Skip to content

Privacy Policy for JustUs

Last updated: September 10, 2026. This Policy applies to the JustUs app and its related pages on this website.

1. Controller

JustLAB Justin Neubert Albertstr. 11 09526 Olbernhau, Germany Email: kontakt@justlab.app

No data protection officer has been appointed because there is currently no legal obligation to do so.

2. Processing principles

We process personal data only where necessary to provide and secure JustUs, perform a contract, respond to an inquiry, or on the basis of consent. We limit processing to necessary data and erase or anonymize it when its purpose and statutory retention duties cease to apply.

3. Registration, account and sign-in

When you register and use an account, we process in particular your name, email address, internal user ID, login and security data, and information required for the selected sign-in method. This is used to create, authenticate, manage and secure the account. The legal basis is Art. 6(1)(b) GDPR; security logs are also processed on the basis of our legitimate interest in secure, abuse-free operation under Art. 6(1)(f) GDPR.

Data marked as required is necessary for the account. Without it, the account cannot be created or used.

4. Profiles, relationships and app content

To provide the features you use, we process profile details, links between connected accounts, and content you submit. This may include text, photos, videos, shared memories, dates, and other voluntary information. Content is made visible to the connected user as required by the selected feature. The legal basis is Art. 6(1)(b) GDPR. Voluntary details and content can be changed or erased in the app.

Please submit content relating to other people only if you are entitled to do so.

5. Location data

JustUs processes your device location only if you have expressly consented and granted the corresponding operating system permission. Depending on your settings, a precise or approximate location may be processed. It is used exclusively to provide the location-based feature you activated.

If you additionally consent to background location access and grant the required system permission, JustUs may retrieve and process your location while the app is not actively open. Background processing is used exclusively for the location feature you activated. Without this separate permission, no background location access takes place.

Location data is not used for advertising or tracking and is not stored as a movement profile. Where server-side processing is necessary, it is transmitted only for the relevant operation and is then erased. The legal basis is your consent under Art. 6(1)(a) GDPR. Access to device information is based on your consent under Section 25(1) TDDDG.

Consent is voluntary. If you decline, JustUs remains usable; only the respective location feature is unavailable. You may restrict or withdraw general or background access at any time in the app or device settings with future effect. Processing carried out before withdrawal remains lawful.

6. Technical data, logs and security

When the app or website is accessed, the IP address, date and time, requested resource, data volume, operating system, app or browser version, device information, and error and security events may be processed. This is used to deliver content, resolve errors, defend against attacks, and operate the service reliably. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure, reliable and economical operation.

Technical logs are generally retained only as long as necessary for operation and security investigations. Longer retention occurs only for a specific incident or statutory duty.

7. Hosting and Appwrite

Our infrastructure is hosted by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. We use Appwrite for database, storage, account and backend functions. Account, profile, relationship, content and technical data are processed on our behalf. Depending on the operation, the legal bases are Art. 6(1)(b) or (f) GDPR. Agreements under Art. 28 GDPR are in place with processors.

8. In-app purchases and subscriptions

Purchases and payments are processed by Apple through the App Store; Apple is independently responsible for this processing. We do not receive full payment details, only transaction, product and status information needed for activation and management. The legal basis is Art. 6(1)(b) GDPR.

We use RevenueCat, Inc., USA, to manage purchases and subscriptions. RevenueCat processes a pseudonymous app user ID, receipts, product and subscription status, and technical information on our behalf. The legal basis is Art. 6(1)(b) GDPR. US transfers rely on the applicable safeguards under Chapter V GDPR, in particular the EU-US Data Privacy Framework where certification is in place or EU Standard Contractual Clauses.

9. Contacting us

When you contact us by email or form, we process your contact details, message and voluntary information to respond. The legal basis for business- or contract-related inquiries is Art. 6(1)(b) GDPR; otherwise, it is our legitimate interest in responding under Art. 6(1)(f) GDPR.

The website contact form is sent through Resend, Inc., USA. Form and technical delivery data are processed on our behalf. Any US transfer relies on the applicable Chapter V GDPR safeguards. We erase inquiries after final handling unless contractual, evidentiary or statutory retention duties apply.

10. Recipients and international transfers

Recipients are limited to the providers named here, connected users for content expressly shared in the app, and authorities or other bodies where legally required. Any other disclosure requires consent or another legal basis.

For transfers outside the EEA, we use an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, in particular EU Standard Contractual Clauses. A copy of the applicable safeguards may be requested from us.

11. Retention and account deletion

We generally retain account, profile, relationship and app content for the lifetime of the account. Individual content and the account can be erased in the app; deletion may also be requested by email. After account deletion, associated active data is erased or anonymized. Technical backups are overwritten in the regular backup cycle.

This excludes data needed for statutory retention duties or to establish, exercise or defend legal claims. Such data is restricted from other use and erased after the applicable period.

12. Your rights

Subject to statutory conditions, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Consent may be withdrawn at any time with future effect; prior processing remains lawful.

You can exercise your rights at kontakt@justlab.app. You may also lodge a complaint with a supervisory authority, particularly at your habitual residence, place of work, or place of the alleged infringement.

13. Objection and automated decisions

Where processing is based on legitimate interests under Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your situation. We will cease processing unless compelling legitimate grounds or legal claims take precedence.

We do not use solely automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.

14. Changes to this Policy

We update this Privacy Policy when features, providers or the law change. The version published in the app or on this website applies.