For the Folino app. Last updated: 3 September 2026.
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Tobias Schiek
Nutzung 17
09353 Oberlungwitz
Germany
Phone: +49 155 65 73 50 69
Email: apps@tschiek.dev
No data protection officer has been appointed, as the requirements of Art. 37 GDPR and Section 38 of the German Federal Data Protection Act (BDSG) are not met.
Folino stores your notes, images and voice recordings on your device. There is no user account with us, and we do not operate a database containing your content.
What is transmitted to us are anonymous usage statistics – in the Android version only (Section 4) – and brief technical error reports (Section 5). Neither contains any identifier that would allow a report to be linked to you or your device. Any other data leaves your device only when you initiate it yourself: when backing up to your Google Drive (Section 6), when making in-app purchases processed by Apple or Google (Section 7), and when using the feedback form (Section 8).
Folino requests individual permissions in order to provide certain features. A permission is requested only at the moment you use the respective feature for the first time, and you may decline it – the remaining features of the app will continue to work. The content created in this way remains on your device. It is transmitted neither to us nor to any third party.
To add an image to a note, you can take a photo or select an existing image. For this purpose the app accesses the camera or your photo library. Only the image you selected or captured is processed; the app does not access the rest of your library. The image is copied into the app's own data store on your device.
Folino can record voice memos as part of a note. The microphone is used only during a recording you have started yourself. The recording is saved as a file on your device. No speech recognition, no analysis of the content and no transmission to us or to third parties takes place.
You can lock individual notes. To unlock them, the app uses your device's screen lock – fingerprint, face recognition or your device passcode. The verification is performed entirely by the operating system; the app only learns whether it succeeded. The app never collects, processes or stores biometric data – such data never leaves the protected area of your device.
When you export a note as a PDF or text file, the app needs access to the storage location you have chosen in order to save the file there. You decide the location and the file name yourself. No further browsing of your storage takes place.
To understand which features of Folino are actually used, and to find errors, we collect usage events to a very limited extent in the Android version of Folino. No such collection takes place in the iOS version.
The database is technically incapable of holding more: it has no column for any further attribute. In addition, only event names from a fixed list stored on the server are accepted – anything else is discarded.
We do not collect IP addresses, device identifiers, advertising IDs, location data or any other attribute that would allow conclusions about you or your device. The content of your notes is never transmitted.
Events are not combined into a usage profile. Immediately upon receipt, events are aggregated into plain counts; individual occurrences are not stored. It is technically impossible for us to determine which events originate from the same device or in which order they occurred.
Because the events are collected without any identifier and immediately aggregated into totals, attributing them to a person is neither intended nor possible. They therefore do not constitute personal data within the meaning of Art. 4(1) GDPR; in accordance with Recital 26, the Regulation does not apply to this processing.
Nor does any access to, or storage of, information on your terminal device within the meaning of Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) take place: for this purpose the app neither reads anything from your device nor stores anything on it. In particular, no cookies or comparable identifiers are set.
The data is stored on servers in Germany operated by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, and deleted after 12 months at the latest. A data processing agreement pursuant to Art. 28 GDPR is in place with this provider. No transfer to third countries outside the EU/EEA takes place. The data is not shared with third parties.
When the statistics service is accessed, the hosting provider inevitably generates access logs. The IP address is
truncated at the moment of writing (11.22.33.44 becomes 11.22.0.0), so that no link
to an individual connection can be established. These logs serve solely to keep the service secure, are never
combined with the statistics data, and are deleted after 30 days.
If an error occurs in the app, it automatically sends a brief report to us so that we can find and fix the error. This applies to both the Android and the iOS version.
The report contains: a technical description of the error, the device model, the operating system version, and the name and version of the app.
The report does not contain: a device identifier, your IP address, the name of your device, or any other attribute that would allow conclusions about you. We are unable to link a report to you or your device; nor can we tell whether two reports originate from the same device.
Legal basis is our legitimate interest in a stable and error-free app pursuant to Art. 6(1)(f) GDPR (cf. Recital 49 GDPR). Since the reports cannot be attributed to any person, the interference is minimal; our interest in becoming aware of errors at all prevails.
Storage location and retention. The reports are stored on our server in Germany operated by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany (data processing agreement pursuant to Art. 28 GDPR in place), and deleted after 90 days. They are not shared with third parties.
On request, the app backs up your data to your own Google account. This feature is optional and switched off by default. To enable it, you sign in with Google. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
For access to Google Drive the app uses exclusively the drive.appdata permission. This limits
access to a hidden folder in your Google Drive created specifically for the app. We can neither see nor
access any of your other files in Google Drive.
When you sign in, the app additionally requests the basic details of your Google account (permissions
openid, email and profile): your email address, your display name and
your profile picture. These details serve solely to show you in the app which account you are signed in with.
They remain on your device and are not transmitted to us. The sign-in token is stored in your device's protected
key store (Keychain or Keystore) and deleted when you sign out.
Your backup file resides in your account, not with us; we receive neither a copy of it nor access to it. No personal data is stored on our servers in this context – sign-in and the storage of the backup take place directly between your device and Google. Which data Google processes in the course of this is governed by Google's privacy policy.
Legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give by signing in. You may withdraw it at any time with effect for the future by signing out in the app or by revoking the app's access in the security settings of your Google account. The lawfulness of processing carried out before the withdrawal remains unaffected.
For data transfers to the USA, Google has certified under the EU-US Data Privacy Framework, which – on the basis of an adequacy decision of the European Commission – ensures compliance with the European level of data protection.
Folino is free to use. Individual additional features can be unlocked for a fee; you may also voluntarily support the development.
Payment is handled exclusively by Apple or Google through your account with them. We do not receive any payment data – neither account number, card details, nor your name or postal address. The app is merely informed whether a purchase was successful so that the feature can be unlocked. This information is stored on your device.
Which data Apple or Google process in the course of the payment is governed by their respective privacy policies; we have no influence over this.
You can reach us by email or use the feedback form within the app. Via the form, your message and – only if you provide it – your email address for a reply are transmitted to us through our server. Providing your email address is optional; without it we simply cannot reply to you. No further details, in particular about your device or your notes, are transmitted with the form.
We process the transmitted data exclusively to handle and respond to your request. The legal basis is our legitimate interest in responding to your enquiry pursuant to Art. 6(1)(f) GDPR; if your enquiry is aimed at concluding a contract, additionally Art. 6(1)(b) GDPR. Your data is deleted once your request has been conclusively dealt with and no statutory retention obligations stand in the way.
Under applicable data protection law you have the following rights vis-à-vis the controller:
Note on usage statistics and error reports. The counts and error reports described in Sections 4 and 5 cannot be attributed to any person, and we retain no additional information that would make such attribution possible. Pursuant to Art. 11(2) GDPR, we are therefore unable to identify individual records, to provide access to them, or to rectify or erase them. Your rights apply without restriction to all other processing described in this Privacy Notice.
No automated decision-making. No automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
The counts of the usage statistics are deleted automatically after 12 months at the latest, technical error reports after 90 days. The hosting provider's access logs are deleted after 30 days. Data from a contact request is deleted once the request has been conclusively dealt with. Data you back up to your Google Drive remains under your own control and is not stored by us.
Your notes, images and voice recordings reside exclusively on your device. They remain there until you delete them yourself or remove the app; there is no retention period on our part, because we have no access to this content.
Otherwise, stored personal data is deleted once it is no longer necessary for the purposes for which it was collected or otherwise processed, and no statutory retention periods stand in the way.
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for us is:
Die Sächsische Datenschutzbeauftragte
(Saxon Commissioner for Data Protection)
Devrientstraße 5
01067 Dresden
Germany
We update this Privacy Notice whenever the app's features or the legal situation change. The version available at this address is the authoritative one; the date of the last change is shown at the top of the document.
This English version is provided for convenience. In the event of any discrepancy, the German version prevails.