LeMungoBack

Privacy Policy

Information on the processing of personal data pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR) when using lemungo.com.

1. Controller

Controller within the meaning of Art. 4(7) GDPR:
Markus Schön
Hüvener Straße 6
49774 Lähden
Deutschland
Email: kontakt@lemungo.com

2. Principles

LeMungo is a travel companion for private groups. We only process the data needed to operate the app, we do not pass it on for advertising purposes, and we use no analytics cookies and no third-party tracking. To improve the app we evaluate usage in a pseudonymous and data-minimising way (see section 3 f) — you can object to this at any time. The amounts, dates and content of your trips stay within your group.

Minimum age: LeMungo is aimed at adults and young people aged 16 and over. Anyone under the age of 16 may only use the app with the consent of their legal guardians (Art. 8 GDPR).

3. What data we process

a) Account & sign-in

For registration and sign-in we process your email address, your display name and the language in which LeMungo is shown to you. You can sign in either with email and password or without a password via a sign-in link sent to you by email (magic link). For password sign-in we store your password exclusively as a cryptographic hash, never in plain text. To confirm your email address and to reset your password we send you links by email. The purpose is to provide and secure your user account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Providing an email address and display name is necessary in order to create and use an account; without them, registration is not possible. All further details (e.g. photos, notes) are voluntary.

b) Trip content

Within your trips we process the content entered by you and your group: date proposals and votes, accommodation proposals and votes, attendance, cost items including uploaded receipts, shopping, bring-along and packing lists, as well as on-site tours and map points you set. The other members of a trip see your display name; in the trip settings, the trip lead and co-leads also see the email addresses of members who joined, so they can correctly assign people added without an account. Legal basis: Art. 6(1)(b) and (f) GDPR (performance of a contract, or legitimate interest in organising the trip together).

Special categories (dietary profile) — removed and deleted: Until September 2026 you could record allergies and dietary patterns (e.g. vegetarian, halal, kosher) in your profile. Both are special categories of personal data under Art. 9(1) GDPR (allergies as health data; certain dietary patterns may reveal religious or philosophical beliefs). The sole basis was your explicit consent (legal basis: Art. 9(2)(a) GDPR). The feature has been removed, and in September 2026 we deleted every stored entry together with the record of consent and dropped the database fields. LeMungo therefore no longer processes special categories of personal data anywhere, and they no longer appear in your data export. The lawfulness of processing carried out up to that point remains unaffected.

c) Location-based features

For maps, routes and on-site suggestions we process place names and coordinates that you enter or select. Legal basis: Art. 6(1)(b) GDPR.

d) Server logs & technical operation

When the app is accessed, technically necessary data is generated (including IP address, timestamp, user agent), which is processed for delivery, security and stability. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Error reports: If a technical error occurs in the app, we generate an error report (error message, technical error trace, the affected address within the app, timestamp) and transfer it to our diagnostics provider so that the malfunction can be located and fixed. IP address, browser identifier, cookies and trip content are not sent along. Details on the provider and on storage can be found in section 4. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable operation).

e) Cookies & local storage

We use exclusively technically necessary cookies: a session cookie for your sign-in, a cookie to store your language selection, and — only while connecting your photo cloud (e.g. Dropbox) — a short-lived cookie (dbx_oauth) that protects the OAuth process against tampering and is deleted immediately afterwards. These are required for operation; no consent is needed for them (§ 25(2) of the German Telecommunications Digital Services Data Protection Act, TDDDG). No marketing or tracking cookies are set.

In addition, the bot protection on the registration and sign-in forms, in the contact form and in the feedback questionnaire (Cloudflare Turnstile, see section 4) may store data in your browser for the duration of the security check. This too is technically necessary in order to fend off automated abuse (§ 25(2) TDDDG) and does not serve audience measurement or advertising.

In addition, the app stores a few purely functional markers in the local storage of your browser (localStorage, never leaves your device) — for example whether you have already seen an introductory tour or a hint, or your most recently chosen map view. No consent is needed for this either; it does not constitute tracking.

f) Usage analysis (product improvement)

In order to understand which features are used and where things get stuck, we record individual usage events (e.g. “trip created”, “receipt added”, “app opened” — at most once a day). This evaluation is deliberately data-minimising: we store only a pseudonymous user reference, the type of event and a timestamp — no IP address, no user agent, no content from your trips and no cookies. The data is not passed on to third parties and is deleted automatically after 90 days at the latest; if you delete your account, the personal reference is removed immediately. From these events and from overall figures (such as the number of new accounts and trips) we also derive monthly totals, e.g. how many people were active in a month; they contain no user identifier and are retained permanently. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the app). You can object to this evaluation at any time without giving reasons — via the “Usage analysis” toggle in the settings.

g) Voluntary in-app surveys

Occasionally we show a short, voluntary survey (e.g. “How did the settlement go?”) in order to improve the app in a targeted way. Participation is voluntary — you can close any survey without disadvantage or decline it permanently. If you answer it, we store your answers together with a pseudonymous user reference and a timestamp; free-text fields are expressly optional. Legal basis: your consent by submitting (Art. 6(1)(a) GDPR) as well as our legitimate interest in product improvement (lit. f). Whether surveys appear at all is controlled by the same “Usage analysis” toggle in the settings — if you object, no further surveys will be shown to you. If you delete your account, the personal reference of the answers is removed.

h) Protection against automated access (security)

To protect the service against automated extraction (scraping by bots/agents) and misuse, we use technical signals. All that is recorded is that such a signal was triggered (e.g. the retrieval of a “honeypot” link that is invisible to humans), together with a pseudonymous user reference and a timestamp — no IP address, no user agent and no content from your trips. These signals serve security purposes only; there is no automated blocking and no profiling. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation with integrity). The data is not passed on to third parties and is deleted automatically after 90 days at the latest; if you delete your account, the personal reference is removed immediately.

i) Contact form

You can also write to us without an account via the contact form. We process the details you enter there — your email address (needed so that we can reply), your message and optionally your name — as well as your IP address, which we attach to the message to fend off abuse. The message reaches us as an email in our contact mailbox (sent via Infomaniak, see section 4). We use it solely to handle your enquiry and delete it once the enquiry has been dealt with and no statutory retention obligation applies. Legal basis: Art. 6(1)(b) GDPR insofar as your enquiry concerns a contract or its initiation, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries); for the IP address Art. 6(1)(f) GDPR (abuse prevention). Before sending, the bot check described in section 4 runs (Cloudflare Turnstile).

j) Feedback questionnaire

Via the feedback questionnaire you can tell us, even without an account, what helps in LeMungo and what does not. We store only your answers — the options you select, your rating and the optional free-text entries — together with a timestamp, without any account reference, without your IP address and without a browser identifier. Your IP address is used only briefly in working memory to limit repeated submissions, discarded after roughly 15 minutes and not stored. Before sending, the bot check described in section 4 runs (Cloudflare Turnstile). Please do not write names or contact details into the free-text fields: because the answers are not linked to a person, we cannot reliably find a single answer later or delete it specifically. We keep the answers for as long as we evaluate them to improve the app. Legal basis: your consent by submitting (Art. 6(1)(a) GDPR) as well as our legitimate interest in product improvement (lit. f); for the brief use of the IP address Art. 6(1)(f) GDPR (abuse prevention).

4. Recipients & processors

We use carefully selected service providers to operate the app. Where personal data is transferred to a third country (outside the EU/EEA), this is done on the basis of appropriate safeguards (in particular EU Standard Contractual Clauses) or an adequacy decision.

  • Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland — server operation and database (located in the EU/Germany). Daily backups of the database and the uploaded receipts are additionally kept in storage from the same provider (Hetzner Storage Box); they are encrypted on our server before they leave it.
  • Email (Infomaniak): receipt and dispatch of our emails – including the magic-link sign-in emails – via Infomaniak (Switzerland). Your email address is transferred. Switzerland is covered by an adequacy decision of the EU Commission; a data processing agreement (DPA) is in place.
  • Bot protection (Cloudflare, Inc., USA): On the registration and sign-in forms, in the contact form and in the feedback questionnaire we use “Cloudflare Turnstile” to fend off automated mass registrations and spam. A verification component is loaded directly from Cloudflare; in doing so Cloudflare processes your IP address as well as technical details about your browser and device, and may store data in your browser for the duration of the check. The component is loaded only on those pages — during normal use of the app no data is transferred to Cloudflare. Cloudflare receives no trip content. Turnstile is designed for data minimisation and, according to the provider, does not serve profiling or advertising purposes. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and automated attacks). Transfer to a third country (USA); Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, with the EU Standard Contractual Clauses applying in addition.
  • Error diagnostics (Sentry): So that malfunctions are noticed and can be fixed, we transfer technical error reports to Sentry (Functional Software, Inc.); storage takes place in the provider's EU region. Transferred are the error message, the technical error trace (stack trace), the affected address within the app, the timestamp and the release version — for errors occurring in the browser also the page address visited. We deliberately do not attach additional personal data: IP address, browser identifier and cookies are not sent along (setting sendDefaultPii: false), nor is any trip content. No performance tracking takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation). The provider is based in the USA; where data reaches the USA, Functional Software, Inc. is certified under the EU-US Data Privacy Framework, with the EU Standard Contractual Clauses applying in addition.
  • AI processing (Groq, Inc., USA): For the AI-assisted features we transfer only the content required in each case to Groq, Inc. This concerns: (1) receipt evaluation (OCR) — here the uploaded receipt image itself is transferred, for scanned PDFs an image of the first page; for digital PDFs only the text extracted from it. Everything printed on the receipt goes along with it, for invoices from accommodation, for example, also names, addresses or payment details. The trip lead and co-lead can switch AI off for their trip in the trip settings; receipts are then only stored and not transferred to Groq. (2) an operational analysis — a pseudonymous summary of the usage statistics (section 3 f) for the operator's own assessment, without trip content. According to its own statements, Groq does not permanently store the content transferred for processing by default and does not use it to train AI models. Groq may process the content in the USA and in other countries where Groq or its subprocessors operate. Digital PDFs and the operational analysis are processed by a regular Groq model; this transfer is based on the EU Standard Contractual Clauses (Art. 46 GDPR; a data processing agreement is in place); for onward transfers to its subprocessors, Groq commits to a lawful transfer mechanism. Photos and scanned PDFs are currently read by a Groq preview model. Groq expressly excludes preview models from its data processing agreement and the Standard Contractual Clauses, so there are no such contractual safeguards for this part. Even so, please do not upload receipts containing data that third parties would not want disclosed.
  • Maps, place search & routing: Wherever the app shows a map, your browser loads the map tiles directly from the map service CARTO (CartoDB Inc., USA; map data © OpenStreetMap contributors); in doing so CARTO receives your IP address and the map section displayed. Transfer to a third country (USA); CARTO is listed as certified on the official EU-US Data Privacy Framework list. Addresses and places you enter — for example the address of a proposed accommodation — are converted into coordinates by our server via the OpenStreetMap service Nominatim; places nearby are queried from the OpenStreetMap service Overpass. Only the place searched for or the coordinates are transferred, not your person. Routes are calculated by OpenRouteService. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • Link previews: If you add a link — for example to a video, a playlist or an accommodation listing — our server retrieves the linked page or the provider's preview interface (e.g. YouTube, Vimeo, Spotify, SoundCloud) in order to take over the title and preview image; only the link is transferred, not your person. Your browser then loads the preview image directly from the respective provider, which receives your IP address in doing so. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • Google Maps / Places (optional, USA): If enabled, place and location details are transferred to Google LLC (USA) for enrichment in the “On site” area. Transfer to a third country; Google is certified under the EU-US Data Privacy Framework (adequacy decision). Without the service enabled, no transfer to Google takes place.
  • Weather (OpenWeather Ltd., United Kingdom): For weather-related information, place details of your trip are transferred to the weather service. Transfer to a third country (United Kingdom) on the basis of the EU Commission's adequacy decision for the UK (2021) — no additional safeguard required.
  • Trip photos (cloud, e.g. Dropbox): Photos and videos of a trip are stored in the cloud that a member has connected for the trip — not on our servers. All recordings of a trip end up in that one member's cloud account. On our side we store details about the recordings (including the time taken and — if contained in the file — the location) as well as the name and email address of the connected cloud account and encrypted access keys. Videos are loaded by your browser directly from the cloud provider, which receives your IP address in doing so; photos and preview images are fetched from the cloud provider by our server. The privacy terms of your cloud provider apply in addition. Dropbox, Inc. (USA) is certified under the EU-US Data Privacy Framework. Only upload images for which you have the consent of the people depicted (right to one's own image, §§ 22, 23 of the German Act on Copyright in Works of Fine Art and Photography, KunstUrhG); within the trip they are visible to all members.

Transfer of the service: Should LeMungo ever be taken over by another operator, the data needed to run the service will pass to that operator. The purposes stated in this policy remain binding; this is not a sale of data. Pseudonymous usage and security data (section 3 f and h) do not pass over. We will inform you before the transfer so that you can object or delete your account. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in continuing the service).

5. Retention period

We store account and trip data for as long as your account exists or as long as it is necessary for the purposes stated. Sign-in sessions (including the IP address and browser identifier stored with them) are removed when the session expires or when you sign out; sign-in and confirmation links expire after one hour at the latest. If you delete your account, your identity is anonymised; contributions remaining in shared settlements are kept without your name so that the balances of the other members stay correct. Statutory retention obligations remain unaffected. Deleted data disappears from the backups as soon as they are overwritten on rotation — on our server after roughly 14 days, in the encrypted off-site storage after roughly six months at the latest.

6. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can exercise access and data portability yourself at any time via the data export in the settings ; you can also delete your account there. For all other matters you can reach us at kontakt@lemungo.com. We respond within 30 days.

7. Right to lodge a complaint

Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence. The authority responsible for the controller is: Die Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen), 30159 Hannover.

8. Data security

Transmission is encrypted via HTTPS (TLS). We take appropriate technical and organisational measures to protect your data against loss and unauthorised access.

9. Changes

We adapt this privacy policy when the legal situation or our processing changes. The version published here at the relevant time applies.

Last updated: 13 September 2026.