Privacy Policy of digirom GmbH for the TrackPlate App
Last Updated: 19.11.2025
1. Data Controller (Art. 13 GDPR)
The entity responsible for data processing under the GDPR is:
- digirom GmbH
- Lechtermanns Ort 11, 48317 Drensteinfurt, Germany
- Roman Perich
- Email: info@digiromeu
2. Collection and Processing of Personal Data
We process personal data only to the extent necessary to provide, operate, and enable the functions of the app.
2.1 Registration and Account Data
- Email address
- Password (stored encrypted)
Supabase is used as the provider for authentication and account management. Supabase stores the data in the cloud and processes it exclusively on behalf of digirom GmbH. A data processing agreement according to Art. 28 GDPR is in place.
2.2 User Inputs
- Text entries
- Uploaded images/prompts
These data are used to provide personalized content and features in the app. They are stored in our cloud.
2.3 Processing by Third Parties
- OpenRouter, Inc: Your text entries and images are transmitted to OpenRouter, Inc to generate AI-based content. OpenRouter, Inc processes these data according to their own privacy policy: Openrouter, Inc Privacy Policy
- Supabase: See section 2.1
3. Legal Basis (Art. 6 GDPR)
- Art. 6(1)(b) GDPR – Processing necessary for the performance of the contract (provision of the app and its functions)
- Art. 6(1)(f) GDPR – Legitimate interest in ensuring app functionality and security
4. Storage and Deletion
- Data is stored as long as the user account exists
- After account deletion, personal data is deleted within 30 days, unless legal retention requirements apply
- Text entries and images are also removed from the cloud after account deletion
5. International Data Transfer
- OpenRouter, Inc is based in the USA. Data is transferred in accordance with the EU–US Data Privacy Framework
- Supabase may store data outside the EU; EU standard contractual clauses are used
6. User Rights
Users have the right to:
- Access their personal data
- Correct inaccurate data
- Delete data (“right to be forgotten”)
- Restrict processing
- Object to processing
- Data portability
To exercise these rights, contact: digirom GmbH - Lechtermanns Ort 11, 48317 Drensteinfurt, Germany
Users also have the right to lodge a complaint with a data protection authority:
- Bavarian State Office for Data Protection Supervision (BayLDA)
- Email: [email protected]
7. Security Measures
- Encrypted transmission to third parties (TLS/HTTPS)
- Access restrictions within the cloud
8. Sharing with Third Parties
Data is only shared with Supabase and OpenRouter, Inc to the extent necessary to provide the app. Other sharing occurs only if legally required.
9. Profiling
No automated decision-making or profiling occurs under Art. 22 GDPR, except for providing personalized content within the app.
10. Changes to the Privacy Policy
We reserve the right to change this privacy policy. Users will be informed in the app about significant changes. Continued use after changes constitutes acceptance.
11. Contact
For privacy questions, contact:
- digirom GmbH
- Phone: +49 1522 7790145, +49 2538 26 29 812
- Email: [email protected]