Soba Apps — Legal

Privacy Policy — Leben in Deutschland — Done!

Last updated: 9 July 2026

This Privacy Policy explains what personal data the Leben in Deutschland — Done! mobile application (the “App”) collects, the purposes for which it is processed, where it is stored, and the rights you have over your information. It is written to comply with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Digital Services Act (Digitale-Dienste-Gesetz, DDG) together with the TDDDG.

For any privacy-related question or request, contact hello@sobaapps.com.


1. Data controller (Verantwortlicher / Art. 4(7) GDPR)

The data controller responsible for the processing described in this Policy is:

Anastasiia Kirzhanova Trading as Soba Apps Am Kutscherhaus 6 12555 Berlin, Germany Email: hello@sobaapps.com

Soba Apps is operated as a sole proprietorship (Einzelunternehmen) under the small business scheme of §19 UStG.

This Policy uses “Soba Apps”, “we”, “us”, and “our” to refer to the controller.


2. Data Protection Officer (§ 38 BDSG)

Soba Apps is not required to appoint a Data Protection Officer (DPO). The operator has no employees and does not carry out large-scale automated profiling or systematic monitoring within the meaning of § 38 BDSG. All data protection enquiries are handled directly by the controller at the contact above.


3. Summary

The remainder of this Policy provides the detail required by Articles 13 and 14 of the GDPR.


4. Categories of personal data processed

4.1 Identity and authentication data

4.2 User preferences

4.3 Usage data

4.3a Purchase and entitlement events

While the App runs, the following data is processed through RevenueCat (see Section 6): the account’s user identifier (UUID), Apple transaction and receipt data (transaction identifier, product identifier, purchase timestamp, price and currency as reported by Apple), entitlement status, app version, device type and device identifier (IDFV), device locale, and the IP address from which the App connects. RevenueCat does not receive the user’s name, email address, study progress, or payment instrument details.

4.3b Device-side preferences (iCloud)

The selected Bundesland, language preference, translation display mode, and free-tier usage are additionally stored in the user’s own iCloud key-value storage so they follow the user across their own Apple devices. This synchronisation happens inside the user’s personal iCloud account under Apple’s terms; Soba Apps has no access to the user’s iCloud.

4.3c Usage statistics and crash reports

To understand how features are used, the App sends product analytics events to PostHog (screens viewed, features used, app version, device model, OS version), tied to a pseudonymous identifier. When the App crashes or encounters an error, a crash report (stack trace, device model, OS version, app version, and the sequence of screens opened shortly before the crash) is sent to Sentry. Neither service receives the user’s email address, name, or study answers. Both services are configured to store data in the European Union. Neither is used for advertising, attribution, or cross-app tracking. Usage statistics can be switched off at any time in the App’s settings.

4.3d Technical server logs

When the App communicates with the backend, the receiving servers record the IP address and technical request metadata (timestamp, endpoint, response code) for a short period. These logs exist for security and abuse prevention and are deleted automatically.

4.4 Correspondence

When the user contacts hello@sobaapps.com, the email address and the content of the message are processed for the purpose of handling the request (the mailbox is hosted on Google Workspace).

4.5 Data not collected

The App does not collect: device contacts, photo library, location, microphone or camera input, health or fitness data, financial data beyond the Apple-issued purchase receipt, or advertising identifiers (IDFA).


Data category Purpose Legal basis
Email, display name, user ID Account creation, sign-in, cross-device progress sync Contract (Art. 6(1)(b))
Bundesland, language preference Delivering the correct, readable subset of questions Contract
Per-question progress, ticket attempts Personal progress tracking and resume across devices Contract
Free-tier usage, Full access flag Enforcing the freemium gating rules Contract
Purchase / entitlement events (Section 4.3a) Verifying the purchase, unlocking and restoring the Full access entitlement across devices Contract
Purchase / entitlement events, server logs (4.3d) Fraud prevention, security, abuse prevention Legitimate interest (Art. 6(1)(f))
Usage statistics, crash reports (4.3c) Understanding feature usage, finding and fixing defects Legitimate interest (Art. 6(1)(f))
Correspondence (4.4) Handling the user’s request Contract or legitimate interest
Any data, on valid legal order Compliance with legal obligations Legal obligation (Art. 6(1)(c))

Processing based on legitimate interest is limited to technical data, is never used for advertising, and can be objected to under Art. 21 GDPR (see Section 11). The App does not rely on consent (Art. 6(1)(a)) for any of its current processing.


6. Storage location, processors, and providers

User data is stored on a database operated by Supabase Inc. in the EU region (Frankfurt, Germany). Supabase acts as a data processor under Art. 28 GDPR.

The following further processors are used:

The following companies act as independent providers (separate controllers) when the user interacts with their services:

Payments are processed exclusively by Apple. Soba Apps does not collect, receive, or store any payment instrument details; only Apple transaction data confirming the purchase is retained for entitlement verification.


7. Retention periods


8. Recipients of personal data

Personal data is shared only with the processors and providers listed in Section 6. Where required by Art. 28 GDPR, data processing agreements are in place or the providers operate under their published DPAs.

Personal data is not sold, rented, traded, or otherwise transferred to third parties. The App does not share data with advertisers, data brokers, or marketing networks.

Soba Apps will disclose personal data where legally compelled to do so (e.g., a valid court order; legal basis Art. 6(1)(c) GDPR). Where permitted by law, the affected user will be notified.


9. Advertising and tracking

The App does not integrate advertising networks (Google AdMob, Meta Audience Network, or similar), attribution SDKs (Adjust, AppsFlyer, Branch, or similar), or cross-app tracking systems. The App is a native mobile application and does not use cookies. Because no advertising identifier (IDFA) is collected, the App does not require the iOS App Tracking Transparency prompt.

The usage data received by Soba Apps is limited to the in-app interaction data described in Section 4.3 (stored on the Soba Apps backend) and the pseudonymous statistics and crash reports described in Section 4.3c (PostHog, Sentry — EU-hosted, never used for advertising). RevenueCat processes purchase events exclusively as payment infrastructure.


10. International transfers

Account and study data is stored in the European Union (Supabase, Frankfurt). No replication of the account database outside the EU is performed. Usage statistics and crash reports are stored in the European Union (PostHog, Sentry). PostHog, Inc. and Functional Software, Inc. (Sentry) are US companies; the data itself remains EU-hosted, and any access from the United States (for example for support) is covered by the EU Standard Contractual Clauses in their data processing agreements.

The following transfers to the United States occur:

  1. Purchase and entitlement events (Section 4.3a) are processed by RevenueCat, Inc. on US servers. This transfer is based on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses incorporated in RevenueCat’s data processing agreement.
  2. Account emails (verification codes, password recovery) are delivered through Twilio SendGrid, a US provider, under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
  3. The authentication and platform providers (Apple, Google) are US-headquartered companies and their internal data flows may involve transfers to the United States. Such transfers take place under the EU-US Data Privacy Framework or other appropriate safeguards published by the respective provider.

11. Rights of the data subject

Under the GDPR, the following rights apply:

  1. Access (Art. 15) — obtain a copy of the personal data held about the user.
  2. Rectification (Art. 16) — correct inaccurate or incomplete data.
  3. Erasure (Art. 17) — request deletion of personal data. The fastest route is Settings → Delete account inside the App.
  4. Restriction of processing (Art. 18) — request that processing be paused, e.g. during the resolution of a dispute.
  5. Data portability (Art. 20) — receive the stored data in a structured, machine-readable format. On request Soba Apps provides a JSON export.
  6. Objection (Art. 21) — object to processing based on legitimate interest (Art. 6(1)(f)). For the usage statistics described in Section 4.3c, the simplest route is the switch in the App’s settings.
  7. Withdrawal of consent (Art. 7) — applicable only where consent is the legal basis. The App does not currently rely on consent.
  8. Complaint to a supervisory authority (Art. 77) — see Section 12.

Requests are processed free of charge within the one-month deadline set by Art. 12(3) GDPR. Send all requests to hello@sobaapps.com.


12. Supervisory authority

The competent supervisory authority for Soba Apps is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI) Alt-Moabit 59-61 10555 Berlin, Germany mailbox@datenschutz-berlin.de https://www.datenschutz-berlin.de

Users resident in another EU member state may instead lodge a complaint with their local supervisory authority. A directory is maintained by the European Data Protection Board at https://edpb.europa.eu/about-edpb/about-edpb/members_en.


13. Children

The App is intended for users aged 16 or older, mirroring the official examination: naturalisation applicants aged 16 and above take the test themselves, while children under 16 are naturalised together with their parents and do not take it. Accounts of users under 16 will be deleted on notification.


14. Provision of data

Use of the App is voluntary. Once an account is created, the data described in Sections 4.1–4.3b is the minimum necessary to provide the contracted service; without it, the App cannot be operated. The usage statistics described in Section 4.3c are not required for the service and can be switched off in the App’s settings.


15. Automated decision-making (Art. 22 GDPR)

The App does not carry out automated decision-making, including profiling, that produces legal effects concerning the user or similarly significantly affects the user. The mastery grid is a passive aggregate of the user’s own answers and does not produce any decision in the sense of Art. 22 GDPR.


16. Changes to this Policy

Soba Apps may amend this Policy from time to time. Material changes will be communicated in-app and reflected in the “Last updated” date at the top of this document.


17. Contact

For all privacy questions, GDPR requests, and complaints:

Soba Apps Anastasiia Kirzhanova Am Kutscherhaus 6 12555 Berlin, Germany hello@sobaapps.com

Formal GDPR requests are answered within the one-month deadline of Art. 12 GDPR.