Deutsch · English · Español · Português · Français
Last updated: 1 September 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Michael Lopes Pinto
trading as: 3D Druck Michael Lopes Pinto (sole proprietorship)
Staufener Str. 26
79189 Bad Krozingen
Germany
Email: info@mlp3d.de
This policy applies to the "Abgehakt" app on all platforms we offer it on (Android, iPhone/iPad and Mac). Data processing is identical across all platforms; where differences exist, they are set out explicitly below.
Abgehakt is built so that your data stays on your device by default. Data is only stored in the cloud if you voluntarily sign in and actively share lists. If you choose Abgehakt+, payment is handled through the App Store or Google Play; to manage and verify your membership we additionally use the specialist service provider RevenueCat — its software component is included in every version of the app and becomes active at startup even without a subscription (see section 5 for details). The app displays no advertising, contains no analytics or tracking services and does not create usage profiles.
If you use the app without signing in ("Continue without an account"), all lists are stored exclusively on your device. The automatic backup copies of your lists are also kept only in the app's protected storage area on your device. No personal data is transmitted to us or to any third party.
If you sign in with your Google or Apple account, we process the following data:
— The display name, email address and user identifier (UID) provided by your account provider, for the purpose of signing you in and so that connected devices can display your name. With Apple, this may be a private relay email address provided by Apple if you prefer not to share your real email address.
— The contents of the lists you share (title, entries including free-form, multi-line notes, quantities, completion status, groups, the priority you have set and the time of the last edit) as well as the user identifiers of the people connected to you, in order to provide synchronisation.
Lists you have not shared remain exclusively on your device, even when you are signed in. Signing in is voluntary; all core functions of the app also work without an account.
What you write in your lists is entirely up to you. In notes lists you can also store longer, freely worded text. We do not read this content, do not analyse it and do not pass it on to anyone other than the people you have actively shared a list with. Content in lists you have not shared does not leave your device at all and is stored there in encrypted form within the app (AES-256-GCM); if you use the home screen widget described further below for such a list, this does not apply to the content shown there. Please note: content in shared lists is technically stored on the servers named in section 6 and is readable by all members of that list. We therefore recommend that you do not enter credentials such as passwords, or particularly sensitive information (for example relating to health, religion or sexual orientation), in shared lists.
The legal basis for this processing is Article 6(1)(b) GDPR (provision of the functions you actively use).
A daily limit applies to each account for changes made in shared lists, so that the costs of shared use remain predictable. Once it is reached, the app can no longer write the most recently edited state to the cloud until the next day. Shared lists exist exclusively in the cloud, so in this case the app stores this state once per list and day as an additional local list on your device, identifiable by the title "Copy: …". This copy also contains entries written by other members. It is not reconnected to the cloud, is not transmitted to us and remains on your device until you delete it. The legal basis is Article 6(1)(b) GDPR.
In a shared list you can see who besides you has access to it. Only the display name from that person's Google or Apple account is shown, or a name they have chosen themselves in their settings. Email addresses are not shown to other members; nor are they stored for this purpose. Conversely, other members see your display name. The legal basis is Article 6(1)(b) GDPR: anyone sharing a list must be able to see with whom.
Notifications for shared lists
If another member adds new entries to a list you share with them, Abgehakt can let you know. The feature stays switched off until you enable it in the settings under "Notifications" and additionally grant your operating system's permission. It exists only on Android, iPhone and iPad, not on the Mac.
The notification contains the title of the list and the display name of the person who added something. What was added is not included: the contents of your lists therefore never appear on a lock screen. Only new entries trigger a notification, not completing, deleting or renaming. Several entries in quick succession are combined into a single notification.
For this we process: the identifier that Firebase Cloud Messaging assigns to your app installation (the device token), together with your user identifier and your device's language, so that the notification reaches your device and is written in your language; the state of your switch, the lists you have muted and the time at which you enabled the feature, as a record of your consent; and, for the duration of the grouping, the identifier of the list and the user identifier of the person who added something. This last marker contains no list content and is deleted once the notification is sent.
The notifications are assembled and triggered by a server function we operate (Google Cloud Functions, region europe-west1, Belgium). They are delivered via Firebase Cloud Messaging from Google, and on iPhone and iPad additionally via Apple's push service (Apple Push Notification service). The two operating systems provide no other delivery route. Both services receive the device token and the text of the notification, that is the list title and the display name. See section 6 for details.
The legal basis is your consent under Article 6(1)(a) GDPR; the same consent covers storing and reading the device token on your device under Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDG). You can withdraw it at any time with effect for the future by switching the feature off again. We then delete the device token immediately, and without a token nothing is delivered any more. You can mute individual lists in the menu of the list concerned without switching the feature off entirely. We do not use these notifications for advertising.
The reverse also applies: if you add something to a shared list yourself, the app stores your user identifier in the list header as that of the person who last edited it. All members of the list can see it, and it is how our server recognises who triggered a notification. If other members have switched notifications on, your display name and the title of the list are transmitted to the push services of Google and Apple for that purpose and displayed on those people's devices. This happens regardless of whether you have switched notifications on yourself. The legal basis for this is Article 6(1)(b) GDPR (provision of the sharing function you actively use), not your consent.
Home screen widget
If you add the Abgehakt widget to your phone's or tablet's home screen, it displays the title and entries of the list you selected for it. This content is therefore visible without opening the app — including to anyone who glances at your unlocked device. You can hide the content at any time via the eye icon in the widget; only the app's name is then shown there.
For the widget to display a list without starting the app, the app stores the data it needs for this in a storage area shared by the app and the widget: the titles of your lists together with the number of entries, and for local lists additionally their full content (entries, quantities, completion status, notes). This data is stored there unencrypted, because the widget could not otherwise display it. It stays on your device and is not transmitted to us. If your Abgehakt+ membership ends, the app clears this area again. There is no widget on the Mac.
If you take out an Abgehakt+ subscription, the purchase itself is handled entirely by the relevant store — for the App Store by Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland), for Google Play by Google Commerce Limited (70 Sir John Rogerson's Quay, Dublin 2, D02R296, Ireland). We never receive your payment details (for example your credit card number) at any point. A subscription can only be taken out in the iPhone/iPad app and the Android app; the Mac app merely checks whether a membership already exists for your signed-in account.
To manage membership status (which plan is active, how many seats belong to it, when a subscription renews) we use the service provider RevenueCat, Inc. (2261 Market Street #5205, San Francisco, CA 94114, USA). For the app to be able to determine whether a membership exists at all, RevenueCat's software component (SDK) is a fixed part of the app and contacts RevenueCat's servers as soon as the app starts — even if you have not taken out a subscription and are not signed in. This transmits a pseudonymous identifier (a randomly generated device identifier before sign-in, your Firebase UID after sign-in), technical details about the app and device (including platform, app and OS version, country) and, where available, your store's purchase or subscription identifier. RevenueCat does not receive names, email addresses or list content.
The legal basis for existing or pending memberships is Article 6(1)(b) GDPR (performance of a contract); otherwise — i.e. for the mere status check without a subscription — it is Article 6(1)(f) GDPR (our legitimate interest in reliably unlocking paid features, across devices, only for authorized people). A data processing agreement is in place with RevenueCat; transfers of data to the USA are covered by Standard Contractual Clauses (Article 46 GDPR).
If you assign Abgehakt+ seats to other people ("Manage seats"), we store this assignment in our own cloud database (see section 6): the user ID of the person receiving the seat, your user ID, your display name (so it's clear who the seat came from), and the time of the assignment. If you assign a seat via an invitation link that you send yourself, we initially store only your user ID, your display name and the time for that link. When someone redeems the link, that person's user ID and display name and the time of redemption are added, so that you can see in the app who accepted your invitation and so that the same link cannot be redeemed a second time. A redeemed link remains stored as a record of the assignment. A link that is still open can be withdrawn in the app, in which case it is deleted. The legal basis is Article 6(1)(b) GDPR.
For security reasons, every assignment runs through a server function we operate (Google Cloud Functions, region europe-west1, Belgium). Right before assigning a seat, it checks with RevenueCat whether your membership is actually active and a seat is still available. To do this, your user ID (Firebase UID) is sent to RevenueCat — the same ID the app already transmits anyway. The user ID of the person receiving the seat is not sent to RevenueCat. The legal basis is Article 6(1)(b) GDPR (performance of your membership) and, additionally, Article 6(1)(f) GDPR (our legitimate interest in ensuring paid features aren't unlocked without a valid membership).
Your membership also involves a record of the devices you use it on. For this purpose, the app generates a random identifier once that does nothing but distinguish this installation from others. It is not derived from device or hardware characteristics, says nothing about your device and is not visible to other apps. This identifier and the time of last use are stored together with your verified membership status in our cloud database (section 6). How many devices we store depends on where your membership comes from: if you took out a subscription yourself, it is as many devices as your plan has seats. If you are using a seat that someone else assigned to you, it is two. If a further device is added, the entry for the device that has not been used for the longest time is deleted. If you reinstall the app, a new identifier is created and the device counts as a new device. The legal basis is Article 6(1)(b) GDPR (performance of your membership within the scope booked) and, in addition, Article 6(1)(f) GDPR (our legitimate interest in a membership not being used beyond the scope booked).
We use the Firebase Authentication and Cloud Firestore services provided by Google for sign-in and synchronisation, and additionally Google Cloud Functions for individual server-side checks (see section 5). Our contracting party and processor within the meaning of Article 28 GDPR is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement is in place with Google (Google Cloud Data Processing Addendum).
List data is stored in the Google Cloud region europe-west3 (Frankfurt am Main, Germany); our server functions run in the region europe-west1 (St. Ghislain, Belgium). Both regions are within the European Union. Calling a server function generates technical log data at Google (including the time, the outcome of the call, and your device's IP address), used for troubleshooting and abuse prevention, which is automatically deleted after 30 days. The legal basis is Article 6(1)(f) GDPR. Signing in via Google or Apple may involve a transfer of data to Google LLC or Apple Inc. (both USA). Google LLC is certified under the EU-US Data Privacy Framework (DPF); transfers to Google are therefore covered by an adequacy decision of the European Commission (Article 45 GDPR). According to its own statements, Apple Inc. bases international transfers of data out of the EU on Standard Contractual Clauses (Article 46 GDPR) and not on the DPF. Standard Contractual Clauses additionally apply to transfers to Google.
We also use Firebase App Check (Google Play Integrity on Android, Apple DeviceCheck on iOS/iPadOS and macOS) to confirm that requests to our servers genuinely originate from a real, unmodified installation of this app. The legal basis is Article 6(1)(f) GDPR (our legitimate interest in protection against abuse, for example automated attacks). It does not serve to track or profile individual users.
For delivering notifications about shared lists (section 4) we additionally use Firebase Cloud Messaging, likewise provided by Google Ireland Limited and likewise covered by the data processing agreement. Unlike list data, this service cannot be pinned to a European region: Google processes device tokens and notification text on its worldwide infrastructure, including outside the EU. Transfers to Google LLC (USA) are covered by the adequacy decision named above (EU-US Data Privacy Framework) and, in addition, by Standard Contractual Clauses.
On iPhone and iPad, a notification only reaches your device via Apple's push service (Apple Push Notification service); the operating system provides no other route. Apple receives the device token and the text of the notification, that is the list title and the display name, and forwards both to your device. Our contracting party for Apple's developer services is Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland); a transfer to Apple Inc. in the USA cannot be ruled out and is, according to Apple, based on Standard Contractual Clauses (Article 46 GDPR). On Android, Google performs this role.
Your shared lists are also visible to the people you have actively connected your account with, and that is precisely the purpose of sharing. Such a connection is created in two ways: by connecting to each other via QR code, or by redeeming an Abgehakt+ invitation link. Redeeming connects your account and the account of the person who invited you. You then see each other's display names and can offer each other lists to share. You can undo a connection in the app at any time.
If you write to abgehakt@mlp3d.de or info@mlp3d.de, we process your email address, your name if you give it, and everything contained in your message and its attachments. We use this solely to deal with your request and to reply to you. The legal basis is Article 6(1)(b) GDPR where your membership or your use of the app is concerned, otherwise Article 6(1)(f) GDPR. Our legitimate interest is answering enquiries.
Our mailbox is operated on our behalf by manitu GmbH, Welvertstraße 2, 66606 St. Wendel, Germany. A data processing agreement under Article 28 GDPR is in place with them. Under that agreement, processing takes place solely in Germany, in another member state of the European Union, or in a state party to the European Economic Area; no transfer to a third country takes place. There are no further recipients of your message.
We delete support messages no later than twelve months after your request has been dealt with. We keep them longer only while a statutory retention obligation applies or while we need them to establish or defend legal claims.
Please do not send us anything we do not need. A description is almost always enough for a problem with the app. If you send us a screenshot or an extract from a list, we see everything on it, including entries made by other members. If that exceptionally contains special category data within the meaning of Article 9 GDPR, such as health information, we process it solely to answer your request on the basis of your explicit consent under Article 9(2)(a) GDPR and delete it as soon as the request has been dealt with.
Point of contact under the Digital Services Act. The same address abgehakt@mlp3d.de is our point of contact under Articles 11 and 12 of Regulation (EU) 2022/2065. Authorities and you yourself can reach us there, in German and English. If you report unlawful content in a shared list to us or complain about a measure we have taken, we process your details in order to review the report, respond to it, and give you a statement of reasons. The legal basis is Article 6(1)(c) GDPR in conjunction with Articles 16 and 17 of that Regulation. We keep such reports and our replies for no longer than three years so that we can evidence them in a dispute and towards authorities. The twelve-month period does not apply to them.
Local lists and local backups are retained until you delete them or uninstall the app. Shared lists remain stored in the cloud until you (or another member) delete them or end sharing.
If you stop sharing a list ("Stop sharing"), the app first saves a complete copy of that list locally on your device and then deletes the list in the cloud. It is then no longer available to the other members either. The local copy contains all entries of the list, including those from other members, and stays on your device until you delete it.
You can delete your account and all associated cloud data yourself at any time in the app settings ("Delete account"). This removes your user record, deletes shared lists that have no remaining members, removes you from shared lists and sync groups, and disconnects device connections. An active Abgehakt+ membership (section 5) is independent of this and continues until you cancel it through Apple's or Google's native subscription management. If you have redeemed an invitation, we also remove your display name from that invitation when your account is deleted. The invitation itself remains with the person who sent it, so that the same link cannot be redeemed a second time; afterwards it contains only your user ID, which can no longer be linked to anyone once your account is gone.
If you switch off notifications about shared lists, sign out or delete your account, we delete the device token immediately; when you delete your account we also delete your setting together with the time of your consent and the tokens of all your devices. A token that your operating system has withdrawn, for example after an uninstall, is deleted as soon as a delivery to it fails. The short-lived markers used for grouping notifications are deleted when the notification is sent.
Messages you write to us at abgehakt@mlp3d.de or info@mlp3d.de are deleted after the period stated in section 8.
You have the right to obtain access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and to object to processing based on Article 6(1)(f) GDPR (Article 21). To exercise these rights, simply contact us at the email address given above.
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Germany (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, www.baden-wuerttemberg.datenschutz.de). You may also contact the supervisory authority in the country where you live.
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place. The app's category recognition (for example "milk" to "dairy") runs entirely locally on your device against a keyword list that ships with the app.
You are under no statutory or contractual obligation to provide personal data. Without signing in with a Google or Apple account, only the sync and sharing functions are unavailable.
We update this policy when the app or the legal framework changes. The current version is always available in the app settings.