Privacy Policy – LensGuard App
1. Controller
Velletti Consulting
Munich, Bavaria, Germany
Email: vel-consulting@ame.velletti.de
Further details: Legal notice (Impressum)
2. Overview
LensGuard helps contact lens wearers with wear-time tracking, replacement reminders, price alerts, and managing a prescription profile. The app uses Google Firebase services. This policy describes which personal data is processed.
3. Account and sign-in
Sign-in uses Firebase Authentication via email/password or Google Sign-In. This processes your email address, a user ID, and – with Google Sign-In – your Google account data (email, name, profile picture). Legal basis: Art. 6(1)(b) GDPR.
4. Health data (prescription)
If you set up your prescription profile, we store your dioptre values (left/right) and your preferred lens brand and model in Cloud Firestore. Dioptre values are health data under Art. 9 GDPR. We process them solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by voluntarily entering these values. You may withdraw consent at any time by deleting the values or your account (see section 8).
5. Stored account data
Your user profile (Cloud Firestore) contains: email address, dioptre values, preferred lens brand/model, the start date of your current lens pair, the last notified price, the device token for push notifications (FCM token), and the account creation date. [PLACEHOLDER: verify and state the Firebase/Firestore region, e.g. europe-west3]
6. Push notifications and local reminders
Price alerts are delivered via Firebase Cloud Messaging; a device token is stored in your profile for this purpose. Daily replacement reminders are local notifications generated directly on your device; reminder settings are stored locally only and never transmitted.
7. Crash reports, analytics, and performance
The app uses Firebase Crashlytics (crash reports, stack traces, device information), Firebase Analytics (app interactions, device identifiers, approximate location), and Firebase Performance Monitoring (app start times, network latencies). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in app stability and improvement) [PLACEHOLDER: add an analytics consent dialog and switch the legal basis to consent – legitimate interest is legally shaky for analytics in the EU]. No advertising SDKs are used and no data is shared with third parties for advertising purposes.
8. Account deletion
You can delete your account at any time directly in the app. This fully removes your user profile in Cloud Firestore and your authentication account (Art. 17 GDPR). Instructions: Delete account.
9. Recipients and international transfers
Google LLC / Google Ireland Ltd. acts as processor (Firebase services). Data may be transferred to the United States. Google is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses apply in addition. More information: firebase.google.com/support/privacy.
10. Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR). To exercise them, email vel-consulting@ame.velletti.de. You also have the right to lodge a complaint with a data protection supervisory authority.
Last updated: 2026-07-12