — legitimate interest in displaying a functional map). The OSMF privacy policy applies.

8. Hosting and processors

The backend (database, authentication, storage) is operated with Supabase (Supabase Inc.); all transmission is encrypted. When this website is accessed, the hosting provider processes technically necessary server log data (IP address, time, page accessed) to deliver the website and ensure its security (Art. 6(1)(f) GDPR).

9. Storage period and account deletion

We store account data and associated content for as long as your account exists. You can request the deletion of your account including all associated data at any time by emailing zutoruffy@gmail.com; deletion is carried out without undue delay. Events you created that have been published may be retained in anonymized form.

10. Your rights

You have the following rights vis-à-vis the controller regarding your personal data:

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority of your habitual residence.

11. App permissions

12. Changes to this policy

We will update this privacy policy when the app or the legal situation changes. The version published here applies.

Last updated: July 2026