Datenschutzhinweise zur Android-App ViMiViTa (Planung, Training, Ernährung, Tracking, Fortschritt und Empfehlungen)
Diese Datenschutzerklärung wurde mit Unterstützung von Claude (Anthropic) als Entwurf erstellt und ist keine Rechtsberatung. Der Verantwortliche ist keine Juristin/kein Jurist. Vor der Veröffentlichung im Google Play Store wird empfohlen, den Text durch eine rechtlich fachkundige Person (Anwältin/Anwalt für Datenschutzrecht) prüfen zu lassen – insbesondere im Hinblick auf die konkrete Vertragsgestaltung mit den unten genannten Drittanbietern und auf länderspezifische Besonderheiten.
Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) für die Verarbeitung personenbezogener Daten im Rahmen der App ViMiViTa ist:
ViMiViTa wird nicht im Rahmen einer gewerblichen Tätigkeit angeboten. Ein Hinweis zur eventuell separat zu prüfenden Impressumspflicht findet sich in Abschnitt 17.
ViMiViTa ist so gebaut, dass möglichst viel lokal auf deinem Gerät bleibt. Ohne aktives Anlegen eines Cloud-Kontos läuft die App vollständig offline und lokal; es werden dann keine Daten an mich oder Dritte übertragen (mit Ausnahme automatischer Absturz- und Integritätsdiagnosen, siehe Abschnitte 7–8).
Erst wenn du bestimmte optionale Funktionen aktiv nutzt, verlassen Daten dein Gerät:
| Funktion | Optional? | Wohin gehen die Daten? |
|---|---|---|
| Cloud-Synchronisierung (Firebase-Konto) | Ja – muss aktiv eingerichtet werden | Firebase (Google) Authentication & Firestore |
| KI-gestützte Foto-Analyse / Plan-Import | Ja – erfordert eigenen API-Key | Direkt an den von dir gewählten KI-Anbieter (OpenAI, Anthropic, Google Gemini oder eigener Endpunkt) |
| Absturzberichte | Automatisch bei Abstürzen/Fehlern | Firebase Crashlytics (Google) |
| Geräte-Integritätsprüfung | Automatisch bei Cloud-Nutzung | Google Play Integrity / Firebase App Check |
Wenn du dich entscheidest, ein Konto anzulegen (z. B. um deine Daten zwischen Geräten zu synchronisieren oder als Backup), nutzt ViMiViTa Firebase Authentication von Google. Dabei werden verarbeitet:
Diese Anmeldedaten werden benötigt, um deine synchronisierten Daten eindeutig deinem Konto zuzuordnen und den Zugriff darauf abzusichern.
Kernfunktion von ViMiViTa ist die Erfassung und Auswertung folgender Daten, die du selbst eingibst oder über verbundene Quellen importierst:
Diese Daten gelten als Gesundheitsdaten im Sinne von Art. 9 Abs. 1 DSGVO und unterliegen einem besonderen Schutz. Sie werden standardmäßig ausschließlich lokal auf deinem Gerät in einer verschlüsselten/lokalen Datenbank gespeichert. Eine Übertragung erfolgt nur, wenn du die Cloud-Synchronisierung (Abschnitt 6) aktiv einrichtest.
Update-Sicherheit: Deine lokalen Daten bleiben bei App-Updates erhalten. Schema-Änderungen erfolgen ausschließlich additiv (keine Löschung bestehender Spalten/Tabellen), sodass du nach einem Update deine bisherigen Daten unverändert wiederfindest.
ViMiViTa bietet optionale KI-gestützte Funktionen an, z. B. die Analyse von Mahlzeitenfotos oder den Import von Trainings-/Ernährungsplänen aus Dateien. Diese Funktionen sind standardmäßig deaktiviert und erfordern, dass du selbst einen API-Key für einen der folgenden Anbieter in der App hinterlegst:
Wichtig: ViMiViTa betreibt hierfür keinen eigenen Server und keinen eigenen Proxy. Wenn du eine KI-Funktion nutzt, werden die dafür notwendigen Daten (z. B. ein Mahlzeitenfoto oder der Inhalt einer importierten Plandatei) direkt von deinem Gerät an den von dir ausgewählten und konfigurierten Anbieter gesendet – unter Verwendung deines eigenen API-Keys. Es ist stets nur ein Anbieter gleichzeitig aktiv.
Es gelten zusätzlich die Datenschutzbestimmungen des jeweils von dir gewählten Anbieters (OpenAI, Anthropic bzw. Google), da dieser als eigenständig Verantwortlicher für die Verarbeitung der an ihn übermittelten Daten auftritt. Ich habe als Entwickler des Hobbyprojekts keinen Einblick in diese Übertragung und keinen Zugriff auf deinen API-Key oder die übermittelten Inhalte.
Wenn du die Cloud-Synchronisierung aktivierst, werden deine App-Daten (Profile, Trainings- und Ernährungspläne, Protokolle, Fortschrittswerte) verschlüsselt über das Internet an Google Firebase (Cloud Firestore) übertragen und dort unter deiner Nutzer-ID gespeichert, damit du sie auf mehreren Geräten nutzen und bei Geräteverlust wiederherstellen kannst.
Der Zugriff auf diese Daten ist serverseitig über Sicherheitsregeln so eingeschränkt, dass ausschließlich du selbst (authentifiziert über dein Konto) lesend und schreibend auf deine eigenen Daten zugreifen kannst. Ein Hard-Delete einzelner Datensätze über die App ist aus synchronisationstechnischen Gründen bewusst nicht vorgesehen (stattdessen „Tombstone“-Markierungen); die vollständige Löschung erfolgt über die in Abschnitt 12 beschriebene Funktion.
Zur Verbesserung der Stabilität der App nutzt ViMiViTa Firebase Crashlytics von Google. Im Falle eines Absturzes oder unbehandelten Fehlers werden automatisch technische Diagnoseinformationen übermittelt, u. a.:
Diese Berichte enthalten nach Möglichkeit keine Inhalte deiner Gesundheits- oder Trainingsdaten, sondern beschränken sich auf technische Fehlerinformationen zur Fehlerbehebung.
Zur Absicherung der Cloud-Funktionen gegen Missbrauch (z. B. automatisierte Zugriffe, manipulierte App-Versionen) nutzt ViMiViTa Google Play Integrity in Verbindung mit Firebase App Check. Dabei werden geräte- und app-bezogene Integritätssignale an Google übermittelt, um zu bestätigen, dass Anfragen von einer echten, unveränderten Installation der App stammen. Diese Prüfung findet nur statt, wenn du Cloud-Funktionen nutzt.
Lokale Daten verbleiben auf deinem Gerät, bis du sie selbst löschst (z. B. durch Löschen des lokalen Profils oder Deinstallation der App). Cloud-synchronisierte Daten werden auf Servern von Google Firebase gespeichert (Rechenzentren gemäß der von Google für das jeweils genutzte Projekt festgelegten Region) und dort so lange vorgehalten, bis du dein Konto und deine Cloud-Daten aktiv löschst (Abschnitt 12) oder eine gesetzliche Aufbewahrungspflicht entgegensteht.
Absturzberichte und Integritätssignale werden gemäß den Standard-Aufbewahrungsfristen von Google Firebase Crashlytics bzw. Google Play Integrity verarbeitet und gespeichert.
Die Verarbeitung deiner Daten erfolgt auf folgenden Rechtsgrundlagen:
Du kannst eine erteilte Einwilligung jederzeit mit Wirkung für die Zukunft widerrufen, z. B. durch Deaktivieren der Cloud-Synchronisierung oder vollständige Löschung deines Kontos.
Dir stehen nach der DSGVO insbesondere folgende Rechte zu:
Für die Ausübung dieser Rechte kannst du dich jederzeit formlos per E-Mail an die in Abschnitt 16 genannte Kontaktadresse wenden.
ViMiViTa bietet dir zwei unterschiedliche, direkt in der App verfügbare Löschwege, je nachdem, welche Daten du entfernen möchtest:
Über die Benutzerverwaltung in der App kannst du ein einzelnes lokales Profil löschen. Dabei werden ausschließlich die lokal auf dem Gerät gespeicherten Daten dieses Profils entfernt. Eventuell in der Cloud gespeicherte Daten dieses Kontos bleiben davon unberührt.
Im Bereich „Sync Center“ der App steht die Funktion „Konto und Cloud-Daten löschen“ zur Verfügung. Nach einer zweistufigen Sicherheitsabfrage (Bestätigung durch Eingabe deiner E-Mail-Adresse) wird ein serverseitiger Löschvorgang ausgelöst, der dein Firebase-Konto sowie sämtliche zugehörigen Cloud-Daten (Profile, Pläne, Protokolle, Änderungsverlauf) unwiderruflich entfernt. Dieser Vorgang kann nicht rückgängig gemacht werden.
Alternativ kannst du dein Löschbegehren auch jederzeit per E-Mail an mich richten (Kontakt siehe Abschnitt 16).
Folgende Dritte können im Rahmen der oben beschriebenen, jeweils optionalen Funktionen Zugriff auf (Teile deiner) Daten erhalten:
| Anbieter | Zweck | Datenschutzhinweise |
|---|---|---|
| Google / Firebase (Google Ireland Ltd. bzw. Google LLC) | Authentifizierung, Cloud-Synchronisierung, Absturzberichte, App-/Geräteintegrität | policies.google.com/privacy |
| OpenAI (nur bei aktiver Nutzung mit eigenem Key) | KI-Analyse von Fotos/Plänen | openai.com/policies/privacy-policy |
| Anthropic (nur bei aktiver Nutzung mit eigenem Key) | KI-Analyse von Fotos/Plänen | anthropic.com/legal/privacy |
| Google Gemini (nur bei aktiver Nutzung mit eigenem Key) | KI-Analyse von Fotos/Plänen | policies.google.com/privacy |
Eine Übermittlung an einen eigenen, von dir angegebenen OpenAI-kompatiblen Endpunkt liegt vollständig in deiner eigenen Verantwortung; ich habe keinen Einfluss auf und keine Kenntnis von dessen Datenverarbeitung.
ViMiViTa richtet sich nicht gezielt an Kinder. Personen unter 16 Jahren sollten die App nur mit Zustimmung eines Erziehungsberechtigten nutzen, insbesondere im Hinblick auf die Verarbeitung von Gesundheitsdaten und die Nutzung optionaler Cloud- und KI-Funktionen.
Diese Datenschutzerklärung kann angepasst werden, wenn sich die Funktionen von ViMiViTa oder die zugrunde liegenden rechtlichen Anforderungen ändern. Die jeweils aktuelle Version ist über den in der App bzw. im Play Store hinterlegten Link abrufbar; das Datum unter „Stand“ am Anfang dieses Dokuments zeigt die letzte Aktualisierung.
Für Fragen zum Datenschutz, zur Ausübung deiner Rechte oder zur Löschung deiner Daten wende dich bitte per E-Mail an:
Dieses Dokument ist ein von Claude (Anthropic) im Auftrag des Verantwortlichen erstellter Entwurf. Es stellt keine Rechtsberatung dar und ersetzt keine individuelle rechtliche Prüfung. Es wird ausdrücklich empfohlen, den Text vor der Veröffentlichung von einer fachkundigen Rechtsanwältin/einem fachkundigen Rechtsanwalt für Datenschutzrecht prüfen zu lassen.
Ob neben dieser Datenschutzerklärung zusätzlich ein gesondertes Impressum (z. B. nach § 5 DDG/TMG bzw. den entsprechenden Nachfolgeregelungen) erforderlich ist, hängt von Kriterien ab, die hier nicht abschließend beurteilt werden können – u. a. davon, ob die Bereitstellung der App trotz „Hobbyprojekt“-Charakters als geschäftsmäßiger Telemediendienst gilt (z. B. bei Regelmäßigkeit, Umfang, ggf. auch bei kostenloser Bereitstellung mit Werbe- oder Reichweitenabsicht). Dies sollte gesondert und im konkreten Einzelfall rechtlich geprüft werden; dieses Dokument trifft dazu bewusst keine abschließende rechtliche Einschätzung.
Privacy information for the ViMiViTa Android app (planning, training, nutrition, tracking, progress and recommendations)
This privacy policy was drafted with the help of Claude (Anthropic) and is not legal advice. The controller is not a lawyer. The German version is the original; this English text is a translation provided for convenience. Before publishing on Google Play, it is recommended to have the text reviewed by a qualified data-protection lawyer, especially regarding the exact contractual arrangements with the third-party providers named below and any country-specific requirements.
The controller responsible for the processing of personal data within the ViMiViTa app, as defined by the General Data Protection Regulation (GDPR), is:
ViMiViTa is not offered as part of a commercial activity. A note on whether a separate legal notice ("Impressum") requirement may apply is included in section 17.
ViMiViTa is built so that as much as possible stays local on your device. Without actively creating a cloud account, the app runs entirely offline and locally; in that case no data is transmitted to me or to any third party (with the exception of automatic crash and integrity diagnostics, see sections 7–8).
Data only leaves your device once you actively use certain optional features:
| Feature | Optional? | Where does the data go? |
|---|---|---|
| Cloud synchronization (Firebase account) | Yes – must be actively set up | Firebase (Google) Authentication & Firestore |
| AI-assisted photo analysis / plan import | Yes – requires your own API key | Directly to the AI provider you choose (OpenAI, Anthropic, Google Gemini, or your own endpoint) |
| Crash reports | Automatic on crashes/errors | Firebase Crashlytics (Google) |
| Device integrity check | Automatic when using cloud features | Google Play Integrity / Firebase App Check |
If you choose to create an account (e.g. to synchronize your data across devices or as a backup), ViMiViTa uses Firebase Authentication from Google. This processes:
This sign-in data is needed to uniquely associate your synchronized data with your account and to secure access to it.
The core function of ViMiViTa is collecting and evaluating the following data, which you enter yourself or import from connected sources:
This data qualifies as health data under Art. 9(1) GDPR and is subject to special protection. By default it is stored exclusively locally on your device in a local database. It is only transmitted elsewhere if you actively set up cloud synchronization (section 6).
Update safety: Your local data is preserved across app updates. Schema changes are strictly additive (existing columns/tables are never deleted), so after an update you will find your existing data unchanged.
ViMiViTa offers optional AI-assisted features, such as analyzing meal photos or importing training/nutrition plans from files. These features are disabled by default and require you to enter your own API key for one of the following providers in the app:
Important: ViMiViTa does not operate its own server or proxy for this purpose. When you use an AI feature, the data needed for it (e.g. a meal photo or the contents of an imported plan file) is sent directly from your device to the provider you selected and configured, using your own API key. Only one provider is ever active at a time.
The privacy policy of the provider you chose (OpenAI, Anthropic, or Google respectively) additionally applies, since that provider acts as an independent controller for the data transmitted to it. As the developer of this hobby project, I have no visibility into that transmission and no access to your API key or the content sent.
If you enable cloud synchronization, your app data (profiles, training and nutrition plans, logs, progress values) is transmitted over an encrypted connection to Google Firebase (Cloud Firestore) and stored there under your user ID, so you can use it across multiple devices and restore it if you lose a device.
Access to this data is restricted server-side through security rules so that only you (authenticated via your account) can read and write your own data. Hard-deleting individual records through the app is deliberately not supported for synchronization reasons (tombstone markers are used instead); full deletion is handled by the function described in section 12.
To improve app stability, ViMiViTa uses Firebase Crashlytics from Google. In the event of a crash or unhandled error, technical diagnostic information is automatically transmitted, including:
Where possible, these reports do not contain the content of your health or training data — they are limited to technical error information used for troubleshooting.
To protect the cloud features against abuse (e.g. automated access, tampered app builds), ViMiViTa uses Google Play Integrity together with Firebase App Check. This transmits device- and app-related integrity signals to Google to confirm that requests originate from a genuine, unmodified installation of the app. This check only happens when you use cloud features.
Local data stays on your device until you delete it yourself (e.g. by deleting the local profile or uninstalling the app). Cloud-synchronized data is stored on Google Firebase servers (data-center region as determined by Google for the project in use) and retained there until you actively delete your account and cloud data (section 12), or unless a legal retention obligation requires otherwise.
Crash reports and integrity signals are processed and stored according to the standard retention periods of Google Firebase Crashlytics and Google Play Integrity respectively.
Your data is processed on the following legal bases:
You may withdraw any consent given at any time, with effect for the future, e.g. by disabling cloud synchronization or fully deleting your account.
Under the GDPR you have, in particular, the following rights:
To exercise these rights, you may contact me informally at any time by email using the contact address given in section 16.
ViMiViTa offers two different deletion paths, available directly in the app, depending on which data you want to remove:
Through the user management section in the app, you can delete a single local profile. This removes only the data stored locally on the device for that profile. Any data for that account stored in the cloud remains unaffected.
The "Sync Center" section of the app offers a "Delete account and cloud data" function. After a two-step confirmation (a warning plus typing your email address to confirm), a server-side deletion process is triggered that irrevocably removes your Firebase account and all associated cloud data (profiles, plans, logs, change history). This action cannot be undone.
Alternatively, you may send your deletion request to me by email at any time (see contact details in section 16).
The following third parties may receive access to (parts of) your data, depending on which of the optional features described above you use:
| Provider | Purpose | Privacy information |
|---|---|---|
| Google / Firebase (Google Ireland Ltd. / Google LLC) | Authentication, cloud synchronization, crash reports, app/device integrity | policies.google.com/privacy |
| OpenAI (only if actively used with your own key) | AI analysis of photos/plans | openai.com/policies/privacy-policy |
| Anthropic (only if actively used with your own key) | AI analysis of photos/plans | anthropic.com/legal/privacy |
| Google Gemini (only if actively used with your own key) | AI analysis of photos/plans | policies.google.com/privacy |
Any transmission to a custom, OpenAI-compatible endpoint that you specify yourself is entirely your own responsibility; I have no influence over, and no knowledge of, how that endpoint processes data.
ViMiViTa is not specifically directed at children. Individuals under 16 should only use the app with the consent of a parent or legal guardian, particularly with regard to the processing of health data and the use of optional cloud and AI features.
This privacy policy may be updated if ViMiViTa's features or the underlying legal requirements change. The current version is always available via the link provided in the app or on the Play Store listing; the date under "Last updated" at the top of this document shows the most recent revision.
For questions about privacy, to exercise your rights, or to request deletion of your data, please contact:
This document is a draft prepared by Claude (Anthropic) on behalf of the controller. It does not constitute legal advice and does not replace an individual legal review. It is expressly recommended that the text be reviewed by a qualified data-protection lawyer before publication.
Whether, in addition to this privacy policy, a separate legal notice ("Impressum", e.g. under German law such as § 5 DDG/TMG or its successor provisions) is required depends on criteria that cannot be conclusively assessed here — among other things, on whether offering the app, despite its "hobby project" character, qualifies as a commercial telemedia service (e.g. due to regularity, scope, or possibly even free provision with an advertising or reach-building intent). This should be reviewed separately, on a case-by-case legal basis; this document deliberately makes no conclusive legal assessment on this point.
Thông tin về quyền riêng tư cho ứng dụng Android ViMiViTa (lập kế hoạch, tập luyện, dinh dưỡng, theo dõi, tiến độ và đề xuất)
Chính sách quyền riêng tư này được soạn với sự hỗ trợ của Claude (Anthropic) và không phải là tư vấn pháp lý. Người chịu trách nhiệm không phải là luật sư. Bản tiếng Đức là bản gốc; văn bản tiếng Việt này là bản dịch nhằm mục đích tham khảo. Trước khi đăng lên Google Play, nên có một luật sư chuyên về bảo vệ dữ liệu xem xét lại nội dung, đặc biệt liên quan đến các thỏa thuận cụ thể với các nhà cung cấp bên thứ ba được nêu dưới đây và các yêu cầu đặc thù theo từng quốc gia.
Người chịu trách nhiệm theo Quy định Bảo vệ Dữ liệu chung của Liên minh Châu Âu (GDPR) đối với việc xử lý dữ liệu cá nhân trong ứng dụng ViMiViTa là:
ViMiViTa không được cung cấp trong khuôn khổ một hoạt động thương mại. Lưu ý về việc liệu có cần một bản "Impressum" (thông báo pháp lý) riêng hay không được nêu tại mục 17.
ViMiViTa được thiết kế để càng nhiều dữ liệu càng tốt được lưu trên thiết bị của bạn. Nếu bạn không chủ động tạo tài khoản đám mây, ứng dụng hoạt động hoàn toàn ngoại tuyến và cục bộ; trong trường hợp đó không có dữ liệu nào được gửi đến tôi hoặc bên thứ ba (ngoại trừ dữ liệu chẩn đoán lỗi và tính toàn vẹn được gửi tự động, xem mục 7–8).
Dữ liệu chỉ rời khỏi thiết bị của bạn khi bạn chủ động sử dụng một số tính năng tùy chọn sau:
| Tính năng | Tùy chọn? | Dữ liệu được gửi đến đâu? |
|---|---|---|
| Đồng bộ hóa đám mây (tài khoản Firebase) | Có – phải được thiết lập chủ động | Firebase (Google) Authentication & Firestore |
| Phân tích ảnh bằng AI / nhập kế hoạch | Có – cần khóa API riêng của bạn | Gửi trực tiếp đến nhà cung cấp AI bạn chọn (OpenAI, Anthropic, Google Gemini hoặc điểm cuối riêng của bạn) |
| Báo cáo lỗi (crash) | Tự động khi xảy ra lỗi/sự cố | Firebase Crashlytics (Google) |
| Kiểm tra tính toàn vẹn thiết bị | Tự động khi dùng tính năng đám mây | Google Play Integrity / Firebase App Check |
Nếu bạn quyết định tạo tài khoản (ví dụ để đồng bộ dữ liệu giữa các thiết bị hoặc để sao lưu), ViMiViTa sử dụng Firebase Authentication của Google. Các dữ liệu được xử lý bao gồm:
Dữ liệu đăng nhập này cần thiết để gắn dữ liệu đã đồng bộ của bạn với đúng tài khoản của bạn và để bảo vệ quyền truy cập vào dữ liệu đó.
Chức năng cốt lõi của ViMiViTa là thu thập và phân tích các dữ liệu sau, do chính bạn nhập hoặc nhập từ các nguồn được kết nối:
Những dữ liệu này được xem là dữ liệu sức khỏe theo Điều 9(1) GDPR và được bảo vệ đặc biệt. Theo mặc định, dữ liệu này chỉ được lưu hoàn toàn cục bộ trên thiết bị của bạn trong một cơ sở dữ liệu cục bộ. Dữ liệu chỉ được truyền đi khi bạn chủ động thiết lập đồng bộ hóa đám mây (mục 6).
An toàn khi cập nhật: Dữ liệu cục bộ của bạn được giữ nguyên qua các lần cập nhật ứng dụng. Các thay đổi về cấu trúc dữ liệu chỉ mang tính bổ sung (không xóa các cột/bảng hiện có), vì vậy sau khi cập nhật bạn sẽ vẫn tìm thấy dữ liệu cũ của mình không thay đổi.
ViMiViTa cung cấp các tính năng AI tùy chọn, ví dụ như phân tích ảnh bữa ăn hoặc nhập kế hoạch tập luyện/dinh dưỡng từ tệp. Các tính năng này bị tắt theo mặc định và yêu cầu bạn tự nhập khóa API của một trong các nhà cung cấp sau vào ứng dụng:
Quan trọng: ViMiViTa không vận hành máy chủ hay máy chủ trung gian (proxy) riêng cho việc này. Khi bạn sử dụng một tính năng AI, dữ liệu cần thiết (ví dụ: một ảnh bữa ăn hoặc nội dung của một tệp kế hoạch đã nhập) được gửi trực tiếp từ thiết bị của bạn đến nhà cung cấp mà bạn đã chọn và cấu hình, sử dụng khóa API của riêng bạn. Luôn chỉ có một nhà cung cấp hoạt động tại một thời điểm.
Chính sách quyền riêng tư của nhà cung cấp bạn chọn (OpenAI, Anthropic hoặc Google) cũng sẽ được áp dụng, vì nhà cung cấp đó đóng vai trò là bên kiểm soát dữ liệu độc lập đối với dữ liệu được gửi đến họ. Với vai trò là người phát triển dự án cá nhân này, tôi không có quyền truy cập hoặc hiểu biết gì về việc truyền dữ liệu đó, cũng như không có quyền truy cập vào khóa API hay nội dung bạn đã gửi.
Nếu bạn kích hoạt đồng bộ hóa đám mây, dữ liệu ứng dụng của bạn (hồ sơ, kế hoạch tập luyện và dinh dưỡng, nhật ký, chỉ số tiến độ) sẽ được truyền qua kết nối được mã hóa đến Google Firebase (Cloud Firestore) và được lưu tại đó dưới mã người dùng của bạn, để bạn có thể sử dụng trên nhiều thiết bị và khôi phục khi mất thiết bị.
Việc truy cập vào dữ liệu này được giới hạn ở phía máy chủ thông qua các quy tắc bảo mật, sao cho chỉ chính bạn (đã xác thực qua tài khoản của mình) mới có thể đọc và ghi dữ liệu của riêng mình. Vì lý do kỹ thuật đồng bộ hóa, việc xóa cứng từng bản ghi riêng lẻ qua ứng dụng không được hỗ trợ (thay vào đó sử dụng cơ chế đánh dấu "tombstone"); việc xóa hoàn toàn được thực hiện qua chức năng được mô tả ở mục 12.
Để cải thiện độ ổn định của ứng dụng, ViMiViTa sử dụng Firebase Crashlytics của Google. Khi xảy ra sự cố hoặc lỗi không được xử lý, thông tin chẩn đoán kỹ thuật sẽ được tự động gửi đi, bao gồm:
Trong khả năng cho phép, các báo cáo này không chứa nội dung dữ liệu sức khỏe hoặc tập luyện của bạn, mà chỉ giới hạn ở thông tin lỗi kỹ thuật dùng để khắc phục sự cố.
Để bảo vệ các tính năng đám mây khỏi bị lạm dụng (ví dụ: truy cập tự động, phiên bản ứng dụng bị chỉnh sửa), ViMiViTa sử dụng Google Play Integrity kết hợp với Firebase App Check. Việc này gửi các tín hiệu toàn vẹn liên quan đến thiết bị và ứng dụng đến Google để xác nhận rằng các yêu cầu xuất phát từ một bản cài đặt ứng dụng thật, không bị chỉnh sửa. Việc kiểm tra này chỉ diễn ra khi bạn sử dụng các tính năng đám mây.
Dữ liệu cục bộ vẫn nằm trên thiết bị của bạn cho đến khi bạn tự xóa (ví dụ: bằng cách xóa hồ sơ cục bộ hoặc gỡ cài đặt ứng dụng). Dữ liệu đã đồng bộ lên đám mây được lưu trên các máy chủ của Google Firebase (khu vực trung tâm dữ liệu theo quy định của Google cho dự án đang sử dụng) và được giữ lại cho đến khi bạn chủ động xóa tài khoản và dữ liệu đám mây của mình (mục 12), hoặc trừ khi có nghĩa vụ lưu trữ theo luật pháp yêu cầu khác.
Báo cáo lỗi và tín hiệu toàn vẹn được xử lý và lưu trữ theo thời hạn lưu trữ tiêu chuẩn của Google Firebase Crashlytics và Google Play Integrity tương ứng.
Việc xử lý dữ liệu của bạn dựa trên các cơ sở pháp lý sau:
Bạn có thể rút lại sự đồng ý đã cho vào bất kỳ lúc nào, có hiệu lực cho tương lai, ví dụ bằng cách tắt đồng bộ hóa đám mây hoặc xóa hoàn toàn tài khoản của bạn.
Theo GDPR, bạn có các quyền sau, đặc biệt là:
Để thực hiện các quyền này, bạn có thể liên hệ với tôi qua email vào bất kỳ lúc nào, theo địa chỉ liên hệ được nêu tại mục 16.
ViMiViTa cung cấp hai cách xóa khác nhau, có sẵn trực tiếp trong ứng dụng, tùy thuộc vào loại dữ liệu bạn muốn xóa:
Thông qua phần quản lý người dùng trong ứng dụng, bạn có thể xóa một hồ sơ cục bộ. Việc này chỉ xóa dữ liệu được lưu cục bộ trên thiết bị của hồ sơ đó. Dữ liệu của tài khoản này (nếu có) được lưu trên đám mây sẽ không bị ảnh hưởng.
Trong phần "Sync Center" của ứng dụng có chức năng "Xóa tài khoản và dữ liệu đám mây". Sau bước xác nhận hai lần (một cảnh báo và yêu cầu nhập địa chỉ email để xác nhận), một quy trình xóa ở phía máy chủ sẽ được kích hoạt, xóa vĩnh viễn tài khoản Firebase của bạn cùng toàn bộ dữ liệu đám mây liên quan (hồ sơ, kế hoạch, nhật ký, lịch sử thay đổi). Hành động này không thể hoàn tác.
Ngoài ra, bạn cũng có thể gửi yêu cầu xóa dữ liệu đến tôi qua email vào bất kỳ lúc nào (xem thông tin liên hệ tại mục 16).
Các bên thứ ba sau có thể nhận được quyền truy cập vào (một phần) dữ liệu của bạn, tùy theo tính năng tùy chọn nào được mô tả trên đây mà bạn sử dụng:
| Nhà cung cấp | Mục đích | Thông tin quyền riêng tư |
|---|---|---|
| Google / Firebase (Google Ireland Ltd. hoặc Google LLC) | Xác thực, đồng bộ hóa đám mây, báo cáo lỗi, tính toàn vẹn ứng dụng/thiết bị | policies.google.com/privacy |
| OpenAI (chỉ khi bạn chủ động sử dụng với khóa riêng) | Phân tích ảnh/kế hoạch bằng AI | openai.com/policies/privacy-policy |
| Anthropic (chỉ khi bạn chủ động sử dụng với khóa riêng) | Phân tích ảnh/kế hoạch bằng AI | anthropic.com/legal/privacy |
| Google Gemini (chỉ khi bạn chủ động sử dụng với khóa riêng) | Phân tích ảnh/kế hoạch bằng AI | policies.google.com/privacy |
Việc truyền dữ liệu đến một điểm cuối tương thích OpenAI do bạn tự chỉ định hoàn toàn thuộc trách nhiệm của riêng bạn; tôi không có ảnh hưởng hoặc hiểu biết gì về cách điểm cuối đó xử lý dữ liệu.
ViMiViTa không hướng đến đối tượng trẻ em một cách cụ thể. Người dưới 16 tuổi chỉ nên sử dụng ứng dụng khi có sự đồng ý của cha mẹ hoặc người giám hộ hợp pháp, đặc biệt liên quan đến việc xử lý dữ liệu sức khỏe và việc sử dụng các tính năng đám mây và AI tùy chọn.
Chính sách quyền riêng tư này có thể được cập nhật khi các tính năng của ViMiViTa hoặc các yêu cầu pháp lý liên quan thay đổi. Phiên bản hiện hành luôn có thể được truy cập qua liên kết trong ứng dụng hoặc trên trang Play Store; ngày ghi tại "Cập nhật lần cuối" ở đầu tài liệu này cho biết lần sửa đổi gần nhất.
Đối với các câu hỏi về quyền riêng tư, để thực hiện quyền của bạn, hoặc để yêu cầu xóa dữ liệu, vui lòng liên hệ qua email:
Tài liệu này là một bản dự thảo được Claude (Anthropic) soạn theo yêu cầu của người chịu trách nhiệm. Đây không phải là tư vấn pháp lý và không thay thế cho việc xem xét pháp lý riêng biệt. Khuyến nghị rõ ràng là nên có một luật sư chuyên về pháp luật bảo vệ dữ liệu xem xét văn bản này trước khi công bố.
Việc liệu có cần một "Impressum" riêng biệt (ví dụ theo § 5 DDG/TMG của Đức hoặc các quy định thay thế tương ứng) ngoài chính sách quyền riêng tư này hay không phụ thuộc vào các tiêu chí không thể đánh giá dứt điểm ở đây — trong đó có việc liệu việc cung cấp ứng dụng, dù mang tính chất "dự án cá nhân/sở thích", có được xem là một dịch vụ truyền thông điện tử mang tính kinh doanh hay không (ví dụ do tính thường xuyên, quy mô, hoặc thậm chí do cung cấp miễn phí nhưng với mục đích quảng cáo hoặc mở rộng phạm vi tiếp cận). Vấn đề này cần được xem xét pháp lý riêng biệt theo từng trường hợp cụ thể; tài liệu này chủ ý không đưa ra đánh giá pháp lý dứt điểm về vấn đề này.