Rudelruf™

Privacy Notice

Convenience translation — not legally binding. The binding version of this privacy notice is the German original. This English translation is provided for information only. The paid subscription is offered in selected EU/EEA countries only; the countries in which it can be purchased are shown in Google Play. This English version is provided for readers in those countries and does not by itself extend the service to any other country.

As of: 9 September 2026 · Applies to the Rudelruf™ app (de.lialabs.rudelruf), the associated backend and the website rudelruf.de.

Rudelruf™ is an emergency safety net for pets left alone. You register that your pet is alone; if you do not report back by the deadline, the server alerts your carer network. So that the carers can help in an emergency, we deliberately process sensitive information (e. g. home address, key location, alarm code, location, absence times) and treat it with particular care (see section 7).

1. Controller

Lia Labs, owner Stefan Mayer (sole proprietorship)
c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany
E-mail: info@lialabs.de · Telephone: +49 155 62922172 · see also Legal Notice.

A data protection officer has not been appointed.

2. Which data we process

Account and owner master data: first name, surname, e-mail, optionally telephone as well as street, house number, postal code and city; password only as a hash. Name, telephone and address are stored encrypted.

Pet profile: name, species (dog/cat/other), breed, sex, date of birth, weight, temperament, a profile photo as well as – for the found-pet help – up to three additional photos. Optionally, for the identification of your pet: chip number and Tasso registration number. The assignment in the case of a find is done primarily via the generated found-pet code or QR code. The Tasso registration number is – only as long as your pet is reported missing – shown additionally in the app and on the found-pet page (rudelruf.de/fundtiere) (it is on the Tasso tag anyway). The chip number serves only your own overview, is stored encrypted (section 7) and is not displayed publicly.

"Report as missing": If you report your pet as missing, we process the missing status (since when the search has been ongoing), an optional info text (stored encrypted, section 7), the photos of your pet and – if you select it on the map – the last known location of your pet (also stored encrypted). We show this information to your carer network and – if the function is activated – to other Rudelruf™ users in the vicinity of the last known location (each within the radius of their personal search radius), so that a larger circle can help search. Visible in the process are only name and species of the pet, the photos, your info text and the last known location – not your home address and not your name or contact.

Health of the pet: medication/plan, pre-existing conditions, allergies, vet and clinic data, emergency treatment authorisation (yes/no, € limit as well as your signature = name and date as consent; the signature is stored encrypted).

Feeding & care: food, quantity and feeding times as well as information on walking/exercise, temperament and routine – so that a carer can take over the provision.

Insurance of the pet: pet-owner liability, surgery and health insurance with provider and policy number (optionally a contact). This information is sensitive and is stored encrypted (section 7).

Emergency contact: name and – stored encrypted (section 7) – telephone number of a person of trust (e. g. neighbour with a spare key).

Betreuungs-Steckbrief (care profile): For a help request, you can specifically release which of this information the carer chosen by you may see. The insurance information is excluded by default and becomes visible only after express release – and exclusively for the chosen carer, not for the open community. Your home access data (address, key, alarm code) and the emergency contact (third-party personal data) cannot at all be shared via the Betreuungs-Steckbrief; the Community-Dienste are access-free.

Full profile in an emergency (handover): If a private carer led by you takes over the care of your pet in an emergency (SOS) (confirmation "I'll take over"), only this one carer receives access to the complete Betreuungs-Steckbrief (including feeding, care, medicine, vet, treatment authorisation, insurance) for the duration of the deployment, so that they can look after your pet. The access is time-bound and ends as soon as you as the owner confirm "The dog is back with me" (the carer themselves cannot end it; the mere completion of the emergency alert does not end it as long as the pet is still with the carer). Your home access data also remain excluded here; a community carer does not receive this full profile (only the emergency coordination data).

Access to the home: address, key location, alarm code, entry notes – this information is stored encrypted (section 7).

Location: Homezone coordinates and – only with your release – your device location (GPS), for "automatically sign off when you are at home" (in the foreground and – with separate release – also in the background when the app is closed; see section 4).

Absence/alert: absence sessions (start, expected return, deadline, status), alerts, deliveries, key releases.

Carer network: who leads whom as a carer, order, availability, radius.

Technical: push token (device), API token, IP address/server logs, login attempts (misuse protection), successful sign-ins including time, IP address, country and device details (detection of unauthorised access; automatically deleted after 30 days), the app version you use (for support and compatibility assistance).

Error reports (diagnostic data): If you report an error yourself via Settings → "Report a problem", we process your free text ("What happened?") as well as automatically attached technical diagnostic data: app version, operating-system/Android version, device model, language setting, the page last opened in the app, the time and a short log/error excerpt (the last technical messages incl. any stack trace). The log excerpt is limited to technical app messages and contains no passwords, location coordinates or chat content. You see free text and log excerpt before sending. Details in section 5h.

Dokumenten-Ablage (document storage) (voluntary): If you store documents about your pet as a scan, we process the image pages of these scans as well as title, type, the associated pet and optionally date and amount. You determine the content yourself; it is visible only to you. Details in section 5i.

Tierakte (pet record) (optional): If you use it, we process, per pet, your own entries on health (date, type, finding/occasion, costs, "next due on"), medication (name, dose, rhythm, duration from/to, note), weight (date, kilograms, note), costs (date, category, purpose, amount) and appointments (date, time, title, note) and — for non-neutered female dogs — the heat cycle (Läufigkeit) (start date, note; average interval, forecast and cycle phase are only calculated from this, not stored). The free texts – finding, medication details, notes, cost purposes and appointment titles – are stored encrypted; date, quantity and amount fields (kilograms, cent amounts, due date) are stored unencrypted in the database. The record is owner-private; only the owner of the pet can make entries. An exception is governed by the Betreuungs-Steckbrief: if you release the "Medicine" area there, the carer chosen by you sees the medications current at the respective time (name, dose, rhythm, end) – expired information is no longer shown to them. Costs, weight history, findings and the heat cycle are not shared — for the heat cycle there is deliberately no release option at all. On request, we remind you by push notification of due entries, appointments and the expected next heat cycle; the reminder names the pet name and occasion. The record is deleted as soon as you delete the associated pet or your account.

Collar/found-pet help: random found-pet code, your releases for the display of the owner's phone number and for notification as well as tag requests. In the case of a find report, we store the time, pet reference, a daily-rotating hash of the IP address and only whether location or finder phone number were sent along. Voluntarily transmitted GPS coordinates and finder phone numbers are stored encrypted, shown exclusively to the owner in the found-pet history and automatically deleted after 30 days. The owner can delete individual entries beforehand.

3. Purposes and legal bases (Art. 6 GDPR)

Do you have to provide this data? There is no legal obligation to give us your data – but without certain information Rudelruf™ does not work. Required are e-mail address and password for your account, your name so that you can be addressed within the carer network and, if you are an owner, your home address and access instructions so that a carer can help at all in an emergency. Without them, no contract comes about or the alert comes to nothing. Voluntary is everything else – phone number, photo, pet record, documents, community role, location release. Without this information the app remains usable; individual functions are then not available.

3a. Sign-in with Google (optional)

You can optionally sign in with your Google account instead of entering e-mail and password. This is voluntary – the route via e-mail and password always remains available.

What is transmitted in the process: your e-mail address, your name (if stored in the Google account) and an immutable identifier of your Google account. We store this identifier in order to recognise you next time.

What we do not store: no Google access or refresh tokens, no contacts, no calendar or other Google data. After sign-in, we no longer access any Google services.

Existing account: If an account with the same e-mail address already exists, we link it – but only if Google confirms to us that the address belongs to you. We additionally inform you of every linking by e-mail.

Legal basis: Art. 6 (1) b GDPR. When you call up the Google sign-in, Google processes its own data according to its own privacy policy.

4. Location data

Found-pet page and app: A finder can voluntarily release the current device or browser location so that the owner receives the location of the find. Device or browser expressly ask for permission for this. Without release, the owner can still be informed. Coordinates and a voluntarily entered finder phone number are stored encrypted in the owner's found-pet history and automatically deleted after 30 days; no movement profile is created.

The app uses your location exclusively for the Homezone and the automatic sign-off when you are back home – when opening the app and, with separate release, also in the background when the app is closed. For this it requests an Android location permission:

Before the background release, the app expressly explains the purpose to you (information before the system dialog) and asks for your consent. The permission is voluntary and can be revoked at any time in the device settings. Without location release, the app remains fully usable – you then sign off manually. If you allow location only in the foreground (not "Always"), the automatic sign-off when opening the app is retained; only the sign-off when the app is closed ceases.

Coarse area cell for the radius search: Your precise location information – Homezone, a meeting-point pin and the last known location of a missing pet – is always stored encrypted (section 7). So that radius and neighbourhood searches (emergency ring, service proximity, walking meet-ups, missing pets) remain fast even with many users, we additionally store a coarse grid cell of these points unencrypted – a grid field rounded to about 2 km ("district level"). From this, only the coarse cell (its centre point) can be derived, not your exact position – the same granularity that the radius density map already shows anyway. The cell serves exclusively as an internal pre-filter; to other users, only an approximate distance class continues to go, never a coordinate.

5. Recipients and third-party services

Note on third-country transfer: The OpenStreetMap Foundation has its seat in the United Kingdom (third country within the meaning of the GDPR). When loading the map tiles, your IP address is transmitted to servers of the OpenStreetMap Foundation. Legal basis is our legitimate interest in a functioning map display (Art. 6 (1) lit. f GDPR). For the United Kingdom there is an adequacy decision of the European Commission, so that an adequate level of data protection is recognised.

Website visit (rudelruf.de): When you call up our website, our host (Uberspace, Germany) automatically processes technically necessary access data in server log files – in particular your IP address, date and time, the page called up, the browser type and, if applicable, the previously visited page. This is necessary for the secure operation and delivery of the website; legal basis is our legitimate interest (Art. 6 (1) lit. f). These logs are not merged with other data and are not used to create user profiles. The files rotate by size; their retention lies with our hoster, who keeps them for us as a processor. The website itself sets no cookies and integrates no tracking, no fonts and no third-party advertising or analysis services.

Embedded video (YouTube): On the start page and in the manual, we offer an explanatory video. We integrate it in a data-minimising way via "click to load": Initially only a preview image stored with us is shown – in the process, no connection to Google/YouTube arises. Only when you actively start the video is the YouTube player loaded in privacy mode (youtube-nocookie.com). From that point in time, Google Ireland Ltd. (or Google LLC) processes technical data such as your IP address in order to deliver the video, and can set cookies or similar technologies. Legal basis is your consent through the click (Art. 6 (1) lit. a GDPR); a data transfer to the USA is done on the basis of the EU-U.S. Data Privacy Framework (Google LLC is certified), additionally standard contractual clauses. If you do not start the video, none of this data is transmitted. Further details in the privacy policy of Google.

5a. Community-Ring (community ring) and Community-Dienste (community services)

If you switch on the Community-Ring or the Community-Dienste (both are optional and off by default), we process additional data so that suitable helpers near you can reach you and you can select in peace. These functions are voluntary, free neighbourhood help – they trigger no payment or subscription processing.

Which additional data

Encryption: Sensitive free-text and contact information – your profile short description, your schedule, the notes of your service requests, the name of your key holder as well as telephone and address – is stored encrypted (see section 7).

Purposes and legal bases (Art. 6 GDPR)

Visibility and contact release only after the selection

Recipients

Recipients of the above-mentioned data are – depending on the role and status of the request – other users (requesting owners see the provider profile; after the assignment, the users involved exchange contact details). A passing on to third parties for advertising purposes does not take place. The technical delivery of notifications runs, as with the rest of the app, via the push service (section 5).

Retention and deletion

Requests, expressions of interest and brokerage/audit information we keep – as with the deployment log of the ring – only as long as it is necessary for provability and misuse protection, and we then delete or anonymise it at the latest 90 days after completion, rejection or withdrawal of the respective request. Upon deletion of your account, your service role, your profile and your open requests are removed with it; an anonymised proof log without clear data may briefly continue to exist under section 8. Your provider profile is no longer visible for new requests after revocation of the consent.

5b. Walking together (Rudel-Walk / "Gemeinsam Gassi")

If you use "Gemeinsam Gassi" (walking together; optional, off by default), we process the necessary information to find suitable joint walks in your vicinity.

Which data

Visibility – data minimisation before the confirmation

Before joining, other users see only coarse, non-identifying information: type of meet-up, time, coarse meeting point, pet species and an approximate distance class (e. g. "< 5 km"), never your exact coordinates or home address and not your name or contact. Name and contact become visible only after joining between the participants of a meet-up.

Inviting acquaintances (instead of radius)

You can specifically invite people from your acquaintances list (section 5j) to a meet-up. Invitees see the meet-up regardless of the distance and also without their own Homezone; a meet-up can optionally be visible only to invitees and then appears in no radius list. Stored in the process is who invited whom to which meet-up and whether they accepted, declined or not yet answered. Only the person who created the meet-up may invite; invitable are exclusively one's own acquaintances. The data minimisation above also applies to invitees: the exact meeting point becomes visible only after the confirmation. The only exception: the name of the inviting person is immediately visible – you know each other from the acquaintances list.

Legal bases

Your free-text note for a meet-up is stored encrypted (see section 7). Retention and deletion are done as with the Community-Dienste (section 5a): only as long as necessary for provability and misuse protection; upon account deletion, your meet-ups and participations are removed with it.

5c. Data of persons who do not use the app themselves (Art. 14 GDPR)

In two cases, we process data of persons who did not enter it with us themselves:

Those affected by these processings have the same rights as in section 9 and can contact info@lialabs.de at any time.

5d. Rudel-Chat (messages with your carers)

If the Rudel-Chat is activated (optional), you can exchange 1:1 text messages with the carers of your private pack. We process for this the message text, the persons involved (owner ↔ respective private carer), the time and the read status. The recipient of a message is exclusively the other person of the respective carer relationship – no one else.

Text only, encrypted, short storage period. The chat transmits exclusively text (no images or files). The message texts are stored encrypted (section 7). They are automatically deleted at the latest 30 days after sending and immediately when the carer relationship is severed or a participating account is deleted. A note about new messages is delivered via the push service (section 5); in your app notification history, the message text is not permanently stored.

Purposes and legal bases: provision of the chat you use for coordination around the care (Art. 6 (1) lit. b GDPR) as well as legitimate interest in IT security and misuse protection (Art. 6 (1) lit. f). The chat is an addition to coordination and not an alert or emergency-call channel.

5e. Gassi-Gruppenchat (messages in a meet-up)

If the Gassi-Gruppenchat is activated (optional), each walking meet-up receives a group thread. We process for this the message text, the sending person (with display of the name towards the other participants), the time as well as the read position per participant (in order to count unread items and to show the senders whether all those involved have read a message; an individual read time is not shown to others).

Recipient circle "group". Unlike the 1:1 Rudel-Chat, the recipients of a message are all parties to this one meet-up – the organiser and the confirmed participants, no one else. Anyone who only views a meet-up but has not joined does not see the chat. If the organiser removes a participant from the meet-up, that participant simultaneously loses access to the group chat.

Text only, encrypted, bound to the meet-up. The chat transmits exclusively text (no images or files); the texts are stored encrypted (section 7). Writing is only possible as long as the meet-up runs; once it is over, cancelled or completed, the history becomes read-only. The messages are automatically deleted at the latest 30 days after sending; upon account deletion, your own messages and your own meet-ups are removed with it. A note about new messages is delivered via the push service (section 5) to the participants; in the app notification history, the message text is not permanently stored.

Purposes and legal bases: provision of the group chat you use for coordination around the joint walk (Art. 6 (1) lit. b GDPR) as well as legitimate interest in IT security and misuse protection (Art. 6 (1) lit. f). The group chat is an addition to coordination and not an alert or emergency-call channel.

5f. Suche-Gruppenchat (messages during a missing-pet search)

If the chat is activated (optional) and you have reported your pet as missing (section 3), there is a group thread with the helpers for this search. We process for this the message text, the sending person (with display of the name towards the other participants), the time as well as the read position per person (in order to count unread items and to show the senders whether all those involved have read a message; an individual read time is not shown to others).

Recipient circle of the search. The recipients of a message are the owner of this search and all persons who have reported a sighting for it – whoever reports a sighting thereby hooks in as a helper. The owner can remove individual helpers again; these then lose access to the group chat and see no further location updates. Phone numbers are not disclosed via the chat.

Text only, encrypted, bound to the search. The chat transmits exclusively text; the texts are stored encrypted (section 7). It lives only as long as the search: if you end the search, the group chat is immediately closed and the history deleted. Independently of this, the messages are automatically deleted at the latest 30 days after sending; upon deletion of the pet or a participating account, the associated messages are removed with it. A note about new messages is delivered via the push service (section 5) to those involved.

Purposes and legal bases: provision of the group chat for the coordination of the search (Art. 6 (1) lit. b GDPR) as well as legitimate interest in IT security and misuse protection (Art. 6 (1) lit. f). The chat is an aid to coordination and not an alert or emergency-call channel.

5g. Dienst-Chat (messages for a Community-Dienst request)

If the chat is activated (optional) and you have selected a person for a Community-Dienst request (dog walking, vet visit, travel & transport, care, day care, spontaneous care; section 5a), you can exchange 1:1 text messages. We process for this the message text, the persons involved (owner ↔ selected helper), the time and the read status. The recipient of a message is exclusively the other person of this request – no one else.

Text only, encrypted, bound to the request. The chat transmits exclusively text; the texts are stored encrypted (section 7). It is only possible from the selection and closes again as soon as the request is completed or cancelled. The messages are automatically deleted at the latest 30 days after sending and are removed upon deletion of the request or a participating account. A note about new messages is delivered via the push service (section 5).

Purposes and legal bases: provision of the chat for the coordination of the agreed service (Art. 6 (1) lit. b GDPR) as well as legitimate interest in IT security and misuse protection (Art. 6 (1) lit. f). The chat is an addition to coordination and not an alert or emergency-call channel.

5h. Error reports from the app (diagnostic data)

Via Settings → "Report a problem" you can voluntarily report an error to us directly from the app. The purpose is exclusively troubleshooting and improving the app. Transmitted are your free text and automatically attached technical diagnostic data (app version, operating-system/Android version, device model, language, page last opened, time and a short log/stack-trace excerpt). You decide for yourself whether and what you report, and see text and diagnostics before sending.

Data-minimising and encrypted. The log excerpt is limited to technical app messages and contains no passwords, no location coordinates and no chat content. Free text and log excerpt are stored encrypted (section 7). Each report receives a reference number (format RR-XXXXXX), which is shown to you after sending, so that you can refer to it for follow-up queries.

Recipients and retention. The reports are only accessible to the operator and are not passed on to third parties. They are automatically deleted at the latest after 90 days and are removed upon deletion of your account.

Purposes and legal bases: handling of your error report as well as legitimate interest in the stability, security and improvement of the app (Art. 6 (1) lit. f GDPR). The report is voluntary and not necessary for the use of the app.

5i. Dokumenten-Ablage (document storage) (scans)

The Dokumenten-Ablage is voluntary. You photograph documents about your pet (e. g. vet invoices, findings, vaccination card, care or purchase contract, insurance policy) and store them in the app. Stored are the image pages of your scans, plus title, type (invoice, finding, vaccination card, contract, insurance, other), the associated pet as well as optionally date and amount. The title is stored encrypted (section 7).

Third-party content. Your scans can contain personal data of others – such as address and bank details of a veterinary practice or information of a contracting party. You decide for yourself what you store.

Capture with the document scanner. For capturing, the app uses on Android devices the document scanner of the Google Play Services (edge detection, straightening, cropping). The capture and editing takes place on your device; the finished image comes to us, not to Google. If the scanner component is not yet on the device, it is loaded from Google the first time – for this a brief connection to Google exists. If the scanner is not available, you capture the pages with the normal camera.

Encryption and access. The image pages are stored encrypted on the server, separately from the public image area of the app, and are delivered to you only after sign-in and check of the authorisation; a separate, derived key is used per account. To be honest: Since this key is on the server, we could technically read the documents. We do not do it, and in the operator's administration tools there is no way there – there, only the size and number of the files are visible. You are thereby protected against theft of the data carriers, against backup copies in the wrong hands and against accidental delivery – not against a compromised server.

Visibility. Your documents are visible exclusively to you. They do not appear in the Notfall-Steckbrief (emergency profile), not with carers, not in the community, and are not shared. An export as PDF is possible – what you do with it, you decide. The exported PDF file is thereby stored unencrypted in a temporary folder of your device, so that a PDF viewer or your mail program can open it; the operating system clears this folder itself again.

Linking with the Tierakte (pet record). You can link a document to an entry in your Tierakte – with a cost line or with an entry in the Health area (the vet invoice usually belongs to the finding). Stored in the process at the respective line is only the identifier of the document; a further copy of the scan does not arise, and we do not read out any content. The link is – like the Tierakte itself – visible only to you. If you delete the document, the Tierakte entry remains and only loses the reference.

Purpose and legal basis: retrieval of your own documents about the pet; performance of the usage contract (Art. 6 (1) lit. b GDPR). Use is voluntary.

Retention and deletion. Documents remain until you delete them – there is no automatic deletion. Upon deletion of your account, all image pages including preview images are removed from the servers. If you delete a pet, an already stored invoice remains (you may need it for tax or warranty) and only loses the assignment to the pet. The storage space per account is limited; the storage is a second copy and not an archiving service – continue to keep important originals yourself.

5j. Acquaintances list ("My acquaintances")

You can invite people to your acquaintances list – by e-mail, by shared link (e. g. via a messenger) or by QR code. An acquaintance is not a role: it establishes no task in the emergency and no place in your alert chain. Who is called in the alert you decide in a separate step (carer request).

There is one case in which an acquaintance arises without an invitation of your own: when you join a family household (section 5h), you and the other members of that household are linked automatically. You are already carers for one another there; the acquaintance simply makes that visible. It is stored with the origin “family household”, and you are told before joining that it will arise. If you later leave the household, the acquaintance remains – you can end it yourself at any time, like any other.

Which data.

What the other side sees. Both sides see the name of each other – nothing more. Telephone number and address are not released thereby; they remain bound to an active carer relationship or an ongoing alert. The web page behind an invitation link deliberately names no name, because such links are forwarded; who invited is only learned in the app after signing in.

Legal bases. Performance of the usage contract (Art. 6 (1) lit. b) and – towards the invited person until their registration – legitimate interest in the building of your personal network (Art. 6 (1) lit. f).

Ending and retention. An acquaintance can be ended by either side at any time; it is then immediately removed on both sides. If someone is blocked, a note remains with the blocking person, so that the same person does not return via a new link. Unredeemed invitations expire automatically (link 14 days, QR code 60 minutes) and are deleted at the latest 30 days after expiry or revocation. Upon deletion of your account, all acquaintances and open invitations cease.

We do not read out any phone book. Rudelruf™ does not import any contacts from your device – we process exclusively whom you invite yourself and who accepts this invitation.

5k. iPhone waiting list on our website

On rudelruf.de you can leave your email address to be notified once as soon as Rudelruf™ is available for iPhone. This is not a newsletter: we send you exactly that one message and never write again.

Which data. Your email address, the language of the page you used (for the language of the message), and the time of sign-up and of confirmation. In addition we store, for at most one hour, a daily-rotating checksum of your IP address (not the address itself) to protect the form against mass abuse.

Confirmation (double opt-in). After signing up we send you an email with a confirmation link. Only when you click it will you be notified. If you don't confirm, we delete the address automatically after 7 days – so nothing remains of an address entered by mistake or by someone else.

Legal basis. Your consent (Art. 6(1)(a) GDPR), given by clicking the confirmation link.

Withdrawal and deletion. Every email contains an unsubscribe link; one click deletes your address immediately and completely. The list is deleted at the latest once the announcement has been sent. Signing up does not create an account, the address is not linked to any account and is not passed on to anyone.

6. Sensitive data

So that you and your pet can be helped in an emergency, we process information such as home address, key location, alarm code and health data of the pet. This data is only visible to the alerted carers in the active alert case and is blocked again afterwards.

7. Security (Art. 32 GDPR)

Name and first/surname, the structured home address (street, house number, postal code, city), the home access data (address, key location, alarm code, entry notes), the emergency phone number of the owner, the name of your key holder, the health and vet data of the pet, the coordinates of your Homezone as well as – for the Community-Dienste – your profile short description, the schedule of your Community role, the free-text notes of your service requests, – for "Gemeinsam Gassi" – the free-text note of your meet-ups, the info text and the last known location of a missing report, the chip number of your pet, the insurance information of your pet (provider, policy number and contact), the telephone number of your emergency contact, the texts of your Rudel-Chat, the Gassi-Gruppenchat, the Suche-Gruppenchat and the Dienst-Chat, – in the Tierakte – findings, medication information, appointment titles, notes (also those on the heat cycle) and cost purposes as well as the free text and the log/diagnostic excerpt of your error reports as well as title and text of the messages stored in your app notification history (push history) are stored encrypted (libsodium secretbox; key separate from the database). Passwords and API tokens only as a hash. Transmission via HTTPS. Login rate limit against brute force. Key releases are automatically revoked after the deployment. Access to emergency data (incl. emergency phone number of the owner) only in the active alert case. The e-mail address remains readable as a login search key in the database.

Check against known data breaches: When you set a new password (registration, reset, password change), we check whether it has appeared in known data breaches. Your password does not leave our server: we compute a check value (SHA-1) locally and send only the first five characters of it to the service "Have I Been Pwned" (operated by Troy Hunt, delivered via Cloudflare). Those five characters point to one of more than a million buckets and allow no conclusion about your password or about you; the comparison itself happens on our side. The request is made by our server, not by your app — your IP address is not transmitted, nor is your name, your email address or an account identifier. If the service is unavailable, you can still set your password. The legal basis is our legitimate interest in the security of your account (Art. 6(1)(f) GDPR).

Optional app lock: You can additionally lock the app with a device PIN and – provided your device supports it – biometrically (fingerprint/face). PIN and biometrics setting are held exclusively locally on your device and are not transmitted to us.

8. Storage period and deletion

Account data and associated pet/access data we store as long as your account exists.

Account deletion: You can delete your account yourself at any time – in the app under Settings → "Delete account" (confirmation with your password). The deletion is done immediately and irrevocably and removes, cascading, all personal data (name, e-mail, pets, access and medical data, Homezone, registered devices, carer links, chat messages, error reports, subscription/purchase data such as purchase token, product, status and expiry date). This also includes the files uploaded by you themselves – pet and found-pet photos, tag templates and your carer profile picture: they are removed not only from the database, but also physically deleted from the server. Alternatively without the app: e-mail to info@lialabs.de from the registered address. Instructions also at rudelruf.de/konto-loeschen.html.

Automatic deletion of inactive accounts: In accordance with the principle of storage limitation (Art. 5(1)(e) GDPR) we do not keep accounts indefinitely. A permanently free account that, over a continuous period of 24 months, has neither been used (no sign-in, no use of the app) nor been part of another user's network as a carer will be deleted after advance warning. We notify you beforehand in text form – as a rule 30, 14 and 7 days before the planned deletion – by email to the address stored in the account (additionally as a notice in the app); a single sign-in or use within this period averts the deletion. Excepted are accounts with a running paid subscription, active members of a Familien-Abo, and accounts that are part of a carer network. The deletion removes, cascading, the same data as an account deletion by you; the exceptions set out below (community proofs, anonymised proof log, statutory retention obligations) remain unaffected. The legal basis is § 4a of the terms of use together with our legitimate interest in data-minimising operation (Art. 6(1)(f) GDPR).

Exception for community proofs: Frozen deployment proofs from the Community-Ring and the Community-Dienste (e.g. who took on which deployment when) are retained, for protection against misuse and for the securing of possible legal claims (Art. 17 (3) lit. e GDPR), for up to 90 days after the end of the deployment and are then anonymised – even if you delete your account beforehand. If an incident is reported for a deployment, the relevant proof is retained until clarification. These proofs are only accessible to the operator and are only released upon legitimate official request.

Anonymised proof log: Since Rudelruf™ is a safety-critical emergency network, we store, after deletion for proof purposes (legitimate interest, Art. 6 (1) lit. f), an anonymised deployment log – only the pure course of an alert (times, status, whether a key was handed over), without name, e-mail, address, key or medical data. Optionally, a salted, non-reversible pseudonym hash is stored. This log is automatically deleted after 90 days.

Error reports: Self-reported error reports (free text, diagnostic/log excerpt; section 5h) are automatically deleted at the latest after 90 days and are immediately removed with an account deletion.

Login attempts. We store failed and successful login attempts exclusively to protect against automated attacks (rate limit). They are deleted automatically after 120 minutes at the latest; after a successful login, the entries for the address concerned are removed immediately.

Statutory retention obligations for payment receipts remain unaffected (insofar as receipts are available to us; the payment runs through Google Play).

9. Your rights

You have the right to access (Art. 15), rectification (16), erasure (17), restriction (18) and data portability (20) as well as a right to object (21) to processing on the basis of legitimate interest, and the right to revoke consent given at any time (Art. 7 (3)). Requests to info@lialabs.de.

Automated decision-making: An exclusively automated decision within the meaning of Art. 22 GDPR that produces legal effect towards you or similarly significantly affects you does not take place. The reliability information shown in the app (e.g. how often help was provided, cancellation rate) is a pure guide – the selection of helpers you always make yourself.

Right to lodge a complaint with a supervisory authority

Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your place of residence, your place of work or the place of the alleged infringement. The supervisory authority competent for the provider is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW), Heilbronner Straße 35, 70191 Stuttgart, www.baden-wuerttemberg.datenschutz.de

10. Age

Rudelruf™ is aimed exclusively at persons of full legal age (from 18 years). Use presupposes full legal age; accounts of minors are not permitted.

11. Amendments

We adapt this notice when the app or the legal situation changes. The current version published in the app or on the website applies.