Privacy Policy – whiffy App

Last updated: June 2026

Overview

This privacy policy explains what data the whiffy app collects, how we use it, and what rights you have. The data controller within the meaning of the General Data Protection Regulation (GDPR) is Whiffy Labs UG (haftungsbeschränkt), Friedrichstr. 155, 10117 Berlin, Germany.

1. What data we collect

When using the app, we collect: • Account data: name (optional), email address, password (stored encrypted) • Usage data: number of sessions, scents used, session duration • Settings: your notification and marketing preferences • Analytics and device data: app version, operating system, screen views and in-app interactions, collected via our analytics provider to improve app functionality

We do not collect location, camera, or microphone data.

2. Purpose of data processing

We use your data exclusively to: • create and manage your account • provide you with personal statistics about your whiffy sessions • inform you about offers and promotions, if you have consented • operate the app in a technically functional and secure manner We do not process your data for any other purpose without your consent.

3. Legal basis

Processing is based on Art. 6(1)(b) GDPR (performance of a contract, since an account is required to use the app) and Art. 6(1)(a) GDPR (consent) for optional marketing communication.

4. Storage and third-party providers

Your data is stored with our backend provider, Supabase Inc., which provides authentication and data storage for the app. Data is transmitted exclusively over encrypted connections (HTTPS/TLS). We do not sell or rent your data to third parties. Local session data (e.g. your login status) is additionally cached in encrypted form on your device.

5. Retention period

We store your data for as long as your account exists. After your account is deleted, all personal data is removed immediately and irrevocably (see section 6).

6. Your rights

You have the right to: • access the data we hold about you (Art. 15 GDPR) • correct inaccurate data (Art. 16 GDPR) • delete your data (Art. 17 GDPR) — directly in the app via "Profile" → "Delete account", or by emailing us • restrict processing (Art. 18 GDPR) • data portability (Art. 20 GDPR) • withdraw any consent given, with effect for the future To exercise your rights, contact us at mail@whiffy.com. You also have the right to lodge a complaint with a data protection supervisory authority.

7. Children

The app is not directed at children under the age of 16. We do not knowingly collect data from children under this age.

8. Changes to this policy

We may update this privacy policy from time to time. The current version is always available in the app. We will inform you in the app of any material changes.

9. Contact

If you have any questions about data protection, please contact: Whiffy Labs UG (haftungsbeschränkt) Friedrichstr. 155 10117 Berlin Germany Email: mail@whiffy.com VAT ID: DE457986923