BrainMaxx Download on the App Store
EnglishDeutsch

Last Updated: September 25, 2026

Privacy Policy

How BrainMaxx collects, uses, shares, and protects personal information.

Privacy Policy — BrainMaxx

Last Updated: September 25, 2026

Juan Vizoso Prado - JV Studio, Einzelunternehmen ("BrainMaxx", "we", "us", or "our"), based in Germany, with registered address at August Bebel Allee 3, 28329 Bremen, Germany, operates the BrainMaxx mobile application ("App") and any associated website (collectively, the "Service").

This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), and other applicable data protection laws.

By using the Service, you agree to the data practices described below. If you do not agree, do not use the Service.

1. Lawful Basis and Transparency

We process personal data based on:

  • Contract — to provide the Service (account management, task tracking, photo and smile verification, app blocking and breaks, brain health scoring, subscription processing).
  • Consent — for optional features such as enabling notifications, granting Screen Time / Family Controls access, granting camera access (for photo and smile verification, watched timed tasks, exercise counting, and the video-call intervention), permitting app tracking for advertising attribution (via Apple's App Tracking Transparency prompt), and (where applicable) providing data for AI processing.
  • Legitimate Interests — for diagnostics and operational logging, product analytics for the onboarding and subscription experience, aggregate (non-identifying) advertising campaign measurement, fraud prevention, security, and improving the Service, balanced against your rights.
  • Legal Obligation — to comply with applicable law (e.g., tax, consumer-protection, and law-enforcement requirements).

This Privacy Policy is accessible in-App and at https://brainmaxxapp.com/privacy. Processing is fair, lawful, transparent, and limited to the purposes set out below.

2. Information We Collect

We minimise data collection and only collect what is necessary to operate the Service.

a. Account Information

  • Sign in with Apple: when you sign in with Apple, we receive your Apple-issued user identifier and, if you choose to share it, your email address (which may be a private "Hide My Email" relay address) and name.
  • Email & password: when you create an account using email, we collect your email address and a hashed password (handled by our authentication provider).
  • Anonymous accounts: you may use the App without creating a permanent account. In that case, we generate a random anonymous identifier so your data persists on your device and in our backend. Anonymous accounts are not linked to any personal identifier unless and until you upgrade to Sign in with Apple or email.

Purpose: account creation, session management, syncing your data across devices.

Legal basis: contract.

b. User-Generated Content

When you use the App, you may create or upload the following:

  • Tasks: titles, descriptions, categories, icons, how often a task can be completed (for example, once per day or repeatable), the reward amount, the chosen verification method (photo or smile), and completion records — including when a task was completed, the points earned, and, for timed or counted tasks, the duration or count. This covers both the built-in tasks you use or favourite and any custom tasks you create.
  • Onboarding answers: your responses to the onboarding questionnaire (your goals, the effects of screen time you say you notice, how you describe yourself, whether you feel you lose control of your screen time, what you have tried before, your daily screen hours and target, and your age bracket). These are your own self-descriptions; we do not ask about medical conditions.
  • Photos for task verification: when a task requires photo proof, you may take a photo using the App. Photos are compressed on-device and transmitted for AI analysis (see Section 4).
  • Automatic photo check-ins for "watched" timed tasks: some timed tasks (for example Read, Study, or Meditate) keep the camera on for the duration of the session and automatically capture a still image every few minutes to confirm you are still doing the task. Each image is compressed on-device and sent for AI analysis in the same way as a verification photo (see Section 4); we store only the pass/fail result, never the image. The camera stops when you leave the session.
  • Selfies for smile verification: when a task requires a smile to be detected, the App uses on-device face/smile detection (Apple's Core Image / Vision frameworks). The image is processed locally on your device and is not transmitted to our servers or to any third party. We do not perform facial recognition, biometric identification, or identity verification, and we do not create or store face templates, faceprints, or biometric identifiers.

Purpose: providing the Service, displaying your content back to you, generating verification results, tracking progress.

Legal basis: contract.

c. Subscription and Purchase Information

  • Apple App Store transactions: when you purchase a subscription, the App Store processes the payment. We do not receive your payment-card details. We receive a transaction identifier, original transaction identifier, product identifier, purchase environment (production / sandbox), and renewal/expiration dates from RevenueCat (our subscription processor).
  • Brain Health points: we record the points you earn by completing tasks (stored internally as "coins"), the task each award came from, and your daily balance, which resets each day. Points have no monetary value and cannot be purchased, spent, transferred, or cashed out.
  • Refund requests: refunds are decided solely by Apple. When you request a refund from Apple, Apple asks us for limited information to help it make a fair decision, and RevenueCat responds to that request on our behalf. The information shared with Apple is limited to: whether the purchased content or subscription was delivered to you, our general refund-handling preference, and confirmations that sample content (the App's free functionality) was available before purchase and that this data sharing has been disclosed to you. We do not share your in-App content or activity data with Apple for this purpose.

Purpose: managing subscriptions, restoring purchases, preventing fraud, supporting the fair resolution of refund requests, fulfilling our contract with you.

Legal basis: contract; legal obligation; legitimate interests (fraud prevention and fair refund resolution). Data sharing for refund requests is also covered by the consent you give under our Terms and Conditions when making in-app purchases.

d. App Blocking Configuration

If you enable the App-Blocking feature, you select which apps or categories of apps to block using Apple's Family Controls / Screen Time framework. We receive and store the limited app-blocking configuration information that Apple's framework makes available to the App so we can apply your block lists and schedules and manage breaks. Your block lists, schedules, and the apps you mark as excluded from brain health are stored only on your device. When the blocking shield appears, the App reads the blocked app's display name to show it on the shield; it is not stored or sent to us. We do not see what you are doing inside other apps, and we do not collect screen contents, keystrokes, messages, browsing activity, or live screen recordings. When you take a break from an intervention, the App records how much break time you use each day (a duration in seconds, with no app names attached) and syncs it to our backend so your progress statistics can reflect it.

Purpose: providing the App-Blocking feature.

Legal basis: contract; consent (Family Controls authorisation).

e. Screen Time and Brain Health

If you grant Screen Time access, iOS provides your screen-time data (time per app, pickups, and history) to a separate report extension that runs inside the App and draws the Screen Time page, the Home screen, and the share card. Apple designs this extension so that the data it receives can never be read by the rest of the App or transmitted anywhere; the extension has no network access. Your Brain Health score is computed inside that extension from your screen time, the difficulty you chose, and the task points you earned today. The score itself never leaves your device. The App writes only data such as your task points, difficulty, and excluded-app selection to shared storage on your device so the extension can read them. Your chosen difficulty and your app-open streak are stored on your device.

The share card lets you export an image of your own statistics (screen time, streak, and Brain Health) through the iOS share sheet. Sharing is entirely your choice; we do not receive or store the image.

Purpose: showing your Screen Time and Brain Health.

Legal basis: consent (Screen Time authorisation); contract.

f. Device, Diagnostic, and Operational Data

  • Local operational logs: we may log technical events (e.g., "subscription refreshed") locally on your device using Apple's `os.log` system. These local logs are not transmitted off-device.
  • Backend operational logs: our backend may create technical logs when processing requests, including timestamps, endpoint names, status or error codes, request identifiers, user or account identifiers, and limited request/response details needed to diagnose issues. For photo verification, logs may include the task title, AI-visible objects or scene descriptions, verification reasons, raw AI responses, and error messages.
  • Apple crash and usage reports: if you have opted in to share diagnostics with app developers in your iOS settings, Apple may provide us with aggregated crash reports through the App Store developer tools. These are governed by Apple's privacy policy; we do not operate our own crash-reporting SDK.

Purpose: diagnosing bugs, maintaining stability and security.

Legal basis: legitimate interests.

g. Notifications

If you grant notification permission, we schedule local notifications on your device (e.g., task reminders, a prompt when you open a blocked app, break-timer expiration). The content and timing of those notifications are stored on your device. All notifications are local to your device; we do not send remote push notifications.

Purpose: delivering reminders and contextual support.

Legal basis: consent.

h. Product Analytics

We use PostHog for product analytics — which onboarding steps you reach, where people drop off, how subscription options perform, and how you use the App's features after onboarding — so we can improve the Service. It collects:

  • Product-usage events that we send deliberately: the onboarding steps you reach, your interactions with the subscription screens (such as viewing a plan, starting a purchase, and the purchase outcome — including the displayed price and currency), and taps on the reminder notifications the App schedules; and how you use the App itself: which screens you open and for how long, the tasks you start, verify and complete (by task type, never the title or description of a task you created), whether a photo or smile check was accepted or rejected and the reason shown to you, timed-session and exercise-counter results (counts, durations, points), whether app blocking is enabled and how many apps or categories you selected (never which ones), how often the blocking screen appeared and whether you tapped its button, which intervention you were shown and how it ended (for example whether you took a break and for how long), the intervention style you chose, the block lists and schedules you save (how many apps and which weekdays, never which apps), the number of apps you excluded from brain health, your Brain Health difficulty, streak rewards, the share card being opened, the daily points reset, progress-screen interactions, settings changes, permission decisions (Screen Time, notifications), and account actions (sign up, sign in, sign out, deletion). A few status attributes are attached to your analytics profile: your subscription product, whether app blocking is on, and your current streak and points balance. We also receive standard app-lifecycle events whenever you use the App (such as the App being opened or backgrounded) and basic technical context attached to those events — the App version and build, your device model and type, operating-system name and version, language/region and time zone, screen dimensions, network connection type (Wi-Fi or cellular), and a session identifier. Where available, campaign-attribution information from AppsFlyer (such as the advertising network and campaign that brought you to the App — see Section 2.i) is also attached to your analytics profile. We also automatically detect rapid repeated taps anywhere in the App and, when that happens, record which screen it occurred on, the tap position, and the type of interface element tapped (occasionally including a tapped button's visible label), so we can find broken or confusing screens. We do not record or replay your screen.

This data is pseudonymous — it is associated with your in-App account identifier but does not include your name, email, or any free-text content you type. The onboarding questionnaire does not ask for sensitive personal data. An approximate location (country, region, city) derived from your IP address at the time of the event may be attached to events; the IP address itself is not stored. Analytics data is hosted in the European Union (Frankfurt, Germany).

We use this data only for our own product analytics. We do not sell it, share it with data brokers, or use it for advertising.

Purpose: understanding and improving the onboarding, subscription, and in-App experience.

Legal basis: legitimate interests, balanced against your rights. You may object to this processing at any time by emailing support@doerpal.com, and we will delete the analytics data associated with your account.

i. Advertising Attribution (AppsFlyer)

We advertise BrainMaxx on advertising platforms (for example TikTok, Meta, and Google). To understand which advertising campaigns bring people to the App — and to spend our advertising budget responsibly — we use AppsFlyer, a mobile measurement (attribution) provider. AppsFlyer helps us answer one question: "did this install or subscription come from one of our ads?" We do not show advertisements inside the App.

App Tracking Transparency (ATT). During onboarding, the App asks for your permission under Apple's App Tracking Transparency framework. Your choice matters:

  • If you allow tracking, the App shares your device's advertising identifier (IDFA) with AppsFlyer so your install and subscription events can be matched to the specific ad you interacted with. AppsFlyer may share the attribution result — including device identifiers and app events such as subscription purchases and their value, where permitted — with the advertising network that showed you the ad, so we and that network can measure and optimise campaign performance.
  • If you decline tracking (or ignore the prompt), the IDFA is not available and is not shared. We receive aggregated, anonymous campaign statistics through Apple's privacy-preserving SKAdNetwork framework, which cannot identify you or your device. In addition, app events without any advertising identifier — together with the technical data described below, such as IP address and device model — may be shared with advertising networks for campaign measurement, where permitted. Where this sharing requires your consent (for example in the EEA or the UK), we forward your ATT choice as your consent signal and declining suppresses it.

Data processed by AppsFlyer (depending on your ATT choice):

  • Device identifiers: the IDFA (only with your ATT permission), the identifier-for-vendor (IDFV), and a random AppsFlyer-generated install identifier.
  • Our pseudonymous in-App account identifier (so install and subscription events belong to the same record). This does not include your name, email, or any content you create in the App.
  • Technical data: IP address (which may be used to derive an approximate, city-level location), device model, operating-system version, and App version.
  • App events: first launch (install), App opens, and subscription events (free-trial start, purchase, renewal — including the product identifier and price). Subscription events are forwarded to AppsFlyer server-side by RevenueCat, our subscription processor.

AppsFlyer processes this data only on our behalf and does not use it for its own purposes; it is not an ad network or data broker and does not sell end-user data. We forward your consent status (your ATT choice) to AppsFlyer so it can honour it under the GDPR and the EU Digital Markets Act.

Purpose: measuring which advertising campaigns lead to installs and subscriptions; paying advertising partners accurately.

Legal basis: consent (identifier-based attribution, via the ATT prompt); legitimate interests (aggregated, non-identifying SKAdNetwork campaign measurement and, where consent is not required, identifier-free campaign measurement). You can withdraw ATT consent at any time in iOS Settings → Privacy & Security → Tracking, and you can object to identifier-free campaign measurement by emailing support@doerpal.com.

j. Support and Feedback

When you contact support or send feedback through the App or our website, we collect the message you write and, if you provide it, your email address, together with your account identifier, App version, iOS version, device model, and IP address (used for abuse prevention). Feedback is delivered to our support inbox by Resend, our email-delivery provider (see Section 5), and stored in our backend. Support and feedback records are retained after account deletion so we can keep a record of support history and prevent abuse.

Purpose: answering your questions, fixing reported problems, preventing abuse.

Legal basis: legitimate interests; contract (where your request concerns your account or purchases).

k. What We Do Not Collect

  • Apart from the product analytics described in Section 2.h and the advertising attribution described in Section 2.i, we do not use third-party analytics or advertising SDKs (no Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude, no Meta Pixel).
  • We do not display advertisements inside the App. The only data shared with advertising platforms is the campaign-measurement (attribution) data described in Section 2.i; your advertising identifier (IDFA) is shared only with your App Tracking Transparency permission.
  • We do not collect your screen-time history or your Brain Health score; both are processed only in the on-device report extension described in Section 2.e. We do not collect your full list of installed apps or information about what you do inside other apps.
  • We do not collect precise location data. (An approximate, city-level location may be derived from your IP address for attribution and analytics, as described above.)
  • We do not record or replay your screen.
  • We do not sell or rent your personal data to anyone.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: maintaining your account, syncing your tasks and progress; verifying photo and smile-based task completions; running the app-blocking, intervention, and break features.
  • Subscription management: processing purchases, restoring entitlements, sending renewal notifications, detecting refunds, and responding to Apple's refund-information requests when you ask Apple for a refund (see Section 2.c).
  • Service improvement: diagnosing errors through operational logs; understanding how people move through onboarding and use the App's features via PostHog (see Section 2.h), including occasionally testing different versions of our subscription screens and prices with different users — the version you were shown is recorded with your account and analytics data; understanding aggregate, technical reliability metrics.
  • Advertising measurement: understanding which advertising campaigns bring users to BrainMaxx (see Section 2.i). We do not use your in-App content (tasks, photos, onboarding answers) for advertising, and we do not build behavioural marketing profiles from what you do inside the App.
  • Legal and security: enforcing our Terms, complying with law, preventing abuse and fraud, protecting our rights and yours.

4. Photos, Camera, and AI Processing — In Detail

Because the App uses AI in ways that may be sensitive, we explain those flows separately:

a. Photo Verification

When you take a photo to verify a task:

  • The photo is captured by the App on your device.
  • The App resizes the image to a maximum of 1024×1024 pixels and applies JPEG compression.
  • The compressed image is sent through our backend (Supabase Edge Functions) to our AI provider, OpenRouter, which routes the request to an AI model for analysis. The specific AI model may change over time to improve reliability, safety, cost, or performance.
  • The AI model returns a structured verification result (a yes/no decision and a short reason) describing whether the photo plausibly relates to the task.
  • We store only the verification result — not the photo itself — in our database.
  • The temporary copy of the photo on your device is deleted as soon as the verification request completes.

For "watched" timed tasks, the same flow runs automatically at intervals during the session rather than on a single tap; only the pass/fail result is stored.

The title of the task is sent along with the photo so the AI model knows what to look for. When you create or rename a custom photo task, its title is also sent (without any photo) to generate a short description of what a matching photo should show; that description is stored with the task.

We do not retain the photo on our servers, and we do not use your photos to train AI models. OpenRouter's and applicable model-provider privacy and data-retention policies apply to data while it is being processed. See:

  • OpenRouter: https://openrouter.ai/privacy

b. Smile Verification

Smile detection is performed entirely on your device using Apple's Core Image / Vision frameworks. The image is not transmitted off-device, is not sent to any third party, and is not stored on our servers. We do not generate or store face templates or biometric identifiers.

c. Exercise Counting (Push-Ups, Squats, Plank)

Some tasks count repetitions or time a hold using your device's camera and Apple's Vision body-pose framework. All pose detection happens entirely on your device; the camera feed is not transmitted off-device, not sent to any third party, and not stored on our servers. We store only the resulting count or duration. We do not perform identity recognition and do not create biometric identifiers.

d. Video-Call Intervention

One intervention shows your front camera on screen, as in a video call, while your brain talks to you. The camera feed is a live preview only. No frames are captured, stored, analysed, or transmitted, and no microphone is used.

5. Third-Party Service Providers

We use the following service providers ("processors"), each of whom we have contracted with to handle data only on our instructions and to maintain appropriate security measures:

ProviderPurposeData SharedPrivacy Policy
Apple Inc.Sign in with Apple, App Store payment processingApple-issued user identifier, optional name and email (or relay), App Store receiptshttps://www.apple.com/legal/privacy/
Supabase, Inc.Backend hosting (Postgres database, authentication, Edge Functions). Data is hosted in West US (North California).All account, task, onboarding-answer, points, break-time, and subscription recordshttps://supabase.com/privacy
OpenRouter, Inc. and AI model providers available through OpenRouterAI inference routing and model processing for photo verification and watched-task check-ins. The specific AI models may change over time.Task titles, photos for verification, and the task's verification criteriahttps://openrouter.ai/privacy
RevenueCat, Inc.Subscription management and entitlement validation; responding to Apple's refund-information requests on our behalf (see Section 2.c); server-side forwarding of subscription events to AppsFlyer (see Section 2.i)Apple App Store transaction identifiers, product identifiers, purchase events; pseudonymous user identifier; device advertising identifiers for attribution (IDFA only with your ATT permission, IDFV); refund-request consumption data shared with Apple (delivery status, refund-handling preference)https://www.revenuecat.com/privacy
PostHog (PostHog, Inc., hosted on PostHog Cloud EU in Frankfurt, Germany)Product analytics (onboarding, subscription screens, and in-App feature usage)Pseudonymous in-App account identifier, product-usage events (onboarding steps and subscription/paywall interactions, including displayed price and currency), screens viewed, and feature-usage events (task starts and completions by task type, verification outcomes, timed-session results, app-blocking status and item counts, intervention and break events, block-list and schedule counts, excluded-app counts, difficulty, streak rewards, progress and settings interactions, permission and account actions), plus profile attributes (subscription product, blocking status, streak, points balance), app-lifecycle events, rapid-repeated-tap detection events (screen and tap position), campaign-attribution properties (see Section 2.h), approximate IP-derived location (country/region/city; IP not stored), App version and build, device model and type, OS name and version, language/region, time zone, screen dimensions, network connection type, session identifierhttps://posthog.com/privacy
AppsFlyer Ltd.Mobile advertising attribution (campaign measurement) — see Section 2.iDevice identifiers (IDFA only with your ATT permission, IDFV, AppsFlyer install ID), pseudonymous in-App account identifier, IP address and derived city-level location, device model, OS and App version, install/app-open events, subscription eventshttps://www.appsflyer.com/legal/services-privacy-policy/
Resend, Inc.Delivery of support and feedback emails to our support inbox (see Section 2.j)Feedback message, optional email address, account identifier, App/iOS version, device model, IP addresshttps://resend.com/legal/privacy-policy

We do not sell or rent personal information to any third party. Apart from the product analytics described in Section 2.h and the advertising attribution described in Section 2.i, we do not use advertising or marketing-analytics partners. Where attribution results are shared with the advertising network that showed you an ad (Section 2.i), that network acts as a separate controller of that data under its own privacy policy.

6. International Data Transfers

We are based in Germany, but the Service uses processors in the United States and other countries, including Supabase hosting in West US (North California). When data is transferred to processors outside the EEA (such as OpenRouter, AI model providers, RevenueCat, Resend, Apple, and Supabase), we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum where applicable, and supplementary measures such as encryption in transit and at rest. AppsFlyer Ltd. is headquartered in Israel, which is covered by a European Commission adequacy decision; where AppsFlyer uses sub-processors outside the EEA, transfers are safeguarded by SCCs.

By using the Service you understand that your data may be transferred to and processed in countries with data-protection laws different from those of your country.

7. Data Retention

We retain personal data only as long as necessary for the purposes described above:

  • Account data, tasks, onboarding answers, points transactions, break-time totals, subscription records: retained for the lifetime of your account.
  • Photos for task verification: not retained on our servers (processed in flight only).
  • Product analytics (PostHog): retained for twelve (12) months.
  • Advertising attribution data (AppsFlyer): retained while we run advertising campaigns, in line with AppsFlyer's data-retention policy; deleted earlier on request (see the Your Rights section below).
  • Backend operational logs: retained only as long as reasonably needed for debugging, security, abuse prevention, and service reliability, then deleted or anonymised under our provider retention settings.
  • Subscription webhook payloads: retained for twelve (12) months, then deleted.
  • Photo-verification records: the AI's raw text response is deleted from our database after ninety (90) days; the verification outcome is kept for the lifetime of your account.
  • Support and feedback messages: the sender IP address is deleted after ninety (90) days; the message itself is retained (see Section 2.j).
  • Rate-limit counters: retained for up to thirty (30) days, then deleted. Short-term per-IP counters are deleted after two (2) days.
  • Backups: incremental database backups taken by Supabase are retained per Supabase's standard policy and are purged on rotation.

When you delete your account (Settings → Delete my account, or by emailing support@doerpal.com), we delete your records from our database and instruct RevenueCat to delete your customer record. Deletion cascades through all related tables (tasks, points transactions, subscription records). Raw subscription webhook payloads are not linked to your account record and are deleted on the twelve-month schedule described above. On request, we will also instruct AppsFlyer to delete the attribution record associated with your device/account. Support and feedback messages are retained after account deletion (see Section 2.j). Anonymised, aggregated information that does not identify you may be retained indefinitely.

Note: deleting the App or signing out does not automatically delete your account. You must explicitly delete the account.

8. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data (you can update most data directly in the App).
  • Erasure — request deletion of your account and personal data.
  • Restriction — request that we limit processing of your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — for any processing based on consent (e.g., notifications, camera, Family Controls, app tracking for advertising attribution). You can withdraw tracking consent at any time in iOS Settings → Privacy & Security → Tracking.
  • No automated decision-making — we do not make decisions producing legal or similarly significant effects about you using solely automated means. AI photo verification is informational only; you can retry, skip verification, or contact us to dispute a result.
  • Lodge a complaint — with your local supervisory authority (see the EU / EEA / UK Residents section below).

To exercise these rights, use the in-App Settings (sign-out and account deletion are available there) or email support@doerpal.com. We respond within one calendar month, extendable by two further months for complex requests as permitted by law.

California Residents (CCPA / CPRA)

If you are a California resident, you have the rights to know, access, correct, delete, limit use of sensitive personal information, opt out of "selling" or "sharing", and not be discriminated against for exercising your rights. We do not sell your personal information. As described in Section 2.i, we disclose device identifiers and campaign-measurement data to our attribution provider, and attribution data (including app events such as subscription purchases) may be shared with advertising networks for advertising measurement — your advertising identifier (IDFA) only with your App Tracking Transparency permission. To the extent this constitutes "sharing" for cross-context behavioural advertising under the CCPA/CPRA, you may opt out of identifier-based sharing at any time by declining the App Tracking Transparency prompt or disabling tracking in iOS Settings → Privacy & Security → Tracking, and you may opt out of all attribution sharing by emailing support@doerpal.com. The categories of personal information we collect and disclose to processors are described in Section 2 above.

To exercise your CCPA / CPRA rights, email support@doerpal.com. We will verify your identity using the email associated with your account.

EU / EEA / UK Residents

You have the rights set out in Articles 15–22 of the GDPR. You may lodge a complaint with the data-protection authority in your EU member state, the UK Information Commissioner's Office (ICO, https://ico.org.uk), or the Swiss FDPIC.

As we are based in Germany, the competent supervisory authority is the data-protection authority of the federal state ("Land") in which our registered address is located. You may also lodge a complaint with the supervisory authority in your EU member state, place of work, or place of the alleged infringement. A list of European data-protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may complain to the Information Commissioner's Office at https://ico.org.uk.

9. Children's Privacy

The Service is not directed at children under 13, and you must be at least 13 years old to use it (see our Terms and Conditions). If you are in the European Union and under 16 (the age of digital consent in Germany and several other member states), any processing based on your consent requires the consent of a parent or legal guardian. If we learn that we have collected personal data from a child under 13, we will delete that account and its data. Parents or guardians can contact us at support@doerpal.com.

10. Security

We implement industry-standard technical and organisational measures to protect your personal data, including:

  • TLS 1.2+ for all network traffic.
  • Encryption at rest for our backend database (provided by Supabase).
  • Row-level security policies that limit access to your own records.
  • Server-side rate limiting to prevent abuse.
  • Secret management for third-party API keys (OpenRouter, RevenueCat).
  • Restricted, audited access to production systems.

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority — the Bremen State Commissioner for Data Protection and Freedom of Information (Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen) — within 72 hours of becoming aware of it, and we will inform affected users without undue delay.

No system is 100% secure. You are responsible for keeping your device, your Apple ID, and your account credentials secure. If you believe your account has been compromised, contact us immediately at support@doerpal.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our processors, or applicable law. When we make changes, we will update the "Last Updated" date at the top of this document and post the revised Policy in the App and on our website. Where applicable law specifically requires individual notice of a particular change, we will provide it. Your continued use of the Service after the updated Policy is posted constitutes acceptance of the changes.

Language: this Privacy Policy is available in English at https://brainmaxxapp.com/privacy and in German at https://brainmaxxapp.com/de/privacy. If you are a data subject habitually resident in Germany, the German version is binding and prevails in case of conflict. For all other users the English version prevails.

12. Contact Us

Juan Vizoso Prado - JV Studio, Einzelunternehmen is the data controller of your personal data.

  • Email: support@doerpal.com
  • Postal address: August Bebel Allee 3, 28329 Bremen, Germany
  • Website: https://www.jvstudio.org/
BrainMaxx

Block the scroll. Heal your brain.

HomeFAQImpressumPrivacyTerms
support@doerpal.com

© BrainMaxx 2026, All Rights Reserved.